IP Library Granted Patent US 12,712,713
Granted Patent B2
US 12,712,713 · App. 18/017,284 · Granted Aug 18, 2026

Generating shared private keys

Inventor: Michaella Pettit (London, GB)
Assignee: nChain Licensing AG
H04L9/085H04L9/0861H04L9/14H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,713
App. No.
18/017,284
Granted
Aug 18, 2026
Kind
B2
Abstract

A computer-implemented method of generating shares of private keys, wherein the method is performed by a first participant of a group of participants and comprises: obtaining a first seed share, wherein each other participant has a respective seed share; generating a first master private key share of a shared master private key, wherein the first master private key share is generated based on the first seed share and the respective seed share of each other participant, and wherein each other participant has a respective master private key share; and generating one or more first private key shares based on the first master private key share, wherein each first private key share is a share of a respective shared private key.

Claims (54)

1 . A computer-implemented method of generating shares of private keys, wherein the method is performed by a first participant of a group of participants and comprises:

obtaining a first seed share, wherein each other participant has a respective seed share;

inputting at least the first seed share to a cryptographic hash function and executing the cryptographic hash function on at least the first seed share to generate a first component of a first data item, wherein each other participant has a respective data item;

obtaining the respective data items generated by the other participants;

generating a first master private key share of a shared master private key, wherein the first master private key share is generated based on the first data item and the respective data items generated by the other participants, and wherein each other participant has a respective master private key share of the shared master private key; and

generating one or more first private key shares based on the first master private key share, wherein each first private key share is a share of a respective shared private key;

generating a hierarchical deterministic key structure of private key shares, wherein the one or more first private key shares generated based on the first master private key share are respective parent private key shares, and/or respective child private key shares, wherein each parent private key share of a given level in the key structure is a parent to one or more child private key shares in a subsequent level in the key structure;

generating a first parent chain code share of a first parent private key share, the first parent private key share being a share of a first parent private key;

obtaining a respective parent chain code share from each other participant;

generating a common chain code based on each parent chain code share; and

obtaining a first parent public key corresponding to the first private key, wherein one or more first child key shares are generated based on a respective first term and a respective second term, wherein the respective first term is generated based on the first parent private key share, and wherein the respective second term is generated by inputting into a hash function at least i) the first parent public key, ii) a respective index of the respective first child private key share, and iii) the common chain code.

2 . The method of claim 1 , wherein the inputting of at least the first seed share to the hash function comprises inputting at least the first seed share to a HMAC function to generate a first HMAC value, and wherein the first data item is a first part of the first HMAC value.

3 . The method of claim 1 , wherein the first master private key share is generated by performing a secret sharing scheme to generate a share of a first secret, wherein the first secret is the master private key.

4 . The method of claim 1 , comprising obtaining one or more auxiliary private keys, and wherein each of the one or more first private key shares is generated based on the first master private key share and a respective one of the one or more auxiliary private keys.

5 . The method of claim 4 , comprising generating a first auxiliary master private key, and wherein each of the one or more auxiliary private keys is generated based on the first auxiliary master private key.

6 . The method of claim 5 , comprising obtaining a common seed value, wherein each other participant has the same common seed value, and wherein the first auxiliary master private key is generated based on the common seed value.

7 . The method of claim 6 , wherein generating the common seed value comprises:

performing a secret sharing scheme to generate a first share of a second secret, wherein the second secret is a second private key;

generating a first combined share based on the first master private key share and the first secret share of the second private key;

obtaining at least a predetermined number of other combined shares, wherein each other combined share is generated by another participant and is based on a respective share of the master private key and a respective share of the second private key; and

generating the common seed based on the first combined share and at least the predetermined number of other combined shares.

8 . The method of claim 6 , wherein generating the first auxiliary master private key comprises inputting the common seed value to a hash function.

9 . The method of claim 8 , wherein inputting the common seed to the hash function comprises inputting the common seed to a HMAC function to generate a second HMAC value, and wherein the first master private key share is a first component of the second HMAC value.

10 . The method of claim 1 , wherein each first child private key share is generated based on a respective parent private key share, wherein each first child private key share is generated based on a respective first term and a respective second term, wherein the respective first term is generated based on the respective parent private key share, and wherein the respective second term is generated by inputting into a hash function at least i) the respective parent private key share or corresponding public key, and ii) a respective index of the respective first child private key share.

