IP Library › Granted Patent US 12,489,624
Granted Patent B2
US 12,489,624 · App. 18/704,524 · Granted Dec 2, 2025

Authenticating an electronic device based on threshold cryptography using partial secret keys

Inventors: Frans Lundberg (Saltsjöbaden, SE); Martin Kaufmann (Graz, AT); Adam Augustyn (Krzeszowice, PL)
Assignee: ASSA ABLOY AB
H04L9/0894H04L9/3252
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,624
App. No.
18/704,524
Granted
Dec 2, 2025
Kind
B2
Abstract

It is provided a method for performing an action by an electronic device ( 2 ), based on a first partial secret key ( 10 a ) and a corresponding second partial secret key ( 10 b ), wherein the first partial secret key ( 10 a ) and the second partial secret key ( 10 b ) form part of a threshold cryptography scheme ( 11 ) associated with a public key ( 12 ). The method comprises: transmitting ( 40 ), upon the device initialising, a request for a first partial secret key ( 10 a ) to a key server ( 3 ); receiving ( 42 ) the first partial secret key ( 10 a ) from the key server ( 3 ); storing ( 44 ) the first partial secret key ( 10 a ) only in volatile memory ( 70 ); retrieving ( 46 ) a second partial secret key ( 10 b ) from non-volatile memory ( 71 ); and performing ( 48 ) an action based on applying both the first partial secret key ( 10 a ) and the second partial secret key ( 10 b ).

Claims (39)

1 . A method for performing an action by an electronic device, based on a first partial secret key and a corresponding second partial secret key, wherein the first partial secret key and the second partial secret key form part of a threshold cryptography scheme associated with a public key, the method being performed by the electronic device, the method comprising:

transmitting, upon the electronic device initializing, a request for the first partial secret key to a key server;

receiving the first partial secret key from the key server;

storing the first partial secret key only in volatile memory;

retrieving the second partial secret key from non-volatile memory; and

performing an action based on applying both the first partial secret key and the second partial secret key, wherein the performing an action comprises:

interacting with an authentication server to authenticate the electronic device based on performing a cryptographic operation, such that the electronic device applies both the first partial secret key and the second partial secret key, wherein a threshold of at least two partial secret keys of the threshold cryptography scheme are required for applying the threshold cryptography scheme for performing the cryptographic operation, wherein a positive authentication is necessary for normal operation of the electronic device and a negative authentication results in the electronic device setting itself in a non-operational state.

2 . The method according to claim 1 , wherein the performing an action comprises at least one of: decrypting data stored in the non-volatile memory, communicating with an external entity, or communicating with an internal entity in which the electronic device is provided.

3 . The method according to claim 1 , further comprising:

receiving an updated second partial secret key, corresponding to an updated first partial secret key, that collectively form part of the threshold cryptography scheme that still corresponds to the public key; and

replacing the second partial secret key previously stored in non-volatile memory with the updated second partial secret key.

4 . The method according to claim 1 , wherein the interacting comprises applying a cryptographic signature to a data item provided by the authentication server.

5 . The method according to claim 1 , wherein the threshold of partial secret keys required for applying the threshold cryptography scheme is two and the threshold cryptography scheme contains only two partial secret keys.

6 . The method according to claim 1 , wherein the threshold cryptography scheme is based on an Elliptic Curve Digital Signature Algorithm, ECDSA.

7 . An electronic device for performing an action based on a first partial secret key and a corresponding second partial secret key, wherein the first partial secret key and the second partial secret key form part of a threshold cryptography scheme associated with a public key, the electronic device comprising:

a processor; and

a memory storing instructions that, when executed by the processor, cause the electronic device to:

transmit, upon the electronic device initializing, a request for the first partial secret key to a key server;

receive the first partial secret key from the key server;

store the first partial secret key only in volatile memory;

retrieve the second partial secret key from non-volatile memory; and

perform an action based on applying both the first partial secret key and the second partial secret key;

wherein the instructions to perform an action comprise instructions that, when executed by the processor, cause the electronic device to:

interact with an authentication server to authenticate the electronic device based on performing a cryptographic operation, such that the electronic device applies both the first partial secret key and the second partial secret key, wherein a threshold of at least two partial secret keys of the threshold cryptography scheme are required for applying the threshold cryptography scheme for performing the cryptographic operation, wherein a positive authentication is necessary for normal operation of the electronic device and a negative authentication results in the electronic device setting itself in a non-operational state.

