Key data processing method and apparatus, and server
Abstract
The original key of the shared object in the blockchain is obtained. The number of parties sharing the original key is determined. processing the original key using a predetermined algorithm to generate a number of child keys equal to the number of parties sharing the original key, wherein the child keys obtain the original key when the same number of child keys are obtained. used to restore

Term
Projected expiry 28 August 2038.
- Priority
- Filed
- Published
- Today
- Projected expiry
11 claims: 1 independent, 10 dependent
- 1키 데이터를 프로세싱하기 위한 방법에 있어서, 블록체인 내의 공유되는 객체(shared object)의 원본 키(original key)를 획득하는 단계(S0);상기 원본 키를 공유하는 파티(party)들의 수를 결정하는 단계(S0);및 상기 원본 키를 공유하는 파티들의 수와 동일한 수의 차일드 키(child key)들을 생성하기 위해, 미리결정된 알고리즘을 사용함으로써 상기 원본 키를 프로세싱하는 단계(S2)로서, 상기 차일드 키들은 상기 동일한 수의 차일드 키들이 획득되었을 때 상기 원본 키를 복원하는데 사용되는 것인, 상기 원본 키를 프로세싱하는 단계(S2)를 포함하는, 키 데이터를 프로세싱하기 위한 방법.
- 2제1 항에 있어서, 상기 차일드 키들을 대응하는 객체 공유 파티들에 전송하는 단계(S4);및 상기 원본 키를 삭제하는 단계(S6)를 더 포함하는, 키 데이터를 프로세싱하기 위한 방법.
- 3제1 항 또는 제2 항에 있어서, 상기 미리결정된 알고리즘은, 상기 원본 키를 공유하는 파티들의 수와 동일한 수의 차일드 키들을 생성하기 위해, 무작위로 생성된 문자열(character string)을 사용함으로써 상기 원본 키에 연산을 수행하는 것을 포함하는 것인, 키 데이터를 프로세싱하기 위한 방법.
- 4제3 항에 있어서, 상기 미리결정된 알고리즘은, (N+1)개의 공유 파티들이 있을 때, N개의 난수(random number)들 Ri - 상기 Ri는 i번째 난수이고, i∈[1, N]임 - 를 생성하는 것(S200);소수(prime number) P - 상기 소수 P는 적어도 상기 원본 키의 값 S 및 상기 난수 Ri 중 어느 하나보다 크고, 상기 Ri는 [0, P-1] 범위임 - 를 결정하는 것(S202);및 상기 (N+1)개의 차일드 키들을 획득하기 위해, (S+R 1 X+R 2 X 2 +R 3 X 3 +…+R N X N )이 계산된 후 P에 모듈로 연산(modulo operation)을 수행하고, [1, N+1]로부터 X의 값을 선택하는 것(S204) - 여기서, N≥1이고, X 및 N은 정수임 - 을 포함하는 것인, 키 데이터를 프로세싱하기 위한 방법.
- 5제3 항에 있어서, 상기 무작위로 생성된 문자열의 하나 이상의 문자는, 상기 차일드 키들을 생성하기 위해, 순차적으로 상기 원본 키에 개별적으로 삽입되는 것인, 키 데이터를 프로세싱하기 위한 방법.
- 6제1 항 내지 제5 항 중 어느 한 항에 있어서, 입력된 차일드 키들을 수신하는 단계(S80);및 상기 차일드 키들의 수가 대응하는 원본 키를 공유하는 파티들의 수와 동일하다고 결정되었을 때, 상기 대응하는 원본 키를 획득하기 위해, 상기 미리 결정된 알고리즘을 사용함으로써 상기 차일드 키들에 기초하여 상기 원본 키를 계산을 통해 복원하는 단계(S82)를 더 포함하는, 키 데이터를 프로세싱하기 위한 방법.
- 7제1 항 또는 제2 항에 있어서, 상기 미리결정된 알고리즘은, (N-1)개의 난수들 - 상기 난수들의 이진 길이(binary length)들은 상기 원본 키의 이진 길이와 동일하고, N은 상기 원본 키를 공유하는 파티들의 수임 - 을 생성하는 것(S210);배타적 OR 차일드 키를 획득하기 위해, 상기 원본 키 및 상기 (N-1)개의 난수들 각각에 비트단위 배타적 OR 연산(bitwise exclusive OR operation)을 수행하는 것(S214);및 상기 배타적 OR 차일드 키 및 상기 (N-1)개의 난수들을 N개의 출력 차일드 키들로서 사용하는 것을 포함하는 것인, 키 데이터를 프로세싱하기 위한 방법.
- 8제1 항 내지 제7 항 중 어느 한 항에 있어서, 상기 원본 키는 로컬 서버에 의해 생성되거나 원격 서버로부터 수신되는 것인, 키 데이터를 프로세싱하기 위한 방법.
- 9제1 항 내지 제7 항 중 어느 한 항에 있어서, 상기 블록체인은 블록체인 데이터를 저장하도록 구성된 복수의 블록들을 포함하는 것인, 키 데이터를 프로세싱하기 위한 방법.
- 10제9 항에 있어서, 상기 블록체인 데이터는 제품 구매(product purchasing) 또는 이전(transferring)을 위해 사용되는 자산(assets)을 포함하는 것인, 키 데이터를 프로세싱하기 위한 방법.
- 11키 데이터를 프로세싱하기 위한 장치에 있어서, 제1 항 내지 제10 항 중 어느 한 항에 따른 방법을 수행하도록 구성된 복수의 모듈들을 포함하는, 키 데이터를 프로세싱하기 위한 장치.
Independent claims11
127 paragraphs, as filed
Key data processing method and apparatus, and server
associative use case
This application claims priority to Chinese Patent No. 201710747807.5, filed on August 28, 2017, the entire disclosure of which is incorporated herein by reference.
The implementation of the present application relates to the field of blockchain data processing technology, and in particular to a key data processing method, apparatus and server.
A blockchain is a distributed database. A blockchain is a chained data structure obtained by combining data blocks in chronological order. Encryption methods are used to ensure that data cannot be tampered with or falsified. Because blockchain can effectively guarantee data reliability, it is applied in more fields.
Typically, data on a blockchain is signed and verified using asymmetric encryption methods. In a blockchain, the initiator of a transaction can use the private key to sign a transaction, and the miner (computing node) can verify the transaction using the initiator's public key. If the verification of the transaction is successful, it can indicate that the funds used for the transaction are owned by the normal asset owner, and information about the transaction is placed in a new block of the blockchain. In the process of asset trading in a blockchain, a private key is usually stored, for example, on an individual's mobile phone or computer, and is owned by a single party. Thus, ownership and management of assets can be considered to belong to the party that owns the private key. However, in reality, some assets are shared by multiple people, for example real estate or joint ventures jointly owned by a couple. If an asset is to be shared by multiple parties, the parties must share the same private key. By using the private key, each sharing party can control and transact the asset, and transfer the asset without anyone else's knowledge. As a result, the trading risk is relatively high. Therefore, there is an urgent need for a safer and more reliable method to ensure the security of assets shared on the blockchain.
Implementation of the present specification is intended to provide a key data processing method, apparatus and server. In this way, the same number of child keys can be automatically generated based on the number of asset sharing parties, and the original key can be restored using the child keys during a transaction. and can effectively guarantee the security of asset sharing in the blockchain.
The key data processing method, apparatus and server provided in the implementation of the present specification are implemented in the following manner:
The key data processing method includes: obtaining an original key of a shared object in a block chain; determining a number of parties sharing the original key; and processing the original key using a predetermined algorithm to generate a number of child keys equal to a number of parties sharing the original key, wherein the child keys become the original key when the same number of child keys are obtained. Used to restore the key - contains .
The key data processing apparatus includes: an original key information acquisition module, configured to acquire an original key of a shared object in a block chain, and determine the number of parties sharing the original key; and a child key generation module that processes the original key using a predetermined algorithm to generate a number of child keys equal to the number of parties sharing the original key, the child keys being the same number of child keys obtained. used to restore the original key when
A key data processing device comprising a processor and a memory configured to store instructions executable by the processor, wherein when executing the instructions, the processor implements the following operations: an original key of a shared object in a blockchain obtaining and determining the number of parties sharing the original key; and processing the original key using a predetermined algorithm to generate a number of child keys equal to a number of parties sharing the original key, wherein the child keys become the original key when the same number of child keys are obtained. Used to restore the key - .
