Methods and systems for blockchain-implemented event-lock encryption
A computer-implemented method includes encrypting a plaintext message to a cryptographic public key in accordance with an identity-based encryption scheme using at least a congress public key to generate an encrypted message, wherein the congress public key is associated with members of a congress, respective members of the congress having access to private key shares usable in a threshold decryption scheme in which at least a threshold of private key shares are sufficient to derive a decryption key through the combination of partial contributions to the decryption key on behalf of the congress, generating, using at least a cryptographic private key corresponding to the cryptographic public key, a digital signature over a first set of instructions to perform cryptographic operations upon an occurrence of an event; and broadcasting one or more transactions to a proof-of-work blockchain network, the one or more transactions comprising the encrypted message, the cryptographic public key.
1 . A method for updating private key share distribution, the method comprising:
in response to a change of a membership of a group of nodes comprising a congress:
detecting a redistribution request to redistribute key shares amongst a new group of nodes;
generating a new private key share for each of the nodes in the new group of nodes; and transferring digital assets from a public address associated with the previous group of nodes to a new public address associated with the new group of nodes and a new public key.
2 . The method of claim 1 , wherein the new private key shares are to be used in a threshold signature scheme in which at least a threshold of private key shares must be used to generate a valid signature for a transaction on behalf of the congress comprising the new group of nodes.
3 . The method of claim 1 , wherein generating the private key shares comprises generating a random polynomial of order t with a constant term
zero
f
n
+
1
0
(
x
)
;
calculating a point
f
n
+
1
0
(
n
+
1
)
and sewing unis as a private key share of a first node of the new group of nodes.
4 . The method of claim 3 , further comprising distributing points on this polynomial
f
n
+
1
0
(
i
)
to each of the congress members in the new group of nodes, i=1, . . . , n.
5 . The method of claim 4 , wherein each congress member (i=1, . . . , n) adds the received value to their existing private key share to obtain the new private key share.
6 . The method of claim 1 , wherein the redistribution request is detected when a prospective new member has transferred digital assets into a public group address.
7 . The method of claim 6 , wherein the redistribution request is detected when an existing member of the previous group of nodes requests withdrawal of a member deposit.
8 . The method of claim 7 , further comprising, in response to receiving the request, evaluating the request against determined criteria.
9 . The method of claim 8 , further comprising facilitating withdrawal of the member deposit, wherein the withdrawal is facilitated in accordance with a threshold signature scheme so that the withdrawal is only effected if at least a threshold number of congress members authorize the withdrawal.
10 . The method of claim 9 , further comprising performing the withdrawal after the member who desires to disenroll is suspended from activity for a period of time.
11 . The method of claim 1 , wherein when the redistribution request is detected, identifying members of the previous group comprising the congress using one or more attributes in at least some transactions of digital assets to a public group address.
12 . A computer readable storage medium comprising computer-executable instructions which, when executed, configure a processor to perform a method in response to a change of a membership of a group of nodes comprising a congress, the method comprising:
detecting a redistribution request to redistribute key shares amongst a new group of nodes;
generating a new private key share for each of the nodes in the new group of nodes; and transferring digital assets from a public address associated with the previous group of nodes to a new public address associated with the new group of nodes and a new public key.
13 . An electronic device comprising:
an interface device;
a processor coupled to the interface device;
a memory coupled to the processor, the memory having stored thereon computer executable instructions which, when executed, configure the processor to perform a method in response to a change of a membership of a group of nodes comprising a congress, the method comprising:
detecting a redistribution request to redistribute key shares amongst a new group of nodes;
generating a new private key share for each of the nodes in the new group of nodes; and
transferring digital assets from a public address associated with the previous group of nodes to a new public address associated with the new group of nodes and a new public key.
14 . The electronic device of claim 13 , wherein the processor includes a trusted execution environment and wherein the computer executable instructions are executed within the trusted execution environment.
15 . The electronic device of claim 13 , wherein the new private key shares are to be used in a threshold signature scheme in which at least a threshold of private key shares must be used to generate a valid signature for a transaction on behalf of the congress comprising the new group of nodes.
16 . The electronic device of claim 13 , wherein generating the private key shares comprises generating a random polynomial of order t with a constant term zero
f
n
+
1
0
(
x
)
;
calculating a point
f
n
+
1
0
(
n
+
1
)
and setting this as a private key share of a first node of the new group of nodes; and
distributing points on this polynomial
f
n
+
1
0
(
i
)
to each of the congress members in the new group of nodes, i=1, . . . , n.
17 . The electronic device of claim 16 , wherein each congress member (i=1, . . . , n) adds the received value to their existing private key share to obtain the new private key share.
18 . The electronic device of claim 13 , wherein the redistribution request is detected when a prospective new member has transferred digital assets into a public group address.
19 . The electronic device of claim 18 , wherein the redistribution request is detected when an existing member of the previous group of nodes requests withdrawal of a member deposit, in response to receiving the request, evaluating the request against determined criteria; and
facilitating withdrawal of the member deposit, wherein the withdrawal is facilitated in accordance with a threshold signature scheme so that the withdrawal is only effected if at least a threshold number of congress members authorize the withdrawal.
20 . The electronic device of claim 13 , wherein when the redistribution request is detected, identifying members of the previous group comprising the congress using one or more attributes in at least some transactions of digital assets to a public group address.