Secure multiparty loss resistant storage and transfer of cryptographic keys for blockchain based systems in conjunction with a wallet management system
Abstract
The invention provides a computer-implemented solution for controlling access to a computer-related resource such as, for example, a digital wallet. In one or more embodiments, the wallet may be implemented using a blockchain such as the Bitcoin blockchain but the invention is not limited in this regard. Use of the invention during the initial set-up of the wallet can enable subsequent operations such as wallet transactions to be handled in a secure manner over an insecure channel such as the internet. A method according to an embodiment of the invention can comprise the steps of splitting a verification element (such as a private key in an asymmetric cryptography pair) into a plurality of shares; determining a common secret at two or more nodes in a network; and using the common secret to transmit at least one share of the verification element between the two or more nodes. The shares can be split such that no share on its own is sufficient to arrive at the verification element. This means that no one party stores the entire private key, providing for enhanced security of the key. Two or more shares are required to restore the key. The shares are stored at separate locations one of which is an independent back-up or safe-storage location. If one of the other shares becomes unavailable, the share can be retrieved from back up to ensure that the key (and thus the controlled resource) is still accessible. To ensure safe transmission of the share(s), the common secret is generated at two different nodes independently of each other and then used to generate an encryption key. The encryption key can be used to encrypt at least one share of the verification element, or a message comprising it, to ensure that the share(s) are transmitted securely.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
25 claims: 10 independent, 15 dependent
- 1一種以電腦完成控制一資源存取的方法,該方法包含下列步驟: 將一確認元件分割成複數個份額; 決定一網路中二個或更多節點上的一共同私密;以及 使用該共同私密在該二個或更多節點之間傳送該確認元件的至少一份額。
- 2如請求項1所述之方法,其中該確認元件為一加密金鑰、一加密金鑰的表現,或是可用來存取、計算或取回該加密金鑰的一些元件。
- 3如請求項1或2所述之方法,更包含使用共同私密來產生一加密金鑰的步驟,其中該加密金鑰係用來加密該確認元件的該至少一份額,或加密包含或相關於該至少一份額的一信息。
- 4如前述請求項之任一項所述之方法,更包含下列步驟: 儲存該確認元件的至少三個份額於彼此互相相關的不同位置上; 其中該三個份額的至少其中之一係儲存於一個備用或安全儲存的設備中,該設備係與至少二個其他的位置為分離、互相獨立或彼此不同的。
- 5如前述請求項之任一項所述之方法,其中該資源係為一數位錢包,或其他與一些貨幣形式相關的資源。
- 6如前述請求項之任一項所述之方法,其中該確認元件分割成複數個份額,使得確認元件可由二個或多個份額來恢復或重新產生;其中該確認元件使用Shamir秘密共享方案來分割成複數個份額。
- 7如前述請求項之任一項所述之方法,其中該共同私密為: i) 在該至少二個彼此互相獨立的節點上決定,使得該共同私密不需要透過一通信通道在節點之間傳輸;以及/或者 ii) 僅在該至少二節點之間分享。
- 8如前述請求項之任一項所述之方法,包含設立、創造或註冊一數位錢包的步驟,其中該確認元件與該數位錢包相關連。
- 9如前述請求項之任一項所述之方法,其中該共同私密係由網路中的一第一節點(C)及一第二節點(S)來決定,其中該第一節點(C)與具有一第一節點主要私人金鑰(V 1C )及一第一節點主要公用金鑰(P 1C )的一第一不對稱加密對相關連,而該第二節點(S)與具有一第二節點主要私人金鑰(V 1S )及一第二節點主要公用金鑰(P 1S )的一第二不對稱加密對相關連;其中該方法更包含下列步驟: 根據至少該第一節點主要私人金鑰(V 1C )及一產生器值(GV)來決定一第一節點第二私人金鑰(V 2C ); 根據至少該第二節點主要公用金鑰(P 1S )及該產生器值(GV)來決定一第二節點第二公用金鑰(P 2S );以及 根據該第一節點第二私人金鑰(V 2C )及該第二節點第二公用金鑰(P 2S )決定該共同私密; 其中根據一第一節點第二公用金鑰(P 2C )及一第二節點第二私人金鑰(V 2S ),該第二節點(S)具有相同的共同私密,其中: 該第一節點第二公用金鑰(P 2C )係根據於至少該第一節點主要公用金鑰(P 1C )及該產生器值(GV);以及 該第二節點第二私人金鑰(V 2S )係根據於至少該第二節點主要私人金鑰(V 1S )及該產生器值(GV)。
- 10如請求項9所述之方法,其中該產生器值(GV)係根據於一信息(M)。
- 11如請求項10所述之方法,更包含下列步驟: 根據該信息(M)及該第一節點第二私人金鑰(V 2C )來產生一第一簽名信息(SM1);以及 透過該通信網路傳送該第一簽名信息(SM1)到該第二節點(S); 其中該第一簽名信息(SM1)係利用一第一節點第二公用金鑰(P 2C )來確認,以認證該第一節點(C)。
- 12如請求項10或11所述之方法,更包含下列步驟: 透過該通信網路,自該第二節點(S)接收一第二簽名信息(SM2); 利用該第二節點第二公用金鑰(P 2S )來確認該第二簽名信息(SM2);以及 根據該第二簽名信息(SM2)的確認結果來認證該第二節點(S); 其中該第二簽名信息(SM2)係根據該信息(M)或一第二信息(M2),及該第二節點第二私人金鑰(V 2S )來產生。
- 13如請求項9至12之任一項所述之方法,更包含下列步驟: 產生一信息(M);以及 透過一通信網路傳送該信息(M)到該第二節點(S)。
- 14如請求項10至13之任一項所述之方法,更包含下列步驟: 透過該通信網路自該第二節點(S)接收該信息(M)。
- 15如請求項10至14之任一項所述之方法,更包含下列步驟: 透過該通信網路自另一節點接收該信息(M)。
- 16如請求項9至15之任一項所述之方法,其中該第一節點主要公用金鑰(P 1C )、該第二節點主要公用金鑰(P 1S ),係個別根據該第一節點主要私人金鑰(V 1C )及該第二節點主要私人金鑰(V 1S )分別與一基準點(G)的橢圓曲線點乘法。
- 17如請求項9至16之任一項所述之方法,更包含下列步驟: 透過該通信網路接收該第二節點主要公用金鑰(P 1S );以及 將該第二節點主要公用金鑰(P 1S )儲存於與該第一節點(C)相關連的一資料儲存中。
- 18如請求項9至17之任一項所述之方法,更包含下列步驟: 在一第一節點(C)產生第一節點主要私人金鑰(V 1C )及第一節點主要公用金鑰(P 1C ); 透過該通信網路傳送第一節點主要公用金鑰(P 1C )到第二節點(S)及/或其他節點;以及 儲存第一節點主要私人金鑰(V 1C )於與該第一節點(C)相關連的一第一資料儲存。
- 19如請求項9至18之任一項所述之方法,其中該產生器值(GV)係根據前一個產生器值(GV)的一雜湊來決定。
- 20如請求項9至19之任一項所述之方法,其中該第一不對稱加密對及該第二不對稱加密對,係分別根據前一個第一不對稱加密對及前一個不對稱加密對的一函數。
- 21一種以電腦為基礎的系統,設置為實行前述請求項的任一項的步驟。
- 22如請求項第21項所述之系統,其中:該資源為一數位錢包或與一些形式的貨幣相關的其他資源。
- 23如請求項20至22所述之系統,其中該系統包含軟體,其設置為致能一數位錢包的設立、創造或註冊,其中該確認元件係與該數位錢包相關連。
- 24一種以電腦來完成的系統,設置為控制一數位錢包的存取,該系統的操作是用來: 根據至少一第一實體主要私人金鑰及一產生器值來決定一第一實體第二私人金鑰; 根據至少一第二實體主要私人金鑰及該產生器值來決定一第二實體第二私人金鑰; 根據該第一實體第二私人金鑰及一第二實體第二公用金鑰來決定該第一實體上的一共同私密(CS),及根據該第二實體第二私人金鑰及一第一實體第二公用金鑰來決定該第二實體上的共同私密(CS);以及 其中: 該第一實體第二公用金鑰及該第二實體第二公用金鑰係個別根據於至少該第一/第二實體主要金鑰及該產生器值。
- 25一種控制一數位錢包的存取的方法,該方法包含下列步驟: 根據至少一第一實體主要私人金鑰及一產生器值來決定一第一實體第二私人金鑰; 根據至少一第二實體主要私人金鑰及該產生器值來決定一第二實體第二私人金鑰; 根據該第一實體第二私人金鑰及一第二實體第二公用金鑰來決定該第一實體上的一共同私密(CS),及根據該第二實體第二私人金鑰及一第一實體第二公用金鑰來決定該第二實體上的共同私密(CS);以及 其中: 該第一實體第二公用金鑰及該第二實體第二公用金鑰係個別根據於至少該第一/第二實體主要金鑰及該產生器值。
Independent claims25
148 paragraphs, as filed
Used for blockchain-based systems combined with secure multi-party loss-proof storage and encryption key transfer in the wallet management system
Secure Multiparty loss resistant Storage and Transfer of Cryptographic Keys for blockchain based systems in conjunction with a wallet management system
The present invention generally relates to computer and data security, and more particularly, the present invention relates to the safe handling of highly sensitive data items such as encryption keys. The present invention provides an access control mechanism. The invention is particularly suitable for, but not limited to, electronic (software) wallets. This can include, for example, wallets used in relation to cryptocurrencies such as Bitcoin. The present invention provides an advantageous access control mechanism.