A server comprising at least one processor and a memory configured to store instructions executable by the processor, wherein when executing the instructions, the processor implements the following operations: Obtaining an original key of a shared object in a blockchain and determining the number of parties sharing the original key; and processing the original key using a predetermined algorithm to generate a number of child keys equal to a number of parties sharing the original key, wherein the child keys become the original key when the same number of child keys are obtained. Used to restore the key - .
According to the key data processing method, apparatus and server provided in one or more implementations of this specification, the original key is to be divided into a plurality of child keys based on the number of parties sharing the original key of a shared object, such as an asset or data. and the generated child keys may be displayed to the corresponding asset sharing parties. If the shared object needs to be computed, each asset-sharing party can provide a child key. And the original key may be restored using the child keys, and corresponding operations such as signing and asset transaction may be performed. As such, in the implementation of the present specification, in order to ensure the security of transactions of assets shared in the blockchain, when an asset in the blockchain is shared by a plurality of people, one person is the asset without the knowledge of the other person. can be effectively prevented from operating.
In order to more clearly describe the technical solutions in the implementation or the existing technology of the present specification, the following briefly introduces the accompanying drawings for describing the implementation or the existing technology. Apparently, the accompanying drawings in the following description show only some implementations of the present specification, and a person skilled in the art may still derive other drawings from these accompanying drawings without creative efforts. 1 is a flowchart illustrating an example of a key data processing method according to the present specification. 2 is a flowchart illustrating an exemplary method according to another implementation of the present specification. 3 is a flowchart illustrating a process for generating a child key according to an implementation of the present specification. 4 is a flowchart illustrating an exemplary method according to another implementation of the present specification. 5 is a schematic diagram illustrating another process of generating a child key based on a predetermined algorithm according to the present specification. 6 is a schematic structural diagram illustrating a module of a key data processing apparatus according to an implementation of the present specification. 7 is a schematic structural diagram illustrating a module of a key data processing apparatus according to another implementation of the present specification. 8 is a schematic structural diagram illustrating a child key generation module in an apparatus according to an implementation of the present specification. 9 is a schematic structural diagram illustrating a key data processing apparatus according to another implementation of the present specification. 10 is a schematic structural diagram illustrating a child key generation module in an apparatus according to another implementation of the present specification. 11 is a schematic structural diagram illustrating a module using a wallet application according to an implementation of the present specification. 12 is a schematic structural diagram illustrating a server for implementing a method or apparatus according to an implementation of the present specification. 13 is a flowchart illustrating an example of a computer-implemented method for managing shared ownership in a blockchain network according to an implementation of the present disclosure.
In order to enable those skilled in the art to better understand the technical solutions of the present specification, the following clearly and comprehensively describes the technical solutions in one or more implementations of the present specification with reference to the accompanying drawings. Obviously, the described implementations are some but not all of the implementations herein. All other implementations obtained without creative efforts by those skilled in the art based on one or more implementations of this specification shall fall within the protection scope of the implementations of this specification.
Although this specification provides the following implementations or method operating steps or apparatus structures shown in the accompanying drawings, the method or apparatus may incorporate more or fewer operational steps or module units based on conventional or non-creative efforts in the method or apparatus. may include In a step or structure for which a necessary cause and effect relationship does not logically exist, the module structure of the sequence or apparatus for executing this step is not limited to the implementation sequence or module structure shown in the implementations herein or in the accompanying drawings. In an actual device, server, or terminal product application, the method or module structure may be performed sequentially or in parallel based on the implementation or the method or module structure shown in the accompanying drawings (eg, a parallel processor or multi-threaded processing environment). , or implementation environments including distributed processing and server clustering).
A blockchain generally includes multiple blocks. Blocks are logical data structures and can be used to store blockchain data. Blockchain data may include data information generated by operations such as flowing and changing funds, money flows, asset changes, etc. on the blockchain. In a blockchain, the flow of money or a change in an asset is generally referred to as a transaction. The assets of the blockchain described in some implementations of this specification may include money, securities, and precious metals stored on the blockchain in the form of electronic data. For example, a wallet function provided by some applications may store monetary assets, and the assets of the wallet may be used for product purchasing or transferring.
Data on the blockchain can validate transactions through asymmetric encryption. Asymmetric encryption generally includes a public key and a private key; The public key may be public, and the private key is not. Asymmetric encryption is one of the main tools for transaction verification in blockchain asset transactions. A trading party may use the private key to sign a transaction, and a verifier may use the public key of the trading party to verify the signature. If verification is successful, it may indicate that the transaction is from the actual owner of the private key corresponding to the public key, and the transaction is valid. Transactions can be placed in new blocks on the blockchain. From the previous process, it can be seen that the private key plays a very important role in blockchain asset transactions. When an asset is shared by multiple people, the asset carries the interests of multiple people. When asset sharing parties need to jointly participate in asset transactions, one or more implementations of this specification can effectively ensure the operational security of assets shared on a blockchain.
Specifically, the implementation process of the present solution is described herein using the wallet application's blockchain transaction as an implementation scenario. A wallet can contain an application on the client or server side, and can implement blockchain asset transactions, typically by generating an asymmetric key to compute a public key address. When a new asset is confirmed or the asset sharing party changes, the wallet may automatically calculate and generate child keys based on the number of asset sharing parties. The number of generated child keys is equal to the number of asset sharing parties. These child keys can be transmitted to the corresponding asset sharing parties, so that each asset sharing party owns one child key. If the asset transaction requires the original private key, these child keys can be used to restore the original private key, and the transaction is initiated with a signature using the restored private key.
Of course, in the implementation of the present specification, the shared object is not necessarily limited to the previous electronic money asset, and the original key is not limited to the private key in asymmetric encryption. The shared object may include service data of a corresponding type in other implementation scenarios, for example, billing data, user data, public information, and the like. The original key may include other data information for data encryption, for example, a character string, or even key data such as images, voices and fingerprints. In the following implementation, the process of generating a plurality of child keys based on the original key and restoring the original key using the received child keys may be completed through calculation by a miner of the blockchain. A miner is usually a node with sufficient computing capability. A miner puts together the collected multiple transaction records, uses the miner's key to try various padding bits for encryption, and broadcasts the block to the entire network, so that other nodes can use the blockchain You can see that a new block has been created.
Specifically, one implementation is shown in FIG. 1 . In an implementation of the key data processing method provided herein, the method may include the following steps.
S0. Obtain the original key of the shared object in the blockchain, and determine the number of parties that share the original key.
S2. Process the original key using a predetermined algorithm to generate a number of child keys equal to the number of parties sharing the original key, and the child keys are used to restore the original key when the same number of child keys are obtained .
In this implementation, the computing device may obtain information about the original key corresponding to the asset and information about the number of parties sharing the asset. The original key may then be calculated and processed using a pre-selected or designed predetermined algorithm to generate the same number of child keys as the parties sharing the asset. The shared object described in the implementation scenario of this implementation may include assets in the wallet. The original key may be generated by a local wallet (server) or may be an original key received and transmitted by another wallet (server). In the present implementation, by using each of the plurality of child keys generated based on the original key, transaction verification cannot be independently performed or verification cannot be successful. When all child keys generated based on the same original key are collected together, the original key can be restored. If there is no child key or any child key is incorrect, the original key cannot be restored, and the restored original key is incorrect.
For example, in the application scenario of this implementation, the blockchain network may include a plurality of nodes, and each node may have a public key and a private key. Assuming there is a wallet application on the node, the wallet is a shared object in this implementation, and the private key of the wallet is the original key. The private key of the wallet is called S, and the number of people sharing the wallet is 2. Two child keys: S1 and S2 can be generated using a preselected or designed algorithm based on the private key S. The wallet's child key S1 cannot sign the transaction, or the signature cannot be successfully verified. Likewise, the wallet's child key S2 cannot sign the transaction, or the signature cannot be successfully verified. However, the original private key S may be restored based on the child key S1 and the child key S2. To recover the original private key S, a corresponding calculation may be performed. The calculation is based on the predetermined algorithm used to generate the child key, eg, an inverse algorithm as opposed to the predetermined algorithm for generating the child key. Of course, the calculation may be based on other algorithms such as interpolation and child key correlation. The original key may be restored by referring to third-party auxiliary data.
Also, in another implementation of the method provided herein, after a number of child keys equal to the number of asset sharing parties are generated, the child keys can be displayed to the corresponding asset sharing parties, so that each asset sharing party has its own You can get a child key. Then, the original key can be deleted. For example, the original private key can be completely deleted from the wallet (or the storage unit that stores the original private key). As such, any asset-sharing party with the child key does not store the original key, further ensuring key data security and preventing the asset-sharing party from using the private key for private asset transactions. Specifically, another implementation of the method herein is shown in FIG. 2 , the method may further include the following steps:
S4. Send the child keys to the corresponding object sharing parties.
