IP Library Granted Patent US 12,192,352
Granted Patent B2
US 12,192,352 · App. 17/103,475 · Granted Jan 7, 2025

Key reclamation in blockchain network via OPRF

Inventors: Yacov Manevich (Haifa, IL); Nitin Gaur (Roundrock, TX); Dulce B. Ponceleon (Palo Alto, CA); Petr Novotny (Mount Kisco, NY)
Assignee: International Business Machines Corporation
H04L9/0894H04L9/0637H04L9/085H04L9/0863H04L9/0891H04L9/14H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,352
App. No.
17/103,475
Granted
Jan 7, 2025
Kind
B2
Abstract

An example operation may include one or more of encrypting a private key with an encryption key, generating a plurality of keys based on the encryption key and converting the plurality of keys into a plurality of key shares based on a secret input value, storing the encrypted private key on a blockchain, and distributing the plurality of key shares to a plurality of blockchain peers of the blockchain, where the distributing comprises transmitting a different key share from among the plurality of key shares to each blockchain peer among the plurality of blockchain peers.

Claims (59)

1. An apparatus comprising:

a processor that, when executing instructions stored in an associated memory, is configured to:

encrypt, via a client application, a private key with an encryption key,

generate a plurality of keys based on the encryption key,

convert the plurality of keys into a plurality of key shares based on a secret input value that is received from and known only to a user of the client application,

store the encrypted private key in a blockchain comprising a plurality of peers via a blockchain transaction,

transmit a different key share of the plurality of key shares to each blockchain peer of the plurality of peers;

wherein a minimum number of corresponding different key shares is received from the plurality of peers;

wherein the secret input value from the user is received; and

wherein the encryption key is recovered based on an execution of an oblivious pseudorandom function (OPRF).

2. The apparatus of claim 1 , wherein the plurality of keys comprises a plurality of pseudorandom values; and

wherein the processor is further configured to:

register the plurality of pseudorandom values with corresponding ones of the plurality of blockchain peers.

3. The apparatus of claim 1 , wherein, when the processor converts the plurality of keys into the plurality of key shares, the processor is further configured to:

convert the plurality of keys into corresponding key shares based on the oblivious pseudorandom function (OPRF) that uses the plurality of keys and the secret input value to generate the corresponding key shares.

4. The apparatus of claim 3 , wherein, when the processor converts the plurality of keys into the plurality of key shares, the processor is further configured to:

iteratively execute the OPRF for each key of the plurality of keys based on the secret input value to generate the corresponding key shares.

5. The apparatus of claim 1 , wherein the secret input value comprises a password.

6. The apparatus of claim 1 , wherein the processor is configured to:

distribute the blockchain transaction to the plurality of blockchain peers, where the blockchain transaction further comprises a payment value.

7. The apparatus of claim 1 , wherein the processor is further configured to:

decrypt a fee transaction that is stored by the plurality of peers using the recovered encryption key,

transmit the decrypted fee transaction to the plurality of peers,

in response to the plurality of peers receiving the decrypted fee transaction, receive the encrypted private key from a peer of the plurality of peers, and

decrypt the encrypted private key based on the recovered encryption key.

8. A method comprising:

encrypting, via a client application, a private key with an encryption key;

generating a plurality of keys based on the encryption key;

converting the plurality of keys into a plurality of key shares based on a secret input value that is received from and known only to a user of the client application;

storing the encrypted private key in a blockchain comprising a plurality of peers via a blockchain transaction;

transmitting a different key share of the plurality of key shares to each blockchain peer of the plurality of peers;

wherein a minimum number of corresponding different key shares is received from the plurality of peers;

wherein the secret input value from the user is received; and

wherein the encryption key is recovered based on an execution of an oblivious pseudorandom function (OPRF).

9. The method of claim 8 , wherein the plurality of keys comprise a plurality of pseudorandom values, and

wherein the method further comprises:

registering the plurality of pseudorandom values with corresponding ones of the plurality of blockchain peers.

10. The method of claim 8 , wherein the converting further comprises:

converting the plurality of keys into corresponding key shares based on an oblivious pseudorandom function (OPRF) that uses the plurality of keys and the secret input value to generate the corresponding key shares.

