IP Library Granted Patent US 12,346,902
Granted Patent B2
US 12,346,902 · App. 16/638,706 · Granted Jul 1, 2025

Rewarded puzzle solution

Inventors: Ying Chan (Cambridge, GB); Dean Kramer (London, GB); Craig Steven Wright (London, GB)
Assignee: NCHAIN LICENSING AG
G06Q20/401G06F16/2379G06Q10/10G06Q20/065G06Q20/0658G06Q20/3674G06Q20/3827H04L9/0637H04L9/0643H04L9/0662H04L9/3247G06Q2220/00H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,902
App. No.
16/638,706
Granted
Jul 1, 2025
Kind
B2
Abstract

The invention relates to distributed ledge technologies such as consensus-based blockchains. Computer-implemented methods for a secure random number generation within blockchain scripts are described. The invention is implemented using a blockchain network, which may be, for example, a Bitcoin blockchain. A first transaction that includes a puzzle is validated at a node in a blockchain network, with the first transaction being associated with a digital asset, and with a solution to the puzzle being indeterminable at a time of validation of the first transaction. A pseudorandom number, based at least in part on a solution to the puzzle that is included in a second transaction, is generated at least in part by validating the second transaction, the second transaction created to transfer control of the digital asset associated with the first transaction. Control of the digital asset is transferred based at least in part on the pseudorandom number.

Claims (40)

1. A computer-implemented method comprising:

validating, at a node in a blockchain network, a first transaction that includes a puzzle, wherein validation of the first transaction is processed by hardware of the node, wherein the puzzle is a set of operation codes comprising a proof of work function in a locking script of the first transaction, wherein the first transaction is associated with a digital asset, and wherein a solution to the puzzle is indeterminable at a time of the validation of the first transaction;

generating, at least in part by validating a second transaction created to transfer control of the digital asset associated with the first transaction, a pseudo random number that is based at least in part on the solution included in the second transaction, wherein the solution:

is derived at least in part from a header of a future block on or after a specified time in the blockchain network, wherein the header was indeterminable at the time that the first transaction was successfully validated;

solves the puzzle of the first transaction; and

is used at least in part to derive a seed to a pseudorandom number generation algorithm in the locking script of the first transaction;

after the validation of the first transaction, receiving, as input to the locking script of the first transaction, the solution to the puzzle generated at least in part as a result of validating the second transaction; and

as a result of execution of the set of operation codes in the locking script with the solution as input, transferring control of the digital asset based at least in part on the pseudorandom number.

2. The computer-implemented method according to claim 1 , wherein the puzzle is a cryptographic hash puzzle.

3. The computer-implemented method according to claim 1 , wherein solving the puzzle is more computationally difficult than verifying the solution.

4. The computer-implemented method according to claim 1 , wherein transferring control of the digital asset includes:

on a condition that the pseudorandom number is a first value, validation of the second transaction is successful; and

on a condition that the pseudorandom number is a second value, different from the first value, validation of the second transaction is unsuccessful.

5. The computer-implemented method according to claim 1 , wherein the locking script constrains the validation of the second transaction to a particular time frame.

6. The computer-implemented method according to claim 5 , wherein expiration of the particular time frame enables a specified party to receive the control of the digital asset.

7. The computer-implemented method according to claim 6 , wherein the specified party is a party that created the first transaction.

8. The computer-implemented method according to claim 1 , wherein a distribution for solving the puzzle is larger than the digital asset.

9. A system, comprising:

a processor; and

memory including executable instructions that, as a result of execution by the processor, causes the system to:

validate a first transaction that includes a puzzle, wherein the puzzle is a set of operation codes comprising a proof of work function in a locking script of the first transaction, wherein the first transaction is associated with a digital asset, and wherein a solution to the puzzle is indeterminable at a time of the validation of the first transaction;

generate, at least in part by validating a second transaction created to transfer control of the digital asset associated with the first transaction, a pseudo random number that is based at least in part on the solution included in the second transaction, wherein the solution:

is derived at least in part from a header of a future block on or after a specified time in the blockchain network, wherein the header was indeterminable at the time that the first transaction was successfully validated;

solves the puzzle of the first transaction; and

is used at least in part to derive a seed to a pseudorandom number generation algorithm in the locking script of the first transaction;

after the validation of the first transaction, receive, as input to the locking script of the first transaction, the solution to the puzzle generated at least in part as a result of validating the second transaction; and

as a result of execution of the set of operation codes in the locking script with the solution as input, transfer control of the digital asset based at least in part on the pseudorandom number.