S6. Delete the original key.
2 is a flowchart illustrating an exemplary method according to another implementation of the present specification. In this implementation, after generating the public key and the private key, the wallet generates a number of child keys equal to the number of people sharing based on the private key, displays the child keys to the asset sharing parties, and sends the private key can be deleted. In a specific implementation process, one child key may be set to be transmitted to one asset sharing party. Of course, the present disclosure does not exclude the situation in which one asset sharing party has more than one child key. For example, mutually trusted asset sharing parties may store each other's child keys.
In one implementation, the child key may be sent by the wallet to the object sharing party. In another implementation, after generating the child key, the wallet outputs a plurality of generated child keys, and another processing party (eg, a dedicated child key assignment device) sends the child keys to the object sharing parties. The generated child key may be randomly selected and transmitted, or a specific child key may be selected based on a specific rule and transmitted to a corresponding object sharing party.
The predetermined algorithm for generating child keys in the previous implementation may be implemented in multiple implementations. One implementation of the present specification provides a predetermined algorithm for generating a child key using an original key. In order to generate a child key, an operation of referencing the original key using an arbitrary string may be performed. Specifically, in one implementation of the method herein, the predetermined algorithm may include the following steps:
S20. To generate the same number of child keys as the number of parties sharing the original key, an operation is performed on the original key using a randomly generated string.
The string may include numbers, letters, symbols, and the like. The wallet can store these randomly generated strings for subsequent restoration of the original key. The specific method for the operation on the original key using the randomly generated string may be predetermined. For example, a string of fixed length is randomly generated, and one or more characters of the string are individually inserted into the original key in a specific sequence to generate child keys. The values of the corresponding bits of the string may be appended to the original key. In this implementation, in order to further ensure the security of the generated child keys and improve the security of the original key, the child keys of the original key may be generated using an arbitrary character string.
In another implementation of the method herein, child keys are generated using a random number, a prime number and a modulo operation. Details are shown in FIG. 3 . 3 is a flowchart illustrating a process of generating a child key according to an implementation of the present specification. The predetermined algorithm may include the following steps:
If there are S200.(N+1) sharing parties, generate N random numbers Ri, where Ri is the i-th random number, and i[1, N].
S202. Determine a prime number P, wherein the prime number P is greater than at least one of the value S of the original key and the random number Ri, and Ri is in the range [0, P-1].
S204. To obtain the (N+1) child keys, (S+R<sub>1</sub>X+R<sub>2</sub>X<sup>2</sup>+R<sub>3</sub>X<sup>3</sup>+ +R<sub>N</sub>X<sup>N</sup>) is calculated, then perform a modulo operation on P, and select the value of X from [1, N+1], where N1, and X and N are integers.
In general, the length of the private key generated by the asymmetric key algorithm used in blockchain is usually 1024 bits or 2048 bits. Thus, in a specific implementation process of one implementation scenario, the wallet may pre-store a known prime greater than 1024 bits or 2048 bits. In this implementation, the pre-stored prime may be used as a data storage device when the wallet generates child keys. Assuming that the private key is S, the wallet may select a random number Ri based on the number of shared persons. In order to satisfy the child key calculation condition, a prime number P having a length greater than the length of the private key S or the random number Ri may be selected. Also, to generate child keys, (S+R<sub>1</sub>X+R<sub>2</sub>X<sup>2</sup>+R<sub>3</sub>X<sup>3</sup>+ +R<sub>N</sub>X<sup>N</sup>) can be used to perform modulo operations on P. A specific example may appear as follows:
(1) if two people share an asset, the generated child keys are respectively: generated by performing a modulo operation on P using child key 1: (S+R); and child key 2: (S+2R) may be generated by performing a modulo operation on P.
(2) If three people share an asset, the generated child keys are each: (S+R<sub>1</sub>+R<sub>2</sub>) to perform a modulo operation on P using the child key 1; (S+2R)<sub>1</sub>+4R<sub>2</sub>), the child key 2 generated by performing a modulo operation on P; and (S+3R<sub>1</sub>+9R<sub>2</sub>) may be a child key 3 generated by performing a modulo operation on P.
Similarly, if (N+1) people share an asset, (N+1) child keys need to be generated, and (S+R)<sub>1</sub>X+R<sub>2</sub>X<sup>2</sup>+R<sub>3</sub>X<sup>3</sup>+ +R<sub>N</sub>X<sup>N</sup>) can be used to perform modulo operations on P. Child keys can be obtained through calculation by selecting the value of X from [1, N+1]. In another example, when 4 people share an asset, the process for generating 4 child keys using the previous method could be as follows: (S+R<sub>1</sub>+R<sub>2</sub>+R<sub>3</sub>) to perform a modulo operation on P using the child key 1; (S+2R)<sub>1</sub>+4R<sub>2</sub>+8R<sub>3</sub>), the child key 2 generated by performing a modulo operation on P; (S+3R<sub>1</sub>+9R<sub>2</sub>+27R<sub>3</sub>), the child key 3 generated by performing a modulo operation on P; and (S+4R<sub>1</sub>+16R<sub>2</sub>+64R<sub>3</sub>), a child key generated by performing a modulo operation on P 4.
According to the predetermined algorithm for calculating the child keys provided in this embodiment, the number of child keys equal to the number of parties sharing the original key is the original using a predetermined method of combining random numbers, decimals, and modulo operations. It may be automatically generated based on the number of parties sharing the key. Since the child key generation method is used, the generated child keys are kept more confidential, the risk of the child keys being cracked is reduced, and the transaction is more secure.
In another implementation of the method provided herein, a plurality of corresponding child keys may be generated based on the original key of the shared object, and the original key may be restored based on the received child keys. Specifically, in another implementation of the method provided herein, the method may further comprise the following steps:
S80. Receive the input child keys.
S82. If it is determined that the number of child keys is equal to the number of parties sharing the corresponding original key, an original key based on the child keys is calculated and restored using a predetermined algorithm to obtain the corresponding original key.
Of course, the method may further comprise the following steps:
S84: Compute the shared object using the original key obtained after restoration through calculation.
4 is a flowchart illustrating an exemplary method according to another implementation of the present specification. If the original key is required for asset operation, each asset-sharing party of the original key can enter its own child key. Because the child key is distributed to a plurality of asset sharing parties, in this implementation, the original key is restored when a number of child keys equal to the number of parties sharing the original key is received. For example, a wallet's private key creates three child keys, which are stored in each of the three wallet sharers. When wallet fund operation is to be performed, each wallet sharing party enters its own child key. In this situation, upon receiving the three child keys, the wallet can use the three child keys to restore the wallet's private key. If the wallet receives only one or two child keys, or receives three or more child keys, it may indicate that the number of child keys is different from the number of wallet sharing persons, and the original key cannot be restored.
The original key may be restored based on the child keys referencing the characteristics of the child keys using an algorithm or some specific method corresponding to the algorithm for generating the child keys. For example, in one or more processes herein for reconstructing the original key, in implementations using random, decimal, and modulo operations to generate a child key, the original private key S may be reconstructed using Lagrange's equations.
After the restored original key is obtained, the corresponding shared object can be computed using the key. For example, a transaction may be signed to confirm that it was created by a user authorized by the wallet. Furthermore, the wallet can broadcast information about signed transactions to the blockchain network and store the information in a new block.
The preceding implementation provides a predetermined algorithm for generating child keys using a random number string or a random number, decimal, or the like. Another implementation herein provides another implementation that generates a corresponding number of child keys based on the original key. In this implementation, an exclusive OR calculation may be performed on the original key and each random number generated at any time, where the random numbers have the same length. The values obtained after the exclusive OR calculation and these random numbers are used as child keys. Specifically, in another implementation of the method provided herein, the predetermined algorithm may include the following steps:
S210. Generate (N-1) random numbers, where the binary lengths of the random numbers are equal to the binary length of the original key, and N is the number of parties sharing the original key.
S212. To obtain an exclusive OR child key, a bitwise exclusive OR operation is performed on the original key and each (N-1) random number.
S214. The exclusive OR child key and (N-1) random numbers are used as the N output child keys.
In this implementation, if the shared object can generate (N-1) random numbers in advance, the length of the random numbers may be equal to the length of the original key, for example, a binary number of 1024 bits or 2048 bits. To obtain a value, an exclusive OR calculation may be performed on the original key and each (N-1) random number. The value and (N-1) previously generated random numbers are used as child keys, and one child key is assigned to each individual sharing party.
