IP Library Granted Patent US 12,732,384
Granted Patent B2
US 12,732,384 · App. 18/746,162 · Granted Sep 8, 2026

Systems and methods for securely adding and removing users from a signing group for key-based transactions in multi-party computation systems

Inventors: Nicolas Alhaddad (Boston, MA); Olaf Stelling (Florence, IT); Cat-Tuong Le-Huy (London, GB)
Assignee: MPC HOLDING, INC.
H04L9/3255H04L9/085H04L9/3247G06Q20/401H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,384
App. No.
18/746,162
Granted
Sep 8, 2026
Kind
B2
Abstract

The disclosure describes technology for adjusting a quantity of users in a signing group for authorizing transactions utilizing multi-party-computation (MPC). A method can include receiving, by a server from a first signing client device amongst signing client devices in a signing group, a request to add or remove a signing client device from the group, the group including a polynomial designating a first threshold of devices required to authorize a transaction using respective shares of a cryptographic key, transmitting, to each remaining device in the group, a request for authorizing the request, receiving, from each, authorization of the request, initiating communication amongst a modified group of devices resulting from the authorization to generate new shares of the cryptographic key based on a bivariate polynomial having a second threshold signing requirement different from the first threshold, authenticating the new shares using the second threshold, and returning authentication of the new shares.

Claims (52)

1 . A method for adjusting a quantity of users in a signing group for authorizing transactions utilizing multi-party-computation (MPC) across a network, the method comprising:

receiving, by a server from a first signing client device amongst a plurality of signing client devices included in a signing group, a request to add or remove at least one signing client device from the signing group, wherein the signing group includes a polynomial designating a first threshold of signing client devices in the signing group that is required to authorize a transaction using respective shares of a cryptographic key;

transmitting, by the server to each remaining signing client device in the signing group, a request for authorizing the request to add or remove the at least one signing client device from the signing group;

receiving, by the server from each remaining signing client device in the signing group, authorization of the request to add or remove the at least one signing client device from the signing group, wherein a modified signing group including a modified group of signing client devices results from the authorization of the request;

initiating, by the server in response to receiving the authorization from each remaining signing client device, communication amongst the modified group of signing client devices to generate new shares of the cryptographic key, wherein generating the new shares of the cryptographic key comprises:

computing a bivariate polynomial that has a second threshold signing requirement different from the first threshold, wherein the bivariate polynomial further comprises a constant coefficient that is shared amongst two univariate polynomials, wherein the two univariate polynomials are derived from the polynomial associated with the first threshold and the signing group, and

dynamically generating group authentication information associated with the modified group of signing client devices that includes the bivariate polynomial and the second threshold;

authenticating, by the server, the new shares using the second threshold; and

returning, by the server, authentication of the new shares of the cryptographic key.

2 . The method of claim 1 , wherein returning, by the server, authentication of the new shares of the cryptographic key comprises updating authentication information associated with the signing group to include information comprising unique identifiers corresponding to each signing client device of the modified group of signing client devices.

3 . The method of claim 1 , wherein initiating, by the server in response to receiving the authorization from each remaining signing client device, communication amongst the modified group of signing client devices to generate new shares of the cryptographic key comprises:

generating, by each signing client device in the modified group of signing client devices, a new random polynomial where a constant coefficient of the new random polynomial is an old share for the respective signing client device with the second threshold.

4 . The method of claim 3 , further comprising distributing, by each signing client device in the modified group of signing client devices, the new shares based on generating the new random polynomials.

5 . The method of claim 3 , further comprising:

aggregating, by each signing client device in the modified group of signing client devices, the new random polynomials of the signing client devices in the modified group to construct the bivariate polynomial of a degree to the first threshold in one dimension and the second threshold in a different dimension.

6 . The method of claim 4 , further comprising:

deleting, by each signing client device in the modified group of signing client devices, non-used shares of the cryptographic key.