Cryptography involves the safe preservation of sensitive information and the technology of secure communication between two or more nodes in the network. A node can include a mobile communication device, a tablet computer, a notebook computer, a desktop computer, other forms of computing devices and communication devices, a server device in the network, a client device in the network, and distributed One or more nodes in a distributed network, etc. A node can be related to, for example, a natural person, a group of people such as employees of a company, a system such as a banking system, or a distributed point-to-point account (for example, a blockchain).
Two or more nodes can be connected via a communication network that is insecure and vulnerable to eavesdropping or interception by unauthorized third parties. Therefore, the information transmitted between nodes is often transmitted in an encrypted manner. When receiving, the intended recipient uses the corresponding decryption key or other decryption method to decrypt the information. Therefore, the security of such communication depends on preventing a third party from determining the corresponding decryption key.
One known encryption method involves the use of symmetric key algorithms. In the sense that the same symmetric key is used for both the encryption of ordinary text information and the decryption of cipher text information, these keys are symmetric. However, the symmetric key must be transmitted to the two nodes in a secure manner to prevent unauthorized access to the key. This can include, for example, essentially transmitting the symmetric key to the (authorized) node so that the symmetric key will never be transmitted through an insecure communication network. However, the delivery of substance is not always a practical choice. Therefore, a problem in this encryption system is to establish a symmetric key between two nodes (which can be based on a common secret) through an insecure electronic network such as the Internet. Therefore, the step of providing a symmetric key (such as shared secrets) is a potential catastrophic weakness. When the symmetric key and protocol are simple and widely used, the two nodes need to be able to safely determine a common privacy in an insecure network environment.
The use of asymmetric keys, also known as public key cryptography, alleviates this problem to a certain extent. When the private key is kept private, the corresponding public key can become publicly available. The interception of a private key on the Internet will not be a catastrophic event. Existing protocols include Diffie-Hellman key exchange and Three Pass Protocol.
However, the storage of private keys raises major security concerns. Consider a digital wallet, such as a Bitcoin wallet. Digital wallets contain software that allows users to connect with other nodes in order to use their electronic assets to perform transactions, such as using Bit Funds to purchase products and services. Public key cryptography is often used to protect critical information needed for connections and transactions. The private key is stored via a wallet installed on the user's device ("client") or via a wallet service provider ("server"). However, if the private key is only stored on the client, the private key may be lost through theft, loss, or damage to the user's hardware, such as a computer or mobile phone. Similarly, if the user dies or becomes incapacitated, the knowledge or access rights of the private key will be lost, and the funds related to the wallet will also become inaccessible. When server-side storage of private keys can overcome these problems, users must be prepared to trust service providers to keep their private keys private. A security breach on the server side is a real and significant risk.
Therefore, it is desirable to provide a solution that can handle privacy safely. The secret can be an encryption key and/or something that can provide access to the key. This improved solution has now been developed. According to the present invention, an improved solution as defined in the appended claims is provided.
The present invention can provide a computer-based method. This method can control the access of a resource. This method can be called a confirmation or authentication method. This method can also be called an encryption key management solution. Resources can be any form of physical or electronic resources. In one embodiment, the resource is a digital wallet or other resources related to a form of currency. The resource can be a Bitcoin wallet or a wallet used for the management of cryptocurrency resources. The present invention can provide a method for controlling the access right of a digital wallet (and corresponding system).
The present invention can be used during startup, during registration, or during the creation of a digital wallet via an insecure communication channel (such as the Internet) to allow subsequent wallet-related operations, such as processing, communication and/or creation The transaction can be completed in a safe manner.
One or more embodiments of the present invention may include the step of generating an encryption key from an existing encryption key pair. This step may include the following steps: determining a second private key of the first entity based on at least one primary private key of the first entity and a generator value; determining a second private key of the first entity based on at least one primary private key of the second entity and the generator value Determine the second private key of a second entity; determine the common secret (CS) on the first entity according to the second private key of the first entity and the second public key of the second entity, and according to the second entitys second public key The private key and the second public key of the first entity are used to determine the common secret (CS) on the second entity; and wherein: the second public key of the first entity and the second public key of the second entity are based on At least the primary key and generator value of the first/second entity.
Additionally or alternatively, the present invention includes a method of controlling access to a digital wallet, the method comprising the following steps: determining a first entity and a second entity based on at least one primary private key of a first entity and a generator value Private key; determining a second private key of a second entity based on at least one primary private key of the second entity and the generator value; determining a second private key of the second entity based on the second private key of the first entity and the second public key of the second entity Determine the common secret (CS) on the first entity, and determine the common secret (CS) on the second entity according to the second private key of the second entity and the second public key of the first entity; and where: The second public key of an entity and the second public key of the second entity are respectively based on at least the primary key of the first/second entity and the generator value.
Additionally or alternatively, the method may include the following steps: dividing a confirmation component into a plurality of shares; determining a common privacy on two or more nodes on a network; using the common privacy A node of the network transmits at least one share of the confirmation element to at least another node.
The confirmation element can be an encryption key. It can be a private key in an asymmetric encryption pair. Additionally or alternatively, the confirmation element can be represented as an encryption key, or some transactions that can be used to access, calculate, generate, or retrieve an encryption key. It can be some secrets or values that can be used in the confirmation program, for example, mnemonic or seed.
Therefore, one aspect of the present invention relates to dividing a secret, such as a private key, into (unique) multiple shares. The confirmation element can be divided into a plurality of shares, so that the confirmation element can be restored or regenerated from two or more shares. The Shamir secret sharing scheme can be used to split the confirmation element into multiple shares.
These shares can be divided so that any share itself has no value, which means that the share cannot be used to reach the (original undivided) confirmation element. The implementation of the split may result in the confirmation that the component can only be recovered when a predetermined number of shares are combined. In one embodiment, any two shares are sufficient to restore the confirmation element.
Another aspect of the invention relates to the safe handling or storage of individual shares. The share can be transmitted to different parties or stored by different parties. Some or all of the parties may be nodes on the network. In an embodiment, the method may include a step of storing at least three shares of the confirmation element in different positions relative to each other.
At least one share can be stored in a backup or "safe storage" device. This equipment can be separated from other locations where shares are stored, independent of each other, or distinct from each other. This method provides an important advantage, because it can restore the confirmation component when one of the other shares becomes unavailable. In this case, the shares can be retrieved from the secure storage device.
The confirmation procedure can be carried out before using the share to restore the confirmed component. The confirmation procedure may include confirming a predetermined or designated personal identity, and/or confirming a computing resource.
Another aspect of the invention may include a security distribution with respect to one or more shares. The method may include a step of generating an encryption key using a common secret, wherein the encryption key is used to encrypt at least one share of the confirmation element, or information containing the at least one share.
The mutual privacy can be determined on at least two nodes that are independent of each other. Therefore, each node can determine or generate its own privacy without having to input from or communicate with another node or other parties. This means that mutual privacy may not need to be transmitted on a communication channel. Because mutual privacy cannot be intercepted by unauthorized parties, this approach provides enhanced security. The common privacy is common to the at least two nodes (meaning, shared). The common secret can then be used to generate an encryption key, and the encryption key can be used to securely transmit shares. Other data can also be sent using encryption keys.
