Computer-implemented systems and methods for authorising blockchain transactions with low-entropy passwords
Abstract
There may be provided a blockchain-implemented security method involving a requestor and a group of nodes, which includes generating a cryptographic key of the requestor based on a password chosen by the requestor and first quantities sent by the group of nodes (which are derived from private key shares of the group of nodes and a generator function of a digital signature scheme employing a bilinear mapping on an elliptic curve). A cryptographic signature for a requestor blockchain transaction can be generated where the signature corresponds to the requestor's cryptographic key. The signature can be based on the password and second quantities sent by the group of nodes (which are also derived from the group private key shares). The method can further include verifying the cryptographic signature of the blockchain transaction using the requestor's cryptographic key. Additionally or alternatively, the method can employ a consensus mechanism involving the group of nodes to allow the requestor to authorise a transaction with a password. The method can be logically partitioned into a sequence of phases, including an initialisation phase, a funding phase, and a payment authorization phase (which involves a pre-spending transaction and a spending transaction).
Claims
exact text as granted — not AI-modified1 . A blockchain-implemented security method for a threshold signature scheme involving a requestor that belongs to a group of nodes in a blockchain network, the method performed at the requestor comprising:
generating a cryptographic public key of the requestor based on i) a password chosen by the requestor and ii) a plurality of first quantities received at the requestor, wherein the plurality of first quantities is sent to the requester by the group of nodes and is based on private key shares of the group of nodes and a generator function of a digital signature scheme employing a bilinear mapping on an elliptic curve; generating a cryptographic signature for a blockchain transaction of the requestor, the cryptographic signature corresponding to the cryptographic public key of the requestor based on the bilinear mapping on an elliptic curve of the digital signature scheme, wherein the cryptographic signature is based on i) the password chosen by the requestor and ii) a plurality of second quantities received at the requestor, wherein the plurality of second quantities is sent to the requester by the group of nodes and is based on the private key shares of the group of nodes; and verifying the cryptographic signature of the blockchain transaction using the cryptographic public key of the requestor.
2 . The blockchain-implemented security method according to claim 1 , further comprising:
establishing the group of nodes operably coupled to one another via at least one communication network, wherein each node of the group transfers a digital asset to the group; and/or receiving a funding transaction from a requestor, wherein the funding transaction specifies one or more digital assets of the requestor where all or some of such digital assets may be transferred using a password chosen by the requestor; and/or receiving a spending transaction that transfers some portion of the one or more digital assets of the requestor as specified in the funding transaction, wherein the spending transaction includes the cryptographic signature corresponding to the cryptographic public key of the requestor; and/or verifying the cryptographic signature included in the spending transaction using the cryptographic public key of the requestor.
3 . The blockchain-implemented security method according to claim 2 , further comprising:
receiving an initialisation transaction from the requestor, wherein the initialisation transaction indicates a desire to set the password associated with the requestor; and/or generating a first quantity in response to the initialisation transaction; and/or sending a first message to the requestor, wherein the first message includes the first quantity.
4 . The blockchain-implemented security method according to claim 2 , further comprising:
receiving a pre-spending transaction from the requestor, wherein the pre-spending transaction transfers a transaction deposit and includes a hash of at least part of the spending transaction, wherein the hash of at least part of the spending transaction is based on a hash function of the digital signature scheme; and/or generating a second quantity in response to the pre-spending transaction; and/or sending a second message to the requestor, wherein the second message includes the second quantity.
5 . The blockchain-implemented security method according to claim 1 , further comprising:
broadcasting a funding transaction from the requestor for communication to the group of nodes, wherein the funding transaction specifies one or more digital assets of the requestor where all or some of such digital assets may be transferred using a password chosen by the requestor; and/or broadcasting a spending transaction from the requestor for communication to the group of nodes, wherein the spending transaction transfers some portion of the one or more digital assets of the requestor as specified in the funding transaction, and wherein the spending transaction includes the cryptographic signature.
6 . The blockchain-implemented security method according to claim 5 , further comprising:
broadcasting an initialisation transaction from the requestor for communication to the group of nodes, wherein the initialisation transaction indicates a desire to set the password associated with the requestor, wherein the plurality of first quantities are generated and sent by the group of nodes in response to the initialisation transaction; and/or generating the cryptographic public key based at least in part on the password chosen by the requestor and the plurality of first quantities sent by the group of nodes in response to the initialisation transaction.
7 . The blockchain-implemented security method according to claim 5 , further comprising:
broadcasting a pre-spending transaction from the requestor for communication to the group of nodes, wherein the pre-spending transaction transfers a transaction deposit and includes a hash of at least part of the spending transaction, wherein the hash of at least part of the spending transaction is based on a hash function of the digital signature scheme, wherein the plurality of second quantities are generated and sent by the group of nodes in response to the pre-spending transaction.
