IP Library Granted Patent US 12,218,922
Granted Patent B2
US 12,218,922 · App. 18/367,404 · Granted Feb 4, 2025

Methods and devices for increasing entropy of a blockchain using blinded outcome diversification

Inventors: Silvia Bartolucci (London, GB); Pauline Bernat (London, GB); Daniel Joseph (London, GB); Craig Steven Wright (London, GB)
Assignee: NCHAIN LICENSING AG
H04L63/0464H04L9/16H04L63/0478H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,922
App. No.
18/367,404
Granted
Feb 4, 2025
Kind
B2
Abstract

An implementation of the present application provides a computer-implemented method to increase the security of a blockchain-implemented transaction, the transaction including participation from a plurality of participating nodes, each participating node participating as a message originator, selector, and propagator. The method, implemented at a participating node, includes: receiving ciphertext from a prior node and determining whether the participating node is a selector node for said ciphertext received from the prior node. When the participating node is the selector node for said ciphertext, the method includes selecting a subset of said ciphertext, decrypting the selected subset of said ciphertext to provide opted ciphertext and transmitting said opted ciphertext to the next node. When the participating node is other than the selector node for said ciphertext, the method includes decrypting said ciphertext received from the prior node and transmitting the decrypted ciphertext to the next node.

Claims (35)

1. A computer-implemented method to increase security of a blockchain-implemented transaction, in a network comprising a dealer node, and a plurality of participating nodes each having its own public key and private key, the method comprising:

for each of a plurality of cycles, obtaining a set of output addresses by:

at a dealer node, ordering said participating nodes such that there exists a cycle node order, designating a first node in the node order as a message originator, and the last node as a propagator, and designating one of the remaining participating nodes as a selector, wherein each node is not the message originator in more than one cycle node order, and each node is not the propagator in more than one cycle order, and designating one of said participating nodes as a selector node;

at the message originator, generating ciphertext comprising a nested encrypted first message and a nested encrypted second message, each message comprising one or more transaction details, and transmitting said ciphertext to a next participating node in said cycle node order, wherein:

each one of the transaction details comprises a transaction amount and an output address, and

for each cycle, the sum of the transaction amounts in the first message is equal to the sum of the transaction amounts in the second message;

transmitting said ciphertext from node to node in said cycle node order, each node decrypting the ciphertext before transmitting it, wherein the selector additionally removes one of the nested encrypted messages from the ciphertext before transmitting it; and

at the propagator, decrypting the remaining single message to obtain the one or more transaction details contained in the message;

at all the nodes designated as propagator, generating a shuffled order of the transaction details obtained from all the cycles; and

generating a blockchain transaction wherein each output of the transaction is based on one of the transaction details, and the outputs are ordered according to the shuffled order.

2. The computer-implemented method of claim 1 , wherein said step of generating a shuffled order comprises:

at each of said propagators, encrypting each one of the transaction details obtained in its respective cycle using its public key, adding it to a shuffled set of encrypted transaction details, and shuffling the set.

3. The computer-implemented method of claim 2 , further comprising the step of:

at each of said propagators except the last, encrypting the shuffled set with the public key of another propagator and transmitting the encrypted set to that propagator.

4. The computer-implemented method of claim 1 , wherein for each cycle, said step of generating ciphertext at each message originator comprises:

generating the first message and the second message; and

successively encrypting each message using a transaction public key for the cycle and an ordered list of the public keys of the other participating nodes to generate two nested encrypted messages.

5. The computer-implemented method of claim 4 , further comprising:

for each cycle, at said dealer node, providing said transaction public key for the cycle and said ordered list of node public keys to the message originator, wherein said ordered list is in the reverse order to the cycle node order.

6. The computer-implemented method of claim 5 , further comprising:

for each cycle, at each said propagator node, generating a transaction public key for the cycle and a corresponding transaction private key for the cycle, and transmitting the transaction public key to said dealer node.

7. The computer-implemented method of claim 6 , wherein for each cycle, said step of decrypting said nested message at said propagator comprises decrypting it with the private key of the propagator and then decrypting it with the transaction private key for the cycle.

