IP Library Granted Patent US 12,500,746
Granted Patent B2
US 12,500,746 · App. 18/192,287 · Granted Dec 16, 2025

Key management for multi-party computation

Inventors: Oleg Gryb (San Francisco, CA); Sekhar Nagasundaram (San Ramon, CA)
Assignee: Visa International Service Association
H04L9/085H04L9/0861H04L9/0897H04L2209/46
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,746
App. No.
18/192,287
Granted
Dec 16, 2025
Kind
B2
Abstract

Methods and systems for managing cryptographic keys in on-premises and cloud computing environments and performing multi-party cryptography are disclosed. A cryptographic key can be retrieved from a hardware security module by a key management computer. The key management computer can generate key shares from the cryptographic key, and securely distribute the key shares to computer nodes or key share databases. The computer nodes can use the key shares in order to perform secure multi-party cryptography.

Claims (45)

1 . A method comprising:

receiving, by a second computer node, a second key share from a key management computer;

receiving, by the second computer node, an initial message from a first computer node, wherein the first computer node received the initial message from a client computer, the initial message comprising a request for an encryption operation or a decryption operation;

generating, by the second computer node, a second garbled circuit, a garbled second key share based on the second key share and the second garbled circuit, and a garbled message based on the initial message and the second garbled circuit; and

transmitting, by the second computer node to a third computer node, the second garbled circuit, the garbled second key share, and the garbled message, wherein the third computer node also receives, from the first computer node, a garbled first key share based on a first key share stored at the first computer node and a first garbled circuit, which causes the third computer node to generate a subsequent message by inputting the first garbled key share, the second garbled key share, and the garbled message into either the first garbled circuit or the second garbled circuit, and transmit the subsequent message to the first computer node,

wherein the first computer node transmits the subsequent message or a derivative thereof to the client computer.

2 . The method of claim 1 , wherein the garbled message is a second garbled message and wherein the third computer node also receives from the first computer node, a first garbled message based on the initial message and the first garbled circuit.

3 . The method of claim 1 , wherein receiving, by the second computer node, the second key share from the key management computer comprises:

retrieving, by the second computer node, the second key share from a second key share database, wherein the key management computer transmitted the second key share to the second key share database.

4 . The method of claim 1 , wherein the second computer node receives the second key share from the key management computer via a proxy.

5 . The method of claim 1 , wherein the initial message additionally comprises information about a requested operation, the information about the requested operation indicating whether the initial message should be encrypted or decrypted by the first computer node, the second computer node, and the third computer node.

6 . The method of claim 1 , wherein the key management computer generated the second key share from a key stored in a hardware security module.

7 . The method of claim 1 , further comprising:

storing, by the second computer node, the second key share in a secure memory element associated with the second computer node.

8 . The method of claim 1 , wherein, prior to receiving, by the second computer node, the second key share from the key management computer, the key management computer verifies or authenticates the second computer node using a certificate corresponding to the second computer node.

9 . The method of claim 1 , wherein the initial message is ciphertext and the subsequent message or the derivative thereof is plaintext.

10 . A second computer node comprising:

a processor; and

a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium comprising code, executable by the processor, for implementing a method including:

receiving a second key share from a key management computer;

receiving an initial message from a first computer node, wherein the first computer node received the initial message from a client computer, the initial message comprising a request for an encryption operation or a decryption operation;

generating a second garbled circuit, a garbled second key share based on the second key share and the second garbled circuit, and a garbled message based on the initial message and the second garbled circuit; and

transmitting to a third computer node, the second garbled circuit, the garbled second key share, and the garbled message, wherein the third computer node also receives, from the first computer node, a garbled first key share based on a first key share stored at the first computer node and a first garbled circuit,

which causes the third computer node to generate a subsequent message by inputting the first garbled key share, the second garbled key share, and the garbled message into either the first garbled circuit or the second garbled circuit, and transmit the subsequent message to the first computer node, wherein the first computer node transmits the subsequent message or a derivative thereof to the client computer.

