Identity-based public-key generation protocol
A computer-implemented method for generating an identity-based cryptographic key, the method comprising: obtaining a set of private key shares and a set of corresponding public key shares, wherein each private key share is generated based on the personal identifier, and wherein at least one of the set of private key shares is generated by a respective one of a set of key-generating parties; generating an identity-based private key based on each of the one or more private key shares; and generating a partial identity-based public key, wherein the partial identity-based public key is generated based on each of the set of corresponding public key shares; transmitting the partial identity-based public key to at least one of the set of key-generating parties for generating the identity-based public key; and/or generating the identity-based public key, wherein the identity-based public key comprises the personal identifier and the partial identity-based public key.
1 . A computer-implemented method for generating an identity-based cryptographic key, the method being performed by a first party having a personal identifier, and comprising:
obtaining a set of private key shares and a set of corresponding public key shares, wherein each private key share is generated based on the personal identifier of the first party, and wherein at least one of the set of private key shares is generated by a respective one of a set of key-generating parties;
generating an identity-based private key based on each of the set of each of the one or more private key shares; and
generating a partial identity-based public key based on each of the set of corresponding public key shares, wherein the partial identity-based public key does not correspond to the identity-based private key; and
wherein the method also comprises;
transmitting the partial identity-based public key to at least one of the set of key-generating parties for generating the a complete identity-based public key, wherein the complete identity-based public key comprises the personal identifier and the partial identity-based public key; and/or
generating the complete identity-based public key based on the personal identifier and the partial identity-based public key, wherein the complete identity-based public key corresponds to the identity-based private key; and
wherein the method further comprises:
i) encrypting a first message using the complete identity-based public key to generate a first encrypted message; and
transmitting the first encrypted message to a second party, and/or generating a second blockchain transaction comprising an output that comprises the encrypted message; or
ii) obtaining a second encrypted message encrypted using the complete identity-based public key; and decrypting the second encrypted message using the private key to reveal a second message.
2 . The method of claim 1 , wherein a first output of a first blockchain transaction comprises the complete identity-based public key, the complete identity-based public key comprising the personal identifier and the partial identity-based public key, and wherein the method comprises obtaining the complete identity-based public key from the first blockchain transaction.
3 . The method of claim 2 , wherein said obtaining of the complete identity-based public key from the first blockchain transaction comprises:
obtaining a transaction identifier of the first blockchain transaction from at least one of the one or more key-generating parties; and
using the transaction identifier to obtain the first blockchain transaction from a blockchain in which the first blockchain transaction is recorded.
4 . The method of claim 1 , comprising:
obtaining the complete identity-based public key from at least one of the set of key-generating parties.
5 . The method of claim 1 , comprising, transmitting the personal identifier to at least one of the one or more key-generating parties.
6 . The method of claim 5 , wherein said transmitting of the personal identifier comprises:
generating a third blockchain transaction comprising an output that comprises the personal identifier; and
transmitting the third blockchain transaction to one or more nodes of the blockchain network for inclusion in the blockchain.
7 . The method of claim 2 , wherein the first party has a first public key, wherein the first blockchain transaction comprises a second output locked to the first public key of the first party, and wherein the method comprises:
generating a fourth blockchain transaction comprising an input that a) references the second output of the first blockchain transaction, and b) comprises a signature generated based on a private key corresponding to the first public key of the first party; and
transmitting the fourth blockchain transaction to one or more nodes of the blockchain network for inclusion in the blockchain.
8 . The method of claim 1 , wherein said transmitting of the partial identity-based public key to the at least one of the set of key-generating parties comprises:
generating a fifth blockchain transaction comprising an output that comprises the partial identity-based public key; and
transmitting the fifth blockchain transaction to one or more nodes of the blockchain network for inclusion in the blockchain.
9 . The method of claim 1 , wherein the identifier of the first party comprises one or more of: a name and/or address of the first party, an email address of the first party, a phone number, a passport number, a driving license number, a social media profile, a birth date, and a group member identifier.