11. The method of claim 10 , wherein the converting further comprises:

iteratively executing the OPRF for each key of the plurality of keys based on the secret input value to generate the corresponding key shares.

12. The method of claim 8 , wherein the secret input value comprises a password.

13. The method of claim 8 , further comprising:

distributing the blockchain transaction to the plurality of blockchain peers, where the blockchain transaction further comprises a payment value.

14. The method of claim 8 , further comprising:

decrypting a fee transaction that is stored by the plurality of peers using the recovered encryption key;

transmitting the decrypted fee transaction to the plurality of peers

in response to the plurality of peers receiving the decrypted fee transaction, receiving the encrypted private key from a peer of the plurality of peers; and

decrypting the encrypted private key based on the recovered encryption key.

15. A non-transitory computer-readable medium comprising instructions that, when executed by a processor, cause the processor to perform:

encrypting, via a client application, a private key with an encryption key;

generating a plurality of keys based on the encryption key; converting the plurality of keys into a plurality of key shares based on a secret input value that is received from and known only to a user of the client application;

storing the encrypted private key in a blockchain comprising a plurality of peers via a blockchain transaction

transmitting a different key share of the plurality of key shares to each blockchain peer of the plurality of peers;

wherein a minimum number of corresponding different key shares is received from the plurality of peers;

wherein the secret input value from the user is received; and

wherein the encryption key is recovered based on an execution of an oblivious pseudorandom function (OPRF).

16. The non-transitory computer-readable medium of claim 15 , wherein the converting further comprises:

converting the plurality of keys into corresponding key shares based on the oblivious pseudorandom function (OPRF) that uses the plurality of keys and the secret input value to generate the corresponding key shares.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2020
From: MANEVICH, YACOV; GAUR, NITIN; PONCELEON, DULCE B.; NOVOTNY, PETR
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 054462/0167 →
Continuity (1)
Related Publication 20220166616A1 · May 26, 2022
References Cited (25)
US 9407431B2 · Bellare et al. · 2016 [cited by applicant]
US 9413735B1 · Hird · 2016 [cited by applicant]
US 10601585B1 · Robinson · 2020 [cited by examiner]
US 20050240591A1 · Marceau · 2005 [cited by examiner]
US 20160212109A1 · Hird · 2016 [cited by examiner]
US 20170221055A1 · Carlsson · 2017 [cited by examiner]
US 20180130130A1 · Dechu · 2018 [cited by examiner]
US 20180336553A1 · Brudnicki · 2018 [cited by examiner]
US 20190080321A1 · Mundis · 2019 [cited by examiner]
US 20190280860A1 · Peddada · 2019 [cited by examiner]
US 20190296896A1 · Resch · 2019 [cited by examiner]
US 20190342084A1 · Mehedy et al. · 2019 [cited by applicant]
US 20200036523A1 · Patin · 2020 [cited by examiner]
US 20200127835A1 · Fletcher · 2020 [cited by examiner]
US 20210109825A1 · Liao · 2021 [cited by examiner]
US 20210135855A1 · Sunkavally · 2021 [cited by examiner]
US 20220103532A1 · Manevich · 2022 [cited by examiner]
CN 107623569A · 2018 [cited by applicant]
CN 111507710A · 2020 [cited by applicant]
CN 110929290B · 2022 [cited by applicant]
WO WO2018109010A1 · 2018 [cited by examiner]
WO 2020143246A1 · 2020 [cited by applicant]
Aydara el al., “Private key encryption and recovery in blockchain” Jun. 25, 2020 ; https://doi.org/10.48550/arXiv.1907.04156, Cryptography and Security (cs.CR); Distributed, Parallel, and Cluster Computing (cs.DC) pp. 1… [cited by examiner]
Ra et al., “A Key Recovery System Based on Password-Protected Secret Sharing in a Permissioned Blockchain,” CMC—Computers Materials & Continua 65, No. 1 (2020): 153-170; accepted Jun. 8, 2020. [cited by applicant]
ISR issued in the international application No. PCT/CN2021/125947, mailed Jan. 28, 2022. [cited by applicant]