IP Library Granted Patent US 12,423,684
Granted Patent B2
US 12,423,684 · App. 17/764,814 · Granted Sep 23, 2025

Digital signature generation using a cold wallet

Inventors: Jakob Illeborg Pagter (Aarhus V, DK); Thomas Pelle Jakobsen (Marslet, DK)
Assignee: BLOCKDAEMON APS
G06Q20/3825G06Q20/3674G06Q20/3829G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,423,684
App. No.
17/764,814
Filed
Mar 29, 2022
Granted
Sep 23, 2025
Kind
B2
Art Unit
3697
USPC
705/67
Abstract

A method and a system for providing a digital signature are disclosed. A private signature key is distributed among two or more nodes of a cold wallet. Each node of the cold wallet generates a pre-signature, based on its share(s) of the private signature key, and transmits the pre-signature to one of two or more pre-signature nodes. A signing application requests a signature and transmits a message to be signed to each of the pre-signature nodes. In response to receiving the request for a signature and the message to be signed, each pre-signature node generates a partial signature, based on its pre-signature and on the message to be signed. Each pre-signature node transmits its partial signature to the signing application, and the signing application computes a digital signature from the partial signatures.

Claims (29)

1. A method for providing a digital signature, the method comprising the steps of:

receiving by two or more nodes of a cold wallet, one or more shares of a private signature key, each node of the cold wallet thereby being in the possession of the one or more shares of the private signature key, and none of the nodes of the cold wallet being in the possession of all shares of the private signature key;

generating by each node of the cold wallet a pre-signature, based on its share(s) of the private signature key, and transmitting the pre-signature to one of two or more pre-signature nodes, in such a manner that each pre-signature node receives a pre-signature from only one of the nodes of the cold wallet;

requesting by a signing application a signature and transmitting a message to be signed to each of the pre-signature nodes;

in response to receiving the request for a signature and the message to be signed, generating by each pre-signature node a partial signature, based on its pre-signature and on the message to be signed;

transmitting by each pre-signature node its partial signature to the signing application; and

in response to receiving the partial signatures from each pre-signature node, computing by the signing application a digital signature from the received partial signatures;

wherein the step of each node of the cold wallet transmitting the pre-signature to one of the pre-signature nodes is performed using a one-way communication channel.

2. The method according to claim 1 , further comprising the step of each of the pre-signature nodes deleting the pre-signature after the step of generating a partial signature and before the step of transmitting the partial signature.

3. The method according to claim 1 , wherein the step of receiving a private signature key is performed by the nodes of the cold wallet generating the private signature key by means of a multi-party computation protocol.

4. The method according to claim 1 , wherein each node of the cold wallet generates the pre-signature as part of a batch comprising two or more pre-signatures.

5. The method according to claim 1 , wherein at least the steps of receiving a private signature key, generating pre-signatures and transmitting the pre-signatures to the pre-signature nodes are performed as pre-processing steps prior to the step of the signing application requesting a signature.

6. The method according to claim 1 , wherein the step of each node of the cold wallet generating a pre-signature, based on its share(s) of the private signature key, and transmitting the pre-signature to one of two or more pre-signature nodes is initiated by the pre-signature nodes in response to receipt of a request for a signature from the signing application.

7. The method according to claim 1 , wherein the step of each pre-signature node generating a partial signature is performed without internal communication among the pre-signature nodes.

8. The method according to claim 1 , further comprising the step of authorizing the request for a signature from the signing application.

9. The method according to claim 1 , wherein the nodes of the cold wallet fulfil a threshold condition, t, and the pre-signature nodes fulfil a threshold condition, t′, where t′≥t.

10. The method according to claim 1 , further comprising the steps of:

at least some of the nodes of the cold wallet generating one or more additional pre-signature shares, encrypting the additional pre-signature share(s), and transmitting the encrypted additional pre-signature share(s) to one or more of the pre-signature nodes along with the pre-signatures; and

each pre-signature node which has received an encrypted additional pre-signature share transmitting the encrypted additional pre-signature share to the signing application along with the partial signature;

wherein the step of the signing application computing a digital signature comprises the steps of:

the signing application decrypting the received encrypted additional pre-signature share(s);

the signing application generating an additional pre-signature, based on the decrypted additional pre-signature share(s), and generating an additional partial signature based on the additional pre-signature and on the message to be signed; and

the signing application computing the digital signature from the partial signatures received from the pre-signature nodes and the generated additional partial signature.

