IP Library Granted Patent US 12,307,447
Granted Patent B2
US 12,307,447 · App. 18/368,473 · Granted May 20, 2025

Computer-implemented system and method for exchange of data

Inventor: Thomas Trevethan (London, GB)
Assignee: NCHAIN LICENSING AG
G06Q20/3829G06F16/2365G06F16/2379G06F16/2465G06Q20/0655G06Q20/1235G06Q20/38215G06Q20/3825G06Q20/3827G06Q20/389G06Q20/401G06Q30/0185G06Q30/0215G06Q40/04H04L9/008H04L9/0637H04L9/0819H04L9/0869H04L9/3066H04L9/3073H04L9/3221G06F7/725G06F2216/03G06Q2220/00H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,307,447
App. No.
18/368,473
Granted
May 20, 2025
Kind
B2
Abstract

The invention relates to a method of enabling zero-knowledge proof or verification of a statement (S) for enabling exchange of data between a prover and a verifier, wherein the prover has access to first data on a first blockchain, and the verifier has access to second data on a second blockchain. In the method, a prover sends to a verifier a set of data including a statement, which for a given function circuit output and an elliptic curve point, the function circuit input is equal to the corresponding elliptic curve point multiplier. The statement can be that the prover knows a private key for an address on a blockchain network.

Claims (45)

1. A computer-implemented method for enabling zero-knowledge proof or verification of a statement (S) for enabling exchange of data between a prover and a verifier, wherein the prover has access to first data on a first blockchain, and the verifier has access to second data on a second blockchain, the method including:

the prover generating a key-pair for the second blockchain, sending a public key (P A ) of said pair to the verifier, and retaining a private key (s_A) of said pair;

the prover receiving a verifier's public key (P B ) for the first blockchain, said verifier having generated a key-pair for the first blockchain and retaining a private key (s B ) of said pair;

the prover computing a function circuit output (h) based at least in part on a secure random number generated by the prover, and an input (P x ) corresponding to the secure random number;

the prover sending a data set to the verifier, said data set including a zero-knowledge proof statement (S), one or more commitments, the input (P x ) and the function circuit output (h), wherein the data further comprises a vanity address, and wherein the zero-knowledge proof statement (S) comprises data indicative of a pre-image of the function circuit output (h) being equal to a private key used to generate the input (P x ), wherein the vanity address is obtained from a third party, wherein the prover sends a batch of wire to form a proving key (PrK);

the prover creating a first blockchain transaction Tx A that transfers access to the first data to a common public key address (P c ), and broadcasts said transaction on a first blockchain network, said address defined by a sum of the input (P x ) and the verifier's public key (P B )

P C =P B +P x

the prover verifying a second blockchain transaction Tx B , said transaction created and broadcast on a second blockchain network by the verifier after confirming inclusion of the first blockchain transaction Tx A in the first blockchain, said transaction transferring access to the second data to the prover's public key address (P A ) that is accessible by the prover using:

a valid signature (s A ) for the prover's public key address (P A ), and

a value (x) that is the function circuit input that determines the function circuit output (h), and

the prover confirming the second blockchain transaction Tx B is included on the second blockchain and accessing the second data by providing their signature (s A ) and the value (x) that is the function circuit input of the function circuit output (h), thus enabling the verifier to observe the value (x) that is the function circuit input that determines the function circuit output (h) and access the first data by providing a signature using the private key for P C , which is s B +x from the homomorphic properties of elliptic curve point multiplication.

2. The method of claim 1 , wherein the vanity address comprises a string identifying a party.

3. A computer-implemented method according to claim 1 for enabling zero-knowledge proof or verification of a statement (S) in which a prover proves to a verifier that a statement is true while keeping a witness (w) to the statement a secret, the method including:

the prover sending to the verifier:

a statement (S) represented by an arithmetic circuit with m gates and n wires configured to implement a function circuit and determine whether for a given function circuit output (h) and an elliptic curve point (P), the function circuit input (s) to a wire of the function circuit is equal to a corresponding elliptic curve point multiplier (s);

individual wire commitments and/or a batched commitment for wires of the circuit;

a function circuit output (h); and

the proving key (PrK),

which enables the verifier to determine that the circuit is satisfied and calculate the elliptic curve point (P) and validate the statement, thus determining that the prover holds the witness (w) to the statement (S).

4. A computer-implemented method according to claim 3 , wherein the prover sends to the verifier a random value (x) for enabling the verifier to determine that the statement (S) is true and calculate the elliptic curve point (P).

5. A computer-implemented method according to claim 3 , wherein

the commitment W i is:

W i =Com ( w i , r i ),

wherein

Com is the commitment to the function circuit,

w i is the wire value,

r i is a random number—different for each wire commitment, and

i is a wire denomination,

such that

Com ( w, r )= w×G+r×F,

wherein

F and G are elliptic curve points.

6. A computer-implemented method according to claim 5 , wherein the input for the wire n in the arithmetic circuit is:

ko n =r×F+Σ i=1 n−1 w i ×K i ,

wherein

ko n is a key-opening input,

r is a random number, and

F is a point on an elliptic curve.

