IP Library › Granted Patent US 12,609,838
Granted Patent B2
US 12,609,838 · App. 18/533,090 · Granted Apr 21, 2026

Digital signatures

Inventor: Michaella Pettit (London, GB)
Assignee: nChain Licensing AG
H04L9/3257H04L9/085H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,838
App. No.
18/533,090
Granted
Apr 21, 2026
Kind
B2
Abstract

A computer-implemented method of generating a share of a digital signature of a message, wherein a threshold number of different signature shares from respective participants of a group of participants are required to generate the digital signature, wherein each participant has a respective private key share, the method being performed by a first one of the participants and comprising: generating a first message-independent component and a first message-dependent component, wherein the message-independent component is generated based on a first private key share and wherein the message-dependent component is generated based on the message; causing the first message-independent component to be made available to a coordinator; and causing a first signature share to be made available to the coordinator for generating the signature based on at least the threshold number of signature shares, wherein the first signature share comprises at least the message-dependent component.

Claims (29)

1 . A method of jointly generating a digital signature by distributed nodes in a computing network, the computing network including a set of at least 2t+1 nodes including a first node and a coordinating node, wherein the digital signature is generated by the coordinating node through joint participation of at least t+1 of the nodes in the set, where t>1, the method including a signature phase that comprises:

receiving, by the first node, a request for a signature share from the coordinating node;

calculating, by the first node, the signature share, wherein the first node does not receive communications relating to generation of the digital signature from any other nodes of the set during the signature phase except for the coordinating node; and

transmitting, by the first node, the signature share to the coordinating node to enable the coordinating node to generate the digital signature through interpolation of respective signature shares received from the at least t nodes, but fewer than 2t nodes, of the nodes in the set.

2 . The method claimed in claim 1 , wherein the first node does not receive a communication relating to generation of the digital signature from the coordinating node other than the request during the signature phase.

3 . The method claimed in claim 2 , wherein the first node does not receive any communication from the coordinating node during the signature phase other than the request.

4 . The method claimed in claim 1 , wherein the signature phase starts with transmission of the request by the coordinating node.

5 . The method claimed in claim 1 , wherein the first node does not employ joint verifiable random secret sharing during the signature phase.

6 . The method claimed in claim 1 , wherein the first node does not perform a zero knowledge proof during the signature phase.

7 . The method claimed in claim 1 , wherein the first node does not use homomorphic encryption during the signature phase.

8 . The method claimed in claim 1 , wherein the calculating the signature share includes hashing a message to generate a message digest and calculating the signature share using the message digest and a pre-signature share stored at the first node.

9 . The method claimed in claim 8 , wherein the pre-signature share is an intermediary value minus a blinding secret share.

10 . The method claimed in claim 1 , further comprising a pre-signature phase prior to the signature phase, wherein the pre-signature phase includes jointly generating and verifying at least three secret shares with the at least t nodes of the set.

11 . The method claimed in claim 10 , wherein the at least three secret shares include a private key share, an ephemeral key share, and a blinding secret share.

12 . The method claimed in claim 11 , wherein jointly generating and verifying includes using joint verifiable random secret sharing.

13 . A computing device implementing a first node in a computing network for jointly generating a digital signature, the computing network including a set of at least 2t+1 nodes including the first node and a coordinating node, wherein the digital signature is generated by the coordinating node through joint participation of at least t+1 of the nodes in the set, where t>1, the computing device comprising:

one or more processing units; and

memory storing processor-executable instructions that, when executed by the one or more processing units, are to cause the one or more processing units to, during a signature phase:

receive, by the first node, a request for a signature share from the coordinating node;

calculate the signature share, wherein the first node does not receive communications relating to generation of the digital signature from any other nodes of the set during the signature phase except for the coordinating node; and

transmit the signature share to the coordinating node to enable the coordinating node to generate the digital signature through interpolation of respective signature shares received from the at least t nodes, but fewer than 2t nodes, of the nodes in the set.

14 . The computing device claimed in claim 13 , wherein the first node does not receive a communication relating to generation of the digital signature from the coordinating node other than the request during the signature phase.

15 . The computing device claimed in claim 14 , wherein the first node does not receive any communication from the coordinating node during the signature phase other than the request.

16 . The computing device claimed in claim 13 , wherein the instructions, when executed, are to cause the one or more processing units to calculate the signature share by at least hashing a message to generate a message digest and calculating the signature share using the message digest and a pre-signature share stored at the first node.

17 . The computing device claimed in claim 16 , wherein the pre-signature share is an intermediary value minus a blinding secret share.

