IP Library › Granted Patent US 12,531,744
Granted Patent B2
US 12,531,744 · App. 18/562,242 · Granted Jan 20, 2026

Partial SHA-based hash function

Inventors: Wei Zhang (London, GB); Steven Patrick Coughlan (London, GB); John Murphy (London, GB); Arthur Gordan (London, GB)
Assignee: nChain Licensing AG
H04L9/3239H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,531,744
App. No.
18/562,242
Granted
Jan 20, 2026
Kind
B2
Abstract

A computer-implemented method of verifying the integrity of part of a pre-image corresponding to a hash digest generated by hashing the preimage with a SHA-based hash function, wherein the pre-image comprises a first message and a second message, and wherein the method comprises: a) receiving an iteration input vector; b) obtaining a second sequence of blocks; c) generating a final iteration output vector by performing an iteration of the SHA-based hash computation for each of the second sequence of blocks in order of a respective position in the second sequence of blocks, wherein the iteration of the SHA-based hash computation performed on a first one of the second sequence of blocks is based on the obtained iteration input vector; and d) generating a candidate hash digest based on the final iteration output vector, the candidate hash digest being for comparison with the hash digest.

Claims (52)

1 . A computer-implemented method of verifying an integrity of part of a pre-image corresponding to a hash digest generated by hashing the pre-image with a SHA-based hash function, wherein the pre-image comprises a first message and a second message, and wherein the method is performed by a verifying party and comprises:

a) receiving, from a proving party, an iteration input vector, wherein the iteration input vector is generated by partially executing the SHA-based hash function, wherein partially executing the SHA-based hash function comprises:

i) obtaining a first sequence of blocks, wherein the first sequence of blocks is obtained by either padding a binary representation of the pre-image to generate a first padded sequence, and splitting the first padded sequence into a first sequence of blocks, or by splitting a binary representation of the first message into the first sequence of blocks, and

ii) performing an iteration of a SHA-based hash computation for each of the first sequence of blocks in order of a respective position in the first sequence of blocks, up until a block that comprises one or more bits representing the second message;

b) obtaining a second sequence of blocks, wherein the second sequence of blocks is generated by:

i) padding a binary representation of the second message to generate a second padded sequence,

ii) splitting the second padded sequence into the second sequence of blocks;

c) generating a final iteration output vector by performing an iteration of the SHA-based hash computation for each of the second sequence of blocks in order of a respective position in the second sequence of blocks, wherein the iteration of the SHA-based hash computation performed on a first one of the second sequence of blocks is based on the obtained iteration input vector; and

d) generating a candidate hash digest based on the final iteration output vector, the candidate hash digest being for comparison with the hash digest.

2 . The method of claim 1 , comprising:

obtaining the hash digest; and

verifying that the second message is part of the pre-image of the obtained hash digest based on a comparison of the candidate hash digest and the obtained hash digest.

3 . The method of claim 1 , wherein said receiving of the iteration input vector comprises receiving the iteration input vector from a proving party.

4 . The method of claim 1 , comprising obtaining the second message.

5 . The method of claim 4 , wherein said obtaining of the second sequence of blocks comprises generating the second sequence of blocks.

6 . The method of claim 4 , comprising obtaining a length of the pre-image, and wherein said generating of the second padded sequence is based on the second message and the length of the pre-image.

7 . The method of claim 4 , comprising obtaining a length of the first message, and wherein generating of the second padded sequence is based on the second message and the length of the first message.

8 . The method of claim 1 , wherein said obtaining of the second sequence of blocks comprises receiving the second sequence of blocks.

9 . The method of claim 1 , wherein the first message is not available to the verifying party, such that the integrity of the second message is verified without revealing the first message.

10 . The method of claim 1 , wherein the pre-image comprises at least part of a blockchain transaction.

11 . The method of claim 10 , wherein the second message comprises one or more outputs of the blockchain transaction.

12 . The method of claim 1 , wherein the pre-image comprises at least part of an identity document.