11 . The second computer node of claim 10 , wherein the garbled message is a second garbled message and wherein the third computer node also receives from the first computer node, a first garbled message based on the initial message and the first garbled circuit.

12 . The second computer node of claim 10 , wherein receiving the second key share from the key management computer includes:

retrieving the second key share from a second key share database, wherein the key management computer transmitted the second key share to the second key share database.

13 . The second computer node of claim 10 , wherein the second computer node receives the second key share from the key management computer via a proxy.

14 . The second computer node of claim 10 , wherein the initial message additionally comprises information about a requested operation, the information about the requested operation indicating whether the initial message should be encrypted or decrypted by the first computer node, the second computer node, and the third computer node.

15 . The second computer node of claim 10 , wherein the key management computer generated the second key share from a key stored in a hardware security module.

16 . The second computer node of claim 10 , wherein the second computer node additionally comprises a secure memory element, and wherein the method further includes:

storing the second key share in the secure memory element.

17 . The second computer node of claim 10 , wherein in the method, prior to receiving the second key share from the key management computer, the key management computer verifies or authenticates the second computer node using a certificate corresponding to the second computer node.

18 . A third computer node comprising:

a processor; and

a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium comprising code, executable by the processor, for implementing a method including:

receiving, from a first computer node, a first garbled circuit, a garbled first key share generated by the first computer node based on the first garbled circuit, and a first garbled message generated by the first computer node based on an initial message and the first garbled circuit, wherein the first computer node received the initial message from a client computer, the initial message comprising a request for an encryption operation or a decryption operation;

receiving, from a second computer node, a second garbled circuit, a garbled second key share generated by the second computer node based on the second garbled circuit, and a second garbled message generated by the second computer node based on the initial message and the second garbled circuit, wherein the second computer node received the initial message from the first computer node;

generating, by the third computer node, a subsequent message by inputting the first garbled key share, the second garbled key share and the first garbled message or second garbled message into either the first garbled circuit or the second garbled circuit; and

transmitting the subsequent message to the first computer node, wherein the first computer node transmits the subsequent message or a derivative thereof to the client computer.

19 . The third computer node of claim 18 , wherein the method further includes:

verifying that the first garbled circuit and the second garbled circuit match and that the first garbled message and the second garbled message match.

20 . The third computer node of claim 18 , wherein:

verifying that the first garbled circuit and the second garbled circuit match includes performing a bitwise or bytewise comparison of first garbled circuit data corresponding to the first garbled circuit and second garbled circuit data corresponding to the second garbled circuit; and

verifying that the first garbled message and the second garbled message match includes performing a bitwise comparison or bytewise comparison of first garbled message data corresponding to the first garbled message and second garbled message data corresponding to the second garbled message.

