IP Library › Granted Patent US 12,346,893
Granted Patent B2
US 12,346,893 · App. 18/199,145 · Granted Jul 1, 2025

Methods, devices, and systems for creating and managing Web3 app credentials

Inventors: Karl Jin (Keene, NH); Hoa Mai (Palo Alto, CA); Sisun Lee (Los Angeles, CA); Vinh The Nguyen (Ho Chi Minh, VN); Thanh Le (Ho Chi Minh, VN)
Assignee: RAMPER LABS, LLC
G06Q20/3674G06F21/53G06Q20/4014H04L9/0891H04L9/16H04L9/3213G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,893
App. No.
18/199,145
Granted
Jul 1, 2025
Kind
B2
Abstract

Systems, devices, and methods for creating and managing web3 app credentials, including: determining a private key and a public key; encrypting the determined private key into a plurality of separate keys; transmitting the first key to a third party provider; transmitting the second key to a cloud storage device; encrypting the first key and the second key; decrypting the second key; transmitting the decrypted second key; transmitting a transaction sign request to a secure third-party trusted execution environment; performing a user identity verification; transmitting a request to the third party provider for the first key; performing reconstruction of the original private key based on the first key and the second key; and signing a digital wallet transaction based on the reconstructed original private key received from the trusted execution environment.

Claims (62)

1. A system comprising:

a cloud storage device;

a secure third-party trusted execution environment;

a third-party provider; and

a user computing device having a processor and addressable memory, the user computing device in communication with the cloud storage device having a processor and addressable memory, the secure third-party trusted execution environment having a processor and addressable memory, and the third-party provider;

wherein the user computing device is configured to:

determine, via a Secure Web Sandbox being executed on the user computing device, a private key and a public key based on receiving a request from a user to create a digital wallet;

encrypt the determined private key into a plurality of separate keys, wherein the plurality of separate keys are split via encoding the private key into a first key and a second key;

transmit the first key to a third party provider; transmit the

second key to a cloud storage device; and

wherein the cloud storage device is configured to:

encrypt the second key via cloud encryption-at-rest;

store the encrypted second key for future retrieval and decryption; wherein the third party provider is a key management system configured to:

encrypt the first key via an individualized hardware security module encryption key; and

store the encrypted first key for future retrieval and decryption; wherein the cloud storage device is further configured to:

perform a multi-factor authentication verification based on a received request from the user computing device for the second key;

decrypt the second key based on a successful authentication, wherein the authentication is determined to be successful by a multi-factor authentication service;

transmit the decrypted second key to the user computing device;

wherein the user computing device is further configured to:

transmit a transaction sign request to the trusted execution environment wherein the request comprises transaction details and the decrypted second key;

wherein the trusted execution environment is further configured to:

perform a user identity verification;

transmit, if the user identify verification is successful, a request to the third-party provider for the first key via a secure access;

perform reconstruction of the original private key based on the first key received from the third-party provider and the second key received from the cloud storage device;

sign a digital wallet transaction based on the reconstructed original private key; and

return the signed digital wallet transaction to the user computing device; and

wherein the user computing device is further configured to: broadcast the signed transaction details, via a decentralized

application, to a blockchain.

2. The system of claim 1 further comprising an authentication system configured to provide an additional step of authenticating the user as part of the key management system.

3. The system of claim 2 , wherein the third-party provider is further configured to determine a user identity confirmation via the authentication system.

4. The system of claim 1 , wherein the multi-factor authentication service is controlled by at least one of: an authentication provider of an authentication system and a third-party entity.

5. The system of claim 1 , wherein each key of the plurality of separate keys is stored in a different location.

6. The system of claim 1 , wherein the user identity verification is further performed using an access token associated with the user, wherein the access token is a time-limited user access token.

7. The system of claim 1 , wherein the private key is a password.

8. The system of claim 1 , wherein the plurality of separate keys are split via encoding the private key into a first key, a second key, and a third key.

