IP Library › Granted Patent US 12,580,774
Granted Patent B2
US 12,580,774 · App. 17/919,994 · Granted Mar 17, 2026

Digital signatures of messages using signature shares

Inventor: Michaella Pettit (London, GB)
Assignee: nChain Licensing AG
H04L9/3257H04L9/0894H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,774
App. No.
17/919,994
Granted
Mar 17, 2026
Kind
B2
Abstract

A computer-implemented method of generating a share of a digital signature of a message, wherein a threshold number of different signature shares from respective participants of a group of participants are required to generate the digital signature, wherein each participant has a respective private key share, the method being performed by a first one of the participants and comprising: generating a first message-independent component and a first message-dependent component, wherein the message-independent component is generated based on a first private key share and wherein the message-dependent component is generated based on the message; causing the first message-independent component to be made available to a coordinator; and causing a first signature share to be made available to the coordinator for generating the signature based on at least the threshold number of signature shares, wherein the first signature share comprises at least the message-dependent component.

Claims (47)

1 . A computer-implemented method of participating in a threshold signature scheme for generating a digital signature (r, s) of a message m, wherein the digital signature comprises an r value and an s value, wherein a threshold number of different shares of the s value generated by respective participants of a group of participants are required to generate the s value of the digital signature, wherein each participant has a respective private key share a i of a private key a corresponding to a public key P that is usable to validate the digital signature, wherein each participant has a respective ephemeral private key share k i of an ephemeral private key k, and wherein the method is performed by a first one of the participants and comprises:

prior to obtaining the message m, generating a first message-independent component of a first share s i of the s value, wherein the first message-independent component is generated as a function of a first private key share a i of the private key a but not as a function of the message m,

after obtaining the message m, generating a first message-dependent component of the first share s i of the s value, wherein the first message-dependent component is generated as a function of a cryptographic hash of the message m,

wherein the first message-independent component and/or the first message-dependent component is also generated as a function of a first ephemeral private key share k i of the ephemeral private key k,

and

causing a first signature share s i to be made available to the coordinator, wherein the first signature share s i is generated as a function of the first message-independent component and the first message-dependent component, and wherein the coordinator is configured to generate the signature based on each of at least the threshold number of respective signature shares s i , each respective signature share s; being generated by a respective participant and being generated as a function of a respective message-independent component and a respective message-dependent component, the respective message-independent component being generated by the respective participant as a function of the respective private key share a i of the private key a and the respective message-dependent component being generated by the respective participant as a function of the cryptographic hash of the message m, wherein the respective message-independent component and/or the respective message-dependent component is also generated as a function of a respective ephemeral private key share k i of the ephemeral private key k.

2 . The method of claim 1 , wherein the first private key share is generated using a joint secret sharing scheme for generating a share of a first private key.

3 . The method of claim 2 , wherein the first ephemeral private key share is generated using the joint secret sharing scheme for generating a share of the ephemeral private key.

4 . The method of claim 1 , wherein the first value is generated based on an inverse corresponding to the first ephemeral private key share.

5 . The method of claim 4 , wherein generating the inverse of the first ephemeral private key share comprises:

generating an intermediate value based on the ephemeral private key and a first blinding key; and

generating the inverse of the first ephemeral private key share based on an inverse of the intermediate value and a first blinding key share of the first blinding key.

6 . The method of claim 5 , wherein the first blinding key share is generated using a joint secret sharing scheme for generating a share of the first blinding key.

7 . The method of claim 5 , wherein the intermediate value is generated by:

generating a first multiplicative key share based on the first ephemeral private key share and the first blinding key share;

obtaining a respective multiplicative key share from at least the threshold number of participants; and

generating the intermediate value based on the first multiplicative key share and each of the respective multiplicative key shares.

8 . The method of claim 5 , wherein the second value is generated based on a second blinding key share of a second blinding key.

9 . The method of claim 8 , wherein the second blinding key share is generated using a joint secret sharing scheme for generating a share of the second blinding key.

10 . The method of claim 4 , wherein the second value is generated based on a first pre-signature share, wherein the first pre-signature share is generated based on:

a first intermediary share, the first intermediary share being generated based on the first private key share and the inverse corresponding to the first ephemeral private key share; and

a respective intermediary share obtained from at least the threshold number of participants.

11 . The method of claim 5 , wherein the second value is generated based on a first pre-signature share, wherein the first pre-signature share is generated based on:

a first intermediary share, the first intermediary share being generated based on the first private key share and the first blinding key share; and

a respective intermediary share obtained from at least the threshold number of participants.

