IP Library Granted Patent US 12,639,705
Granted Patent B2
US 12,639,705 · App. 18/304,955 · Granted May 26, 2026

Methods and apparatus for provable backup confirmation for digital wallets using key shards

Inventors: Benjamin J. Ness (Sugar Grove, IL); Anna Rittenburg (Cambridge, MA); Paul J. Sussex (Chester, NJ); Yair Frankel (Westfield, NJ)
Assignee: EYGS LLP
G06Q20/3829G06Q20/3674G06Q20/3827
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,705
App. No.
18/304,955
Granted
May 26, 2026
Kind
B2
Abstract

An apparatus includes a custodial mechanism that receive, from each compute device from at a quorum, an encrypted shard associated with a private key of a digital wallet and a cryptographic proof. The encrypted shard can be generated using an encryption key for the compute device. The cryptographic proof indicates that the compute device can decrypt the encrypted shard using a decryption key associated with that compute device and without revealing a value of the private key for the digital wallet. The apparatus generates, for each compute device, a cryptographic proof verification based on the encrypted shard for that compute device and an encryption witness for the private key of the digital wallet. The cryptographic proof verification indicates that the set of shards decrypted from the set of encrypted shards can be combined to reconstruct the private key.

Claims (87)

1 . An apparatus comprising:

a processor; and

a memory operatively coupled to the processor, the memory storing instructions to cause the processor to:

set a predetermined count of compute devices in at least a quorum of compute devices;

select, from a plurality of compute devices and based on the predetermined count of compute devices, at least the quorum of compute devices;

generate a polynomial having (1) a degree that is based on the predetermined count of compute devices and (2) a set of coefficients that are randomly generated;

produce a plurality of shards based on a plurality of points on a curve defined by the polynomial;

cause the plurality of shards to be sent to each compute device from at least the quorum of compute devices;

in response to causing the plurality of shards to be sent to each compute device from at least the quorum of compute devices, receive, from each compute device that is from at least the quorum of compute devices, (1) an encrypted shard from a plurality of encrypted shards associated with a private key for a digital wallet, the encrypted shard generated from a shard that is from the plurality of shards and that was encrypted using an encryption key for that compute device, and (2) a cryptographic proof (a) from a plurality of cryptographic proofs, (b) being based on an encryption witness (i) for the private key for the digital wallet and (ii) determined by performing a group operation based on the private key for the digital wallet, and (c) indicating (i) that the compute device can decrypt the encrypted shard using a decryption key associated with that compute device and (ii) without revealing a value of the private key for the digital wallet; and

generate, for each compute device from at least the quorum of compute devices, a cryptographic proof verification from a plurality of cryptographic proof verifications based on the encrypted shard for that compute device and the encryption witness, the cryptographic proof verification indicating that the plurality of shards decrypted from the plurality of encrypted shards can be combined to reconstruct the private key for the digital wallet.

2 . The apparatus of claim 1 , wherein the cryptographic proof verification from the plurality of cryptographic proof verifications further indicates that at least a quorum of encrypted shards from the plurality of encrypted shards can be combined to generate an encrypted private key for the digital wallet without decryption of the plurality of encrypted shards.

3 . The apparatus of claim 2 , wherein:

the encrypted private key is generated from an encryption of the private key for the digital wallet using an encryption key for the digital wallet and that is associated with a decryption key for the digital wallet,

the cryptographic proof verification is a first cryptographic proof verification,

the plurality of cryptographic proof verifications is a first plurality of cryptographic proof verifications, and

the memory stores instructions to further cause the processor to:

generate, for each compute device from at least the quorum of compute devices, a decrypted shard from a plurality of decrypted shards from the decryption key for the digital wallet, the plurality of decrypted shards is periodically distributed among at least the quorum of compute devices;

receive, from each compute device from at least the quorum of compute devices, a second cryptographic proof from a plurality of second cryptographic proofs indicating that the plurality of decrypted shards can reconstruct the decryption key for the digital wallet; and

generate, for each compute device from at least the quorum of compute devices, a second cryptographic proof verification from a plurality of second cryptographic proof verifications based on the second cryptographic proof for that compute device, the second cryptographic proof verification indicating that the encrypted private key for the digital wallet can be decrypted using the decryption key for the digital wallet that was reconstructed using the plurality of decrypted shards.

4 . The apparatus of claim 1 , wherein the memory stores instructions to further cause the processor to:

generate, for one or more compute devices from at least the quorum of compute devices, a digital attestation (1) based on (a) the cryptographic proof verification for the one or more compute devices and (b) a private key of an asymmetric key pair for that compute device and (2) that indicates a reference to a public key for the digital wallet.

