US10652014B2 — Determining a common secret for the secure exchange of information and hierarchical, deterministic cryptographic keys
Document text
Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.
US010652014B2
United States Patent (10 ) Patent No.: US 10,652,014 B2
Wright et al. (45 ) Date of Patent: May 12 , 2020
(54 ) DETERMINING A COMMON SECRET FOR (56 ) References Cited
THE SECURE EXCHANGE OF
INFORMATION AND HIERARCHICAL , U.S. PATENT DOCUMENTS
DETERMINISTIC CRYPTOGRAPHIC KEYS 2/1997 Rueppel et al.
5,600,725 A
(71) Applicant: nChain Holdings Limited, St. John's 5,761,305 A 6/1998 Vanstone et al.
(AG ) (Continued )
(72 ) Inventors: Craig Steven Wright, London (GB );
Stephane Savanah , London (GB ) FOREIGN PATENT DOCUMENTS
(73 ) Assignee: nChain Holdings Limited , St. Johns AU 2016100059 A4 3/2016
(AG ) CN 103440209 A 12/2013
( * ) Notice : Subject to any disclaimer , the term of this (Continued )
patent is extended or adjusted under 35
U.S.C. 154 (b ) by 77 days . OTHER PUBLICATIONS
(21) Appl. No.: 16 /078,630
(22) PCT Filed : Feb. 16 , 2017 UK Commercial Search Report dated May 9 , 2016 , Patent Appli
cation No. GB1603114.8 , filed Feb. 23 , 2016 , 2 pages .
( 86 ) PCT No .: PCT/ IB2017 /050856 (Continued )
§ 371 (c ) ( 1 ),
(2 ) Date : Aug. 21, 2018 Primary Examiner Samson B Lemma
(87 ) PCT Pub . No.: WO2017 / 145016 (74 ) Attorney, Agent, or Firm — Davis Wright Tremaine
PCT Pub. Date : Aug. 31 , 2017 LLP
(65 ) Prior Publication Data
US 2019/0052458 A1 Feb. 14 , 2019 (57 ) ABSTRACT
( 30 ) Foreign Application Priority Data A method (300) and system ( 1 ) of determining a common
Feb. 23 , 2016 (GB) 1603117.1 secret for two nodes (3 , 7). Each node (3, 7) has a respective
Nov. 15 , 2016 (GB ) 1619301.3
asymmetric cryptography pair, each pair including a master
private key and a master public key. Respective second
(51) Int. Ci. private and public keys may be determined based on the
H04L 9/32 ( 2006.01 ) master private key, master public key and a deterministic
H04L 9/08 ( 2006.01) key. A common secret may be determined at each of the
(Continued ) nodes based on the second private and public keys . In one
(52) U.S. CI. example , a node (3 , 7 ) may determine the common secret
CPC H04L 9/0825 ( 2013.01) ; H04L 9/008 based on (i) a second private key based on the node's own
( 2013.01) ; H04L 9/0844 ( 2013.01); master private key and the deterministic key ; and ( ii ) a
(Continued ) second public key based on the other node's master public
(58 ) Field of Classification Search key and the deterministic key. The invention may be suited
CPC ... HO4L 9/0825 ; H04L 9/3066 ; H04L 9/0844 ; for use with , but not limited to , digital wallets , blockchain
HO4L 9/008 ; H04L 9/0861; H04L ( e.g. Bitcoin ) technologies and personal device security .
2209/56
(Continued ) 47 Claims, 11 Drawing Sheets
3 Network
First node Second node
Share message (M ) between the first and second modes
300 400
330
Determine a first rode second private Determine a first node second public
key ( Vac ) based on the first nede key (Pac ) based on the first rode
master private key Vid )and the master publickey Pc)and the
deterministic key (OK) determiniclic key (DK)
Cenerate a first signed message SM1) 350 430
based on the message (N ) and the first
node second private key ( 2c ).
Sond the first signed message ( 541) 360
to the cond node. 440
Receive the first signed message( SH1}
from the first node.
450 Validate signature on the first sigted
Inessage (SMS) with the determined
first node second public key Pac)
460
Authenticate the first node base on the
370 result of valldatingfirst signed message (SM1)
Determine a second node second public 470 Determine a second node second private
key (Pas) based on te second node key (Vas)based on the second node
master public key (Pis ) and the master private key(V5) and the
deterministic key(DO deterministic key (DK )
480
Determine corrmon secret (CS) based on Determine common se gre (CS )based on
first node second private key (V2c ) and second node second private key Vas !
380
Second node second public key (P2s), and first node second public key (P2c ).
US 10,652,014 B2
Page 2
(51) Int. Ci. 2015/0324764 A1 11/2015 Van Rooyen et al.
H04L 9/30 (2006.01 ) 2015/0332224 A1 11/2015 Melika et al.
H04L 9/00 (2006.01) 2015/0350171 A1 12/2015 Brumley
2015/0356523 A1 12/2015 Madden
(52) U.S. CI. 2015/0363770 A1 12/2015 Ronca et al.
CPC H04L 9/0861 (2013.01) ; H04L 9/3066 2016/0086175 A1 3/2016 Finlow -Bates et al.
( 2013.01 ); H04L 2209/56 (2013.01 ) 2016/0092988 A1 3/2016 Letourneau
2016/0140335 Al 5/2016 Proulx et al .
(58 ) Field of Classification Search 2016/0149878 A1 5/2016 Pogorelik et al.
USPC 713/168 , 171 2016/0261408 Al 9/2016 Peddada et al.
See application file for complete search history . 2016/0261565 A1 9/2016 Lorenz et al.
2016/0269182 Al 9/2016 Sriram et al .
(56 ) References Cited 2016/0283941 Al 9/2016 Andrade
2016/0335924 Al 11/2016 Ikarashi et al.
U.S. PATENT DOCUMENTS 2016/0352518 A1 12/2016 Ford et al.
2016/0379208 A1 12/2016 Deliwala et al.
5,889,865 A 3/1999 Vanstone et al. 2017/0103385 A1 4/2017 Wilson , Jr. et al.
5,896,455 A 4/1999 Vanstone et al. 2017/0132621 A1 5/2017 Miller et al .
5,933,504 A 8/1999 Vanstone et al. 2017/0154331 A1 6/2017 Voorhees
6,061,449 A 5/2000 Candelore et al . 2017/0243193 A1 8/2017 Manian et al .
6,078,667 A 6/2000 Johnson 2017/0250801 A1 8/2017 Chen et al.
6,122,736 A 9/2000 Vanstone et al . 2018/0109377 Al 4/2018 Fu
6,141,420 A 10/2000 Vanstone et al. 2018/0367298 A1 12/2018 Wright et al.
6,618,483 B1 9/2003 Vanstone et al. 2019/0149337 A1 5/2019 Savanah et al.
6,704,870 B2 3/2004 Vanstone et al . 2019/0158470 A1 5/2019 Wright et al.
6,785,813 B1 8/2004 Vanstone et al. 2019/0220859 Al 7/2019 Weight et al.
6,792,530 B1 9/2004 Qu et al. 2019/0229911 A1 7/2019 Allen
7,006,633 B1 * 2/2006 Reece HO4L 9/08 2019/0238334 A1 * 8/2019 Nakamura G06F 21/44
380/260
7,095,851 B1 8/2006 Scheidt FOREIGN PATENT DOCUMENTS
8,522,011 B2 8/2013 Spalka et al. 103927656 A
9,209,980 B2 * 12/2015 Bowman HO4L 9/3273 CN 7/2014
9,258,130 B2 * 2/2016 Hwang H04L 9/08 DE 102010002241 B4 3/2012
10,050,779 B2 8/2018 Alness et al . EP 1477882 A2 11/2004
10,068,228 B1 9/2018 Winklevoss et al. EP 2538606 A1 12/2012
2001/0050990 A1 12/2001 Sudia EP 2975570 A1 1/2016
2003/0046202 A1 3/2003 Knapp FR 3018370 A1 9/2015
2004/0049687 A1 3/2004 Orsini et al . FR 3018377 A1 9/2015
2004/0193890 A1 9/2004 Girault FR 3018378 A1 9/2015
2006/0023887 Al 2/2006 Agrawal et al. FR 3018379 A1 9/2015
2006/0153368 A1 7/2006 Beeson JP H11289324 A 10/1999
2006/0156013 A1 7/2006 Beeson JP 2000502553 A 2/2000
2006/0179319 Al 8/2006 Krawczyk JP 2007242221 A 9/2007
2007/0055880 A1 3/2007 Lauter et al . JP 2009526411 A 7/2009
2007/0192842 Al 8/2007 Beaulieu et al. JP 2011082662 A 4/2011
2008/0082817 A1 4/2008 Takahashi et al. WO 2005107141 A1 11/2005
2008/0144836 A1 6/2008 Sanders et al. WO 2013053058 Al 4/2013
2008/0288773 A1 11/2008 Nguyen et al. WO 2015127789 A1 9/2015
2009/0161876 A1 6/2009 Sherkin WO 2015171580 A1 11/2015
2010/0023771 A1 1/2010 Struik WO 2015175854 A2 11/2015
2010/0131755 Al 5/2010 Zhu et al. WO 2016161073 Al 10/2016
2010/0150341 A1 6/2010 Dodgson et al.
2010/0172501 Al 7/2010 Tian et al. OTHER PUBLICATIONS
2010/0199095 A1 8/2010 Ho
2010/0228973 Al 9/2010 Dancer et al. UK IPO Search Report dated Jul. 26 , 2016 , Patent Application No.
2011/0022854 A1 1/2011 Macchetti et al .
2011/0202773 A1 8/2011 Ghouti et al . GB1603114.8 , filed Feb. 23 , 2016 , 5 pages.
2011/0307698 Al 12/2011 Vanstone UK IPO Search Report dated Jul. 4 , 2016 , Patent Application No.
2011/0311051 A1 12/2011 Resch et al. GB1603125.4 , filed Feb. 23 , 2016 , 6 pages.
2012/0011362 Al 1/2012 Lambert UK IPO Search Report dated Jul. 5 , 2016 , Patent Application No.
2012/0039474 A1 2/2012 Ho GB1603123.9 , filed Feb. 23, 2016 , 5 pages.
2012/0100833 A1 4/2012 Gao UK IPO Search Report dated Oct. 17, 2016 , Patent Application No.
2012/0290830 A1 11/2012 Resch et al . GB1603117.1, filed Feb. 23 , 2016 , 5 pages.
2012/0331287 Al 12/2012 Bowman et al. UK IPO Search Report dated Oct. 26 , 2016 , Patent Application No.
2013/0051552 A1 2/2013 Handschuh et al. GB1603122.1, filed Feb. 23 , 2016 , 4 pages .
2013/0061049 Al 3/2013 Irvine UK IPO Search Report dated Sep. 9 , 2016 , Patent Application No.
2013/0177157 A1 7/2013 Li et al. GB1605571.7 , filed Apr. 1, 2016 , 5 pages.
2013/0191632 A1 7/2013 Spector et al. Whitequark ,“ # bitcoin -wizardson Jul. 30 , 2015 — irc logs atwhitequark .
2014/0082358 Al 3/2014 Nakhjiri et al. org ," whitequark.org , https://irclog.whitequark.org/bitcoin-wizards/
2014/0129844 A1 5/2014 Johnson et al. 2015-07-30 , Jul. 30 , 2015 (retrieved Dec. 12 , 2018 ], 8 pages.
2015/0066748 Al 3/2015 Winslow et al . Wikipedia , “ Shamir's Secret Sharing,” Wikipedia the Free Ency
2015/0086020 A1 3/2015 Harjula et al. clopedia, Jan. 20, 2017 version (retrieved on Jan. 9 , 2019 ], https: //
2015/0188700 Al 7/2015 Ben Saied et al.
2015/0205929 Al 7/2015 Brama en.wikipedia.org/w/index.php?title=Shamir’s_Secret_Sharing&oldid=
2015/0206106 Al 7/2015 Yago 761082071, 6 pages .
2015/0213433 A1 * 7/2015 Khan G06Q 20/3227 Wikipedia, “ Shamir's Secret Sharing,” Wikipedia the Free Ency
705/71 clopedia,Mar. 6 , 2016 version [retrieved on Jun . 24 , 2019 ], https: //
2015/0302401 A1 10/2015 Metral en.wikipedia.org/w/index.php?title=Shamir’s_Secret_Sharing&oldid=
2015/0304302 Al 10/2015 Zhang 708636892, 6 pages .
US 10,652,014 B2
Page 3
( 56 ) References Cited Friedenbach et al., “Freimarkets : extending bitcoin protocol with
user-specified bearer instruments, peer-to -peer exchange , off -chain
OTHER PUBLICATIONS accounting, auctions, derivatives and transitive transactions,” Ver
sion v0.01, http://freico.in/docs/freimarkets-v0.0.1.pdf, Aug. 24 ,
Wood , “ Ethereum : A Secure Decentralised Generalised Transaction 2013 [retrieved Dec. 12 , 2018 ], 25 pages.
Ledger: Final Draft — Under Review ," Etereum Project Yellow Gennaro et al.,“ Threshold -Optimal DSA /ECDSA Signatures and an
Paper, http://tech.lab.carl.pro/kb/ethereum/yellowpaper, Apr. 2014 , Application to Bitcoin Wallet Security,” International Conference
32 pages. on Applied Cryptography and Network Security, Jun . 9 , 2016 , 42
Wright,“ Registry and Automated ManagementMethod for Blockchain pages.
