Computer implemented system and method for sharing a common secret
Abstract
A method of sharing a first common secret among multiple nodes (A, B, C) is disclosed to enable secure communication of blockchain transactions as in the Bitcoin blockchain. The method involves multiple second common secrets (S) for at least one first node (A).APC, SAIn the step of determining PB), each second common secret is common to the first node and each second node (B), and in the first node, the first secret key of the first node ( SA) And the first public key (PC, PB) of the second node, the first private key (SB, SC) of the second node and the first public key (SB, SC) of the first node in the second node. PA) Is determined. The third common secret (SBPC, SCPB) common to the second node (B) and the third node (C) is determined for the second node. The method includes, at the first node, a step of encrypting a share of the first common secret known to the first node and a step of transmitting the encrypted share to the second node. .. The method is a step of receiving an encrypted share of the first common secret from the second node in the first node, and each of the plurality of nodes accesses the first common secret. Further includes steps that allow the share of the threshold number of the first common secret to be reached.

Term
Projected expiry 11 September 2039.
- Priority
- Filed
- Published
- Today
- Projected expiry
31 claims: 6 independent, 25 dependent
- 1複数のノードの間で第1共通シークレットを共有する方法であって、各々の前記ノードは、前記複数のノードに共通の暗号システムのそれぞれの第1秘密鍵及びそれぞれの第1公開鍵を有するそれぞれの非対称暗号第1鍵ペアに関連付けられ、前記第1共通シークレットは、前記ノードの各々の前記第1秘密鍵に基づき、前記方法は、 少なくとも1つの第1ノードについて、複数の第2共通シークレットを決定するステップであって、各々の前記第2共通シークレットは、前記第1ノード及びそれぞれの第2ノードに共通であり、前記第1ノードにおいて前記第1ノードの前記第1秘密鍵及び前記第2ノードの前記第1公開鍵に基づき決定され、前記第2ノードにおいて前記第2ノードの前記第1秘密鍵及び前記第1ノードの前記第1公開鍵に基づき決定され、前記第1共通シークレットの複数のシェアはそれぞれ、少なくとも1つのそれぞれの第2共通シークレットに基づき、前記第1共通シークレットが閾数の前記シェアにアクセス可能になるが、前記閾数より少ないシェアにアクセス不可能になる、ステップと、 少なくとも1つの第2ノードについて、少なくとも1つのそれぞれの第3共通シークレットを決定するステップであって、それぞれの第3共通シークレットは、前記第2ノード及びそれぞれの第3ノードに共通であり、前記第2ノードにおいて前記第2ノードの前記第1秘密鍵及び前記第3ノードの前記第1公開鍵に基づき決定され、前記第3ノードにおいて前記第3ノードの前記第1秘密鍵及び前記第2ノードの前記第1公開鍵に基づき決定され、前記第1共通シークレットの少なくとも1つのシェアは、少なくとも1つのそれぞれの前記第3共通シークレットに基づく、ステップと、 少なくとも1つの前記第1ノードにおいて、前記第1ノードに知られている前記第1共通シークレットの少なくとも1つのシェアを、暗号システムのそれぞれの非対称暗号第2鍵ペアの第2秘密鍵に基づき、暗号化するステップであって、前記第2鍵ペアは前記第1ノードに知られているそれぞれの前記第2共通シークレットに基づく、ステップと、 少なくとも1つの前記の暗号化されたシェアを、前記第1ノードから、前記第2鍵ペアが基づく前記第2共通シークレットが共通であるそれぞれの前記第2ノードへ送信するステップと、 少なくとも1つの前記第1ノードにおいて、少なくとも1つの前記第2ノードから、前記第2ノードに知られており前記暗号システムのそれぞれの非対称暗号第2鍵ペアの第2秘密鍵に基づき暗号化された前記第1共通シークレットの少なくとも1つのそれぞれのシェアを受信するステップであって、前記第2鍵ペアは、前記第1ノード及び前記第2ノードに共通の前記第2共通シークレットに基づき、前記複数のノードの各々が前記第1共通シークレットの前記閾数のシェアに達することを可能にする、ステップと、 を含む方法。
- 2複数の前記の暗号化されたシェアは、それぞれ、対応する前記ノードに知られている複数の前記共通シークレットの結合に基づく、請求項1に記載の方法。
- 3複数の前記の暗号化されたシェアは、対応する前記ノードに知られている複数の前記共通シークレットの少なくとも1つのそれぞれのXOR結合に基づく、請求項2に記載の方法。
- 4複数の前記の暗号化されたシェアは、対応する前記ノードに知られている複数の前記共通シークレットの乗算結合に基づく、請求項2又は3に記載の方法。
- 5前記乗算結合は(x 1 ,x 2 ,x 3 ) mod nの形式であり、x 1 ,x 2 ,x 3 はノードに知られている共通シークレットであり、nは暗号システムの次数である、請求項4に記載の方法。
- 6複数の前第1シェアは、第1多項式関数のシェアであり、前記第1共通シークレットは、少なくとも閾数の前記シェアの多項式補間により決定される、請求項1~5のいずれか一項に記載の方法。
- 7前記第1共通シークレットの少なくとも閾数のシェアを受信するステップであって、各々の前記シェアは前記第1多項式関数のそれぞれの値に対応する、ステップと、 前記第1共通シークレットを決定するために、前記シェアの複数の知られている値から、前記第1多項式関数の係数を決定することにより、前記第1多項式関数を決定するステップと、 を更に含む請求項6に記載の方法。
- 8前記第1多項式関数を決定するステップは、誤り訂正アルゴリズムを実行するステップを含む、請求項7に記載の方法。
- 9前記第1多項式関数を決定するステップは、Berlekamp-Welch復号アルゴリズムを実行するステップを含む、請求項8に記載の方法。
- 10前記第1多項式関数を決定するステップは、 誤り位置多項式関数及び第2多項式関数を定義するステップであって、前記第2多項式関数は、前記第1多項式関数と前記誤り位置多項式関数との積である、ステップと、 前記部分署名の複数の知られている値から、前記第2多項式関数及び前記誤り位置多項式関数の係数を決定するステップと、 前記第1共通シークレットを決定するために、前記第2多項式関数及び前記誤り検出多項式関数から前記第1多項式関数を決定するステップと、 を含む、請求項7又は8に記載の方法。
- 11少なくとも1つの前記暗号システムは、準同型特性を有する、請求項1~10のいずれか一項に記載の方法。
- 12少なくとも1つの前記暗号システムは、楕円曲線暗号システムである、請求項11に記載の方法。
- 13少なくとも第1ノードのマスタ秘密鍵(V 1C )と前記第1及び第2ノードと共通な決定性鍵(DK)とに基づき、少なくとも1つの前記第1ノードの前記第1秘密鍵を決定するステップと、 前記第2ノードのマスタ公開鍵(P 1S )と共通暗号システムを用いる前記決定性鍵(DK)の暗号化とに基づき、少なくとも1つの前記第2ノードの前記第1公開鍵(P 2S )を決定するステップと、 を更に含む請求項1~12のいずれか一項に記載の方法。
- 14前記決定性鍵(DK)は、メッセージ(M)に基づく、請求項13に記載の方法。
- 15前記メッセージ(M)及び前記第1ノードの第1秘密鍵(V 2C )に基づき、第1署名付きメッセージ(SM1)を生成するステップと、 通信ネットワークを介して、前記第1署名付きメッセージ(SM1)を前記第2ノード(S)へ送信するステップであって、前記第1署名付きメッセージ(SM1)は、前記第1ノード(C)を認証するために、前記第1ノードの第1公開鍵(P 2C )により検証できる、ステップと、 を更に含む請求項14に記載の方法。
- 16通信ネットワークを介して、前記第2ノード(S)から第2署名付きメッセージ(SM2)を受信するステップと、 前記第2ノードの前記第1公開鍵(P 2S )により、前記第2署名付きメッセージ(SM2)を検証するステップと、 前記第2署名付きメッセージ(SM2)を検証した結果に基づき、前記第2ノード(S)を認証するステップと、 を更に含み、 前記第2署名付きメッセージ(SM2)は、メッセージ(M)又は第2メッセージ(M2と前記第2ノードの前記第1秘密鍵(V 2S )とに基づき生成されたものである、請求項14又は15に記載の方法。
- 17メッセージ(M)を生成するステップと、 通信ネットワークを介して、前記メッセージ(M)を前記第2ノードへ送信するステップと、 を更に含む請求項14~16のいずれか一項に記載の方法。
- 18通信ネットワークを介して、前記第2ノード(S)から前記メッセージ(M)を受信するステップ、 を更に含む請求項14~17のいずれか一項に記載の方法。
- 19通信ネットワークを介して、別のノードから前記メッセージ(M)を受信するステップ、 を更に含む請求項14~18のいずれか一項に記載の方法。
- 20データストア及び/又は前記第1ノード(C)に関連付けられた入力インタフェースから、前記メッセージ(M)を受信するステップ、 を含む請求項14~19のいずれか一項に記載の方法。
- 21前記暗号システムは楕円曲線暗号(ECC)システムであり、前記第1ノードのマスタ公開鍵(P 1C )及び第2ノードのマスタ公開鍵(P 1S )は、それぞれ第1ノードのマスタ秘密鍵(V 1C )及び第2ノードのマスタ秘密鍵(V 1S )と生成元(G)との楕円曲線点積に基づく、請求項13~20のいずれか一項に記載の方法。
- 22通信ネットワークを介して、前記第2ノードのマスタ公開鍵(P 1S )を受信するステップと、 前記第1ノード(C)に関連付けられたデータストアに、前記第2ノードのマスタ公開鍵(P 1S )を格納するステップと、 を更に含む請求項13~21のいずれか一項に記載の方法。
- 23第1ノード(C)において、第1ノードのマスタ秘密鍵(V 1C )及び第1ノードのマスタ秘密鍵(P 1C )を生成するステップと、 通信ネットワークを介して、前記第1ノードのマスタ公開鍵(P 1C )を前記第2ノード(S)及び/又は他のノードへ送信するステップと、 前記第1ノード(C)に関連付けられた第1データストアに、前記第1ノードのマスタ秘密鍵(V 1C )を格納するステップと、 を更に含む請求項13~22のいずれか一項に記載の方法。
- 24通信ネットワークを介して、前記第2ノードへ、少なくとも1つの前記共通シークレット(CS)を決定する方法のために共通暗号システムを使用することを示す通知を送信するステップ、を更に含み、 前記第1ノードのマスタ秘密鍵(V 1C )及び前記第1ノードのマスタ公開鍵(P 1C )を生成するステップは、 前記共通暗号システムで指定される許容範囲内のランダムな整数に基づき、前記第1ノードのマスタ秘密鍵(V 1C )を生成するステップと、 前記第1ノードのマスタ秘密鍵(V 1C )の暗号化に基づき、前記第1ノードのマスタ公開鍵(P 1C )を決定するステップと、 を含む、請求項13~23のいずれか一項に記載の方法。
- 25前記共通暗号システムは、共通の生成元(G)を有する楕円曲線暗号(ECC)システムであり、前記第1ノードのマスタ公開鍵(P 1C )は、次式:P 1C =V 1C ×G に従い、前記第1ノードのマスタ秘密鍵(V 1C )及び前記共通の生成元(G)の楕円曲線点積に基づき決定される、請求項13~24のいずれか一項に記載の方法。
- 26メッセージ(M)のハッシュを決定することに基づき、前記決定性鍵(DK)を決定するステップ、を更に含み、 前記第1ノードの第1秘密鍵(V 2C )を決定するステップは、次式:V 2C =V 1C +DK に従う、前記第1ノードのマスタ秘密鍵(V 1C )及び前記決定性鍵(DK)のスカラー加算に基づき、 前記第2ノードの第1公開鍵(P 2S )を決定するステップは、次式: P 2S =P 1S +DK×G に従う、前記決定性鍵(DK)及び前記共通の生成元(G)の楕円曲線点積への前記第2ノードのマスタ公開鍵(P 1S )の楕円曲線点加算に基づき、 前記決定性鍵(DK)は、前の決定性鍵のハッシュを決定することに基づき得る、 請求項13~25のいずれか一項に記載の方法。
- 27複数のノードの間のセキュアな通信の方法であって、前記方法は、 請求項1~26のいずれか一項に記載の方法により、複数のノードの間で第1共通シークレットを共有するステップと、 前記第1共通シークレットに基づき対称鍵を決定するステップと、 前記対称鍵により第1通信メッセージを暗号化して、暗号化第1通信メッセージにするステップと、 通信ネットワークを介して、前記複数のノードのうちの1つのノードから前記複数のノードのうちの他のノードへ、前記暗号化第1通信メッセージを送信するステップと、 を含む方法。
- 28通信ネットワークを介して、前記複数のノードのうちの1つのノードから、暗号化第2通信メッセージを受信するステップと、 前記対称鍵により前記暗号化第2通信メッセージを復号して、第2通信メッセージにするステップと、 を更に含む請求項27に記載の方法。
- 29複数のノードの間のオンライントランザクションを実行する方法であって、前記方法は、 請求項1~26のいずれか一項に記載の方法により、複数のノードの間で第1共通シークレットを共有するステップと、 前記第1共通シークレットに基づき対称鍵を決定するステップと、 前記対称鍵により第1トランザクションメッセージを暗号化して、暗号化第1トランザクションメッセージにするステップと、 通信ネットワークを介して、前記複数のノードのうちの第1ノードから前記複数のノードのうちの他のノードへ、前記暗号化第1トランザクションメッセージを送信するステップと、 を含む方法。
- 30システムであって、 プロセッサと、 前記プロセッサによる実行の結果として、前記システムに請求項1~29のいずれか一項に記載の方法を実行させる実行可能命令を含むメモリと、 を含むシステム。