13 . The method of claim 12 , wherein the identity document comprises one of: a driving license, a passport, a birth certificate, and a resident permit.

14 . The method of claim 12 , wherein the second message comprises one or more data fields of the identity document.

15 . A computer-implemented method of proving an integrity of part of a pre-image corresponding to a hash digest generated by hashing the pre-image with a SHA-based hash function, wherein the pre-image comprises a first message and a second message, and wherein the method is performed by a proving party and comprises:

a) generating an iteration input vector, wherein the iteration input vector is generated by partially executing the SHA-based hash function, wherein partially executing the SHA-based hash function comprises:

i) obtaining a first sequence of blocks, wherein the first sequence of blocks is obtained by either padding a binary representation of the pre-image to generate a first padded sequence, and splitting the first padded sequence into a first sequence of blocks, or by splitting a binary representation of the first message into the first sequence of blocks, and

ii) performing an iteration of a SHA-based hash computation for each of the first sequence of blocks in order of a respective position in the first sequence of blocks, up until a block that comprises one or more bits representing the second message; and

b) making the iteration input vector available to a verifying party.

16 . The method of claim 15 , comprising making the hash digest available to the verifying party.

17 . The method of claim 15 , comprising making the second message available to the verifying party.

18 . The method of claim 15 , comprising making a bit-length of the pre-image or the first message available to the verifying party.

19 . Computer equipment comprising:

memory comprising one or more memory units; and

processing apparatus comprising one or more processing units, wherein the memory stores code arranged to run on the processing apparatus, the code being configured so as when run on the processing apparatus, the processing apparatus performs a method of verifying an integrity of part of a pre-image corresponding to a hash digest generated by hashing the pre-image with a SHA-based hash function, wherein the pre-image comprises a first message and a second message, and wherein the method is performed by a verifying party and comprises:

a) receiving an iteration input vector, wherein the iteration input vector is generated by partially executing the SHA-based hash function, wherein partially executing the SHA-based hash function comprises:

i) obtaining a first sequence of blocks, wherein the first sequence of blocks is obtained by either padding a binary representation of the pre-image to generate a first padded sequence, and splitting the first padded sequence into a first sequence of blocks, or by splitting a binary representation of the first message into the first sequence of blocks, and

ii) performing an iteration of a SHA-based hash computation for each of the first sequence of blocks in order of a respective position in the first sequence of blocks, up until a block that comprises one or more bits representing the second message;

b) obtaining a second sequence of blocks, wherein the second sequence of blocks is generated by:

i) padding a binary representation of the second message to generate a second padded sequence,

ii) splitting the second padded sequence into the second sequence of blocks;

c) generating a final iteration output vector by performing an iteration of the SHA-based hash computation for each of the second sequence of blocks in order of a respective position in the second sequence of blocks, wherein the iteration of the SHA-based hash computation performed on a first one of the second sequence of blocks is based on the obtained iteration input vector; and

d) generating a candidate hash digest based on the final iteration output vector, the candidate hash digest being for comparison with the hash digest.

20 . A computer program embodied on non-transitory computer-readable storage media and configured so as, when run on one or more processors, the one or more processors perform a method of verifying an integrity of part of a pre-image corresponding to a hash digest generated by hashing the pre-image with a SHA-based hash function, wherein the pre-image comprises a first message and a second message, and wherein the method is performed by a verifying party and comprises:

a) receiving an iteration input vector, wherein the iteration input vector is generated by partially executing the SHA-based hash function, wherein partially executing the SHA-based hash function comprises:

i) obtaining a first sequence of blocks, wherein the first sequence of blocks is obtained by either padding a binary representation of the pre-image to generate a first padded sequence, and splitting the first padded sequence into a first sequence of blocks, or by splitting a binary representation of the first message into the first sequence of blocks, and

ii) performing an iteration of a SHA-based hash computation for each of the first sequence of blocks in order of a respective position in the first sequence of blocks, up until a block that comprises one or more bits representing the second message;

b) obtaining a second sequence of blocks, wherein the second sequence of blocks is generated by:

