IP Library Granted Patent US 12,445,287
Granted Patent B2
US 12,445,287 · App. 17/603,332 · Granted Oct 14, 2025

Computer implemented method and system for knowledge proof in blockchain transactions

Inventors: Craig Steven Wright (London, GB); Alexander Tennyson Mackay (London, GB); Wei Zhang (London, GB)
Assignee: NCHAIN LICENSING AG
H04L9/3218H04L9/0825H04L9/50H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,287
App. No.
17/603,332
Granted
Oct 14, 2025
Kind
B2
Abstract

A method of enabling knowledge proof in a blockchain transaction is disclosed. The method comprises sending, from a verifier to a prover, a blockchain transaction redeemable by means of data including (i) first data (y) based on a combination of an ephemeral key (r), second data (c) and a private key of a public-private key pair of a cryptography system, wherein the public key (v) is based on an integer generator raised to a first power, wherein the first power is based on the private key, and wherein knowledge of the private key is required in order to determine the ephemeral key from the first data, and (ii) third data (x) based on the integer generator raised to a second power, wherein the second power is based on the ephemeral key.

Claims (31)

1. A method of enabling knowledge proof in a blockchain transaction, the method comprising:

generating, at a verifier computing system, a first blockchain transaction comprising a locking script, the locking script comprising:

(i) fourth data based on a public key of a public-private key pair of a cryptography system,

(ii) second data, and

(iii) a prime number shared between the verifier computing system and a prover computing system that are outside of a blockchain network, and wherein the prime number is used in computation of intermediate results to validate the first blockchain transaction;

wherein the first blockchain transaction is redeemable by means of a second blockchain transaction comprising an unlocking script, the unlocking script including:

(i) first data based on a combination of an ephemeral key, the second data and a private key of the public-private key pair of the cryptography system, wherein the public key of the public-private key pair of the cryptography system is based on an integer generator raised to a first power, wherein the first power is based on the private key, and

(ii) third data based on the integer generator raised to a second power that is different than the first power, wherein the second power is based on the ephemeral key;

transmitting, by the verifier computing system, the first blockchain transaction to the blockchain network for validation; and

responsive to receiving an indication of a success validation of the first blockchain transaction by the blockchain network, generating the second blockchain transaction to enable redemption of the first blockchain transaction on the blockchain network, the second blockchain transaction being generated by the prover computing system and the redemption of the first blockchain transaction is performed on the blockchain network based on modular arithmetic operations,

wherein execution of the locking and unlocking scripts on the blockchain network functions as a proof of knowledge that the prover computing system possesses the private key of the public-private key pair, and

wherein the public key, components of the first data, the fourth data, and the intermediate results are pre-computed off-chain.

2. The method according to claim 1 , wherein the integer generator is 2.

3. The method according to claim 1 , wherein the second data is provided by the verifier computing system.

4. The method according to claim 1 , further comprising:

sending, at the verifier computing system, the second data to the prover computing system separately from the first blockchain transaction.

5. The method according to claim 1 , wherein the first data is of the form:

y=r+s·c mod q,

where y is the first data, r is the ephemeral key, s the private key, c is the second data and q is prime.

6. The method according to claim 1 , wherein the second data is provided based on a message.

7. The method according to claim 6 , wherein the message includes data for implementing a smart contract.

8. The method according to claim 6 , wherein the second data is of the form:

c=H ( x∥m )mod q

where c is the second data, x is the third data, m is the message, q is prime and H is a hash function.

9. The method according to claim 6 , further comprising:

receiving, at the verifier computing system, the message.

10. The method according to claim 1 , wherein the ephemeral key is shared between the verifier and the prover computing systems.

11. The method according to claim 1 , further comprising:

receiving, by the verifier computing system, said public key.

12. The method according to claim 1 , further comprising:

receiving, by the verifier computing system, said first data and said second data.