12 . The method of claim 11 , wherein the first pre-signature share is generated based on the inverse corresponding to the first ephemeral private key share.

13 . The method of claim 10 , wherein the first intermediary share is generated based on a second blinding key share.

14 . The method of claim 10 , wherein the first pre-signature share is generated based on the shared value.

15 . The method of claim 14 , wherein the first intermediary share is generated based on the shared value.

16 . The method of claim 1 , wherein the message comprises at least part of a blockchain transaction.

17 . The method of claim 1 , wherein the threshold number of participants is less than a total number of participants in the group of participants.

18 . Computer equipment comprising:

memory comprising one or more memory units; and

processing apparatus comprising one or more processing units, wherein the memory stores code arranged to run on the processing apparatus, the code being configured so as when run on the processing apparatus, the processing apparatus performs a method of

participating in a threshold signature scheme for generating a digital signature (r, s) of a message m, wherein the digital signature comprises an r value and an s value, wherein a threshold number of different shares of the s value generated by respective participants of a group of participants are required to generate the s value of the digital signature, wherein each participant has a respective private key share a i of a private key a corresponding to a public key P that is usable to validate the digital signature, wherein each participant has a respective ephemeral private key share k i of an ephemeral private key k, and wherein the method is performed by a first one of the participants and comprises:

prior to obtaining the message m, generating a first message-independent component of a first share s i of the s value, wherein the first message-independent component is generated as a function of a first private key share a i of the private key a but not as a function of the message m,

after obtaining the message m, generating a first message-dependent component of the first share s i of the s value, wherein the first message-dependent component is generated as a function of the message m,

wherein the first message-independent component and/or the first message-dependent component is also generated as a function of a first ephemeral private key share k i of the ephemeral private key k,

and

causing a first signature share s i to be made available to the coordinator, wherein the first signature share s i is generated as a function of the first message-independent component and the first message-dependent component, and wherein the coordinator is configured to generate the signature based on each of at least the threshold number of respective signature shares s i , each respective signature share s i being generated by a respective participant and being generated as a function of a respective message-independent component and a respective message-dependent component, the respective message-independent component being generated by the respective participant as a function of the respective private key share a i of the private key a and the respective message-dependent component being generated by the respective participant as a function of the message m, wherein the respective message-independent component and/or the respective message-dependent component is also generated as a function of a respective ephemeral private key share k i of the ephemeral private key k.

19 . A computer program embodied on computer-readable storage and configured so as, when run on computer equipment, to perform a method of

participating in a threshold signature scheme for generating a digital signature (r, s) of a message m, wherein the digital signature comprises an r value and an s value, wherein a threshold number of different shares of the s value generated by respective participants of a group of participants are required to generate the s value of the digital signature, wherein each participant has a respective private key share a i of a private key a corresponding to a public key P that is usable to validate the digital signature, wherein each participant has a respective ephemeral private key share k i of an ephemeral private key k, and wherein the method is performed by a first one of the participants and comprises:

prior to obtaining the message m, generating a first message-independent component of a first share s i of the s value, wherein the first message-independent component is generated as a function of a first private key share a i of the private key a but not as a function of the message m,

after obtaining the message m, generating a first message-dependent component of the first share s i of the s value, wherein the first message-dependent component is generated as a function of the message m,

wherein the first message-independent component and/or the first message-dependent component is also generated as a function of a first ephemeral private key share k i of the ephemeral private key k,