Enforced Smart Contracts,” U.S. Appl. No. 15/ 138,717 , filed Apr. Gitbook , “ Ethereum Frontier Guide,” Gitbook ( Legacy ), Feb. 4 ,
26 , 2016 . 2016 , 293 pages.
Wuille, “ HierarchicalDeterministic Wallets,” Github , https:// github . Goldfeder et al., “ Securing Bitcoin Wallets via a New DSA /ECDSA
com /bitcoin /bips/blob /ab90b5289f0356282397fa9b8aa47d2238a7b380 / threshold signature scheme,” manuscript, https://www.cs.princeton .
bip -0032.mediawiki, Feb. 12 , 2016 (retrieved Mar. 23, 2017), 9 edu/~ stevenag/threshold_sigs.pdf, 2015 [retrieved Jun . 21, 2018 ],
pages. 26 pages.
Zyskind et al., “Decentralizing Privacy : Using a Blockchain to Gutoski et al., “ Hierarchical deterministic Bitcoin wallets that
Protect Personal Data,” 2015 IEEE CS Security and Privacy Work tolerate key leakage ( Short paper)," Financial Cryptography and
shops, May 21 , 2015 , 5 pages . Data Security : 19th International Conference, FC 2015 , Revised
“ Bitcoin Developer Guide,” Bitcoin Project, https://web.archive . Selected Papers, Jan. 26 , 2015 , 9 pages.
org/web /20160515171209/https://bitcoin.org/en/developer-guide,May Hao , “ On Robust Key Agreement Based on Public Key Authenti
15, 2016 [retrieved Mar. 13 , 2019 ], 55 pages . cation ,” International Conference on Financial Cryptography and
Allison , “ Symbiont's Adam Krellenstein : There's really only two Data Security , Jan. 25 , 2010 , 12 pages .
smart contract systems— Ethereum's and ours," International Busi Harayama et al., “ Key escrow method of personal decryptographic
ness Times, https://www.ibtimes.co.uk/symbionts-adam-krellenstein key by using elliptic curve calculation,” Institute of Electronics,
theres-really -only -two- smart- contract -systems-ethereums-ours Information and Communication Engineers ( IEICE) Technical Report
1530490 , Nov. 25 , 2015 [retrieved Dec. 12 , 2018 ], 4 pages. 109( 85 ) :91-96 , Jun . 11 , 2009 .
Antonopoulos, “Mastering Bitcoin Unlocking Digital Cryptocur Herbert et al., “ A Novel Method for Decentralised Peer- to -Peer
rencies,” O'Reilly Media , Inc., Dec. 20 , 2014, 282 pages . Software License Validation Using Cryptocurrency Blockchain
bitcoininvestor.com , “ All-Star Panel:Ed Moy, Joseph VaughnPerling , Technology," Proceedings of the 38th Australasian Computer Sci
Trace Mayer, Nick Szabo , Dr. Craig Wright,” YouTube, https: // ence Conference , Jan. 27 , 2015 , 9 pages .
youtu.be/LdvQTwjVmrE , Bitcoin Investor Conference, Oct. 29, International Search Report and Written Opinion dated Apr. 26 ,
2015 [retrieved Dec. 12 , 2018 ], 1 page . 2017 , International Patent Application No. PCT/IB2017 /050865,
Bitfury Group , “ Smart Contracts on Bitcoin Blockchain ,” BitFury filed Feb. 16 , 2017, 9 pages.
Group Limited , Aug. 13 , 2015 (updated Sep. 4 , 2015 ), http : // bitfury . International Search Report and Written Opinion dated Apr. 3, 2017 ,
com /content/5 -white-papers-research/contracts- 1.1.1.pdf, 20 pages. Patent Application No. PCT/IB2017 /050824 , filed Feb. 14 , 2017 , 13
Brow et al., “ Standards for Efficient Cryptography : Elliptic pages .
Curve Cryptography Version 2.0," Certicom Research , May 21, International Search Report and Written Opinion dated May 29 ,
2009, 144 pages.
Brown et al., “ Standards for Efficient Cryptography 2 : Recom 2017 , International Patent Application No. PCT/IB2017 /050815 ,
mended Elliptic Curve Domain Parameters Version 2.0 ,” Certicom filed Feb. 14 , 2017, 10 pages.
Research , Jan. 27, 2010 , 37 pages . International Search Report and Written Opinion dated May 31 ,
Buterin , “ Secret Sharing DAOs: The Other Crypto 2.0 ," Ethereum 2017, Patent Application No. PCT/IB2017 /050856 , filed Feb. 16 ,
Blog , Dec. 26 , 2014 [retrieved Nov. 21 , 2019 ], https:// ethereum . 2017, 11 pages .
github.io/blog/2014/12/26/secret-sharing-daos-crypto-2-01, 10 pages. Killerstorm et al., “ Transcript for # bitcoin -dev Sep. 3 , 2012 ,"
Campagna et al., “ Standards for Efficient Cryptography 4 : Elliptic BitcoinStats, http://www.bitcoinstats.com/irc/bitcoin-dev/logs/2012/
Curve Qu - Vanstone Implicit Certificate Scheme (ECRV ) Version 09/03 , Sep. 3 , 2012 [retrieved Dec. 21 , 2018 ], 14 pages .
1.0 ,” Certicom Research , Jan. 24 , 2013 , 32 pages. Koblitz et al., “ Cryptocash , Cryptocurrencies, and Cryptocontracts ,"
Coinprism , “ 80 bytes OP_RETURN explained ,” Coinprism Blog, Designs, Codes and Cryptography 78 (1 ):87-102 , publication avail
http://blog.coinprism.com/2015/02/11/80-bytes-op-return/, Feb. 11, able online Oct. 1 , 2015 , print publication Jan. 2016 .
2015 [retrieved Dec. 21 , 2018 ], 8 pages . Krawczyk , " HMQV: A High - Performance Secure Diffie-Hellman
Corallo, “ [Bitcoin -development ] Relative CheckLockTimeVerify Protocol,” Annual International Cryptology Conference 2005, Aug.
(was CLTV proposal),” Linux Foundation, https://lists.linuxfoundation . 14 , 2005 , first disclosed online Jul. 5 , 2005, 66 pages.
org/ pipermail/bitcoin -dev /2015 -May/007858.html, May 4 , 2015 Krellenstein , “ The Counterparty Protocol,” GitHub , https: // github .
[retrieved Dec. 12 , 2018 ], 3 pages .
Decker, “ [BIP ] Normalized transaction IDs,” Bitcoin -Dev, https: // com /jsimnz /Counterparty /blob/master/README.md, Jan. 8, 2014
bitcoin-development.narkive.com/DjOYjEig/bip-normalized [Dec. 12 , 2018 ], 4 pages .
transaction -ids, Oct. 19 , 2015 [retrieved Dec. 12 , 2018 ], 16 pages. Maxwell et al., “ Deterministic wallets,” Bitcoin Forum , https: //
Drcode,“ New Kid on the Blockchain,” Hacker News, https://news. bitcointalk.org/index.php?topic=19137.0;all, Jun . 18, 2011 [retrieved
ycombinator.com/item?id=11372455 ,Mar. 28 , 2016 [Dec. 12 , 2018 ], Dec. 10 , 2018 ], 104 pages.
32 pages. McCorry et al., “ Authenticated Key Exchange over Bitcoin ,” Inter
Eragmus et al., “ Time to lobby Bitcoin's core devs: " SF Bitcoin national Conference on Research in Security Standardisation 2015 ,
Devs Seminar — Scalability to billions of transactions per day, Dec. 15 , 2015 , 18 pages.
satoshi-level Micropayments, near-zero risk of custodial theft, & OpenSSL Wiki, “ Elliptic Curve Diffie Hellman ,” OpenSSL , https ://
Instant transactions” ...but only w / a malleability - fixing soft fork ,” wiki.openssl.org/index.php/Elliptic_Curve_Diffie_Hellman ,Mar. 10 ,
Reddit r/bitcoin , https://www.reddit.com/r/Bitcoin/comments/2z2191/ 2014 [retrieved Dec. 10 , 2018 ], 5 pages .
time_to_lobby_bitcoins_core_devs_sf_bitcoin_devs/, Mar. 14 , 2015 OpenSSL Wiki, “ EVP Key Agreement,” OpenSSL , https: //wiki.
[Dec. 12, 2018 ], 21 pages . openssl.org/index.php/EVP_Key_Agreement, Apr. 28 , 2017 [retrieved
European Communication pursuant to Article 94 (3 ) EPC dated Jul. Dec. 10 , 2018 ], 2 pages.
1 , 2019, Application No. 17707121.4-1218 , filed Feb. 14 , 2017 , 6 Poon et al., “ The Bitcoin Lightning Network : Scalable Off-Chain
pages. Instant Payments,” https://www.bitcoinlightning.com/wp-content/
Familiar et al., “ Transcript for # bitcoin -dev Mar. 27 , 2015," BitcoinStats, uploads/2018/03/ lightning-network -paper.pdf, Jan. 14 , 2016 [retrieved
http://bitcoinstats.com/irc/bitcoin-dev/logs/2015/03/27 ,Mar. 27, 2015 Dec. 10 , 2018 ], 59 pages .
[archived version Jun . 27 , 2016 ], 11 pages. Pornin , “Deterministic Usage of the Digital Signature Algorithm
Flood et al., “Contract as Automaton : The Computational Repre (DSA ) and Elliptic Curve Digital Signature Algorithm ( ECDSA ),"
sentation of Financial Agreements,” Office of Financial Research Request for Comments: 6979 , Independent Submission , Aug. 2013,
Working Paper No. 15-04 , Mar. 26 , 2015, 25 pages. 79 pages.
US 10,652,014 B2
Page 4
( 56 ) References Cited UK Commercial Search Report dated Jun . 27 , 2016 , Patent Appli
cation No. GB1603123.9 , filed Feb. 23, 2016 , 11 pages.
OTHER PUBLICATIONS UK Commercial Search Report dated Jun . 27 , 2016 , Patent Appli
cation No. GB1603125.4 , filed Feb. 23, 2016 , 11 pages .
Reiner et al., “ Bitcoin Wallet Identity Verification Specification ," UK Commercial Search Report dated Jun . 28, 2016 , Patent Appli
diyhpluswiki, http://diyhpl.us/-bryan/papers2/bitcoin/armory cation No. GB1603122.1, filed Feb. 23 , 2016 , 12 pages.
verisign -bitcoin -wallet -identityspecification.pdf, Feb. 27, 2015 (retrieved UK Commercial Search Report dated Jun . 9, 2016 , Patent Appli
Jan. 27 , 2016 ), 24 pages. cation No. GB1603117.1 , filed Feb. 23 , 2016 , 12 pages .
Scott , “ Counterparty to Create First Peer-to - Peer Digital Asset
Exchange Platform ,” Cointelegraph , https://cointelegraph.com/news/ UK Commercial Search Report dated May 24 , 2016 , Patent Appli
counterparty_to_create_first_peer_to_peer_digital_asset_exchange_ cation No. GB1605571.7 , filed Apr. 1, 2016 , 3 pages.
platform , Apr. 10 , 2014 [retrieved Dec. 12 , 2018 ], 2 pages. European Communication pursuant to Article 94( 3) EPC dated Jan.
Tasca et al ., “ Digital Currencies: Principles, Trends, Opportunities, 2 , 2020 , Patent Application No. 18166910.2-1218, filed Feb. 16 ,
and Risks,” ECUREX Research Working Paper, Sep. 7, 2015 ( Oct. 2017, 4 pages .
2015 version ), 110 pages. Extended European Search Report dated Jul. 18, 2018 , Patent
Third -Party Submission Under 37 CFR 1.290 mailed Jun . 12, 2019 , Application No. 18166910.2-1218 , filed Feb. 16 , 2017, 8 pages.
U.S. Appl. No. 16 /078,605 , filed Aug. 21 , 2018 , 31 pages. Japanese Office Action dated Jan. 22, 2019 , Patent Application No.
Third -Party Submission Under 37 CFR 1.290 mailed Jun . 12 , 2019 , 2018-516682 , filed Feb. 16 , 2017 , 14 pages.
U.S. Appl. No. 16 /079,089 , filed Aug. 22 , 2018 , 19 pages. UK Commercial Search Report dated Apr. 25, 2016 , Patent Appli
Timeisnow77724 et al., “ Help understanding counterparty, thanks in cation No. 11603117.1 , filed Feb. 23 , 2016 , 11 pages .
advance !, ” Reddit r/ counterparty_xcp , https://www.reddit.com/r/ Vietnamese Office Action dated Sep. 27 , 2018, Patent Application
counterparty_xcp /comments/2qntze/help_understanding_counterparty_ No. 1-2018-03358 , filed Feb. 16 , 2017, 2 pages .
thanks_in_advance /, Dec. 28 , 2014 [retrieved Dec. 11, 2018 ], 4
pages . * cited by examiner
U.S. Patent May 12 , 2020 Sheet 1 of 11 US 10,652,014 B2
9
Plc M -19
Pis!
Third node
3 7
5 27
Network
23 Second node
First node
VicPic Vis Pls
Is
15 Pic
11
13 17
25
Eavesdropper
Fig . 1
U.S. Patent May 12 , 2020 Sheet 2 of 11 US 10,652,014 B2
5
7
3 Network
og
First node Second node
Share message (M ) between the first and second nodes
300 400
330
Determine a firstnode second private Determine a first node second public
key (V2c) based on the firstnode key (Pac )based on the firstnode
master private key (Vic) and the master public key (Pic) and the
deterministic key (DK ) deterministic key (DK )
Generate a first signed message (SM1) 430
350
based on themessage (M ) and the first
node second private key Vac ).