7 . The method of claim 1 , further comprising:

receiving, by the server and from a primary client device, policy data that defines a transaction signing policy, wherein the policy data comprises:

(i) a designation of the signing group,

(ii) a designation of the plurality of signing client devices that are included in the signing group, and

(iii) for each transaction class of a plurality of transaction classes, a corresponding first threshold number of the plurality of signing client devices that is required to authorize the transaction, wherein the transaction is a member of the transaction class.

8 . The method of claim 1 , wherein the bivariate polynomial is private and unknown to each signing client device in the modified group of signing client devices.

9 . The method of claim 1 , wherein each signing client device in the modified group of signing client devices is configured to aggregate a respective new share with a respective original share to update the respective original share without changing the cryptographic key.

10 . A system for adjusting a quantity of users in a signing group for authorizing transactions utilizing multi-party-computation (MPC) across a network, the system comprising:

a plurality of signing client devices; and

a server in wireless network communication with the plurality of signing client devices, wherein the server is configured to:

receive, from a first signing client device amongst the plurality of signing client devices included in a signing group, a request to add or remove at least one signing client device from the signing group, wherein the signing group includes a polynomial designating a first threshold of signing client devices in the signing group that is required to authorize a transaction using respective shares of a cryptographic key;

transmit, to each remaining signing client device in the signing group, a request for authorizing the request to add or remove the at least one signing client device from the signing group;

receive, from each remaining signing client device in the signing group, authorization of the request to add or remove the at least one signing client device from the signing group, wherein a modified signing group including a modified group of signing client devices results from the authorization of the request;

initiate, in response to receiving the authorization from each remaining signing client device, communication amongst the modified group of signing client devices to generate new shares of the cryptographic key, wherein generating the new shares of the cryptographic key comprises:

computing a bivariate polynomial that has a second threshold signing requirement different from the first threshold, wherein the bivariate polynomial further comprises a constant coefficient that is shared amongst two univariate polynomials, wherein the two univariate polynomials are derived from the polynomial associated with the first threshold and the signing group, and

dynamically generating group authentication information associated with the modified group of signing client devices that includes the bivariate polynomial and the second threshold;

authenticate the new shares using the second threshold; and

return authentication of the new shares of the cryptographic key.

11 . The system of claim 10 , wherein returning authentication of the new shares of the cryptographic key comprises updating authentication information associated with the signing group to include information comprising unique identifiers corresponding to each signing client device of the modified group of signing client devices.

12 . The system of claim 11 , wherein the modified group of signing client devices includes the at least one signing client device that was added or removed from the signing group in response to and based on receiving the authorization of the request to add or remove the at least one signing client device from the signing group.

13 . The system of claim 10 , wherein initiating, in response to receiving the authorization from each remaining signing client device, communication amongst the modified group of signing client devices to generate new shares of the cryptographic key comprises:

generating, by each signing client device in the modified group of signing client devices, a new random polynomial where a constant coefficient of the new random polynomial is an old share for the respective signing client device with the second threshold.

14 . The system of claim 13 , further comprising distributing, by each signing client device in the modified group of signing client devices, the new shares based on generating the new random polynomials.

15 . The system of claim 13 , further comprising:

aggregating, by each signing client device in the modified group of signing client devices, the new random polynomials of the signing client devices in the modified group to construct the bivariate polynomial of a degree to the first threshold in one dimension and the second threshold in a different dimension.

16 . The system of claim 15 , further comprising:

deleting, by each signing client device in the modified group of signing client devices, non-used shares of the cryptographic key.

17 . The system of claim 10 , wherein the server is further configured to:

receive, from a primary client device, policy data that defines a transaction signing policy, wherein the policy data comprises:

(i) a designation of the signing group,

(ii) a designation of the plurality of signing client devices that are included in the signing group, and

(iii) for each transaction class of a plurality of transaction classes, a corresponding first threshold number of the plurality of signing client devices that is required to authorize the transaction, wherein the transaction is a member of the transaction class.

18 . The system of claim 10 , wherein the bivariate polynomial is private and unknown to each signing client device in the modified group of signing client devices.

19 . The system of claim 10 , wherein each signing client device in the modified group of signing client devices is configured to aggregate a respective new share with a respective original share to update the respective original share without changing the cryptographic key.

