IP Library › Granted Patent US 12,647,282
Granted Patent B2
US 12,647,282 · App. 18/682,087 · Granted Jun 2, 2026

Generating digital signature shares

Inventor: Michaella Pettit (London, GB)
Assignee: nChain Licensing AG
H04L9/3255H04L9/085H04L9/3242H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,282
App. No.
18/682,087
Filed
Feb 7, 2024
Granted
Jun 2, 2026
Kind
B2
Art Unit
2497
USPC
713/180
Abstract

A computer-implemented method of generating a respective signature share of a digital signature for signing a message, wherein the method is performed by a first participant of the group and comprises: obtaining at least the threshold number of respective participant indexes, wherein the obtained respective participant indexes comprises a first participant index associated with the first participant; generating a private key index, wherein the private key index is generated based on a hash of a combination of the obtained respective participant indexes; generating a second common private key of the first hierarchical key structure; and generating a first signature share of the digital signature.

Claims (44)

1 . A computer-implemented method of generating a respective signature share of a digital signature for signing a message, wherein each participant of a group of participants has i) a respective private key share of a shared private key, wherein the shared private key can only be generated with at least a threshold number of respective private key shares, ii) a respective ephemeral private key share of a shared ephemeral private key, iii) a first co-ordinate of an ephemeral public key corresponding to the shared ephemeral private key, and iv) a first common private key of a first hierarchical key structure, wherein each participant is associated with a respective participant index, and wherein the method is performed by a first participant of the group and comprises:

obtaining at least a threshold number of respective participant indexes, wherein the obtained respective participant indexes comprises a first participant index associated with the first participant;

generating a private key index, wherein the private key index is generated based on a hash of a combination of the obtained respective participant indexes;

generating a second common private key of the first hierarchical key structure, wherein the second common private key is generated based on the first common private key and a first hash value, wherein the first hash value is generated by inputting at least a) the first common private key or a corresponding public key, and b) the private key index into a hash function; and

generating a first signature share of the digital signature, wherein the first signature shared is generated based on a first ephemeral key share of the shared ephemeral private key, the message, the second common private key, the first co-ordinate of the ephemeral public key, and a first private key share of the shared private key.

2 . The method of claim 1 , wherein each participant has v) a respective share of a message-independent component, MIC, of the respective signature share, wherein each respective share of the MIC is generated based on the respective ephemeral private key share, the respective private key share and the first co-ordinate of the ephemeral public key, and wherein the first signature share is based on a first share of the MIC.

3 . The method of claim 1 , wherein the first participant is a coordinating party, and wherein the method comprises:

obtaining, from respective participants, at least the threshold number of respective signature shares of the digital signature, wherein said obtaining of the respective signature shares comprises said generating of the first signature share of the digital signature; and

generating the digital signature based on at least the obtained threshold number of respective signature shares.

4 . The method of claim 1 , comprising:

making the first signature share of the digital signature available to a coordinating party for generating the digital signature based on at least the threshold number of respective signature shares of the digital signature generated by respective participants.

5 . The method of claim 4 , wherein said obtaining of at least the threshold number of respective participant indexes comprises obtaining some of all of the respective participant indexes from the coordinating party.

6 . The method of claim 1 , wherein said obtaining of at least the threshold number of respective participant indexes comprises obtaining at least some of the respective participant indexes from the respective participants.

7 . The method of claim 1 , wherein the hash function is a HMAC function.

8 . The method of claim 7 , wherein the first common private key is associated with a first chain code, and wherein the first hash value is generated by inputting at least the first chain code, the first common private key, the private key index into the HMAC function.

9 . The method of claim 7 , wherein the first hash value is a first part of a result of inputting at least the first common private key and the private key index into the HMAC function.

10 . The method of claim 1 , wherein the first common private key is a master private key of the first hierarchal key structure.

11 . The method of claim 1 , wherein the first common private key is a private key of the first hierarchical key structure other than a master private key.

12 . The method of claim 1 , comprising:

obtaining an indication of which private key of the first hierarchical key structure is to be used as the first common private key.

13 . The method of claim 1 , wherein the first private key share of the shared private key is generated by:

obtaining a first seed share, wherein each other participant has a respective seed share;

generating a first master private key share of a shared master private key, wherein the first master private key share is generated based on the first seed share and the respective seed share of each other participant, and wherein each other participant has a respective master private key share, and wherein the first private key share is the first master private key share or one of one or more auxiliary private key shares generated based on the first master private key share.