Send the first signed message (SM1) 360
to the second node. 440
Receive the first signedmessage (SM1)
from the firstnode.
450 Validate signature on the first signed
message (SM1) with the determined
first node second public key (P2c).
460
Authenticate the first node basec on the
370
result of validating first signed message (SM1)
Determine a second node second public 470 Determine a second node second private
key (P2s) based on the second node key (Vas) based on the secondnode
master publickey (Pus )and the masterprivate key ( 1s) and the
deterministic key (DK ) deterministic key (DK )
480
Determine common secret (CS) based on Determine common secret (CS) based on
firstnode second private key (V2c )and second node second private key (V2s)
380
second node second public key (Pas). and first node second public key (Pac).
Fig . 2
U.S. Patent May 12 , 2020 Sheet 3 of 11 US 10,652,014 B2
5
100
3
mm
WATTIVITITIVT
First node
110
Network
G
Second node
7
200
? 210
Settle on ECC system using a Settle on ECC system using a
common generator (G ) common generator (G )
120
Generate first asymmetric cryptography
pair including :a firstnode master private
key (Vic );and a first nodemaster public
key (P1c) based on the first node private
master key (Vic ) and G
130
Send clientmaster public key (Pic )
to the second node
220
Receive the firstnode
master public key (Pic )
230
Store first node
master public key (P10 )
240
Generate second asymmetric cryptography
pair indluding: a second nodemaster private
key V1s);and a second nodemaster public
key (Pus) based on the second nodemaster
private key ( s ) and generator (G )
140 250
Send second node
Receive second node master public key (P?s ) to firstnode
master public key(P18 )
Store second node -150
master public key (P18 )
Fig . 3
U.S. Patent May 12 , 2020 Sheet 4 of 11 US 10,652,014 B2
5
7
3 Network
300
First node 310 Second node
400
Generate a message (M )
315
/
410
Send themessage (M ) to thesecond node
320
Receive the message (M ) from the firstnode
Determine a deterministic key (DK ) 420
based on the message (M ) Determine a deterministickey (DK)
330 based on themessage (M )
430 '
Determine a firstnode second private
key (V2c)based on the firstnodemaster private Determine a first node second public
key (Vic) and the deterministic key (DK ) key (Pac )based on the firstnode master public
key (Pic ),deterministic key (DK), and generator (G )
Generate a first signed message (SM1) 350
based on themessage (M ) and the first 440
node second private key (V2c ). Receive first signed message (SM1)
from the first node
360 450
Send firstsigned message (SM1)
to the second node Validate signature on the first signed message (SM1)
with thedetermined first node second public key (Pac)
460
Authenticate the firstnode based on the result of
validating the first signedmessage (SM1)
370 ' 470
Determine a second node second public Determine a second node second private
key (P28 )based on the second nodemasterpublic key (Vas)based on the second node master private
key (PiS),deterministic key ( DK ) and generator (G ) key (V18) and the deterministic key (DK )
380 480
Determine common secret(CS) based on first node Determine common secret (CS) based on second node
second private key (Vac ) and second node second second private key (Vas) and firstnode second
public key (P2 ) public key (P2c)
Fig . 4
U.S. Patent May 12 , 2020 Sheet 5 of 11 US 10,652,014 B2
5
3 7
Network 600
500
First node Second node /
Determine a symmetric -key based on 510 Determine a symmetric-key based on 610
the shared common secret (CS) the shared common secret (CS)
Encrypting a first communication message, 520
with the symmetric-key, to an encrypted
first communication message
530
Sending the encrypted first communication 620
message, over the communications
network , to the second node Receiving the encrypted first
communication message
Decryptingthe encrypted first communication 630
message,with the symmetric-key,tothe
firstcommunication message
Encrypting a second communication message, 640
with the symmetric -key, to an encrypted
second communication message
540 Sending the encrypted second communication 650
message,over the communications network.
Receiving the encrypted second to the first node
communication message
550
Decryptingthe second communication
message, with the symmetric-key,to the
second communication message
Fig . 5
U.S. Patent May 12, 2020 Sheet 6 of 11 US 10,652,014 B2
707
?|
6
.
Fig
701 Network 5
IIS
U.S. Patent May 12 , 2020 Sheet 7 of 11 US 10,652,014 B2
801
CA -7 '
5
Network KALAU ADMINIMatatir
WS
803 3 7"
7"
Fig . 7
U.S. Patent May 12 , 2020 Sheet 8 of 11 US 10,652,014 B2
5
3
7
Network
300 400
First node Second node
ii ...
il/Wt . 1-1, " >
War
14 in this for kiritiri 17 : 115: 4.
Generate a first signed message (SM1) 350
based on the message (M ) and the first
node second private key (V2c).
360
Send the first signed message (SM1) 440
to the second node.
Receive the first signed message (SM1)
from the first node.
Validate signature on the first signed 450
message(SM1) with thedetermined
firstnode second public key (Pac).
Authenticate the first node based on the result 460
of validating the firstsigned message (SM1)
Generate a second signed message (SM2) 462
based on the message (M ) and the second
node second private key (Vas ).
372
Send the second signedmessage (SM2) 464
Receive the second signed message to the first node .
(SM2) from second node.
Validate signature on the second signed 374
message (SM2) with the determined
second node second public key (P2s ).
376
Authenticate the second node based on the
result ofvalidating the second signedmessage (SM2)
MYHYPER***** .wwntoh :
14 *+ 1MIC . - 14.1 .
Fig . 8
U.S. Patent May 12 , 2020 Sheet 9 of 11 US 10,652,014 B2
901 Bitcoin ibntoernedst
Bpiatymceonitns Salary
Savings
Fig
9
.
aBcaountks aCchoeuqnutse
XYZPIN
Maskeyt r Pasworcs wAebBsitCe!
U.S. Patent May 12 , 2020 Sheet 10 of 11 US 10,652,014 B2
903
V1C
V2c
V20
V2C " V3C
V3C
Fig . 10
U.S. Patent May 12 , 2020 Sheet 11 of 11 US 10,652,014 B2
23/27
Memory
1520
Processor Data
1510
1522
Instructions
1524
1530
Bus 7
Interface
1540
To/from user To/from
interface 15 and/ or network 5
peripherals 13/17
Fig . 11
US 10,652,014 B2
1 2
DETERMINING A COMMON SECRET FOR other things . Existing protocols include as the Diffie -Hell
THE SECURE EXCHANGE OF man Key Exchange and the Three Pass Protocol enable the
INFORMATION AND HIERARCHICAL , secure sharing of a secret across unsecure networks. How
DETERMINISTIC CRYPTOGRAPHIC KEYS ever these methods are computationally expensive in some
cases, such as where new secrets are to be continuously
5
TECHNICAL FIELD generated and shared .
Alternative asymmetric key hierarchies ( such as
The present disclosure relates to determining a common described in the Bitcoin Developer's Guide ) rely on a
secret for two nodes. In some applications, the common random seed and an index structure resulting in poor key
secret may be used for cryptography to enable secure 10 management. In contrast, embodiments of the present inven
communication between two nodes. The invention may be tion may comprise the use of meaningful ‘messages' (M ) to
suited for use with , but not limited to , digital wallets , not only generate asymmetric keys but also deterministic
blockchain (e.g. Bitcoin ) technologies and personal device hierarchical shared secrets which are provably associated
security with specific data .
15 Any discussion of documents, acts, materials, devices ,
BACKGROUND articles or the like which has been included in the present
specification is not to be taken as an admission that any or
Cryptography involves techniques for secure communi all of these matters form part of the prior art base or were
cation between two or more nodes . A node may include a common general knowledge in the field relevant to the
mobile communication device, a tablet computer, a laptop 20 present disclosure as it existed before the priority date of
computer, desktop , other forms of computing devices and each claim of this application .
communication devices, a server device in a network , a Throughout this specification the word “ comprise” , or
client device in a network , one ormore nodes in a distributed variations such as “ comprises ” or “ comprising” , will be
network , etc. The nodes may be associated with a natural understood to imply the inclusion of a stated element,
person , a group of people such as employees of a company, 25 integer or step , or group of elements , integers or steps , but
a system such as a banking system , etc. not the exclusion of any other element, integer or step , or
In some cases , the two ormore nodes may be linked by group of elements, integers or steps .
a communications network that is unsecure . For example ,
the two nodes may be linked by a communications network SUMMARY
where a third party may be able to eavesdrop on the 30
communication between the nodes. Therefore , messages According to an aspect of the present invention , there is
sent between nodes can be sent in encrypted form and provided a computer- implemented method of determining,
where, upon receipt, the intended recipients may decrypt the at a first node (C ), a common secret ( CS ) that is common
messages with corresponding decryption key (s) (or other with the first node (C ) and a second node (S ), wherein the
decryption methods). Thus the security of such communi- 35 first node (C ) is associated with a first asymmetric cryptog
cation may be dependent on preventing the third party from raphy pair having a first node master private key (Vic ) and
determining the corresponding decryption key. a first nodemaster public key (Pic), and the second node (S )
One method of cryptography includes using symmetric is associated with a second asymmetric cryptography pair
key algorithms. The keys are symmetric in the sense that the having a second node master private key (Vis ) and a second
same symmetric -key is used for both encryption of a plain 40 node master public key (Pis), wherein the method com
text message and decryption of cipher text. One consider prises:
ation of using symmetric -key algorithms is how to transmit determining a first node second private key (V20 ) based
the symmetric -key to both nodes in a secure way to prevent on at least the first node master private key (Vic ) and
an eavesdropper from acquiring the symmetric-key . This a deterministic key (DK );
may include , for example , physically delivering the sym- 45 determining a second node second public key (P2s) based
metric -key to the authorised ) nodes so that the symmetric on at least the second node master public key (Pis) and
key is never transmitted over an unsecure communications the deterministic key (DK ); and
network . However, physical delivery in not always an determining the common secret (CS ) based on the first
option . Therefore a problem in such cryptographic systems node second private key (V2c ) and the second node
is the establishment of the symmetric -key (which may be 50 second public key (P2 ),
based on a common secret ) between the nodes across an wherein the second node (S ) has the same common secret
unsecure network . In recent times , situations may make it (CS) based on a first node second public key (P2c ) and a
desirable that transmission of keys is usually done electroni second node second private key (V2s), wherein : the first
cally over communications systems such as the internet. node second public key (P2c) is based on at least the first
Thus this step of providing a shared secret (e.g. the sym- 55 node master public key (Pic ) and the deterministic key
metric -key ) is a potentially catastrophic vulnerability. As the (DK ); and the second node second private key ( V2s) is based
symmetric -key algorithms (and protocols) are simple and on at least the second node master private key (Vis) and the
widely used , there is a need for an ability for two nodes to deterministic key (DK ).
determine a common secret key securely across an unsecure This provides the advantage of enabling the second public
network . 60 keys to be derived independently at each node , thereby
Other existing cryptography methods include using asym increasing security , while also enabling a machine to auto
metric -keys. These may be used in public -key cryptography mate generation of sub -keys. The advantage is also provided
where they asymmetric-keys include a private key and a of having matched transaction inputs that cannot be tracked ,
corresponding public key . The public key may be made since the relationship between the public keys cannot be
publicly available whereas the private key , as the name 65 determined by third parties. This therefore enables a higher
implies, is kept private . These asymmetric -keys may be used level of anonymity to be achieved, thereby improving secu
for public- key encryption and for digital signature amongst rity .
US 10,652,014 B2
3 4
The deterministic key (DK ) may be based on a message The step of determining a second node second public key
(M ). The method may further comprise : generating a first (P2S) may be based on the second node master public key
signed message (SM1) based on the message (M ) and the (P1s) with elliptic curve point addition to the elliptic curve
first node second private key (V2c ); and sending, over the point multiplication of the deterministic key (DK ) and the
communications network , the first signed message (SM1) to 5 common generator (G ) according to the following formula :
the second node ( S ), wherein the first signed message (SM1) P2s = P1s + DK?G .
can be validated with a first node second public key (P2c ) to
authenticate the first node (C ). The deterministic key (DK ) may be based on determining
The method may also comprise : receiving , over the com a hash of a previous deterministic key.
The first asymmetric cryptography pair and the second
munications network , a second signed message (SM2) from 10 asymmetric cryptography pair may be based on a function of
the second node (S ); validating the second signed message respective previous first asymmetric cryptography pair and
(SM2) with the second node second public key (P2S ); and previous second asymmetric cryptography pair .
authenticating the second node (S ) based on the result of
validating the second signed message (SM2), wherein the 15 there is provided a method ofof secure
According to another aspect the present invention ,
second signed message (SM2) was generated based on the between a first node and a second node with communication
message (M ), or a second message (M2), and the second algorithm , wherein the method comprises : symmetric -key
node second private key (V2s). determining a symmetric -key based on the common secret
The method may further comprise generating a message determined according to the method described above ;
(M ); and sending , over a communications network , the 20 encrypting a first communication message ,with the sym
message (M ) to the second node (S ). Alternatively , the metric-key, to an encrypted first communication mes
method may comprise receiving the message (M ), over the sage; and
communications network , from the second node ( S ). In yet sending, over a communications network , the encrypted
another alternative, the method may comprise receiving the first communication message from the first node (C ) to
message (M ), over the communications network , from 25 the second node (S ).
another node . In yet another alternative , the method may The method may further comprise: receiving, over a
comprise receiving the message (M ) from a data store, communications network , an encrypted second communi
and /or an input interface associated with the first node (C ). cation message from the second node (S ); and decrypting the
The first node master public key (Pic) and second node encrypted second communication message, with the sym
master public key (Pls ) may be based on elliptic curve point
multiplication of respective first node master private key 30 metric -key, to a second communication message .
