Linking system and method

The linking system securely connects Web2 and Web3 accounts by verifying information through a signed message and server parameters, facilitating secure and transparent access to digital assets.

WO2026015070A1PCT designated stage Publication Date: 2026-01-15RAZER ASIA PACIFIC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/SG2024/050443
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-09
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

There is a need for an improved method and system to link a centralized Web2 account with a decentralized Web3 wallet account, ensuring secure and transparent transactions and data storage across multiple participants.

Method used

A linking system comprising a network of computing devices and a server, which receives and verifies information from a Web3 wallet account using a signed message and signature to securely link a Web2 account with a Web3 wallet account, utilizing server parameters and time stamps for authentication.

Benefits of technology

Ensures secure and transparent linking of Web2 and Web3 accounts, enabling seamless access to digital assets without compromising security or decentralization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SG2024050443_15012026_PF_FP_ABST
    Figure SG2024050443_15012026_PF_FP_ABST
Patent Text Reader

Abstract

A method for linking a first account of a user with a second account of the user by a linking system comprising a network of computing devices where a first application and a second application are operated and a server that the network of computing devices is connected to, the method comprising: receiving, by the first application, a first information associated with the second account from the second application; generating, by the second application, a signed message comprising a message and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein the message comprises an identification associated with the first account, and the first information associated with the second account; verifying, by at least one of the network of computing devices and the server, if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message; and linking, by the server, the first account with the second account when the first information is verified to be a true information.
Need to check novelty before this filing date? Find Prior Art

Description

LINKING SYSTEM AND METHODTECHNICAL FIELD

[0001] This disclosure relates to a method for linking a first account (c.g., a wcb2 account) of a user with a second account (e.g., a web3 wallet account) of the user by a linking system comprising a network of computing devices and a server. This disclosure also relates to the linking system.BACKGROUND

[0002] Web3 wallet is a digital wallet that can interact with a blockchain network, a decentralized system that enable secure, transparent, and tamper-proof transactions and data storage across multiple participants. The Web3 wallet can store, send and receive digital assets such as encrypted currency, tokens, etc.

[0003] Web2 account may refer to a user account managed and utilized in the Web2 ecosystem, which is characterized by traditional and centralized internet services. Web2 encompasses a broad range of services including social media platforms, email providers, etc.

[0004] Therefore, there exists a need for providing an improved method and system for linking a web2 account with a web3 wallet account.SUMMARY

[0005] According to a first aspect of the present disclosure, a method for linking a first account of a user with a second account of the user by a linking system is provided. The linking system may comprise a network of computing devices where a first application and a second application are operated and a server that the network of computing devices is connected to. The method may comprise: receiving, by the first application, a first information associated with the second account from the second application; generating, by the second application, a signed message comprising a message and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein the message comprises an identification associated with the first account, and the first information associated with the second account; verifying, by at least one of the network of computing devices and the server, if the first information associated with the second account is a true information based on a second information associated with the second account derivedfrom the second account signature in the signed message; and linking, by the server, the first account with the second account when the first information is verified to be a true information.

[0006] According to a second aspect of the present disclosure, a linking system for linking a first account of a user with a second account of the user is provided. The linking system may comprise: a network of computing devices where a first application and a second application are operated; and a server that the network of computing devices is connected to, wherein the network of computing devices is configured to: receive, by the first application, a first information associated with the second account from the second application; generate, by the second application, a signed message comprising a message and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein the message comprises an identification associated with the first account and the first information associated with the second account, wherein the at least one of the network of computing devices and the server is configured to verify if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message, wherein the server is configured to link the first account with the second account when the first information is verified to be a true information.BRIEF DESCRIPTION OF THE DRAWINGS

[0007] In the drawings, like reference characters generally refer to like parts throughout the different views. The drawings are not necessarily to scale, emphasis instead generally being placed upon illustrating the principles of the disclosure. In the following description, various embodiments of the disclosure are described with reference to the following drawings, in which:

[0008] FIG. 1 shows a schematic illustration of a linking system configured to link a first account of a user with a second account of the user in accordance with some embodiments of the present disclosure;

[0009] FIG. 2 shows a schematic illustration of a linking system configured to link a first account of a user with a second account of the user in accordance with some embodiments of the present disclosure;

[0010] FIG. 3 shows a flow chart depicting an exemplary verification process;

[0011] FIG. 4 and FIG. 5 show an example of the first graphical user interface (GUI) and the second GUI of the network of computing devices 130, respectively;

[0012] FIG. 6 is a flow chart depicting a method for linking a first account of a user with a second account of the user according to some embodiments.DETAILED DESCRIPTION

[0013] The following detailed description refers to the accompanying drawings that show, by way of illustration, specific details, and embodiments in which the disclosure may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the disclosure. Other embodiments may be utilized, and structural, logical, optical and electrical changes may be made without departing from the scope of the disclosure. The various embodiments arc not necessarily mutually exclusive, as some embodiments can be combined with one or more other embodiments to form new embodiments.

