IP Library Granted Patent US 10,785,018
Granted Patent B2
US 10,785,018 · App. 16/390,253 · Granted Sep 22, 2020

Asymmetric key management in consortium blockchain networks

Inventors: Yixiang Zhang (Hangzhou, CN); Shubo Li (Hangzhou, CN)
Assignee: Alibaba Group Holding Limited
H04L9/0825G06F21/00G06F21/602H04L9/0637H04L9/14H04L9/30H04L9/3239H04L9/3268H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,785,018
App. No.
16/390,253
Granted
Sep 22, 2020
Kind
B2
Abstract

Implementations of the present specification provide for management of service keys for consortium blockchain networks within a blockchain-as-a-service (BaaS) platform. Implementations include actions of receiving a request for a service key from a participant in a consortium blockchain network provisioned within the BaaS platform, determining that the participant is authorized for the service key based on a service authorization table that records participant privileges within the consortium blockchain network, providing a key package including an encrypted private key of the service key, and a public key of the service key, and sending the key package to the participant, the participant decrypting the private key of the service key using a public key associated with the participant.

Claims (34)

1. A computer-implemented method for management of service keys for consortium blockchain networks within a blockchain-as-a-service (BaaS) platform, the method comprising:

receiving a request for a service key from a participant in a consortium blockchain network provisioned within the BaaS platform;

determining that the participant is authorized for the service key based on a service authorization table that records participant privileges within the consortium blockchain network;

providing a key package comprising an encrypted private key of the service key, and a public key of the service key; and

sending the key package to the participant, the participant decrypting the private key of the service key using a key associated with the participant.

2. The method of claim 1 , further comprising, prior to receiving the request for the service key from the participant, receiving an identity certificate from the participant.

3. The method of claim 2 , wherein the identity certificate is received as an encrypted identity certificate, and the BaaS platform decrypts the identity certificate using a public key of the participant.

4. The method of claim 1 , further comprising encrypting the private key of the service key using a public key associated with the participant.

5. The method of claim 1 , wherein the service key is generated using a key derivation function (KDF) key tree in response to determining that the participant is authorized for the service key.

6. The method of claim 1 , wherein the service key is absent from the BaaS platform after sending the key package to the participant.

7. The method of claim 1 , wherein the participant uses the private key of the service key to encrypt transactions with one or more other participants within the consortium blockchain network.

8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations for management of service keys for consortium blockchain networks within a blockchain-as-a-service (BaaS) platform, the operations comprising:

receiving a request for a service key from a participant in a consortium blockchain network provisioned within the BaaS platform;

determining that the participant is authorized for the service key based on a service authorization table that records participant privileges within the consortium blockchain network;

providing a key package comprising an encrypted private key of the service key, and a public key of the service key; and

sending the key package to the participant, the participant decrypting the private key of the service key using a key associated with the participant.

9. The non-transitory, computer-readable storage medium of claim 8 , wherein operations further comprise, prior to receiving the request for the service key from the participant, receiving an identity certificate from the participant.

10. The non-transitory, computer-readable storage medium of claim 9 , wherein the identity certificate is received as an encrypted identity certificate, and the BaaS platform decrypts the identity certificate using a public key of the participant.

11. The non-transitory, computer-readable storage medium of claim 8 , wherein operations further comprise encrypting the private key of the service key using a public key associated with the participant.

12. The non-transitory, computer-readable storage medium of claim 8 , wherein the service key is generated using a key derivation function (KDF) key tree in response to determining that the participant is authorized for the service key.

13. The non-transitory, computer-readable storage medium of claim 8 , wherein the service key is absent from the BaaS platform after sending the key package to the participant.

14. The non-transitory, computer-readable storage medium of claim 8 , wherein the participant uses the private key of the service key to encrypt transactions with one or more other participants within the consortium blockchain network.

15. A system for management of service keys for consortium blockchain networks within a blockchain-as-a-service (BaaS) platform, comprising:

one or more computers; and

one or more computer-readable memories coupled to the one or more computers and having instructions stored thereon which are executable by the one or more computers to:

receive a request for a service key from a participant in a consortium blockchain network provisioned within the BaaS platform;

determine that the participant is authorized for the service key based on a service authorization table that records participant privileges within the consortium blockchain network;

provide a key package comprising an encrypted private key of the service key, and a public key of the service key; and

send the key package to the participant, the participant decrypting the private key of the service key using a key associated with the participant.

16. The system of claim 15 , wherein the one or more computer-readable memories are configured with further instructions executable by the one or more computers to, prior to receiving the request for the service key from the participant, receive an identity certificate from the participant.

17. The system of claim 16 , wherein the identity certificate is received as an encrypted identity certificate, and the BaaS platform decrypts the identity certificate using a public key of the participant.

18. The system of claim 15 , wherein the one or more computer-readable memories are configured with further instructions executable by the one or more computers to encrypt the private key of the service key using a public key associated with the participant.

19. The system of claim 15 , wherein the service key is generated using a key derivation function (KDF) key tree in response to determining that the participant is authorized for the service key.

20. The system of claim 15 , wherein the service key is absent from the BaaS platform after sending the key package to the participant.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053754/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053743/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2019
From: ZHANG, YIXIANG; LI, SHUBO
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 049997/0767 →
Continuity (2)
Continuation PCTCN2018117576 · Nov 27, 2018
Related Publication 20190253245A1 · Aug 15, 2019