11 . The method of claim 10 , comprising for each first child private key share, generating a respective parent chain code share of the respective parent private key share, wherein the respective second term is generated by inputting into the hash function iii) a first master chain code share.

12 . The method of claim 10 , wherein the hash function is a HMAC function.

13 . The method of claim 1 , comprising performing a signing phase of a digital signature scheme, wherein said performing comprises:

obtaining a message; and

generating a first signature share based on the message and one of the first private key shares.

14 . The method of claim 13 , wherein the message comprises at least part of a blockchain transaction.

15 . A computing device comprising:

memory comprising one or more memory units; and

processing apparatus comprising one or more processing units, wherein the memory stores code arranged to run on the processing apparatus, the code being configured so as when run on the processing apparatus, the processing apparatus performs method of generating shares of private keys, wherein the method is performed by a first participant of a group of participants and comprises:

obtaining a first seed share, wherein each other participant has a respective seed share;

inputting at least the first seed share to a cryptographic hash function to generate a first component of a first data item and executing the cryptographic hash function on at least the first seed share, wherein each other participant has a respective data item;

obtaining the respective data items generated by the other participants;

generating a first master private key share of a shared master private key, wherein the first master private key share is generated based on the first data item and the respective data items generated by the other participants, and wherein each other participant has a respective master private key share; and

generating one or more first private key shares based on the first master private key share, wherein each first private key share is a share of a respective shared private key;

generating a hierarchical deterministic key structure of private key shares, wherein the one or more first private key shares generated based on the first master private key share are respective parent private key shares, and/or respective child private key shares, wherein each parent private key share of a given level in the key structure is a parent to one or more child private key shares in a subsequent level in the key structure;

generating a first parent chain code share of a first parent private key share, the first parent private key share being a share of a first parent private key;

obtaining a respective parent chain code share from each other participant; and

generating a common chain code based on each parent chain code share;

obtaining a first parent public key corresponding to the first private key, wherein one or more first child key shares are generated based on a respective first term and a respective second term, wherein the respective first term is generated based on the first parent private key share, and wherein the respective second term is generated by inputting into a hash function at least i) the first parent public key, ii) a respective index of the respective first child private key share, and iii) the common chain code.

16 . A non-transitory computer-readable storage medium, comprising a computer program configured so as, when run on one or more processors, the one or more processors perform a method of generating shares of private keys, wherein the method is performed by a first participant of a group of participants and comprises:

obtaining a first seed share, wherein each other participant has a respective seed share;

inputting at least the first seed share to a cryptographic hash function and executing the cryptographic hash function on at least the first seed share to generate a first component of a first data item, wherein each other participant has a respective data item;

obtaining the respective data items generated by the other participants

generating a first master private key share of a shared master private key, wherein the first master private key share is generated based on the first data item and the respective data item generated by the other participants, and wherein each other participant has a respective master private key share; and

generating one or more first private key shares based on the first master private key share, wherein each first private key share is a share of a respective shared private key;

generating a hierarchical deterministic key structure of private key shares, wherein the one or more first private key shares generated based on the first master private key share are respective parent private key shares, and/or respective child private key shares, wherein each parent private key share of a given level in the key structure is a parent to one or more child private key shares in a subsequent level in the key structure;

generating a first parent chain code share of a first parent private key share, the first parent private key share being a share of a first parent private key;

obtaining a respective parent chain code share from each other participant; and

generating a common chain code based on each parent chain code share;