7. A computer-implemented method according to claim 1 , wherein the prover additionally sends a fully opened commitment to at least one wire of the function circuit.

8. A computer-implemented method according to claim 1 , wherein the statement uses only one arithmetic circuit for the function circuit.

9. A computer-implemented method according to claim 1 , wherein the function circuit implements a hash function.

10. A non-transitory computer-readable storage medium having stored thereon executable instructions that, as a result of being executed by a processor of a computer system, cause the computer system to at least perform the computer-implemented method according to claim 1 .

11. An electronic device comprising: an interface device; one or more processor(s) coupled to the interface device; a memory coupled to the one or more processor(s), the memory having stored thereon computer executable instructions which, when executed, configure the one or more processor(s) to perform the method of claim 1 .

12. A node of a blockchain network, the node configured to perform the method of claim 1 .

13. A blockchain network having a node according to claim 12 .

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2024
From: TREVETHAN, THOMAS
To: NCHAIN HOLDINGS LTD
Reel/Frame 066266/0587 →
CHANGE OF NAME Recorded Jan 26, 2024
From: NCHAIN HOLDINGS LTD
To: NCHAIN LICENSING AG
Reel/Frame 066376/0050 →
Priority Claims (3)
GB 1804739 · Mar 23, 2018 · national
GB 1804740 · Mar 23, 2018 · national
GB 1804742 · Mar 23, 2018 · national
Continuity (2)
Continuation 17040484
Related Publication 20240078541A1 · Mar 7, 2024
References Cited (66)
US 6282295B1 · Young et al. · 2001 [cited by applicant]
US 8751806B1 · Adler et al. · 2014 [cited by applicant]
US 11049128B1 · Olson · 2021 [cited by applicant]
US 11055707B2 · Lingappa · 2021 [cited by applicant]
US 11151558B2 · Ferenczi et al. · 2021 [cited by applicant]
US 11310060B1 · Poelstra et al. · 2022 [cited by applicant]
US 11496309B2 · del Pino et al. · 2022 [cited by applicant]
US 11645658B2 · Mohassel et al. · 2023 [cited by applicant]
US 11831748B1 · Fisher · 2023 [cited by examiner]
US 20070121933A1 · Futa et al. · 2007 [cited by applicant]
US 20150244525A1 · McCusker et al. · 2015 [cited by applicant]
US 20150341792A1 · Walsh et al. · 2015 [cited by applicant]
US 20160358165A1 · Maxwell · 2016 [cited by applicant]
US 20170278100A1 · Kraemer et al. · 2017 [cited by applicant]
US 20170286717A1 · Khi et al. · 2017 [cited by applicant]
US 20170346833A1 · Zhang · 2017 [cited by applicant]
US 20170366347A1 · Smith · 2017 [cited by applicant]
US 20180159689A1 · Keuffer et al. · 2018 [cited by applicant]
US 20180270065A1 · Brown et al. · 2018 [cited by applicant]
US 20190026821A1 · Bathen et al. · 2019 [cited by applicant]
US 20190034923A1 · Greco et al. · 2019 [cited by applicant]
US 20190213584A1 · Shanmugam · 2019 [cited by applicant]
US 20200053054A1 · Ma et al. · 2020 [cited by applicant]
US 20200219099A1 · Mohassel et al. · 2020 [cited by applicant]
US 20200342452A1 · Diamond · 2020 [cited by applicant]
US 20210027294A1 · Trevethan · 2021 [cited by applicant]
US 20210158342A1 · Bartolucci et al. · 2021 [cited by applicant]
FR 3097093A1 · 2020 [cited by applicant]
JP H08160857A · 1996 [cited by applicant]
WO 2016200885A1 · 2016 [cited by applicant]
WO 2017079652A1 · 2017 [cited by applicant]
WO 2017095671A1 · 2017 [cited by applicant]
WO 2018007828A2 · 2018 [cited by applicant]
WO 2023046409A1 · 2023 [cited by applicant]
Antonopoulos, “Mastering Bitcoin—Unlocking Digital Cryptocurrencies,” O'Reilly Media, Inc., Dec. 20, 2014, 282 pages. [cited by applicant]
Banasik et al., “Efficient Zero-Knowledge Contingent Payments in Cryptocurrencies Without Scripts,” European Symposium on Research in Computer Security, Sep. 15, 2016, 25 pages. [cited by applicant]
Bartok et al., “Trouble Understanding Range Proof of Greg Maxwell's Confidential Transaction,” https://crypto.stackexchange.com/questions/47392/trouble-understanding-range-proof-of-greg-maxwells-confidential-transaction… [cited by applicant]
Bootle et al., “Efficient Zero-Knowledge Arguments for Arithmetic Circuits in the Discrete Log Settings”, Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, Berlin, Hei… [cited by applicant]
Bootle et al., “Efficient Zero-Knowledge Proof Systems,” Foundations of Security Analysis and Design, Aug. 14, 2016, 32 pages. [cited by applicant]