The method may include a step of determining a common secret (CS) in a first node (C), the common secret (CS) is common between the first node (C) and a second node (S), wherein the first node (C) Node (C) has a primary private key (V<sub>1C</sub>) And a primary public key of the first node (P<sub>1C</sub>) Is connected to a first asymmetric encryption pair, and the second node (S) is connected with a second node's primary private key (V<sub>1S</sub>) And a second node's main public key (P<sub>1S</sub>) Is associated with a second asymmetric encryption pair, wherein the method includes: according to at least the primary private key of the first node (V<sub>1C</sub>) And a generator value (GV) to determine a first node second private key (V<sub>2C</sub>); According to at least the primary public key of the second node (P<sub>1S</sub>) And the generator value (GV) to determine a second node's second public key (P<sub>2S</sub>); and according to the second private key of the first node (V<sub>2C</sub>) And the second public key of the second node (P<sub>2S</sub>) To determine the common secret (CS); where the second node (S) is based on a first node's second public key (P<sub>2C</sub>) And a second node second private key (V<sub>2S</sub>) Have the same common privacy, where: the second public key of the first node (P<sub>2C</sub>) Is based on the primary public key of the first node (P<sub>1C</sub>) And the generator value (GV); and the second private key of the second node (V<sub>2S</sub>) Is based on the main private key of the second node (V<sub>1S</sub>) And generator value (GV).
The generator value (GV) can be based on a message (M). The method may further include: according to the information (M) and the second private key of the first node (V<sub>2C</sub>) To generate a first signature message (SM1); and transmit the first signature message (SM1) to the second node (S) through the communication network, wherein the first signature message (SM1) uses the second public key of the first node (P<sub>2C</sub>) To confirm to authenticate the first node (C).
The method also includes: receiving a second signature message (SM2) from the second node (S) through the communication network; using the second node's second public key (P<sub>2S</sub>) To confirm the second signature information (SM2); and to authenticate the second node (S) according to the confirmation result of the second signature information (SM2), where the second signature information (SM2) is based on the information (M) or a second Information (M2), and the second private key of the second node (V<sub>2S</sub>) To produce.
The method further includes: generating a message (M); and transmitting the message (M) to the second node (S) through a communication network. Optionally, the method may include receiving information (M) from the second node (S) via a communication network. Alternatively, the method may include receiving information from another node via a communication network (M). Alternatively, the method may include receiving information (M) from a data storage and/or an input interface connected to the first node (C).
The primary public key of the first node (P<sub>1C</sub>), the main public key of the second node (P<sub>1S</sub>) Can be based on the primary private key of the first node (V<sub>1C</sub>) And the main private key of the second node (V<sub>1S</sub>) Are respectively multiplied by the elliptic curve points of a generator (G).
The method may further include the following steps: receiving the primary public key (P) of the second node through the communication network<sub>1S</sub>); and the main public key of the second node (P<sub>1S</sub>) Is stored on a data store connected to the first node (C).
The method may further include the following steps: Generate the primary private key (V) of the first node on the first node (C)<sub>1C</sub>) And the primary public key of the first node (P<sub>1C</sub>); Transmit the primary public key of the first node through the communication network (P<sub>1C</sub>) To the second node (S) and/or other nodes; and transfer the primary private key of the first node (V<sub>1C</sub>) Is stored on a first data storage connected to the first node (C).
The method may also include the following steps: send a notification to the second node through the communication network, the notification uses a common elliptic curve cryptography (ECC) system with a reference point (G) to determine the common privacy (CS) Method. Generate the primary private key of the first node (V<sub>1C</sub>) And the primary public key of the first node (P<sub>1C</sub>) May include: generating the primary private key of the first node (V<sub>1C</sub>), the random integer is within an allowable range specified by the common elliptic curve cryptography system; and according to the primary private key of the first node (V<sub>1C</sub>) And the reference point (G) of the elliptic curve point multiplication, according to the following formula to determine the main public key of the first node (P<sub>1C</sub>): P<sub>1C</sub>= V<sub>1C</sub>x G
The method may further include: determining the generator value (GV) depending on a hash of the information (M), wherein the second private key (V) of the first node is determined<sub>2C</sub>) Is based on the primary private key of the first node (V<sub>1C</sub>) And the scalar addition of the generator value (GV), calculated according to the following formula: V<sub>2C</sub>= V<sub>1C</sub>+ GV
Determine the second public key of the second node (P<sub>2S</sub>) Steps can be based on the second nodes main public key (P<sub>1S</sub>) Add the elliptic curve points, add the generator value (GV) and the reference point (G) to the elliptic curve point multiplication, and find out according to the following formula: P<sub>2S</sub>= P<sub>1S</sub>+ GV x G
The generator value (GV) can be determined by a hash of the previous generator value (GV).
The first asymmetric encryption pair and the second asymmetric encryption pair may be individually based on a function of the previous asymmetric encryption pair and the previous second asymmetric encryption pair.
Another alternative word is that the present invention can provide a method that includes the following steps: dividing a confirmation element into a plurality of shares; generating a result at a first node according to a first main asymmetric key pair (Or second) private encryption key; Use the obtained private key to encrypt and/or secure at least part of the transmission confirmation component.
The method can also include generating the same obtained private key on a second node, which can be generated independently of the first node and based on a second main asymmetric key pair.
The obtained private key can be a part of an asymmetric key pair composed of the private key and the public key. The first and/or second node can use elliptic curve cryptography (ECC) to generate a private key (and its corresponding public key).
The method may include the following steps: between the first and second nodes, reach an agreement on the standard ECC system using a reference point (G); on the first and/or second node, use the agreed standard ECC system To generate a public/private key pair and disclose the public key, which can mean making it publicly available; and/or register the primary public key of the first node (P<sub>MC</sub>); and/or register the primary public key of the second node (P<sub>MS</sub>); and/or send information (M) from the first node to the second node, and/or send information (M) from the second node to the first node, and generate a hash of the information; the information can use the money obtained Key to sign; this step can represent what is needed to: (1) establish a shared secret between nodes and (2) initiate a unique transmission of a secure communication between nodes. The first or second node can use the received information (M) to generate its own (secondary) public/private key pair. This allows the node to calculate the public key obtained by other nodes; and/or receive information and independently calculate a hash of the information M (for example, SHA-256(M)); and/or calculate a public key (P<sub>2C</sub>), which can be obtained from the main key (P<sub>MC</sub>) To obtain; and/or for the calculated P<sub>2C</sub>To confirm the signature (Sig-V<sub>2C</sub> )。
The obtained private key can be obtained decisively from the primary public key of the first or second node.
The present invention may also include a computer-completed system that is configured and configured to complete any embodiment of the above-mentioned method. The system can include or use a blockchain network or platform. Additionally or alternatively, it may include a digital wallet provider or management system.
Any feature of one aspect or embodiment of the present invention described above can be used in any other aspect of the present invention. For example, the features described in relation to the method can be applied to the system and vice versa.
These and other aspects of the present invention will be explained and become obvious and understandable with reference to the embodiments described herein.
An embodiment of the present invention will now be described with reference to the accompanying drawings, which are used as examples only, in which:
As explained above, there has always been a need to strengthen private storage and/or private exchange, or the need for privacy that can be used to generate keys. Privacy can be a seed of the wallet's mnemonic symbol, or other Security-related objects. The present invention provides such a solution. The following embodiment is used for explanation purposes, and is illustrated with the background of a digital wallet completed in a blockchain. However, the present invention is not limited to this way of completion, and can be implemented for any computer-based network or system.
As mentioned above, the use of public key cryptography is often related to digital wallets. If the end user (we can call it "client" or simply "user" here) is responsible for storing their private key, when the user or their hardware becomes unavailable, the problem may be This happened because it would make the private key, and thus the funds of the wallet, inaccessible. However, the storage of keys on the side of the wallet provider (we can call it the "server side") requires a certain degree of trust in the provider and their security mechanisms. Therefore, there is a need to store the private key as a private key that cannot be obtained by unauthorized parties, but can be copied when necessary. The term "user" can be a human user or a computer-completed resource.
