IP Library Granted Patent US 10,673,626
Granted Patent B2
US 10,673,626 · App. 16/237,542 · Granted Jun 2, 2020

Threshold secret share authentication proof and secure blockchain voting with hardware security modules

Inventors: William Sandberg-Maitland (Ottawa, CA); Burton George Tregub (Encino, CA)
Assignee: SPYRUS, INC.
H04L9/085G06F16/1824G06F16/1834H04L9/0643H04L9/0822H04L9/321H04L9/3247H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,626
App. No.
16/237,542
Granted
Jun 2, 2020
Kind
B2
Abstract

For an encryption-protected decentralized and replicated blockchain file storage system maintained and managed by a channel of peers, the invention creates the additional levels of trust that are needed for peer voter authentication and transaction proposal endorsement. The invention effectively excludes hostile agents from influencing or impersonating legitimate voter peers through the mathematical strength of the K-of-N mechanism based on secret sharing with cryptographic hashing. In a further embodiment an extension to nested signatures is disclosed to enforce signing order.

Claims (19)

1. A method for secure voting among M peers in a channel on an action proposal, comprising:

a) selecting a secret ;

b) dividing the secret into M unique shares by using a threshold secret sharing scheme;

c) providing M hardware security modules with secure storage and firmware;

d) provisioning each of said M hardware security modules with a distinct one of the M unique shares, and the secret , and storing said distinct unique share and secret in the hardware security module's secure storage;

e) controlling login to each said provisioned hardware security module as a function of that hardware security module's provisioned distinct unique share;

enabling calculation of a trial secret ′ as a function of that hardware security module's provisioned distinct unique share;

g) further enabling each of the M hardware security modules to compare the trial secret ′ with the stored provisioned secret and if identical, to compute a credential by concatenation of a nonce with the provisioned secret and one or more identity factors to create a concatenation value, and thereafter computing a one-way hash of the concatenation value, resulting in a KNAP credential;

h) assigning each of the provisioned and enabled hardware security modules to a distinct one of the M peers;

i) facilitating the transmission of the action proposal from one of the M peers, together with that peer's KNAP credential, identity factors, and the nonce used to compute said KNAP credential to all other peers in the channel;

j) still further enabling each of the M peers to authenticate the received action proposal using the sender's KNAP credential, and transmitted identity factors and nonce;

k) receiving a vote on the action proposal from one of the M peers; and

l) recording said vote in a distributed ledger.

2. The method of claim 1 where the firmware of the M hardware security modules can be changed by an authenticated trusted party so that the secret is maintained.

3. The method of claim 1 where the assigning step further includes authentication of the identity of each peer.

4. The method of claim 1 , where the second enabling step further comprises hashing the secret before it is concatenated with the nonce.

5. The method of claim 1 , where the one or more identity factors are chosen from the group comprising the channel object identity, the peer identification of the sender of the action proposal, a timestamp, the peer's current voting status, and an identifier for a vote.

6. The method of claim 1 , where order of voting is enforced by a nested signature message.

7. The method of claim 6 where the nested signature message comprises the KNAP credential of the provisioning step.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE SECOND CONVEYING PARTY ON THE COVER SHEET (INCORRECTLY LISTED ON THE COVER SHEET AS WILLIAM SANFORD-MAITLAND) PREVIOUSLY RECORDED ON REEL 048819 FRAME 0811. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 15, 2019
From: TREGUB, BURTON GEORGE; SANDBERG-MAITLAND, WILLIAM
To: SPYRUS, INC.
Reel/Frame 048901/0788 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2019
From: TREGUB, BURTON GEORGE; SANFORD-MAITLAND, WILLIAM
To: SPYRUS, INC.
Reel/Frame 048819/0811 →
Continuity (2)
Provisional Application 62650856 · Mar 30, 2018
Related Publication 20190305938A1 · Oct 3, 2019
Cited By (5)
US 12,190,314 US 12,321,469 US 12,430,639 US 12,483,538 US 12,718,229