[0014] Embodiments described in the context of one of the methods or devices are analogously valid for the other methods or devices. Similarly, embodiments described in the context of a method are analogously valid for a device, and vice versa.

[0015] Features that arc described in the context of an embodiment may correspondingly be applicable to the same or similar features in the other embodiments. Features that are described in the context of an embodiment may correspondingly be applicable to the other embodiments, even if not explicitly described in these other embodiments. Furthermore, additions and / or combinations and / or alternatives as described for a feature in the context of an embodiment may correspondingly be applicable to the same or similar feature in the other embodiments.

[0016] It should be understood that the terms “on”, “over”, “top”, “bottom”, “down”, “side”, “back”, “left”, “right”, “front”, “back”, “lateral”, “side”, “up”, “down”, “vertical”, “horizontal” etc., when used in the following description are used for convenience and to aid understanding of relative positions or directions, and not intended to limit the orientation of any device, or structure or any part of any device or structure. In addition, the singular terms "a", "an", and "the" include plural references unless context clearly indicates otherwise. Similarly, the “or” is intended to include “and” unless the context clearly indicates otherwise.

[0017] It will be further understood that the terms “comprise” (and any form of comprise, such as “comprises” and “comprising”), “have” (and any form of have, such as “has” and “having”), “include” (and any form of include, such as “includes” and “including”), and “contain” (and any form of contain, such as “contains” and “containing”) are open-ended linking verbs. As a result, a method or device that “comprises,” “has,” “includes” or “contains” one or more steps or elements possesses those one or more steps or elements, but is not limited to possessing onlythose one or more steps or elements. Likewise, a step of a method or an element of a device that “comprises,” “has,” “includes” or “contains” one or more features possesses those one or more features, but is not limited to possessing only those one or more features. Furthermore, a device or structure that is configured in a certain way is configured in at least that way, but may also be configured in ways that are not listed.

[0018] Approximating language, as used herein throughout the specification and claims, may be applied to modify any quantitative representation that could permissibly vary without resulting in a change in the basic function to which it is related. Accordingly, a value modified by a term or terms, such as “about,” “substantially”, is not limited to the precise value specified but within tolerances that are acceptable for the operation of the embodiment for an application for which it is intended. Tn some instances, the approximating language may correspond to the precision of an instrument for measuring the value.

[0019] The term “exemplary” may be used herein to mean “serving as an example, instance, or illustration”. Any aspect or design described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other aspects or designs.

[0020] The terms “at least one” and “one or more” may be understood to include a numerical quantity greater than or equal to one (e.g., one, two, three, four, [...], etc.). The term “a plurality” may be understood to include a numerical quantity greater than or equal to two (e.g., two, three, four, five, [...], etc.). The phrase “at least one of’ with regard to a group of elements may be used herein to mean at least one element from the group consisting of the elements. For example, the phrase “at least one of’ with regard to a group of elements may be used herein to mean a selection of: one of the listed elements, a plurality of one of the listed elements, a plurality of individual listed elements, or a plurality of a multiple of listed elements.

[0021] The words “plural” and “multiple” in the description and the claims expressly refer to a quantity greater than one. Accordingly, any phrases explicitly invoking the aforementioned words (e.g., “a plurality of (objects)”, “multiple (objects)”) referring to a quantity of objects expressly refer to more than one of the said objects. The terms “group (of)”, “set (of)”, “collection (of)”, “series (of)”, “sequence (of)”, “grouping (of)”, etc., and the like in the description and in the claims, if any, refer to a quantity equal to or greater than one, i.c. one or more.

[0022] The term “first”, “second”, “third” detailed herein are used to distinguish one element from another similar element and may not necessarily denote order or relative importance, unless otherwise stated.

[0023] As used herein, the phrase of the form of “at least one of A or B” may include A or B or both A and B. Correspondingly, the phrase of the form of “at least one of A or B or C”, or including further listed items, may include any and all combinations of one or more of the associated listed items.

[0024] The following examples pertain to various aspects of the present disclosure.