- 31実行可能命令を記憶した非一時的コンピュータ可読記憶媒体であって、前記実行可能命令は、コンピュータシステムのプロセッサにより実行された結果として、前記コンピュータシステムに、請求項1~29のいずれか一項に記載の方法を実行させる、非一時的コンピュータ可読記憶媒体。
Independent claims31
188 paragraphs, as filed
The present disclosure relates generally to how to share a common secret among multiple nodes, and in particular to how to share a common secret among at least three nodes. This disclosure is particularly suitable for, but not limited to, use in cryptography to enable secure communication between nodes, including but not limited to digital wallets, blockchain (eg, Bitcoin) technologies, and for individuals. May be suitable for use with device security.
As used herein, we use the term "blockchain" to include all forms of electronic, computer-based, distributed ledgers. These include consensus-based blockchain and transaction chain technologies, licensed and unauthorized ledgers, shared ledgers, and variants thereof. The most widely known application of blockchain technology is the Bitcoin ledger, although other blockchain implementations have been proposed and developed. Bitcoin is herein referred to herein for convenience and illustration purposes, but the present disclosure is not limited to its use with the Bitcoin blockchain, and alternative blockchain implementations and protocols are included within the scope of this disclosure. It should be noted that. The term "user" may here represent a human or processor-based resource.
A blockchain is a peer-to-peer electronic ledger implemented as a computer-based decentralized decentralized system, composed of blocks, which are also composed of transactions. Each transaction is a data structure that encodes the transfer of control of a digital asset between participants in a blockchain system and contains at least one input and at least one output. Each block contains a hash of the previous block, and these blocks are joined together to produce a permanent, immutable record of all transactions that have been written to the blockchain since their origin. A transaction involves a small program known as a script. The script embeds those inputs and outputs and specifies how and by whom the transaction outputs are accessible. On the Bitcoin platform, these scripts are written using a stack-based scripting language.
In order for a transaction to be written to the blockchain, it must be validated. The network node (minor) performs work to ensure that invalid transactions are rejected from the network and each transaction is valid. Software clients installed on the node are unspent transactions, Perform this verification work on the UTXO by running the UTXO) lock and unlock scripts. If the lock and unlock script execution evaluates to TRUE, then the transaction is valid and the transaction is written to the blockchain. Therefore, in order for a transaction to be written to the blockchain, (i) it is verified by the first node that received the transaction, and if the transaction is valid, the node relays the transaction to other nodes in the network. It needs to be (ii) added to a new block built by the miner, (iii) mined, that is, added to the public ledger of past transactions.
Blockchain technology is best known for the use of cryptocurrency implementations, but both the Bitcoin-based crypto security system and the data that digital entrepreneurs can store in the blockchain to implement new systems. Beginning to develop use. It would be very advantageous if blockchain could be used for automated tasks and processes that are not limited to the field of cryptocurrencies.
Such solutions can take advantage of blockchain benefits (eg, permanence, tamper resistance of event recording, decentralized processing, etc.) and make their uses more diverse.
International Patent Application WO 2017/145016 discloses a method of sharing a common secret between two nodes in order to enable secure communication between the nodes.
However, it is desirable to provide a way to share a common secret between two or more nodes.
Such an improved solution is devised here.
Therefore, according to the present disclosure, the method specified in the attached claims is provided.
According to the present disclosure, it is a method of sharing a first common secret among a plurality of nodes, and each said node is a first secret key of a cryptographic system common to the plurality of nodes and a first of each. Associated with each asymmetric cryptographic first key pair having a public key, the first common secret is based on the first private key of each of the nodes, and the method is multiple for at least one first node. In the step of determining the second common secret, each of the second common secrets is common to the first node and each second node, and in the first node, the first secret of the first node. Determined based on the key and the first public key of the second node, determined on the second node based on the first private key of the second node and the first public key of the first node, said first. Multiple shares of one common secret are each based on at least one each second common secret, and the first common secret can access the share of the threshold number, but cannot access the share less than the threshold number. Become, step and It is a step of determining at least one each third common secret for at least one second node, and each third common secret is common to the second node and each third node, and is said to be the first. In the 2 nodes, the first secret key of the 2nd node and the 1st public key of the 3rd node are determined, and in the 3rd node, the 1st secret key of the 3rd node and the 2nd node of the 3rd node. Determined based on the first public key, at least one share of the first common secret is based on at least one each said third common secret, in a step and at least one said first node. A step of encrypting at least one share of the first common secret known to a node based on the second secret key of each asymmetric cryptographic second key pair in the cryptosystem, the second key pair. Based on each of the second common secrets known to the first node, A step of transmitting at least one of the encrypted shares from the first node to each of the second nodes having the second common secret based on the second key pair, and at least one of the above. In the first node, from at least one of the second nodes, the first secret known to the second node and encrypted based on the second secret key of each asymmetric cryptographic second key pair of the cryptosystem. In the step of receiving at least one share of the above, the second key pair is based on the second common secret common to the first node and the second node, and each of the plurality of nodes said. A method comprising steps is provided that allows the share of the threshold number of the first common secret to be reached.