14 . The method of claim 13 , wherein the first master private key share and each of the one or more auxiliary private key shares are arranged in a second hierarchical key structure, wherein the one or more auxiliary private key shares are respective parent private key shares, and/or respective child private key shares, wherein each parent private key share of a given level in the second hierarchical key structure is a parent to one or more child private key shares in a subsequent level in the second hierarchical key structure, and wherein the first private key share occupies a same position in the second hierarchical key structure as the second common private key in the first hierarchical key structure.

15 . The method of claim 1 , wherein each participant has a public key corresponding to the shared private key, and wherein the method comprises:

generating a second public key corresponding to the second common private key; and

generating a target public key for verifying the digital signature, wherein the target public key is generated based on the public key corresponding to the shared private key and the second public key corresponding to the second common private key.

16 . The method of claim 15 , comprising:

sending, to a verifying party, the target public key for verifying the digital signature.

17 . The method of claim 1 , comprising:

sending, to a verifying party, proof that the private key index used to generate the second common private key was generated based on the first participant index associated with the first participant, thereby proving that the first participant generated a signature share of the digital signature.

18 . The method of claim 1 , wherein the message comprises at least part of a blockchain transaction.

19 . Computer equipment comprising:

memory comprising one or more memory units; and

processing apparatus comprising one or more processing units, wherein the memory stores code arranged to run on the processing apparatus, the code being configured so as when run on the processing apparatus the processing apparatus is configured to perform a method of generating a respective signature share of a digital signature for signing a message, wherein each participant of a group of participants has i) a respective private key share of a shared private key, wherein the shared private key can only be generated with at least a threshold number of respective private key shares, ii) a respective ephemeral private key share of a shared ephemeral private key, iii) a first co-ordinate of an ephemeral public key corresponding to the shared ephemeral private key, and iv) a first common private key of a first hierarchical key structure, wherein each participant is associated with a respective participant index, and wherein the method is performed by a first participant of the group and comprises:

obtaining at least a threshold number of respective participant indexes, wherein the obtained respective participant indexes comprises a first participant index associated with the first participant;

generating a private key index, wherein the private key index is generated based on a hash of a combination of the obtained respective participant indexes;

generating a second common private key of the first hierarchical key structure, wherein the second common private key is generated based on the first common private key and a first hash value, wherein the first hash value is generated by inputting at least a) the first common private key or a corresponding public key, and b) the private key index into a hash function; and

generating a first signature share of the digital signature, wherein the first signature share is generated based on a first ephemeral key share of the shared ephemeral private key, the message, the second common private key, the first co-ordinate of the ephemeral public key, and a first private key share of the shared private key.

20 . A computer program embodied on non-transitory computer-readable storage media and configured so as, when run on one or more processors, to perform a method of generating a respective signature share of a digital signature for signing a message, wherein each participant of a group of participants has i) a respective private key share of a shared private key, wherein the shared private key can only be generated with at least a threshold number of respective private key shares, ii) a respective ephemeral private key share of a shared ephemeral private key, iii) a first co-ordinate of an ephemeral public key corresponding to the shared ephemeral private key, and iv) a first common private key of a first hierarchical key structure, wherein each participant is associated with a respective participant index, and wherein the method is performed by a first participant of the group and comprises:

obtaining at least a threshold number of respective participant indexes, wherein the obtained respective participant indexes comprises a first participant index associated with the first participant;

generating a private key index, wherein the private key index is generated based on a hash of a combination of the obtained respective participant indexes;

generating a second common private key of the first hierarchical key structure, wherein the second common private key is generated based on the first common private key and a first hash value, wherein the first hash value is generated by inputting at least a) the first common private key or a corresponding public key, and b) the private key index into a hash function; and