A specific example of a processing method for performing a bitwise exclusive OR operation on an original key and respective random numbers is shown in FIG. 5 . 5 is a schematic diagram illustrating another process for generating a child key based on a predetermined algorithm in accordance with the present disclosure; In a binary system, it is assumed that the length of the original key S is 1024 bits, and the number of parties sharing the original key is 4. Accordingly, three random binary numbers of 1024 bits can be generated first. Then, an exclusive OR operation may be performed on the original key S and the first random number to obtain R1, and an exclusive OR operation may be performed on R1 and the second random number to obtain R2. After all, an exclusive OR operation is performed on R2 and the third random number to obtain R3, and R3 is the exclusive OR child key in this implementation. R3 and 3 random binary numbers of 1024 bits are used as 4 child keys obtained through calculation. When the original key needs to be restored, an inverse exclusive-OR operation may be performed on the child keys obtained by performing an exclusive-OR operation in the present implementation. The exclusive OR operation is used during encryption, and the inverse operation of the exclusive OR operation is performed during decryption. In this way, the original key can be obtained. The exclusive OR operation method provided in this embodiment is used to ensure all correct child keys that need to be collected during decryption, and the original key can be quickly obtained by performing an exclusive OR operation on the child keys. As such, it is easier to restore the key, and the processing speed of restoring the original key during decryption is increased while maintaining asset transaction security.
Implementations herein are described in an inventive manner, and reference may be made to such implementations for identical or similar parts in the implementations, with each implementation focusing on differences from other implementations. For details, reference may be made to the description in the previous related processing and related implementations. Details are not described here.
Specific implementations of this specification have been described above. Other implementations are within the scope of the appended claims. In some circumstances, the acts or steps recited in the claims may be performed in a sequence other than the implementation above and the desired results may still be achieved. Further, the processes depicted in the accompanying drawings do not necessarily require a particular sequence or sequence of sequences to achieve the desired result. In some implementations, multitask processing and parallel processing may be feasible or advantageous.
According to the key data processing method provided in one or more implementations of this specification, the original key may be partitioned into a plurality of child keys based on the number of parties sharing the original key of a shared object, such as an asset or data, and the generated Child keys may be displayed to corresponding asset sharing parties. If a shared object needs to be operated, each asset-sharing party can provide a child key. The original key can then be restored using the child keys, and corresponding operations such as signing and asset trading can be performed. As such, in this implementation of the present specification, when the assets in the blockchain are shared by a plurality of people, in order to ensure the security of the transaction of the shared assets of the blockchain, one person uses the assets without the knowledge of others. operation can be effectively prevented.
Based on the previous user key data processing method, one or more implementations of the present specification further provide a key data processing apparatus. The apparatus may include an apparatus having the necessary implementation hardware of the method in the implementation of the present specification and using a system (including a distributed system), software (application), module, component, server, client, and the like. Based on the same innovative concept, an apparatus provided in one or more implementations of this specification is described in the following implementations. Since the problem solving implementation solution of the apparatus is similar to that of the above method, for the specific implementation of the apparatus in the implementation of the present specification, the implementation of the previous method may be referred to. No repeat description is provided. The term "unit" or "module" used in the following implementation may implement a combination of software and/or hardware of predetermined functions. The apparatus described in the following implementations is preferably implemented by software, but implementations in hardware or a combination of software and hardware are conceivable. Specifically, FIG. 6 is a schematic structural diagram illustrating a module of a key data processing apparatus according to an implementation of the present specification. As shown in FIG. 6 , the device may include an original key information obtaining module 101 and a child key generating module 102 . The original key information acquisition module 101 is configured to acquire the original key of an object shared in the block chain, and determine the number of parties sharing the original key. The child key generation module 102 is configured to process the original key using a predetermined algorithm, generate a number of child keys equal to a number of parties sharing the original key, and when obtaining the same number of child keys The keys are used to restore the original key.
According to the key data processing apparatus provided in the present implementation, the original key may be divided into a plurality of child keys based on the number of parties sharing the original key of a shared object such as an asset or data. Since each sharer owns one child key, when a plurality of people share an asset, the asset transaction requires the joint participation of the plurality of people. In this way, it is possible to effectively prevent asset sharing parties from privately operating transaction data on the blockchain, thereby ensuring the security of asset transactions.
7 is a schematic structural diagram illustrating a module of a key data processing apparatus according to another implementation of the present specification. In another implementation of the device, the device includes: a child key output module 103, configured to send a child key to corresponding object sharing parties; and an original key deletion module 104 configured to delete the original key.
In the present implementation, by using each of the plurality of child keys generated based on the original key, transaction verification cannot be independently performed or verification cannot be successful. When all child keys generated with the same original key are collected together, the original key can be restored.
After the number of child keys equal to the number of asset sharing parties is generated, the child key may be presented to the corresponding asset sharing party, so that each asset sharing party can obtain a child key. Then, the original key can be deleted. For example, the original private key can be completely deleted from the e-wallet. As such, to further ensure key data security and prevent the asset sharing party from using the private key for asset transactions privately, no asset sharing party with the child key stores the original key.
In another implementation of the device, the predetermined algorithm used in the child key generation module 102 uses the randomly generated string to generate a number of child keys equal to the number of parties sharing the original key. It may include the step of performing an operation on.
Another implementation of the apparatus herein provides an implementation for generating a child key using random, decimal, and modulo operations. 8 is a schematic structural diagram illustrating a child key generation module in an apparatus according to an implementation of the present specification. As shown in FIG. 8 , the child key generation module 102 may include a random number generation unit 1021 , a prime selection unit 1022 , and a child key calculation unit 1023 . The random number generating unit 1021 generates N random numbers Ri, when there are (N+1) sharing parties, where Ri is the i-th random number and i[1, N]. The prime number selection unit 1022 is configured to determine a prime number P, wherein the prime number P is greater than at least any one of the value S of the original key and the random number Ri, and the range of Ri is [0, P-1]. The child key calculation unit 1023 is configured to obtain (N+1) child keys, (S+R<sub>1</sub>X+R<sub>2</sub>X<sup>2</sup>+R<sub>3</sub>X<sup>3</sup>+ +R<sub>N</sub>X<sup>N</sup>) is computed, then perform a modulo operation on P, and select a value of X from [1, N+1], where N1, X and N are integers.
Based on the predetermined algorithm for calculating child keys provided in this implementation and the number of parties sharing the original key, the number of parties sharing the original key using a predetermined method of combining random, decimal, and modulo operations. The same number of child keys can be automatically generated. By using the above-described method of generating child keys, child keys can be generated more securely, the risk of the child keys being broken is reduced, and the transaction is more secure.
In another implementation of the apparatus provided herein, a plurality of corresponding child keys may be generated based on the original key of the shared object, and the original key may be further restored based on the received child keys. 9 is a schematic structural diagram illustrating a key data processing apparatus according to another implementation of the present specification. As shown in FIG. 9 , the apparatus may further include a receiving module 1051 and an original key recovery module 1052 . The receiving module 1051 is configured to receive the inputted child key. The original key recovery module 1052, to obtain a corresponding original key, when it is determined that the number of child keys is equal to the number of parties sharing the corresponding original key, through calculation, the child keys using a predetermined algorithm Restore the original key based on
10 is a schematic structural diagram illustrating a child key generation module in an apparatus according to another implementation of the present specification. As shown in FIG. 10 , the child key generation module 102 may include a random number generation unit 20 , an exclusive OR calculation unit 21 , and a child key determination unit 22 . The random number generating unit 20 is configured to generate (N-1) random numbers, where the binary lengths of the random number are equal to the binary length of the original key, and N is the number of parties sharing the original key. The exclusive-OR calculation unit 21 is configured to perform a bitwise exclusive-OR operation on each of the original key and (N-1) random numbers to obtain an exclusive-OR child key. The child key determining unit 22 is configured to use the exclusive OR child key and (N-1) random numbers as the N output child keys.
In this implementation, an exclusive OR calculation may be performed on each of the original key and a random number of the same length generated at any time, to obtain a value, then the value generated after the exclusive OR calculation and these random numbers are used as child keys is used as
The exclusive OR operation method provided in this implementation is used to ensure all correct child keys that must be collected during decryption, and by performing an exclusive OR operation on the child key, the original key can be quickly obtained. As such, it is easier to restore the key, and the processing speed of restoring the original key during decryption is greatly improved while maintaining the security of the asset transaction.
