IP Library Granted Patent US 12,732,386
Granted Patent B2
US 12,732,386 · App. 18/854,450 · Granted Sep 8, 2026

Statement proof and verification

Inventor: Enrique Larraia (London, GB)
Assignee: nChain Licensing AG
H04L9/3271H04L9/0825H04L9/0869H04L9/3013H04L9/3066H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,386
App. No.
18/854,450
Granted
Sep 8, 2026
Kind
B2
Abstract

A method of proving that a secret committed in a commitment is a discrete logarithm of a public element of a finite group of data elements, comprising: obtaining a first vector used to generate the commitment, the first vector comprising n components, wherein one of the n components of the first vector is at a position which corresponds to the secret; generating a second vector comprising n components, wherein a component of the second vector, at a predetermined position corresponding to the position in the first vector, is set to zero; generating a further commitment to the second vector; transmitting the further commitment to a verifying device; receiving a random challenge from the verifying device; generating a response using the first vector, the second vector and the random challenge; and transmitting the response to the verifying device to prove that the secret is the discrete logarithm of the public element.

Claims (43)

1 . A computer implemented method of proving that a secret that is committed in a batched commitment is a discrete logarithm of a public element of a finite group of data elements, the method performed on a computing device and comprising:

obtaining a first vector used to generate the batched commitment, the first vector comprising n components, wherein the secret is one of the n components of the first vector at a position in the first vector;

generating a second vector comprising n components, wherein a component of the second vector, at a predetermined position corresponding to the position in the first vector, is set to zero;

generating a further batched commitment to the second vector;

transmitting the further batched commitment to a verifying computing device;

receiving a random challenge from the verifying computing device;

generating a response to the random challenge using the first vector, the second vector and the random challenge; and

transmitting the response to the verifying computing device to prove that the secret is the discrete logarithm of the public element.

2 . The computer implemented method of claim 1 , wherein the finite group of data elements are of an elliptic curve.

3 . The computer implemented method of claim 2 , wherein the element of said finite group of data elements is a public key and the secret is a signing key.

4 . The computer implemented method of claim 2 , wherein generating the further batched commitment to the second vector uses a commitment key vector comprising n components from the finite group of data elements and one of the n components of the commitment key vector is a base point of the elliptic curve at a predetermined position which corresponds to the position in the first vector, the public element obtained by multiplying said base point with the secret.

5 . The computer implemented method of claim 1 , wherein generating the response to the random challenge comprises:

modifying the first vector by replacing the secret at said position with a zero to generate a modified first vector;

generating a response vector by combining the modified first vector with the second vector using the random challenge;

wherein the response comprises the response comprising the response vector.

6 . The computer implemented method of claim 1 , wherein remaining components of the second vector are random values.

7 . The computer implemented method of claim 1 , further comprising generating a random element, and generating the further batched commitment using the random element.

8 . The computer implemented method of claim 7 , wherein the method further comprises generating a combined random element by combining the random element with a further random element used to generate the batched commitment, wherein the response comprises the combined random element.

9 . The computer implemented method of claim 1 , wherein the batched commitment is a batched Pedersen commitment.

10 . The computer implemented method of claim 1 , wherein the further batched commitment is a batched Pedersen commitment.

11 . A computer implemented method of verifying that a secret that is committed in a batched commitment is a discrete logarithm of a public element of a finite group of data elements, the method performed on a computing device and comprising:

obtaining the batched commitment, wherein the batched commitment is a commitment to a first vector comprising n components and one of the n components of the first vector is the secret and is at a position in the first vector;

receiving a further batched commitment from a proving computing device, wherein the further batched commitment is a commitment to a second vector comprising n components, wherein a component of the second vector, at a predetermined position corresponding to the position in the first vector, is set to zero;

in response to receiving the further batched commitment generating a random challenge and transmitting the random challenge to the proving computing device;

receiving a response to the random challenge from the proving computing device; and

verifying that the secret is the discrete logarithm of the public element using the response, the batched commitment, the further batched commitment, and the random challenge.

