IP Library › Granted Patent US 12,388,633
Granted Patent B2
US 12,388,633 · App. 18/590,920 · Granted Aug 12, 2025

Techniques for single round multi-party computation for digital signatures

Inventors: Dan Yadlin (Tel-Aviv, IN); Ben Riva (Givatayim, IN); Alon Navon (Tel-Aviv, IN); Lev Pachmanov (Haifa, IL); Jonathan Katz (Silver Spring, MD)
Assignee: PAYPAL, INC.
H04L9/0861H04L9/0825H04L9/085H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,633
App. No.
18/590,920
Granted
Aug 12, 2025
Kind
B2
Abstract

A system and method for digitally signing data. A method includes generating, by a first device, at least one first secret share based on a secret key chosen by the first device, wherein the first device is offline with respect to a second device; partially signing data by the first device using the at least one secret share, wherein the data is received from the second device without establishing direct communications between the first device and the second device; and sending the partially signed data from the first device to the second device, wherein the second device generates signed data using the partially signed data, wherein the signed data corresponds to a public key generated based on the at least one first secret share and at least one second secret share generated by the second device.

Claims (42)

1. A method, comprising:

accessing data by a first device, wherein the data is accessed via an intermediary data transfer mechanism, wherein the intermediary data transfer mechanism comprises a hard drive, a memory card, a quick response (QR) code, a modem, a one-way link, a printed paper and a camera, or a scanner, and wherein the first device is offline with respect to at least a second device;

accessing, by the first device, a first secret share generated based on a first secret key;

sending, by the first device to the second device via the intermediary data transfer mechanism, at least one of: a commitment on a value that is calculated based on the first secret key or a non-interactive zero-knowledge proof of knowledge of the first secret key;

after the sending, partially signing the data, by the first device, using the first secret share; and

providing the second device access to the partially signed data at a time the first device is offline with respect to the second device;

wherein the partially signed data enables the second device to generate further signed data that corresponds to a public key generated based on a plurality of secret shares including the first secret share and a second secret share.

2. The method of claim 1 , wherein no portion of the first secret share is revealed to the second device after the partially signing the data, and wherein no portion of the second secret share is revealed to the first device due to the second device generating the further signed data.

3. The method of claim 1 , wherein the partially signed data comprises data related to a blockchain transaction.

4. The method of claim 3 , wherein the data related to a blockchain transaction comprises data corresponding to a transfer of an amount of cryptocurrency.

5. The method of claim 1 , further comprising:

wherein the further signed data is recordable onto a blockchain upon being transmitted to a plurality of computing devices associated with the blockchain.

6. The method of claim 1 , wherein the second secret share is generated based on a second secret key associated with the second device.

7. The method of claim 1 , wherein the intermediary data transfer mechanism includes a non-transitory storage medium and does not include a central processing unit (CPU).

8. The method of claim 1 , wherein the intermediary data transfer mechanism comprises a universal serial bus (USB) key.

9. The method of claim 1 , wherein the data is partially signed using a digital signature

that is generated based on the data, the first secret share, and a value determined via a deterministic key derivation process, wherein the deterministic key derivation process is known to each of the first and second devices.

10. A non-transitory computer readable medium having stored thereon machine-readable instructions that are executable to cause a first device to perform operations comprising:

accessing data via an intermediary data transfer mechanism, wherein the intermediary data transfer mechanism comprises a hard drive, a memory card, a quick response (QR) code, a modem, a one-way link, a printed paper and a camera, or a scanner, and wherein the first device is offline with respect to at least a second device;

accessing a first secret share generated based on a secret key;

sending, to the second device via the intermediary data transfer mechanism, information containing at least one of: a commitment on a value that is calculated based on the secret key, or a zero-knowledge proof associated with the secret key;

after the information has been sent, partially signing the data using the first secret share; and

providing the second device access to the partially signed data at a time the first device is offline with respect to the second device, wherein the second device is configured to generate further signed data based on the partially signed data, wherein the further signed data corresponds to a public key generated based on a plurality of secret shares including the first secret share and a second secret share.

11. The non-transitory computer readable medium of claim 10 , wherein no portion of the first secret share is revealed to the second device after the partially signing the data, and wherein no portion of the second secret share is revealed to the first device due to the second device generating the further signed data.

12. The non-transitory computer readable medium of claim 10 , wherein the partially signed data comprises data related to a blockchain transaction.

13. The non-transitory computer readable medium of claim 12 , wherein the data related to a blockchain transaction comprises data corresponding to a transfer of an amount of cryptocurrency.

14. The non-transitory computer readable medium of claim 10 , wherein the intermediary data transfer mechanism does not include a hard drive mounted internally within the first device.

15. The non-transitory computer readable medium of claim 10 , wherein the operations further comprise:

causing the further signed data to be recorded onto a blockchain.

16. A system, comprising:

a processor; and

a non-transitory computer readable medium having stored thereon machine-readable instructions that are executable to cause the system to perform operations comprising:

accessing data by a first device via an intermediary data transfer mechanism, wherein the intermediary data transfer mechanism comprises a hard drive, a memory card, a quick response (QR) code, a modem, a one-way link, a printed paper and a camera, or a scanner, and wherein the first device is offline with respect to at least a second device;

accessing a first secret share generated based on a secret key;

communicating, to the second device at least in part via the intermediate data transfer mechanism, a commitment on a value that is calculated based on the secret key, or a zero-knowledge proof associated with the secret key;

after the communicating, partially signing the data using the first secret share; and

providing the second device access to the partially signed data at a time the first device is offline with respect to the second device, wherein the second device is configured to generate further signed data based on the partially signed data, wherein the further signed data corresponds to a public key generated based on a plurality of secret shares including the first secret share and a second secret share.