obtaining a first parent public key corresponding to the first private key, wherein one or more first child key shares are generated based on a respective first term and a respective second term, wherein the respective first term is generated based on the first parent private key share, and wherein the respective second term is generated by inputting into a hash function at least i) the first parent public key, ii) a respective index of the respective first child private key share, and iii) the common chain code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2023
From: PETTIT, MICHAELLA
To: NCHAIN LICENSING AG
Reel/Frame 062441/0534 →
Priority Claims (1)
GB 2011686 · Jul 28, 2020 · national
Continuity (1)
Related Publication 20230224147A1 · Jul 13, 2023
References Cited (135)
US 7246232B2 · Dutertre · 2007 [cited by applicant]
US 8144874B2 · McGough · 2012 [cited by applicant]
US 8806197B2 · Struik et al. · 2014 [cited by applicant]
US 9813244B1 · Triandopoulos et al. · 2017 [cited by applicant]
US 9894151B2 · Dhuse et al. · 2018 [cited by applicant]
US 10211981B2 · Camenisch et al. · 2019 [cited by applicant]
US 10491404B1 · Yamamoto · 2019 [cited by examiner]
US 10511436B1 · Machani · 2019 [cited by applicant]
US 10574451B2 · Adams · 2020 [cited by examiner]
US 10764043B2 · Traynor et al. · 2020 [cited by applicant]
US 10797865B2 · Wu · 2020 [cited by examiner]
US 10903991B1 · Craige et al. · 2021 [cited by applicant]
US 11323267B1 · Griffin et al. · 2022 [cited by applicant]
US 11481761B2 · Lam · 2022 [cited by applicant]
US 11563567B2 · Le Saint · 2023 [cited by applicant]
US 11637708B2 · Hung · 2023 [cited by applicant]
US 11973867B2 · Tysor et al. · 2024 [cited by applicant]
US 12309196B2 · Pettit · 2025 [cited by applicant]
US 20020116611A1 · Zhou et al. · 2002 [cited by applicant]
US 20030009694A1 · Wenocur et al. · 2003 [cited by applicant]
US 20030059041A1 · Mackenzie et al. · 2003 [cited by applicant]
US 20100037055A1 · Fazio · 2010 [cited by examiner]
US 20110138192A1 · Kocher · 2011 [cited by examiner]
US 20120254619A1 · Dhuse et al. · 2012 [cited by applicant]
US 20140164769A1 · D'Souza · 2014 [cited by applicant]
US 20140325309A1 · Resch · 2014 [cited by examiner]
US 20150100781A1 · Yann et al. · 2015 [cited by applicant]
US 20150288525A1 · Camenisch et al. · 2015 [cited by applicant]
US 20170223008A1 · Camenisch et al. · 2017 [cited by applicant]
US 20170250972A1 · Ronda et al. · 2017 [cited by applicant]
US 20180060248A1 · Liu et al. · 2018 [cited by applicant]
US 20180074889A1 · Resch et al. · 2018 [cited by applicant]
US 20180101697A1 · Rane et al. · 2018 [cited by applicant]
US 20180183601A1 · Campagna · 2018 [cited by applicant]
US 20180212772A1 · Leavy · 2018 [cited by examiner]
US 20180307573A1 · Abraham et al. · 2018 [cited by applicant]
US 20180349867A1 · Trieflinger · 2018 [cited by applicant]
US 20180351754A1 · Wallrabenstein et al. · 2018 [cited by applicant]
US 20190007205A1 · Corduan et al. · 2019 [cited by applicant]
US 20190014124A1 · Reddy et al. · 2019 [cited by applicant]
US 20190280864A1 · Cheng et al. · 2019 [cited by applicant]
US 20190370792A1 · Lam · 2019 [cited by examiner]
US 20190372759A1 · Rix · 2019 [cited by examiner]
US 20200005290A1 · Madisetti · 2020 [cited by examiner]
US 20200044863A1 · Yadlin · 2020 [cited by examiner]
US 20200074450A1 · Fletcher et al. · 2020 [cited by applicant]
US 20200145231A1 · Trevethan · 2020 [cited by applicant]
US 20200153640A1 · Ranellucci · 2020 [cited by examiner]
US 20200169391A1 · Kapp et al. · 2020 [cited by applicant]
US 20200213099A1 · Wright · 2020 [cited by applicant]
US 20200213113A1 · Savanah et al. · 2020 [cited by applicant]
US 20200259638A1 · Carmignani et al. · 2020 [cited by applicant]
US 20200259651A1 · Mohassel et al. · 2020 [cited by applicant]
US 20200311678A1 · Fletcher et al. · 2020 [cited by applicant]
US 20200353167A1 · Vivek et al. · 2020 [cited by applicant]
US 20200389306A1 · Dolan · 2020 [cited by examiner]
US 20210036841A1 · Craige et al. · 2021 [cited by applicant]
US 20210049600A1 · Spector · 2021 [cited by examiner]
