1.空天信息安全与可信计算教育部重点实验室 武汉大学 国家网络安全学院,湖北 武汉 430072
2.武汉天喻信息产业股份有限公司,湖北 武汉 430223
肖 健,男,硕士生,现从事密码学、区块链方向的研究。E-mail:1339675740@qq.com
E-mail: yangm@whu.edu.cn
收稿:2021-11-08,
纸质出版:2023-02-24
移动端阅览
肖健,杨敏,孟庆树.多答案保护秘密共享协议[J].武汉大学学报(理学版),2023,69(1):51-59. DOI:10.14188/j.1671-8836.2021.0308.
XIAO Jian,YANG Min,MENG Qingshu.Multi-Answer Protected Secret Sharing Protocol [J].J Wuhan Univ (Nat Sci Ed),2023,69(1):51-59. DOI:10.14188/j.1671-8836.2021.0308(Ch).
针对目前基于口令解决区块链私钥丢失问题的方案中面临的口令遗忘和泄露的问题,提出一种基于密保问题的多答案保护秘密共享方案(multi-answer protected secret sharing,MAPSS)。该方案允许用户将一个秘密共享给多个服务器,并令所有服务器存储多个密保问题,之后用户仅需向部分(阈值)服务器提供部分(阈值)密保问题的答案就能重构该秘密。该方案不仅可以用于区块链私钥找回,还支持抗遗忘和泄露的找回策略;该方案无需公钥基础设施且高效。在随机预言机模型下证明了该方案的安全性基于Threshold Parallel One-More Diffie-Hellman (TP-OMDH)假设,实现了该方案的系统原型,验证了该方案的实用性。
Aiming at solving the problem of password forgetting and leakage in the current password-based solution to the problem of blockchain private key loss
this paper proposed a Multi-Answer Protected Secret Sharing Scheme (MAPSS) based on secret problems. This scheme allows users to share a secret with multiple servers
and all servers store multiple secret questions. The scheme can not only be used to recover the private key of the blockchain
but also support the retrieval strategy against forgetting and leakage
and the scheme does not require public key infrastructure and is efficient. After that
the user only needs to provide a threshold number of answers to a threshold number of servers to reconstruct the secret. Finally
this paper not only proved that the security of the scheme is based on the Threshold Parallel One-More Diffie-Hellman (TP-OMDH) assumption under the random oracle model
but also implemented the system prototype of the scheme
which proved the practicality of the scheme.
韩璇 , 袁勇 , 王飞跃 . 区块链安全问题:研究现状与展望 [J]. 自动化学报 , 2019 , 45 ( 1 ): 206 - 225 . DOI: 10.16383/j.aas.c180710 http://dx.doi.org/10.16383/j.aas.c180710 .
HAN X , YUAN Y , WANG F Y . Security problems on blockchain: The state of the art and future trends [J]. Acta Automatica Sinica , 2019 , 45 ( 1 ): 206 - 225 . DOI: 10.16383/j.aas.c180710(Ch http://dx.doi.org/10.16383/j.aas.c180710(Ch ).
GENNARO R , GOLDFEDER S , NARAYANAN A . Threshold-optimal DSA/ECDSA signatures and an application to bitcoin wallet security [J]. International Conference on Applied Cryptography and Network Security , 2016 , 9696 : 156 - 174 . DOI: 10.1007/978-3-319-39555-5_9 http://dx.doi.org/10.1007/978-3-319-39555-5_9
BREUER F , GOYAL V , MALAVOLTA G . Cryptocurrencies with security policies and two-factor authentication [EB/OL]. [ 2021-03-29 ]. https://eprint.iacr.org/2021/416 https://eprint.iacr.org/2021/416 . DOI: 10.1109/eurosp51992.2021.00020 http://dx.doi.org/10.1109/eurosp51992.2021.00020 .
BAGHERZANDI A , JARECKI S , SAXENA N , et al . Password-protected secret sharing [C]// Proceedings of the 18th ACM Conference on Computer and Communications Security . New York : ACM , 2011 : 433 - 444 . DOI: 10.1145/2046707.2046758 http://dx.doi.org/10.1145/2046707.2046758 .
CAMENISCH J , LEHMANN A , LYSYANSKAYA A , et al . Memento: How to reconstruct your secrets from a single password in a hostile environment [C]// Advances in Cryptology—CRYPTO 2014 . Heidelberg : Springer , 2014 : 256 - 275 . DOI: 10.1007/978-3-662-44381-1_15 http://dx.doi.org/10.1007/978-3-662-44381-1_15 .