8 . The electronic device according to claim 7 , wherein the instructions to perform an action comprise instructions that, when executed by the processor, cause the electronic device to perform at least one of: decrypting data stored in the non-volatile memory, communicating with an external entity, or communicating with an internal entity in which the electronic device is provided.

9 . The electronic device according to claim 7 , further comprising instructions that, when executed by the processor, cause the electronic device to:

receive an updated second partial secret key, corresponding to an updated first partial secret key, that collectively form part of the threshold cryptography scheme that still corresponds to the public key; and

replace the second partial secret key previously stored in non-volatile memory with the updated second partial secret key.

10 . The electronic device according to claim 7 , wherein the instructions to interact comprise instructions that, when executed by the processor, cause the electronic device to apply a cryptographic signature to a data item provided by the authentication server.

11 . The electronic device according to claim 7 , wherein the threshold of partial secret keys required for applying the threshold cryptography scheme is two and the threshold cryptography scheme contains only two partial secret keys.

12 . The electronic device according to claim 7 , wherein the threshold cryptography scheme is based on an Elliptic Curve Digital Signature Algorithm, ECDSA.

13 . A non-transitory computer readable medium storing a computer program for performing an action by an electronic device based on a first partial secret key and a corresponding second partial secret key, wherein the first partial secret key and the second partial secret key form part of a threshold cryptography scheme associated with a public key, the computer program comprising computer program code which, when executed on an electronic device, causes the electronic device to:

transmit, upon the electronic device initializing, a request for the first partial secret key to a key server;

receive the first partial secret key from the key server;

store the first partial secret key only in volatile memory;

retrieve the second partial secret key from non-volatile memory; and

perform an action based on applying both the first partial secret key and the second partial secret key;

wherein the computer program code for performing the action comprises computer program code which, when executed on an electronic device, causes the electronic device to:

interact with an authentication server to authenticate the electronic device based on performing a cryptographic operation, such that the electronic device applies both the first partial secret key and the second partial secret key, wherein a threshold of at least two partial secret keys of the threshold cryptography scheme are required for applying the threshold cryptography scheme for performing the cryptographic operation, wherein a positive authentication is necessary for normal operation of the electronic device and a negative authentication results in the electronic device setting itself in a non-operational state.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2024
From: LUNDBERG, FRANS; KAUFMANN, MARTIN; AUGUSTYN, ADAM
To: ASSA ABLOY AB
Reel/Frame 067219/0756 →
Priority Claims (6)
SE 2151304-9 · Oct 26, 2021 · national
SE 2151305-6 · Oct 26, 2021 · national
SE 2151306-4 · Oct 26, 2021 · national
SE 2151307-2 · Oct 26, 2021 · national
SE 2151308-0 · Oct 26, 2021 · national
SE 2151309-8 · Oct 26, 2021 · national
Continuity (1)
Related Publication 20250023726A1 · Jan 16, 2025
References Cited (68)
US 9032212B1 · Juels · 2015 [cited by applicant]
US 9397827B2 · O'Hare · 2016 [cited by examiner]
US 9455968B1 · Machani et al. · 2016 [cited by applicant]
US 9813244B1 · Triandopoulos et al. · 2017 [cited by applicant]
US 11025598B1 · Laghaeian et al. · 2021 [cited by applicant]
US 11057210B1 · Sierra et al. · 2021 [cited by applicant]
US 20010055388A1 · Kaliski · 2001 [cited by applicant]
US 20150317480A1 · Gardner et al. · 2015 [cited by applicant]
US 20160162671A1 · Baca et al. · 2016 [cited by applicant]
US 20160269186A1 · Wallrabenstein · 2016 [cited by applicant]
US 20160294562A1 · Oberheide · 2016 [cited by examiner]
US 20170063559A1 · Wallrabenstein · 2017 [cited by applicant]
US 20170103228A1 · Yavuz · 2017 [cited by applicant]
US 20170142579A1 · Gaudet et al. · 2017 [cited by applicant]
US 20170187523A1 · Andrews · 2017 [cited by examiner]
US 20180323969A1 · Pahl et al. · 2018 [cited by applicant]
US 20190034936A1 · Nolan et al. · 2019 [cited by applicant]
US 20190229929A1 · Camenisch et al. · 2019 [cited by applicant]
US 20200127835A1 · Fletcher et al. · 2020 [cited by applicant]
US 20200134212A1 · Hutchison et al. · 2020 [cited by applicant]
US 20200162246A1 · Schouppe · 2020 [cited by applicant]
US 20200213113A1 · Savanah et al. · 2020 [cited by applicant]
US 20200353167A1 · Vivek · 2020 [cited by examiner]
US 20200396212A1 · Schiffman et al. · 2020 [cited by applicant]
US 20210081547A1 · Marson et al. · 2021 [cited by applicant]
US 20210167969A1 · Cheon et al. · 2021 [cited by applicant]
US 20210306139A1 · Wright et al. · 2021 [cited by applicant]
US 20210314142A1 · Lai et al. · 2021 [cited by applicant]
CN 110289968 · 2019 [cited by applicant]
CN 112054898 · 2020 [cited by applicant]
EP 1197032 · 2007 [cited by applicant]
EP 3265943 · 2018 [cited by applicant]
EP 3496331 · 2019 [cited by applicant]
WO 2006078557 · 2006 [cited by applicant]
WO 2017172314 · 2017 [cited by applicant]
WO 2021035295 · 2021 [cited by applicant]
WO 2021130748 · 2021 [cited by applicant]
WO 2023073040 · 2023 [cited by applicant]
“SE application 2151304-9 Office Actin mailed Jun. 9, 2022”, 9 pages. [cited by applicant]
“SE application 2151304-9 Office Actin mailed Sep. 22, 2023”, 6 pages. [cited by applicant]
“SE application 2151305-6 Office Actin mailed May 20, 2022”, 9 pages. [cited by applicant]
“SE application 2151305-6 Office Actin mailed Aug. 29, 2023”, 6 pages. [cited by applicant]
“SE application 2151306-4 Office Actin mailed Jun. 13, 2022”, 8 pages. [cited by applicant]
“SE application 2151307-2 Office Actin mailed Jul. 1, 2022”, 11 pages. [cited by applicant]
“SE application 2151308-0 Office Actin mailed Jun. 22, 2022”, 12 pages. [cited by applicant]
“SE application 2151309-8 Office Actin mailed Jun. 23, 2022”, 9 pages. [cited by applicant]