This provides the advantage of sharing a common secret among multiple nodes and providing an efficient way in which the common secret can be used as the basis for secure communication between the nodes.
Each of the plurality of the encrypted shares is based on the combination of the plurality of the common secrets known to the corresponding node.
This obfuscates individual common secrets to third parties, thereby improving efficiency while allowing for improved privacy, for example when shared secrets are included in the script of a blockchain transaction. Provides the advantage of.
The plurality of said encrypted shares may each be based on their respective XOR coupling of at least one of the plurality of said common secrets known to the corresponding node.
This provides the advantage of simplifying the process, thereby facilitating the restoration of the first common secret by the receiving node.
The plurality of the encrypted shares may be based on the multiplication and coupling of the plurality of the common secrets known to the corresponding node.
The multiplication combination is (x<sub>1</sub>, x<sub>2</sub>, x<sub>3</sub>) Can be in the form of mod n, x<sub>1</sub>, x<sub>2</sub>, x<sub>3</sub>Is a common secret known to the node and n is the order of the cryptosystem.
The plurality of said shares may be the shares of the first polynomial function, and the first secret may be determined by polynomial interpolation of the shares of at least a threshold number.
The method is a step of receiving at least a share of the threshold number of the first common secret, wherein each share corresponds to a value of the first polynomial function, and the step and the first common secret. To determine, further include the step of determining the first polynomial function by determining the coefficients of the first polynomial function from a plurality of known values of the share.
The step of determining the first polynomial function may include a step of executing an error correction algorithm.
The step of determining the first polynomial function may include the step of executing the Berlekamp-Welch decoding algorithm.
The step of determining the first polymorphic function is a step of defining an error position polymorphic function and a second polynomial function, and the second polynomial function is the product of the first polynomial function and the error position polymorphic function. In order to determine the first common secret, the step of determining the coefficients of the second polynomial function and the error position polymorphic function from a step and a plurality of known values of the subsignature. 2 It may include a step of determining the first polynomial function from the polymorphic function and the error detection polymorphic function.
At least one of the cryptosystems may have homomorphic properties.
This offers the advantage of allowing more flexible and efficient operation of the method.
The at least one digital signature may be based on an elliptic curve cryptosystem.
This provides high security benefits for a given key size.
The method is at least the master private key of the first node (V).<sub>1C</sub>) And the deterministic key (DK) common to the first and second nodes, the step of determining the first private key of at least one of the first nodes, and the master public key (P) of the second node.<sub>1S</sub>) And the encryption of the deterministic key (DK) using the common cryptosystem, the first public key (P) of at least one of the second nodes.<sub>2S</sub>) And may be further included.
The deterministic key (DK) may be based on the message (M).
The message (M) and the first secret key (V) of the first node.<sub>2C</sub>), The first signed message (SM1) is generated, and the first signed message (SM1) is transmitted to the second node (S) via the communication network. The first signed message (SM1) is the first public key (P) of the first node in order to authenticate the first node (C).<sub>2C</sub>) May include further steps, which can be verified by.
The method includes a step of receiving a second signed message (SM2) from the second node (S) via the communication network, and the first public key (P) of the second node.<sub>2S</sub>) Further includes a step of verifying the second signed message (SM2) and a step of authenticating the second node (S) based on the result of verifying the second signed message (SM2). The second signed message (SM2) may be the message (M) or the second message (M2) and the first private key (V) of the second node.<sub>2S</sub>) And.
The method may further include a step of generating a message (M) and a step of transmitting the message (M) to the second node via a communication network.
The method may further include the step of receiving the message (M) from the second node (S) via the communication network.
The method may further include the step of receiving the message (M) from another node via the communication network.
The method may include receiving the message (M) from a data store and / or an input interface associated with the first node (C).
The cryptosystem may be an Elliptic Curve Cryptography (ECC) system and is the master public key (P) of the first node.<sub>1C</sub>) And the master public key of the second node (P<sub>1S</sub>) Is the master private key (V) of the first node, respectively.<sub>1C</sub>) And the master private key of the second node (V)<sub>1S</sub>) And the generator (G) may be based on the elliptic curve dot product.
The method is a master public key (P) of the second node via the communication network.<sub>1S</sub>) And the master public key (P) of the second node in the data store associated with the first node (C).<sub>1S</sub>) Storing, and may further include.
In the above method, in the first node (C), the master secret key (V) of the first node is used.<sub>1C</sub>) And the master private key of the first node (P)<sub>1C</sub>) And the master public key (P) of the first node via the communication network.<sub>1C</sub>) To the second node (S) and / or another node, and the master secret key (V) of the first node to the first data store associated with the first node (C).<sub>1C</sub>) Storing, and may further include.
The method further comprises sending a notification via the communication network to the second node indicating that a common cryptosystem is used for the method of determining at least one common secret (CS). It may include the master secret key (V) of the first node.<sub>1C</sub>) And the master public key of the first node (P)<sub>1C</sub>) Is based on a random integer within the permissible range specified by the common cryptosystem, and the master secret key (V) of the first node.<sub>1C</sub>) And the master private key (V) of the first node.<sub>1C</sub>), The master public key (P) of the first node.<sub>1C</sub>) And include.
The common cryptosystem is an elliptic curve cryptosystem (ECC) system having a common source (G), and is the master public key (P) of the first node.<sub>1C</sub>) Is: P<sub>1C</sub>= V<sub>1C</sub>× According to G, the master secret key (V) of the first node.<sub>1C</sub>) And the elliptic curve dot product of the common generator (G).
The method may further include a step of determining the deterministic key (DK) based on determining the hash of the message (M), the first secret key (V) of the first node.<sub>2C</sub>) Is determined by the following equation: V<sub>2C</sub>= V<sub>1C</sub>Master private key (V) of the first node according to + DK<sub>1C</sub>) And the scalar addition of the deterministic key (DK), the first public key (P) of the second node.<sub>2S</sub>) Is determined by the following equation: P<sub>2S</sub>= P<sub>1S</sub>The master public key (P) of the second node to the elliptic curve dot product of the deterministic key (DK) and the common source (G) according to + DK × G.<sub>1S</sub>) Based on elliptic curve point addition.
The deterministic key (DK) may be based on determining the hash of the previous deterministic key.
The present disclosure is a method of secure communication between a plurality of nodes, wherein the method determines a first common secret by the above method and a symmetric key based on the first common secret. A step, a step of encrypting the first communication message with the symmetric key to make the encrypted first communication message, and one of the plurality of nodes to the plurality of nodes via the communication network. A method including a step of transmitting the encrypted first communication message to another node may also be provided.
The method comprises receiving an encrypted second communication message from one of the plurality of nodes via a communication network, and decrypting the encrypted second communication message with the symmetric key. It may further include a step to make it a second communication message.
The present disclosure is a method of executing an online transaction between a plurality of nodes, wherein the method determines a first common secret by the above method and a symmetric key based on the first common secret. Steps to encrypt the first transaction message with the symmetric key to make the encrypted first transaction message, and the first node among the plurality of nodes to the plurality of nodes via the communication network. Further methods may be provided, including the step of sending the encrypted first transaction message to other of our nodes.
The present disclosure also provides a system comprising a processor and, as a result of execution by the processor, a memory containing executable instructions that cause the system to perform any embodiment of the methods performed by a computer as described herein. do.
The present disclosure is a non-temporary computer-readable storage medium that stores an executable instruction, wherein the executable instruction is at least described herein in the computer system as a result of being executed by a processor of the computer system. Also provided is a non-temporary computer-readable storage medium that implements the methods performed by the computer.
These and other aspects of the present disclosure are evident from the embodiments described herein and are taught with reference to them.
The embodiments of the present disclosure are described below with reference to the accompanying drawings, by way of example only.<figref num="1">It is a schematic of an exemplary system for determining a common secret of the first node and the second node.</figref><figref num="2">It is a flowchart of a computer-implemented method of determining a common secret.</figref><figref num="3">It is a flowchart of the method performed by a computer to register the 1st and 2nd nodes.</figref><figref num="4">Another flow chart of the computer-implemented method of determining a common secret.</figref><figref num="5">It is a flowchart of a method performed by a computer for secure communication between the first node and the second node.</figref><figref num="6">It is a flowchart of the method performed by a computer to authenticate the first node and the second node.</figref><figref num="7">It is a figure which shows the method of realizing this disclosure which shares a common secret among three nodes.</figref><figref num="8">It is a flowchart of the method of FIG.</figref><figref num="9">A Berlekamp-Welch decoder that restores the first common secret in a way to achieve this disclosure is shown.</figref><figref num="10">It is a flowchart of the method of realizing this disclosure which shares a common secret among four nodes.</figref><figref num="11">It is a schematic diagram which shows the computing environment which can implement various embodiments.</figref>
<Overview> First, a method, an apparatus, and a system for determining a common secret (CS), which is the same common secret as that in the second node (S), is described in the first node (C). It is used to determine a second common secret between a pair of nodes, and then multiple nodes containing 3 or more nodes, as detailed below with reference to FIGS. 7 and 8. Used to share the first common secret between. FIG. 1 shows a system 1 including a first node 3 communicating with a second node 7 via a communication network 5. The first node 3 has a related first processing device 23, and the second node 5 has a related second processing device 27. The first and second nodes 3 and 7 may include electronic devices such as computers, tablet computers, mobile communication devices, computer servers, and the like. In one example, the first node 3 may be a client device and the second node 7 is a server.