It is noteworthy that the previous apparatus may further include other implementations based on the description of method implementations. For a specific implementation, reference may be made to the description in the relevant method implementation, and details are not described herein.
In the previous device implementation, in the actual product application, each module or sub-module may be combined or divided based on the implementation environment or data processing requirements. When one or more implementations of the present specification are implemented, the function of each module may be implemented with one or more software and/or hardware, or a module implementing the same function may be implemented with a plurality of sub-modules or a combination of sub-parts. The device implementations described are by way of example only. For example, unit division is only logical function division and may be another division in actual implementation. For example, a plurality of units or components may be combined or integrated into another system, or some features may be ignored or not performed.
11 is a schematic structural diagram illustrating a module using a wallet application according to an implementation of the present specification. 11 , the public and private key generation component of the wallet may generate public and private keys of the wallet. The prime storage component pre-stores a plurality of prime numbers whose length is greater than the length of the private key. The random number generation component may generate a corresponding number of random numbers when it needs to generate child keys. The child key calculation unit may generate a plurality of child keys corresponding to the private key, and output the child keys. Output child keys may be assigned to corresponding wallet sharing parties. When an asset transaction is performed in the wallet, each sharing party enters a child key, and the private key recovery calculation component calculates the original key based on the corresponding algorithm to restore the original key, and uses the original key to You can sign, verify, and so on. After a transaction is created, the transaction can be broadcast to the entire blockchain network.
According to the key data processing apparatus provided in one or more implementations of the present specification, the original key is divided into a plurality of child keys based on the number of parties sharing the original key of a shared object such as an asset or data, and the generated child key may be displayed to the corresponding asset sharing parties. Each asset-sharing party can provide a child key if the shared object needs to operate. The original key is then restored using the child keys, and corresponding operations such as signing and asset trading can be performed. As such, in this implementation of the present specification, when the assets in the blockchain are shared by a plurality of people, in order to ensure the security of the transaction of the shared assets of the blockchain, one person acquires the asset without the knowledge of another person. operation can be effectively prevented.
The method or apparatus in the previous implementation of the present specification may implement the service logic using a computer program and record the service logic in a storage medium, in order to implement the effect of the solution described in the present invention of the present specification, the storage medium The medium can be read and executed by a computer. A storage medium may include a physical device for storing information, which is typically digitized and stored on a medium such as electrical, magnetic or optical. The storage medium may include a device for storing information in an electrical energy manner, for example, a storage device such as RAM or ROM; devices that store information in a magnetic energy manner, such as hard disks, floppy disks, magnetic tape, magnetic core memory, magnetic bubble memory, or USB flash drives; and a device for storing information in an optical manner, such as a CD or DVD. Of course, other forms of readable storage media such as quantum memory or graphene memory also exist.
The method or apparatus for processing user key data provided in the implementation of the present specification may be implemented by a processor of a computer by executing a corresponding program instruction, for example, a server using the c++ language in a Windows operating system, a server based on a Linux system It can be implemented on a server, a server system terminal using Android, iOS system programming language, or it can be implemented using a processing logic based on a quantum computer. The program instructions may be stored in a storage medium. In another implementation of the key data processing apparatus provided herein, a processor and a memory configured to store instructions executable by the processor may be included, and when executing the instructions, the processor implements the following operations: obtaining the original key of the object and determining the number of parties sharing the original key; and processing the original key using a predetermined algorithm to generate a number of child keys equal to the number of parties sharing the original key, wherein the child keys restore the original key when the same number of child keys are obtained. used to do
It is noteworthy that the previous apparatus may further include other implementations based on the description of method implementations. For example, the processor deletes the data of the original key, generates child keys using random number, decimal, and modular operations, restores the original key using Lagrange equations, and performs an exclusive OR operation to generate child keys and perform an inverse operation to restore the original key. For a specific implementation, reference may be made to a description of a related method implementation, which is not described in detail herein.
The previous method or apparatus can be used in multiple servers for key data processing, for example, a daemon server in a wallet, a server in a miner node in a blockchain, and a service server in a node in a blockchain. Servers may contain separate servers, or they may contain servers in a distributed system or architectural patterns of server clusters. Specifically, the present specification provides a server as shown in FIG. 12 , and the server may include at least one processor and a memory configured to store instructions executable by the processor. When executing the instruction, the processor implements the following operations: obtaining the original key of the shared object in the blockchain, and determining the number of parties sharing the original key; and processing the original key using the predetermined algorithm to generate a number of child keys equal to the number of parties sharing the original key. When the number of obtained child keys is equal to the number of parties sharing the original key, the child keys can be used to restore the original key.
It is noteworthy that the previous server may further include other implementations based on the description of the method or apparatus implementation. For example, the processor deletes the data in the original key, generates a child key using random, decimal, and modular operations, restores the original key using Lagrange's formula, and performs an exclusive OR operation to generate a child key. and perform an inverse operation to restore the original key. For a specific implementation, reference may be made to a description of a related method or apparatus implementation, which is not described in detail herein.
Implementations herein are described in an inventive manner, and reference may be made to such implementations for identical or similar parts in the implementations, with each implementation focusing on differences from other implementations. In particular, the hardware and program implementation are basically similar to the method implementation, and thus will be briefly described, and for related parts, partial descriptions in the method implementation may be referred to.
Specific implementations of this specification have been described above. Other implementations are within the scope of the appended claims. In some circumstances, the acts or steps recited in the claims may be performed in a different sequence than in implementations and the desired results may still be achieved. Furthermore, the processes depicted in the accompanying drawings do not necessarily require a particular sequence or sequence to achieve the desired result. In some implementations, multitask processing and parallel processing may be feasible or advantageous.
According to the key data processing method, apparatus, and server provided in one or more implementations of the present specification, the original key may be divided into a plurality of child keys based on the number of parties sharing the original key of a shared object, such as an asset or data. and the generated child keys may be displayed to corresponding asset sharing parties. When a shared object needs to be operated, each sharing party can provide a child key. The original key is then restored using the child keys, and corresponding operations such as signing and asset trading can be performed. As such, in this implementation of the present specification, when the assets in the blockchain are shared by a plurality of people, in order to ensure the security of the transaction of the shared assets of the blockchain, one person uses the assets without the knowledge of others. operation can be effectively prevented.
The content of implementations of this specification includes data generation, definition, acquisition, interaction, calculation, determination, etc., for example, generating child keys using random, decimal, and modulo operations, and using exclusive OR operations to create child keys. , restore the original key using Lagrange's equation, and delete the original private key after child key assignment. However, implementations herein are not limited to satisfying industry communication standards, blockchain data rules, standard computer data processing and storage rules, or the circumstances described in one or more implementations herein. An implementation solution using some industry standard or slightly modified in a self-defined manner or based on the described implementation may realize the same, equivalent, or similar implementation effect as the described implementation, or an expected implementation effect after conversion. Implementations of obtaining, storing, determining, processing the modified or altered data, etc. may still fall within the scope of optional implementation solutions of the implementations herein.
Specific implementations of this specification have been described above. Other implementations are within the scope of the appended claims. In some circumstances, the acts or steps recited in the claims may be performed in a different sequence than in implementations and the desired results may still be achieved. Further, the processes depicted in the accompanying drawings do not necessarily require a particular sequence or sequence of sequences to achieve the desired result. In some implementations, multitask processing and parallel processing may be feasible or advantageous.