A known cryptographic algorithm, known as the "Shamir Secret Sharing Scheme" (4S), teaches the division of privacy into unique parts or shares, which are then distributed to different parties. In the future, shares can be used to rebuild privacy. Each individual share has no value or is used alone until it is combined with one or more shares. The number of shares needed to rebuild privacy will vary according to the needs of the situation. In some cases, all shares are needed to rebuild privacy, but in other cases, only a sufficient number of shares are needed to rebuild privacy. This is called a threshold scheme, in which any value of k in the share is sufficient to rebuild the original privacy.
In this illustrative example, 4S is used to split a secret, such as a private key or mnemonic seed, into several parts. It can also be used to regenerate a key or mnemonic seed from a certain number of parts. The use of mnemonics is known to be in conjunction with digital wallets. A mnemonic symbol is a human-friendly code or a group of characters, which can be transformed into a binary seed for the generation of a wallet or data.
Here, the following nouns will be used: "Privacy" (S) is a secret (for example, several values), which needs to be shared securely among multiple parties. "Share" is a piece of privacy. The privacy is divided into segments, and each segment is called a share. It is calculated from the given privacy. In order to restore privacy, we must obtain a certain number of shares. "Threshold" (k) is the minimum share that we need to regenerate or restore privacy. Only when we have more than or equal to k shares can we regenerate privacy. "Large prime number" (p) is a random prime.
From a broad perspective, the illustrative embodiment includes the following methods. In this example, we use a "2-of-3" (meaning k=2) scheme: the user registers with a wallet provider to generate and set a new wallet connected to the user. In this example, the wallet is a Bitcoin wallet, which uses the blockchain; generates a public-private key pair and is associated with the users wallet; uses 4S to divide the private key into shares; one share of the private key It is sent to the user via a secure transmission; the other share of the private key is reserved by the service provider and stored on a server; the other share is sent via a secure transmission to a remote for safe storage. The term "distant" does not imply any special geographic distance or location. Instead, it is used here to mean that the shares are kept in one secure storage device or resource, in a sense independent of the wallet provider or user (preferably both). "Independent" may include substantial, logical, financial, political, and/or organizational independence. For example, we can outsource secure storage to a commercial entity that charges a fee to provide secure storage services; or it can be stored by the users lawyer, or some other selected (and trusted) party who accepts the storage share Responsibilities, and if there is a demand, shares will be provided upon request. The wallet provider can destroy any or all copies of the complete private key. This is because the copy is no longer needed. When a private key is needed for subsequent user authorization (for example, because the user now wants to conduct a transaction), the key will be reconstructed from the users share and the wallet providers share, where the users share when needed Will be provided to wallet suppliers.
One advantage of this approach is that even if the wallet providers security is flawed, unauthorized parties cannot gain access to the users private key. This is because the users private key is not stored in the wallet providers Anywhere in the system, and the wallet providers system itself does not include enough shares to allow the private key to be rebuilt. This advantage can also be applied to the situation when the security of the client is vulnerable.
Another advantage is that by storing shares to a safe storage location, the private key will be retrieved from the safe storage and reconstructed with the share of the wallet provider. Therefore, if the user dies or becomes incapacitated, or if the user's hardware (and therefore shares) is lost, damaged or stolen, the funds in the wallet can still be accessed. In this situation, the identity of the user can be confirmed. In some cases, the identity of a proven and trusted party, such as an executor or lawyer of a real estate, can be confirmed. This can be done through, for example, the production of evidence, such as a death certificate, a passport, a legal document, or other forms of identification. When the authorized identity is confirmed, the private share can be taken out of the secure storage. Therefore, safe storage is a backup device that can be used in special or predetermined situations.
Therefore, the present invention provides an enhanced system/data security and convenient combination of advantages. It provides a simple, effective and safe solution for access control.
It should be noted that in the above example, the private key is generated by the wallet service provider, and the individual part is transmitted to the user and the safe storage resource. However, in other embodiments, this may not be true. In addition, it is important to note that part of the transmission between the parties (which may be referred to as "nodes") must be performed in a secure manner. This is because any unauthorized interception of multiple shares may enable the interceptor to reestablish privacy (for example, via mnemonics or keys). This secure exchange problem can also be solved by the present invention, as described below.
For the sake of understanding, more detailed aspects of the present invention will now be described. It should be noted that the Shamir secret sharing scheme is a technology known in the technical field, and those familiar with the technology can understand, understand and use this technology. Therefore, the following are only provided for complete explanation.
<b>Divide privacy into shares</b>
Given a secret S, several participants n, a threshold number k, and some large prime numbers p, we establish a polynomial with a constant term S:<i>y =</i><i>ƒ</i><i>(x) of degree k</i><i>−</i><i>1 (modulo our prime p)</i>
Next, we select n unique random integers between 1 and p-1 (including 1, p-1), and evaluate the polynomials at these n points. Each of the N stakeholders is assigned an (x, y) pair. This can be achieved through the following steps:
1. Converting to an integer For the 4S algorithm, the privacy must be an integer. Therefore, if the private format is some other format (for example, string, hexadecimal, etc.), it must first be replaced with an integer. If the privacy is already an integer, this step can be ignored. For this example, let<i>S = 1234</i> 。
2. Decide on the number of shares (n) and thresholds (k)<i>k</i>This part is needed to regenerate privacy. So choose<i>S</i>and<i>k</i>So that when privacy is restored,<i>k</i>The parts are always available. For this example, let<i>n=6, k=3</i> 。
3. Create a polynomial:
We need to create a polynomial in the form:<i>y =</i><i>ƒ</i><i>(x) mod p</i>i. Determine the degree of constant term and polynomial<i>ƒ</i><i>(x) = a<sub>0</sub>+ a<sub>1</sub>x + a<sub>2</sub>x<sup>2</sup>+a<sub>3</sub>x<sup>3</sup> +</i><i>…</i><i>+a<sub>k-1</sub>x<sup>k-1</sup></i>Constant term<i>a<sub>0</sub>= S</i>Degree of polynomial =<i>k-1</i>So for<i>k=3</i>and<i>S=1234</i>, We need to create a frequency of 2 and<i>a<sub>0</sub> =1234</i>The polynomial.<i>ƒ</i><i>(x) = 1234 + a<sub>1</sub>x + a<sub>2</sub>x<sup>2</sup></i>ii. The coefficient of determination selects k-1 random numbers (using a random (or pseudo-random) number generator) such that:<i>0 < a<sub>n</sub>< S</i>Let<i>a<sub>1</sub> = 166</i><i>; A<sub>2</sub> =94</i>therefore,<i>ƒ</i><i>(x) = 1234 + 166x + 94 x<sup>2</sup></i>iii. Choose a random prime number such that:<i>p > max(S</i><i>, N)</i>Let<i>p = 1613</i>iv. The final polynomial is<i>y =</i><i>ƒ</i><i>(x) mod p</i><i>y = (1234 + 166x + 94 x<sup>2</sup>) mod 1613</i>
<b>Create share</b>
In order to divide the privacy into n shares, we need to use the following polynomial to establish n points (shares):<i>y = (1234 + 166x + 94 x<sup>2</sup>) mod 1613</i>For this example,<i>n = 6</i>, We will have six points. Note that we start with<i>x = 1</i>and<i>NOT x = 0</i>Start. for<i>x = 1 to 6</i>, The six points are listed as follows:<i>(1</i><i>、 1494)、 (2、329)、 (3、965)、 (4、176)、 (5、 1188)、 (6、775)</i>Among these n (6) points, any k (3) points can be used to regenerate the private key.
Rebuild privacy from a given number of shares i. Obtain a private integer In order to rebuild privacy, we need the following information:<i>n = 6</i><i>, K =3, p =1613,</i><i>k</i>Shares<i>: (X0, y0) = (1, 1494); (x1, y1) = (2, 329); (x2, y2) =</i><i>(3</i><i>、965)</i>Once we have the above information, we can use a technique such as Lagrangian interpolation, which is known in the art field and can be quickly understood by those who are familiar with the art. Using this technique, we can reconstruct the entire polynomial. The coefficient is calculated according to the following formula:<i>a</i><i>i (x)= [</i>Ʃ<i><sup>k</sup></i><i><sup>-</sup></i><i><sup>1</sup></i><i><sub>i</sub></i><i><sub>=0</sub></i><i>y</i><i><sub>i</sub></i><i>Π</i><i><sub>0</sub></i><i><sub><=j<=k-1</sub></i><i><sub>, J</sub></i><sub>≠</sub><i><sub>i</sub></i><i>(</i><i>xx</i><i><sub>j</sub></i><i>)</i><i>/</i><i>(x</i><i><sub>i</sub></i><i> X</i><i><sub>j</sub></i><i>)] mod p</i>However, due to<i>S = a</i><i><sub>0</sub></i>, We just need to find out<i>a<sub>0</sub>= a<sub>0</sub></i><i>(0)</i><img file="TW201733302A_D0001.tif" he="78" id="i0021" img-content="drawing" img-format="jpg" inline="no" orientation="portrait" wi="254" /><img file="TW201733302A_D0001.tif" he="78" id="i0021" img-content="drawing" img-format="jpg" inline="no" orientation="portrait" wi="254" /><i>a<sub>0</sub> =</i><i>mod p</i>in<i>x<sub>i</sub></i><i>–</i><i>x<sub>j</sub></i><i>≠</i><i>0</i>. Those who are familiar with the technology will know that in the above formula, the exponent 1 means to perform the multiplicative inverse. Most programming languages include built-in packages to perform mathematical operations, such as multiplication and inverse. ii. Convert an integer to the desired format. If you perform step 1 to convert a specific format to an integer, we follow the reverse operation to convert the integer back to the desired format.