5 . The apparatus of claim 1 , wherein:

at least the quorum of compute devices is at least a first quorum of compute devices, and

each encrypted shard from the plurality of encrypted shards is divided into a new set of encrypted shards from a plurality of new sets of encrypted shards, the plurality of new sets of encrypted shards is associated with the private key for the digital wallet, each new set of encrypted shards from the plurality of new sets of encrypted shards is periodically distributed, prior to a future division of each new encrypted shard from each new set of encrypted shards, (1) among at least the first quorum of compute devices, (2) to at least a second quorum of compute devices from the plurality of compute devices that is different from at least the first quorum of compute devices, or (3) to at least a third quorum of compute devices from the plurality of compute devices, at least the third quorum of compute devices including one or more compute devices from at least the first quorum of compute devices and at least the second quorum of compute devices.

6 . The apparatus of claim 1 , wherein each cryptographic proof from the plurality of cryptographic proofs is a zero-knowledge proof (ZKP).

7 . The apparatus of claim 1 , wherein:

the encrypted shard from the plurality of encrypted shards for each compute device from at least the quorum of compute devices is included in a data element from a plurality of data elements recorded on a public platform,

for each compute device from at least the quorum of compute devices:

the cryptographic proof from the plurality of cryptographic proofs includes a hash value from a plurality of hash values that is computed based on a hash of the data element and a timestamp indicating that the cryptographic proof for that compute device is generated after the encrypted shard for that compute device was recorded on the public platform, and

the memory stores instructions to further cause the processor to:

generate, for each compute device from at least the quorum of compute devices, the cryptographic proof verification from the plurality of cryptographic proof verifications that is based on the cryptographic proof and the hash value for that compute device and that further confirms that the cryptographic proof for that compute device is generated after the data element associated with the encrypted shard for that compute device was recorded the public platform.

8 . The apparatus of claim 7 , wherein the public platform is a blockchain.

9 . The apparatus of claim 1 , wherein prior to receiving the encrypted shard from the plurality of encrypted shards, the memory stores instructions to cause the processor to:

set a predetermined threshold of shards; and

select, from the plurality of compute devices, at least the quorum of compute devices based on the predetermined threshold of shards, each compute device from the plurality of compute devices having at least one encrypted shard from the plurality of encrypted shards.

10 . The apparatus of claim 1 , wherein:

the cryptographic proof verification from the plurality of cryptographic proof verifications indicates validity of a public key of an asymmetric key pair for that compute device; and

the memory stores instructions to further cause the processor to:

generate, for one or more compute devices from at least the quorum of compute devices, a digital attestation from a plurality of digital attestations based on the cryptographic proof verification for the one or more compute devices and that indicates a reference to a public key for the digital wallet, and

transmit the plurality of digital attestations to a public platform such that the digital attestation associated with the compute device that owns the digital wallet can prove that the public key from the cryptographic proof for that compute device is the public key for the digital wallet.

11 . The apparatus of claim 1 , wherein the instructions to cause the processor to generate the cryptographic proof verification include instructions to cause the processor to:

generate a challenge based on a hash of the encryption witness;

in response to generating the challenge, receive a response from the compute device associated with that encrypted shard; and

generate the cryptographic proof verification based on the challenge and the response.

12 . An apparatus comprising:

a processor; and

a memory operatively coupled to the processor, the memory storing instructions to cause the processor to:

set a predetermined count of compute devices in at least a quorum of compute devices;

select, from a plurality of compute devices and based on the predetermined count of compute devices, at least the quorum of compute devices;

generate a polynomial having (1) a degree that is based on the predetermined count of compute devices and (2) a set of coefficients that are randomly generated;

produce a plurality of shards based on a plurality of points on a curve defined by the polynomial;

cause the plurality of shards to be sent to each compute device from at least the quorum of compute devices;

in response to causing the plurality of shards to be sent to each compute device from at least the quorum of compute devices, receive, from each compute device from at least the quorum of compute devices, (1) an encrypted shard from a plurality of encrypted shards associated with (a) a private key of a digital wallet and (b) the plurality of shards and (2) a first cryptographic proof (a) from a plurality of first cryptographic proofs, (b) being based on an encryption witness for the private key, the encryption witness being determined by performing a group operation based on the private key, and (c) indicating that that compute device can decrypt the encrypted shard;

generate, for each compute device from at least the quorum of compute device, a first cryptographic proof verification from a plurality of first cryptographic proof verifications based on the encrypted shard for that compute device and the encryption witness for the private key, the first cryptographic proof verification indicating that the plurality of encrypted shards can be combined to reconstruct an encrypted private key for the digital wallet without decryption of the plurality of encrypted shards;

generate, for each compute device from at least the quorum of compute devices, a decrypted shard from a plurality of decrypted shards from a decryption key for the digital wallet, the plurality of decrypted shards being periodically distributed among at least the quorum of compute devices;

receive, from each compute device from at least the quorum of compute devices, a second cryptographic proof from a plurality of second cryptographic proofs indicating that the plurality of decrypted shards can reconstruct the decryption key for the digital wallet; and

generate, for each compute device from at least the quorum of compute devices, a second cryptographic proof verification from a plurality of second cryptographic proof verifications based on the second cryptographic proof for that compute device indicating that the encrypted private key for the digital wallet can be decrypted using the decryption key that was reconstructed using the plurality of decrypted shards.