10 . A computer-implemented method for generating an identity-based cryptographic key, wherein a first party has a personal identifier, and wherein the method is performed by a first key-generating party and comprises:
transmitting a private key share to the first party, wherein the private key share is generated based on the personal identifier of the first party and has a corresponding public key share;
obtaining a partial identity-based public key, based on the corresponding public key share, wherein the partial identity-based public key does not correspond to the identity-based private key;
generating and/or obtaining the complete identity-based public key, wherein the complete identity-based public key is generated based on the partial identity-based public key and the personal identifier, and wherein the complete identity-based public key corresponds to the identity-based private key; and
generating a first blockchain transaction comprising a first output that comprises the complete identity-based public key.
11 . The method of claim 10 , comprising, transmitting the first blockchain transaction to one or more nodes of a blockchain network for inclusion in a blockchain.
12 . The method of claim 10 , comprising, transmitting the first blockchain transaction to the first party.
13 . The method of claim 11 , comprising, obtaining the personal identifier from the first party.
14 . The method of claim 10 , wherein the first key-generating party has a first public key, and wherein the first blockchain transaction comprises a second output locked to the first public key of the first key-generating party.
15 . The method of claim 14 , comprising:
generating a fourth blockchain transaction comprising an input that a) references the second output of the first blockchain transaction, and b) comprises a signature generated based on a private key corresponding to the public key of the first key-generating party; and
transmitting the fourth blockchain transaction to one or more nodes of the blockchain network for inclusion in the blockchain.
16 . The method of claim 10 , wherein the first party has a first public key, and wherein the first blockchain transaction comprises a second output locked to the first public key of the first party.
17 . Computer equipment comprising:
memory comprising one or more memory units; and
processing apparatus comprising one or more processing units, wherein the memory stores code arranged to run on the processing apparatus, the code being configured so as when on the processing apparatus to perform a method of generating an identity-based cryptographic key, the method being performed by a first party having a personal identifier, and comprising:
obtaining a set of private key shares and a set of corresponding public key shares, wherein each private key share is generated based on the personal identifier of the first party, and wherein at least one of the set of private key shares is generated by a respective one of a set of key-generating parties;
generating an identity-based private key based on each of the one or more private key shares; and
generating a partial identity-based public key based on each of the set of corresponding public key shares, wherein the partial identity-based public key does not correspond to the identity-based private key; and
wherein the method also comprises;
transmitting the partial identity-based public key to at least one of the set of key-generating parties for generating the a complete identity-based public key, wherein the complete identity-based public key comprises the personal identifier and the partial identity-based public key; and/or
generating the complete identity-based public key based on the personal identifier and the partial identity-based public key, wherein the complete identity-based public key corresponds to the identity-based private key; and
wherein the method further comprises:
i) encrypting a first message using the complete identity-based public key to generate a first encrypted message; and
transmitting the first encrypted message to a second party, and/or generating a second blockchain transaction comprising an output that comprises the encrypted message; or
ii) obtaining a second encrypted message encrypted using the complete identity-based public key; and decrypting the second encrypted message using the private key to reveal a second message.
18 . A computer program embodied on computer-readable storage and configured so as, when run on computer equipment, to perform a method of generating an identity-based cryptographic key, the method being performed by a first party having a personal identifier, and comprising:
obtaining a set of private key shares and a set of corresponding public key shares, wherein each private key share is generated based on the personal identifier of the first party, and wherein at least one of the set of private key shares is generated by a respective one of a set of key-generating parties;
generating an identity-based private key based on each of the one or more private key shares; and
generating a partial identity-based public key based on each of the set of corresponding public key shares, wherein the partial identity-based public key does not correspond to the identity-based private key; and
wherein the method also comprises;
transmitting the partial identity-based public key to at least one of the set of key-generating parties for generating the a complete identity-based public key, wherein the complete identity-based public key comprises the personal identifier and the partial identity-based public key; and/or
generating the complete identity-based public key based on the personal identifier and the partial identity-based public key, wherein the complete identity-based public key corresponds to the identity-based private key; and
wherein the method further comprises:
i) encrypting a first message using the complete identity-based public key to generate a first encrypted message; and
transmitting the first encrypted message to a second party, and/or generating a second blockchain transaction comprising an output that comprises the encrypted message; or
ii) obtaining a second encrypted message encrypted using the complete identity-based public key; and decrypting the second encrypted message using the private key to reveal a second message.