The first node 3 is the master secret key (V) of the first node.<sub>1C</sub>) And the master public key of the first node (P)<sub>1C</sub>) Is associated with the first asymmetric cryptographic pair. The second node (7) is the master secret key (V) of the second node.<sub>1S</sub>) And the master public key of the second node (P<sub>1S</sub>) Is associated with the second asymmetric cryptographic pair. The first and second asymmetric crypto pairs of the first and second nodes 3 and 7, respectively, may be generated during registration. Registration methods 100, 200 performed by the first and second nodes 3, 7 will be described in more detail with reference to FIG. The public key of each node may be publicly shared, for example, via the communication network 5.
In order to determine the common secret (CS) on both the first node 3 and the second node 7, the nodes 3 and 7 of the methods 300 and 400, respectively, without communicating the private key via the communication network 5. Perform the steps.
Method 300 performed on first node 3 is at least the first node's master private key (V).<sub>1C</sub>) And the second private key (V) of the first node based on the deterministic key (DK)<sub>2C</sub>) Includes step 320. The deterministic key may be based on the message (M) shared between the first and second nodes. This may include sharing messages over the communication network 5, as described in more detail below. Method 300 is at least the master public key of the second node (P)<sub>1S</sub>) And the second public key (P) of the second node based on the deterministic key (DK)<sub>2S</sub>) Also includes step 370 to determine. Method 300 is the second private key (V) of the first node.<sub>2C</sub>) And the second public key of the second node (P)<sub>2S</sub>) Includes step 380 to determine the common secret (CS).
Importantly, the same common secret (CS) can be determined at node 7 by method 400. Method 400 is the master public key of the first node (P).<sub>1C</sub>) And the second public key (P) of the first node based on the deterministic key (DK)<sub>2C</sub>) Includes step 430 to determine. Method 400 is based on the master secret key (V1S) and deterministic key (DK) of the second node and the second secret key (V) of the second node.<sub>2S</sub>) Also includes step 470 to determine. Method 400 is the second private key (V) of the second node.<sub>2S</sub>) And the second public key of the first node (P<sub>2C</sub>) Includes step 480 to determine the common secret (CS).
The communication network 5 may include a local area network, a wide area network, a cellular network, a wireless communication network, the Internet, and the like.
In these networks, data may be transmitted over communication media such as wires, fiber optics, or radio, and can be eavesdropped by eavesdroppers.
Methods 300, 400 may allow both the first node 3 and the second node 7 to independently determine a common secret without transmitting a common secret over the communication network 5. Therefore, one advantage is that the common secret (CS) can be determined securely by each node without the need to send the private key over the potentially insecure communication network 5. Also, the common secret can be used as a secret key (or as the basis of the secret key) for encrypted communication between the first node and the second nodes 3 and 7 via the communication network 5.
Methods 300, 400 may include additional steps. Method 300 is the message (M) and the second secret key (V) of the first node in the first node 3.<sub>2C</sub>) May include a step to generate a signed message (SM1). Method 300 further comprises step 360 of sending a first signed message (SM1) to a second node 7 over a communication network. In addition, the second node 7 may execute step 440 to receive the first signed message (SM1). Method 400 is the second public key of the first node (P).<sub>2C</sub>) Further includes step 450 for verifying the first signed message (SM1) and step 460 for verifying the first signed message (SM1) and authenticating the first node 3 based on the result. Advantageously, this allows the second node 7 to authenticate that the self-proclaimed first node (where the first signed message was generated) is the first node 3.
This is because only the first node 3 is the master secret key of the first node (V).<sub>1C</sub>), So only node 3 has access to the first node's second private key (V) for generating the first signed message (SM1).<sub>2C</sub>) Is based on the premise that it can be determined. It should be understood that the second signed message (SM2) can be generated at the second node 7 and sent to the first node 3. As a result, the first node 3 can authenticate the second node 7, as in the peer-to-peer scenario.
Sharing the message (M) between the first and second nodes may be accomplished in various ways. In one example, the message may be generated at the first node 3 and then transmitted over the communication network 5 to the second node 7. Alternatively, the message may be generated at the second node 7 and then transmitted over the communication network 5 to the second node 7. In yet another example, the message may be generated at the third node 9 and the message is sent to both the first and second nodes 3 and 7. In yet another example, the user may enter a message to be received by the first and second nodes 3, 7 through the user interface. In yet another example, the message (M) may be read from the data store 19 and sent to both the first and second nodes 3, 7. In some examples, the message (M) may be public and therefore sent over insecure network 5.
In a further example, one or more messages (M) may be stored in data stores 13, 17, 19, and the messages may be in a session, transaction, etc. between the first node 3 and the second node 7. May be associated. Therefore, the message (M) may be read at the first node 3 and the second node 7, respectively, and used to regenerate the common secret (CS) associated with the session or transaction. Advantageously, a record may be retained to allow the regeneration of the common secret (CS), and the record itself does not need to be stored secretly or transmitted securely. This is advantageous when a large number of transactions are executed on the first node 3 and the second node 7, and it is not practical to store the entire message (M) in the node itself.
<Registration methods 100, 200> Examples of registration methods 100, 200 will be described with reference to FIG. Here, method 100 is executed by the first node 3, and method 200h is executed by the second node 7. This involves establishing a first and second asymmetric crypto pair for each of the first node 3 and the second node 7.
Asymmetric crypto pairs include associated private and public keys, such as those used in public key cryptography. In this example, the asymmetric cryptographic pair is generated using the characteristics of Elliptic Curve Cryptography (ECC) and Elliptic Curve Arithmetic.
Standards for ECC may include known standards such as those developed by the Standards for Efficient Cryptography Group (www.sceg.org).
Elliptic curve cryptography is US5,600,725, US5,761,305, US5889,865, US5,896,455, US5,933,504, US6,122,736, US6,141,420, US6,618,483, US6,704,870, US6,785,813, US6,078,667, US6 It is also described in, 792,530.
In methods 100, 200, this includes steps 110, 210 in which the first and second nodes determine to use a common ECC system and a common generator (G, common generator; in one example, a common ECC system. May be based on secp256K1 which is the ECC system used by Bitcoin. The common generator (G) may be selected, randomly generated or assigned.
With reference to first node 3, method 100 includes step 110 to determine a common ECC system and a common generator (G). This may include the step of receiving a common ECC system and a common generator from the second node 7 or the third node 9. Alternatively, the user interface 15 may be associated with a first node 3, whereby the user may selectively provide a common ECC system and / or a common generator (G). In yet another alternative, one or both of the ECC system and / or the common generator (G) may be randomly selected by the first node 3. The first node 3 may send a notification to the second node 7 indicating that the common ECC system is used with the common generator (G) via the communication network 5. The second node 7 may also be determined by sending an acknowledgment indicating the use of the common ECC system and the common generator (G) 210.
In method 100, the first node 3 is the master secret key of the first node (V).<sub>1C</sub>) And the master public key of the first node (P)<sub>1C</sub>) Is further included in step 120 to generate a first asymmetric cryptographic pair. This is, at least in part, the master secret key (V) of the first node, based on a random integer within the tolerance specified by the common ECC system.<sub>1C</sub>) Includes steps to generate. This is the master private key (V) of the first node according to the following equation.<sub>1C</sub>) And the elliptic curve dot product of the common generator (G), the master public key (P) of the first node<sub>1C</sub>) Is further included.
<maths num="1"><img file="JP2022500920A_D0001.tif" /></maths> Therefore, the first asymmetric cryptographic pair includes:
V<sub>1C</sub>: The master secret key of the first node that is kept secret by the first node.
P<sub>1C</sub>: The master public key of the first node made publicly known.
The first node 3 is the master secret key (V) of the first node.<sub>1C</sub>) And the master public key of the first node (P)<sub>1C</sub>) May be stored in the first data store 13 associated with the first node 3. For security, the master private key of the first node (V)<sub>1C</sub>) May be stored in the secure part of the first data store 13 to ensure that it remains a key field secret.
Method 100 is a master public key (P) of the first node to the second node 7 via the communication network 5.<sub>1C</sub>) Is further included in step 130. The second node 7 is the master public key of the first node (P).<sub>1C</sub>) Is received 220, the master public key of the first node (P)<sub>1C</sub>) May be stored in the second data store 17 associated with the second node 7. 230.
Similar to the first node 3, the method 200 of the second node 7 is the master secret key (V) of the second node.<sub>1S</sub>) And the master public key of the second node (P<sub>1S</sub>) Includes step 240 to generate a second asymmetric cipher pair with). Master private key of the second node (V<sub>1S</sub>) Is also a random integer within the permissible range. Also, the master public key of the 2nd node (P)<sub>1S</sub>) Is determined by the following equation.
<maths num="2"><img file="JP2022500920A_D0002.tif" /></maths> Therefore, the second asymmetric cryptographic pair includes:
V<sub>1S</sub>: The master secret key of the second node that is kept secret by the second node.
P<sub>1S</sub>: The master public key of the second node made publicly known.
The second node 7 may store the second asymmetric cryptographic pair in the second data store 17. Method 200 is to go to the first node 3 and the master public key of the second node (P).<sub>1S</sub>) Is further included in step 250. The first node 3 is the master public key of the second node (P).<sub>1S</sub>) Receive 140, may store 150.