According to a further aspect of the present invention ,
(Vic ) and second node master private key (Vis) and a there is provided a method of performing an online trans
generator (G ). action between a first node and a second node, wherein the
The method may further comprise the steps of: receiving, method comprises: determining a symmetric -key based on
publicthekeycommunications
over network
(P1s); and storing , the store
, at a data secondassociated
node master
with 35 the common secret determined according to the method
the first node (C ), the second node master public key (Pis). transaction to message
according the above described method; encrypting a first
, with the symmetric -key, to an
The method may further comprise the steps of: generat encrypted first transaction message; sending, over a com
ing , at a first node ( C ), the first node master private key munications network, the encrypted first transaction mes
(Vic)theandcommunications
over the first node master public
network , thekeyfirst(Pic); sending
node master, 40 sage from the first node (C ) to the second node (S); receiv
public key (Pic ) to the second node (S ) and /or other node; ing , over a communications network , an encrypted second
and storing, in a first data store associated with the first node transaction
ing the
message from the second node (S ) ; and decrypt
encrypted second transaction message, with the
( C ), the first node master private key (Vic ). symmetric -key , to a second transaction message.
The method may also comprise: sending , over the com 45 According to a further
munications network , to the second node, a notice indicative there is provided a device foraspect of the present invention ,
of using a common elliptic curve cryptography (ECC ) a common secret (CS) that is common, atwith determining a first node (c ),
a second
system with a common generator (G ) for the method of node (S ), wherein the first node (C ) is associated with a first
determining a common secret (CS ). The step of generating asymmetric cryptography pair having a first node master
the first node master private key (Vic) and the first node
master public key (Pic) may comprise: generating the first 50 private
and the
key (Vic ) and a first node master public key (Pic ),
second node (S ) is associated with a second asym
node master private key (Vic ) based on a random integer in metric cryptography
an allowable range specified in the common ECC system ; private key (Vis ) and apair having a second node master
and determining the first nodemaster public key (Pic) based wherein the device comprises node second
a
master public key (P1s ),
first processing device to
on elliptic curve pointmultiplication of the first node master 55 perform the method as defined above to determine the
private key (Vic ) and the common generator (G ) according common secret.
to the following formula : According to a further aspect of the present invention ,
Pic = VicxG there is provided a device for secure communication , or
performing a secure online transaction between a first node
The method may further comprise: determining the deter- 60 and a second node, wherein the device includes a first
ministic key (DK ) based on determining a hash of the processing device to : perform the method of secure com
message (M ), wherein the step of determining a first node munication or secure online transaction described above .
second private key (V2C ) is based on a scalar addition of the The device may comprise a first data store to store one or
first node master private key (Vic ) and the deterministic key more of the first nodemaster private key (Vic ). The first data
(DK ) according to the following formula : 65 store may also store one or more of the first node master
public key (Pic ), the second node master public key (P1s),
V2c = Vic + DK and the message (M ).
US 10,652,014 B2
5 6
The devicemay further comprise a communications mod processing device is configured to : receive the message (M ),
ule to send and/ or receive , over a communications network , and wherein the second processing device is configured to
one or more of the message (M ), the first node master public receive the message (M ).
key (Pic), the second node master public key (P1s ), the first In yet another alternative, the system comprises a system
signed message (SM1), the second signed message (SM2), 5 data store and /or input interface, wherein the first processing
the notice indicative of using a common elliptic curve device and second processing device receives the message
cryptography (ECC ) system with a common generator (G ). (M ), or the secondmessage (M2) from the system data store
According to a further aspect of the present invention , and/or input interface.
there is provided a system for determining a common secret The first processing device may receive the second node
between a first node (C ) and a second node (S ), wherein : 10 master public key (Pis) from the system data store and /or
the first node (C ) is associated with a first asymmetric input device, and the second processing device may receive
cryptography pair having a first node master private key the first node master public key (Pic ) from the system data
(Vic ) and a first node master public key (Pic ); and store and /or input device .
the second node (S ) is associated with a second asym The first node master public key (Pic ), second node
metric cryptography pair having a second node master 15 master public key (Pis)may be based on elliptic curve point
private key (Vis) and a second node master public key multiplication of respective first node master private key
(Pis), and the system comprising : (Vic ) and second node master private key (Vis) and a
a first processing device , associated with the first node generator (G ).
(C ), configured to : The system may further comprise: a first data store
determine a first node second private key (V2c) based 20 associated with the first node (C ) to store the first node
on at least the first nodemaster private key (Vic ) and master private key (Vic ); and a second data store associated
a deterministic key (DK ; with the second node (S ) to store the second node master
determine a second node second public key (P2s) based private key (Vis).
on at least the second node master public key (P1s ) In the system , the first processing device may be config
and the deterministic key (DK ); and 25 ured to : generate the first node master private key (Vic ) and
determine the common secret (CS ) based on the first the first node master public key (Pic); send the first node
node second private key (V2c ) and the second node master public key (Pic); and store the first node master
second public key (Ps); and private key (Vic) in the first data store , wherein the second
a second processing device , associated with the second processing device is configured to: generate the second node
node ( S ), configured to : 30 master private key (Vis) and the second node master public
determine a first node second public key (P2c ) based on key (P1s); send the second node master public key (P1s); and
at least the first node master public key (Pic ) and the store the second node master private key (Vis) in the second
deterministic key (DK ); and data store .
determine a second node second private key (V2s ) In the system , the first data store may receive and store the
based on at least the second nodemaster private key 35 second node master public key (P1s); and the second data
(Vis ) and the deterministic key (DK ); and store may receive and store the first node master public key
determine the common secret based on the first node (Pic) .
second public key (P2c ) and a second node second In the system , the first processing device may be further
private key (V2s), configured to : generate the first node master private key
wherein the first processing device and the second pro- 40 (Vic) based on a random integer in an allowable range
cessing device determine the same common secret (CS ). specified in a common elliptic curve cryptography ( ECC )
In the system , the deterministic key (DK ) is based on a system ; and determine the first nodemaster public key (Pic )
message (M ), and the first processing device is further based on elliptic curve point multiplication of the first node
configured to : generate a first signed message (SM1) based master private key (Vic) and a common generator (G )
on the message (M ) and the first node second private key 45 according to the formula :
(V2c ); and send , over the communications network , the first Pic = VicXG
signed message (SM1) to the second node (S ). The second
processing device may be further configured to : receive the The second processing device may be further configured
first signed message (SM1); validate the first signed message to : generate the second node master private key (Vis ) based
( SM1) with the first node second public key (P2c); and 50 on a random integer in the allowable range specified in the
authenticate the first node ( C ) based on a result of the common ECC system ; and determine the second node
validated first signed message (SM1). master public key (P1s) based on elliptic curve point mul
In the system , the second processing device may be tiplication of the second node master private key (Vis) and
further configured to : generate a second signed message the common generator (G ) according to the formula :
(SM2) based on the message (M ), or a second message 55 Pus = V1sXG .
(M2), and the second node second private key (V2s); send
the second signed message (SM2) to the first node (C ), In the system , the first processing device may be config
wherein the first processing device is further configured to : ured to : determine the deterministic key (DK ) based on a
receive the second signed message (SM2); validate the hash of the message ( M ), and wherein : the first node second
second signed message (SM2) with the second node second 60 private key (V2c) is based on a scalar addition of the first
public key (P2s); authenticate the second node (S ) based on node master private key (Vic) and the deterministic key
a result of the validated second signed message (SM2). (DK ) according to the formula :
In the system , the first processing device may be further V2c = Vic + DK
configured to : generate the message (M ); and send the
message (M ), wherein the second processing device is 65 and the second node second public key (P2s) is based on the
configured to : receive themessage (M ). In one alternative , second nodemaster public key (Pls ) with elliptic curve point
the message is generated by another node, wherein the first addition to the elliptic curve point multiplication of the
US 10,652,014 B2
7 8
deterministic key (DK ) and the common generator (G ) In the above described system , the first and second
according to the following formula : communication messages may be transaction messages
between the first node and second node for an online
P2s = P 15+ DKxG transaction between the first node and the second node .
The second processing device may be further configured to : 5 According to a further aspect of the present invention ,
determine the deterministic key (DK ) based on a hash of the there is provided a computer program comprising machine
message (M ), and wherein the second node second private readable instructions to cause a processing device to imple
key (V2s ) is based on a scalar addition of the second node ment any one of the method described above .
master private key (Vis ) and the deterministic key (DK )
according to the formula : 10 BRIEF DESCRIPTION OF DRAWINGS
V2s = Vic + DK Examples of the present disclosure will be described with
and the first node second public key (P2c ) is based on the reference to :
first node master public key ( Pic ) with elliptic curve point FIG . 1 is a schematic diagram of an example system to
addition to the elliptic curve point multiplication of the 15 determine a common secret for a first node and second node;
deterministic key (DK ) and the common generator (G ) FIG . 2 is a flow chart of computer- implemented methods
according to the following formula : for determining a common secret;
P2c = Pic + DKxG FIG . 3 is a flow chart of computer-implemented methods
to register the first and second nodes;
The system may further comprise : a first communications 20 FIG . 4 is another flow chart of computer- implemented
module associated with the first processing device to send methods for determining a common secret;
and /or receive, over a communications network , one or more FIG . 5 is a flow chart of computer-implemented methods
of the message (M ), the first node master public key (Pic ), of secure communication between the first node and second
the second node master public key (Pis), the first signed node ;
message (SM1), the second signed message (SM2), and a 25 FIG . 6 is a schematic diagram of an example system for
notice indicative of using a common elliptic curve cryptog electronic resource rental;
raphy (ECC ) system with a common generator (G ); and a FIG . 7 is a schematic diagram of an example system that
second communications module associated with the second applies the methods to password replacement;
processing device to send and/or receive, over a communi FIG . 8 is a flow chart of computer implemented methods
cations network , one or more of the message (M ), the first 30 to authenticate the first node and the second node ;
node master public key (Pic), the second node master public FIG . 9 is an example of a tree structure of different keys
key (P1s ), the first signed message (SM1), the second signed for different purposes ;
message ( SM2), and the notice indicative of using a com FIG . 10 is an example of a tree structure using the master
mon elliptic curve cryptography (ECC ) system with a com key spawning method; and
mon generator (G ). 35 FIG . 11 illustrates a schematic of an example processing
In the system , the deterministic key (DK ) may be based device .
on determining a hash of a previous deterministic key.
In the system , the first asymmetric cryptography pair and DESCRIPTION OF EMBODIMENTS
the second asymmetric cryptography pair may be based on
a function of respective previous first asymmetric cryptog- 40 Overview
raphy pair and previous second asymmetric cryptography A method , device and system to determine a common
pair. secret (CS) at a first node (C ) that is the same common secret
According to a further aspect of the present invention , at a second node ( S ) will now be described . FIG . 1 illustrates
there is provided a system for secure communication a system 1 that includes a first node 3 that is in communi
between a first node and a second node with symmetric -key 45 cation with , over a communications network 5 , with a
algorithm , wherein the system comprises: a system second node 7. The first node 3 has an associated first
described above to determine a common secret with the first processing device 23 and the second node 5 has an associ
processing device and the second processing device , ated second processing device 27. The first and second
wherein the first processing device is further configured to : nodes 3, 7 may include an electronic device, such as a
determine a symmetric -key based on the common secret; 50 computer, tablet computer, mobile communication device ,
encrypt a first communication message ,with the symmetric computer server etc. In one example , the firstnode 3 may be
key, to an encrypted first communication message ; and send a client device and the second node 7 a server.
the encrypted first communication message . The second The first node 3 is associated with a first asymmetric
processing device is further configured to : determine the cryptography pair having a first node master private key
same symmetric -key based on the common secret ; receive 55 (Vic) and a first nodemaster public key (Pic ). The second
the encrypted first communication message ; and decrypt the node (7) is associated with a second asymmetric cryptogra
encrypted first communication message, with the symmet phy pair having a second node master private key (Vis) and
ric -key , to the first communication message. a second node master public key (P1s). The first and second
In the system for secure communication , the second asymmetric cryptography pairs for the respective first and
processing device may be further configured to : encrypt a 60 second nodes 3, 7 may be generated during registration .
second communication message , with the symmetric -key, to Methods of registration 100 , 200 performed by the first and
the encrypted second communication message ; and send the second nodes 3 , 7 will be described in further detail below
encrypted second communication message. The first pro with reference to FIG . 3. The public key for each node may
cessing device may be further configured to : receive the be shared publicly, such as over the communications net
encrypted second communication message; decrypt the 65 work 5
encrypted second communication message, with the sym To determine the common secret (CS ) at both the first
metric -key , to the second communication message . node 3 and second node 7 , the nodes 3 , 7 perform steps of
US 10,652,014 B2
9 10
respective methods 300, 400 without communicating private Sharing the message (M ) between the first and second
keys over the communications network 5 . nodes may be achieved in a variety of ways . In one example,
The method 300 performed by the first node 3 includes the message may be generated at the first node 3 which is
determining 330 a first node second private key (V2c ) based then sent, over the communications network 5 , the second
on at least the first node master private key (Vic ) and a 5 node 7. Alternatively , the message may be generated at the
deterministic key (DK ). The deterministic key may bebased second node 7 and then sent, over the communications
on a message (M ) that is a shared between the first and network 5 , to the second node 7. In yet another example , the
second nodes, which may include sharing the message over message may be generated at a third node 9 and themessage
the communications network 5 as described in further detail 10 sent to both the first and second nodes 3, 7. In yet another
below . The method 300 also includes determining 370 a alternative, a user may enter the message through a user
second node second public key (P2s) based on at least the interface 15 to be received by the first and second nodes 3 ,
second node master public key (P1s) and the deterministic 7. In yet another example , the message (M )may be retrieved
key (DK ). The method 300 includes determining 380 the from a data store 19 and sent to the first and second nodes
common secret (CS ) based on the first node second private 15 3 , 7. In some examples, the message (M ) may be public and
key (V2c ) and the second node second public key (P2s). therefore may be transmitted over an unsecure network 5 .