[0025] Example 1 is a method for linking a first account of a user with a second account of the user by a linking system comprising a network of computing devices where a first application and a second application arc operated and a server that the network of computing devices is connected to, the method comprising: receiving, by the first application, a first information associated with the second account from the second application; generating, by the second application, a signed message comprising a message and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein the message comprises an identification associated with the first account, and the first information associated with the second account; verifying, by at least one of the network of computing devices and the server, if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message; and linking, by the server, the first account with the second account when the first information is verified to be a true information.

[0026] In Example 2, the subject matter of Example 1 may optionally include that the first information is verified to be a true information when the second information is the same as the first information.

[0027] In Example 3, the subject matter of Example 1 may optionally include: obtaining, by the first application, prior to generating the signed message by the second application, at least one server parameter from the server by sending the first information associated with the second account to the server; wherein the message further comprises the at least one server parameter, wherein the at least one server parameter comprises a nonce and a time stamp, wherein the linking of the first account with the second account occurs when (i) the second information is the same as the first information, (ii) the nonce in the signed message is generated by the server, and (iii) the signed message is returned to the server within a predetermined time duration from the time stamp.

[0028] In Example 4, the subject matter of Example 3 may optionally include that the identification associated with the first account and a fust account signature signed using aprivate key of the first account arc sent to the server by the first application for obtaining the at least one server parameter from the server.

[0029] In Example 5, the subject matter of Example 1 may optionally include: checking, by the first application, whether the first account is linked with the second account; and requesting, by the first application, the first information associated with the second account from the second application when the first account is unlinked with the second account.

[0030] In Example 6, the subject matter of Example 1 may optionally include creating, by the first application, the message for the user to sign.

[0031] In Example 7, the subject matter of Example 1 may optionally include generating a public key from the second account signature in the signed message by the first application; and deriving the second information from the public key by the first application.

[0032] In Example 8, the subject matter of Example 1 may optionally include receiving the signed message from the network of computing devices by the server; generating a public key from the second account signature in the signed message by the server; and deriving the second information from the public key by the server.

[0033] In Example 9, the subject matter of Example 1 may optionally include informing the user, by an output interface of the network of computing devices, that a local verification fails when the first and second information are determined to be different by the network of computing devices.

[0034] In Example 10, the subject matter of Example 1 may optionally include storing, by the server, the linking of the first account with the second account in a database.

[0035] In Example 11, the subject matter of Example 1 may optionally include informing the user, by an output interface of the network of computing devices, that the linking is successful when the first account is linked with the second account.

[0036] In Example 12, the subject matter of Example 1 may optionally include that the second account is a web3 wallet account.

[0037] In Example 13, the subject matter of Example 1 may optionally include that the first account is a web2 account managed by a centralized server.

[0038] Example 14 is a linking system for linking a first account of a user with a second account of the user, the linking system comprising: a network of computing devices where a first application and a second application are operated; and a server that the network of computing devices is connected to, wherein the network of computing devices is configured to: receive, by the first application, a first information associated with the second account from the second application; generate, by the second application, a signed message comprising amessage and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein the message comprises an identification associated with the first account and the first information associated with the second account, wherein the at least one of the network of computing devices and the server is configured to verify if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message, wherein the se r ver is configured to link the first account with the second account when the first information is verified to be a true information.

[0039] In Example 15, the subject matter of Example 14 may optionally include that the first information is verified to be a true information w'hen the second information is the same as the first information.

[0040] In Example 16, the subject matter of Example 14 may optionally include that the network of computing devices is configured to obtain, by the first application, prior to generating the signed message by the second application, at least one server parameter from the server by sending the first information associated with the second account to the server, wherein the message further comprises the at least one server parameter, wherein the at least one server parameter comprises a nonce and a time stamp, wherein the linking of the first account with the second account occurs when (i) the second information is the same as the first information, (ii) the nonce in the signed message is generated by the server, and (iii) the signed message is returned to the server within a predetermined time duration from the time stamp.

[0041] In Example 17, the subject matter of Example 16 may optionally include that the identification associated with the first account and a first account signature signed using a private key of the first account are sent to the server by the first application for obtaining the at least one server parameter from the server.

[0042] In Example 18, the subject matter of Example 14 may optionally include that the network of computing devices is configured to: check, by the first application, whether the first account is linked with the second account; and request, by the first application, the first information associated with the second account from the second application when the first account is unlinked with the second account.

[0043] In Example 19, the subject matter of Example 14 may optionally include that the network of computing devices is configured to create, by the first application, the message for the user to sign.