It should be understood that in some alternatives, each public master key is received and stored in a third data store 19 associated with a third node 9 (like a trusted third party). .. This may include a third party acting as a public directory, such as a certification authority. Therefore, in some examples, only when it is necessary to determine the common secret (CS) is the master public key (P) of the first node.<sub>1C</sub>) May be requested and received by the second node 7 (and vice versa).
The registration step only needs to occur once as an initial setup. Later, the master key can be reused for security reasons, especially to generate a common secret that depends on the deterministic key (DK).
<Starting a session and determining a common secret by the first node 3> An example of determining a common secret (CS) is described below with reference to FIG. A common secret (CS) may be used between the first node 3 and the second node 7 for a specific session, time, transaction, or other purpose, and the same common secret (CS) may be used. It may be undesirable or unsafe. Therefore, the common secret (CS) may be changed between different sessions, times, transactions, etc.
<Generation of message (M) 310> In this example, the method 300 executed by the first node 3 includes step 310 of generating a message (M). The message (M) may be random, pseudo-random, or user-defined. In one example, the message (M) is based on Unix time and nonce (and any value). For example, the message (M) may be provided as follows.
<maths num="3"><img file="JP2022500920A_D0003.tif" /></maths> In some examples, the message (M) is optional. However, it should be understood that the message (M) may have selective values (such as Unix time) that may be useful in some applications.
Method 300 includes step 315 sending a message (M) to node 7 over the communication network. Since the message (M) does not contain information about the private key, the message (M) may be sent over an insecure network.
<Determinating Key Determination 320> Method 300 further comprises step 320 of determining a deterministic key (DK) based on the message (M). In this example, this involves determining the cryptographic hash of the message.
An example of a cryptographic hash algorithm includes SHA-256 for generating a 256-bit deterministic key (DK). in short:
<maths num="4"><img file="JP2022500920A_D0004.tif" /></maths> It should be understood that other hash algorithms may be used. It has algorithms within the Secure Hash Algorithm (SHA) family. Some specific examples include instances within a SHA-3 subset that includes SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAAKE128, SHKE256. Other hash algorithms may include algorithms within the RIPEMD (RACE Integrity Primitives Evaluation Message Digest) family. Certain examples may include RIPEMD-160. Other hash algorithms may include Zemor-Tillich hash functions and families based on knapsack-based hash functions.
<Determining the second private key of the first node 330> Method 300 then uses the master secret key of the second node (V).<sub>1C</sub>) And the second private key (V) of the first node based on the deterministic key (DK)<sub>2C</sub>) Includes step 330 to determine.
This is the master private key (V) of the first node according to the following equation:<sub>1C</sub>) And the scalar addition of the deterministic key (DK).
<maths num="5"><img file="JP2022500920A_D0005.tif" /></maths> Therefore, the second private key of the first node (V)<sub>2C</sub>) Is not a random value, but instead is decisively derived from the master secret key of the first node. The corresponding public key in the crypto pair, that is, the second public key of the first node (P)<sub>2C</sub>) Has the following relationship.
<maths num="6"><img file="JP2022500920A_D0006.tif" /></maths> V from equation 5<sub>2C</sub>Is assigned to Equation 6
<maths num="7"><img file="JP2022500920A_D0007.tif" /></maths> Here, the "+" operator represents scalar addition, and the "x" operator represents elliptic curve point multiplication.
Keeping in mind that elliptic curve cryptographic algebra is distributed, Equation 7 is expressed as follows.
<maths num="8"><img file="JP2022500920A_D0008.tif" /></maths> Finally, Equation 1 is assigned to Equation 7 to give:
<maths num="9"><img file="JP2022500920A_D0009.tif" /></maths> In equations 8 to 9.2, the "+" operator represents elliptic curve point addition. Therefore, the second public key of the corresponding first node (P)<sub>2C</sub>) Is the master public key of the first node (P)<sub>1C</sub>) And the knowledge of the message (M) can be derived. The second node 7 is the second public key of the first node (P), as described in more detail below with respect to method 400.<sub>2C</sub>) May have such knowledge in order to determine independently.
<Generation of 1st signed message (SM1) based on message and 2nd secret key of 1st node 350> Method 300 is the message (M) and the 2nd secret key (V) of the determined 1st node.<sub>2C</sub>), Further includes step 350 to generate a first signed message (SM1). The steps to generate a signed message include applying a digital signature algorithm to digitally sign the message (M). In one example, this is the second private key (V) of the first node to get the first signed message (SM1).<sub>2C</sub>) Is applied to the message in the Elliptic Curve Digital Signature Algorithm (ECDSA).
Examples of ECDSA include those based on ECC systems with secp256k1, secp256r1, secp384r1, se3cp521r1.
The first signed message (SM1) is the second public key (P) of the first node in the second node 7.<sub>2C</sub>) Can be verified. This validation of the first signed message (SM1) may be used by the second node 7 to authenticate the first node 3. This is discussed in Method 400 below.
<Determining the 2nd public key of the 2nd node 370'> The 1st node 3 is then the 2nd public key of the 2nd node (P).<sub>2S</sub>) May be determined 370. As mentioned above, the second public key of the second node (P)<sub>2S</sub>) Is the master public key of the second node (P)<sub>1S</sub>) And the deterministic key (DK). In this example, the public key is determined by the elliptic curve dot product of the private key and the generator (G), so 370', the second public key of the second node (P).<sub>2S</sub>) Can be expressed by the following equation as in equation 6.
<maths num="10"><img file="JP2022500920A_D0010.tif" /></maths> The mathematical proof of Equation 10.2 is the second public key of the first node (P).<sub>2C</sub>) Is the same as described above for deriving Equation 9.1. The first node 3 can determine the second public key of the second node independently of the second node 7370.
<Determining the common secret 380 in the first node 3> The first node 3 is the second secret key (V) of the determined first node.<sub>2C</sub>) And the determined second public key of the second node (P)<sub>2S</sub>) May determine the common secret (CS) 380. The common secret (CS) may be determined by the first node 3 by the following equation.
<maths num="11"><img file="JP2022500920A_D0011.tif" /></maths> <Method 400 performed on second node 7> Corresponding method 400 performed on second node 7 is described below. It should be understood that some of these steps are similar to the steps described above performed by the first node 3.
The method 400 includes step 410 of receiving a message (M) from the first node 3 via the communication network 5. This may include the message (M) sent by the first node 3 in step 315. The second node 7 then determines the deterministic key (DK) based on the message (M) 420. Step 420 for determining the deterministic key (DK) by the second node 7 is similar to step 320 described above performed by the first node. In this example, the second node 7 performs this determining step, which is independent of the first node 3.
The next step is the master public key of the first node (P)<sub>1C</sub>) And the second public key (P) of the first node based on the deterministic key (DK)<sub>2C</sub>) Includes step 430 to determine. In this example, the public key is determined by the elliptic curve dot product of the private key and the generator (G), so 430', the second public key of the first node (P).<sub>2C</sub>) Can be expressed by the following equation as in equation 9.
<maths num="12"><img file="JP2022500920A_D0012.tif" /></maths> The mathematical proof of equations 12.1 and 12.2 is the same as described above for equations 10.1 and 10.2.
<Second node 7 authenticates first node 3> Method 400 may include a step performed by second node 7 to authenticate that self-proclaimed first node 3 is first node 3. .. As mentioned above, this includes step 440 of receiving the first signed message (SM1) from the first node 3. The second node 7 is the second public key (P) of the first node determined in step 430.<sub>2C</sub>) May verify the signature on the first signed message (SM1) 450.
Digital signature verification may be performed according to the Elliptic Curve Digital Signature Algorithm (ECDSA) as described above. Importantly, V<sub>2C</sub>And P<sub>2C</sub>Form a cryptographic pair, so the second secret key (V) of the first node<sub>2C</sub>The first signed message (SM1) signed by) is the second public key (P) of the corresponding first node.<sub>2C</sub>) Should be read and verified correctly. These keys are the master secret key (V) of the first node generated during the registration of the first node 3.<sub>1C</sub>) And the master public key of the first node (P)<sub>1C</sub>), So the verification of the 1st signed message (SM1) is that the self-proclaimed 1st node sending the 1st signed message (SM1) is the same 1st node 3 as registered. Can be used as the basis for authentication. Therefore, the second node 7 may further perform the step (460) of authenticating the first node 3 based on the result of the step (450) of verifying the first signed message.
The above authentication may be suitable for scenarios where one of the two nodes is a trusted node and only one of these nodes needs to be authenticated. For example, the first node 3 may be a client and the second node 7 may be a server trusted by the client. Therefore, the server (second node 7) may need to authenticate the credentials of the client (first node 3) in order to allow the client to access the server system. The server does not have to be authenticated by the client with the server's credentials. However, in some scenarios it may be desirable for both nodes to authenticate each other, as in the peer-to-peer scenario, as described below in another example.
<Second node 7 determines the common secret> In method 400, the second node 7 is the master secret key of the second node (V).<sub>1S</sub>) And the second private key (V) of the second node based on the deterministic key (DK)<sub>2S</sub>) May be further included. The second private key (V) of the second node, similar to step 330 performed by the first node 3.<sub>2S</sub>) Is the master private key (V) of the second node according to the following equation.<sub>1S</sub>) And the scalar addition of the deterministic key (DK).
<maths num="13"><img file="JP2022500920A_D0013.tif" /></maths> The second node 7 then, independently of the first node 3, based on the following equation, is the second secret key (V) of the second node.<sub>2S</sub>) And the determined second public key of the second node (P)<sub>2C</sub>) May determine the common secret (CS) 480.