Importantly, the same common secret (CS) can also be In further examples, one or more messages (M ) may be
determined at the second node 7 by method 400. The method stored in a data store 13 , 17 , 19 , where the message may be
400 determining 430 a first node second public key (P2c ) associated with a session , transaction , etc , between the first
based on the first node master public key (Pic) and the 20 node 3 and the second node 7. Thus the messages (M ) may
deterministic key (DK ). The method 400 further include be retrieved and used to recreate, at the respective first and
determining 470 a second node second private key (V2s) second nodes 3, 7 , the common secret (CS) associated with
based on the second node master private key (Vis) and the that session , or transaction . Advantageously, a record to
deterministic key (DK ). The method 400 includes determin allow recreation of the common secret (CS) may be kept
ing 480 the common secret ( CS ) based on the second node 25 without the record by itself having to be stored privately or
second private key (V2s) and the first node second public transmitted securely. This may be advantageous if numerous
key (P2c). transactions are performed at the first and second nodes 3, 7
The communications network 5 , may include a local area and it would be impractical to store all the messages (M ) at
network , a wide area network , cellular networks, radio the nodes themselves.
communication network, the internet, etc. These networks, 30 Method of Registration 100, 200
where data may be transmitted via communicationsmedium
such as electrical wire, fibre optic, or wirelessly may be An example of a method of registration 100, 200 will be
susceptible to eavesdropping, such as by an eavesdropper described with reference to FIG . 3 , where method 100 is
performed by the first node 3 and method 200 is performed
11. The method 300 , 400 may allow the first node 3 and
second node 7 to both independently determine a common 35 by the second
second node 7.cryptography
asymmetric This includes pairs
establishing
for thetherespective
first and
secret without transmitting the common secret over the
communications network 5. Thus one advantage is that the firstTheandasymmetric
second nodes 3 , 7 .
cryptography pairs include associated
common secret (CS) may be determined securely by each
node without having to transmit a private key over a private and public keys, such as those used in public -key
potentially unsecure communications network 5. In turn, the 40 encryption . In this example, the asymmetric cryptography
common secretmay be used as a secret key (or as the basis pairs are generated using Elliptic Curve Cryptography
of a secret key ) for encrypted communication between the (ECC ) and properties of elliptic curve operations .
first and second nodes 3 , 7 over the communications net Standards for ECC may include known standards such as
work 5 . those described by the Standards for Efficient Cryptography
The methods 300 , 400 may include additional steps. The 45 Group (www.sceg.org ). Elliptic curve cryptography is also
method 300 may include, at the first node 3, generating a described in U.S. Pat. Nos. 5,600,725,5,761,305,5,889,865 ,
signed message (SM1) based on the message (M ) and the 5,896,455 , 5,933,504 , 6,122,736 , 6,141,420 , 6,618,483 ,
first node second private key (V2c). The method 300 further 6,704,870 , 6,785,813 , 6,078,667, 6,792,530 .
includes sending 360 the first signed message (SM1), over In themethod 100 , 200 , this includes the first and second
the communications network , to the second node 7. In turn , 50 nodes settling 110 , 210 to a common ECC system and using
the second node 7 may perform the steps of receiving 440 a common generator (G ). In one example , the common ECC
the first signed message (SM1). The method 400 also system may be based on secp256K1 which is an ECC system
includes the step of validating 450 the first signed message used by Bitcoin . The common generator (G ) may be
( SM1) with the first node second public key (P2c ) and selected , randomly generated , or assigned .
authenticating 460 the first node 3 based on the result of 55 Turning now to the first node 3 , the method 100 includes
validating the first signed message (SMI). Advantageously , settling 110 on the common ECC system and common
this allows the second node 7 to authenticate that the generator (G ). This may include receiving the common ECC
purported first node (where the first signed message was system and common generator from the second node 7 , or a
generated ) is the first node 3. This is based on the assump third node 9. Alternatively , a user interface 15 may be
tion that only the first node 3 has access to the first node 60 associated with the first node 3, whereby a user may
master private key (Vic) and therefore only the first node 3 selectively provide the common ECC system and /or com
can determine the first node second private key (V2c) for mon generator (G ). In yet another alternative one or both of
generating the first signed message (SM1). It is to be the common ECC system and/or common generator (G ) may
appreciated that similarly, a second signed message (SM2) be randomly selected by the first node 3. The first node 3
can be generated at the second node 7 and sent to the first 65 may send , over the communications network 5 , a notice
node 3 such that the first node 3 can authenticate the second indicative of using the common ECC system with a common
node 7 , such as in a peer-to -peer scenario . generator (G ) to the second node 7. In turn , the second node
US 10,652,014 B2
11 12
7 may settle 210 by sending a notice indicative of an Session Initiation and Determining the Common Secret by
acknowledgment to using the common ECC system and the First Node 3
common generator (G ). An example of determining a common secret ( CS ) will
The method 100 also includes the first node 3 generating now be described with reference to FIG . 4. The common
120 a first asymmetric cryptography pair that includes the 5 secret (CS ) may be used for a particular session , time,
first node master private key (Vic ) and the first node master transaction , or other purpose between the first node 3 and the
public key (Pic). This includes generating the first node second node 7 and it may not be desirable, or secure, to use
master private key (Vic) based , at least in part, on a random the same common secret (CS). Thus the common secret (CS)
integer in an allowable range specified in the common ECC may be changed between different sessions, time, transac
system . This also includes determining the first node master 10 tions, etc.
public key (Pic) based on elliptic curve point multiplication Generating a Message (M ) 310
of the first nodemaster private key (Vic ) and the common In this example, the method 300 performed by the first
generator (G ) according to the formula : node 3 includes generating 310 a message (M ). Themessage
( M )may be random , pseudo random , or user defined . In one
Pic = VicxG (Equation 1) 15 example, themessage ( M ) is based on Unix time and a nonce
Thus the first asymmetric cryptography pair includes: (and arbitrary value ). For example , the message (M )may be
Vic: The first node master private key that is kept secret provided as:
by the first node. Message (M ) = Unix Time+nonce (Equation 3 )
Pic: The first node master public key that is made publicly 20 In some examples, the message (M ) is arbitrary. However
known. it is to be appreciated that the message (M ) may have
The first node 3 may store the first node master private selective values ( such as Unix Time, etc ) that may be useful
key (Vic) and the first node master public key (Pic ) in a first in some applications.
data store 13 associated with the first node 3. For security , The method 300 includes sending 315 the message (M ),
the first node master private key (Vic ) may be stored in a 25 over the communications network 3, to the second node 7 .
secure portion of the first data store 13 to ensure the key The message ( M ) may be sent over an unsecure network as
remains private . themessage (M ) does not include information on the private
The method 100 further includes sending 130 the first keys.
node master public key (Pic ), over the communications Determining a Deterministic Key 320
network 5 , to the second node 7. The second node 7 may , on 30 The method 300 further includes the step of determining
receiving 220 the first node master public key (Pic ), store 320 a deterministic key (DK ) based on the message (M ). In
230 the first node master public key (Pic ) in a second data this example, this includes determining a cryptographic hash
store 17 associated with the second node 7 . of the message . An example of a cryptographic hash algo
Similar to the first node 3 , the method 200 of the second rithm includes SHA - 256 to create a 256 - bit deterministic
node 7 includes generating 240 a second asymmetric cryp- 35 key (DK ). That is:
tography pair that includes the second node master private DK = SHA -25 (Equation 4 )
key (Vis) and the second node master public key (P1s). The
second node master private key (Vis) is also a random It is to be appreciated that other hash algorithmsmay be
integer within the allowable range. In turn , the second node used . This may include other has algorithms in the Secure
master public key (Pis) is determined by the following 40 Hash Algorithm (SHA ) family . Some particular examples
formula : include instances in the SHA - 3 subset, including SHA3-224 ,
SHA3-256 , SHA3-384 , SHA3-512, SHAKE128 ,
Pus = V1sXG (Equation 2 ) SHAKE256 . Other hash algorithmsmay include those in the
Thus the second asymmetric cryptography pair includes: RACE Integrity Primitives Evaluation Message Digest
Iis : The second node master private key that is kept 45 EMD
(RIPEMD ) family. A particular example may include RIP
- 160. Other hash functionsmay include families based
secret by the second node .
Pis: The second node master public key that is made on Zémor- Tillich hash function and knapsack -based hash
publicly known. functions.
The second node 7 may store the second asymmetric Determining a First Node Second Private Key 330
cryptography pair in the second data store 17. The method 50 The method 300 then includes the step 330 of determining
200 further includes sending 250 the second node master 330 the first node second private key (V2c ) based on the
public key (P1s) to the first node 3. In turn , the first node 3 second node master private key (Vic ) and the deterministic
may receive 140 and stores 150 the second node master key (DK ). This can be based on a scalar addition of the first
node master private key (Vic ) and the deterministic key
public key (P1s).
It is to be appreciated that in some alternatives, the 55 (DK ) according to the following formula:
respective public master keys may be received and stored at V2c = Vic + DK ( Equation 5 )
a third data store 19 associate with the third node 9 ( such as Thus the first node second private key (V2c ) is not a
a trusted third party ). This may include a third party that acts random value but is instead deterministically derived from
as a public directory , such as a certification authority. Thus the first node master private key. The corresponding public
in some examples, the first node master public key (Pic ) 60 key in the cryptographic pair , namely the first node second
may requested and received by the second node 7 only when public key (P2c ), has the following relationship :
determining the common secret (CS) is required (and vice
versa ). P2c = V2cxG (Equation 6 )
The registration steps may only need to occur once as an Substitution of V2c from Equation 5 into Equation 6
initial setup . Afterwards, the master keys can be reused in a 65 provides :
secure matter to generate common secret(s ) that are depen
dent, inter alia, on the deterministic key (DK ). P2c = (Vic + DK )xG ( Equation 7)
US 10,652,014 B2
13 14
Where the ' + ' operator refers to scalar addition and the ‘ x ' Method 400 Performed at the Second Node 7
operator refers to elliptic curve point multiplication . Noting The corresponding method 400 performed at the second
that elliptic curve cryptography algebra is distributive , node 7 will now be described . It is to be appreciated that
Equation 7 may be expressed as : some of these steps are similar to those discussed above that
P2c = VicxG + DKxG
were performed by the first node 3 .
(Equation 8 )
5
The method 400 includes receiving 410 themessage (M ),
Finally , Equation 1 may be substituted into Equation 7 to over the communications network 5 , from the first node 3 .
provide : This may include the message (M ) sent by the first node 3
at step 315. The second node 7 then determines 420 a
P2c = Pic + DKxG (Equation 9.1 ) 10 deterministic key (DK ) based on the message (M ). The step
of determining 420 the deterministic key (DK ) by the second
P2c = Pic + SHA- 256 (M )xG (Equation 9.2 ) node 7 is similar to the step 320 performed by the first node
In equations 8 to 9.2 , the ‘ +' operator refers to elliptic described above . In this example , the second node 7 per
curve point addition . Thus the corresponding first node 15 formsthis determining step 420 independent of the first node
second public key (P2c ) can be derivable given knowledge 3 . The next step includes determining 430 a first node
of the first node master public key (Pic ) and the message second public key (P2c ) based on the first node master
( M ). The second node 7 may have such knowledge to
independently determine the first node second public key public key (Pic ) and the deterministic key (DK ). In this
example , since the public key is determined 430' as the
(P2 ) asto will
respect be discussed
the method 400 . in further detail below with 20 private key with elliptic curve point multiplication with the
Generate a First Signed Message (SM1) Based on the expressed,(Gin ),athefashion generator first node second public key (P2c) can be
similar to Equation 9, as:
Message and the First Node Second Private Key 350
The method 300 further includes generating 350 a first P2c = V2cXG ( Equation 12.1)
signed message (SM1) based on the message (M ) and the 25
determined first node second private key (V2c ). Generating
a signed message includes applying a digital signature P2c = Pic + DKxG ( Equation 12.2 )
algorithm to digitally sign the message (M ). In one example , Themathematical proof for Equations 12.1 and 12.2 is the
this includes applying the first node second private key same as those discussed above for Equations 10.1 and 10.2 .
(Algorithm
V2c ) to the(ECDSA
message) into anobtain
ElliptictheCurve Digital Signature
first signed message
30 The Second Node 7 Authenticating the First Node 3
(SM1).
The method 400 may include steps performed by the
Examples of ECDSA include those based on ECC sys is the first node 3.authenticate
second node 7 to
As discussed
that the alleged first node 3 ,
previously, this includes
tems with secp256k1, secp256rl , secp384r1, se3cp521rl .