US 20210067345A1 · Shamai et al. · 2021 [cited by applicant]
US 20210089676A1 · Ford et al. · 2021 [cited by applicant]
US 20210090072A1 · Sewell et al. · 2021 [cited by applicant]
US 20210352054A1 · Urian · 2021 [cited by applicant]
US 20210359843A1 · Li et al. · 2021 [cited by applicant]
US 20210377049A1 · Nix · 2021 [cited by applicant]
US 20220172180A1 · Komiyama · 2022 [cited by applicant]
US 20220182235A1 · Tysor et al. · 2022 [cited by applicant]
US 20220239509A1 · Jang · 2022 [cited by examiner]
US 20220286276A1 · Li et al. · 2022 [cited by applicant]
US 20220311623A1 · Tomlinson · 2022 [cited by examiner]
US 20220321340A1 · Tsitrin · 2022 [cited by examiner]
US 20230066711A1 · Wright et al. · 2023 [cited by applicant]
US 20230361993A1 · Camenisch et al. · 2023 [cited by applicant]
US 20240054206A1 · Belgarric et al. · 2024 [cited by applicant]
JP H11239124A · 1999 [cited by applicant]
JP 2006203754A · 2006 [cited by applicant]
JP 2007124032A · 2007 [cited by applicant]
JP 2008199278A · 2008 [cited by applicant]
JP 2013513312A · 2013 [cited by applicant]
JP 2015194959A · 2015 [cited by applicant]
JP 2018005089A · 2018 [cited by applicant]
JP 2019507539A · 2019 [cited by applicant]
JP 2020516164A · 2020 [cited by applicant]
WO 9937052A1 · 1999 [cited by applicant]
WO 2015160839A1 · 2015 [cited by applicant]
WO 2017145010A1 · 2017 [cited by applicant]
WO 2018189656A1 · 2018 [cited by applicant]
WO 2019034951A1 · 2019 [cited by applicant]
WO 2019034986 · 2019 [cited by applicant]
WO 2019158209A1 · 2019 [cited by applicant]
WO 2019193452A1 · 2019 [cited by applicant]
WO 2019246206A1 · 2019 [cited by applicant]
WO 2020084418A1 · 2020 [cited by applicant]
WO 2020230695A1 · 2020 [cited by applicant]
WO 2020240319A1 · 2020 [cited by applicant]
WO 2021213959 · 2021 [cited by applicant]
WO 2021254702 · 2021 [cited by applicant]
WO 2023072502A1 · 2023 [cited by applicant]
A. Castiglione et al., “Hierarchical and Shared Access Control,” in IEEE Transactions on Information Forensics and Security, vol. 11, No. 4, pp. 850-865, Apr. 2016, doi: 10.1109/TIFS.2015.2512533. (Year: 2016). [cited by examiner]
PCT/EP2021/067673 International Search Report and Written Opinion dated Sep. 28, 2021, 13 pages. [cited by applicant]
GB2011686.9 Combined Search and Examination Report dated Apr. 22, 2021, 10 pages. [cited by applicant]
Adriano Di Luzio et al, “Arcula: A Secure Hierarchical Deterministic Wallet for Multi-asset Blockchains” section 2; Cornell University Library, 2019, pp. 6-7. [cited by applicant]
Steven Goldfeder et al, “We Securing Bitcoin wallets via threshold signatures”, 2014, URL: https://www.cs.princeton.edu/~stevenag/bitcoin_threshold_signatures.pdf sections “Threshold ECDSA signature generation” and “Thr… [cited by applicant]
Daniele Fornaro, “Elliptic Curve Hierarchical Deterministic Private Key Sequences: Bitcoin Standards and Best Practices” 2018, URL: https://www.politesi.polimi.it/bitstream/10589/140112/1/2018_04_Fornaro.pdf pp. 17-26. [cited by applicant]
Cachin Christian, “Security and Fault-tolerance in Distributed Systems—Distributed Cryptography”, Dec. 31, 2012 (Dec. 31, 2012), XP055903112, Retrieved from the Internet: URL: https://cachin.com/cc/sft12/ distcrypto.pdf… [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2105992.8 mailed on Jan. 17, 2022, 9 pages. [cited by applicant]
Damgard I., et al., “Fast Threshold ECDSA with Honest Majority”, Aug. 23, 2020, Computer Vision—ECCV2020: 16th European Conference, Proceedings; Part of the Lecture Notes in Computer Science, 35 pages. [cited by applicant]
Denis Kolegov et al: “Towards Threshold Key Exchange Protocols”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Dec. 27, 2020 (Dec. 27, 2020), XP081849900, section 2.2. [cited by applicant]
GB2101590.4 Combined Search and Examination Report dated Jul. 30, 2021,7 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2022/058085 mailed on Jul. 26, 2022, 14 pages. [cited by applicant]
Joonsang Baek et al: “Simple and efficient threshold cryptosystem from the gap diffie-hell ma n group”, GLOBECOM '03. 2003-IEEE Global Telecommunications Conference. Conference Proceedings. San Francisco, CA, Dec. 1-5, … [cited by applicant]
