Secure dynamic threshold signature scheme employing trusted hardware

US12513004B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12513004-B2
Application numberUS-202418679367-A
CountryUS
Kind codeB2
Filing dateMay 30, 2024
Priority dateMay 5, 2017
Publication dateDec 30, 2025
Grant dateDec 30, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques are presented for using a processing resource to control access to a resource. Steps comprise generating an elliptic curve digital signature algorithm signature comprising a first signature component, r, and a second signature component, w, the generation step comprising: forming, by a node, a signing group with other nodes; obtaining, by the node, based on a secure random number: a) a multiplicative inverse of the secure random number; and b) the first signature component, r, wherein the first signature component is determined based on the secure random number and an elliptic curve generator point; determining, by the node, a partial signature; receiving partial signatures from other nodes of the signing group; generating the second component; and using the signature to control access to the and/or transfer of a resource over a computer-implemented network.

First claim

Opening claim text (preview).

What is claimed is: 1 . A computer-implemented method of controlling access to a resource, the method implemented by a processing resource of a node in the blockchain network, the method comprising the step of: generating an elliptic curve digital signature algorithm signature comprising a first signature component, r, and a second signature component, w, to enable a threshold number of nodes to cooperatively sign a blockchain transaction without revealing private secret shares and without changing a group public key, the generation step comprising: forming, by the node, a signing group with other nodes; obtaining, by the processing resource of the node within an enclave of a trusted execution environment (TEE), based on a secure random number: a) a multiplicative inverse of the secure random number; and b) the first signature component, r, wherein the first signature component is determined based on the secure random number and an elliptic curve generator point; determining, by the processing resource of the node within the enclave of the TEE, a partial signature based on a private secret share, the multiplicative inverse of the secure random number, and the first signature component, r; receiving, by the processing resource of the node within the enclave of the TEE, partial signatures from other nodes of the signing group; generating, by the processing resource of the node within the enclave of the TEE, the second signature component, w, based on the determined partial signature and the received partial signatures; and using, by the node, the signature to control access to the resource and/or transfer of the resource. 2 . The computer-implemented method of claim 1 , wherein obtaining comprises generating, within the enclave, the multiplicative inverse and the first signature component, r, and wherein the method further comprises sending, from the enclave, the multiplicative inverse to the other nodes of the signing group. 3 . The computer-implemented method of claim 2 , wherein obtaining comprises provisioning the enclave associated with the TEE of the node to generate the secure random number. 4 . The computer-implemented method of claim 1 , wherein obtaining comprises receiving, within the enclave, the multiplicative inverse and the first signature component, r, from one of the other nodes of the signing group. 5 . The computer-implemented method of claim 1 , further comprising, prior to forming the signing group, signalling, by the node, an intention to participate in distributed signature generation for the blockchain transaction. 6 . The computer-implemented method of claim 1 , wherein the partial signature is determined by performing Lagrangian interpolation to compute a Lagrangian interpolation coefficient used in generating the partial signature based on the private secret share, the multiplicative inverse of the secure random number, and the first signature component, r. 7 . The computer-implemented method of claim 1 , wherein the method further includes, after generating the second signature component, w, sending the elliptic curve digital signature algorithm from the enclave to a host portion of the node for adding to the blockchain transaction. 8 . The computer-implemented method of claim 1 , further comprising adding the signature to the blockchain transaction and broadcasting the blockchain transaction to a blockchain network. 9 . The computer-implemented method of claim 1 , further comprising, prior to forming the signing group, obtaining the private secret share based on secret share data received from a plurality of existing members of the signing group. 10 . The computer-implemented method of claim 9 , wherein the private secret share is determined within the enclave. 11 . The computer-implemented method of claim 1 , wherein the partial signature, v i , is determined as: v i =k −1 rb i s i mod p, where b i is a Lagrangian interpolation coefficient, k −1 is the multiplicative inverse of the secure random number, s i is the private secret share, r is the first signature component, and p is an order. 12 . The computer-implemented method of claim 1 , wherein the resource is an unspent transaction output (UTXO) encumbered by the group public key, and wherein using the signature comprises unlocking the encumbrance on the UTXO to enable transfer of the UTXO in the blockchain transaction, the blockchain transaction being validated by a blockchain network to authorize access to a digital asset represented by the UTXO. 13 . The computer-implemented method of claim 1 , wherein using the signature to control access to the resource comprises executing a smart contract on a blockchain network, the smart contract verifying the signature to unlock a cryptographic lock controlling access to a hardware-based resource external to the blockchain network. 14 . The computer-implemented method of claim 13 , wherein the hardware-based resource comprises a physical access control device, and wherein executing the smart contract causes the physical access control device to transition from a locked state to an unlocked state to permit physical access to a restricted area or device. 15 . A non-transitory computer-readable storage medium comprising computer-executable instructions that, when executed by a processor of a node, cause the processor to perform a method of controlling access to a resource, the method comprising: generating an elliptic curve digital signature algorithm signature comprising a first signature component, r, and a second signature component, w, to enable a threshold number of nodes to cooperatively sign a blockchain transaction without revealing private secret shares and without changing a group public key, the generation step comprising: forming, by the node, a signing group with other nodes; obtaining, by the processor of the node within an enclave of a trusted execution environment (TEE) of the node, based on a secure random number: a) a multiplicative inverse of the secure random number; and b) the first signature component, r, wherein the first signature component is determined based on the secure random number and an elliptic curve generator point; determining, by the processor of the node within the enclave of the TEE, a partial signature based on a private secret share, the multiplicative inverse of the secure random number, and the first signature component, r; receiving, by the processor of the node within the enclave of the TEE, partial signatures from other nodes of the signing group; generating, by the processor of the node within the enclave of the TEE, the second signature component, w, based on the determined partial signature and the received partial signatures; and using, by the node, the signature to control access to the resource and/or transfer the resource. 16 . An electronic device, wherein the electronic device is a node, the electronic device comprising: an interface device to communicate with other nodes; a processor coupled to the interface device; and a memory coupled to the processor, the memory having stored thereon computer-executable instructions that, when executed by the processor, cause the processor to perform a method of controlling access to a resource, the method comprising: generating an elliptic curve digital signature algorithm signature comprising a first signature component, r, and a second signature component, w, to enable a threshold number of nodes to cooperatively sign a blockchain transaction without revealing private secret shares and without changing a g

Assignees

Inventors

Classifications

  • using hash chains, e.g. blockchains or hash trees · CPC title

  • Trusted platform modules [TPM] · CPC title

  • H04L9/3255Primary

    using group based signatures, e.g. ring or threshold signatures · CPC title

  • involving non-keyed hash functions, e.g. modification detection codes [MDCs], MD5, SHA or RIPEMD · CPC title

  • H04L9/085Primary

    Secret sharing or secret splitting, e.g. threshold schemes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12513004B2 cover?
Techniques are presented for using a processing resource to control access to a resource. Steps comprise generating an elliptic curve digital signature algorithm signature comprising a first signature component, r, and a second signature component, w, the generation step comprising: forming, by a node, a signing group with other nodes; obtaining, by the node, based on a secure random number: a)…
Who is the assignee on this patent?
Nchain Licensing Ag
What technology area does this patent fall under?
Primary CPC classification H04L9/3255. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 30 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).