i) padding a binary representation of the second message to generate a second padded sequence,

ii) splitting the second padded sequence into the second sequence of blocks;

c) generating a final iteration output vector by performing an iteration of the SHA-based hash computation for each of the second sequence of blocks in order of a respective position in the second sequence of blocks, wherein the iteration of the SHA-based hash computation performed on a first one of the second sequence of blocks is based on the obtained iteration input vector; and

d) generating a candidate hash digest based on the final iteration output vector, the candidate hash digest being for comparison with the hash digest.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2023
From: COUGHLAN, STEVEN PATRICK; ZHANG, WEI; MURPHY, JOHN; GORDON, ARTHUR
To: NCHAIN LICENSING AG
Reel/Frame 065606/0872 →
Priority Claims (1)
GB 2107350 · May 24, 2021 · national
Continuity (1)
Related Publication 20250097045A1 · Mar 20, 2025
References Cited (17)
US 9800403B1 · Gomes · 2017 [cited by examiner]
US 11037118B2 · Kraemer · 2021 [cited by examiner]
US 11449842B2 · Baldet · 2022 [cited by examiner]
US 20180227131A1 · Ebrahimi · 2018 [cited by examiner]
US 20230114002A1 · Flint · 2023 [cited by examiner]
WO WO2019217934A1 · 2019 [cited by examiner]
Naik,“Optimising the SHA256 Hashing Algorithm for Faster and More Efficient Bitcoin Mining”, (Sep. 2, 2013), Retrieved: URL:http://www.nicolascourtois.com/bitcoin/Optimising%20the%20SHA256%20Hashing%20Algorithm%20for%20… [cited by examiner]
Distributed Ledger Technology Distributed Ledger Technology Use Cases: “Technical Report FG DL T D2.1 Distributed ledger technology use cases”, ITU-T Draft; Study Period 2017-2020; Study Group 16, International Telecomm… [cited by applicant]
GB2107350.7 Combined Search and Examination Report dated Mar. 8, 2022, 11 pages. [cited by applicant]
Lias Giechaskiel et al: “On Bitcoin Security in the Presence of Broken Crypto Primitives”, Iacr, International Association for Cryptologic Research, vol. 20160219:201915, Feb. 19, 2016 (Feb. 19, 2016), pp. 1-17, XP06102… [cited by applicant]
PCT/EP2022/060827 International Search Report and Written Opinion dated Aug. 4, 2022, 14 pages. [cited by applicant]
Quynh H Dang: “Secure Hash Standard NIST FIPS 180-4”, NIST, National Institute of Standards and Technology (NIST), Jul. 24, 2015 (Jul. 24, 2015), pp. 1-36, XP061049267, DOI: 10.6028/NIST.FIPS.180-4 Retrieved from the In… [cited by applicant]
Rahul P. Naik et al: “Optimising the SHA256 Hashing Algorithm for Faster and More Efficient Bitcoin Mining”, Sep. 2, 2013 (Sep. 2, 2013), XP055233141, Retrieved from the Internet: URL:http://www.nicolascourtois.com/bitc… [cited by applicant]
Secure Hash Standard (SHS), Federal Information Processing Standards Publication, Aug. 2015, 36 pages, Department of Commerce United States of America, URL: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf. [cited by applicant]
Wikipedia Contributors (Oct. 17, 2023). SHA-2, In Wikipedia, The Free Encyclopedia, URL: https://en.wikipedia.org/w/index.php?title=SHA-2&oldid=1180509463. [cited by applicant]
Zhang, Wei, Simplified Payment Verification, Medium, Aug. 25, 2020, 7 pages, URL: https://medium.com/nchain/simplified-payment-verification-48ac60f1b26c. [cited by applicant]
Aitzhan N.Z., et al., “Security and Privacy in Decentralized Energy Trading through Multi-Signatures, Blockchain and Anonymous Messaging Streams,” IEEE Transactions on Dependable and Secure, Jan. 1, 2016, XP055409982, 1… [cited by applicant]