IP Library Granted Patent US 11,528,127
Granted Patent B2
US 11,528,127 · App. 16/639,101 · Granted Dec 13, 2022

Computer-implemented system and method for highly secure, high speed encryption and transmission of data

Inventor: Craig Steven Wright (London, GB)
Assignee: nChain Holdings Ltd
H04L9/0656H04L9/0825H04L9/0869H04L9/0872H04L9/3066H04L9/3239H04L9/3252H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,528,127
App. No.
16/639,101
Granted
Dec 13, 2022
Kind
B2
Abstract

The present disclosure relates to highly secure, high speed encryption methodologies suitable for applications such as media streaming, streamed virtual private network (VPN) services, large file transfers and the like. For example, encryption methodologies as described herein can provide stream ciphers for streaming data from, for example, a media service provider to a plurality of users. Certain configurations provide wire speed single use encryption. The methodologies as described herein are suited for use with blockchain (e.g. Bitcoin) technologies.

Claims (41)

1. A computer-implemented method of encrypting and transmitting data from a first node to a second node over a network, the method comprising:

deriving, at the first node, a secret key from a common secret which is known by the first and second nodes, wherein:

the first node is associated with a first asymmetric cryptography key pair and the second node is associated with a second asymmetric cryptography key pair, and the common secret is derived at the first and second nodes from the respective first and second asymmetric cryptography key pairs without transmitting the common secret between the first and second nodes;

deriving the secret key includes combining the common secret, or a symmetric key resulting from conversion of the common secret, with additional data for transmission of the encrypted data; and

the additional data includes a time variable or a cryptographic function of a time variable;

utilizing the secret key as a seed for a pseudo random number generator;

combining output from the pseudo random number generator with data to be transmitted to produce encrypted data; and

transmitting the encrypted data to the second node.

2. The method according to claim 1 , wherein derivation of the secret key includes converting the common secret into a symmetric key.

3. A method according to claim 1 , wherein the additional data is derived at the first and second nodes without transmitting the additional data between the first and second nodes.

4. The method according to claim 1 , wherein the additional data includes a single use value or a cryptographic function of a single use value.

5. The method according to claim 1 , wherein the additional data is combined with the common secret or a symmetric key using an exclusive or (XOR) operation to produce the seed for the pseudo random number generator, the symmetric key resulting from conversion of the common secret to the symmetric key.

6. The method according to claim 1 , wherein the pseudo random number generator is based on a Zeta function or a Wolfram Rule 30 function.

7. The method according to claim 1 , wherein the output of the pseudo random number generator is combined with the data to be transmitted using an exclusive or (XOR) operation to produce the encrypted data.

8. The method according to claim 1 , wherein the output of the pseudo random number generator is used as a one-time pad.

9. The method according to claim 1 , wherein the transmitting of the encrypted data comprises transmission of a pseudorandom bit stream.

10. The method according to claim 9 , wherein the pseudorandom bit stream is one or more of a virtual private network (VPN) service or a streamed data service.

11. The method according to claim 1 , wherein the first node is a service provider configured to transmit encrypted data to a plurality of users using a different shared symmetric key for each user.

12. The method according to claim 1 , wherein the second node receives the encrypted data and decrypts the data using the common secret.

13. The method according to claim 1 , wherein the second node decrypts the encrypted data as it is being received by applying an exclusive or (XOR) operation to the encrypted data as it is being received.

14. The method according to claim 1 , wherein the second node seeds its own pseudo random number generator independently of the first node in order to decrypt the encrypted data.

15. The method according to claim 1 , wherein the network is a blockchain network.

16. A non-transitory computer readable storage medium comprising computer-executable instructions that, when executed, configure one or more processors to:

derive, at a first node capable of encrypting and transmitting data to a second node over a network, a secret key from a common secret which is known by the first and second nodes, wherein:

the first node is associated with a first asymmetric cryptography key pair and the second node is associated with a second asymmetric cryptography key pair, and the common secret is derived at the first and second nodes from the respective first and second asymmetric cryptography key pairs without transmitting the common secret between the first and second nodes;

deriving the secret key includes combining the common secret, or a symmetric key resulting from conversion of the common secret, with additional data for transmission of the encrypted data; and

the additional data includes a time variable or a cryptographic function of a time variable;

utilize the secret key as a seed for a pseudo random number generator;

combine output from the pseudo random number generator with data to be transmitted to produce encrypted data; and

transmit the encrypted data to the second node.

17. An electronic device capable of encrypting and transmitting data as a first node to a second node over a network, the electronic device comprising:

an interface device;

one or more processors coupled to the interface device; and

a memory coupled to the one or more processors, the memory having stored thereon computer executable instructions which, when executed, configure the one or more processors to:

derive, at the first node, a secret key from a common secret which is known by the first and second nodes, wherein:

the first node is associated with a first asymmetric cryptography key pair and the second node is associated with a second asymmetric cryptography key pair, and the common secret is derived at the first and second nodes from the respective first and second asymmetric cryptography key pairs without transmitting the common secret between the first and second nodes;

deriving the secret key includes combining the common secret, or a symmetric key resulting from conversion of the common secret, with additional data for transmission of the encrypted data; and

the additional data includes a time variable or a cryptographic function of a time variable;

utilize the secret key as a seed for a pseudo random number generator;

combine output from the pseudo random number generator with data to be transmitted to produce encrypted data; and

transmit the encrypted data to the second node.

Assignments (2)
CHANGE OF NAME Recorded May 7, 2023
From: NCHAIN HOLDINGS LTD
To: NCHAIN LICENSING AG
Reel/Frame 063560/0252 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2020
From: WRIGHT, CRAIG
To: NCHAIN HOLDINGS LTD
Reel/Frame 052717/0421 →
Priority Claims (2)
GB 1713499 · Aug 23, 2017 · national
WO PCT/IB2017/005073 · Aug 23, 2017 · international
Continuity (1)
Related Publication 20200235915A1 · Jul 23, 2020
Cited By (1)
US 12,259,996