<maths num="14"><img file="JP2022500920A_D0014.tif" /></maths> <Proof of common secret (CS) determined by 1st node 3 and 2nd node 7> The common secret (CS) determined by 1st node 3 is the common secret (CS) determined by 2nd node 7. Is the same as. The mathematical proof that equations 11 and 14 are the same common secret (CS) is described below.
Considering the common secret (CS) determined by the first node 3, Equation 10.1 can be assigned to Equation 11 as follows.
<maths num="15"><img file="JP2022500920A_D0015.tif" /></maths> Considering the common secret (CS) determined by the second node 7, Equation 12.1 can be assigned to Equation 14 as follows.
<maths num="16"><img file="JP2022500920A_D0016.tif" /></maths> Since ECC algebra is commutative, equations 15 and 16 are equivalent:
<maths num="17"><img file="JP2022500920A_D0017.tif" /></maths> <Common Secret (CS) and Secret Key> Common Secret (CS) is the basis of a secret key or as a secret key in a symmetric key algorithm for secure communication between the first node 3 and the second node 7. May be used as.
The common secret (CS) is the elliptic curve point (x)<sub>S</sub>, y<sub>S</sub>) May be in the form. It may be converted to a standard key format using standard publicly known operations agreed by nodes 3 and 7. For example, x<sub>S</sub>The value may be a 256-bit integer that can be used as the key for AES256 encryption. It can be further converted to a 160-bit integer using RIPEMD160 for any application that requires a 160-bit long key.
The common secret (CS) may be determined as needed. Importantly, the first node 3 does not need to store the common secret (CS) because the common secret (CS) can be redetermined based on the message (M). In some examples, the message (M) used is stored in data stores 13, 17, 19 (or other data stores) without having the same level of security required for the master private key. It's okay. In some examples, the message (M) may be publicly available.
However, depending on some uses, the common secret (CS) is the master secret key (V) of the first node.<sub>1C</sub>), The common secret (CS) can be stored in the first data store (X) associated with the first node.
In addition, the disclosed system may allow the determination of multiple common secrets that may correspond to multiple secure secret keys based on a single master key cryptographic pair. This advantage can be explained by the following example.
In situations where there are multiple sessions, each associated with multiple respective common secrets (CS), then having records associated with these multiple sessions, each common secret (CS) will be redetermined in the future. It may be desirable to be able to. In known systems, this requires storing multiple secret keys in a secure data store, which can be expensive or inconvenient to maintain.
In contrast, the system of the invention may keep the master key secure at the first and second nodes while other deterministic keys or messages may be stored securely or non-securely. Multiple common secrets (CS) are kept secure because the master private key needed to determine the common secret remains secure instead of the deterministic key (DK) or message (M) being stored insecurely. Dripping.
The method may be used to generate a "session key" for a temporary communication link, for example to securely send a login password.
<Peer-to-peer authentication> In a peer-to-peer scenario, the first node 3 and the second node 7 may need to authenticate each other's authentication information. An example of this is described below with reference to FIG. In this example, the steps of methods 300, 400 for authenticating the first node 3 based on the verified first signed message (SM1) are similar to those described above.
However, the method 400 performed by the second node 7 is the message (M) and the secret key (V) of the second node.<sub>2S</sub>), Further includes step 462 to generate a second signed message (SM2). In some alternatives, the second signed message (SM2) is the second message (M2) and the private key of the second node (V).<sub>2S</sub>), The second message (M2) is shared with the first node 3. Method 400 further comprises step 464 of sending a second signed message (SM2) to first node 3 over the communication network 5.
At first node 3, method 300 includes the step of receiving a second signed message (SM2) from second node 7. The method is the second public key (P) of the second node determined in step 370.<sub>2S</sub>) Includes step 374 to verify the signature on the second signed message (SM2). Method 300 may then include step 376 to authenticate the second node 7 based on the result of validating the second signed message (SM2). As a result, the first node 3 and the second node 7 authenticate each other.
<Hierarchical structure of deterministic keys> In one example, a series of consecutive deterministic keys may be determined, and each consecutive key may be determined based on the preceding deterministic key.
For example, instead of repeating steps 310-370 and 410-470 to generate a continuous single-purpose key, by prior agreement between the nodes, both parties to build a hierarchical structure of deterministic keys. , The previously used deterministic key (DK) can be repeatedly rehashed. In effect, the hash-based deterministic key of the message (M) can be the next generation message (M') for the next generation deterministic key (DK'). Doing this allows the continuous generation of a common secret to be calculated without the need to send multiple messages for each generation of the common secret, in particular the transmissions established by further protocols. The next-generation common secret (CS') can be calculated as follows.
First, both the first node 3 and the second node 7 independently determine the next-generation deterministic key (DK'). This is similar to steps 320 and 420, but is applied by the following equation.
<maths num="18"><img file="JP2022500920A_D0018.tif" /></maths> The first node 3 is then similar to steps 370 and 330 above, but is adapted by the following equation to be the second public key (P) of the next generation second node.<sub>2S</sub>') And the second private key of the first node (V)<sub>2C</sub>') May be decided.
<maths num="19"><img file="JP2022500920A_D0019.tif" /></maths> The second node 7 is then similar to steps 430 and 470 above, but is adapted by the following equation to be the second public key (P) of the next generation first node.<sub>2C</sub>') And the second private key of the second node (V)<sub>2S</sub>') May be decided.
<maths num="20"><img file="JP2022500920A_D0020.tif" /></maths> The first node 3 and the second node 7 may then determine the next generation common secret (CS'), respectively. In particular, the first node 3 determines the next-generation common secret (CS') by the following equation.
<maths num="21"><img file="JP2022500920A_D0021.tif" /></maths> The second node 7 determines the next-generation common secret (CS') by the following equation.
<maths num="22"><img file="JP2022500920A_D0022.tif" /></maths> Further generations (CS'', CS''', etc.) can be calculated in the same way, producing a chain hierarchy.
This technique ensures that both node 3 and node 7 track the original message (M) or the initially calculated deterministic key (DK), and which node it is associated with. Request. Since this is publicly known information, there are no security issues regarding the retention of this information. Therefore, this information may be kept in a "hash table" (linking the hash value to the public key) and freely distributed across network 5 (eg using torrents). In addition, if none of the individual common secrets (CS) in the hierarchy are compromised, then this is the private key V.<sub>1C</sub>, V<sub>1S</sub>If remains secure, it does not affect the security of any other common secret in the hierarchy.
<Key tree structure> Similar to the chain (linear) hierarchical structure described above, it is possible to generate a hierarchical structure in the form of a tree structure.
According to the tree structure, various keys for different purposes such as authentication key, encryption key, signature key, payment key, etc. can be determined. All of these keys are then linked to a single secure master key.
<Explanation of Embodiment> FIG. 7 shows a method for realizing the present disclosure for sharing a first common secret among three nodes A, B, and C, and FIG. 8 shows a flowchart of the method. Each node A, B, C is associated with its own private / public key pair (S, P), for example the private / public key pair of node A is (S).<sub>A</sub>, P<sub>A</sub>). Each private key or public key may be derived from each master private key or master public key and deterministic key of the node in the same manner as described above with reference to FIGS. 1-6. A secret-public key pair is a key pair in an elliptic curve cryptosystem. For example, P<sub>A</sub>= S<sub>A</sub>× G and G are elliptic curve reference points (generator points). Secure communication between each pair of nodes A and B, A and C, and B and C is performed in step 80 of FIG. 8 for each pair of nodes using the method described above with reference to FIGS. 1-6. Established by determining a second common secret between. In the configuration shown in FIG. 7, the following relationships apply.
<maths num="23"><img file="JP2022500920A_D0023.tif" /></maths> The first common secret that should be shared between nodes A, B, and C is:
<maths num="24"><img file="JP2022500920A_D0024.tif" /></maths> Once a secure communication channel has been established between each pair of nodes, in step 82 of FIG. 8, each node is based on that second secret, in the form of a second secret join known to that node. Encrypt the share of the first secret using a private-public key pair. This is done by each node and encodes the XOR coupling of the second common secret x pair known to that node. Therefore, for node A, the common secret x<sub>1</sub>And x<sub>2</sub>Is known to node A, so node A joins (x)<sub>1</sub>) XOR (x<sub>2</sub>), And then the private key x of the private-public key pair for each communication channel.<sub>1</sub>Or x<sub>2</sub>Based on, this join is coded separately from each other node. In step 84 of Figure 8, node A then x<sub>1</sub>Encrypted join based on (x<sub>1</sub>) XOR (x<sub>2</sub>) To node B, x<sub>2</sub>Encrypted join based on (x<sub>1</sub>) XOR (x<sub>2</sub>) Is sent to node C. Each of these encrypted shares is expressed by the following equation.