<b>Secure transfer of shares</b>
As mentioned before, it is important to transfer the private share to individual recipients in a secure manner to prevent unauthorized parties from being able to re-establish privacy. In a preferred embodiment, secure transmission can be achieved in the manner described below.
A common secret (CS) is established between the two parties, and then the common secret (CS) is used to generate a secure encryption key to transmit one or more shares. This common privacy (CS) should not be confused with the privacy (S) mentioned above. The common secret (CS) is generated to enable the secret (S), such as the secure exchange of keys or their shares.
The two parties can be any two wallet service providers, users, safe storage resources, or some other legal parties. Hereafter, for convenience of explanation, they are referred to as a first node (C) and a second node (S). The purpose is to generate a common secret (CS), which is known by two nodes but does not allow the common secret to be transmitted via a communication channel, thereby eliminating the possibility of unauthorized discovery of the common secret. The private segmentation and secure storage technology, combined with the secure transmission technology described below, provides a key management solution.
The secure transmission technology of the present invention involves a common secret (CS) generated at each end of the transmission in an independent manner, so that when two nodes know the CS, the CS does not need to move through a potentially insecure communication channel. Once the CS is established at both ends, it can be used to generate a secure encryption key that both nodes can use for subsequent transmissions. In the process of wallet registration, this is particularly helpful for the transmission of the split private key from one party to the other.
Figure 1 shows a system 1 including a first node 3 that communicates with a second node 7 via a communication network 5. The first node 3 has a related first processing device 23, and the second node 7 has a related second processing device 27. The first and second nodes 3, 7 may include an electronic device, such as a computer, a phone, a tablet computer, a mobile communication device, a computer server, and so on. In an example, the first node 3 may be a client (user) device, and the second node 7 may be a server. The server may be a server of a digital wallet provider.
The first node 3 has a primary private key of the first node (V<sub>1C</sub>) And a primary public key of the first node (P<sub>1C</sub>) Is associated with a first asymmetric encryption pair. The second node (7) and the master private key (V<sub>1S</sub>) And a second node's main public key (P<sub>1S</sub>) Is associated with a second asymmetric encryption pair. In other words, the first and second nodes each hold a public-private key pair individually.
The respective first and second asymmetric encryption pairs of the first and second nodes 3, 7 can be generated during the registration process, such as the process of registering a wallet. The public key of each node can be publicly shared, for example, through the communication network 5.
In order to determine the common privacy (CS) on both the first node 3 and the second node 7, the nodes 3 and 7 implement the steps of the methods 300 and 400 separately without communicating their private keys through the communication network 5.
The method 300 implemented by the first node 3 includes step 330, which is based on at least the primary private key of the first node (V<sub>1C</sub>) And a generator value (GV) to determine a first node second private key (V<sub>2C</sub>). The generator value can be based on a piece of information (M) shared between the first and second nodes, where sharing between the first and second nodes can include sharing information through the communication network 5, as described in further detail below By. The method 300 also includes a step 370 for performing at least the second node's primary public key (P<sub>1S</sub>) And the generator value (GV) to determine a second node's second public key (P<sub>2S</sub>). The method 300 also includes a step 380 for performing a second private key (V<sub>2C</sub>) And the second public key of the second node (P<sub>2S</sub>) To determine common privacy (CS).
What is important is that the same common secret (CS) can also be determined by the method 400 on the second node 7. The method 400 includes step 430 to perform a method according to the primary public key of the first node (P<sub>1C</sub>) And the generator value (GV) to determine a first node second public key (P<sub>2C</sub>). The method 400 further includes step 470, which is based on the master private key of the second node (V<sub>1S</sub>) And the generator value (GV) to determine a second node's second private key (V<sub>2S</sub>). The method 400 includes a step 480, according to the second private key of the second node (V<sub>2S</sub>) And the second public key of the first node (P<sub>2C</sub>) To determine common privacy (CS).
The communication network 5 can be a local area network, a wide area network, a mobile phone network, a radio communication network, the Internet, and so on. The data in these networks can be transmitted via communication media such as wires, optical fibers, or wireless, and are vulnerable to eavesdropping, such as being eavesdropped by an eavesdropper 11. The methods 300 and 400 can allow both the first node 3 and the second node 7 to independently determine a common secret, without the need to transmit the common secret through the communication network 5.
One advantage of this is that the common secret (CS) can be determined securely and independently by each node, without the need to transmit a private key through a potentially insecure communication network 5. Conversely, the common secret can be used as a private key (or as the basis of a private key) and used for encrypted communication between the first and second nodes 3 and 7 through the communication network 5.
The methods 300, 400 may include additional steps. The method 300 may be included on the first node 3, according to the information (M) and the second private key (V) of the first node<sub>2C</sub>) To generate a signature message (SM1). The method 300 further includes a step 360 of transmitting the first signature information (SM1) to the second node 7 through the communication network 5. Conversely, the second node 7 can perform step 440 to receive the first signature information (SM1). The method 400 also includes step 450 to use the second public key (P<sub>2C</sub>) To confirm the first signature information (SM1), and step 460 to authenticate the first node 3 according to the confirmation result of the first signature information (SM1). Advantageously, this allows the second node 7 to authenticate the intended first node (where the first signature information is generated) as the first node 3. This is based on the fact that only the first node 3 has the primary private key of the first node (V<sub>1C</sub>) Depends on the assumption of access rights, and therefore only the first node 3 can determine the first node's second private key (V<sub>2C</sub>). It should be understood that, similarly, a second signature message (SM2) can be generated in the second node 7 and transmitted to the first node 3, so that the first node 3 can authenticate the second node 7, such as in a peer-to-peer situation. .
Between the first and second nodes, the sharing of information (M) can be achieved in various ways. In one example, the information can be generated on the first node 3 and then transmitted to the second node 7 through the communication network 5. In another example, the information can be generated on a third node 9 and the information is transmitted to the first and second nodes 3,7. In yet another alternative example, the user can input information via a user interface 15 to be received by the first and second nodes 3 and 7. In another example, the message (M) can be retrieved from a data store 19 and sent to the first and second nodes 3,7. In some examples, the information (M) may be public and therefore may be transmitted through an insecure network 5.
As a further example, one or more pieces of information (M) can be stored in a data store 13, 17, 19, where the information can be associated with some entities, such as digital wallets or established between the first node 3 and the second node 7. One of the communication dialogues is related. Therefore, the information (M) can be retrieved and used to individually recreate the common secret (CS) associated with the wallet or conversation on the first and second nodes 3, 7.
Advantageously, the records used to recreate the common privacy (CS) can be saved, without the need for the record itself to be privately stored or safely transmitted. If several transactions are executed on the first and second nodes 3, 7, this method is advantageous, and it is impractical to store all the information (M) on the node itself.
Registration method 100, 200
An example of the registration methods 100 and 200 will be described with reference to FIG. 3, in which the method 100 is executed by the first node 3, and the method 200 is executed by the second node 7. This involves establishing first and second asymmetric encryption pairs for the first and second nodes 3 and 7.
Asymmetric encryption pairs include related private and public keys, such as the keys used in public key encryption. In this example, the asymmetric encryption pair is generated using the characteristics of elliptic curve cryptography (ECC) and elliptic curve operations.