generating a first signature share of the digital signature, wherein the first signature share is generated based on a first ephemeral key share of the shared ephemeral private key, the message, the second common private key, the first co-ordinate of the ephemeral public key, and a first private key share of the shared private key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2024
From: PETTIT, MICHAELLA
To: NCHAIN LICENSING AG
Reel/Frame 066419/0571 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2024
From: PETTIT, MICHAELLA
To: NCHAIN LICENSING AG
Reel/Frame 066418/0335 →
Priority Claims (1)
GB 2111440 · Aug 9, 2021 · national
Continuity (1)
Related Publication 20240372732A1 · Nov 7, 2024
References Cited (127)
US 7246232B2 · Dutertre · 2007 [cited by applicant]
US 8144874B2 · McGough · 2012 [cited by applicant]
US 8806197B2 · Struik · 2014 [cited by examiner]
US 9813244B1 · Triandopoulos et al. · 2017 [cited by applicant]
US 9894151B2 · Dhuse et al. · 2018 [cited by applicant]
US 10211981B2 · Camenisch et al. · 2019 [cited by applicant]
US 10491404B1 · Yamamoto · 2019 [cited by applicant]
US 10511436B1 · Machani · 2019 [cited by applicant]
US 10764043B2 · Traynor et al. · 2020 [cited by applicant]
US 10903991B1 · Craige · 2021 [cited by examiner]
US 11323267B1 · Griffin et al. · 2022 [cited by applicant]
US 11481761B2 · Lam · 2022 [cited by examiner]
US 11563567B2 · Le Saint · 2023 [cited by applicant]
US 11637708B2 · Hung · 2023 [cited by examiner]
US 11973867B2 · Tysor et al. · 2024 [cited by applicant]
US 12309196B2 · Pettit · 2025 [cited by applicant]
US 20020116611A1 · Zhou et al. · 2002 [cited by applicant]
US 20030009694A1 · Wenocur et al. · 2003 [cited by applicant]
US 20030059041A1 · Mackenzie et al. · 2003 [cited by applicant]
US 20100037055A1 · Fazio et al. · 2010 [cited by applicant]
US 20110138192A1 · Kocher et al. · 2011 [cited by applicant]
US 20120254619A1 · Dhuse · 2012 [cited by examiner]
US 20140164769A1 · D'Souza · 2014 [cited by applicant]
US 20140325309A1 · Resch · 2014 [cited by applicant]
US 20150100781A1 · Yann et al. · 2015 [cited by applicant]
US 20150288525A1 · Camenisch et al. · 2015 [cited by applicant]
US 20170223008A1 · Camenisch et al. · 2017 [cited by applicant]
US 20170250972A1 · Ronda et al. · 2017 [cited by applicant]
US 20180060248A1 · Liu et al. · 2018 [cited by applicant]
US 20180074889A1 · Resch et al. · 2018 [cited by applicant]
US 20180101697A1 · Rane et al. · 2018 [cited by applicant]
US 20180183601A1 · Campagna et al. · 2018 [cited by applicant]
US 20180212772A1 · Leavy et al. · 2018 [cited by applicant]
US 20180307573A1 · Abraham et al. · 2018 [cited by applicant]
US 20180349867A1 · Trieflinger · 2018 [cited by applicant]
US 20180351754A1 · Wallrabenstein et al. · 2018 [cited by applicant]
US 20190007205A1 · Corduan et al. · 2019 [cited by applicant]
US 20190014124A1 · Reddy et al. · 2019 [cited by applicant]
US 20190280864A1 · Cheng et al. · 2019 [cited by applicant]
US 20190370792A1 · Lam · 2019 [cited by applicant]
US 20190372759A1 · Rix · 2019 [cited by applicant]
US 20200005290A1 · Madisetti et al. · 2020 [cited by applicant]
US 20200044863A1 · Yadlin et al. · 2020 [cited by applicant]
US 20200074450A1 · Fletcher et al. · 2020 [cited by applicant]
US 20200145231A1 · Trevethan · 2020 [cited by applicant]
US 20200153640A1 · Ranellucci · 2020 [cited by applicant]
US 20200169391A1 · Kapp et al. · 2020 [cited by applicant]
US 20200213099A1 · Wright · 2020 [cited by applicant]
US 20200213113A1 · Savanah et al. · 2020 [cited by applicant]
US 20200259638A1 · Carmignani et al. · 2020 [cited by applicant]
US 20200259651A1 · Mohassel et al. · 2020 [cited by applicant]
US 20200311678A1 · Fletcher et al. · 2020 [cited by applicant]
US 20200353167A1 · Vivek et al. · 2020 [cited by applicant]
US 20200389306A1 · Dolan et al. · 2020 [cited by applicant]
US 20210049600A1 · Spector · 2021 [cited by applicant]