12 . The computer implemented method of claim 11 , wherein the response comprises a response vector that is a combination of a modified first vector and the second vector using the random challenge, the modified first vector corresponding to the first vector wherein the secret at said position has been replaced with a zero.

13 . The computer implemented method of claim 12 , wherein the response vector comprises a plurality of components, and said verifying comprises determining that a component of the plurality of components of the response vector, at a predetermined position which corresponds to the position in the first vector, is non-zero.

14 . The computer implemented method of claim 11 , wherein the finite group of data elements are of an elliptic curve.

15 . The computer implemented method of claim 12 , wherein the public element of said finite group of data elements is a public key and the secret is a signing key.

16 . The computer implemented method of claim 14 , the method comprising:

computing a combined commitment using the batched commitment, the random challenge, the further batched commitment and the public element of said finite group of data elements; and

verifying that the secret is the discrete logarithm of the public element using the response, the combined commitment, and a commitment key vector, wherein the commitment key vector comprises n components from the finite group of data elements and one of the n components of the commitment key vector is a base point of the elliptic curve at a predetermined position which corresponds to the position in the first vector, the public element obtained by multiplying said base point with the secret.

17 . The computer implemented method of claim 1 , wherein remaining components of the second vector are random values.

18 . The computer implemented method of claim 1 , wherein the batched commitment is a batched Pedersen commitment.

19 . A non-transitory computer readable storage medium comprising computer readable instructions that, when executed by a computing device, cause the computing device to perform a method of proving that a secret that is committed in a batched commitment is a discrete logarithm of a public element of a finite group of data elements, the method performed on a computing device and comprising:

obtaining a first vector used to generate the batched commitment, the first vector comprising n components, wherein the secret is one of the n components of the first vector at a position in the first vector;

generating a second vector comprising n components, wherein a component of the second vector, at a predetermined position corresponding to the position in the first vector, is set to zero;

generating a further batched commitment to the second vector;

transmitting the further batched commitment to a verifying computing device;

receiving a random challenge from the verifying computing device;

generating a response to the random challenge using the first vector, the second vector and the random challenge; and

transmitting the response to the verifying computing device to prove that the secret is the discrete logarithm of the public element.

Priority Claims (1)
GB 2205173 · Apr 8, 2022 · national
Continuity (1)
Related Publication 20250233763A1 · Jul 17, 2025
References Cited (21)
US 8654974B2 · Anderson · 2014 [cited by examiner]
US 10491390B2 · Gurkan et al. · 2019 [cited by applicant]
US 10846372B1 · Jayachandran et al. · 2020 [cited by applicant]
US 11310060B1 · Poelstra et al. · 2022 [cited by applicant]
US 11394550B2 · Youssef · 2022 [cited by applicant]
US 20150207630A1 · Shimoyama · 2015 [cited by examiner]
US 20170279611A1 · Kraemer et al. · 2017 [cited by applicant]
US 20170317834A1 · Smith et al. · 2017 [cited by applicant]
US 20190295182A1 · Kfir et al. · 2019 [cited by applicant]
US 20210028939A1 · Trevethan et al. · 2021 [cited by applicant]
US 20210226795A1 · Covaci et al. · 2021 [cited by applicant]
US 20220075879A1 · Hamburg · 2022 [cited by examiner]
US 20220085984A1 · Khandani · 2022 [cited by examiner]
US 20230071022A1 · Hong · 2023 [cited by examiner]
US 20230254115A1 · Hamburg · 2023 [cited by examiner]
US 20230401033A1 · Ikarashi · 2023 [cited by examiner]
US 20250117217A1 · Heinecke · 2025 [cited by examiner]
GB2205173.4 Combined Search and Examination Report dated Sep. 30, 2022, 7 pages. [cited by applicant]
GB2205183.3 Combined Search and Examination Report dated Sep. 21, 2022, 5 pages. [cited by applicant]
PCT/EP2023/058236 International Search Report and Written Opinion dated Jul. 10, 2023, 10 pages. [cited by applicant]
PCT/EP2023/058242 International Search Report and Written Opinion dated Jul. 13, 2023, 10 pages. [cited by applicant]