10. The system of claim 9 , wherein the puzzle is a cryptographic hash puzzle.

11. The system of claim 9 , wherein solving the puzzle is more computationally difficult than verifying the solution.

12. The system of claim 9 , wherein transferring control of the digital asset includes:

on a condition that the pseudorandom number is a first value, validation of the second transaction is successful; and

on a condition that the pseudorandom number is a second value, different from the first value, validation of the second transaction is unsuccessful.

13. A non-transitory computer-readable storage medium having stored thereon executable instructions that, as a result of being executed by a processor of a computer system, cause the computer system to:

Validate a first transaction that includes a puzzle, wherein the puzzle is a set of operation codes comprising a proof of work function in a locking script of the first transaction, wherein the first transaction is associated with a digital asset, and wherein a solution to the puzzle is indeterminable at a time of the validation of the first transaction;

generate, at least in part by validating a second transaction created to transfer control of the digital asset associated with the first transaction, a pseudo random number that is based at least in part on the solution included in the second transaction, wherein the solution:

is derived at least in part from a header of a future block on or after a specified time in the blockchain network, wherein the header was indeterminable at the time that the first transaction was successfully validated;

solves the puzzle of the first transaction; and

is used at least in part to derive a seed to a pseudorandom number generation algorithm in the locking script of the first transaction;

after the validation of the first transaction, receive, as input to the locking script of the first transaction, the solution to the puzzle generated at least in part as a result of validating the second transaction; and