8. A network of computing devices, each computing device being one of a plurality of participating nodes or a dealer node, each computing device comprising:

a network interface to provide network connectivity to at least one other participating node in the plurality of participating nodes;

a processor; and

a memory storing non-transitory computer-executable instructions that, if executed by the processor, cause the processor to:

for each of a plurality of cycles, obtain a set of output addresses by:

as a dealer node, order said participating nodes such that there exists a cycle node order, designate a first node in the node order as a message originator, and the last node as a propagator, and designate one of the remaining participating nodes as a selector, wherein each node is not the message originator in more than one cycle node order, and each node is not the propagator in more than one cycle order, and designate one of said participating nodes as a selector node;

as a message originator for the cycle, generate ciphertext comprising a nested encrypted first message and a nested encrypted second message, each message comprising one or more transaction details, and transmit said ciphertext to a next participating node in said cycle node order, wherein:

each one of the transaction details comprises a transaction amount and an output address; and

for each cycle, the sum of the transaction amounts in the first message is equal to the sum of the transaction amounts in the second message;

transmit said ciphertext from node to node in said cycle node order, decrypting the ciphertext before transmitting it, and as a selector additionally remove one of the nested encrypted messages from the ciphertext before transmitting it; and

as a propagator for a cycle, decrypt the remaining single message to obtain the one or more transaction details contained in the message;

as a propagator, generate a shuffled order of the transaction details obtained from all the cycles; and

as one of the propagators, generate a blockchain transaction wherein each output of the transaction is based on one of the transaction details, and the outputs are ordered according to the shuffled order.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: BARTOLUCCI, SILVIA; BERNAT, PAULINE; JOSEPH, DANIEL
To: NCHAIN HOLDINGS LTD.
Reel/Frame 064883/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: WRIGHT, CRAIG STEVEN
To: NCHAIN HOLDINGS LTD.
Reel/Frame 064883/0134 →
CHANGE OF NAME Recorded Sep 12, 2023
From: NCHAIN HOLDINGS LTD
To: NCHAIN LICENSING AG
Reel/Frame 064883/0341 →
Priority Claims (1)
GB 1714907 · Sep 15, 2017 · national
Continuity (3)
Continuation 17570297 · Jan 6, 2022
Continuation 16647111
Related Publication 20240121229A1 · Apr 11, 2024
References Cited (18)
US 20170085562A1 · Schultz · 2017 [cited by examiner]
US 20180076955A1 · Shields · 2018 [cited by examiner]
US 20200127835A1 · Fletcher · 2020 [cited by examiner]
WO 2015179020A2 · 2015 [cited by applicant]
Anonymous, “Bips/bip-dandelion.mediawiki,” GitHub, retrieved from https://github.com/dandelion-org/bips/blob/eaaccf89f3674d64a5ca6f2d433660a7667bee80/bip-dandelion.mediawiki, May 9, 2018, 9 pages. [cited by applicant]
Anonymous, “Lightning Network,” Bitcoin Wiki, Jul. 3, 2017, https://web.archive.org/web/20170729010627/https://en.bitcoin.it/wiki/Lightning_Network, 4 pages. [cited by applicant]
Antonopoulos, “Mastering Bitcoin—Unlocking Digital Cryptocurrencies,” O'Reilly Media, Inc., Dec. 20, 2014, 282 pages. [cited by applicant]
Bojja et al., “Dandelion: Redesigning the Bitcoin Network for Anonymity,” Jan. 16, 2017, 19 pages. [cited by applicant]
International Search Report and Written Opinion mailed Nov. 12, 2018, Patent Application No. PCT/IB2018/056906, 12 pages. [cited by applicant]
Miller et al., “bips/bip-dandelion.mediawiki,” GitHub, Jun. 10, 2017, https://github.com/gfanti/bips/blob/master/bip-dandelion.mediawiki, 8 pages. [cited by applicant]
Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System,” Bitcoin, Oct. 31, 2008, https://bitcoin.org/bitcoin.pdf, 9 pages. [cited by applicant]
Satoshi et al., “Connection Limits,” Bitcoin Forum, Aug. 9, 2010, https://bitcointalk.org/index.php?topic=741.0;prev_next=prev, 2 pages. [cited by applicant]
Shentu et al., “Transaction Remote Release (TRR): A New Anonymization Technology for Bitcoin,” arXiv preprint arXiv:1509.06160, Sep. 21, 2015. 18 pages. [cited by applicant]
Sun et al., “RingCT 2.0: A Compact Accumulator-Based (Linkable Ring Signature) Protocol for Blockchain Cryptocurrency Monero,” European Symposium on Research in Computer Security, Sep. 11, 2017, https://eprint.iacr.org/… [cited by applicant]
UK Commercial Search Report mailed Jan. 26, 2017, Patent Application No. GB1714907.1, 5 pages. [cited by applicant]
UK IPO Search Report mailed Feb. 13, 2018, Patent Application No. GB1714907.1, 8 pages. [cited by applicant]
Venkatakrishnan et al., “Dandelion: Redesigning the Bitcoin Network for Anonymity,” Proceedings of the ACM on Measurement and Analysis of Computing Systems 1(1):1-34, Jun. 13, 2017. [cited by applicant]
Ziegeldorf et al., “CoinParty: Secure Multi-Party Mixing of Bitcoins,” Proceedings of the 5th ACM Conference on Data and Application Security and Privacy, Mar. 2, 2015, 12 pages. [cited by applicant]