IP Library › Granted Patent US 12,732,354
Granted Patent B2
US 12,732,354 · App. 18/689,794 · Granted Sep 8, 2026

Generating shared cryptographic keys

Inventors: Michaella Pettit (London, GB); Alexandru Paunoiu (London, GB); Craig Steven Wright (London, GB)
Assignee: nChain Licensing AG
H04L9/0861H04L9/085H04L9/14H04L9/3255
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,354
App. No.
18/689,794
Granted
Sep 8, 2026
Kind
B2
Abstract

A computer-implemented method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises: generating a first share of a first shared secret, wherein each other participant of the group generates a respective share of the first shared secret; and generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret.

Claims (48)

1 . A computer-implemented method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises:

coordinating with other participants in the group to generate a first share of a first shared secret using a secret sharing scheme, wherein each other participant of the group generates a respective share of the first shared secret;

generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret;

obtaining a message; and

generating a first share of a cryptographic digital signature by inputting the first share of the first shared private key and the message to a cryptographic digital signature algorithm and executing the cryptographic digital signature algorithm.

2 . The method of claim 1 , wherein each participant has a master public key corresponding to the master private key, and wherein the method comprises:

generating a public key corresponding to the first shared secret; and

generating a first public key corresponding to the first shared private key based on the master public key and the public key corresponding to the first shared secret.

3 . The method of claim 1 , comprising:

generating a first share of a second shared secret, wherein each other participant of the group generates a respective share of the second shared secret; and

generating a first share of a second shared private key based on the first share of the master private key and the first share of the second shared secret.

4 . The method of claim 1 , comprising:

generating a first share of a third shared secret, wherein each other participant of the group generates a respective share of the third shared secret; and

generating a first share of a third shared private key based on the first share of the first private key and the first share of the third shared secret.

5 . The method of claim 2 , comprising:

generating a first share of a third shared secret, wherein each other participant of the group generates a respective share of the third shared secret;

generating a first share of a third shared private key based on the first share of the first private key and the first share of the third shared secret;

generating a public key corresponding to the third shared secret; and

generating a third public key corresponding to the third shared private key based on the first public key and the public key corresponding to the third shared secret.

6 . The method of claim 1 , wherein the first share of the first shared private key is generated based on an elliptic curve addition of the first share of the master private key and the first share of the first shared secret.

7 . The method of claim 1 , wherein the first share of the first shared private key is generated based on an elliptic curve multiplication of the first share of the master private key and the first share of the first shared secret.

8 . The method of claim 1 , wherein a respective threshold of the master private key is the same as a respective threshold of the first shared secret.

9 . The method of claim 1 , wherein a respective threshold of the master private key is higher than a respective threshold of the first shared secret.

10 . The method of claim 1 , wherein a respective threshold of the master private key is less than a respective threshold of the first shared secret.

11 . The method of claim 1 , comprising:

generating a first share of a fourth shared secret, wherein each other participant of the group generates a respective share of the fourth shared secret, wherein the first shared private key is an intermediate private key, and wherein the first share of the intermediate private key is further based on the first share of the fourth shared secret;

making the first share of the intermediate private key available to each other participant of the group;

receiving a respective share of the intermediate private key from each other respective participant;

generating the intermediate private key based on the first share of the intermediate private key and the received respective shares of the intermediate private key; and

generating a first share of a fourth private key based on the intermediate private key and the first share of the fourth shared secret.

12 . The method of claim 11 , wherein each of the master private key, the first shared secret and the fourth shared secret have the same threshold.

13 . The method of claim 11 , wherein each of the master private key, the first shared secret and the fourth shared secret have the same threshold, wherein the first share of the intermediate private key is generated based on a multiplication of the first share of the master private key and the first share of the first shared secret, therefore resulting in the intermediate private key having a higher threshold than the master private key.

14 . The method of claim 11 , comprising:

obtaining a message; and

generating a first share of a digital signature based on the first share of the fourth shared private key and the message.

15 . The method of claim 1 , wherein the message comprises at least part of a blockchain transaction.

16 . A computing device, comprising:

memory comprising one or more memory units; and

processing apparatus comprising one or more processing units, wherein the memory stores code arranged to run on the processing apparatus, the code being configured so as when run on the processing apparatus, the processing apparatus performs a method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises:

coordinating with other participants in the group to generate a first share of a first shared secret using a secret sharing scheme, wherein each other participant of the group generates a respective share of the first shared secret;

generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret

obtaining a message; and

generating a first share of a cryptographic digital signature by inputting the first share of the first shared private key and the message to a cryptographic digital signature algorithm and executing the cryptographic digital signature algorithm.