13 . The apparatus of claim 12 , wherein:

at least the quorum of compute devices is at least a first quorum of compute devices, and

the plurality of decrypted shards is periodically distributed to (1) at least a second quorum of compute devices from the plurality of compute devices that is different from at least the first quorum of compute devices or (2) to at least a third quorum of compute devices from the plurality of compute devices, at least the third quorum of compute devices including one or more compute devices from at least the first quorum of compute devices and at least the second quorum of compute devices.

14 . The apparatus of claim 12 , wherein:

the first cryptographic proof verification from the plurality of first cryptographic proof verifications indicates validity of a public key of an asymmetric key pair for that compute device, and

the memory stores instructions to further cause the processor to:

generate, for each compute device from at least the quorum of compute devices, a digital attestation from a plurality of digital attestations based on the first cryptographic proof verification for that compute device and indicating a reference to a public key for the digital wallet; and

transmit the plurality of digital attestations to a public platform such that the digital attestation associated with the compute device that owns the digital wallet can prove that the public key from the first cryptographic proof for that compute device is the public key for the digital wallet.

15 . The apparatus of claim 12 , wherein the memory stores instructions to further cause the processor to:

derive the private key for the digital wallet to generate a plurality of child private keys, the plurality of child private keys distributed among each compute device from at least the quorum of compute devices;

receive, from each compute device from at least the quorum of compute devices, a derivation path that is from a plurality of derivation paths that is used to derive the private key for the digital wallet into a child private key (1) for that compute device and (2) from the plurality of child private keys; and

generate, for each compute device from at least the quorum of compute devices, a path proof from a plurality of path proofs based on the derivation path for that compute device and that indicates that a child public key is associated with the child private key derived from that derivation path.

16 . The apparatus of claim 12 , wherein:

at least the quorum of compute devices is at least a first quorum of compute devices, and

each encrypted shard from the plurality of encrypted shards is divided into a new set of encrypted shards from a plurality of new sets of encrypted shards, the plurality of new sets of encrypted shards is associated with the private key for the digital wallet, each new set of encrypted shards from the plurality of new sets of encrypted shards is periodically distributed, prior to a future division of each new encrypted shard from each new set of encrypted shards, (1) among at least the first quorum of compute devices, (2) to at least a second quorum of compute devices from the plurality of compute devices that is different from at least the first quorum of compute devices, or (3) to at least a third quorum of compute devices from the plurality of compute devices, at least the third quorum of compute devices including one or more compute devices from at least the first quorum of compute devices and at least the second quorum of compute devices.

17 . The apparatus of claim 12 , wherein each first cryptographic proof from the plurality of first cryptographic proofs and each second cryptographic proof from the plurality of second cryptographic proofs is a zero-knowledge proof (ZKP).

18 . The apparatus of claim 12 , wherein the memory stores instructions to further cause the processor to:

generate, for each compute device from at least the quorum of compute devices, transaction data from a plurality of transaction data based on the encrypted shard for that compute device;

transmit each transaction data from the plurality of transaction data to a public platform to be posted on the public platform, each transaction data from the plurality of transaction data including a timestamp indicating a time in which that transaction data was posted on the public platform; and

for each compute device from at least the quorum of compute devices, the first cryptographic proof verification from the plurality of first cryptographic proof verifications based on the first cryptographic proof and the timestamp of the transaction data for that compute device and indicating that the transaction data for that compute device was posted on the public platform before the first cryptographic proof was generated.

19 . A non-transitory, processor-readable medium storing instructions that executed by a processor, cause the processor to:

set a predetermined count of compute devices in at least a quorum of compute devices;

select, from a plurality of compute devices and based on the predetermined count of compute devices, at least the quorum of compute devices;

generate a polynomial having (1) a degree that is based on the predetermined count of compute devices and (2) a set of coefficients that are randomly generated;

produce a plurality of shards based on a plurality of points on a curve defined by the polynomial;

cause the plurality of shards to be sent to each compute device from at least the quorum of compute devices;

in response to causing the plurality of shards to be sent to each compute device from at least the quorum of compute devices, receive, from each compute device that is from at least the quorum of compute devices, (1) an encrypted shard from a plurality of encrypted shards associated with a private key for a digital wallet, the encrypted shard generated from a shard from the plurality of shards that was encrypted using an encryption key for that compute device, and (2) a cryptographic proof from a plurality of cryptographic proofs, the cryptographic proof for that compute device (a) being based on an encryption witness for the private key and (b) indicating that that compute device can decrypt the encrypted shard from the plurality of encrypted shards and for that compute device using a decryption key associated with that compute device;

generate, for each compute device from at least the quorum of compute devices, a cryptographic proof verification from a plurality of cryptographic proof verifications based on the encrypted shard for that compute device and the encryption witness, the cryptographic proof verification for that compute device indicating that the plurality of shards decrypted from the plurality of encrypted shards can be combined to reconstruct the private key for the digital wallet; and

transmit a notification including the plurality of cryptographic proof verifications to at least the quorum of compute devices.