[0044] In Example 20, the subject matter of Example 14 may optionally include that the network of computing devices is configured to: generate a public key from the second account signature in the signed message by the first application; and derive the second information from the public key by the first application.

[0045] In Example 21, the subject matter of Example 14 may optionally include that the server is configured to: receive the signed message from the network of computing devices; generate a public key from the second account signature in the signed message; and derive the second information from the public key.

[0046] In Example 22, the subject matter of Example 14 may optionally include that the second account is a web3 wallet account.

[0047] In Example 23, the subject matter of Example 14 may optionally include that the first account is a web2 account managed by a centralized server.

[0048] In various embodiments, the linking system and the method for linking a first account of a user with a second account of the user will now be described by way of the following nonlimiting examples.

[0049] FIG. 1 shows a schematic illustration of a linking system 100 configured to link a first account for a first applicationa first account of a user with a second account of the user in accordance with some embodiments of the present disclosure.

[0050] The linking system 100 may include a network of computing devices 130 where a first application and a second application are operated. The linking system 100 may include a server 140 that the network of computing devices 130 is connected to. A computing device in the network of computing devices 130 may include a laptop computer, a smart phone, a desktop computer, an electronic tablet, or another suitable computing device. A server 140 may refer to a computer system or software application that provides services, resources, or data to other computers, known as clients, over a network. A server 140 may be configured to manage, process, and respond to requests from the clients.

[0051] In some embodiments, the first account may include a web2 account managed by a centralized server. The second account may include a web3 wallet account. The first account may be associated with the first application in a manner that the user may have access to the first application using the first account. In other words, the first application may be accessed by the user after the user has logged into the first account. The second account may be associated with the second application in a manner that the user may have access to the second application using the second account. In other words, the second application may be accessed by the user after the user has logged into the second account.

[0052] The first application may include a decentralized application (or referred to as Dapp). The decentralized application may refer to software programs / applications that run on a blockchain or peer-to-peer (P2P) network of computing devices instead of on a single computing device (or referred to as centralized server). Rather than operating under the control of a single authority, the decentralized application may be spread across the network of computing devices to be collectively controlled by the users of the computing devices in the network of computing devices. The decentralized application may leverage the blockchain's capabilities for transparency, security, and decentralization.

[0053] The second application may include a web3 wallet (or referred to as web 3.0 wallet, crypto wallet). The web3 wallet may refer to a digital wallet that is able to interact with a blockchain network. The web3 wallet may store, send and receive digital assets such as encrypted currency, non-fungible tokens, etc. The web3 wallet may also interact with a blockchain-based decentralized application (Dapp).

[0054] The first application may include an application providing a broad range of traditional and centralized internet services including social media platforms, email providers, gaming platforms, etc.

[0055] FIG. 2 shows a schematic illustration of a linking system 100 configured to link a first account of a user with a second account of the user in accordance with some embodiments of the present disclosure. The linking system 100 may include a network of computing devices 130 where the first application 110 and the second application 120 are operated. The linking system 100 may include a server 140 that the network of computing devices 130 is connected to.

[0056] After a user (e.g., a gamer) logs into the first account (e.g., a web2 account) of the user, if the user intends to read all the digital assets (e.g., non-fungible tokens (NFTs)) he / she owns in the second account (e.g., web3 wallet account) without logging into the second account, the user may indicate the intention, for example, by clicking a button such as a button named “check NFTs in crypto wallet” in a graphical user interface (GUI) in the first account.

[0057] After the user indicates the intention (e.g., by clicking the button), the network of computing devices 130 may check, by the first application 110, whether the first account is associated with (or referred to as linked with) the second account, e.g., in a local cache 150 or a remote data base 152. The network of computing devices 130 may be configured to receive, by the first application 110, whether the first account is linked with the second account, e.g., from a local cache 150 or a remote data base 152. If the first account is associated with thesecond account, the network of computing devices 130 may display to the user how much digital assets (e.g., NFTs) the user has in his / her second account.

[0058] If the first account is not associated with the second account, the network of computing devices 130 may display a notification that the first account is not associated with the second account, and request the user to confirm if he / she intends to link the first account with a second account.

[0059] Upon the user confirms that he / she intends to link the first account with the second account (e.g., by clicking a button named “yes” in a GUI), the network of computing devices 130 may be configured to request, by the first application 110, a first information associated with the second account from the second application when the first account is unlinked with the second account. A wallet address may be an example of the first information associated with the second account. The network of computing devices 130 may be configured to send, by the second application 120, the first information associated with the second account to the first application 110 upon receiving the request from the first application 110. The network of computing devices 130 may be configured to receive, by the first application 110, a first information associated with the second account from the second application 120.