9. The system of claim 8 , wherein the third key is stored on at least one of: a local device and a different third-party provider.

10. The system of claim 1 , wherein biometric data is used as further authentication requirements to retrieve the first key or the second key.

11. A method comprising:

determining, by a user computing device having a processor and addressable memory, a private key and a public key based on receiving a request from a user to create a digital wallet;

encrypting, by the user computing device, the determined private key into a plurality of separate keys, wherein the plurality of separate keys are split via encoding the private key into a first key and a second key;

transmitting, by the user computing device, the first key to a third-party provider having a processor and addressable memory;

transmitting, by the user computing device, the second key to a cloud storage device having a processor and addressable memory;

encrypting, by the third-party provider executing a key management system, the first key;

storing, by the third-party provider executing the key management system, the encrypted first key for future retrieval and decryption;

encrypting, by the cloud storage device, the second key via cloud encryption-at-rest;

storing, by the cloud storage device, the encrypted second key for future retrieval and decryption;

performing, by the cloud storage device, a multi-factor authentication verification based on a received request from the user computing device for the second key;

decrypting, by the cloud storage device, the second key based on a successful authentication;

transmitting, by the cloud storage device, the decrypted second key to the user computing device;

transmitting, by the user computing device, a transaction sign request to a secure third-party trusted execution environment having a processor and addressable memory, wherein the request comprises transaction details and the decrypted second key;

performing, by the trusted execution environment, a user identity verification;

transmitting, by the trusted execution environment, if the user identify verification is successful, a request to the third-party provider for the first key;

performing, by the trusted execution environment, reconstruction of the original private key based on the first key received from the third-party provider and the second key received from the cloud storage device;

signing, by the trusted execution environment, a digital wallet transaction based on the reconstructed original private key;

returning, by the trusted execution environment, the signed digital wallet transaction to the user computing device; and

broadcasting, by the user computing device, the signed transaction details to a blockchain.

12. The method of claim 11 , wherein the user computing device is in communication with the cloud storage device, the secure third-party trusted execution environment, and the third-party provider.

13. The method of claim 11 , wherein transmitting, if the user identify verification is successful, a request to the third-party provider for the first key via a secure access.

14. The method of claim 11 , wherein determining a private key and a public key is via a Secure Web Sandbox being executed on the user computing device.

15. The method of claim 11 , wherein encrypting the first key is via an individualized hardware security module encryption key.

16. The method of claim 11 , wherein a successful authentication is determined to be successful by a multi-factor authentication service.

17. The method of claim 11 , wherein broadcasting the signed transaction details is via a decentralized application.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2026
From: RAMPER LABS, LLC
To: NINETY EIGHT COMPANY LIMITED
Reel/Frame 075568/0491 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2025
From: NGUYEN, VINH THE; LE, THANH
To: RAMPER LABS, LLC
Reel/Frame 071098/0398 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2023
From: JIN, KARL; MAI, HOA; LEE, SISUN
To: RAMPER LABS, LLC
Reel/Frame 063686/0922 →
Continuity (2)
Provisional Application 63343921 · May 19, 2022
Related Publication 20230376941A1 · Nov 23, 2023
References Cited (9)
US 10699021B2 · Oliveira et al. · 2020 [cited by applicant]
US 11943350B2 · Liu · 2024 [cited by examiner]
US 12062037B1 · Coventry · 2024 [cited by examiner]
US 20190354972A1 · Di Nicola · 2019 [cited by examiner]
US 20200111080A1 · Metcalfe · 2020 [cited by examiner]
US 20210051022A1 · Jarjoui · 2021 [cited by examiner]
US 20210143998A1 · Kuai · 2021 [cited by examiner]
US 20220035932A1 · Baldi · 2022 [cited by examiner]
Brian Spector, “What is Multi-Party Computation (MPC)?”, Jul. 2, 2021 (Year: 2021). [cited by examiner]