17. The system of claim 16 , wherein the system comprises the first device and the second device.

18. The system of claim 16 , wherein no portion of the first secret share is revealed to the second device after the partially signing the data, and wherein no portion of the second secret share is revealed to the first device due to the second device generating the further signed data.

19. The system of claim 16 , wherein the partially signed data comprises data related to a blockchain transaction, and wherein the operations further comprise:

causing the further signed data to be recorded onto a blockchain by transmitting the further signed data to a plurality of computing devices associated with the blockchain.

20. The system of claim 16 , wherein the intermediary data transfer mechanism does not include a hard drive mounted internally within the first device or the second device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2024
From: YADLIN, DAN; RIVA, BEN; NAVON, ALON; PACHMANOV, LEV; KATZ, JONATHAN
To: CURV, LTD.
Reel/Frame 069251/0555 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2024
From: CURV, LTD
To: PAYPAL, INC.
Reel/Frame 069251/0754 →
Continuity (3)
Continuation 18177700 · Mar 2, 2023
Continuation 17019807 · Sep 14, 2020
Related Publication 20250080341A1 · Mar 6, 2025
References Cited (36)
US 10903991B1 · Craige · 2021 [cited by examiner]
US 20100153746A1 · Takeuchi · 2010 [cited by examiner]
US 20150262139A1 · Shtylman · 2015 [cited by applicant]
US 20150262171A1 · Langschaedel et al. · 2015 [cited by applicant]
US 20170155628A1 · Rohloff · 2017 [cited by examiner]
US 20180123804A1 · Smith · 2018 [cited by examiner]
US 20180205547A1 · Lindell · 2018 [cited by applicant]
US 20180357427A1 · Lindell et al. · 2018 [cited by applicant]
US 20180367316A1 · Cheng · 2018 [cited by examiner]
US 20190034919A1 · Nolan et al. · 2019 [cited by applicant]
US 20190222414A1 · Pe'Er et al. · 2019 [cited by applicant]
US 20190245857A1 · Pe'Er et al. · 2019 [cited by applicant]
US 20190280857A1 · Mishli et al. · 2019 [cited by applicant]
US 20200044863A1 · Yadlin et al. · 2020 [cited by applicant]
US 20200145231A1 · Trevethan · 2020 [cited by examiner]
US 20200226332A1 · Patil · 2020 [cited by examiner]
US 20200266997A1 · Monica et al. · 2020 [cited by applicant]
US 20200389306A1 · Dolan · 2020 [cited by examiner]
US 20220045867A1 · Beery · 2022 [cited by examiner]
CA 2949847A1 · 2015 [cited by applicant]
WO 2017145010A1 · 2017 [cited by applicant]
WO 2020053851A1 · 2020 [cited by applicant]
Damgard I., et al., “A Generalization of Paillier's Public-Key System with Applications to Electronic Voting”, International Journal of Information Security, Sep. 30, 2010, pp. 371-372. [cited by applicant]
Damgard I., et al., “A Length-Flexible Threshold Cryptosystem with Applications”, BRICS: Basic Research in Computer Science, Mar. 16, 2003, 34 pages. [cited by applicant]
Examination Search Report for Australian Application No. 2021341778, mailed on Nov. 13, 2023, 4 pages. [cited by applicant]
Feldman P., “A Practical Scheme for Non-Interactive Verifiable Secret Sharing”, FOCS: Foundations of Computer Science, 1987, 11 pages. [cited by applicant]
Gennaro R., et al., “Threshold-optimal DSA/ECDSA Signatures and an Application to Bitcoin Wallet Security”, 2016, 42 pages. [cited by applicant]
Goldfeder S., et al., “Securing Bitcoin Wallets via a new DSA/ECDSA Threshold Signature Scheme,” Retrieved from Internet URL: http://stevengoldfeder.com/papers/threshold_sigs.pdf, Retrieved on Nov. 14, 2021, 26 pages. [cited by applicant]
Haig S., “Curv Launches Offline Signing Solution After Expanding Into Asia,” Apr. 23, 2020, 3 pages. [cited by applicant]
Hazay C., et al., “Efficient RSA Key Generation and Threshold Paillier in the Two-Party Setting”, In Cryptographers Track at the RSA Conference, 2012, 51 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/IB2021/058172, mailed on Mar. 23, 2023, 7 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/IB2021/058172, mailed on Dec. 12, 2021, 9 pages. [cited by applicant]
Poupard G., et al., “Short Proofs of Knowledge for Factoring”, In International Workshop on Public Key Cryptography, 2000, 20 pages. [cited by applicant]
Gennaro Rosario et al: “One Round Threshold ECDSA with Identifiable Abort”, May 19, 2020 (May 19, 2020), XP093196161, Retrieved from the Internet: URL:https://eprint.iacr.org/2020/540.pdf * sections 1, 3, 5 *. [cited by applicant]
Choi Joseph I. et al: “Secure Multiparty Computation and Trusted Hardware: Examining Adoption Challenges and Opportunities”, Security and Communication Networks, vol. 2019, Apr. 2, 2019 (Apr. 2, 2019), pp. 1-28, XP05582… [cited by applicant]
European Patent Application No. 21866178.3, European Intellectual Property Office, Examination search report, dated Sep. 9, 2024, 6 pages. [cited by applicant]