and

causing a first signature share s i to be made available to the coordinator, wherein the first signature share s i is generated as a function of the first message-independent component and the first message-dependent component, and wherein the coordinator is configured to generate the signature based on each of at least the threshold number of respective signature shares s i , each respective signature share s i being generated by a respective participant and being generated as a function of a respective message-independent component and a respective message-dependent component, the respective message-independent component being generated by the respective participant as a function of the respective private key share a i of the private key a and the respective message-dependent component being generated by the respective participant as a function of the message m, wherein the respective message-independent component and/or the respective message-dependent component is also generated as a function of a respective ephemeral private key share k i of the ephemeral private key k.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2022
From: PETTIT, MICHAELLA
To: NCHAIN LICENSING AG
Reel/Frame 061485/0698 →
Priority Claims (1)
GB 2005953 · Apr 23, 2020 · national
Continuity (1)
Related Publication 20230163977A1 · May 25, 2023
References Cited (40)
US 7434046B1 · Srivastava · 2008 [cited by applicant]
US 8392716B2 · Oishi · 2013 [cited by applicant]
US 8490164B2 · Takahashi et al. · 2013 [cited by applicant]
US 9680654B2 · Lam · 2017 [cited by applicant]
US 11063754B2 · Vakili et al. · 2021 [cited by applicant]
US 11716617B2 · Wentz · 2023 [cited by applicant]
US 11979507B2 · Fletcher · 2024 [cited by examiner]
US 12107955B2 · Savanah · 2024 [cited by examiner]
US 12192381B2 · Beery · 2025 [cited by examiner]
US 12238222B2 · Wright · 2025 [cited by examiner]
US 12254452B2 · Wright · 2025 [cited by examiner]
US 20080270790A1 · Brickell et al. · 2008 [cited by applicant]
US 20100215172A1 · Schneider · 2010 [cited by examiner]
US 20110208970A1 · Brown et al. · 2011 [cited by applicant]
US 20140325227A1 · Brown · 2014 [cited by applicant]
US 20160301526A1 · Rietman et al. · 2016 [cited by applicant]
US 20170324548A1 · Anshel et al. · 2017 [cited by applicant]
US 20180367298A1 · Wright · 2018 [cited by examiner]
US 20200084048A1 · Lindell · 2020 [cited by examiner]
US 20200274704A1 · Matsui et al. · 2020 [cited by applicant]
US 20210111875A1 · Saint · 2021 [cited by applicant]
US 20230015219A1 · Lam · 2023 [cited by examiner]
US 20230163977A1 · Pettit · 2023 [cited by examiner]
US 20240121109A1 · Pettit · 2024 [cited by applicant]
CN 108964906A · 2018 [cited by applicant]
WO 2017145010 · 2017 [cited by applicant]
WO 2019166915A1 · 2019 [cited by applicant]
WO 2019193452 · 2019 [cited by applicant]
Goldfeder, Steven and Arvind Narayanan. “Securing Bitcoin wallets via a new DSA / ECDSA threshold signature scheme.” (2015). (Year: 2015). [cited by examiner]
Boneh, D., Gennaro, R., Goldfeder, S. (2019). Using Level-1 Homomorphic Encryption to Improve Threshold DSA Signatures for Bitcoin Wallet Security. In: Lange, T., Dunkelman, O. (eds) Progress in Cryptology—LATINCRYPT 20… [cited by examiner]
Philip MacKenzie, Michael K. Reiter, “Two-party generation of DSA signatures”, Jul. 21, 2004, Springer Verlag, p. 218-239. (Year: 2004). [cited by examiner]
Philip MacKenzie, Michael K. Reiter, “Two-Party Generation of DSA Signatures (Extended Abstract)”, Advances in Cryptology—CRYPTO 2001, Aug. 2001, p. 1-18. (Year: 2001). [cited by examiner]
Catrina O., et al., “Fostering the Uptake of Secure Multiparty Computation in E-Commerce,” 2008 Third International Conference on Availability, Reliability and Security (ARES 08), Mar. 4, 2008, XP031257563, pp. 693-700. [cited by applicant]
Gennaro R., et al., “Threshold-optimal DSA/ECDSA Signatures and an Application to Bitcoin Wallet Security,” LNSC, Applied Cryptography and Network Security (ACNS2016), Jun. 9, 2016, vol. 9696, pp. 156-174. [cited by applicant]
PCT/EP2021/060032 International Search Report and Written Opinion dated Sep. 9, 2021, 15 pages. [cited by applicant]
Anders Dalskov et al: “Securing DNSSEC Keys via Threshold ECDSA From Generic MPC”, IACR, International Association for Cryptologic Research vol. 20190805:221846 Aug. 5, 2019 (Aug. 5, 2019), pp. 1-24, XP061033215, Retrie… [cited by applicant]
Dikshit Pratyush et al: “Efficient weighted threshold ECDSA for securing bitcoin wallet”, 2017 ISEA Asia Security and Privacy (ISEASP), IEEE, Jan. 29, 2017 (Jan. 29, 2017), pp. 1-9, XP033117504, DOI: 10.1 109/ISEASP.201… [cited by applicant]
Marc Green et al: “Strength in Numbers: Threshold ECDSA to Protect Keys in the Cloud”, IACR, International Association for Cryptologic Research, vol. 20151205:042955, Dec. 4, 2015 (Dec. 4, 2015), pp. 1-19, XP061019773, … [cited by applicant]
Gennaro, R, et al. “Robust threshold DSS signatures.” International Conference on the Theory and Applications of Cryptographic Techniques. Springer, Berlin, Heidelberg, 1996. [cited by applicant]
Gennaro, R, and Goldfeder, S. “Fast multiparty threshold ECDSA with fast trustless setup.” Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018. [cited by applicant]