The first signed message (SM1) can be verified with the 35 node 3. The second node 7 may then(SM1
receiving 440 the first signed message ) from the first
corresponding first node second public key (P2c ) at the signature on the first signed message (SM1) with 450 validate
the
the
first
second node 7. This verification of the first signed message node second public key (P2c ) that was determined at step
(SM1) may be used by the second node 7 to authenticate the 430 .
first node 3, which will be discussed in the method 400 Verifying the digital signature may be done in accordance
below . 40 with an Elliptic Curve Digital Signature Algorithm
Determine a Second Node Second Public Key 370 (ECDSA ) as discussed above . Importantly, the first signed
The first node 3 may then determine 370 a second node message
second public key (P2s ). As discussed above , the second private key( SM1 ) that was signed with the first node second
node second public key (P2s) may be based at least on the corresponding first) should (V2c only be correctly verified with the
node second public key (P2c ), since V2c
second(DKnode
key ). Inmaster public ,keysince(Psthe) andpublic
this example the key
deterministic
is deter 45 and P2C form a cryptographic pair. Since these keys are
mined 370 ' as the private key with elliptic curve point the first node master deterministic on the first node master private key (Vic ) and
multiplication with the generator (G ), the second node registration of the firstpublic node
key (Pic ) that were generated at
3, verifying first signed message
second public key (P2s) can be expressed , in a fashion (SM1) can be used as a basis of authenticating that an
similar to Equation 6 , as: 50 alleged first node sending the first signed message (SM1) is
P2s = V25G (Equation 10.1) the same first node 3 during registration . Thus the second
node 7 may further perform the step of authenticating (460)
P2s = P 1s + DKxG (Equation 10.2 )
the first node 3 based on the result of validating (450 ) the
first signed message .
The mathematical proof for Equation 10.2 is the same as 55 The above authentication may be suitable for scenarios
described above for deriving Equation 9.1 for the first node where one of the two nodes are a trusted node and only one
second public key (P2c). It is to be appreciated that the first of the nodes need to be authenticated . For example , the first
node 3 can determine 370 the second node second public key node 3 may be a client and the second node 7 may be a
independently of the second node 7 . server trusted by the client. Thus the server ( second node 7 )
Determine the Common Secret 380 at the First Node 3 60 may need to authenticate the credentials of the client (first
The first node 3 may then determine 380 the common node 3 ) in order to allow the client access to the server
secret (CS ) based on the determined first node second system . It may not be necessary for the server to be
private key (V2c ) and the determined second node second authenticate the credentials of the server to the client.
public key (P2s ). The common secret (CS) may be deter However in some scenarios, it may be desirable for both
mined by the first node 3 by the following formula : 65 nodes to be authenticated to each other, such as in a
peer-to - peer scenario that will be described in another
S = V2cxP2s (Equation 11 ) example below .
US 10,652,014 B2
15 16
The Second Node 7 Determining the Common Secret However depending on some applications , the common
The method 400 may further include the second node 7 secret (CS) could be stored in the first data store ( X )
determining 470 a second node second private key ( V2s) associated with the first node provided the common secret
based on the second node master private key (Vis) and the ( CS ) is kept as secure as the first node master private key
deterministic key (DK ). Similar to step 330 performed by 5 (Vic ).
the first node 3, the second node second private key (V2s) Furthermore , the disclosed system may allow determina
can be based on a scalar addition of the second node master tion of multiple common secrets that may correspond to
private key (Vis) and the deterministic key (DK ) according multiple secure secret keys based on a single master key
to the following formulas: cryptography pair. An advantage of this may be illustrated
10
V2s = Vis+ DK ( Equation 13.1 ) by the following example .
In situations where there are multiple sessions , each
V2s = Vis + SHA -256 (M ) ( Equation 13.2 ) associated with multiple respective common secrets (CS ), it
The second node 7 may then , independent of the first node may be desirable to have a record associated with those
3 , determine 480 the common secret (CS) based on the 15 multiple sessions so that the respective common secrets (CS)
second node second private key (V2s) and the first node can be re -determined for the future . In known systems, this
second public key (P2c ) based on the following formula : may have required multiple secret keys to be stored in a
S = V2sXP 20 ( Equation 14 ) secure data store , which may be expensive or inconvenient
to maintain . In contrast , the present system has the master
Proof of the Common Secret (CS) Determined by the First 20 private keys kept secure at the respective first and second
Node 3 and Second Node 7
The common secret (CS ) determined by the first node 3 is
nodes , whilst the other deterministic keys, or message (M ),
may be stored either securely or insecurely. Despite the
the same as the common secret ( CS ) determined at the deterministic keys (DK , or message ( M ), being stored inse
second node 7. Mathematical proof that Equation 11 and curely , the multiple common secrets (CS) are kept secure
Equation 14 provide the samecommon secret (CS )will now 25 since the master private keys required to determine the
be described . common secrets are still secure .
Turning to the common secret ( CS ) determined by the first The method may also be used for generating “ session
node 3 , Equation 10.1 can be substituted into Equation 11 as keys ” for temporary communication links, such as for
follows: securely transmitting login passwords .
S = V2cXP2s (Equation 11) 30 Example Applications
Themethods, device , and system of the present disclosure
S = V2cx (V25* G ) may have a number of applications including but not limited
to those described below .
S = ( V2cxV2s)xG ( Equation 15 ) Message Encryption
The present disclosure may be used to facilitate secure
Turning to the common secret (CS ) determined by the 35 communication , in particular sending and receiving com
second node 7, Equation 12.1 can be substituted into Equa munication messages
tion 14 as follows: , between the first node 3 and second
node 7 over a potentially unsecure communications network
S = V25XP 20 ( Equation 14 ) 5. This may be achieved by using the common secret (CS)
40 as the basis for a symmetric -key. This method of determin
S = V25* (V2cxG ) ing a common secret (CS) and using the symmetric -key for
S = (V2 * V2cxG ( Equation 16 )
encryption and decryption of the communication messages
may be more computationally efficient compared to known
Since ECC algebra is commutative , Equation 15 and public-key encryption methods.
Equation 16 are equivalent, since: 45 Methods 500 , 600 of secure communication between the
( Equation 17 )
first node 3 and second node 7 will now be described with
S = ( V2cxV2s)xG = ( V25 * V2c)xG reference to FIG . 5. The first node 3 determines 510 a
The Common Secret (CS ) and Secret Key symmetric-key based on the common secret (CS ) deter
The common secret (CS ) may be used as a secret key, or mined in the method above. This may include converting the
as the basis of a secret key in a symmetric -key algorithm for 50 common secret ( CS ) to a standard key format. Similarly , the
secure communication between the first node 3 and second second node 7 can also determine 610 the symmetric -key
node 7 . based on the common secret (CS ) .
The common secret (CS ) may be in the form of an elliptic To send a first communication message securely from the
curve point (xs , ys). This may be converted into a standard first node 3 , over the communications network , to the second
key format using standard publicly known operations agreed 55 node, the first communication message needs to be
by the nodes 3, 7. For example , the xs value may be a 256 - bit encrypted . Thus the symmetric -key is used by the first node
integer that could be used as a key for AES 256 encryption . It for encrypting 520 a first communication message to form
could also be converted into a 160 -bit integer using RIP an encrypted first communication message, which is then
EMD160 for any applications requiring this length key . sent 530 , over the communications network 5 , to the second
The common secret ( CS ) may be determined as required . 60 node 7. The second node 7, in turn , receives 620 the
Importantly , the first node 3 does not need to store the encrypted first communication message 620 , and decrypts
common secret (CS ) as this can be re -determined based on 630 the encrypted first communication message, with the
the message (M ). In some examples, the message (s) (M ) symmetric-key, to the first communication message .
used may be stored in data store 13 , 17 , 19 (or other data Similarly , the second node 7 may encrypt 640 a second
store ) without the same level of security as required for the 65 communication message, with the symmetric -key, to an
master private keys. In some examples, the message (M ) encrypted second communication message, which is then
may be publicly available . sent 650 to the first node 3. The first node 3 may then receive
US 10,652,014 B2
17 18
540 the encrypted second communication message, and The user 803 may wish to communicate with these
decrypt 550 it to the second communication message. institutions, in a secure manner, to access services . In known
Cryptocurrency Wallet systems, this may require the user to have multiple pass
In another example , the method may be used for genera words to login for each of the respective institutions . Using
tion and management of common secrets (CS) such as secret 5 the same password for login for multiple institutions is not
keys for cryptocurrency transactions. Cryptocurrency keys , desirable for security reasons .
such as those used in Bitcoin transactions , are normally In this example , the user and the multiple institutions
associated with funds and assets that can be exchanged for settle on using the same protocol. This may include settling
value . on the ECC system (such as those based on secp256k1,
Electronic Resource Rental 10
secp256r1 , secp384r1, secp521rl ) and a generator (G ). The
An example of using the method and system for facili user may then
tating electronic resource rental will be described with key (Pic ) withregister the
and share the first nodemaster public
plurality of institutions and associated
reference to FIG . 6. This illustrates a system 701 where the additional nodes 7 ', 7 " , 7 "" . The additional nodes 7', 7 " , 7 ""'
first node 3 is associated with a client 703 and the second
node 7 is associated with an electronic resource , such with 15 may each perform steps of themethod similar to the second
node 7 as described above .
a supercomputer facility 707. Thus the client 504 may want
to use the remotely located supercomputer facility 707 for Each time the user 803 wishes to log into one of the
processing large amounts of confidential data . websites of a participating institution they do notneed to use
The supercomputer facility 707 may rent out the super a password . Instead, the protocol replaces the need for
computer CPU time on a per time and /or per CPU cycle 20 passwords for each institution . All that is required at the first
basis . The client 703 may register with the supercomputer node 3 is the Institution's Public Key, which is always
facility by depositing their public key, such as by sending available, and registration of the user at the institutions
130 , over a communications network 5 , the first node master ( including registering the first node master public key (Pic )
public key (Pic ) to the second node 7 . with the institution ). Since registration by the user with an
The supercomputer facility 707 may then provide soft- 25 institution is a normal practice for using web -based services,
ware to the client 703 for performing background processes this is not a burden on the user 803. Once the registration has
such as establishing secure connections using AES encryp been completed , a common secret ( CS ) can be determined ,
tion and for facilitating the steps in the method 300 used and re -used in place of a password. For example at the
described above . start of every session , the first node 3 may generate 310 a
When performing the method 300 , the first node 3 may 30 message
send 360 a first signed message (SM1) which , in part, is involved (inM the ) that is sent to the additional node 7', 7" ,
based on a message (M ) that includes the Unix Time mine 320 , 420 asession . The message (M ) is used to deter
corresponding deterministic key which is
concatenated with a nonce .
The second node 7 , may receive 440 the first signed then used by both the first node 3 and additional node 7', 7 " ,
message (SM1). The second node 7 may further perform a 35 methods
7'" to determine
above.the common secret
Alternatively , the (message
CS) as described
(M ) mayin the
be
step of determining if the Unix Time in the message ( M ) is generated or received from the additional node 7 ', 7 " , 7 " . In
within an allowed value for the Unix Time. For example , the yet another alternative , the message (M ) may be a prede
allowed value for the Unix Time may be set according to
Terms and Conditions settled between the client 703 and the termined message stored in a data store 13 , 17, 19 accessible
supercomputer facility 707. For example, the Unix Time (of 40 by the first node 3 and /or additional node 7', 7 ", 7"" .
the message) may be required to be within a set period (e.g. This technique lifts a significant security burden from the
300 seconds) of when the supercomputer facility receives institutions. In particular , they no longer need to keep a
440 the first signed message (SM1). If the Unix Time in the password file (secret record of passwords or password
message (M ) is outside the allowed time, the exchange of hashes ) as the common secret can be recalculated from
confidential data will not be accepted . 45 non- secret information . Rather, the institution need only
The above steps may ensure that the resultant session key, keep their own master private key secure. Furthermore , the
that is based on the determined common secret (CS) at steps user does not need to memorise or securely store many
380, 480 , can never be reproduced at a later time and is passwords (one for each institution ) so long as they can keep
unique to the session being established . A protocol may then their first node master private key (Vic ) secure .
be used to establish a symmetric session key , such as an AES 50 Variations
encryption /decryption key, for the duration of the session . Some variations will now be described with the following
The session key is used for all communications between the examples.
first node 3 and the second node 7 for the duration of the Peer -to Peer Authentication
session . This allows the client to encrypt code and/or large In a peer- to -peer scenario , the first node 3 and the second
amounts of data , send these to the supercomputer facility 55 node 7 may need to authenticate the credentials of one
707 for processing, and receive encrypted results back from another. An example of this will now be described with
the supercomputer facility 707 . reference to FIG . 8. In this example, the method 300 , 400
Password Replacement, Supplement or Alternative steps to authenticate the first node 3 based on the validated
The system and method may also be used as a password first signed message ( SM1) are similar to those discussed
replacement, supplement, or alternative. Referring to FIG . 7 60 above.
there is provided a system that includes a first node 3 However, the method 400 performed by the second node
associated with a user and a plurality of additional nodes 7', 7 further includes generating 462 a second signed message
7 " , 7 " . The plurality of additional nodes may each be (SM2) based on the message (M ) and the second node
associated with respective institutions participating in the private key (V2s). In some alternatives , the second signed
same protocol . For example , the institutions may include 65 message (SM2) may be based on a second message (M2)
banks, service providers, government services, insurance and the second node private key (V2s ), where the second
companies , telecommunication providers, retailers, etc. message (M2) is shared with the first node 3. The method
US 10,652,014 B2
19 20
400 further includes sending 464 the second signed message track of the original Message (M ) or the originally calcu
(SM2), over the communications network 5 , to the first node lated deterministic key (DK ), and to which node it relates .