[0060] The network of computing devices 130 may be configured to send to a server 140 a request for at least one server parameter (such as nonce and time stamp) by the first application 110. The request for the at least one server parameter may be accompanied by the first information associated with the second account. The request for the at least one server parameter may be accompanied by the identification associated with the first account and a first account signature obtained by signing using a private key of the first account via secure Application Programming Interface (API) when the user has logged into the first account. The private key used herein may refer to a variable in cryptography that is used with an algorithm to sign and decrypt data. The private key may only be shared with the generator of the key or parties authorized to decrypt the data. The first account signature helps to prove an ownership of the identification associated with the first account (e.g., ID ownership), preventing impersonation attack.

[0061] The server 140 may be configured to send the at least one server parameter to the first application 1 10 of the network of computing devices 130 upon receiving the request from the first application 110 for the at least one server parameter. The network of computing devices 130 may be configured to obtain / receive, by the first application 110, the at least one server parameter from the server 140 upon sending the request for the at least one server parameter to the server 140.

[0062] The network of computing devices 130 may be configured to obtain, by the first application 110, the at least one server parameter from the server 140 by sending the first information associated with the second account to the server 140.

[0063] The network of computing devices 130 may be configured to obtain, by the first application 110, the at least one server parameter from the server 140 by sending to the server 140 the first information associated with the second account, the identification associated with the first account and a first account signature obtained by signing using a private key of the first account. The at least one server parameter may include a nonce and a time stamp. The nonce may refer to an arbitrary number which is only used one time in a cryptographic communication. A nonce may include a timestamp, which means it is only valid during a specific amount of time, to help ensure that it is only used once. The time stamp may follow ISO 8601 format.

[0064] For example, the network of computing devices 130 may be configured to send to the server 140 by the first application 110 a first data shown in the following example. The first data may comprise the identification associated with the first account, the first information associated with the second account, and a first account signature.

[0065] In the following example of the first data, ID may be an example of the identification associated with the first account of a user. First wallet address may be an example of the first information associated with the second account received from the second application 120.

[0066] Example of the first data:ID: RZRabcFirst wallet address: 0xa46A10BEal7c7A7c0313FflbD42d3A5cB2Ac27cEFirst account signature:0xe67c81049dc3d2de24b7f8e8668b528fbefcflc29c0a91dcf23e9255c75bd0ca38f05b 0ce5eaa0f600cee592f2ae3e307babcc66cac4df64d085339f8bl38e26

[0067] The network of computing devices 130 may be configured to obtain, by the first application 110, the at least one server parameter (e.g., nonce, time stamp) as indicated in the following example of a second data from the server 140 by sending the above example of the first data to the server 140 by the first application 110. The second data may comprise the identification associated with the first account, the first information associated with the second account, the at least one server parameter (e.g., nonce, time stamp). In the following example of the second data, ID may be an example of the identification associated with the first account of the user. First wallet address may be an example of the first information associated with the second account received from the second application 120.

[0068] Example of the second data:ID: RZRabcFirst wallet address: 0xa46A10BEal7c7A7c0313FflbD42d3A5eB2Ac27eENonce: 5834985385035894Time Stamp: 2024-04-24 14:27:00.100Z

[0069] The network of computing devices 130 may be configured to send a message, by the first application 110 (e.g., Dapp) to the second application 120 (e.g., web3 wallet). The network of computing devices 130 may be configured to generate, by the second application 120 (e.g., web3 wallet), a signed message including the message and a second account signature. The second account signature may be generated upon the user signing the message using the second account The user may sign the message only after the user has logged into the second account. The user may log into the second account by inputting associated password by a second account user interface. The user may sign the message using a private key (privk) of the second account (e.g., web3 wallet account) via secure API when the user has logged into the second account. The message may include an identification associated with the first account. The message may further include the first information associated with the second account received from the second application 120 by the first application 110. The message may further include the at least one server parameter obtained from the server 140 by the first application 1 10. The at least one server parameter may include nonce and time stamp.

[0070] An example of the message is provided as follows. In the following example of the message, ID may be an example of the identification associated with the first account of the user. First wallet address may be an example of the first information associated with the second account received from the second application 120.