<maths num="25"><img file="JP2022500920A_D0025.tif" /></maths> Similarly, common secret x<sub>1</sub>And x<sub>3</sub>Is known to node B, x<sub>3</sub>Represents the third common secret and is common to the second node B and the third node C. Node B is a join (x)<sub>1</sub>) XOR (x<sub>3</sub>) And then the second common secret x<sub>1</sub>And x<sub>3</sub>Based on, this join is coded separately from each other node. In step 84 of Figure 8, node B then x<sub>1</sub>Encrypted join based on (x<sub>1</sub>) XOR (x<sub>3</sub>) Ex<sub>1</sub>[(x<sub>1</sub>) XOR (x<sub>3</sub>)] To node A, x<sub>3</sub>Encrypted join based on (x<sub>1</sub>) XOR (x<sub>3</sub>) Ex<sub>3</sub>[(x<sub>1</sub>) XOR (x<sub>3</sub>)] Is sent to node C. Node C, on the other hand, joins x<sub>2</sub>(XOR) x<sub>3</sub>And then the second common secret x<sub>2</sub>And x<sub>3</sub>Based on, this join is coded separately from each other node. In step 84 of Figure 8, node C then x<sub>2</sub>Encrypted join based on (x<sub>2</sub>) XOR (x<sub>3</sub>) Ex<sub>2</sub>[(x<sub>2</sub>) XOR (x<sub>3</sub>)] To node A, x<sub>3</sub>Ex encrypted based on<sub>3</sub>[(x<sub>2</sub>) XOR (x<sub>3</sub>)] Is sent to node B.
In step 86 of FIG. 8, each of the nodes A, B, and C receives the encrypted share from the other node and decrypts the encrypted share. As a result, each of the nodes has a first shared secret (x) as follows:<sub>1</sub>) XOR (x<sub>2</sub>) XOR (x<sub>3</sub>) Can be reconstructed to get the share of the number of thresholds required.
Node A shares from node B (x<sub>2</sub>) XOR (x<sub>3</sub>) From node C (x<sub>1</sub>) XOR (x<sub>3</sub>) Is received. Node A is x<sub>1</sub>And x<sub>2</sub>In step 88 of Figure 8, node A is x<sub>1</sub>And (x<sub>2</sub>) XOR (x<sub>3</sub>) And or x<sub>2</sub>And (x<sub>1</sub>) XOR (x<sub>3</sub>By XOR with), the first common secret (x)<sub>1</sub>) XOR (x<sub>2</sub>) XOR (x<sub>3</sub>) Can be calculated easily. Similarly, node B shares from node A (x).<sub>1</sub>) XOR (x<sub>2</sub>) From node C (x<sub>2</sub>) XOR (x<sub>3</sub>) Is received. Node B is x<sub>1</sub>And x<sub>3</sub>Because we know individually, x<sub>1</sub>And (x<sub>2</sub>) XOR (x<sub>3</sub>) And or x<sub>3</sub>And (x<sub>1</sub>) XOR (x<sub>2</sub>By XOR with), the first common secret (x)<sub>1</sub>) XOR (x<sub>2</sub>) XOR (x<sub>3</sub>) Can be calculated easily. Furthermore, node C shares from node B (x).<sub>1</sub>) XOR (x<sub>3</sub>) From node A (x<sub>1</sub>) XOR (x<sub>2</sub>) Is received. Node C is x<sub>2</sub>And x<sub>3</sub>Because we know individually, x<sub>2</sub>And (x<sub>1</sub>) XOR (x<sub>3</sub>) And or x<sub>3</sub>And (x<sub>1</sub>) XOR (x<sub>2</sub>By XOR with), the first common secret (x)<sub>1</sub>) XOR (x<sub>2</sub>) XOR (x<sub>3</sub>) Can be calculated easily.
Similar to the method described for the second common secret above, the first common secret (CS) is an elliptic curve point (x).<sub>S</sub>, y<sub>S</sub>) May be in the form. It may be converted to a standard key format using standard publicly known operations agreed by nodes 3 and 7. For example, x<sub>S</sub>The value may be a 256-bit integer that can be used as the key for AES256 encryption. It can be further converted to a 160-bit integer using RIPEMD160 for any application that requires a 160-bit long key.
It is possible to distribute the share of the first common secret by means other than XOR encryption. However, XOR encryption provides the advantage of obfuscating the second common secret when broadcast in the script of a blockchain transaction. As a result, the third party cannot determine the second common secret without knowing the other second common secret of the threshold number. For example, (x<sub>1</sub> x x<sub>2</sub> x x<sub>3</sub>) A simple arithmetic multiplication of the second common secret of the form mod n can be used. Where n is the order of the elliptic curve cryptosystem used.
Further, the share of the first common secret can be distributed as a share of a polynomial function by using Shamir's secret sharing method or a dealer-free secret sharing method familiar to those skilled in the art. If the share of the first common secret is the share of the polynomial function, efficient restoration of the first common secret can be performed by the Berlekamp-Welch decoder as shown in FIG. Referring to FIG. 9, the Berlekamp-Welch decoder 70 performs polynomial interpolation of the share of the polynomial function in order to obtain the polynomial function.
In the traditional use of the Berlekamp-Welch algorithm to correct errors in the transmitted data, the message m is divided into k-byte poetry leases in encoder 72, each byte c0, c1, ..., ck-1 is encoded as an integer modulo p. The message is then represented by a polynomial function.
<maths num="26"><img file="JP2022500920A_D0026.tif" /></maths> The value of the polynomial function m (x) is then determined for a number of known values of x to generate a series of (x, y) pairs, which are then received by transmitter 74. It is sent to the machine 76.
The data M received at receiver 76 (ie, the received message) is a pair (a) corresponding to a point on the polynomial function that represents the original message.<sub>1</sub>, b<sub>1</sub>, ..., a<sub>n</sub>, b<sub>n</sub>)including.
<maths num="27"><img file="JP2022500920A_D0027.tif" /></maths> If some of the transmitted (x, y) pairs are broken during transmission, the error position polynomial function can be defined as follows.
<maths num="28"><img file="JP2022500920A_D0028.tif" /></maths> Product polynomial function Q (a<sub>i</sub>) Is defined as the following equation.
<maths num="29"><img file="JP2022500920A_D0029.tif" /></maths> Then received (a<sub>i</sub>, b<sub>i</sub>) For each pair, b<sub>i</sub>Whether or not the value of is broken
<maths num="30"><img file="JP2022500920A_D0030.tif" /></maths> (a<sub>i</sub>, b<sub>i</sub>For n known values of), E (a)<sub>i</sub>) Is a polynomial function of order e, and P (a)<sub>i</sub>) Is a polynomial function of order (k-1), so Q (a)<sub>i</sub>) Is a polynomial function of order (e + k-1). (a<sub>i</sub>, b<sub>i</sub>) Is therefore known as a linear system.
<maths num="31"><img file="JP2022500920A_D0031.tif" /></maths> The linear system contains 2e + k-1 unknown terms (E (x) to e and Q (x) to e + k-1). As a result, if n> = 2e + k-1, then Q (a)<sub>i</sub>) And E (a<sub>i</sub>) Can be determined. Q (a<sub>i</sub>) And E (a<sub>i</sub>) Can be determined, then P (a) to restore the original message m (x)<sub>i</sub>) Can be determined.
Therefore, it can be seen that the Berlekamp-Welch decoder 70 receives a pair representing a point on a polynomial function as an input and outputs a polynomial function. The decoder 70 can therefore be used as an alternative to Lagrange interpolation in the present disclosure to determine the polynomial function from the share of the number of thresholds represented by the polynomial function.
FIG. 10 shows how to achieve this disclosure, sharing a first common secret among the four nodes A, B, C, D. Each node A, B, C, D is associated with its own private / public key pair (S, P), for example the private / public key pair of node A is (S).<sub>A</sub>, P<sub>A</sub>).
Each private key or public key may be derived from each master private key or master public key and deterministic key of the node in the same manner as described above with reference to FIGS. 1-6. A secret-public key pair is a key pair in an elliptic curve cryptosystem. For example, P<sub>A</sub>= S<sub>A</sub>× G and G are elliptic curve reference points (generator points). , Secure communication between each pair of nodes A and B, A and C, A and D, B and C, B and D, C and D is performed using the method described above with reference to FIGS. 1-6. Established by determining a second common secret between each pair of nodes. In the configuration shown in FIG. 10, the following relationships apply.
<maths num="32"><img file="JP2022500920A_D0032.tif" /></maths>
<maths num="33"><img file="JP2022500920A_D0033.tif" /></maths> Once a secure communication channel has been established between each pair of nodes, each node joins a second secret known to that node in a manner similar to that described above with reference to FIGS. 7 and 8. The share of the first secret is encrypted using the secret-public key pair based on the second secret in the form of. This is done by each node and encodes the XOR coupling of the second common secret x pair known to that node. Therefore, for node A, the common secret x<sub>1</sub>, X<sub>2</sub>And x<sub>3</sub>Is known to node A, so node A joins
<maths num="34"><img file="JP2022500920A_D0034.tif" /></maths> And then the private key x of the private-public key pair for each communication channel<sub>1</sub>, X<sub>2</sub>Or x<sub>3</sub>Based on, this join is coded separately from each other node.
In embodiments of the invention, separate couplings
<maths num="35"><img file="JP2022500920A_D0035.tif" /></maths> Is abbreviated as [A shares] in FIG.
The coded combination is then expressed as:
<maths num="36"><img file="JP2022500920A_D0036.tif" /></maths> Node A then Ex<sub>1</sub>Send [Ashares] to node B, thereby x<sub>1</sub>Become common, Ex<sub>2</sub>Send [Ashares] to node C, thereby x<sub>2</sub>Become common, Ex<sub>3</sub>Send [Ashares] to node D, thereby x<sub>3</sub>Become common.
In a similar way, node B computes the following joins:
<maths num="37"><img file="JP2022500920A_D0037.tif" /></maths> Then, it is encrypted and the following is transmitted.