US 20210067345A1 · Shamai · 2021 [cited by examiner]
US 20210089676A1 · Ford et al. · 2021 [cited by applicant]
US 20210090072A1 · Sewell · 2021 [cited by examiner]
US 20210352054A1 · Urian · 2021 [cited by applicant]
US 20210359843A1 · Li et al. · 2021 [cited by applicant]
US 20210377049A1 · Nix · 2021 [cited by applicant]
US 20220172180A1 · Komiyama · 2022 [cited by applicant]
US 20220182235A1 · Tysor et al. · 2022 [cited by applicant]
US 20220239509A1 · Jang et al. · 2022 [cited by applicant]
US 20220286276A1 · Li et al. · 2022 [cited by applicant]
US 20220311623A1 · Tomlinson · 2022 [cited by applicant]
US 20220321340A1 · Tsitrin · 2022 [cited by applicant]
US 20230066711A1 · Wright · 2023 [cited by examiner]
US 20230361993A1 · Camenisch et al. · 2023 [cited by applicant]
US 20240054206A1 · Belgarric · 2024 [cited by examiner]
JP H11239124A · 1999 [cited by applicant]
JP 2007124032A · 2007 [cited by applicant]
JP 2008199278A · 2008 [cited by applicant]
JP 2013513312A · 2013 [cited by applicant]
JP 2015194959A · 2015 [cited by applicant]
JP 2018005089A · 2018 [cited by applicant]
JP 2019507539A · 2019 [cited by applicant]
WO 9937052A1 · 1999 [cited by applicant]
WO 2015160839A1 · 2015 [cited by applicant]
WO 2017145010A1 · 2017 [cited by applicant]
WO 2018189656A1 · 2018 [cited by applicant]
WO 2019034951A1 · 2019 [cited by applicant]
WO 2019034986A1 · 2019 [cited by applicant]
WO 2019158209A1 · 2019 [cited by applicant]
WO 2019193452A1 · 2019 [cited by applicant]
WO 2019246206A1 · 2019 [cited by applicant]
WO 2020084418A1 · 2020 [cited by applicant]
WO 2021213959A1 · 2021 [cited by applicant]
WO 2021254702A1 · 2021 [cited by applicant]
WO 2023072502A1 · 2023 [cited by applicant]
Dikshit P., et al., “Efficient Weighted Threshold ECDSA for Securing Bitcoin Wallet,” 2017 ISEA Asia Security and Privacy (ISEASP), IEEE, Jan. 29, 2017, pp. 1-9, DOI: 10.1109/ISEASP.2017.7976994. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/EP2022/076636, mailed Jan. 20, 2023, 12 pages. [cited by applicant]
Cachin Christian, “Security and Fault-tolerance in Distributed Systems—Distributed Cryptography”, Dec. 31, 2012 (Dec. 31, 2012), XP055903112, Retrieved from the Internet: URL: https://cachin.com/cc/sft12/distcrypto.pdf,… [cited by applicant]
Combined Search and Examination Report for Application No. GB2009062.7, mailed on Mar. 12, 2021, 10 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2011686.9, mailed on Apr. 22, 2021, 10 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2017103.9 mailed on Jun. 28, 2021, 13 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2105992.8 mailed on Jan. 17, 2022, 9 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2111440.0 mailed on Jan. 25, 2022, 6 pages. [cited by applicant]
Combined Search Report under Sections 17 for Application No. GB2111442.6 mailed on Jan. 25, 2022, 4 pages. [cited by applicant]
Damgard I., et al., “Fast Threshold ECDSA with Honest Majority”, Aug. 23, 2020, Computer Vision—ECCV2020: 16th European Conference, Proceedings; Part of the Lecture Notes in Computer Science, 35 pages. [cited by applicant]
Denis Kolegov et al: “Towards Threshold Key Exchange Protocols”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Dec. 27, 2020 (Dec. 27, 2020), XP081849900, section 2.2. [cited by applicant]
Fornaro D., “Elliptic Curve Hierarchical Deterministic Private Key Sequences: Bitcoin Standards and BestPractices,” Master Thesis, Apr. 19, 2018, retrieved from the URL: https://www.politesi.polimi.it/bitstream/10589/14… [cited by applicant]
GB2101590.4 Combined Search and Examination Report dated Jul. 30, 2021,7 pages. [cited by applicant]
Gennaro R., et al., “Fast Multiparty Threshold ECDSA with Fast Trustless Setup,” Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Oct. 2018, pp. 1179-1194. [cited by applicant]
Gennaro R., et al., “Robust Threshold DSS Signatures,” International Conference on the Theory and Applications of Cryptographic Techniques, 1996, EUROCRYPT '96 pp. 354-371. [cited by applicant]