8 . The blockchain-implemented security method according to claim 5 , further comprising:
establishing the group of nodes operably coupled to one another via at least one communication network, wherein each node of the group transfers a digital asset to the group, and wherein each node of the group stores a corresponding private key share; broadcasting, by a requestor system, an initialisation transaction from the requestor for communication to the group, wherein the initialisation transaction indicates a desire to set a password associated with the requestor; generating, by the nodes of the group, a plurality of first quantities in response to the initialisation transaction, wherein the first quantity generated by a given node is based at least in part on a private key share of the node and a generator function of the digital signature scheme; sending, by the nodes of the group, respective first messages to the requestor, wherein the first messages include the plurality of first quantities; generating, by the requestor system, the cryptographic public key based on the password chosen by the requestor and the plurality of first quantities; broadcasting, by the requestor system, a funding transaction from the requestor for communication to the group, wherein the funding transaction specifies one or more digital assets of the requestor where all or some of such digital assets may be transferred using the password chosen by the requestor; broadcasting, by the requestor system, a pre-spending transaction from the requestor for communication to the group, wherein the pre-spending transaction transfers a transaction deposit and includes a hash of an unsigned spending transaction that transfers some portion of certain funds of the requestor using a hash function of the digital signature scheme; generating, by the nodes of the group, a plurality of second quantities in response to the pre-spending transaction, wherein the second quantity generated by a given node is based at least in part on the hash of the unsigned spending transaction as included in the pre-spending transaction and the private key share of the node; sending, by the nodes of the group, second messages to the requestor, wherein the second messages include the plurality of second quantities; generating, by the requestor system, the cryptographic signature based on the password chosen by the requestor and the plurality of second quantities; broadcasting, by the requestor system, a spending transaction from the requestor for communication to the group, wherein the spending transaction transfers some portion of the certain funds of the requestor, and wherein the spending transaction is based on the unsigned spending transaction and includes the cryptographic signature; and verifying, by at least the nodes of the group, the cryptographic signature of the spending transaction using the cryptographic public key of the requestor.
9 . The blockchain-implemented security method according to claim 3 , wherein:
the initialisation transaction includes an initialisation fee that is paid by the requestor to the group; and/or the initialisation fee is paid to a public group address associated with the group; and/or the initialization fee is returned to the requestor in the event that at least one node of the group sends an inconsistent first quantity to the requestor; and/or inconsistency of the first quantity is determined using a verifiable secret sharing scheme.
10 . The blockchain-implemented security method according to claim 4 , wherein:
the pre-spending transaction further defines a spending fee; and/or the transaction deposit is locked under a public group address associated with the group; and/or the group selectively transfers the transaction deposit less the spending fee back to the requestor in the event that the verifying is successful; and/or the group selectively confiscates the transaction deposit in the event that the verifying fails; and/or the transaction deposit is returned to the requestor in the event that at least one node of the group of nodes sends an inconsistent second quantity to the requestor; and/or inconsistency of the second quantity is determined using a verifiable secret sharing scheme; and/or the spending fee is paid to a public group address associated with the group; and/or the nodes of the group verify that the spending fee is sufficient, wherein sufficiency of the spending fee is based on computation resources required to process a third transaction and the spending transaction; and/or the nodes of the group selectively bypass further processing of the pre-spending transaction in the event of failed verification of sufficiency of the spending fee; and/or the group selectively distributes the spending fee to the group in the event of successful verification of the signature of the spending transaction.
11 . The blockchain-implemented security method according to claim 2 , wherein:
the funding transaction specifies that the one or more digital assets of the requestor are locked by the cryptographic public key and thus can be spent by the cryptographic signature; and the verifying of the signature of the spending transaction is performed by the group and optionally by other nodes that do not belong to the group.
12 . The blockchain-implemented security method according to claim 2 , wherein:
the funding transaction specifies that the one or more digital assets of the requestor are locked by a public key of the group and thus can be spent by a signature based on a threshold number of private key shares of the group; the verifying of the signature of the spending transaction is performed only by the group; and upon successful verification of the signature of the spending transaction, the group cooperates to generate a signature based on a threshold number of private key shares of the group and to construct a secondary spending transaction that includes such signature.
13 . The blockchain-implemented security method according to claim 2 , wherein:
the plurality of first quantities are included in private messages sent from the nodes of the group to the requestor and/or are encrypted with a public key of the requestor; and/or the nodes of the group each have a trusted execution environment that stores a private key share of the node; and/or the trusted execution environment of the node generates the first quantity based at least in part on a private key share of the node and the generator function of the digital signature scheme; and/or the plurality of second quantities are included in private messages sent from the nodes of the group to the requestor and/or are encrypted with a public key of the requestor; and/or the trusted execution environment of the node generates the second quantity based at least in part on a hash of the unsigned spending transaction as included in a pre-spending transaction and a private key share of the node; and/or the private message sent from a node of the group to the requestor is associated with the public key of the trusted execution environment of the node and is signed with a corresponding private key of the trusted execution environment of the node; and/or one or more nodes mine the funding transaction and the spending transaction for storage in a proof-of-work blockchain.
14 . A computer readable storage medium comprising computer-executable instructions that, when executed, configure a processor to perform any part of the method of claim 1 .
15 . An electronic device comprising:
an interface device; a processor coupled to the interface device; and a memory coupled to the processor, the memory having stored thereon computer executable instructions that, when executed, configure the processor to perform any part of the method of claim 1 .Join the waitlist — get patent alerts
Track US2023131970A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.