<maths num="38"><img file="JP2022500920A_D0038.tif" /></maths> Node C computes the following joins:
<maths num="39"><img file="JP2022500920A_D0039.tif" /></maths> Then, it is encrypted and the following is transmitted.
<maths num="40"><img file="JP2022500920A_D0040.tif" /></maths> Node C then computes the following joins:
<maths num="41"><img file="JP2022500920A_D0041.tif" /></maths> Then, it is encrypted and the following is transmitted.
<maths num="42"><img file="JP2022500920A_D0042.tif" /></maths> Nodes A, B, C, and D each receive an encrypted share from the other node and have the appropriate second common secret x.<sub>1</sub>, X<sub>2</sub>, X<sub>3</sub>, X<sub>4</sub>, X<sub>5</sub>, Or x<sub>6</sub>Decrypt the encrypted share with the private key corresponding to, and as a result, each of the nodes has the first common secret as follows:
<maths num="43"><img file="JP2022500920A_D0043.tif" /></maths> You can get the share of the number of thresholds needed to reconstruct.
Node A shares from node B
<maths num="44"><img file="JP2022500920A_D0044.tif" /></maths> Received and x<sub>1</sub>, X<sub>2</sub>, And x<sub>3</sub>Know separately, therefore
<maths num="45"><img file="JP2022500920A_D0045.tif" /></maths> From x<sub>4</sub>And x<sub>5</sub>Can be calculated respectively.
Node A shares from node C
<maths num="46"><img file="JP2022500920A_D0046.tif" /></maths> Received and x<sub>1</sub>, X<sub>2</sub>, And x<sub>3</sub>Know separately, therefore
<maths num="47"><img file="JP2022500920A_D0047.tif" /></maths> From x<sub>6</sub>Can be calculated, resulting in x<sub>1</sub>~ x<sub>6</sub>Can be calculated separately and the first common secret can be calculated.
By performing the same processing, each of the other nodes B, C, and D can acquire the entire second common secret and determine the first common secret that is now shared among all the nodes.
Referring to FIG. 11, a simplified block diagram for illustration of a computing device 2600 that may be used to implement at least one embodiment of the present disclosure is provided. In various embodiments, the computing device 2600 may be used to implement any of the systems illustrated above. For example, the computing device 2600 may be configured for use as a data server, web server, portable computing device, personal computer, or any electronic computing device. As shown in FIG. 11, the computing device 2600 has one or more levels of cache memory and memory controls (collectively) that can be configured to communicate with storage subsystem 2606, which includes main memory 2608 and permanent storage 2610. May include one or more processors with (labeled 2602). The main memory 2608 may include a dynamic random access memory (DRAM) 2618 and a read-only memory (ROM) 2620, as shown. The storage subsystem 2606 and cache memory 2602 may be used to store information such as the details associated with transactions and blocks as described in this disclosure. Processor 2602 may be utilized to provide the steps or functions of any embodiment as described in the present disclosure.
Processor 2602 can also communicate with one or more user interface input devices 2612, one or more user interface output devices 2614, and network interface subsystem 2616.
The bus subsystem 2604 may provide various components of the computing device 2600 and a mechanism that allows the subsystems to communicate with each other as intended.
Although the bus subsystem 2604 is schematically shown as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. The network interface subsystem 2616 may provide an interface to other computing devices and networks.
Network interface subsystem 2616, in some embodiments, computer may function as an interface for transmitting the received and data to it the data from other systems in the computing device 2600. For example, the network interface subsystem 2616 allows data engineers to connect the device to the network. As a result, the data technician can send data to and receive data from the device if he is in a remote location such as a data center.
The user interface input device 2612 is a keyboard, an integrated mouse, a trackball, a touch pad, or an instruction device such as a graphic tablet, a scanner, a bar code scanner, a touch screen built into a display, a voice recognition system, a microphone, etc. It may include one or more user input devices, such as audio input devices and other types of input devices. Generally, the use of the term "input device" is intended to include all possible types of devices and mechanisms for inputting information into the computing device 2600.
One or more user interface output devices 2614 may include a display subsystem, a printer, or a non-visual display such as an audio output device, and the like. The display subsystem may include a cathode ray tube (CRT), a liquid crystal display (LCD), a light emitting diode (LED) display, or a planar device such as a projection, or other display device. Generally, the use of the term "output device" is intended to include all possible types of devices and mechanisms that output information from the computing device 2600. One or more user interface output devices 2614, for example, present a user interface and realize such interaction when appropriate for user interaction with the application performing the processes and variants described herein. May be used for.
A storage subsystem 2606 may provide a computer-readable storage medium for storing basic programming and data structures that provide the functionality of at least one embodiment of the present disclosure. When executed by one or more processors, an application (eg, a program, code module, instruction) may provide the functionality of one or more embodiments of the present disclosure and be stored in a storage subsystem 2606. These application modules or instructions may be executed by one or more processors 2602. The storage subsystem 2606 further provides a repository for storing data used in accordance with the present disclosure. For example, main memory 2608 and cache memory 2602 can provide volatile storage for programs and data. Permanent storage 2610 can provide permanent (nonvolatile) storage of programs and data, including magnetic hard disk drives, one or more floppy disk drives associated with removable media, and one or more associated with removable media. It may include an optical drive (eg, CD-ROM, or DVD, or Blue-Ray) drive, and other similar storage media. Such programs and data may include programs for performing the steps of one or more embodiments described in this disclosure, as well as data associated with transactions and blocks described in this disclosure.
The computing device 2600 may be of various types, including portable computer devices, tablet computers, workstations, or any other device described below. Further, the computing device 2600 may include another device that can be connected to the computing device 2600 through one or more ports (eg, USB, headphone jack, optical connector, etc.). A device that may be connected to the computing device 2600 may include multiple ports configured to receive fiber optic connectors. Therefore, the device may be configured to convert an optical signal into an electrical signal transmitted to the computing device 2600 through a port connecting the device for processing. Due to the ever-changing characteristics of computers and networks, the description of the computing device 2600 shown in FIG. 11 is intended only as a specific example for purposes of illustrating preferred embodiments of the device. Many other configurations are possible with more or less components than the system shown in Figure 11.
The embodiments described above are not limited to this disclosure, but are described, and those skilled in the art can devise many alternative embodiments without departing from the scope of the present disclosure as defined by the appended claims. Should be noted. In the claims, any reference code in parentheses is not intended to limit the claim. The terms "have" and "comprising", etc. do not preclude the existence of any element or step other than those listed in any claim or specification. In the present specification, "having" means "having or being composed", and "including" means "including or being composed". A singular reference to an element does not exclude multiple references to that element. The reverse is also true. The present disclosure can be implemented by hardware containing several separate elements and by a properly programmed computer. In a device claim enumerating several means, some of these means may be embodied by one and the same hardware item. The fact that certain means are described in different dependent claims does not indicate that the combination of these means is not used in an advantageous manner.
59 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| JP2001268070A | Cites | Japan | A | Search report | – |
| JP2002527993A | Cites | Japan | A | Search report | – |
| JP2013090199A | Cites | Japan | A | Search report | – |
| JP2017187573A | Cites | Japan | Y | Search report | 6-10 |
| EP2363977A1 | Cites | European Patent Office (EPO) | XY | Search report | 1-12,27-31,13-26 |
| ANTONOPOULOS, A. M.: "Chapter 4. Keys, Addresses, Wallets", MASTERING BITCOIN, vol. First Edition, JPN6019037348, December 2014 (2014-12-01), pages 1 - 23, ISSN: 0005338366 | Non-patent | – | – | Search report | – |
| 尾花 賢: "秘密分散法における不正防止技術", 2017年電子情報通信学会基礎・境界ソサイエティ/NOLTAソサエティ大会講演論文集, JPN6023034459, 7 March 2017 (2017-03-07), JP, pages 30 - 33, ISSN: 0005133336 | Non-patent | – | – | Search report | – |
17 members in 9 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 18153965 | United Kingdom | – | |
| 201815396 | United Kingdom | A | |
| 2019057632 | International Bureau of the World Intellectual Property Organization (WIPO) | W |
Members17
| Document | Office | Kind | |
|---|---|---|---|
| GB201815396D0 | United Kingdom | D0 | |
| WO2020058806A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW202025666A | Taiwan Province of China | A | |
| SG11202102221SA | Singapore | A | |
| CN112771832A | China | A | |
| KR20210063378A | Republic of Korea | A | |
| EP3854052A1 | European Patent Office (EPO) | A1 | |
| US2021367772A1 | United States of America | A1 | |
| JP2022500920AThis record | Japan | A | |
| US11616641B2 | United States of America | B2 | |
| TWI807103B | Taiwan Province of China | B | |
| US2023299947A1 | United States of America | A1 | |
| US12034840B2 | United States of America | B2 | |
| US2024305451A1 | United States of America | A1 | |
| JP2025000864A | Japan | A | |
| EP3854052B1 | European Patent Office (EPO) | B1 | |
| KR102871872B1 | Republic of Korea | B1 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2022500920
- Application
- 2021514094
Titles2
- Japanese
- コンピュータにより実施される、共通シークレットを共有するシステム及び方法
- English
- Systems and methods for sharing common secrets implemented by computers
Classification
- CPC, 6
- H04L63/065
- H04L9/0841
- H04L9/085
- H04L63/061
- H04L9/3066
- H04L9/0825
- IPC, 1
- H04L9 08
Designated states5
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo
- National, 1
- Trinidad and Tobago