Generating shared cryptographic keys
A computer-implemented method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises: generating a first share of a first shared secret, wherein each other participant of the group generates a respective share of the first shared secret; and generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret.
1 . A computer-implemented method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises:
coordinating with other participants in the group to generate a first share of a first shared secret using a secret sharing scheme, wherein each other participant of the group generates a respective share of the first shared secret;
generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret;
obtaining a message; and
generating a first share of a cryptographic digital signature by inputting the first share of the first shared private key and the message to a cryptographic digital signature algorithm and executing the cryptographic digital signature algorithm.
2 . The method of claim 1 , wherein each participant has a master public key corresponding to the master private key, and wherein the method comprises:
generating a public key corresponding to the first shared secret; and
generating a first public key corresponding to the first shared private key based on the master public key and the public key corresponding to the first shared secret.
3 . The method of claim 1 , comprising:
generating a first share of a second shared secret, wherein each other participant of the group generates a respective share of the second shared secret; and
generating a first share of a second shared private key based on the first share of the master private key and the first share of the second shared secret.
4 . The method of claim 1 , comprising:
generating a first share of a third shared secret, wherein each other participant of the group generates a respective share of the third shared secret; and
generating a first share of a third shared private key based on the first share of the first private key and the first share of the third shared secret.
5 . The method of claim 2 , comprising:
generating a first share of a third shared secret, wherein each other participant of the group generates a respective share of the third shared secret;
generating a first share of a third shared private key based on the first share of the first private key and the first share of the third shared secret;
generating a public key corresponding to the third shared secret; and
generating a third public key corresponding to the third shared private key based on the first public key and the public key corresponding to the third shared secret.
6 . The method of claim 1 , wherein the first share of the first shared private key is generated based on an elliptic curve addition of the first share of the master private key and the first share of the first shared secret.
7 . The method of claim 1 , wherein the first share of the first shared private key is generated based on an elliptic curve multiplication of the first share of the master private key and the first share of the first shared secret.
8 . The method of claim 1 , wherein a respective threshold of the master private key is the same as a respective threshold of the first shared secret.
9 . The method of claim 1 , wherein a respective threshold of the master private key is higher than a respective threshold of the first shared secret.
10 . The method of claim 1 , wherein a respective threshold of the master private key is less than a respective threshold of the first shared secret.
11 . The method of claim 1 , comprising:
generating a first share of a fourth shared secret, wherein each other participant of the group generates a respective share of the fourth shared secret, wherein the first shared private key is an intermediate private key, and wherein the first share of the intermediate private key is further based on the first share of the fourth shared secret;
making the first share of the intermediate private key available to each other participant of the group;
receiving a respective share of the intermediate private key from each other respective participant;
generating the intermediate private key based on the first share of the intermediate private key and the received respective shares of the intermediate private key; and
generating a first share of a fourth private key based on the intermediate private key and the first share of the fourth shared secret.
12 . The method of claim 11 , wherein each of the master private key, the first shared secret and the fourth shared secret have the same threshold.
13 . The method of claim 11 , wherein each of the master private key, the first shared secret and the fourth shared secret have the same threshold, wherein the first share of the intermediate private key is generated based on a multiplication of the first share of the master private key and the first share of the first shared secret, therefore resulting in the intermediate private key having a higher threshold than the master private key.
14 . The method of claim 11 , comprising:
obtaining a message; and
generating a first share of a digital signature based on the first share of the fourth shared private key and the message.
15 . The method of claim 1 , wherein the message comprises at least part of a blockchain transaction.
16 . A computing device, comprising:
memory comprising one or more memory units; and
processing apparatus comprising one or more processing units, wherein the memory stores code arranged to run on the processing apparatus, the code being configured so as when run on the processing apparatus, the processing apparatus performs a method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises:
coordinating with other participants in the group to generate a first share of a first shared secret using a secret sharing scheme, wherein each other participant of the group generates a respective share of the first shared secret;
generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret
obtaining a message; and
generating a first share of a cryptographic digital signature by inputting the first share of the first shared private key and the message to a cryptographic digital signature algorithm and executing the cryptographic digital signature algorithm.
17 . A computer program embodied on non-transitory computer-readable storage media and configured so as, when run on one or more processors, the one or more processors perform a method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises:
coordinating with other participants in the group to generate a first share of a first shared secret using a secret sharing scheme, wherein each other participant of the group generates a respective share of the first shared secret;
generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret;
obtaining a message; and
generating a first share of a cryptographic digital signature by inputting the first share of the first shared private key and the message to a cryptographic digital signature algorithm and executing the cryptographic digital signature algorithm.