IP Library Granted Patent US 12,574,258
Granted Patent B2
US 12,574,258 · App. 18/372,051 · Granted Mar 10, 2026

Publicly verifiable encryption

Inventors: Yi-Hsiu Chen (San Francisco, CA); Samuel Ranellucci (Montreal, CA); Iftach Haitner (Ramat Hasharon, IL); Arash Afshar (Calgary, CA)
H04L9/3271H04L9/0819
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,258
App. No.
18/372,051
Granted
Mar 10, 2026
Kind
B2
Abstract

Methods, systems, and devices for data management are described. A server may receive a plurality of parts of a secret from a computing device, where the plurality of parts may be individually encrypted and individually associated with respective public parts. The server may transmit a random challenge to the computing device. The computing device may transmit, to the server, a subset of parts in a decrypted state. The server may determine, using the subset of decrypted parts and a corresponding subset of respective public parts, that the subset of decrypted parts corresponds to a polynomial function with a degree corresponding to a quantity of parts in the subset of decrypted parts. The server may verify that the individually encrypted plurality of parts corresponds to a secret based on determining that the subset of decrypted parts corresponds to the polynomial function.

Claims (49)

1 . A method for key management, comprising:

receiving from a computing device, a plurality of parts of a secret, wherein the plurality of parts are individually encrypted and individually associated with respective public parts;

transmitting, to the computing device, a random challenge;

receiving, from the computing device, after transmitting the random challenge, a subset of parts of the plurality of parts, wherein the subset of parts are in a decrypted state;

determining, using the subset of parts in the decrypted state and a corresponding subset of the respective public parts, that the subset of parts corresponds to a polynomial function with a degree corresponding to a quantity of parts in the subset of parts; and

verifying, based at least in part on determining that the subset corresponds to the polynomial function, that the individually encrypted plurality of parts corresponds to the secret without revealing the secret.

2 . The method of claim 1 , wherein the quantity is a threshold quantity of parts usable to determine that the subset of parts corresponds to the polynomial function without revealing the secret.

3 . The method of claim 1 , wherein:

an evaluation of the polynomial function determined using the subset of parts and at least one additional part in the decrypted state results in the secret, and

the evaluation of the polynomial function corresponding to the secret is unobtainable using only the subset of parts in the decrypted state.

4 . The method of claim 1 , wherein the quantity is based at least in part on a total quantity of parts in the individually encrypted plurality of parts.

5 . The method of claim 1 , wherein receiving the plurality of parts comprises:

receiving, from a client application on the computing device, a request to back up the secret that is usable by the client application on the computing device; and

receiving, from the client application after receiving the request to back up the secret, the individually encrypted plurality of parts, wherein the verifying is performed based at least in part on receiving the request to back up the secret.

6 . The method of claim 5 , wherein the client application is an application that supports access to a custodial token platform and the verifying is performed on one or more servers supporting the custodial token platform.

7 . The method of claim 1 , wherein the random challenge includes a selection of the subset of the parts in an encrypted state.

8 . An apparatus for key management, comprising:

one or more memories storing processor-executable code; and

one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:

receive from a computing device, a plurality of parts of a secret, wherein the plurality of parts are individually encrypted and individually associated with respective public parts;

transmit, to the computing device, a random challenge;

receive, from the computing device, after transmitting the random challenge, a subset of parts of the plurality of parts, wherein the subset of parts are in a decrypted state;

determine, using the subset of parts in the decrypted state and a corresponding subset of the respective public parts, that the subset of parts corresponds to a polynomial function with a degree corresponding to a quantity of parts in the subset of parts; and

verifying, based at least in part on determining that the subset corresponds to the polynomial function, that the individually encrypted plurality of parts corresponds to the secret without revealing the secret.

9 . The apparatus of claim 8 , wherein the quantity is a threshold quantity of parts usable to determine that the subset of parts corresponds to the polynomial function without revealing the secret.