11. The method according to claim 10 , wherein the step of generating one or more additional pre-signature shares is performed by each of the nodes of the cold wallet generating an additional pre-signature share and encrypting the additional pre-signature share.

12. The method according to claim 10 , wherein the step of generating one or more additional pre-signature shares is performed by at least two of the nodes of the cold wallet applying a multi-party computation protocol.

13. The method according to claim 10 , wherein the additional pre-signature shares are encrypted and decrypted by means of symmetric encryption keys shared between the respective nodes of the cold wallet and the signing application.

14. The method according to claim 1 , wherein the pre-signatures are generated within the cold wallet, in such a manner that no data enters the cold wallet and no shares of the private signature key leaves the cold wallet.

15. The method according to claim 1 , wherein the cold wallet is air-gapped during the method.

16. The method according to claim 1 , wherein the one-way communication channel comprises a visual output.

Assignments (2)
CHANGE OF NAME Recorded Dec 14, 2023
From: SEPIOR APS
To: BLOCKDAEMON APS
Reel/Frame 065867/0578 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2022
From: PAGTER, JAKOB ILLEBORG; JAKOBSEN, THOMAS PELLE
To: SEPIOR APS
Reel/Frame 059428/0568 →
Priority Claims (2)
EP 19203273 · Oct 15, 2019 · regional
EP 20151197 · Jan 10, 2020 · regional
Continuity (1)
Related Publication 20220327530A1 · Oct 13, 2022
References Cited (26)
US 10540654B1 · James · 2020 [cited by examiner]
US 10903991B1 · Craige · 2021 [cited by examiner]
US 12271898B1 · Arvanaghi · 2025 [cited by examiner]
US 20080095360A1 · Vuillaume · 2008 [cited by examiner]
US 20080181413A1 · Yi · 2008 [cited by examiner]
US 20190280864A1 · Cheng et al. · 2019 [cited by applicant]
US 20190378119A1 · Hyuga et al. · 2019 [cited by applicant]
US 20200252382A1 · Peddada, IV · 2020 [cited by examiner]
US 20200344070A1 · Li · 2020 [cited by examiner]
US 20200356989A1 · Shamai · 2020 [cited by examiner]
US 20210083872A1 · Desmarais · 2021 [cited by examiner]
US 20210083882A1 · Venable, Sr. · 2021 [cited by examiner]
US 20210099294A1 · Guo · 2021 [cited by examiner]
CN 104320253A · 2015 [cited by applicant]
CN 107733648A · 2018 [cited by applicant]
CN 109257179A · 2019 [cited by applicant]
WO 2019043466A1 · 2019 [cited by applicant]
WO 2019159172A1 · 2019 [cited by applicant]
WO 2019193452A1 · 2019 [cited by applicant]
Japanese Office Action from Corresponding Japanese Patent Application No. JP2022-520338, Jul. 30, 2024. [cited by applicant]
Goldfeder et al., “Securing Bitcoin Wallets Via Threshold Signatures,” Jun. 3, 2014, 11 Pages, retrieved from the Internet at https://www.cs.princeton.edu/˜stevenag/bitcoin_threshold_signatures.pdf. [cited by applicant]
Gennaro et al., “Threshold-Optimal DSA/ECDSA Signatures and an Application to Bitcoin Wallet Security,” International Conference on Applied Cryptography and Network Security, Jun. 19, 2016, 42 Pages. [cited by applicant]
Extended Search Report from corresponding European Application No. 19203273.8, Mar. 16, 2020. [cited by applicant]
International Preliminary Report on Patentability from PCT Application No. PCT/EP2020/077977, Sep. 2, 2021. [cited by applicant]
International Search Report and Written Opinion from PCT Application No. PCT/EP2020/077977, Dec. 3, 2020. [cited by applicant]
Office Action from corresponding Chinese Application No. 202080068768.6, Jun. 15, 2023. [cited by applicant]
Cited By (1)
US 12,603,784