“PCT EP 2022079976 ISR mailed Feb. 17, 2023”, 6 pages. [cited by applicant]
“PCT EP 2022079976 Written Opinion mailed Feb. 17, 2023”, 8 pages. [cited by applicant]
Arthur, Marcella P., “Unbound Tech Raises $20M In Series B Funding to Support Global Growth”, [Online]. Retrieved from the Internet: https: www.prnewswire.com news-releases unbound-tech-raises-20m-in-series-b-funding-to… [cited by applicant]
Assa Abloy, “Java library for dual signing two part singning and dual decryption two part decryption based on the NaCl library primitives”, [Online]. Retrieved from the Internet: https: github.com assaabloy-ppi dualsalt… [cited by applicant]
Aumasson, Jean Philippe, “A Survey of ECDSA Threshold Signing”, Cryptology ePrint Archive, (Nov. 2020), 14 pages. [cited by applicant]
Bernstein, Daniel J., “High-speed high-security signatures”, Journal of Cryptographic Engineering vol. 2, (Aug. 14, 2012), 23 pages. [cited by applicant]
Bernstein, Daniel J., “Ed25519 high speed high security signatures”, [Online]. Retrieved from the Internet: https: ed25519.cr.yp.to papers.html, (Accessed online Apr. 22, 2024), 1 pages. [cited by applicant]
BNB Chain TSS LIB, “Threshold Signature Scheme, for ECDSA and EDDSA”, [Online]. Retrieved from the Internet: https: github.com bnb-chain tss-lib, (Accessed online Feb. 26, 2024), 4 pages. [cited by applicant]
Brandao, Luis T. A. N., “NIST Roadmap Toward Criteria for Threshold Schemes for Cryptographic Primitives”, NIST Interagency Internal Report NISTIR 8214A, (Jul. 2020), 39 pages. [cited by applicant]
Certicom Research, “Sec 2: Recommended Elliptic Curve Domain Parameters”, Certicom Research Version 1.0, (Sep. 20, 2000), 51 pages. [cited by applicant]
Dikshit, Pratyush, “Efficient weighted threshold ECDSA for securing bitcoin wallet”, 2017 ISEA Asia Security and Privacy, (Jan. 2017), 9 pages. [cited by applicant]
Gennaro, Rosario, “Fast Multiparty Threshold ECDSA with Fast Trustless Setup”, Session 6C Crypto 3 CCS 2018 Toronto ON Canada, (Oct. 15-19, 2018), 16 pages. [cited by applicant]
Gillmor, D., “Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS)”, ISSN: 2070-1721, (Aug. 2016), 29 pages. [cited by applicant]
Hakanols, “Threshold signing and decryption inspired by TweetNaCl”, [Online]. Retrieved from the Internet: https: github.com hakanols ThresholdSalt, (Accessed online Feb. 26, 2024), 2 pages. [cited by applicant]
Hallam Baker, Phillip, “Threshold Signatures in Elliptic Curves”, [Online]. Retrieved from the Internet: https: datatracker.ietf.org doc draft-hallambaker-threshold-sigs , (Accessed online Feb. 26, 2024), 2 pages. [cited by applicant]
Hallam-Baker, P. M., “Threshold Signatures in Elliptic Curves”, [Online]. Retrieved from the Internet: https: www.ietf.org archive id draft-hallambaker-threshold-sigs-06.html, (Accessed online Apr. 22, 2024), 24 pages. [cited by applicant]
Kel BZ, “P-256 in Sage”, [Online]. Retrieved from the Internet: https: kel.bz post sage-p256 , (Jan. 10, 2020), 3 pages. [cited by applicant]
Mohaisen, Abedelaziz, “Protection Techniques of Secret Information in Non tamper Proof Devices of Smart Home Network”, UIC 2008 Lecture Notes in Computer Science vol. 5061, (Jun. 2008), 15 pages. [cited by applicant]
Parakh, Abhishek, “A Tree Based Recursive Information Hiding Scheme”, IEEE ICC 2010 proceedings, (May 2010), 5 pages. [cited by applicant]
Wikipedia, “Edwards curve”, [Online]. Retrieved from the Internet: https: en.wikipedia.org wiki Edwards_curve, (Accessed online Apr. 22, 2024), 8 pages. [cited by applicant]
Zhang, Chenchen, “A new construction of threshold cryptosystems based on RSA”, Information Sciences 363, (Oct. 2016), 14 pages. [cited by applicant]
Zhao, Shushan, “A Survey of Applications of Identity-Based Cryptography in Mobile Ad-Hoc Networks”, IEEE Communications Surveys and Tutorials vol. 14 Issue 2, (Q2 2012), 21 pages. [cited by applicant]