Assignments (3)
CHANGE OF NAME Recorded Feb 3, 2025
From: NCHAIN HOLDINGS AG
To: NCHAIN LICENSING AG
Reel/Frame 070096/0502 →
CHANGE OF NAME Recorded Apr 17, 2023
From: NCHAIN HOLDINGS LTD
To: NCHAIN LICENSING AG
Reel/Frame 063349/0350 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2021
From: WRIGHT, CRAIG STEVEN; MACKAY, ALEXANDER TENNYSON; ZHANG, WEI
To: NCHAIN HOLDINGS LIMITED
Reel/Frame 057795/0424 →
Priority Claims (1)
GB 1905198 · Apr 12, 2019 · national
Continuity (1)
Related Publication 20220278843A1 · Sep 1, 2022
References Cited (25)
US 4995082A · Schnorr · 1991 [cited by applicant]
US 10050779B2 · Alness et al. · 2018 [cited by applicant]
US 11310060B1 · Poelstra · 2022 [cited by examiner]
US 11481841B2 · Robotham · 2022 [cited by examiner]
US 20180096313A1 · Chenard · 2018 [cited by examiner]
US 20220368538A1 · Gauthier · 2022 [cited by examiner]
WO WO2017187396A1 · 2017 [cited by examiner]
WO 2018189656A1 · 2018 [cited by applicant]
Efficient Signature Generation by Smart Cards, Universitat Frankfurt, C.P. Schnorr (Mar. 1991) (Year: 1991). [cited by examiner]
Anonymous, “Find Sum of Two Nos. Using Only Bitwise Operators,” https://prismoskills.appspot.com/lessons/Bitwise_Operators/Sum_using_only_bitwise_ops.jsp, 2019, 4 pages. [cited by applicant]
Antonopoulos, “Mastering Bitcoin—Unlocking Digital Cryptocurrencies,” O'Reilly Media, Inc., Dec. 20, 2014, 282 pages. [cited by applicant]
Brady et al., “Is There an Algorithm to Split a Number Into the Sum of Powers of 2?,” https://math.stackexchange.com/questions/1553894/is-there-an-algorithm-to-split-a-number-into-the-sum-of-powers-of-2, Nov. 30, 2015, … [cited by applicant]
Chauhan, “Powers of 2 to Required Sum,” Retrieved on May 6, 2022 from https://www.geeksforgeeks.org/powers-2-required-sum/, Apr. 24, 2018, 11 pages. [cited by applicant]
Dryja, “Discreet Log Contracts,” MIT Media Lab, Sep. 2017, 9 pages. [cited by applicant]
Geeksforgeeks, “Add Two Numbers Without Using Arithmetic Operators,” Retrieved on May 6, 2022 from https://www.geeksforgeeks.org/add-two-numbers-without-using-arithmetic-operators/, 15 pages. [cited by applicant]
International Search Report and Written Opinion mailed Oct. 15, 2020, Patent Application No. PCT/IB2020/053214, 7 pages. [cited by applicant]
Jivanyan, “Lelantus: A New Design for Anonymous and Confidential Cryptocurrencies,” Apr. 7, 2019, 1 page. [cited by applicant]
Jivanyan, “Lelantus: Towards Confidentiality and Anonymity of Blockchain Transactions From Standard Assumptions,” IACR Cryptology, 2019, 24 pages. [cited by applicant]
Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System,” Bitcoin, Oct. 31, 2008, https://bitcoin.org/bitcoin.pdf, 9 pages. [cited by applicant]
Orlandi, “Faster Zero-Knowledge Protocols and Applications,” International Conference on Financial Cryptography and Data Security, Oct. 29, 2017, 11 pages. [cited by applicant]
Raitsev et al., “How to Perform Multiplication, Using Bitwise Operators?,” Retrieved on Aug. 6, 2020 from https://stackoverflow.com/questions/3722004/how-to-perform-multiplication-using-bitwise-operators/28158393#:˜:tex… [cited by applicant]
Satoshi et al., “Connection Limits,” Bitcoin Forum, Aug. 9, 2010, https://bitcointalk.org/index.php?topic=741.0;brev_next=prev, 2 pages. [cited by applicant]
Schnorr, “Efficient Identification and Signatures for Smart Cards,” International Conference on Financial Cryptography and Data Security, 1990, 14 pages. [cited by applicant]
UK IPO Search Report mailed Dec. 19, 2019, Patent Application No. GB1905198.6, 5 pages. [cited by applicant]
Espel, et al., “Proposal for Protocol on a Quorum Blockchain with Zero Knowledge”, Nov. 10, 2017, 22 pages. [cited by applicant]
Cited By (1)
US 12,603,792