ECC standards include known standards, such as those described in Standards for Efficient Cryptography Group (www.sceg.org). Elliptic curve cryptography is also described in US patents US 5,600,725, US 5,761,305, US 5889,865, US 5,896,455, US 5,933,504, US 6,122,736, US 6,141,420, US 6,618,483, US 6,704,870, US 6,785,813, US 6,078,667, US 6,792,530.
In the methods 100 and 200, this includes steps 110 and 210, where the first and second nodes reach an agreement on a common ECC system and use a reference point (G). (Note that the reference point can be called a common generator, but the term "reference point" is used to avoid confusion with the generator value GV). In one example, the common ECC system can be based on secp256K1, which is an ECC system used by Bitcoin. The reference point (G) can be selected, randomly generated, or designated.
Attention is now turned to the first node 3, the method 100 includes step 110 to place on a common ECC system and a reference point (G). This includes receiving the common ECC system and reference point from the second node 7 or a third node 9. Optionally, a user interface 15 can be connected to the first node 3, whereby a user can selectively provide a common ECC system and/or reference point (G). Another option is that one or both of the common ECC system and/or the reference point (G) can be randomly selected by the first node 3. The first node 3 can send a notification representing the use of a common ECC system with a reference point (G) to the second node 7 through the communication network 5. Sequentially, in step 210, the second node 7 may be placed by sending a notification representing confirmation of the use of the common ECC system and the reference point (G).
The method 100 includes step 120. The first node 3 generates a master private key (V<sub>1C</sub>) And the primary public key of the first node (P<sub>1C</sub>) Is a first asymmetric encryption pair. This involves generating the primary private key of the first node (V<sub>1C</sub>), where the random integer is within an allowable range specified by the common ECC system. This also contains the main private key (V<sub>1C</sub>) And the reference point (G) of the elliptic curve point multiplication, according to the following formula to determine the main public key of the first node (P<sub>1C</sub>): P<sub>1C</sub>= V<sub>1C</sub>x G (Formula 1)
Therefore, the first asymmetric encryption pair contains: V<sub>1C</sub>: The primary private key P of the first node kept private by the first node<sub>1C</sub>: Become a publicly known master public key of the first node.
The first node 3 can transfer the first node's main private key (V<sub>1C</sub>) And the primary public key of the first node (P<sub>1C</sub>) Is stored in a first data storage 13 associated with the first node 3. For security, the primary private key of the first node (V<sub>1C</sub>) Can be stored in a secure part of the first data storage 13 to ensure that the key remains private.
The method further includes step 130 to transfer the primary public key of the first node (P<sub>1C</sub>) Is transmitted to the second node 7. In step 220, upon receiving the primary public key of the first node (P<sub>1C</sub>), the second node 7 can transfer the primary public key of the first node (P<sub>1C</sub>) Is stored in a second data storage 17 associated with the second node 7.
Similar to the first node 3, the method 200 includes step 240 to generate a master private key (V<sub>1S</sub>) And the main public key of the second node (P<sub>1S</sub>) Is a second asymmetric encryption pair. The main private key of the second node (V<sub>1S</sub>) Is also a random integer within the allowable range. Sequentially, the main public key of the second node (P<sub>1S</sub>) Is determined by the following formula: P<sub>1S</sub>= V<sub>1S</sub>x G (Formula 2)
Therefore, the second asymmetric encryption pair contains: V<sub>1S</sub>: The main private key of the second node kept private by the second node. P<sub>1S</sub>: Become a publicly known master public key of the second node.
The second node 7 can store the second asymmetric encryption pair in the second data storage 17. The method 200 further includes step 250 to transfer the primary public key (P<sub>1S</sub>) Is transmitted to the first node 3. Sequentially, in step 140, the first node 3 may receive the second node's primary public key (P<sub>1S</sub>), and in step 150, the first node 3 can store the second node's primary public key (P<sub>1S</sub> )。
It should be understood that in some alternatives, the individual public master key may be received and stored in a third data storage 19 associated with the third node 9 (eg, a trusted third party) . This may include a third party acting as a public directory, such as a digital certificate authority. Therefore, in some examples, only when the common secret (CS) needs to be determined, the primary public key of the first node (P<sub>1C</sub>) And the second node 7 receives the primary public key of the first node (P<sub>1C</sub>) (And vice versa).
The registration step may only need to happen once, as an initial setting for, for example, a digital wallet.
The conversation starts and the first node 3 decides the mutual privacy
An example of determining common privacy (CS) will now be explained with reference to FIG. 4. Common secret (CS) can be used for a special conversation, time, transaction or other purposes between the first node 3 and the second node 7, and using the same common secret (CS) is undesirable Or unsafe. Therefore, the common privacy (CS) is changeable between different conversations, times, transactions, and so on.
The following provides an explanation of the above-mentioned secure transmission technology.
<i>Step 310:</i><i>Generate a message (M)</i>
In this example, the method 300 executed by the first node 3 includes step 310 to generate a message (M). The information (M) can be random, pseudo-random, or user-defined. In one example, the message (M) is based on Unix time and an arbitrary value (nonce). For example, the available information (M) is: Message (M) = UnixTime + nonce (Formula 3)
In some examples, the information (M) is an arbitrary value. However, it should be understood that the information (M) can have an optional value (such as Unix time, etc.), which is useful in some applications.
The method 300 includes step 315 to transmit information (M) to the second node 7 through the communication network 5. When the message (M) does not contain the information in the private key, the message (M) can be transmitted through an insecure network.
<i>Step 320: Determine a generator value (GV)</i>
The method 300 further includes step 320 to determine a generator value (GV) based on the information (M). In this example, this includes an encrypted hash of the decision information. An example of an encryption hash algorithm includes SHA-256 to create a 256-bit generator value (GV). In other words: GV = SHA-256(M) (Formula 4)
It should be understood that other algorithms can be used. This includes other algorithms including algorithms in the Secure Hash Algorithm (SHA) family. Some special examples include examples in the SHA-3 subset, including SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, and SHAKE256. Other hash algorithms can include algorithms in the RIPEMD (RACE Integrity Primitives Evaluation Message Digest) family. A specific example may include RIPEMD-160. Other hash functions may include family members based on Zémor-Tillich hash functions and knapsack-based hash functions.
<i>Step 330: Determine a second private key of the first node</i>
The method 300 includes a step 330, which is based on the primary private key of the first node (V<sub>1C</sub>) And the generator value (GV) determine the second private key of the first node (V<sub>2C</sub>). This can be based on the primary private key of the first node (V<sub>1C</sub>) And the scalar method of the generator value (GV), calculated according to the following formula: V<sub>2C</sub>= V<sub>1C</sub>+ GV (Formula 5)
Therefore, the second private key of the first node (V<sub>2C</sub>) Is not a random value, but is obtained by a decisive method from the primary private key of the first node. The corresponding public key in the encryption pair means the second public key of the first node (P<sub>2C</sub>), has the following relationship: P<sub>2C</sub>= V<sub>2C</sub>x G (Equation 6)
Change the V of Equation 5<sub>2C</sub>Substituting formula 6 provides: P<sub>2C</sub>= (V<sub>1C</sub>+ GV) x G (Equation 7)
The operator'+' is called elliptic curve point addition. Note that the algebra of elliptic curve cryptography is distributed. Formula 7 can be expressed as: P<sub>2C</sub>= V<sub>1C</sub>x G + GV x G (Equation 8)
Finally, Equation 1 can be replaced with Equation 7 to provide: P<sub>2C</sub>= P<sub>1C</sub>+ GV x G (Equation 9.1) P<sub>2C</sub>= P<sub>1C</sub>+ SHA-256(M) x G (Formula 9.2)
Therefore, the corresponding second public key of the first node (P<sub>2C</sub>) Can be used by the primary public key of the first node (P<sub>1C</sub>) And information (M). The second node 7 can have such knowledge to independently determine the second public key of the first node (P<sub>2C</sub>), as will be described in further detail with reference to the method 400 below.
<i>Step 350:</i><i>Generate a first signature message (SM1) based on the information and the second private key of the first node</i>
The method 300 further includes a step 350, according to the information (M) and the determined second private key of the first node (V<sub>2C</sub>) To generate a first signature message (SM1). Generating a signature message includes applying a digital signature algorithm to digitally sign the message (M). In one example, this contains the second private key (V<sub>2C</sub>) To the information, the elliptic curve digital signature algorithm (ECDSA) is used to obtain the first signature information (SM1).