YI X , HAO F , CHEN L Q , et al . Practical threshold password-authenticated secret sharing protocol [C]// Computer Security — ESORICS 2015 . Cham : Springer International Publishing , 2015 , 9326 : 347 - 365 . DOI: 10.1007/978-3-319-24174-6_18 http://dx.doi.org/10.1007/978-3-319-24174-6_18
YI X , TARI Z , HAO F , et al . Efficient threshold password-authenticated secret sharing protocols for cloud computing [J]. Journal of Parallel and Distributed Computing , 2019 , 128 : 57 - 70 . DOI: 10.1016/j.jpdc.2019.01.013 http://dx.doi.org/10.1016/j.jpdc.2019.01.013 .
JARECKI S , KIAYIAS A , KRAWCZYK H . Round-optimal password-protected secret sharing and T-PAKE in the password-only model [C]// Advances in Cryptology — ASIACRYPT 2014 . Heidelberg : Springer , 2014 : 233 - 253 . DOI: 10.1007/978-3-662-45608-8_13 http://dx.doi.org/10.1007/978-3-662-45608-8_13 .
JARECKI S , KIAYIAS A , KRAWCZYK H , et al . Highly-efficient and composable password-protected secret sharing (or: How to protect your bitcoin wallet online) [C]// 2016 IEEE European Symposium on Security & Privacy . New York : IEEE , 2016 : 276 - 291 . DOI: 10.1109/EuroSP.2016.30 http://dx.doi.org/10.1109/EuroSP.2016.30 .
JARECKI S , KIAYIAS A , KRAWCZYK H , et al . TOPPSS: Cost-minimal password-protected secret sharing based on threshold OPRF [J]. International Conference on Applied Cryptography and Network Security , 2017 , 10355 : 39 - 58 . DOI: 10.1007/978-3-319-61204-1_3 http://dx.doi.org/10.1007/978-3-319-61204-1_3 .
MACKENZIE P , SHRIMPTON T , JAKOBSSON M . Threshold password-authenticated key exchange [C]// Advances in Cryptology — CRYPTO 2002 . Heidelberg : Springer , 2002 : 385 - 400 . DOI: 10.1007/3-540-45708-9_25 http://dx.doi.org/10.1007/3-540-45708-9_25 .
DUPONT P A , HESSE J , POINTCHEVAL D , et al . Fuzzy password-authenticated key exchange [C]// Advances in Cryptology — EUROCRYPT 2018 . Cham : Springer International Publishing , 2018 : 393 - 424 . DOI: 10.1007/978-3-319-78372-7_13 http://dx.doi.org/10.1007/978-3-319-78372-7_13 .
ERWIG A , HESSE J , ORLT M , et al . Fuzzy asymmetric password-authenticated key exchange [C]// Advances in Cryptology — ASIACRYPT 2020 . Cham : Springer International Publishing , 2020 : 761 - 784 . DOI: 10.1007/978-3-030-64834-3_26 http://dx.doi.org/10.1007/978-3-030-64834-3_26 .
BONNEAU J , BURSZTEIN E , CARON I , et al . Secrets, lies, and account recovery: Lessons from the use of personal knowledge questions at Google [C]// Proceedings of the 24th International Conference on World Wide Web . New York : ACM , 2015 : 141 - 150 . DOI: 10.1145/2736277.2741691 http://dx.doi.org/10.1145/2736277.2741691 .
SCHECHTER S , BRUSH A , EGELMAN S . It’s no secret: Measuring the security and reliability of authentication via “secret” questions [C]// Proceedings of the 30th IEEE Symposium on Security and Privacy . New York : IEEE , 2009 : 375 - 390 . DOI: 10.1109/SP.2009.11 http://dx.doi.org/10.1109/SP.2009.11 .
POND R , PODD J , BUNNELL J , et al . Word association computer passwords: The effect of formulation techniques on recall and guessing rates [J]. Computers & Security , 2000 , 19 ( 7 ): 645 - 656 . DOI: 10.1016/S0167-4048(00)07023-1 http://dx.doi.org/10.1016/S0167-4048(00)07023-1 .
SHAMIR A . How to share a secret [J]. Communications of the ACM , 1979 , 22 ( 11 ): 612 - 613 . DOI: 10.1145/359168.359176 http://dx.doi.org/10.1145/359168.359176 .
0
浏览量
1205
下载量
2
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621