PCT/EP2022/050116 International Search Report and Written Opinion dated Apr. 26, 2022, 14 pages. [cited by applicant]
Pettit M. “Shared Secrets and Threshold Signatures,” May 1, 2020, [retrieved on Jun. 14, 2021], pp. 1-23, Retrieved from the Internet: URL: https://nakasendoproject.org/Threshold-Signatures-whitepaper-nchain.pdf, sectio… [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2017103.9 mailed on Jun. 28, 2021, 13 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/076686 mailed on Feb. 14, 2022, 17 pages. [cited by applicant]
Combined Search and Examination Report for Application No. GB2009062.7, mailed on Mar. 12, 2021,10 pages. [cited by applicant]
Gennaro R., et al., “Robust Threshold DSS Signatures,” International Conference on the Theory and Applications of Cryptographic Techniques, 2001, vol. 164, pp. 54-84. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/062941, mailed on Aug. 3, 2021, 14 pages. [cited by applicant]
Pramanik S., et al., “VPSS: A Verifiable Proactive Secret Sharing Scheme in Distributed Systems,” IEEE Military Communications Conference, MILCOM, Oct. 13, 2003, vol. 2, pp. 826-831, XP010698401, DOI: 10.1109/MILCOM.200… [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2111440.0 mailed on Jan. 25, 2022, 6 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2111441.8 mailed on Jan. 25, 2022, 6 pages. [cited by applicant]
Combined Search Report under Sections 17 for Application No. GB2111442.6 mailed on Jan. 25, 2022, 4 pages. [cited by applicant]
Dikshit P., et al., “Efficient Weighted Threshold ECDSA for Securing Bitcoin Wallet,” 2017 ISEA Asia Security and Privacy (ISEASP), IEEE, Jan. 29, 2017, pp. 1-9, DOI: 10.1109/ISEASP.2017.7976994. [cited by applicant]
Ewa Syta et al: “Keeping Authorities “Honest or Bust” with Decentralized Witness Cosigning”, 2016 IEEE Symposium on Security and Privacy (SP), May 1, 2016 (May 1, 2016), pp. 526-545. [cited by applicant]
Gennaro R., et al, “Fast Multiparty Threshold ECDSA with Fast Trustless Setup,” Proceedings of the 2018 ACM SIGSAC Conference on Computerand Communications Security, Oct. 2018, pp. 1179-1194. [cited by applicant]
Gennaro R., et al., “Robust Threshold DSS Signatures,” International Conference on the Theory and Applications of Cryptographic Techniques, 1996, EUROCRYPT '96 pp. 354-371. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2022/069246 mailed on Nov. 3, 2022, 15 pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/EP2022/076636, mailed Jan. 20, 2023, 12 pages. [cited by applicant]
Wuille P., “BIP 32: Hierarchical Deterministic Wallets,” Github Bitcoin BIPs, Feb. 2012, 6 pages, Retrieved from the Internet: URL: https://en.bitcoin.it/wiki/BIP_0032, Retrieved on Aug. 24, 2020. [cited by applicant]
Courtois N.T., et al., “Stealth Address and Key Management Techniques in Blockchain Systems,” Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP 2017), Feb. 21, 2017, pp.… [cited by applicant]
Boldyreva A., et al., “Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap-diffie-hellman-group Signature Scheme,” International Workshop on Public Key Cryptography, Berlin, Heidelberg: Springer … [cited by applicant]
Camenisch J., et al., “Short Threshold Dynamic Group Signatures,” International conference on security and cryptography for networks Cham: Springer International Publishing, 2020, pp. 401-423. [cited by applicant]
Hideyuki F., et al., “Updating Method of Distributed Data in Secret Sharing System,” Research Report of Computer Security (CSEC), Japan, Information Processing Society of Japan, May 15, 2014, vol. 2014-CSEC-65, No. 1, p… [cited by applicant]
Shingu T., et al., “Updating Method of Verifiable Distributed Data in the Secret Sharing Scheme,” Japan, Information Processing Society of Japan, Nov. 28, 2014, vol. 2014-CSEC-67, No. 5, pp. 1-6, 9 pages. [cited by applicant]
Office Action of Korean Application No. 10-2023-7001201 dated May 6, 2026, 9 Pages. [cited by applicant]
Office Action for Japanese Patent Application No. 2024508061, mailed Apr. 28, 2026, 6 Pages. [cited by applicant]