3. As this is publicly known information there are no security
At the first node 3, the method 300 includes receiving the issues regarding the retention of this information . Accord
second signed message (SM2) from the second node 7. The 5 ingly , this information might be kept on ‘hash tables'
method includes validating 374 the signature on the second ( linking hash values to public keys ) and distributed freely
signed message (SM2) with the second node second public across the network 5 ( for example using Torrent). Further
key (P2s) that was determined at step 370. The method 300 more, if any individual common secret ( CS) in the hierarchy
may then include authenticating 376 the second node 7 is ever compromised , this does not affect the security of any
based on the result of validating the second signed message 10 other common secrets in the hierarchy provided the private
(SM2). This results in the first and second nodes 3 , 7 keys Vic, Vis remain secure .
authenticating one another. Tree Structure of Keys
Hierarchy of Deterministic Keys As well as a chain (linear ) hierarchy as described above,
In one example , a series of successive deterministic keys a hierarchy in the form of a tree structure can be created .
may be determined , where each successive key may be 15 With a tree structure, a variety of keys for different
determined based on the preceding deterministic key. purposes such as authentication keys, encryption keys, sign
For example, instead of repeating steps 310 to 370 and ing keys , payment keys, etc. may be determined whereby
410 to 470 to generate successive single - purpose keys, by these keys are all linked to a single securely maintained
prior agreement between the nodes, the previously used master key . This is best illustrated in FIG . 9 that shows a tree
deterministic key (DK ) can be rehashed repeatedly by both 20 structure 901 with a variety of different keys. Each of these
parties to establish a hierarchy of deterministic keys. In can be used to create a shared secret with another party .
effect, the deterministic key, based on the hash of a message Tree branching can be accomplished in several ways,
(M ), can be a next generation message (M ') for the next three of which are described below .
generation of deterministic key (DK '). Doing this allows (i) Master Key Spawning
successive generations of shared secrets to be calculated 25 In the chain hierarchy, each new 'link ' (Public /Private key
without the need for further protocol-establishment trans pair ) is created by adding a multiply rehashed Message to
missions , in particular transmission ofmultiple messages for the original master key . For example , ( showing only the
each generation of common secrets . The next generation private key of the first node 3 for clarity ):
common secret ( CS ') can be computed as follows. V2c = Vic + SHA -256 (M ) ( Equation 24 )
Firstly, both the first node 3 and the second node 7 30
independently determine the next generation of the deter V2c'= V1c +SHA -256 (SHA - 256 (M )) (Equation 25 )
ministic key (DK '). This is similar to steps 320 and 420 but
adapted with the following formulas : V2c " = Vic + SHA - 256 (SHA - 256 ( SHA -256 (M ))) ( Equation 26 )
M = SHA -256 (M ) ( Equation 18 ) 35
and so on .
DK' = SHA - 256 ( M ) (Equation 19.1 ) To create a branch , any key can be used as a sub -master
key. For example V2c ' can be used as a sub -master key (V3c )
DK = SHA - 256 (SHA- 256 ( M )) (Equation 19.2 ) by adding the hash to it as is done for the regularmaster key :
The first node 3 may then determine the next generation 40 V3c = V2c + SHA - 256 (M ) (Equation 27)
of the second node second public key (P2s') and the first The sub -master key (V3c ) may itself have a next genera
node second private key (V2c ") similar to steps 370 and 330 tion key (V3c'), for example :
described above , but adapted with the following formulas:
(Equation 20.1) V3c '= V2c'+ SHA -256 ( SHA - 256 (M )) ( Equation 28 )
P2s'= P1s + DKxG
This provides a tree structure 903 using the master key
45
V2c '= Vic + DK ' (Equation 20.2 ) spawning method as shown in FIG . 10 .
The second node 7 may then determine the next genera ( ii )InLogical this
Association
method all the nodes in the tree (public/private key
tion of the first node second public key (P2c") and the second
node second private key (V2s') similar to steps 430 and 470 pairs ) are generated as a chain ( or in any other way ) and the
described above, but adapted with the following formulas: 50 logical relationships between the nodes in the tree is main
tained by a table in which each node in the tree is simply
P2C = Pic + DK'XG (Equation 21.1 ) associated with its parent node in the tree using a pointer.
(Equation 21.2 )
Thus the pointer may be used to determine the relevant
V2s = V1s + DK ' public /private key pairs for determining the common secret
The first node 3 and the second node 7 may then each 55 key (iii) (Message
CS ) for Multiplicity
the session .
determine the next generation common secret (CS'). New private / public key pairs can be generated by intro
In particular, the first node 3 determines the next genera
tion common secret (CS') with the formula : ducing a new message at any point in the chain or tree . The
CS'= V2c'XP2s
message itself may be arbitrary or may carry somemeaning
(Equation 22) 60 or function ( e.g. it might be related to a ' real'bank account
The second node 7 determines the next generation com number, etc ). It may be desirable that such new messages for
mon secret (CS ') with the formula : forming the new private /public key pairs are securely
retained .
CS' = V28XP2c ' ( Equation 23) Processing Device
Further generations ( CS " , CS" , etc.) can be calculated in 65 As noted above , the first and second nodes 3 , 7 may be an
the same way to create a chain hierarchy. This technique electronic device , such as a computer, tablet computer ,
requires that both the first node 3 and the second node 7 keep mobile communication device , computer server etc. The
US 10,652,014 B2
21 22
electronic device may include a processing device 23 , 27, a been used elsewhere already, the transaction is broadcast to
data store 13 , 17 and a user interface 15 . a network of computing nodes (“miners'). A miner accepts
FIG . 11 illustrates an example of a processing device 23, and records the transaction on the Blockchain only if the
27. The processing device 23, 27 may be used at the first input transaction hash is not yet connected and the signa
node 3 , second node 7 or other nodes 9. The processing 5 tures are valid . A miner rejects the transaction if the input
device 23, 27 includes a processor 1510 , a memory 1520 and transaction hash is already linked to a different transaction .
an interface device 1540 that communicate with each other Allocating cryptocurrency for a token comprises creating
via a bus 1530. The memory 1520 stores instructions and a transaction with the allocated cryptocurrency and the token
data for implementing the method 100 , 200 , 300 , 400 represented in a metadata field in the transaction .
described above , and the processor 1510 performs the 10 When two items are associated, this means that there is a
instructions from the memory 1520 to implement the logical connection between these items. In a database , for
method 100 , 200 , 300 , 400. The interface device 1540 , may example , identifiers for the two itemsmay be stored in the
include a communications module that facilitates commu same records to make the two items associated with each
nication with the communications network 5 and , in some other. In a transaction , identifiers for the two itemsmay be
examples,with the user interface 15 and peripherals such as 15 included in the transaction string to make the two items
data store 13, 17 , 19. It should be noted that although the associated with each other.
processing device 1501 may be independent network ele Using the bitcoin protocol, redeeming a script and /or
ments , the processing device 501may also be part of another unlocking a token comprises calculating a signature string of
network element. Further , some functions performed by the the script and/or transaction using the private key. The script
processing device 1501may be distributed between multiple 20 may require more than one signature derived from different
network elements . For example , the first node 3 may have private keys or other conditions. The output of this transac
multiple processing devices 23 to perform method 100 , 300 tion is then provided to a miner.
in a secure local area network associated with the first node Authorising another entity may comprise calculating a
3. signature string of a transaction using a private key and
Where this disclosure describes that a user, issuer, mer- 25 providing the signature string to the entity to allow the entity
chant, provider or other entity performs a particular action to use the signature to verify the transaction.
( including signing, issuing, determining, calculating, send A user having an account with another entity may com
ing , receiving, creating etc. ), this wording is used for the prise the entity storing information about the user, such as
sake of clarity of presentation. It should be understood that email address, name and potentially public keys. For
these actions are performed by the computing devices oper- 30 example, the entity may maintain a database , such as SQL ,
ated by these entities . OrientDB , MongoDB or others . In some examples, the
Signing may comprise executing a cryptographic func entity may also store one or more of the user's private keys.
tion . The cryptographic function has an input for a clear text The skilled person will appreciate that the present inven
and an input for a key , such as a private key . A processor may tion provides numerous technical benefits and advantages
execute the function to calculate a number or string that can 35 over the prior art . For example , the BIP32 protocol (e.g. as
be used as a signature . The signature is then provided described in the Bitcoin developer's guide ) uses a random
together with the clear text to provide a signed text. The seed to generate the sub -keys. This gives rise to a need to
signature changes completely if the message text or the key maintain a database of indices. In accordance with the
changes by a single bit. While calculating the signature present invention , however, a meaningfulmessage Mis used
requires little computational power, recreating a message 40 to generate the sub -keys (and therefore also the sub - shared
that has a given signature is practically impossible. This secrets ). Advantageously , this obviates the need for a data
way, the clear text can only be changed and accompanied by base of indices, and thus provides a simpler security tech
a valid signature if the private key is available . Further , other nique which is more efficient in terms of the computing
entities can easily verify the signature using the publicly resources needed to execute it. Additionally, it enables the
available public key. 45 association of meaningful information with the sub -keys.
In most circumstances , encrypting and decrypting com For example , reusable sub -keys may be used to represent
prises a processor executing a cryptographic function to specific bank accounts or client codes, etc. Alternatively,
calculate an output string representing the encrypted mes once-only sub -keys may be generated based on hashing a
sage or a clear text message respectively. specific invoice or movie (or other data ) file etc.
Keys , tokens , metadata , transactions, offers, contracts , 50 It will be appreciated by persons skilled in the art that
signatures , scripts,metadata , invitations, and the like refer to numerous variations and /or modifications may be made to
data represented as numbers, text or strings stored on data the above-described embodiments, without departing from
memory, such as variables in program code of type “ string” the broad general scope of the present disclosure as defined
or “ int” or other types or text files . by the appended claims. The present embodiments are ,
An example of the peer -to -peer ledger is the bitcoin 55 therefore, to be considered in all respects as illustrative and
Blockchain . Transferring funds or paying fees in bitcoin not restrictive .
currency comprises creating a transaction on the bitcoin The invention claimed is :
Blockchain with the funds or fees being output from the 1. A computer- implemented method of determining, at a
transaction . An example of a bitcoin transaction includes an first node (C ), a common secret (CS ) that is common with
input transaction hash , a transaction amount, one or more 60 the first node (C ), and a second node (S ), wherein the first
destinations, a public key of a payee or payees and a node (C ) is associated with a first asymmetric cryptography
signature created by using the input transaction as the input pair of a cryptography system having a homomorphic prop
message and a private key of a payer to calculate the erty, the first asymmetric cryptography pair having a first
signature . The transaction can be verified by checking that node master private key (Vic ) and a first node master public
the input transaction hash exists in a copy of the bitcoin 65 key (Pic ), and the second node (S ) is associated with a
Blockchain and that the signature is correct using the public second asymmetric cryptography pair of the cryptography
key . To ensure that the same input transaction hash has not system , the second asymmetric cryptography pair having a
US 10,652,014 B2
23 24
second node master private key (Vis) and a second node and the first node master public key (Pic ) and second node
master public key (P1s),wherein the firstnode master public master public key (Pis ) are based on elliptic curve point
key and second node master public key are based on multiplication of respective first node master private key
encryption of respective first node master private key and (Vic) and second node master private key (Vis ) and a
second node master private key using the cryptography 5 generator (G ).
system common with the first and second nodes, and 10. A method according to claim 1 further comprising the
wherein the method comprises : steps of:
determining a first node second private key (V2c ) based receiving , over a communications network , the second
on at least the first node master private key (Vic ) and node master public key (P 1s); and
a deterministic key (DK ) common with the first and 10 storing , at a data store associated with the first node (C ),
second nodes ; the second node master public key (P1s ).
determining a second node second public key (P2s) based 11. A method according to claim 2 further comprising the
on at least the second nodemaster public key (Pis) and steps of:
encryption of the deterministic key (DK ) using the generating, at a first node (C ), the first node master private
common cryptography system ; and 15 key (Vic ) and the first node master public key (Pic);
determining the common secret (CS ) based on encryption sending, over a communications network , the first node
of the first node second private key (V2c ), using the master public key (Pic ) to the second node (S ) and /or
common cryptography system , and the second node other node ; and
second public key (P2s ), storing , in a first data store associated with the first node
wherein the second node (S ) has the same common 20 (C ), the first node master private key (Vic ).
secret (S ) based on a first node second public key (P2c) 12. A method according to claim 11 further comprising :
and encryption of a second node second private key sending, over a communications network , to the second
( V2s) using the common cryptography system , node , a notice indicative of using a common cryptog
wherein : raphy system for the method of determining a common
the first node second public key (P2c ) is based on at 25 secret (CS ), and
least the first node master public key (Pic ) and wherein the step of generating the first node master
encryption of the deterministic key (DK ) using the private key (Vic ) and the first node master public key
common cryptography system ; and (Pic) comprises:
the second node second private key (V2s) is based on generating the first node master private key (Vic ) based
at least the second node master private key (Vis ) and 30 on a random integer in an allowable range specified
the deterministic key (DK ). in the common cryptography system ; and
2. The method according to claim 1 wherein the deter determining the first node master public key (Pic )
ministic key (DK ) is based on a message (M ). based on encryption of the first node master private
3. The method according to claim 2 further comprising : key (Vic).
generating a first signed message (SM1) based on the 35 13. A method according to claim 12 ,wherein the common
message (M ) and the first node second private key cryptography system is an elliptic curve cryptography
(V20) ; and (ECC ) system with a common generator (G ) and the first
sending, over a communications network , the first signed nodemaster public key (Pic) is determined based on elliptic
message (SM1) to the second node (S ), curve point multiplication of the first node master private
wherein the first signed message (SM1) can be validated 40 key ( Vic ) and the common generator (G ) according to the
with a first node second public key (P2c ) to authenticate following formula :
the first node (C ).