In the 1990s, it can be clearly distinguished whether a technological improvement is a hardware improvement (e.g., an improvement in a circuit structure such as a diode, transistor, or switch) or a software improvement (an improvement of a method procedure). However, as technology advances, improvements in many current method procedures can be regarded as direct improvements in hardware circuit structures. A designer generally programs an improved method procedure into a hardware circuit to obtain a corresponding hardware circuit structure. Thus, the hardware entity module can improve the method procedure. For example, a programmable logic device (PLD) (eg, a field programmable gate array (FPGA)) is such an integrated circuit, and the logical function of the programmable logic device is determined by the user through device programming. Designers do the programming to "integrate" the digital system into the PLD without requiring the chipmaker to design and produce an application-specific integrated circuit chip. Also, programming is mostly implemented by modifying "logic compiler" software, rather than directly building an integrated circuit chip. It is analogous to a software compiler used to develop and write programs. However, the original code obtained before compilation is written in a specific programming language, which is called a hardware description language (HDL). However, Advanced Boolean Expression Language (ABEL), Altera Hardware Description Language (ADL), Confluence, Cornell University Programming Language (CUPL), HDCal, Java Hardware Description Language (JHDL), Lava, Lola ), MyHDL, PALASM, and HDLs such as RHDL (Ruby Hardware Description Language). Currently, VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog are the most popular. A person skilled in the art will realize that only logic programming needs to be performed in the method procedure using some hardware description language described, and some hardware description language is programmed in an integrated circuit, so that a hardware circuit implementing the logical method procedure can be easily obtained. should understand
The controller may be implemented in any suitable manner. The controller may use, for example, a microprocessor or processor, and may be computer readable media, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and computer readable (micro) processors executable on a processor. It may store in the form of an embedded microcontroller that is program code (eg, software or hardware). Controllers include, but are not limited to, microcontrollers such as ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, or Silicone Labs C8051F320. The memory controller may also be implemented as part of the control logic of the memory. Those skilled in the art will also appreciate that, in addition to implementing the controller in a pure computer readable program code manner, logic programming can be completely performed using the method steps above, so that the controller can include logic gates, switches, application specific integrated circuits, programmable logic controllers, The same function is implemented in the form of a built-in microcontroller, etc. Accordingly, the controller may be regarded as a hardware component, and an apparatus for implementing various functions in the controller may be regarded as a structure in the hardware component. Alternatively, an apparatus configured to implement various functions may be regarded as a structure in a software module or hardware component that may implement the method.
A system, apparatus, module, or unit described in the described implementation may be specifically implemented by a computer chip or entity, or may be implemented by a product having a function. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, laptop computer, mobile phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer or wearable device or a combination of such devices. can be
While one or more implementations of this specification provide operational steps of a method according to an implementation or flowchart, conventional or non-creative means may include more or fewer operational steps. The sequence of steps listed in the implementation is only one of a plurality of step execution sequences and does not represent a unique execution sequence. In actual execution of the device or terminal product, the execution may be performed based on the implementation or method sequence shown in the accompanying drawings, or may be performed in parallel (eg, a parallel processor or multi-threaded processing environment, or even distributed data). processing environment). The terms "include", "contain" or other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article or apparatus comprising a set of elements will include such elements. In addition, it also includes other elements not explicitly listed, or further includes elements unique to such process, method, article, or apparatus. An element preceded by "comprising ..." does not exclude, without further limitation, the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
For convenience of description, the described apparatus has been described by dividing the functions into various units. Of course, when one or more implementations of the present specification are implemented, the function of each module may be implemented in one or more software and/or hardware, or a module implementing the same function may be implemented by a plurality of sub-modules or a combination of sub-parts. can The device implementations described are by way of example only. For example, unit division is only logical function division, and may be another division in actual implementation. For example, a plurality of units or components may be combined or integrated into another system, or some features may be ignored or not performed. Also, the displayed or discussed mutual couplings or direct couplings or communication connections may be implemented using some interfaces. Indirect couplings or communication connections between devices or units may be implemented electronically, mechanically, or otherwise.
A person skilled in the art will recognize that in addition to implementing the controller in a pure computer readable program code manner, logic programming can be completely performed using the method steps, so that the controller can include logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded I know that it implements the same function in the form of a microcontroller, etc. Accordingly, the controller may be regarded as a hardware component, and an apparatus for implementing various functions in the controller may be regarded as a structure of the hardware component. Alternatively, an apparatus configured to implement various functions may be regarded as a structure in a software module or hardware component that may implement the method.
The disclosure is described with reference to flowcharts and/or block diagrams of methods, apparatus (systems) and computer program products according to implementations of the disclosure. It should be understood that computer program instructions may be used to implement each process and/or each block in the flowcharts and/or block diagrams and combinations of processes and/or blocks in the flowcharts and/or block diagrams. These computer program instructions are provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing device to create a machine, and the instructions are executed by the processor of the computer or other programmable data processing device processor. creates an apparatus for implementing a particular function in one or more processes in a flowchart or in one or more blocks in a block diagram.
These computer program instructions may be stored in a computer readable memory capable of instructing a computer or any other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory create artifacts comprising the instruction device. do. The instruction device implements particular functions in one or more processes of the flowchart and/or one or more blocks of the block diagram.
These computer program instructions may be loaded into a computer or other programmable data processing device such that a series of actions and steps are performed on the computer or other programmable device to produce computer implemented processing. Accordingly, instructions executed on a computer or other programmable device provide steps for implementing particular functions in one or more processes of a flowchart or one or more blocks of a block diagram.
In a typical configuration, a computing device includes one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
Memory may include forms such as volatile memory, random access memory (RAM) and/or non-volatile memory in a computer-readable medium such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of a computer readable medium.
Computer-readable media includes volatile and nonvolatile, removable and non-removable media, and can store information using any method or technology. The information may be computer readable instructions, data structures, program modules, or other data. Computer storage media include phase change random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programable read-only memory), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic tape, magnetic disk storage, other magnetic storage device, or any other non-transmission medium. Computer storage media may be used to store information that can be accessed by a computing device. As described herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
Those skilled in the art should appreciate that one or more implementations of the present disclosure may be provided as a method, system, or computer program product. Thus, one or more implementations of this specification may use a form of hardware-only implementation, a software-only implementation, or an implementation having a combination of software and hardware. In addition, one or more implementations of this specification may be implemented in a computer program product embodied in one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code. form can be used.
One or more implementations of this specification may be described in the common context of computer-executable instructions being executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular operations or implement particular abstract data types. One or more implementations of this disclosure may also be practiced in distributed computing environments. In such distributed computing environments, operations are performed by remote processing devices that are linked using a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media including storage devices.
The implementations herein are all described in an inventive manner, and reference may be made to these implementations for the same or similar parts in the implementations, with each implementation focusing on differences from other implementations. In particular, the system implementation is essentially similar to the method implementation, so it is briefly described; For a related part, reference may be made to a partial description in method implementation. In the description of this specification, references to terms such as "implementations", "some implementations", "examples", "specific examples" and "some examples" refer to the implementation or included in at least one implementation or example herein. means a particular feature, structure, material, or characteristic described with reference to an example. In this specification, previous example representations of terms are not necessarily related to the same implementation or example. Moreover, a particular feature, structure, material, or characteristic described may be combined in any suitable manner in any one or more implementations or examples. In addition, those skilled in the art may incorporate or combine features of the different implementations or examples described herein without conflicting with each other.
The foregoing description is merely an implementation of one or more implementations of the disclosure, and is not intended to be limiting of one or more implementations of the disclosure. Those skilled in the art will appreciate that one or more implementations of this disclosure may be subject to various modifications and variations. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present application shall fall within the protection scope of the claims.
13 is a flowchart illustrating an example of a computer implemented method 1300 for managing shared ownership in a blockchain network, according to an implementation of the present disclosure. For clarity of presentation, the following description describes method 1300 generally in the context of other figures of this description. However, it may be understood that method 1300 may be suitably performed by, for example, any system, environment, software and hardware, or combination of systems, environment, software and hardware. In some implementations, the various steps of method 1300 may be executed in parallel, in combination, repeated, or in any order.
In a blockchain network, blockchain objects can represent various assets or data to be tracked or recorded by the blockchain. Ownership of a blockchain object generally relates to a public-private key pair, and establishing that a party owns the private key of a public-private key pair is used to indicate ownership of a blockchain object. For example, the owner of a blockchain object can use the private key to encrypt the hash of the blockchain object, while other parties confirm that the owner possesses the private key of the public-private key pair associated with the blockchain object. In order to do this, it can be decrypted using the public key associated with the blockchain object, thus verifying the owner of the object.
In general, assets may be jointly owned by two or more parties. For example, a house, car or bank account may be jointly owned by two or more parties. As such, the ability to jointly own a blockchain object is required. However, in a typical blockchain network, only a single public-private key pair can be associated with a blockchain object, and it may not be possible to modify the blockchain network architecture to associate multiple public-private key pairs with an object. As such, there is a need to manage the shared ownership of blockchain objects in existing blockchain networks. This shared ownership generates multiple child cryptographic keys from the private key of a public-private key pair associated with a blockchain object ("parent cryptographic key"), and provides the child cryptographic keys to the object's co-owners. It can be implemented by distributing it.
Individual child encryption keys are different from the parent encryption key and therefore cannot be used to establish ownership of a blockchain object. However, once the co-owners each provide a child encryption key and a complete set of child encryption keys is obtained, the parent encryption key can be reconstructed from the child encryption keys, which in turn proves joint ownership on the blockchain object and all co-owners agree As such, it can be used to dispose of a blockchain object. Accordingly, joint control over the blockchain object is established, where the blockchain object can only be controlled if all co-owners have provided their consent by providing their child encryption keys.