Bowe, “Pay-to-Sudoku,” GitHub, retrieved from https://github.com/zcash-hackworks/pay-to-sudoku/blob/master/README.md, 2016, 2 pages. [cited by applicant]
Buterin, “Chain Interoperability,” Sep. 9, 2016, 25 pages. [cited by applicant]
Campanelli et al., “Zero-knowledge contingent payments revisited: Attacks and payments for services,” Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Oct. 30, 2017, 28 pages. [cited by applicant]
Chase et al., “Efficient Zero-Knowledge Proof of Algebraic and Non-Algebraic Statements with Applications to Privacy and Preserving Credentials,” Advances in Cryptology, Jul. 21, 2016, 30 pages. [cited by applicant]
Chatch, “Stellar XLM to Ethereum ETH Cross-chain Trades,” retreived from https://github.com/chatch/xcat/blob/master/docs/protocol_stellar_xlm_to_ethereum_et on Sep. 27, 2018, 4 pages. [cited by applicant]
Covaci et al., “NECTAR: Non-Interactive Smart Contract Protocol using Blockchain Technology,” arXiv preprint arXiv:1803.04860, Mar. 13, 2018, 8 pages. [cited by applicant]
Fuchsbauer et al., “Proofs on Encrypted Values in Bilinear Groups and an Applicaiton to Anonymity of Signatures,” Third International Conference on Pairing-based Cryptography, Aug. 2009, 26 pages. [cited by applicant]
Fuhr, Lessons from Vanity Zero-Knowledge Work or What to Trust the C[Ir]o[uw]d With, Confidence.org presentation, 2016, 46 pages. [cited by applicant]
Ganesh, “Zero-Knowledge Proofs: Efficient Techniques for Comnination Statements and Their Applications,” Partial PhD Dissertation, New York University, Sep. 2017, 128 pages. [cited by applicant]
Gibson, “From Zero (Knowledge) to Bulletproofs,” 2018, 48 pages. [cited by applicant]
International Search Report and Written Opinion mailed Jun. 6, 2019, Patent Application No. PCT/IB2019/052185, 14 pages. [cited by applicant]
International Search Report and Written Opinion mailed Jun. 6, 2019, Patent Application No. PCT/IB2019/052186, 13 pages. [cited by applicant]
International Search Report and Written Opinion mailed May 28, 2019 Patent Application No. PCT/IB2019/052184, 14 pages. [cited by applicant]
Jawurek et al., “Zero-Knowledge Using Garbled Circuits or How to Prove Non-Algebraic Statements Efficiently,” ACM SIGSAC conference on Computer & communications security, Nov. 2013, 23 pages. [cited by applicant]
Maxwell, “Confidential Transaction, the Initial Investigation,” Retrieved May 9, 2018 from https://elementsproject.org/features/confidential-transactions/investigation, 9 pages. [cited by applicant]
Maxwell, “The First Successful Zero-Knowledge Contingent Payment,” Bitcoin Core, retrieved from https://bitcoincore.org/en/2016/02/26/zero-knowledge-contingent-payments-announcement/, Feb. 26, 2016, 5 pages. [cited by applicant]
Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System,” Bitcoin, Oct. 31, 2008, https://bitcoin.org/bitcoin.pdf, 9 pages. [cited by applicant]
Satoshi et al., “Connection Limits,” Bitcoin Forum, Aug. 9, 2010, https://bitcointalk.org/index.php?topic=741.0; prev_next=prev, 2 pages. [cited by applicant]
UK Commercial Search Report mailed Sep. 6, 2018, Patent Application No. GB1804739.9, 9 pages. [cited by applicant]
UK IPO Search Report mailed Sep. 24, 2018, Patent Application No. GB1804739.9, 5 pages. [cited by applicant]
UK IPO Search Report mailed Sep. 24, 2018, Patent Application No. GB1804742.3, 5 pages. [cited by applicant]
UK IPO Search Report mailed Sep. 7, 2018, Patent Application No. GB1804740.7, 7 pages. [cited by applicant]
Wikipedia, “Atomic Swap,” retrieved from https://en.bitcoin.it/wiki/Atomic_swap, Dec. 2018, 3 pages. [cited by applicant]
Wikipedia, “Zero Knowledge Contingent Payment,” Bitcoin Wiki, retrieved from https://en.bitcoin.it/wiki/Zero_Knowledge_Contingent_Payment, Apr. 8, 2020, 3 pages. [cited by applicant]
Wikipedia, “Zero-Knowledge Proof,” retrieved from https://en.wikipedia.org/w/index.php?title=Zero-knowledge_proof&oldid=826583201 on May 29, 2019, 9 pages. [cited by applicant]
Zarquan et al., “How Woul I convert Committed Coordinates x and y to a Commitment of the EC POint Without Revealing the Point (in Zero Knowledge) or Vice Versa?” https://crypto.stackexchange.com/questions/52494/how-woul… [cited by applicant]
Wahby, R. S. et al.: “Double-efficient zkSNARKs without trusted setup,” Cryptology ePrint Archive, Paper 2017/1132 ver:20180209:012456, [online], Feb. 9, 2018, pp. 1-29. [cited by applicant]