1.Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
2.Wuhan Tianyu Information Industry Co. ,Ltd,Wuhan 430223,Hubei,China
Aiming at solving the problem of password forgetting and leakage in the current password-based solution to the problem of blockchain private key loss, this paper proposed a Multi-Answer Protected Secret Sharing Scheme (MAPSS) based on secret problems. This scheme allows users to share a secret with multiple servers, and all servers store multiple secret questions. The scheme can not only be used to recover the private key of the blockchain, but also support the retrieval strategy against forgetting and leakage, and the scheme does not require public key infrastructure and is efficient. After that, the user only needs to provide a threshold number of answers to a threshold number of servers to reconstruct the secret. Finally, this paper not only proved that the security of the scheme is based on the Threshold Parallel One-More Diffie-Hellman (TP-OMDH) assumption under the random oracle model, but also implemented the system prototype of the scheme, which proved the practicality of the scheme.
HANX, YUANY, WANGF Y. Security problems on blockchain: The state of the art and future trends [J]. Acta Automatica Sinica, 2019, 45(1): 206-225. DOI: 10.16383/j.aas.c180710(Ch ).
[3]
GENNAROR, GOLDFEDERS, NARAYANANA. Threshold-optimal DSA/ECDSA signatures and an application to bitcoin wallet security [J]. International Conference on Applied Cryptography and Network Security, 2016, 9696: 156-174. DOI: 10.1007/978-3-319-39555-5_9
[4]
BREUERF, GOYALV, MALAVOLTAG. Cryptocurrencies with security policies and two-factor authentication [EB/OL]. [2021-03-29]. DOI: 10.1109/eurosp51992.2021.00020 .
[5]
BAGHERZANDIA, JARECKIS, SAXENAN, et al. Password-protected secret sharing [C]// Proceedings of the 18th ACM Conference on Computer and Communications Security. New York:ACM, 2011: 433-444. DOI: 10.1145/2046707.2046758 .
[6]
CAMENISCHJ, LEHMANNA, LYSYANSKAYAA, et al. Memento: How to reconstruct your secrets from a single password in a hostile environment [C]// Advances in Cryptology—CRYPTO 2014. Heidelberg: Springer, 2014: 256-275. DOI: 10.1007/978-3-662-44381-1_15 .
YIX, TARIZ, HAOF, et al. Efficient threshold password-authenticated secret sharing protocols for cloud computing [J]. Journal of Parallel and Distributed Computing, 2019, 128: 57-70. DOI: 10.1016/j.jpdc.2019.01.013 .
[9]
JARECKIS, KIAYIASA, KRAWCZYKH. Round-optimal password-protected secret sharing and T-PAKE in the password-only model [C]// Advances in Cryptology — ASIACRYPT 2014. Heidelberg: Springer, 2014: 233-253. DOI: 10.1007/978-3-662-45608-8_13 .
[10]
JARECKIS, KIAYIASA, KRAWCZYKH, et al. Highly-efficient and composable password-protected secret sharing (or: How to protect your bitcoin wallet online) [C]// 2016 IEEE European Symposium on Security & Privacy. New York: IEEE, 2016: 276-291. DOI: 10.1109/EuroSP.2016.30 .
[11]
JARECKIS, KIAYIASA, KRAWCZYKH, et al. TOPPSS: Cost-minimal password-protected secret sharing based on threshold OPRF [J]. International Conference on Applied Cryptography and Network Security, 2017, 10355: 39-58. DOI: 10.1007/978-3-319-61204-1_3 .
DUPONTP A, HESSEJ, POINTCHEVALD, et al. Fuzzy password-authenticated key exchange [C]// Advances in Cryptology — EUROCRYPT 2018. Cham: Springer International Publishing, 2018: 393-424. DOI: 10.1007/978-3-319-78372-7_13 .
[14]
ERWIGA, HESSEJ, ORLTM, et al. Fuzzy asymmetric password-authenticated key exchange [C]// Advances in Cryptology — ASIACRYPT 2020. Cham: Springer International Publishing, 2020: 761-784. DOI: 10.1007/978-3-030-64834-3_26 .
[15]
BONNEAUJ, BURSZTEINE, CARONI, et al. Secrets, lies, and account recovery: Lessons from the use of personal knowledge questions at Google [C]// Proceedings of the 24th International Conference on World Wide Web. New York: ACM, 2015: 141-150. DOI: 10.1145/2736277.2741691 .
[16]
SCHECHTERS, BRUSHA, EGELMANS. It’s no secret: Measuring the security and reliability of authentication via “secret” questions [C]// Proceedings of the 30th IEEE Symposium on Security and Privacy. New York:IEEE, 2009: 375-390. DOI: 10.1109/SP.2009.11 .
[17]
PONDR, PODDJ, BUNNELLJ, et al. Word association computer passwords: The effect of formulation techniques on recall and guessing rates [J]. Computers & Security, 2000, 19(7): 645-656. DOI: 10.1016/S0167-4048(00)07023-1 .
[18]
SHAMIRA. How to share a secret [J]. Communications of the ACM, 1979, 22(11): 612-613. DOI: 10.1145/359168.359176 .