At 1302 , a parent encryption key associated with the blockchain object is obtained. This step may be similar to step S0 of FIG. 1 . Because a blockchain object is associated with a single public-private key pair, a blockchain object can initially be owned by a single owner at the time of object creation. When a group of parties jointly owns the created blockchain object or wants to change the ownership of the blockchain object from sole ownership to shared or co-ownership, the private key of the public-private key pair associated with the blockchain object is obtained. The private key can be obtained from the blockchain network at the time of creating the blockchain object, for example, or provided by the current owner of the blockchain object. In some implementations, an intermediary, such as a broker or agent, may obtain a parent encryption key on behalf of interested parties to protect the integrity of ownership of a blockchain object until child encryption keys are generated.
The private key of a public-private key pair is an example of a parent encryption key. A parent encryption key is typically a sequence of bits of a predetermined length depending, for example, on a particular encryption standard or technique. For example, the parent encryption key may have a length of 128, 256, 384, 1024, 2048, 3072 bits or more.
At 1302 , the method 1300 proceeds to 1304 .
At 1304 , a number N of parties to share control over the blockchain object is obtained. N is an integer of 2 or more. Before generating child encryption keys, the number of keys to be generated must first be obtained. For example, parties establishing co-ownership can provide their number N to the blockchain network, the current owner or intermediary of the blockchain object. The number of these keys is usually the number of parties sharing control over the blockchain. Parties sharing control over the blockchain can be joint or shared owners of blockchain objects. In some implementations, parties sharing control may have capacity other than the sharing or co-owner of a blockchain object. For example, a party may be a custodian of a real estate or will, which does not own the blockchain object, but has control over how the blockchain object is disposed of.
At 1304 , the method 1300 proceeds to 1306 .
At 1306, N child encryption keys based on the parent encryption key are generated by applying a predetermined algorithm to the parent encryption key. The N child encryption keys are collectively operable to reconstruct the parent encryption key. This step may be similar to step S2 of FIG. 1 . In general, child encryption keys must meet two criteria. First, individual child encryption keys must be different from the parent encryption key, so that individual child keys cannot be used to establish ownership. It would also be advantageous for the generated child encryption keys to differ from the parent encryption keys in a manner that does not substantially reduce the security level of the parent encryption keys. Second, the complete set of child encryption keys should allow deterministic reconstruction (ie not brute force) of the parent encryption key.
Once the parent encryption key and the number of parties N are obtained, N child encryption keys may be generated from the parent encryption key in various ways. In some implementations, the N child encryption keys are generated by applying a predetermined algorithm to the parent encryption key comprising: generating N-1 random numbers Ri, where i is an integer between 1 and N-1 and Ri is a non-negative integer; determining a prime number P greater than a random number Ri, wherein the prime number P is at least greater than either the value S of the parent encryption key or the random number Ri and greater than the random number Ri; and determining N child encryption keys Cx, where Cx = P modulo (S+R<sub>1</sub>X+R<sub>2</sub>X<sup>2</sup>+R<sub>3</sub>X<sup>3</sup>+ +R<sub>N-1</sub>X<sup>N-1</sup>) and X is an integer between 1 and N. The formula for determining the child encryption keys Cx is<img file="KR20190134634A_D0001.tif" />and can be rewritten in a mathematically equivalent form.
In some implementations, the N child encryption keys may include: generating, in the parent encryption key, N-1 random numbers having a bit length equal to a bit length of the parent encryption key; and generating an XOR child encryption key by performing a series of bitwise exclusive OR (XOR) operations, wherein the series of bitwise XOR operations is performed between the parent encryption key and N-1 random numbers. performing an XOR operation between them; and sequentially performing an XOR operation between the output of the previous XOR operation and one of the remaining random numbers. An XOR child encryption key generated by N-1 random numbers and an XOR operation can be used as the N child encryption keys.
In some implementations, the N child encryption keys are generated by applying a predetermined algorithm to the parent encryption key that includes modifying the parent encryption key based on a randomly generated string. This step may be similar to step S20 described above. A portion of the randomly generated string may be used to otherwise modify the parent encryption keys to generate other child encryption keys. For example, a specific portion of the parent encryption key may be replaced with a specific portion of a randomly generated string to generate a child encryption key. Another portion of the parent encryption key may be replaced with another portion of a randomly generated string to generate a plurality of child encryption keys. The position and length of the replaced part in the parent encryption key and the corresponding position and length of the randomly generated character string may be determined according to a preset algorithm. The preset algorithm may change the position and length of the replaced part in a random manner to improve the robustness of the generated child encryption keys. The location and length of the replaced part may be shared among the parties holding the child encryption keys, for use while reconstructing the parent encryption key from the child encryption keys. In some implementations, in addition to replacing other parts of the parent encryption keys with parts of a randomly generated string, the bit-string generated from the replacement is shuffled according to a preset algorithm to improve robustness. can be scrambled).
1306 Thereafter, the method 1300 stops.
In some implementations of method 1300 , the method includes sending N child encryption keys to corresponding parties; and deleting the parent encryption key. By deleting the parent encryption key, the possibility of a single party to obtain the parent encryption key without reconstructing the parent encryption key from the complete set of child encryption keys is essentially eliminated, thus ensuring the robustness of the shared ownership established through child encryption keys. This is improved. In addition, if an intermediary is involved in the generation of child encryption keys, it is possible to prevent potential unauthorized control of the intermediary's blockchain object by deleting the parent encryption key owned by the intermediary. In some implementations, the method can further include confirming that the transmitted child encryption keys have been received by corresponding parties and deleting the parent encryption key when all parties have confirmed receipt of the child encryption keys.
Once the child encryption keys are generated and sent to the parties, and the parent encryption key is deleted, the blockchain object associated with the parent encryption key cannot be controlled by any single party. When all shared or co-owners of a blockchain object agree to sell or control the blockchain object, the parent encryption key needs to be reconstructed. The parent encryption key may be reconstructed from the complete set of child encryption keys based on the reconstruction algorithm. As such, in some implementations of method 1300 , the method includes receiving a plurality of encryption keys; determining whether the number of received plurality of encryption keys is equal to the number of parties sharing control over the blockchain object; in response to determining that the received plurality of encryption keys is equal to the number of parties sharing control over the blockchain object, reconfiguring the parent encryption key by applying a reconstruction algorithm to the received plurality of encryption keys. . This step may be similar to step S82 of FIG. 4 .
The reconstruction algorithm is generally varied based on a predetermined algorithm for generating the child encryption keys. For example, Lagrange's theorem or Lagrange polynomial can be applied to child encryption keys generated using modulo operations to reconstruct the parent encryption key. As another example, for child encryption keys generated using an XOR-based algorithm, the parent encryption key may be reconstructed using a series of XOR operations. In particular, the XOR operation may be performed in reverse order between the XOR child encryption key and random numbers to reconstruct the parent encryption key. Due to the commutative and associative nature of the XOR operation, reconstruction may be performed by performing a series of XOR operations in any order between the XOR child encryption keys and the random numbers. As such, in some implementations of method 1300 , the method includes receiving an XOR child encryption key and a plurality of encryption keys comprising N-1 random numbers; determining whether the number of received plurality of encryption keys is equal to the number of parties sharing control over the blockchain object; and reconstructing the parent encryption key by performing a series of bitwise XOR operations in response to determining that the number of received plurality of encryption keys is equal to the number of parties sharing control over the blockchain object, The XOR bitwise operation of the XOR operation includes performing an XOR operation between the XOR child encryption key and one of N-1 random numbers; and sequentially performing an XOR operation between the output of the previous XOR operation and one of the remaining random numbers.
The methods and apparatus disclosed herein may improve blockchain networks by allowing sharing or joint control of blockchain objects by multiple parties. Through this joint control or ownership, blockchain networks can support the asset ownership paradigm in traditional ledger and recordkeeping approaches. By generating child encryption keys from a single parent encryption key and reconstructing the parent encryption key from the child encryption keys, shared ownership of a blockchain object can be established in an existing blockchain network without modifying the blockchain architecture. Also, by modifying the parent encryption key using a modulo-based or XOR-based approach to generate the child encryption keys, the result is that the child encryption keys do not contain a significant portion of the parent encryption key. Such child encryption keys enhance the security of a share or joint ownership, for example, compared to an approach in which the parent encryption keys are simply split into parts and provided to the share owners. This partition-based approach may be vulnerable to brute force attempts by a majority, but not all, share owners, since a group of shared owners owns a large portion of the parent encryption key, which reduces the computational burden associated with brute force attempts. significantly reduce, and compromise shared control over blockchain objects.