Examples of ECDSA include those based on the ECC system with secp256k1, secp256r1, secp384r1, se3cp521r1.
The first signature information (SM1) can use the corresponding first node second public key (P<sub>2C</sub>) To confirm. This confirmation of the first signature information (SM1) can be used by the second node 7 to authenticate the first node 3, which will be discussed in the description of the method 400 below.
<i>Step 370</i><i>’</i><i>:</i><i>Determine the second public key of a second node</i>
In step 370, the first node 3 may then determine a second node second public key (P<sub>2S</sub>). As discussed above, the second public key of the second node (P<sub>2S</sub>) Can be based on at least the second node's primary public key (P<sub>1S</sub>) And generator value (GV). In this example, since in step 370', the public key is determined by the elliptic curve point multiplication of the private key and the reference point (G), the second node second public key (P<sub>2S</sub>) Can be expressed in a manner similar to Equation 6 as: P<sub>2S</sub>= V<sub>2S</sub>x G (Equation 10.1) P<sub>2S</sub>= P<sub>1S</sub>+ GV x G (Equation 10.2)
The mathematical proof of formula 10.2, and the above used to obtain the second public key of the first node (P<sub>2C</sub>) Is the same as the formula 9.1. It should be understood that in step 370, the first node 3 can determine the second node's second public key independently of the second node 7.
<i>Step 380:</i><i>Decide on mutual privacy at the first node 3</i>
In step 380, the first node 3 can then determine the second private key (V<sub>2C</sub>) And the second public key (P<sub>2S</sub>) To determine the common privacy (CS). The first node 3 can determine the common privacy (CS) through the following formula: S = V<sub>2C</sub>x P<sub>2S</sub>(Formula 11)
Method 400 implemented at the second node 7
The corresponding method 400 performed at the second node 7 will now be explained. It should be understood that some of these steps are similar to the steps performed by the first node 3 discussed above.
The method 400 includes step 410 to receive information from the first node 3 via the communication network 5 (M). This contains the information (M) sent by the first node 3 in step 315. Then in step 420, the second node 7 determines a generator value (GV) according to the information (M). In step 420, the second node 7 determines the generator value (GV), which is similar to the above-mentioned step 320 performed by the first node. In this example, the second node 7 performs this decisive step 420 independently of the first node 3.
The next step includes step 430, according to the primary public key of the first node (P<sub>1C</sub>) And the generator value (GV) to determine a first node second public key (P<sub>2C</sub>). In this example, since the public key in step 430' is determined by the private key and the elliptic curve point multiplication of the reference point (G), the first node and the second public key (P<sub>2C</sub>) Can be expressed in a manner similar to Equation 9 as: P<sub>2C</sub>= V<sub>2C</sub>x G (Equation 12.1) P<sub>2C</sub>= P<sub>1C</sub>+ GV x G (Equation 12.2)
The mathematical proofs of formulas 12.1 and 12.2 are the same as those of formulas 10.1 and 10.2 discussed above.
<i>The second node 7 authenticates the first node 3</i>
The method 400 includes steps performed by the second node 7 to authenticate the so-called first node 3 as the first node 3. As previously discussed, this includes step 440 to receive the first signature information (SM1) from the first node 3. Then in step 450, the second node 7 can use the second public key of the first node (P<sub>2C</sub>) To confirm the signature in the first signature information (SM1).
The verification of the digital signature can be done according to the elliptic curve digital signature algorithm (ECDSA) discussed above. Whats important is that the second private key (V<sub>2C</sub>) The first signature message (SM1) signed together should only be able to use the second public key of the first node (P<sub>2C</sub>) To confirm correctly. This is because V<sub>2C</sub>Follow P<sub>2C</sub>Form an encrypted pair. Since these keys are related to the primary private key of the first node (V<sub>1C</sub>) And the primary public key of the first node (P<sub>1C</sub>), it is decisive. The confirmation of the first signature information (SM1) can be used as authentication to transmit the first signature information (SM1) during the registration process, which claims that the first node is the same as the first node 3. Base. Therefore, the second node 7 can further implement the authentication of the first node 3 (step 460) according to the confirmation result of the first signature information (step 450).
The above authentication method is suitable when one of the two nodes is a trusted node and only one node needs to be authenticated. For example, the first node 3 may be a client and the second node 7 may be a server trusted by the client, such as a wallet provider. Therefore, the server (the second node 7) may have to authenticate the client's qualifications in order to allow the client to access the server system. It may be unnecessary for the server to authenticate the server's qualifications to the client. However, in some situations, it is desirable to have two nodes authenticate each other, such as in a point-to-point scheme.
<i>The second node 7 decides to share privacy</i>
The method 400 may further include step 470. The second node 7 uses the second node's master private key (V<sub>1S</sub>) And the generator value (GV) to determine the second node's second private key (V<sub>2S</sub>). Similar to step 330 performed by the first node 3, the second node's second private key (V<sub>2S</sub>) Will be based on the second node's main private key (V<sub>1S</sub>) And the scalar addition of the generator value (GV), calculated according to the following formula: V<sub>2S</sub>= V<sub>1S</sub>+ GV (Equation 13.1) V<sub>2S</sub>= V<sub>1S</sub>+ SHA-256(M) (Formula 13.2)
Then, in step 480, the second node 7 according to the second node's second private key (V<sub>2S</sub>) And the second public key of the first node (P<sub>2C</sub>), in a manner independent of the first node 3, the common privacy (CS) is determined according to the following formula: S = V<sub>2S</sub>x P<sub>2C</sub>(Formula 14)
<i>Common Secret (CS) is determined by the first node 3 and the second node 7</i>
The common secret (CS) determined by the first node 3 is the same as the common secret (CS) determined on the second node 7. Equations 11 and 14 provide the same mathematical proof of common privacy (CS), which will now be explained.
Attention is shifted to the common privacy (CS) determined by the first node 3. Formula 10.1 can be replaced with Formula 11, as shown below: S = V<sub>2C</sub>x P<sub>2S</sub>(Equation 11) S = V<sub>2C</sub>x (V<sub>2S</sub>x G) S = (V<sub>2C</sub>x V<sub>2S</sub>) x G (Equation 15)
Attention is shifted to the common privacy (CS) determined by the second node 7. Formula 12.1 can be replaced with Formula 14, as follows: S = V<sub>2S</sub>x P<sub>2C</sub>(Equation 14) S = V<sub>2S</sub>x (V<sub>2C</sub>x G) S = (V<sub>2S</sub>x V<sub>2C</sub>) x G (Equation 16)
Since ECC algebra is commutative, formulas 15 and 16 are equal, so: S = (V<sub>2C</sub>x V<sub>2S</sub>) x G = (V<sub>2S</sub>x V<sub>2C</sub>) x G (Equation 17)
<i>Common Secret (CS) and Private Key</i>
Now the common secret (CS) can be used as a private key, or as the basis of a private key in a symmetric key algorithm used for secure communication between the first node 3 and the second node 7. Such a communication method can be used to convey a part of a private key, a representation or identifier of a private key, or a mnemonic symbol of a private key. Therefore, once the present invention has been used in, for example, a digital wallet or other controlled resource establishment process, communication between the parties can then be implemented.
Common privacy (CS) can be in the form of elliptic curve points (x<sub>S</sub>, Y<sub>S</sub>). This can be converted into a standard key format for publicly known operations using the standard agreed between nodes 3 and 7. For example, x<sub>S</sub>Can be a 256-bit integer, which can be used for AES<sub>256</sub>A key of the encryption algorithm. x<sub>S</sub>You can also use the RIPEMD160 algorithm to convert into a 160-bit integer for use in any application that requires such a lengthy key.
Common privacy (CS) can be determined according to needs. What is important is that the first node 3 does not need to store the common secret (CS), because this can be re-determined based on the information (M). In some examples, the used information (M) can be stored in data storage 13, 17, 19 (or other data storage), and does not require the same security level as required by the main private key. In some examples, the information (M) may be publicly available. However, depending on some applications, it is assumed that the common secret (CS) is the same as the primary private key of the first node (V<sub>1C</sub>) Generally, it is stored safely, and the common secret (CS) can be stored in the first data storage (X) associated with the first node.