Gennaro R., et al., “Robust Threshold DSS Signatures,” International Conference on the Theory and Applications of Cryptographic Techniques, 2001, vol. 164, pp. 54-84. [cited by applicant]
Goldfeder S., et al., “Securing Bitcoin Wallets via Threshold Signatures,” 2014, retrieved from the URL: https://www.cs.princeton.edu/stevenag/bitcoin_threshold_signatures.pdf, sections “Threshold ECDSA Signature Genera… [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/062941, mailed on Aug. 3, 2021, 14 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/076686 mailed on Feb. 14, 2022, 17 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2022/058085 mailed on Jul. 26, 2022, 14 pages. [cited by applicant]
International Search Report and Written Opinion issued in International Application No. PCT/EP2021/067673, mailed on Sep. 28, 2021, 13 pages. [cited by applicant]
Joonsang Baek et al: “Simple and efficient threshold cryptosystem from the gap diffie-hell ma n group”, GLOBECOM '03. 2003—IEEE Global Telecommunications Conference. Conference Proceedings. San Francisco, CA, Dec. 1-5, … [cited by applicant]
Luzio A.D., et al., “Arcula: A Secure Hierarchical Deterministic Wallet for Multi-asset Blockchains,” Section 2, Dec. 10, 2019, 33 pages. [cited by applicant]
PCT/EP2022/050116 International Search Report and Written Opinion dated Apr. 26, 2022, 14 pages. [cited by applicant]
Pettit M. “Shared Secrets and Threshold Signatures,” May 1, 2020, [retrieved on Jun. 14, 2021], pp. 1-23, Retrieved from the Internet: URL: https://nakasendoproject.org/Threshold-Signatures-whitepaper-nchain.pdf, sectio… [cited by applicant]
Pramanik S., et al., “VPSS: A Verifiable Proactive Secret Sharing Scheme in Distributed Systems,” IEEE Military Communications Conference, Milcom, Oct. 13, 2003, vol. 2, pp. 826-831, XP010698401, DOI: 10.1109/ MILCOM.20… [cited by applicant]
Wuille P., “BIP 32: Hierarchical Deterministic Wallets,” Github Bitcoin BIPs, Feb. 2012, 6 pages, Retrieved from the Internet: URL: https://en.bitcoin.it/wiki/BIP_0032, Retrieved on Aug. 24, 2020. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2022/069246 dated Nov. 3, 2022, 15 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Application No. GB2111441.8 mailed on Jan. 25, 2022, 6 pages. [cited by applicant]
Ewa Syta et al: “Keeping Authorities “Honest or Bust” with Decentralized Witness Cosigning”, 2016 IEEE Symposium on Security and Privacy (SP) , May 1, 2016 (May 1, 2016), pp. 526-545. [cited by applicant]
Hideyuki F., et al., “Updating Method of Distributed Data in Secret Sharing System,” Research Report of Computer Security (CSEC), Japan, Information Processing Society of Japan, May 15, 2014, vol. 2014-CSEC-65, No. 1, p… [cited by applicant]
Shingu T., et al., “Updating Method of Verifiable Distributed Data in the Secret Sharing Scheme,” Japan, Information Processing Society of Japan, Nov. 28, 2014, vol. 2014-CSEC-67, No. 5, pp. 1-6, 9 pages. [cited by applicant]
Boldyreva A., et al., “Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap-diffie-hellman-group Signature Scheme,” International Workshop on Public Key Cryptography, Berlin, Heidelberg: Springer … [cited by applicant]
Camenisch J., et al., “Short Threshold Dynamic Group Signatures,” International conference on security and cryptography for networks Cham: Springer International Publishing, 2020, pp. 401-423. [cited by applicant]
Courtois N.T., et al., “Stealth Address and Key Management Techniques in Blockchain Systems,” Proceedings of the 3rd International Conference on Information Systems Security and Privacy (ICISSP 2017), Feb. 21, 2017, pp.… [cited by applicant]
EP Application No. 25202983.0 Extended European Search Report dated Jan. 8, 2026, 10 pages. [cited by applicant]
KR Application No. 10-2023-7013703 Office Action dated Feb. 18, 2026, 3 pages. [cited by applicant]