20 . The system of claim 10 , wherein the request to add or remove at least one signing client device from the signing group is received in response to initiating a regeneration cycle for the cryptographic key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2025
From: MPCH.IO LABS, INC.
To: MPC HOLDING, INC.
Reel/Frame 070162/0595 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2024
From: ALHADDAD, NICOLAS; STELLING, OLAF; LE-HUY, CAT-TUONG
To: MPCH.IO LABS, INC.
Reel/Frame 068345/0213 →
Continuity (2)
Provisional Application 63508958 · Jun 19, 2023
Related Publication 20260052026A1 · Feb 19, 2026
References Cited (35)
US 10084596B1 · Triandopoulos et al. · 2018 [cited by applicant]
US 10211977B1 · Roth et al. · 2019 [cited by applicant]
US 10291622B1 · Rossman et al. · 2019 [cited by applicant]
US 11418329B1 · Miller · 2022 [cited by applicant]
US 11431490B1 · Ranellucci · 2022 [cited by applicant]
US 11689371B2 · Yadlin · 2023 [cited by examiner]
US 12014361B2 · Suurkivi · 2024 [cited by examiner]
US 20170222802A1 · Rubin et al. · 2017 [cited by applicant]
US 20180167203A1 · Belenko · 2018 [cited by applicant]
US 20190372761A1 · Lampkins · 2019 [cited by examiner]
US 20200044863A1 · Yadlin et al. · 2020 [cited by applicant]
US 20200145231A1 · Trevethan · 2020 [cited by applicant]
US 20200153640A1 · Ranellucci · 2020 [cited by examiner]
US 20200204357A1 · Seyfried et al. · 2020 [cited by applicant]
US 20200213113A1 · Savanah et al. · 2020 [cited by applicant]
US 20200336313A1 · Knox · 2020 [cited by applicant]
US 20210051003A1 · Jarjoui et al. · 2021 [cited by applicant]
US 20210111877A1 · Craige · 2021 [cited by examiner]
US 20210119781A1 · Liu et al. · 2021 [cited by applicant]
US 20210135855A1 · Sunkavally · 2021 [cited by applicant]
US 20210158444A1 · Di Nicola et al. · 2021 [cited by applicant]
US 20210194676A1 · Mandal et al. · 2021 [cited by applicant]
US 20210273921A1 · Kumar et al. · 2021 [cited by applicant]
US 20230155989A1 · Kumar et al. · 2023 [cited by applicant]
US 20230245111A1 · Everspaugh et al. · 2023 [cited by applicant]
US 20230246850A1 · Everspaugh · 2023 [cited by examiner]
US 20230421397A1 · Ocegueda et al. · 2023 [cited by applicant]
US 20240296445A1 · Parry · 2024 [cited by examiner]
US 20240420125A1 · Le-Huy · 2024 [cited by examiner]
CN 115134086A · 2022 [cited by applicant]
A. Kate and I. Goldberg, “Distributed Key Generation for the Internet,” 2009 29th IEEE International Conference on Distributed Computing Systems, Montreal, QC, Canada, 2009, pp. 119-128, doi: 10.1109/ICDCS.2009.21. (Yea… [cited by examiner]
International Search Report and Written Opinion in PCT/US2024/034425, dated Oct. 9, 2024, 12 pages. [cited by applicant]
Kate et al., “Distributed Key Generation for the Internet”, Distributed Computing Systems, ICDCS 2009, 29th IEEE International Conference, Piscataway, NJ, Jun. 22, 2009, 20 pages. [cited by applicant]
Catrina et al., “Fostering the Uptake of Secure Multiparty Computation in E-Commerce”, Third International Conference on Availability, Reliability and Security, IEEE, Piscataway, NJ, Mar. 4, 2008, 9 pages. [cited by applicant]
Maram et al., “CHURP:Dynamic-Committee Proactive Secret Sharing”, In 2019 ACMS IGSAC Conference on Computer and Communications Security (CCS '19), Nov. 11-15, 2019, London, United Kingdom. ACM, New York, NY, USA, 18 pag… [cited by applicant]