IP Library Granted Patent US 12688498
Granted Patent B2
US 12688498 · App. 18/172,899 · Granted Jul 21, 2026

Multi-party computation self-custody wallet

Inventors: Yehuda Lindell (Oakland, CA); Nir Steinherz (Oakland, CA); Guy Pe'er (Talmey Yechiel, IL)
G06Q20/3674G06Q20/389H04L9/3247H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12688498
App. No.
18/172,899
Granted
Jul 21, 2026
Kind
B2
Abstract

Methods, systems, and devices for token management are described. A custodial token platform may communicate with a wallet application to support a multi-party computation wallet and transfer of private keys and key shards to support wallet cloning and key export. The custodial token platform may receive a message signed by a first key shard, sign the message using a second key shard, and broadcast the signed message to transfer a token between the wallet application and a recipient address. The custodial token platform may receive an encrypted payload including the first key shard, and transmit the encrypted payload to a second client application for decryption by the second client application on a second user device. Additionally, the wallet application may support export of the private key based one or multiple authentication techniques, which may cause retrieval of the key shards and display of an indication of the private key.

Claims (56)

1 . A method for data processing, comprising:

receiving, at a user interface of a first client application, a first request to broadcast a blockchain message to a blockchain network supported distributed data store;

signing, after receiving the first request, the blockchain message using a first key shard of a private key associated with a first user of a first blockchain address to generate a partially signed blockchain message, the private key generated on a user device that executes the first client application, wherein the partially signed blockchain message comprises an indication of a second blockchain address that is to receive a transfer of one or more tokens from the first blockchain address;

transmitting the partially signed blockchain message to a custodial token platform that signs the partially signed blockchain message using a second key shard of the private key associated with the first user of the first blockchain address and broadcasts a resulting fully signed blockchain message to the blockchain network supported distributed data store to transfer the one or more tokens to the second blockchain address, wherein the first key shard and the second key shard of the private key are associated with the first blockchain address;

receiving, at the user interface of the first client application, a second request to clone the private key to a second device;

authenticating, after receiving the second request, a user of the user device using one or both of a passcode and a biometric authentication process;

encrypting, after receiving the second request and using a public key of a second client application, a payload comprising the first key shard to generate an encrypted payload; and

transmitting the encrypted payload to the custodial token platform in accordance with the second request.

2 . The method of claim 1 , further comprising:

decrypting, after authenticating the user, a copy of the second key shard, the first key shard and the second key shard used to generate the private key; and

transmitting information associated with the private key.

3 . The method of claim 2 , wherein transmitting the information associated with the private key comprises:

displaying, at the user device, the information associated with the private key.

4 . The method of claim 1 , further comprising:

activating, after receiving the second request, a camera of the user device; and

identifying the public key of the second client application using the camera of the user device.

5 . The method of claim 4 , wherein identifying the public key comprises:

scanning, using the camera, a quick response (QR) code associated with the public key.

6 . The method of claim 1 , wherein the second request comprises a request to clone the first key shard to the second client application.

7 . The method of claim 1 , further comprising:

generating, at the user device, the private key;

storing a backup of the first key shard and the second key shard in a secure enclave of the user device;

encrypting the first key shard using an encryption key that is stored in the secure enclave of the user device; and

transmitting, to the custodial token platform, an indication of the second key shard.

8 . An apparatus for data processing, comprising:

a processor;

memory coupled with the processor; and

instructions stored in the memory and executable by the processor to cause the apparatus to:

receive, at a user interface of a first client application, a first request to broadcast a blockchain message to a blockchain network supported distributed data store;

sign, after receiving the first request, the blockchain message using a first key shard of a private key associated with a first user of a first blockchain address to generate a partially signed blockchain message, the private key generated on a user device that executes the first client application, wherein the partially signed blockchain message comprises an indication of a second blockchain address that is to receive a transfer of one or more tokens from the first blockchain address;

transmit the partially signed blockchain message to a custodial token platform that signs the partially signed blockchain message using a second key shard of the private key associated with the first user of the first blockchain address and broadcasts a resulting fully signed blockchain message to the blockchain network supported distributed data store to transfer the one or more tokens to the second blockchain address, wherein the first key shard and the second key shard of the private key are associated with the first blockchain address;

receive, at the user interface of the first client application, a second request to clone the private key to a second device;

authenticate, after receiving the second request, a user of the user device using one or both of a passcode and a biometric authentication process;

encrypt, after receiving the second request and using a public key of a second client application, a payload comprising the first key shard to generate an encrypted payload; and

transmit the encrypted payload to the custodial token platform in accordance with the second request.

9 . The apparatus of claim 8 , wherein the instructions are further executable by the processor to cause the apparatus to:

decrypt, after authenticating the user, a copy of the second key shard, the first key shard and the second key shard used to generate the private key; and

transmit information associated with the private key.

10 . The apparatus of claim 9 , wherein the instructions to transmit the information associated with the private key are executable by the processor to cause the apparatus to:

display, at the user device, the information associated with the private key.

11 . The apparatus of claim 8 , wherein the instructions are further executable by the processor to cause the apparatus to:

activate, after receiving the second request, a camera of the user device; and

identify the public key of the second client application using the camera of the user device.

12 . A non-transitory computer-readable medium storing code for data processing, the code comprising instructions executable by a processor to:

receive, at a user interface of a first client application, a first request to broadcast a blockchain message to a blockchain network supported distributed data store;

sign, after receiving the first request, the blockchain message using a first key shard of a private key associated with a first user of a first blockchain address to generate a partially signed blockchain message, the private key generated on a user device that executes the first client application, wherein the partially signed blockchain message comprises an indication of a second blockchain address that is to receive a transfer of one or more tokens from the first blockchain address;

transmit the partially signed blockchain message to a custodial token platform that signs the partially signed blockchain message using a second key shard of the private key associated with the first user of the first blockchain address and broadcasts a resulting fully signed blockchain message to the blockchain network supported distributed data store to transfer the one or more tokens to the second blockchain address, wherein the first key shard and the second key shard of the private key are associated with the first blockchain address;

receive, at the user interface of the first client application, a second request to clone the private key to a second device;

authenticate, after receiving the second request, a user of the user device using one or both of a passcode and a biometric authentication process;

encrypt, after receiving the second request and using a public key of a second client application, a payload comprising the first key shard to generate an encrypted payload; and

transmit the encrypted payload to the custodial token platform in accordance with the second request.

13 . The non-transitory computer-readable medium of claim 12 , wherein the instructions are further executable by the processor to:

decrypt, after authenticating the user, a copy of the second key shard, the first key shard and the second key shard used to generate the private key; and

transmit an information associated with the private key.

14 . The non-transitory computer-readable medium of claim 13 , wherein the instructions to transmit the information associated with the private key are executable by the processor to:

display, at the user device, the information associated with the private key.