10 . The apparatus of claim 8 , wherein:

an evaluation of the polynomial function determined using the subset of parts and at least one additional part in the decrypted state results in the secret, and

the evaluation of the polynomial function corresponding to the secret is unobtainable using only the subset of parts in the decrypted state.

11 . The apparatus of claim 8 , wherein the quantity is based at least in part on a total quantity of parts in the individually encrypted plurality of parts.

12 . The apparatus of claim 8 , wherein, to receive the plurality of parts, the one or more processors are individually or collectively operable to execute the code to cause the apparatus to:

receive, from a client application on the computing device, a request to back up the secret that is usable by the client application on the computing device; and

receive, from the client application after receiving the request to back up the secret, the individually encrypted plurality of parts, wherein the verifying is performed based at least in part on receiving the request to back up the secret.

13 . The apparatus of claim 12 , wherein the client application is an application that supports access to a custodial token platform and the verifying is performed on one or more servers supporting the custodial token platform.

14 . The apparatus of claim 8 , wherein the random challenge includes a selection of the subset of the parts in an encrypted state.

15 . A non-transitory computer-readable medium storing code for key management, the code comprising instructions executable by one or more processors to:

receive from a computing device, a plurality of parts of a secret, wherein the plurality of parts are individually encrypted and individually associated with respective public parts;

transmit, to the computing device, a random challenge;

receive, from the computing device, after transmitting the random challenge, a subset of parts of the plurality of parts, wherein the subset of parts are in a decrypted state;

determine, using the subset of parts in the decrypted state and a corresponding subset of the respective public parts, that the subset of parts corresponds to a polynomial function with a degree corresponding to a quantity of parts in the subset of parts; and

verifying, based at least in part on determining that the subset corresponds to the polynomial function, that the individually encrypted plurality of parts corresponds to the secret without revealing the secret.

16 . The non-transitory computer-readable medium of claim 15 , wherein the quantity is a threshold quantity of parts usable to determine that the subset of parts corresponds to the polynomial function without revealing the secret.

17 . The non-transitory computer-readable medium of claim 15 , wherein:

an evaluation of the polynomial function determined using the subset of parts and at least one additional part in the decrypted state results in the secret, and

the evaluation of the polynomial function corresponding to the secret is unobtainable using only the subset of parts in the decrypted state.

18 . The non-transitory computer-readable medium of claim 15 , wherein the quantity is based at least in part on a total quantity of parts in the individually encrypted plurality of parts.

19 . The non-transitory computer-readable medium of claim 15 , wherein the instructions to receive the plurality of parts are executable by the one or more processors to:

receive, from a client application on the computing device, a request to back up the secret that is usable by the client application on the computing device; and

receive, from the client application after receiving the request to back up the secret, the individually encrypted plurality of parts, wherein the verifying is performed based at least in part on receiving the request to back up the secret.