20 . The non-transitory, processor-readable medium of claim 19 , wherein verifying the reconstructed private key includes attempting to unlock the digital wallet using the reconstructed private key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2026
From: NESS, BENJAMIN J.; RITTENBURG, ANNA; SUSSEX, PAUL J.; FRANKEL, YAIR; ERNST & YOUNG U.S. LLP
To: EYGS LLP
Reel/Frame 074503/0470 →
Continuity (1)
Related Publication 20240354753A1 · Oct 24, 2024
References Cited (26)
US 4926479A · Goldwasser · 1990 [cited by examiner]
US 10846372B1 · Jayachandran · 2020 [cited by examiner]
US 11831760B1 · Kaplan · 2023 [cited by examiner]
US 20150220928A1 · Allen · 2015 [cited by examiner]
US 20170048209A1 · Lohe · 2017 [cited by examiner]
US 20190318356A1 · Martin et al. · 2019 [cited by applicant]
US 20200153627A1 · Wentz · 2020 [cited by examiner]
US 20210083882A1 · Venable, Sr. · 2021 [cited by examiner]
US 20240283636A1 · Jen · 2024 [cited by examiner]
CN 115941163A · 2023 [cited by applicant]
WO WO2024092935A1 · 2024 [cited by examiner]
WO WO2024218262A1 · 2024 [cited by applicant]
Robin Vassantlal, et al., COBRA: Dynamic Proactive Secret Sharing for Confidential BFT Services, Jul. 27, 2022, IEEE, pp. 1335-1353 (Year: 2022). [cited by examiner]
Kun Peng, Verifiable Secret Sharing with Comprehensive and Efficient Public Verification, Jul. 2011, HAL Open Science, pp. 1-15 (Year: 2011). [cited by examiner]
International Search Report and Written Opinion in Intl. Application No. PCT/EP2024/060647, mailed Jul. 15, 2024, 18 pages. [cited by applicant]
Peng, K., “Verifiable secret sharing with comprehensive and efficient public verification,” 23rd Data and Applications Security (DBSec), Jul. 2011, Richmond, VA, pp. 217-230. [cited by applicant]
Aumasson, Jean-Phillippe et al., “A Survey of ECDSA Threshold Signing,” Cryptology ePrint Archive, 2020, 14 pages (EN abstract only). [cited by applicant]
Bin-Bin, Tu et al., “A Survey of Threshold Cryptosystems,” Journal of Cryptologic Research, 2020, vol. 7, No. 1, pp. 1-14. [cited by applicant]
Brandao, L. et al., “Threshold Schemes for 3 Cryptographic Primitives: Challenges and Opportunities in Standardization and Validation of Threshold Cryptography,” NISTIR, Mar. 1, 2019, 119 pages. [cited by applicant]
Desmedt, YG, “Threshold Cryptography,” Encyclopedia of Cryptography and Security, Jul. 1994, vol. 5, No. 4, pp. 449-458. [cited by applicant]
Kaur, R. et al., “Survey on Different Techniques of Threshold Cryptography,” IOSR Journal of Electronics and Communication Engineering (IOSR-JECE) 2017, pp. 114-119. [cited by applicant]
Sarma, K.N. et al., “A Review of Secret Sharing Schemes,” Research Journal of Information Technology, 2013, vol. 5, No. 2, pp. 67-72. [cited by applicant]
Sun, X. et al., “A Survey on Zero-Knowledge Proof in Blockchain,” IEEE Network, Jul./Aug. 2021, vol. 35, No. 4, pp. 198-205. [cited by applicant]
Venukumar, V. et al., “A survey of applications of threshold cryptography: proposed and practiced,” Information Security Journal: A Global Perspective, Dec. 1, 2016, vol. 25, No. 4-6, pp. 180-190. [cited by applicant]
Desmedt, Y., “Threshold Cryptography”. In: van Tilborg, H.C.A. (eds) Encyclopedia of Cryptography and Security. Springer, Oct. 2005, pp. 606-611. [cited by applicant]
Varghese, P. E. et al., “A Study On The Existing Threshold Cryptography Techniques,” International Journal of Advanced Research in Computer Science, Sep.-Oct. 2020, vol. 11, No. 5, pp. 70-73. [cited by applicant]