[0071] Example of the message:Wallet Owner VerifierID: RZRabcFirst wallet address: 0xa46A10BEal7c7A7c0313FflbD42d3A5eB2Ac27eENonce: 5834985385035894Time Stamp: 2024-04-24T14:27:00.100Z

[0072] An example of the second account signature that is generated upon the user signing the above example of message using the second account is provided as follows:Example of the second account signature:0x723055ec6787f4efb40e99616de4a7c2f27f4del7f881cd44bb2dcabf791b8c54f9977 b89cc22al9f675c4cacla266cla375023297753d9afc95caf517bc0fd01c

[0073] According to some non-limiting embodiments, the at least one of the network of computing devices 130 and the server 140 may be configured to verify if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message. The first information associated with the second account may be verified to be a true information when the second information is the same as the first information.

[0074] The network of computing devices 130 may be configured to receive the signed message, by the first application 110 (c.g., Dapp), from the second application 120 (c.g., wcb3 wallet). The network of computing devices 130 may be configured to verify if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message. The server 140 may be configured to receive the signed message from the first application 110 of the network of computing devices 130. The server 140 may be configured to verify if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message. The server 140 may be configured to verify if the nonce in the signed message is generated by the server 140, and if the signed message is returned to the server 140 within a predetermined time duration from the time stamp in the signed message.

[0075] According to some non-limiting embodiments, the server 140 may be configured to link the first account with the second account when the first information associated wdth the second account is verified to be a true information by the at least one of the network of computing devices 130 and the server 140.

[0076] According to some non-limiting embodiments, the server 140 may be configured to link the first account with the second account when (i) the first information is verified to a true information (e.g., the second information is the same as the first information) by the at least one of the network of computing devices 130 and the server 140, (ii) the nonce in the signed message is generated by the server 140, and (iii) the signed message is returned to the server 140 within a predetermined time duration from the time stamp in the signed message.

[0077] The server 140 may be configured to store the linking of the first account with the second account in a database, e.g., by storing the identification associated with the first account and the first / second information associated w'ith the second account in the database. In some embodiments, only the server 140 can store the linking of the first account with the second account in the database, while other devices (such as the network of computing devices) canonly query the association status (i.c., whether the first account is linked with the second account), e.g., for security reasons. The server 140 may be configured to send to the network of computing devices 130 (or referred to as client) a result that the linking of the first account with the second account is successful when the first account is linked with the second account. The network of computing devices 130 may include an output interface configured to inform the user that a result that the linking of the first account with the second account is successful when the first account is linked with the second account. The output interface may include a display screen of the user’s computing device in the network of computing devices 130. For example, a first GUI 132 as shown in FIG. 4 may display the result that the linking of the first account with the second account is successful when the first account is linked with the second account.

[0078] FIG. 3 shows a flow chart depicting an exemplar}' verification process 600. According to some non-limiting embodiments, referring to FIG. 3, the network of computing devices 130 may verify if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message at step 610. When the first information is not verified to be a true information by the network of computing devices 130, the output interface of the network of computing devices 130 may inform the user that the local verification fails at step 620. For example, the output interface of the network of computing devices 130 may be configured to inform the user that a local verification fails when the first and second information are determined to be different by the network of computing devices 130. When the first information is verified to be a true information by the network of computing devices 130, the local verification is successful and the server 140 may further verify if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message, check if the nonce provided with the signed message by the first application is generated by the server 140, and check if the signed message is returned to the server within a predetermined time duration from the time stamp at step 630. When the first information is not verified to be a true information by the server 140, and / or the nonce is not generated by the server 140, and / or the signed message is not returned to the server within a predetermined time duration from the time stamp, the output interface of the network of computing devices 130 may inform the user that the remote verification fails at step 640. When the first information is verified to be a true information by the server 140, the nonce is generated by the server 140, and the signed message is returned to the server within a predetermined time duration from thetime stamp, the first account may be linked with the second account by the server 140 at step 650.

[0079] According to some non-limiting embodiments, the network of computing devices 130 may be configured to derive a public key from the second account signature in the signed message by the first application 110 and derive the second information from the public key by the first application 110.

[0080] An example of the signed message including the message and second account signature is provided as follows. In the following example of the signed message, ID may be an example of the identification associated with the first account. First wallet address may be an example of the first information associated with the second account received from the second application 120.