20 . The non-transitory computer-readable medium of claim 19 , wherein the client application is an application that supports access to a custodial token platform and the verifying is performed on one or more servers supporting the custodial token platform.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2025
From: CHEN, YI-HSIU; RANELLUCCI, SAMUEL; HAITNER, IFTACH; AFSHAR, ARASH
To: COINBASE, INC.
Reel/Frame 073327/0192 →
Continuity (1)
Related Publication 20250106046A1 · Mar 27, 2025
References Cited (33)
US 10833871B2 · Ranellucci · 2020 [cited by examiner]
US 10846372B1 · Jayachandran · 2020 [cited by examiner]
US 12401530B2 · Stock · 2025 [cited by examiner]
US 20010038696A1 · Frankel · 2001 [cited by examiner]
US 20100185863A1 · Rabin · 2010 [cited by examiner]
US 20200153622A1 · Lindell · 2020 [cited by examiner]
US 20200153640A1 · Ranellucci · 2020 [cited by examiner]
US 20200322132A1 · Covaci · 2020 [cited by examiner]
US 20200351098A1 · Wentz · 2020 [cited by examiner]
US 20230230066A1 · Jakobsson · 2023 [cited by examiner]
US 20230412398A1 · Sarkar · 2023 [cited by examiner]
US 20230421375A1 · Savanah · 2023 [cited by examiner]
US 20240204991A1 · Patel · 2024 [cited by examiner]
US 20240354753A1 · Ness · 2024 [cited by examiner]
US 20250104028A1 · Jakobsen · 2025 [cited by examiner]
US 20250106046A1 · Chen · 2025 [cited by examiner]
US 20250124429A1 · Galansky · 2025 [cited by examiner]
US 20250173721A1 · Wu · 2025 [cited by examiner]
WO WO2023132791A2 · 2023 [cited by examiner]
WO WO2025212130A2 · 2025 [cited by examiner]
Jiaheng Zhang et al., “Polynomial Commitment with a One-to-Many Prover and Applications”, 31st USENIX Security Symposium (USENIX Security 22), Aug. 2022, pp. 2965-2982. (Year: 2022). [cited by examiner]
A. Tomescu et al., “Towards Scalable Threshold Cryptosystems,” 2020 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 2020, pp. 877-893, doi: 10.1109/SP40000.2020.00059. (Year: 2020). [cited by examiner]
P. Feldman, “A practical scheme for non-interactive verifiable secret sharing,” 28th Annual Symposium on Foundations of Computer Science (sfcs 1987), Los Angeles, CA, USA, 1987, pp. 427-438, doi: 10.1109/SFCS.1987.4. (Y… [cited by examiner]
Jian-wei, Ye & Xu-lu, Jiao & Yong-zheng, Zhang. (2009). Verifiable Threshold Secret Sharing and Full Fair Secure Two-Party Computation. 78-83. 10.1109/AST.2009.21. (Year: 2009). [cited by examiner]
Afshar, A., Mohassel, P., Pinkas, B., Riva, B. (2014). Non-Interactive Secure Computation Based on Cut-and-Choose. In: Nguyen, P.Q., Oswald, E. (eds) Advances in Cryptology—EUROCRYPT 2014. EUROCRYPT 2014. Lecture Notes … [cited by examiner]
Lindell. “Secure Two-Party Computation via Cut-and-Choose Oblivious Transfer.” Journal of cryptology: the journal of the International Association for Cryptologic Research. 25.4 (2012): p. 680. (Year: 2012). [cited by examiner]
Lindell et al., “Unbound blockchain-crypto-mpc Library”, White Paper, Unbound, Jul. 15, 2019, p. 1-19. (Year: 2019). [cited by examiner]
Applebaum, B. (2017). Garbled Circuits as Randomized Encodings of Functions: a Primer. In: Lindell, Y. (eds) Tutorials on the Foundations of Cryptography. Information Security and Cryptography. Springer. p. 1-44. (Year:… [cited by examiner]
Lindell, Y. (2017). How to Simulate It—A Tutorial on the Simulation Proof Technique. In: Lindell, Y. (eds) Tutorials on the Foundations of Cryptography. Information Security and Cryptography. Springer, Cham., p. 277-346… [cited by examiner]
Lindell, Y., “Cryptography and MPC in Coinbase Wallet as a Service (WaaS)”, Coinbase, Jun. 15, 2023, p. 1-19. (Year: 2023). [cited by examiner]
Lindell, Y., “Publicly Verifiable Backup of Signing Keys”, Medium.com, Jan. 7, 2020, p. 1-9, https://medium.com/@yehudalindell/publicly-verifiable-backup-of-signing-keys-390c26593. (Year: 2020). [cited by examiner]
Yehuda Lindell and Ariel Nof. 2018. Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency Custody. In Proc. of 2018 ACM SIGSAC Conf. on Computer and Communications Sec… [cited by examiner]
Lindell, Y., “Preventing loss of crypto assets with publicly verifiable encryption and backup”, Coinbase, Mar. 8, 2023, p. 1-5, www.coinbase.com/en-gb/blog/preventing-loss-of-crypto-assets-with-publicly-verifiable-encry… [cited by examiner]