17 . A computer program embodied on non-transitory computer-readable storage media and configured so as, when run on one or more processors, the one or more processors perform a method of generating a share of a shared private key, wherein each participant of a group of participants has a respective share of a master private key, and wherein the method is performed by a first participant of the group and comprises:

coordinating with other participants in the group to generate a first share of a first shared secret using a secret sharing scheme, wherein each other participant of the group generates a respective share of the first shared secret;

generating a first share of a first shared private key based on a first share of the master private key and the first share of the first shared secret;

obtaining a message; and

generating a first share of a cryptographic digital signature by inputting the first share of the first shared private key and the message to a cryptographic digital signature algorithm and executing the cryptographic digital signature algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2024
From: PETTIT, MICHAELLA; PAUNOIU, ALEXANDRU; WRIGHT, CRAIG STEVEN
To: NCHAIN LICENSING AG
Reel/Frame 066697/0096 →
Priority Claims (1)
GB 2112721 · Sep 7, 2021 · national
Continuity (1)
Related Publication 20240380581A1 · Nov 14, 2024
References Cited (40)
US 7136489B1 · Madhusudhana et al. · 2006 [cited by applicant]
US 9673975B1 · Machani · 2017 [cited by applicant]
US 9800411B1 · Brown · 2017 [cited by examiner]
US 10505723B1 · Griffin · 2019 [cited by examiner]
US 10903991B1 · Craige · 2021 [cited by examiner]
US 20120121088A1 · Hata · 2012 [cited by examiner]
US 20140281554A1 · Maletsky et al. · 2014 [cited by applicant]
US 20180212779A1 · Bergmann · 2018 [cited by examiner]
US 20200001456A1 · Golz · 2020 [cited by applicant]
US 20200074088A1 · Fu · 2020 [cited by applicant]
US 20200127829A1 · Hsiao et al. · 2020 [cited by applicant]
US 20210058233A1 · Lee · 2021 [cited by examiner]
US 20210073796A1 · Hennebert · 2021 [cited by examiner]
CN 105763333A · 2016 [cited by applicant]
CN 113079003A · 2021 [cited by examiner]
EP 3741081A1 · 2020 [cited by applicant]
JP H10200520A · 1998 [cited by applicant]
JP 2000075788A · 2000 [cited by applicant]
JP 2010272899A · 2010 [cited by examiner]
JP 2020043464A · 2020 [cited by applicant]
JP 2020531893A · 2020 [cited by applicant]
JP 2020532168A · 2020 [cited by applicant]
KR 20200123029A · 2020 [cited by examiner]
TW 1452889B · 2014 [cited by examiner]
WO 2017145016A1 · 2017 [cited by applicant]
WO 2019034986A1 · 2019 [cited by applicant]
WO WO2019034951A1 · 2019 [cited by examiner]
WO 2021073953A1 · 2021 [cited by applicant]
“Rosario Gennarto”, “Stanislaw Jarecki”, “Hugo Krawczyk”, “Tat Rabin”, “Robust Threshold Signatures” (Year: 1996). [cited by examiner]
“Steven Goldfeder”, “Rosario Gennaro”, “Harry Kalodner”, “Joseph Bonneau”, “Joshu A. Kroll”, “Edward W. Felten”, “Arivind Narayanan”, “Securing Bitcoin wallets via a new DSA/ECDSA threshold signature scheme” (Year: 2015… [cited by examiner]
“Steven Goldfeder”, “Rosario Gennaro”, “Harry Kalodner”, “Joseph Bonneau”, “Joshu A. Kroll”, “Edward W. Felten”, “Arivind Narayanan”, “Securing Bitcoin wallets via a new DSA/ECDSA threshold signature scheme” (Year: 2015… [cited by examiner]
GB2112719.6 Search Report dated Jan. 26, 2022 and Examination Report dated Jul. 11, 2023, 8 pages. [cited by applicant]
GB2112721.2 Search Report dated Jan. 28, 2022 and Examination Report dated Jul. 11, 2023, 7 pages. [cited by applicant]
Gennaro R et al., “Robust Threshold DSS Signatures”, Advances in Cryptology—EUROCRYPT '96. International Conference on the Theory and Application of Cryptographic Techniques. Saragossa, May 12-16, 1996; [Advances in Cry… [cited by applicant]
PCT/EP2022/072210 International Search Report and Written Opinion dated Dec. 7, 2022, 12 pages. [cited by applicant]
PCT/EP2022/072273 International Search Report and Written Opinion dated Dec. 8, 2022, 13 pages. [cited by applicant]
Steven Goldfeder et al., “Securing Bitcoin wallets via threshold signatures”, Jun. 3, 2014 (Jun. 3, 2014) XP055326412, Retrieved from the Internet: URL: http://www.cs.princeton.edu/~stevenag/bitcoin_threshold_signatures… [cited by applicant]
Steven Goldfeder et al: “Securing Bitcoin wallets via a new DSA/ECDSA threshold signature scheme”, cs.princeton, Mar. 8, 2015 (Mar. 8, 2015), pp. 1-26, XP055318844, Retrieved from the Internet: URL: https://www.cs.princ… [cited by applicant]
Wuille, Pieter, “Hierarchical Deterministic Wallets”, Github Bitcoin/bips, Feb. 11, 2012, github.com, URL: https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki. [cited by applicant]
Office Action for Japanese Patent Application No. 2024-514696, mailed Apr. 21, 2026, 12 pages. [cited by applicant]