as a result of execution of the set of operation codes in the locking script with the solution as input, transfer control of the digital asset based at least in part on the pseudorandom number.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2023
From: CHAN, YING; KRAMER, DEAN
To: NCHAIN HOLDINGS LTD
Reel/Frame 063055/0409 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2022
From: CHAN, YING; KRAMER, DEAN
To: NCHAIN HOLDINGS LTD.
Reel/Frame 062048/0539 →
CHANGE OF NAME Recorded Dec 11, 2022
From: NCHAIN HOLDINGS LTD
To: NCHAIN LICENSING AG
Reel/Frame 062114/0346 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2022
From: WRIGHT, CRAIG STEVEN
To: NCHAIN HOLDINGS LTD
Reel/Frame 058667/0789 →
Priority Claims (2)
GB 1713084 · Aug 15, 2017 · national
GB 1713086 · Aug 15, 2017 · national
Continuity (1)
Related Publication 20200219097A1 · Jul 9, 2020
References Cited (41)
US 5778069A · Thomlinson · 1998 [cited by examiner]
US 9614868B2 · Yavuz et al. · 2017 [cited by applicant]
US 20160292680A1 · Wilson, Jr. · 2016 [cited by examiner]
US 20170023120A1 · Zulawski · 2017 [cited by applicant]
US 20170063535A1 · Brown · 2017 [cited by examiner]
US 20170084118A1 · Robinson et al. · 2017 [cited by applicant]
US 20170091750A1 · Maim · 2017 [cited by applicant]
US 20170236120A1 · Herlihy et al. · 2017 [cited by applicant]
Andreas M. Antonopoulos, Mastering Bitcoin, Dec. 1, 2014, O'Reilly Media, 1st Edition, Chapters 5 & 7-8 (Year: 2014). [cited by examiner]
Vitalik Buterin, Ethereum White Paper, 2014, ethereum.org (Year: 2014). [cited by examiner]
Zeng et al., Pseudorandom Number Generators Based on Evolutionary Algorithm, 2003, IEEE, pp. 1662-1668 (Year: 2003). [cited by examiner]
Blum et al., How to Generate Cryptographically Strong Sequences of Pseudo Random Bits, 1982, IEEE, pp. 112-117 (Year: 1982). [cited by examiner]
Anonymous, “Script,” Bitcoin Wiki, Jun. 8, 2017, 12 pages. [cited by applicant]
Antonopoulos et al., “Bitcoin Book,” GitHub, retrieved from https://github.com/bitcoinbook/bitcoinbook, Jun. 8, 2017, 4 pages. [cited by applicant]
Antonopoulos, “Mastering Bitcoin—Unlocking Digital Cryptocurrencies,” O'Reilly Media, Inc., Dec. 20, 2014, 282 pages. [cited by applicant]
Apodaca, “What OP code can I use in the scripting system to make a smart contract that acts similar to a lottery,” Bitcoin Stack Exchange, Jul. 9, 2017 [retrieved Jan. 4, 2018], https://bitcoin.stackexchange.com/questio… [cited by applicant]
BitLotto, “BitLotto—The Bitcoin Lottery / Raffle,” retrieved from https://web.archive.org/web/20121113004141/http://www.bitlotto.com, 2012, 2 pages. [cited by applicant]
Bonneau et al., “Mixcoin—Anonymity for Bitcoin with Accountable Mixes,” 18th International Conference on Financial Cryptography and Data Security, Nov. 2014, 25 pages. [cited by applicant]
Casascius, “Sustainable Nanopayment Idea: Probabilistic Payments,” Bitcoin Forum, Feb. 2012 [retrieved Jan. 2, 2018], https://bitcointalk.org/index.php?topic=62558.0;wap, 5 pages. [cited by applicant]
Decker et al., “Bitcoin Transaction Malleability and MtGox,” European Symposium on Research in Computer Security, Sep. 6, 2014, 13 pages. [cited by applicant]
Deepceleron, “Bitcoin Blockchain Raffle Ticket Picker,” retrieved from https://we.lovebitco.in/raffle.html, 2013, 2 pages. [cited by applicant]
Deviate Fish, “Building a Lottery, Part 4: The trouble with public PRNGs,” Mar. 17, 2017 [retrieved Jan. 4, 2018], https://medium.com/@deviatefish/building-a-lottery-part-4-e2bafaa968fa, six pages. [cited by applicant]
Hess, “How can I securely generate a random number in my smart contract?,” Ethereum Stack Exchange, Jan. 21, 2016 [retrieved Jan. 4, 2018], https://ethereum.stackexchange.com/questions/191/how-can-i-securely-generate-a-… [cited by applicant]
Hyena, “Anonymity in the Bitcoin: Splitting Transactions,” retrieved from https://bitcointalk.org/index.php?topic=1394184.0, 2016, 9 pages. [cited by applicant]
International Search Report and Written Opinion mailed Nov. 30, 2018, Patent Application No. PCT/IB2018/056087, 10 pages. [cited by applicant]
International Search Report and Written Opinion mailed Nov. 30, 2018, Patent Application No. PCT/IB2018/056088, 10 pages. [cited by applicant]
Jeezy, “RNG using Block Informations,” retrieved from https://bitcointalk.org/index.php?topic=289558.0, 2013, 9 pages. [cited by applicant]
Lomashuk et al., “Dao.Casino Whitepaper,” latest edit Jun. 24, 2017 [retrieved Jan. 2, 2018], https://github.com/DaoCasino/Whitepaper/blob/master/DAO.Casino%20WP.md, 12 pages. [cited by applicant]
Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System,” Bitcoin, Oct. 31, 2008, https://bitcoin.org/bitcoin.pdf, 9 pages. [cited by applicant]
Randao, “README.md at master,” GitHub, Jul. 31, 2016 [retrieved Jan. 5, 2018], https://github.com/randao/randao/blob/master/README.md, 8 pages. [cited by applicant]
Satoshi et al., “Connection Limits,” Bitcoin Forum, Aug. 9, 2010, https://bitcointalk.org/index.php?topic=741.0;prev_next=prev, 2 pages. [cited by applicant]
UK Commercial Search Report mailed Jan. 12, 2018, Patent Application No. GB1713084.0, 7 pages. [cited by applicant]
UK Commercial Search Report mailed Jan. 12, 2018, Patent Application No. GB1713086.5, 9 pages. [cited by applicant]
UK IPO Search Report mailed Feb. 8, 2018, Patent Application No. GB1713084.0, 8 pages. [cited by applicant]
UK IPO Search Report mailed Feb. 16, 2018, Patent Application No. GB1713086.5, 4 pages. [cited by applicant]
Vnovak, “Ethereum Lottery—uses Bitcoin Blocks to Pick the Winner (via BTCRelay)” retrieved from https://www.reddit.com/r/ethereum/comments/4qql6d/ethereum_lotter, 2016, 3 pages. [cited by applicant]
Winsome, “Random Number Generation on Winsome.io—Future Blockhashes,” retrieved from https://blog.winsome.io/random-numer-generation-on-winsome-io-future-blockhashes-fe44b1c61d35, 2017, 12 pages. [cited by applicant]
Blum et al., “How to Generate Cryptographically Strong Sequences of Pseudo Random Bits”, 1982, IEEE, 6 pages. [cited by applicant]
Zeng et al., “Pseudorandom Number Generators Based on Evolutionary Algorithm”, 2003, IEEE, 7 pages. [cited by applicant]
Buterin, “Ethereum White Paper”, A Next Generation Smart Contract & Decentralized Application Platform, 2014, 36 pages. [cited by applicant]
Apodaca, “What OP code can use in the scripting system to make a smart contract that acts similar to a lottery,” Bitcoin Stack Exchange, Jul. 9, 2017 [retrieved Jan. 4, 2018], https://bitcoin.stackexchange.com/questions… [cited by applicant]