[0081] Example of signed messageWallet Owner VerifierID: RZRabcFirst wallet address: 0xa46A10BEal7c7A7c0313FflbD42d3A5cB2Ac27cENonce: 5834985385035894Time Stamp: 2024-04-24114:27:00.100Z second account signature:0x723055ec6787f4efb40e99616de4a7c2f27f4del7f881cd44bb2dcabf791b8c54f9977 b89ce22al9f675c4cacla266ela375023297753d9afc95eaf'517be0fd01c

[0082] An example of the public key derived from the second account signature in the above signed message by the first application 110 is provided as follows:Public Key:0x043al7a3cfddb6ba6c4d2dl6213f96d96fbdld06c24a66f40435284473935bl5b6c41 9fc3c63743956eabb3da3f1 daf41 d344e73bb 10de51 e7ebf71079cafcc931

[0083] An example of the second information (e.g., second wallet address) derived from the above public key by the first application 110 is provided as follows:Second wallet address:0xa46A10BEal7c7A7c0313FflbD42d3A5cB2Ac27cE

[0084] After a user has logged into the second account, the user may sign the message using the second account. According to some non-limiting embodiments, obtaining a second account signature upon a user signing a message using the second account may include the following steps:

[0085] Step 1.1: generate ephemeral key k from [1, N -1]. The ephemeral key k may be generated by a random number generator, such as a hardware based random number generator.

[0086] Step 1.2: calculate curve point R, where R= (xl, y 1) = k * G

[0087] Step 1 .3 : calculate r, where r = x 1 mod N, if r = 0, go to step 1 .1

[0088] Step 1.4: calculate s, where

[0089] Step 1.5: generate recovery byte vIf ((xl < N) && (yl parity is Even)) { v = 0;} else If ((xl < N) && (yl parity is Odd)) { v = 1;} else If ((xl > N) && (yl parity is Even)) { v = 2;} else If ((xl > N) && (yl parity is Odd)) { v = 3;}

[0090] Step 1.6 : return second account signature (r, s, v)The curve used herein may refer to the elliptic curve. The base point G used herein may refer to the elliptic curve base point, a point on the curve that generated a subgroup of large prime order n. The elliptic curve base point G may serve as the starting point for cryptographic operations, such as key generation and scalar multiplication. For the widely used secp256kl elliptic curve, which is used in cryptocurrencies such as Bitcoin and Ethereum, the base point is denoted as G, G is defined as G = (Gx, Gy), where Gx and Gy are the x and y coordinates of the base point, respectively. The precise coordinates of the base point G for the secp256kl curve arc defined by the standards. In hexadecimal representation,Gx=0x79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798,Gy=0x483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08F FB10D4B8,N used herein may refer to an integer order of G, where N *G = O, where O is the identity element. Point at infinity may serve as the identity element in the elliptic curve group, privk used herein may refer to a private key, pubk used herein may refer to public key, m used herein may refer to message to sign. The hash(m) used herein may refer to a hash value obtained from hashing a message. A cryptographic hash function may be used to hash a message to obtain a hash value of the message.

[0091] r, s,v may be obtained from the second account signature, c.g., by splitting the second account signature into r, s, v, as described herein.

[0092] According to some non-limiting embodiments, obtaining / deriving a public key from the second account signature in the signed message may include the following steps:

[0093] Step 2.1: verify if r and s are integers in [1, N - 1], if yes, the second account signature is valid; if not, the second account signature is invalid,

[0094] Step 2.2: verify if v is in the range [0, 1, 2, 3], if yes, the second account signature is valid; if not, the second account signature is invalid,

[0095] Step 2.3: calculate curve point R;}Prefix = 0x02;If (V& 1 == 1) Prefix = 0x03;Compressed_point = hex(prefix) + hex(r_adjust);The curve point R may be calculated from Compressed_point using an Elliptic Curve Calculator. The curve point R may be calculated from x co-ordinate with proper y parity. The y co-ordinate may be selected based on the y parity. For example, if parity bit is 0, select y co-ordinate with even number; if parity bit is 1, select y co-ordinate with odd number.

[0096] Step 2.4 : calculate r inverse (ir) using Equation (1) ir = readjust "1mod N (1)

[0097] Step 2.5 : calculate ul using Equation (2) u'l = (—has / ifrn) * ir) mod N (2)

[0098] Step 2.6 : calculate u2 using Equation (3) u2 - (s- * fr) mod. A (3)

[0099] Step 2.7 : calculate public key using Equation (4)

[0100] pubk - u2 * R * ul * G (4)

[0101] According to some non-limiting embodiments, the process of computing / deriving a second information (e.g., second wallet address) associated with the second account from the public key may include the following steps.

[0102] Step 4.1: convert public key from hex string to binary data to obtain a binary public key (i.c., public_kcy_bytcs);Public key input format may be: Ox <x point> <y point>

[0103] Step 4.2 : compute keccak256 hash of the binary public key (i.e., public_key_hash), where public_key_hash is obtained by ethers.keccak256(public_key_bytes).