Continuity (2)
Continuation 17276620
Related Publication 20230254129A1 · Aug 10, 2023
References Cited (42)
US 11664982B2 · Gryb et al. · 2023 [cited by applicant]
US 20090147958A1 · Calcaterra et al. · 2009 [cited by applicant]
US 20110211692A1 · Raykova et al. · 2011 [cited by applicant]
US 20120233460A1 · Kamara et al. · 2012 [cited by applicant]
US 20130191632A1 · Spector et al. · 2013 [cited by applicant]
US 20150341326A1 · Premnath · 2015 [cited by examiner]
US 20160342608A1 · Burshteyn · 2016 [cited by applicant]
US 20170093879A1 · Dayka et al. · 2017 [cited by applicant]
US 20170171174A1 · Campagna · 2017 [cited by applicant]
US 20170359321A1 · Rindal et al. · 2017 [cited by applicant]
US 20180019868A1 · Pe'Er · 2018 [cited by examiner]
US 20210051001A1 · Li · 2021 [cited by examiner]
US 20210051007A1 · Li · 2021 [cited by examiner]
US 20210051008A1 · Li · 2021 [cited by examiner]
US 20210091952A1 · Wentz · 2021 [cited by examiner]
US 20210111875A1 · Saint · 2021 [cited by applicant]
US 20210203484A1 · Veeningen · 2021 [cited by examiner]
CN 106797311A · 2017 [cited by applicant]
CN 108352015A · 2018 [cited by applicant]
WO 2016135738A1 · 2016 [cited by applicant]
Payman Mohassel, Mike Rosulek, and Ye Zhang. 2015. Fast and Secure Three-party Computation: The Garbled Circuit Approach. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS '15… [cited by examiner]
David W Archer, Dan Bogdanov, Yehuda Lindell, Liina Kamm, Kurt Nielsen, Jakob Illeborg Pagter, Nigel P Smart, Rebecca N Wright, From Keys to Databases—Real-World Applications of Secure Multi-Party Computation, Sep. 12, … [cited by examiner]
U.S. Appl. No. 17/276,620 , “Corrected Notice of Allowability”, filed Jan. 30, 2023, 7 pages. [cited by applicant]
U.S. Appl. No. 17/276,620 , “Non-Final Office Action”, filed May 25, 2022, 12 pages. [cited by applicant]
U.S. Appl. No. 17/276,620 , “Notice of Allowance”, filed Jan. 11, 2023, 10 pages. [cited by applicant]
Archer et al., “From Keys to Databases—Real-World Applications of Secure Multi-Party Computation”, International Association For Cryptologic Research, XP061025888, vol. 20180606:062214, Jun. 6, 2018, pp. 1-32. [cited by applicant]
Archer et al., “From Keys to Databases—Real-World Applications of Secure Multi-Party Computation”, International Association for Cryptologic Research, 2018, 32 pages. [cited by applicant]
EP18935825.2, “Extended European Search Report”, Aug. 13, 2021, 8 pages. [cited by applicant]
Hamlin et al., “Cryptography for Big Data Security”, Available Online at: http://www.c-is.cn/wp-content/uploads/2017/05/Cryptography-for-Big-Data-Security.pdf, Dec. 17, 2015, 50 pages. [cited by applicant]
Jayaraman et al., “Decentralized Certificate Authority”, University of Virginia, Oct. 10, 2017, 11 pages. [cited by applicant]
Lindell, “Highly Efficient, Actively Secure,Three-Party Computation with Security Under One Corruption”, Dyadic Security—Confidential, Aug. 30, 2016, pp. 1-14. [cited by applicant]
Mohassel et al., “Fast and Secure Three-party Computation The Garbled Circuit Approach”, User Interface Software and Technology, XP058523669, Oct. 12, 2015, pp. 591-602. [cited by applicant]
Mohassel et al., “Fast and Secure Three-party Computation: The Garbled Circuit Approach”, Interface Software and Technology, Sep. 23, 2015, 18 pages. [cited by applicant]
PCT/US2018/052448, “International Preliminary Report on Patentability”, Apr. 1, 2021, 8 pages. [cited by applicant]
PCT/US2018/052448, “International Search Report and Written Opinion”, Jun. 14, 2019, 11 pages. [cited by applicant]
PCT/US2018/052448, “International Search Report and Written Opinion”, Jun. 14, 2019, 9 pages. [cited by applicant]
SG11202102202R, “Written Opinion”, Dec. 2, 2022, 8 pages. [cited by applicant]
Archer et al., “From Keys to Databases-Real-World Applications of Secure Multi-Party Computation”, The Computer Journal, vol. 61, No. 12, Sep. 12, 2018, pp. 1749-1771. [cited by applicant]
CN201880097930.X , “Office Action”, Sep. 28, 2023, 11 pages. [cited by applicant]
U.S. Appl. No. 17/276,620 , “Corrected Notice of Allowability”, Apr. 26, 2023, 7 pages. [cited by applicant]
EP18935825.2 , “Office Action”, Jun. 5, 2023, 4 pages. [cited by applicant]
SG11202102202R , “Notice of Decision to Grant”, May 30, 2023, 5 pages. [cited by applicant]