It should be noted that the above-mentioned embodiments are to explain the present invention, not to limit the present invention, and those familiar with the art will be able to design many alternative embodiments without departing from the invention as defined in the appended claims. scope. In the request, any reference signs placed in parentheses should not be interpreted as limiting the request. The words "include" and "include" and similar words do not exclude the existence of elements or steps listed in the claim or the entire specification. In this specification, "include and "include"" mean "include or consist of...". The singular designation of an element does not exclude the plural designation of such elements, and vice versa. The present invention can be implemented by hardware including several unique components, and by a suitably programmed computer. Among the device request items that list several devices, several of these devices can be implemented by one piece of hardware and the same item of hardware. The mere fact that certain sizes are listed in different subsidiary claims does not mean that the combination of these sizes cannot be used to produce advantages.
<p>1System</p><p>3First node</p><p>23First processing device</p><p>13, 17, 19Data storage</p><p>27Second processing device</p><p>5Internet</p><p>7Second node</p><p>9Third node</p><p>11Eavesdropper</p><p>15User Interface</p><p>P<sub>1C</sub>The main public key of the first node</p><p>P<sub>1S</sub>The main public key of the second node</p><p>V<sub>1C</sub>The primary private key of the first node</p><p>V<sub>1S</sub>The main private key of the second node</p><p>MInformation</p>
Figure 1 is a schematic diagram of an exemplary system for determining a common privacy between a first node and a second node. According to the present invention, it can be used to securely transmit highly sensitive information, such as a share of a private key; Figure 2 is a flowchart of a computer-based method for determining a common privacy. According to the present invention, it can be used to securely transmit highly sensitive information, such as a share of a private key; Figure 3 is used to The flowchart of the computer-based method for registering the first and second nodes; Figure 4 is another flowchart of the computer-based method for determining a common privacy. According to the present invention, it can be used to securely Transmit highly sensitive information, such as a share of a private key; Figure 5 is a flowchart of a secure communication method between the first node and the second node completed by a computer.
<bio-deposit></bio-deposit>
<sequence-list-text></sequence-list-text>
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| TWI786208B | Cited by | Taiwan Province of China | Examiner |
| TWI821248B | Cited by | Taiwan Province of China | Examiner |
| CN108876359A | Cited by | China | Search report |
| TWI698763B | Cited by | Taiwan Province of China | Examiner |
| TWI729719B | Cited by | Taiwan Province of China | Examiner |
| TWI642005B | Cited by | Taiwan Province of China | Examiner |
646 members in 28 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 16031171 | United Kingdom | – | |
| 201603117 | United Kingdom | A | |
| 16050262 | United Kingdom | – | |
| 201605026 | United Kingdom | A | |
| 16193013 | United Kingdom | – | |
| 201619301 | United Kingdom | A |
Members646
| Document | Office | Kind | |
|---|---|---|---|
| GB201603112D0 | United Kingdom | D0 | |
| GB201603114D0 | United Kingdom | D0 | |
| GB201603117D0 | United Kingdom | D0 | |
| GB201603122D0 | United Kingdom | D0 | |
| GB201603123D0 | United Kingdom | D0 | |
| GB201603125D0 | United Kingdom | D0 | |
| GB201604225D0 | United Kingdom | D0 | |
| GB201604244D0 | United Kingdom | D0 | |
| GB201604493D0 | United Kingdom | D0 | |
| GB201604495D0 | United Kingdom | D0 | |
| GB201604497D0 | United Kingdom | D0 | |
| GB201604498D0 | United Kingdom | D0 | |
| GB201605026D0 | United Kingdom | D0 | |
| GB201607484D0 | United Kingdom | D0 | |
| CA3009731A1 | Canada | A1 | |
| CA3010116A1 | Canada | A1 | |
| CA3013173A1 | Canada | A1 | |
| CA3013180A1 | Canada | A1 | |
| CA3013182A1 | Canada | A1 | |
| CA3013185A1 | Canada | A1 | |
| CA3014726A1 | Canada | A1 | |
| CA3014727A1 | Canada | A1 | |
| CA3014737A1 | Canada | A1 | |
| CA3014748A1 | Canada | A1 | |
| CA3014752A1 | Canada | A1 | |
| CA3015569A1 | Canada | A1 | |
| CA3227439A1 | Canada | A1 | |
| WO2017145002A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145003A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145004A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145005A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145006A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145007A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145008A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145009A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145010A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145016A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145017A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145018A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145019A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145020A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145021A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145047A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145048A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2017145049A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201732666A | Taiwan Province of China | A | |
| TW201732700A | Taiwan Province of China | A | |
| TW201732705A | Taiwan Province of China | A | |
| TW201732706A | Taiwan Province of China | A | |
| TW201733302AThis record | Taiwan Province of China | A | |
| TW201733303A | Taiwan Province of China | A | |
| TW201733304A | Taiwan Province of China | A | |
| EP3257002A1 | European Patent Office (EPO) | A1 | |
| EP3257006A1 | European Patent Office (EPO) | A1 | |
| EP3257191A1 | European Patent Office (EPO) | A1 | |
| EP3259724A1 | European Patent Office (EPO) | A1 | |
| EP3259725A1 | European Patent Office (EPO) | A1 | |
| EP3268914A1 | European Patent Office (EPO) | A1 | |
| EP3257191B1 | European Patent Office (EPO) | B1 | |
| GB201806517D0 | United Kingdom | D0 | |
| GB201806520D0 | United Kingdom | D0 | |
| GB201806522D0 | United Kingdom | D0 | |
| GB201806524D0 | United Kingdom | D0 | |
| GB201806525D0 | United Kingdom | D0 | |
| GB201806526D0 | United Kingdom | D0 | |
| GB201806694D0 | United Kingdom | D0 | |
| GB201806698D0 | United Kingdom | D0 | |
| GB201806700D0 | United Kingdom | D0 | |
| GB201806701D0 | United Kingdom | D0 | |
| GB201806706D0 | United Kingdom | D0 | |
| GB201806719D0 | United Kingdom | D0 | |
| GB201806739D0 | United Kingdom | D0 | |
| GB201806740D0 | United Kingdom | D0 | |
| GB201806741D0 | United Kingdom | D0 | |
| GB201806742D0 | United Kingdom | D0 | |
| EP3268914B1 | European Patent Office (EPO) | B1 | |
| GB2558484A | United Kingdom | A | |
| AU2017223129A1 | Australia | A1 | |
| CN108292402A | China | A | |
| DK3257191T3 | Denmark | T3 | |
| SG11201805472RA | Singapore | A | |
| CN108352015A | China | A | |
| AU2017223133A1 | Australia | A1 | |
| CO2018008191A2 | Colombia | A2 | |
| EP3364598A1 | European Patent Office (EPO) | A1 | |
| AU2017222421A1 | Australia | A1 | |
| AU2017222471A1 | Australia | A1 | |
| AU2017223126A1 | Australia | A1 | |
| AU2017223127A1 | Australia | A1 | |
| AU2017223138A1 | Australia | A1 | |
| AU2017223158A1 | Australia | A1 | |
| ZA201805019A0 | South Africa | A0 | |
| AU2017222468A1 | Australia | A1 | |
| AU2017222469A1 | Australia | A1 | |
| AU2017222470A1 | Australia | A1 | |
| AU2017223136A1 | Australia | A1 | |
| SG10201805995VA | Singapore | A | |
| GB201811774D0 | United Kingdom | D0 | |
| GB2560274A | United Kingdom | A | |
| ES2680851T3 | Spain | T3 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- 201733302
- Application
- 106105706
Titles3
- English
- SECURE MULTIPARTY LOSS RESISTANT STORAGE AND TRANSFER OF CRYPTOGRAPHIC KEYS FOR BLOCKCHAIN BASED SYSTEMS IN CONJUNCTION WITH A WALLET MANAGEMENT SYSTEM
- Chinese
- 用於基於區塊鏈的系統結合錢包管理系統中的安全多方防遺失儲存及加密金鑰轉移
- English
- Used for blockchain-based systems combined with secure multi-party loss-proof storage and encryption key transfer in the wallet management system
Classification
- CPC, 20
- G06Q20/3678
- H04L9/085
- G06Q20/3829
- H04L2209/56
- H04L9/3066
- G06Q2220/00
- H04L9/0838
- H04L9/0861
- G06Q20/36
- G06Q20/38
- H04L9/08
- H04L9/0841
- H04L9/32
- H04L9/3242
- H04L9/3252
- H04L9/0894
- H04L9/0825
- H04L9/3247
- H04L63/0442
- G06Q20/389
- IPC, 3
- H04L9 14
- H04L9 28
- G06Q20 36