首页> 外国专利> Secure manifold loss prevention of cryptographic keys for block-chain-based systems associated with wallet management systems Storage and transmission

Secure manifold loss prevention of cryptographic keys for block-chain-based systems associated with wallet management systems Storage and transmission

机译:安全地防止与钱包管理系统相关的基于区块链的系统的加密密钥丢失

摘要

The present invention provides a computer-implemented solution for controlling access to computer-related resources such as, for example, digital wallets. In one or more embodiments, the wallet may be implemented using a block chain, such as a bit coin block chain, but the invention is not so limited. Using the present invention during initial set-up of a wallet, subsequent tasks such as wallet transactions can be handled in a secure manner on unsecured channels such as the Internet. A method according to an embodiment of the present invention includes dividing a verification element (such as a private key of an asymmetric cipher pair) into a plurality of shares; Determining a common secret at two or more nodes in the network; And transmitting at least one share of the verification element between the two or more nodes using the common secret. SHARE can itself be split so that it is not enough to derive the verification factor. That is, no one can enforce key security because one party does not store the entire private key. To restore a key, you need two or more shares. Shares are stored in a separate location, one of which is an independent backup or secure storage location. If one of the other shares becomes unavailable, you can still retrieve the key from the backup and continue to access that key (and thus the controlled resource). To ensure secure transmission of the share (s), the common secret is generated independently of each other at two different nodes and then used to generate the encryption key. The encryption key may be used to encrypt at least one share of the verification element or a message containing it to ensure that the share is securely transmitted.
机译:本发明提供了一种计算机实现的解决方案,用于控制对诸如数字钱包之类的计算机相关资源的访问。在一个或多个实施例中,可以使用诸如小硬币区块链的区块链来实现钱包,但是本发明不限于此。在钱包的初始设置期间使用本发明,可以在诸如互联网的不安全通道上以安全的方式处理诸如钱包交易之类的后续任务。根据本发明的实施例的方法包括:将验证元素(诸如非对称密码对的私钥)划分为多个份额;确定网络中两个或两个以上节点的公共机密;并且使用公共秘密在两个或多个节点之间传输验证元素的至少一个份额。 SHARE本身可以拆分,因此不足以得出验证因子。也就是说,没有人可以强制执行密钥安全性,因为一方不能存储整个私钥。要还原密钥,您需要两个或多个共享。共享存储在单独的位置,其中之一是独立的备份或安全存储位置。如果其他共享之一不可用,您仍然可以从备份中检索密钥,然后继续访问该密钥(以及受控资源)。为了确保共享的安全传输,将在两个不同的节点上彼此独立地生成公用密钥,然后将其用于生成加密密钥。加密密钥可以用于对验证元素的至少一个共享或包含该共享的消息进行加密,以确保安全地传输该共享。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号