The embodiments and operations described herein may be implemented in digital electronic circuitry, or computer software, firmware, or hardware including the structures disclosed herein, or a combination of one or more of these. An operation may be implemented as an operation performed by a data processing device on data stored on one or more computer-readable storage devices or received from another source. A data processing apparatus, computer, or computing device may include apparatus, apparatus, and machinery for processing data, including, for example, a programmable processor, a computer, a system on a chip, or a plurality, or a combination, described above. The apparatus may include special purpose logic circuitry, for example, a central processing unit (CPU), a field programmable gate array (FPGA), or an application specific integrated circuit (ASIC). The device may also include code that creates an execution environment for the computer program, eg, processor firmware, protocol stack, database management system, operating system (eg, operating system or combination of operating systems), cross platform runtime environment, virtual code that constitutes a machine or a combination of one or more thereof. The device and execution environment can realize various computing model infrastructures such as web services, distributed computing and grid computing infrastructure.
A computer program (also known as, for example, a program, software, software application, software module, software unit, script, or code) is written in any form of programming language, including compiled or interpreted language, declarative or procedural language. It can be written and distributed in any form, including standalone programs or modules, components, subroutines, objects, or other units suitable for use in a computing environment. A program may be a part of another program or file that holds data (e.g., one or more scripts stored in a markup language document), a single file dedicated to that program, or multiple coordinated files (e.g., one or more modules, sub files that store programs or portions of code). A computer program may be executed on a single computer or on multiple computers located at a single point or distributed over a number of points and connected by a communications network.
Processors for the execution of computer programs include, for example, general and special purpose microprocessors, one or more arbitrary processors of any kind, digital computers. Generally, the processor will receive instructions and data from either read-only memory or random access memory or both. An essential element of a computer is a processor for performing operations according to instructions and one or more memory devices for storing instructions and data. In general, a computer also includes one or more mass storage devices for storing data, one or more mass storage devices for receiving data from or sending data to one or more mass storage devices, or both. will be operatively coupled with The computer may be embedded in another device, for example, a mobile device, a Personal Digital Assistant (PDA), a game console, a Global Positioning System (GPS) receiver, or a portable storage device. Apparatus suitable for storing computer program instructions and data include, for example, semiconductor memory devices, non-volatile memory including magnetic disks and magneto-optical disks, media, and memory devices. The processor and memory may be supplemented or integrated by special purpose logic circuitry.
Mobile devices include handsets, user equipment (UEs), cell phones (eg, smart phones), tablets, wearable devices (eg, smart watches and smart glasses), devices implanted within the human body (eg, biosensors). , cochlear implants) or other types of mobile devices. Mobile devices may communicate wirelessly (eg, using radio frequency (RF) signals) with various communication networks (discussed below). The mobile device may include a sensor for determining a characteristic of a current environment of the mobile device. Sensors include cameras, microphones, proximity sensors, GPS sensors, motion sensors, accelerometers, ambient light sensors, moisture sensors, gyroscopes, compasses, barometers, fingerprint sensors, facial recognition systems, RF sensors (e.g., Wi-Fi and cellular). radio), thermal sensors, or other types of sensors. For example, the camera may include a front or rear camera with a movable or fixed lens, a flash, an image sensor, and an image processor. The camera may be a megapixel camera capable of capturing details for face and/or iris recognition. The camera may form a facial recognition system along with a data processor and authentication information stored in memory or accessed remotely. A facial recognition system or one or more sensors, such as a microphone, motion sensor, accelerometer, GPS sensor, or RF sensor, may be used for user authentication.
In order to provide interaction with the user, embodiments may include a display device and an input device, for example a liquid crystal display (LCD) or organic light-emitting diode (OLED)/virtual-VR (VR) for displaying information to the user. It may be implemented in a computer having a reality/augmented-reality (AR) display, and a touch screen, keyboard and pointing device through which a user may provide input to the computer. Other types of devices may be used to provide for interaction with the user; For example, the feedback provided to the user may be any form of sensory feedback, eg, visual feedback, auditory feedback, or tactile feedback; Input from the user may be received in any form including acoustic, voice or tactile input. In addition, the computer may interact with the user by sending and receiving documents to the device used by the user, for example, by sending a web page to the web browser of the user's client device in response to a request received from the web browser. have.
Embodiments may be implemented using wired or wireless digital data communications (or combinations thereof), for example, computing devices interconnected by any form or medium of a communications network. Examples of interconnected devices are remote clients and servers, typically interacting via a communications network. A client, eg, a mobile device, may perform a transaction, eg, purchase, sell, pay, offer, transfer, or perform or approve a loan, either directly, with or through a server. Such transactions can be performed in real time so that actions and responses can be approximated in time; For example, the individual recognizes that the action and the response occur substantially simultaneously, the time difference between the response to the individual's action is less than 1 millisecond (ms) or less than 1 second, or the response takes into account the processing limitations of the system. So there is no intentional delay.
Examples of communication networks include a local area network (LAN), a radio access network (RAN), a metropolitan area network (MAN), and a wide area network (WAN). Communication networks may include all or part of the Internet, other communication networks, or combinations of communication networks. Information may be transmitted in communication networks according to various protocols and standards, including Long Term Evolution (LTE), 5G, IEEE 802, Internet Protocol (IP), or other protocols or protocol combinations. A communication network may transmit voice, video, biometric or authentication data, or other information between connected computing devices.
Features described in separate implementations may be implemented in combination in a single implementation, whereas features described in a single implementation may be implemented in multiple implementations, individually, or in any suitable subcombination. It should not be understood that acts described and claimed in a particular order require a particular order, or that all acts shown must be performed (some acts may be optional). Where appropriate, multitasking or parallel processing (or a combination of multitasking and parallel processing) may be performed.
15 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15
28 members in 10 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 2017107478075 | China | – | |
| 201710747807 | China | A | |
| 2018048370 | United States of America | W |
Members28
| Document | Office | Kind | |
|---|---|---|---|
| CN107465505A | China | A | |
| CA3058476A1 | Canada | A1 | |
| WO2019046317A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201914255A | Taiwan Province of China | A | |
| WO2019046317A8 | World Intellectual Property Organization (WIPO) | A8 | |
| AU2018323458A1 | Australia | A1 | |
| SG11201909012YA | Singapore | A | |
| KR20190134634AThis record | Republic of Korea | A | |
| EP3586473A1 | European Patent Office (EPO) | A1 | |
| TWI686073B | Taiwan Province of China | B | |
| US2020127817A1 | United States of America | A1 | |
| US2020136814A1 | United States of America | A1 | |
| JP2020526050A | Japan | A | |
| US10797865B2 | United States of America | B2 | |
| AU2018323458B2 | Australia | B2 | |
| US10873449B2 | United States of America | B2 | |
| US2021021409A1 | United States of America | A1 | |
| AU2018323458C1 | Australia | C1 | |
| EP3586473B1 | European Patent Office (EPO) | B1 | |
| SG10202105050PA | Singapore | A | |
| CN107465505B | China | B | |
| US11095437B2 | United States of America | B2 | |
| EP3879751A1 | European Patent Office (EPO) | A1 | |
| US2021314147A1 | United States of America | A1 | |
| CN113765657A | China | A | |
| US11356250B2 | United States of America | B2 | |
| JP7118088B2 | Japan | B2 | |
| CN113765657B | China | B |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of rejection after re-examinationX601 | X601 | |
| AmendmentAMND | AMND | |
| Decision to refuse applicationE601 | E601 | |
| Application refused [patent]X091 | X091 | |
| AmendmentAMND | AMND | |
| Notification of reason for refusalE902 | E902 | |
| Notification of change of applicantN231 | N231 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-2019-0134634
- Application
- 1020197028789
Titles4
- Korean
- 키 데이터 프로세싱 방법 및 장치, 및 서버
- English
- Key data processing method and apparatus, and server
- Unlabeled
- 키 데이터 프로세싱 방법 및 장치, 및 서버
- Unlabeled
- Key data processing method and apparatus, and server
Classification
- CPC, 16
- H04L9/0825
- H04L9/085
- H04L9/0836
- H04L9/0819
- G06Q20/3829
- G06Q20/401
- H04L9/0869
- H04L2209/24
- H04L9/50
- H04L2209/38
- H04L9/0894
- G06F9/30029
- H04L9/0637
- H04L9/14
- G06Q20/367
- H04L9/083
- IPC, 3
- H04L9 08
- G06Q20 38
- G06Q20 40