18 . A computer-readable storage medium having stored thereon processor-executable instructions for jointly generating a digital signature by distributed nodes in a computing network, the computing network including a set of at least 2t+1 nodes including a first node and a coordinating node, wherein the digital signature is generated by the coordinating node through joint participation of at least t+1 of the nodes in the set, where t>1, and wherein the instructions, when executed by one or more processors, are to cause the one or more processors to, during a signature phase:

receive, by the first node, a request for a signature share from the coordinating node;

calculate the signature share, wherein the first node does not receive communications relating to generation of the digital signature from any other nodes of the set during the signature phase except for the coordinating node; and

transmit the signature share to the coordinating node to enable the coordinating node to generate the digital signature through interpolation of respective signature shares received from the at least t nodes, but fewer than 2t nodes, of the nodes in the set.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2023
From: PETTIT, MICHAELLA
To: NCHAIN LICENSING AG
Reel/Frame 065809/0286 →
Continuity (3)
Continuation 17464351 · Sep 1, 2021
Provisional Application 63074564 · Sep 4, 2020
Related Publication 20240121109A1 · Apr 11, 2024
References Cited (39)
US 7434046B1 · Srivastava · 2008 [cited by applicant]
US 8392716B2 · Oishi · 2013 [cited by examiner]
US 8490164B2 · Takahashi et al. · 2013 [cited by applicant]
US 9680654B2 · Lam · 2017 [cited by examiner]
US 11063754B2 · Vakili · 2021 [cited by examiner]
US 11716617B2 · Wentz · 2023 [cited by examiner]
US 11979507B2 · Fletcher et al. · 2024 [cited by applicant]
US 12107955B2 · Savanah et al. · 2024 [cited by applicant]
US 12192381B2 · Beery et al. · 2025 [cited by applicant]
US 12238222B2 · Wright et al. · 2025 [cited by applicant]
US 12254452B2 · Wright et al. · 2025 [cited by applicant]
US 20080270790A1 · Brickell et al. · 2008 [cited by applicant]
US 20100215172A1 · Schneider · 2010 [cited by applicant]
US 20110208970A1 · Brown · 2011 [cited by examiner]
US 20140325227A1 · Brown · 2014 [cited by examiner]
US 20160301526A1 · Rietman et al. · 2016 [cited by applicant]
US 20170324548A1 · Anshel et al. · 2017 [cited by applicant]
US 20180367298A1 · Wright et al. · 2018 [cited by applicant]
US 20200084048A1 · Lindell et al. · 2020 [cited by applicant]
US 20200274704A1 · Matsui et al. · 2020 [cited by applicant]
US 20210111875A1 · Le Saint · 2021 [cited by examiner]
US 20230015219A1 · Lam · 2023 [cited by applicant]
US 20230163977A1 · Pettit · 2023 [cited by applicant]
CN 108964906A · 2018 [cited by applicant]
WO 2017145010A1 · 2017 [cited by applicant]
WO 2019166915A1 · 2019 [cited by applicant]
WO 2019193452A1 · 2019 [cited by applicant]
Dalskov A., et al., “Securing DNSSEC Keys via Threshold ECDSAfrom Generic MPC,” IACR, International Association for Cryptologic Research, Aug. 5, 2019, vol. 20190805, No. 221846, pp. 1-24, XP061 033215, Retrieved from t… [cited by applicant]
Dikshit P., et al., “Efficient Weighted Threshold ECDSA for Securing Bitcoin Wallet,” 2017 ISEA Asia Security and Privacy (ISEASP), IEEE, Jan. 29, 2017, pp. 1-9, DOI: 10.1109/ISEASP.2017.7976994. [cited by applicant]
Gennaro R., et al., “Fast Multiparty Threshold ECDSA with Fast Trustless Setup,” Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Oct. 2018, pp. 1179-1194. [cited by applicant]
Gennaro R., et al., “Robust Threshold DSS Signatures,” International Conference on the Theory and Applications of Cryptographic Techniques, 2001, vol. 164, pp. 54-84. [cited by applicant]
Green M., et al., “Strength in Numbers: Threshold ECDSA to Protect Keys in the Cloud,” International Association for Cryptologic Research, Dec. 5, 2015, vol. 20151205, No. 042955, pp. 1-19. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/060032, mailed on Sep. 9, 2021, 15 pages. [cited by applicant]
Catrina O., et al., “Fostering the Uptake of Secure Multiparty Computation in E-Commerce,” 2008 Third International Conference on Availability, Reliability and Security (ARES 08), Mar. 4, 2008, XP031257563, pp. 693-700. [cited by applicant]
Gennaro R., et al., “Threshold-optimal DSA/ECDSA Signatures and an Application to Bitcoin Wallet Security,” LNSC, Applied Cryptography and Network Security (ACNS2016), Jun. 9, 2016, vol. 9696, pp. 156-174. [cited by applicant]
Boneh D., et al., “Using Level-1 Homomorphic Encryption to Improve Threshold DSA Signatures for Bitcoin Wallet Security,” In: Lange T., and Dunkelman O., (Eds.): Progress in Cryptology—LATINCRYPT, 2017, Lecture Notes in… [cited by applicant]
Goldfeder S., et al., “Securing Bitcoin Wallets via a New DSA/ECDSA Threshold Signature Scheme,” cs.princeton.edu, Mar. 8, 2015, pp. 1-26, Retrieved from the Internet: URL: https://www.cs.princeton.edu/˜stevenag/thresho… [cited by applicant]
Mackenzie P., et al., “Two-party Generation of DSA Signatures,” Advances in Cryptology—CRYPTO, Aug. 2001, 18 pages. [cited by applicant]
Mackenzie P., et al., “Two-party generation of DSA signatures,” International journal of security, Jul. 21, 2004, vol. 2, pp. 218-239. [cited by applicant]