4. A method according to claim 2 further comprising: Pic = VicxG .
receiving, over a communications network, a second 45 14. A method according to claim 13 further comprising:
signed message (SM2) from the second node (S ); determining the deterministic key (DK ) based on deter
validating the second signed message (SM2) with the mining a hash of the message (M ), and
second node second public key ( P2S ); and wherein the step of determining a first node second
authenticating the second node (S ) based on the result of private key (V2C ) is based on a scalar addition of the
validating the second signed message (SM2), first node master private key (Vic ) and the determin
wherein the second signed message (SM2) was generated 50 istic key (DK ) according to the following formula :
based on the message (M ), or a second message (M2),
and the second node second private key (V2s). V2c = Vic + DK , and
5. A method according to claim 2 further comprising : wherein the step of determining a second node second
generating a message (M ); and public key (P2S ) is based on the second node master
sending, over a communications network , the message 55 public key (P1s) with elliptic curve point addition to the
( M ) to the second node (S ). elliptic curve point multiplication of the deterministic
6. A method according to claim 2 further comprising : key (DK ) and the common generator (G ) according to
receiving the message (M ), over a communications net the following formula :
work , from the second node (S ) .
7. A method according to claim 2 further comprising : 60
P2s = P1s + DK?G .
receiving the message (M ), over a communications net
work , from another node . 15. A method according to claim 1 wherein the determin
8. A method according to claim 2 further comprising: istic key (DK ) is based on determining a hash of a previous
receiving the message (M ) from a data store , and/or an deterministic key .
input interface associated with the first node (C ). 65 16. A method according to claim 1 wherein the first
9. A method according to claim 1 wherein the cryptog asymmetric cryptography pair and the second asymmetric
raphy system is an elliptic curve cryptography (ECC ) system cryptography pair are based on a function of respective
US 10,652,014 B2
25 26
previous first asymmetric cryptography pair and previous the first node master public key (Pic ), the second node
second asymmetric cryptography pair. master public key (P1s), the first signed message (SM1), the
17. A method of secure communication between a first second signed message (SM2), a notice indicative of using
node and a second node with symmetric-key algorithm , a common cryptography system .
wherein the method comprises : 5
25. A device according to claim 24 , wherein the common
determining a common secret by means of a method cryptography system is an elliptic curve cryptography
according to claim 1 ; (ECC ) system with a common generator (G ).
determining a symmetric-key based on the common 26. A system for determining a common secret between a
secret ; first node (C ) and a second node (S ), wherein :
encrypting a first communication message, with the sym- 10 the first node (C ) is associated with a first asymmetric
metric -key, to an encrypted first communication mes cryptography pair of a cryptography system having a
sage; and homomorphic property , the first asymmetric cryptog
sending, over a communications network , the encrypted raphy pair having a first node master private key (Vic)
first communication message from the first node (C ) to and a first node master public key (Pic), and
the second node ( S ). 15 the second node (S ) is associated with a second asym
18. A method according to claim 17, wherein the method metric cryptography pair of the cryptography system ,
further comprises: the second asymmetric cryptography pair having a
receiving , over the communications network , an second node master private key (Vis) and a second
encrypted second communication message from the node master public key (P1s), wherein the first node
second node (S ); and
master public key and second node master public key
decrypting the encrypted second communication mes
20
are based on encryption of respective firstnode master
private key and second node master private key using
sage , with the symmetric -key , to a second communi the cryptography system common with the first and
cation message . econd nodes, and the system comprising:
19. A method ofperforming an online transaction between a first processing device , associated with the first node
a first node and a second node , wherein the method com- 25 (C ), configured to :
prises: determine a first node second private key (V2c )
determining a common secret by means of a method based on at least the first node master private key
according to claim 1; (Vic ) and a deterministic key (DK ) common with
determining a symmetric-key based on the common the first and second nodes ;
secret; 30 determine a second node second public key (P2s)
encrypting a first transaction message, with the symmet based on at least the second node master public
ric -key , to an encrypted first transaction message ; key (P1s) and encryption of the deterministic key
sending, over a communications net rk , the encrypted (DK ) using the common cryptography system ;
first transaction message from the first node (C ) to the and
second node (S ); 35 determine the common secret (CS) based on encryp
receiving , over the communications network , an tion of the first node second private key (V2c),
encrypted second transaction message from the second using the common cryptography system , and the
node (S ); and second node second public key (P2s); and
decrypting the encrypted second transaction message , a second processing device , associated with the second
node (S ), configured to :
with the symmetric-key , to a second transaction mes- 40 determine a first node second public key (P2c ) based
sage . on at least the first node master public key (Pic )
20. A device for determining, at a first node (c ), a common and encryption of the the deterministic key (DK )
secret (CS ) that is common with a second node (S ), wherein using the common cryptography system ; and
the first node (C ) is associated with a first asymmetric determine a second node second private key (V2s)
cryptography pair having a first node master private key 45 based on at least the second node master private
(Vic ) and a first node master public key (Pic ), and the key (Vis) and the deterministic key (DK );
second node (S ) is associated with a second asymmetric determine the common secret based on the first node
cryptography pair having a second node master private key second public key (P2c ) and encryption of a
(Vis ) and a second node master public key (Pus), wherein second node second private key (V2s) using the
the device comprises a first processing device to perform the 50 common cryptography system ,
method according to claim 4 to determine the common wherein the first processing device and the second
secret. processing device determine the same common
secret .
21. A device for secure communication, or performing a 27. A system according to claim 26 wherein the deter
secure online transaction between a first node and a second
ministic key
node, wherein the device includes a first processing device 55 processing device (DK ) is based on a message (M ), and the first
to :
is further configured to :
perform the method according to claim 17 . generate a first signed message (SM1) based on the
22. A device according to claim 20 further comprising a message ( M ) and the first node second private key
first data store to store one or more of the first node master (V2c ); and
private key (Vic). send, over a communications network , the first signed
60
message (SM1) to the second node (S ),
23. A device according to claim 22 wherein the first data wherein the second processing device is further config
store further stores one or more of the first node master ured to :
public key (Pic), the second node master public key (P1s), receive the first signed message (SM1);
and the message (M ). validate the first signed message (SM1) with the first
24. A device according to claim 20 , further comprising a 65 node second public key (P2c ); and
communications module to send and /or receive , over a authenticate the first node (C ) based on a result of the
communications network , one or more of the message (M ), validated first signed message (SMI).
US 10,652,014 B2
27 28
28. A system according to claim 27 wherein the second 37. A system according to claim 26 wherein the first
processing device is further configured to : processing device is further configured to :
generate a second signed message (SM2) based on the generate the first node master private key (Vic ) based on
message ( M ), or a second message (M2 ), and the a random integer in an allowable range specified in a
second node second private key (V2s) ; and 5 common cryptography system ; and
send the second signed message (SM2 ) to the first node determine the first node master public key (Pic) based on
(C ), encryption of the first node master private key (Vic),
wherein the first processing device is further configured andconfigured
wherein tothe: second processing device is further
to :
receive the second signed message (SM2); 10 generate the second node master private key (Vis)
validate the second signed message (SM2) with the based on a random integer in the allowable range
second node second public key (P2s); and specified in the common cryptography system ; and
authenticate the second node ( S ) based on a result of the determine the second node master public key (Pis)
validated second signed message (SM2). based on encryption of the second node master
29. A system according to claim 27 wherein the first 15 private key (Vis).
processing device is configured to : 38. A system according to claim 37 wherein the common
generate a message (M ); and cryptography system is an elliptic curve cryptography
send the message (M ), (ECC ) system with a common generator (G ), wherein the
wherein the second processing device is configured to : first processing device is further configured to :
receive the message (M ). 20 determine the first node master public key (Pic) based on
30. A system according to claim 29 wherein the message elliptic curve point multiplication of the first node
is generated by another node, wherein the first processing master private key (Vic ) and the common generator
device is configured to : according to the formula :
receive the message (M ), Pic = VicxG .
wherein the second processing device is configured to : 25
receive the message (M ). and wherein the second processing device is further
31. A system according to claim 29 further comprising a configured to :
system data store and / or input interface , wherein the first determine the second node master public key (Pls )
processing device and second processing device receives the based on elliptic curve point multiplication of the
message (M ), or a second message (M2) from the system 30 second node master private key (Vis ) and the com
data store and /or input interface . mon generator according to the formula :
32. A system according to claim 31 , wherein the first Pis = V15xG .
processing device receives the second node master public
key (Pis) from the system data store and /or inputdevice, and 39. A system according to claim 29 wherein the first
the second processing device receives the first node master 35 processing device is configured to :
public key (Pic ) from the system data store and / or input determine the deterministic key (DK ) based on a hash of
device . the message ( M ), and wherein :
33. A system according to claim 26 wherein the cryptog the first node second private key (V2c ) is based on a
raphy system is an elliptic curve cryptography (ECC ) system scalar addition of the first node master private key
and the first node master public key (Pic ), second node 40 (Vic ) and the deterministic key (DK ) according to
the formula :
master public key (Pis ) are based on elliptic curve point
multiplication of respective first node master private key V2c = Vic + DK ; and
(Vic) and second node master private key ( Vis) and a the second node public key (P2s) is based on the second
generator (G ).
34. A system according to claim 26 further comprising : 45 node master public key (P1s) with elliptic curve point
a first data store associated with the first node (C ) to store addition to the elliptic curve point multiplication of
the first node master private key (Vic ); and the deterministic key (DK ) and the common genera
a second data store associated with the second node (S ) to tor (G ) according to the following formula :
store the second node master private key (Vis). P2s = P 1s+ DKxG
35. A system according to claim 34 , wherein the first 50 and wherein the second processing device is configured
processing device is configured to : to :
generate the first node master private key (Vic) and the determine the deterministic key (DK ) based on a hash
first node master public key (Pic ); of the message (M ), and wherein :
send the first node master public key (Pic ); and the second node second private key (V2s) is based on
store the first node master private key (Vic ) in the first 55 a scalar addition of the second node master private
data store, key (Vis) and the deterministic key (DK ) accord
wherein the second processing device is configured to : ing to the formula :
generate the second node master private key (Vis ) and
the second node master public key (P1s); V2s = Vic + DK ; and
send the second node master public key (P1s ); and 60 the first node public key (P2c ) is based on the first
store the second node master private key (Vis ) in the node master public key (Pic ) with elliptic curve
second data store .
36. A system according to claim 34 , wherein : point addition to the elliptic curve point multipli
the first data store receives and stores the second node cation of the deterministic key (DK ) and the
master public key (P1s); and 65 common generator (G ) according to the following
formula :
the second data store receives and stores the first node
master public key (Pic ). P2c = Pic + DKxG .
US 10,652,014 B2
29 30
40. A system according to claim 28 further comprising : encrypt a first communication message, with the sym
a first communications module associated with the first metric -key, to an encrypted first communication
processing device to send and /or receive, over a com message; and
munications network , one or more of the message (M ), send the encrypted first communication message ;
the first node master public key (Pic ), the second node 5 wherein the second processing device is further config
master public key (Pls ), the first signed message ured to :
( SM1), the second signed message (SM2), and a notice determine the same symmetric -key based on the com
indicative of using a common cryptography system ; mon secret;
and
a second communications module associated with the 10 receive the encrypted first communication message ;
and
second processing device to send and/or receive, over decrypt the encrypted first communication message,
a communications network , one or more of the message with the symmetric -key, to the first communication
(M ), the first node master public key (Pic ), the second message .
node master public key (P1s), the first signed message 45. A system according to claim 44 , wherein the second
(SM1), the second signed message (SM2), and the 15
notice indicative of using a common cryptography processing device is further configured to :
encrypt a second communication message , with the sym
system .
41. A system according to claim 40 , wherein the common metric-key, to the encrypted second communication
cryptography system is an elliptic curve cryptography message; and
( ECC ) system with a common generator (G ). 20 send the encrypted second communication message ;
42. A system according to claim 26 , wherein the deter wherein the first processing device is further configured
ministic key (DK ) is based on determining a hash of a to :
previous deterministic key. receive the encrypted second communication message ;
43. A method according to claim 26 wherein the first and
asymmetric cryptography pair and the second asymmetric 25 decrypt the encrypted second communication message ,
cryptography pair are based on a function of respective with the symmetric -key, to the second communica
previous first asymmetric cryptography pair and previous tion message .
second asymmetric cryptography pair. 46. A system according to claim 45 wherein the first and
44. A system for secure communication between a first second communication messages are transaction messages
node and a second node with symmetric -key algorithm , 30 between the first node and second node for an online
wherein the system comprises : transaction between the first node and the second node .
a system according to claim 26 to determine a common 47. A computer program stored in one or more non
secret with the first processing device and the second transitory computer readable media comprising machine
processing device , wherein the first processing device readable instructions to cause a processing device to imple
is further configured to : 35
determine a symmetric -key based on the common ment the method according to claim 1.
secret;