[0104] Step 4.3 : obtain last 40 bytes from the keccak256 hash of the binary public key as the second information (e.g., second wallet address) associated with the second account,

[0105] Step 4.4 : obtain checksum address from the second information (e.g., second wallet address) associated with the second account, where checksum address is obtained by cthcrs.gctAddrcss(wallct address).

[0106] According to some non-limiting embodiments, the server 140 may be configured to receive the signed message from the network of computing devices 130, derive a public key from the second account signature in the signed message, and derive the second information from the public key. The server 140 may be configured to derive a public key from the second account signature in the signed message and derive the second information from the public key using the process described above. Deriving a public key from the second account signature in the signed message may include the steps of (i) splitting the second account signature into r,s,v sections as described herein; (ii) verifying if r and s sections are integers in [1, N - 1], if yes, the second account signature is valid; if not, the second account signature is invalid; (iii) verifying if v section is in the range [0, 1 , 2, 3], if yes, the second account signature is valid; if not, the second account signature is invalid; (iv) calculating curve point R based on Compressed_point which is calculated based on section r and section v; (v) calculating r inverse; (vi) calculating ul based on message and r inverse; (vii) calculating u2 using s and r inverse; (viii) calculating public key using u2, R, ul and base point G. Deriving the second information from the public key may include the steps of (i) converting public key from hex string to binary data to obtain a binary public key; (ii) computing keccak256 hash of the binary public key; (iii) obtaining last bytes (e.g. 40 bytes) from the keccak256 hash of the binary public key as the second information; and (iv) obtain checksum address from the second information.

[0107] An example of the signed message including the message and second account signature received from the network of computing devices 130 by the server 140 is provided as follows. Tn the following example of the signed message, ID may be an example of the identification associated with the first account. First wallet address may be an example of the first information associated with the second account received from the second application 120.

[0108] Example of signed message:Wallet Owner VerifierID: RZRabcFirst wallet address: 0xa46A10BEal7c7A7c0313FflbD42d3A5eB2Ac27eENonce: 5834985385035894Time Stamp: 2024-04-24T14:27:00.100Z second account signature:0x723055ec6787f4efb40e99616de4a7c2f27f4del7f881cd44bb2dcabf791b8c54f9977 b89ce22a 19f675c4cac 1 a266e 1 a375023297753d9afc95eaf517be0fd01c

[0109] An example of the public key derived by the server 140 from the second account signature in the above signed message is provided as follows:Public Key:0x043al 7a3cfddb6ba6c4d2dl62l3f96d96fbdld06c24a66f40435284473935bl5b6c41 9fc3c63743956eabb3da3fldaf41d344e73bbl0de51e7ebf71079cafcc931

[0110] An example of the second information (e.g., a second wallet address) derived from the above public key by the server 140 is provided as follows:Second wallet address:0xa46A10BEal7c7A7c0313FflbD42d3A5eB2Ac27eE

[0111] An example of the result that the linking of the first account with the second account is successful is provided as follows:ID : RZRabc is associated with wallet account :0xa46A10BEal7c7A7c0313FflbD42d3A5eB2Ac27eE

[0112] FIG. 4 and FIG. 5 show an example of a first graphical user interface (GUI) 132 and a second GUI 134 of the network of computing devices 130, respectively. According to some non-limiting embodiments, the network of computing devices 130 may be configured to create, by the first application 110, a message for the user to sign. Referring to FIG. 4, a first graphical user interface (GUI) 132 of the network of computing devices 130 may display the message for the user to sign and a button 10 labelled by “Sign a message”. The user may indicate that the user intends to sign a message by clicking the button 10 labelled by “Sign a message” displayed on the first GUI 132. After the user clicks the button 10, a second graphical user interface (GUI) 134 of the network of computing devices 130 may display the message for the user to sign, a button 22 labelled by “Reject” and a button 20 labelled by “Sign” (see FIG. 5). The user may sign the message by clicking the button 20. The user may reject to sign the message by clicking the button 22. The user may reject to sign the message when the user does not intend to link the first account with second account in the message. After the user sign the message by clicking the button 20, the first GUI 132 may display the second accountsignature that is generated upon the user signing the message and a button 30 labclicd by “Verify signature”. The user may indicate that the user intends to verify the signature by clicking the button 30. After the user clicks the button 30, the first GUI 132 may display the result that the linking of the first account with the second account is successful when the first account is linked with the second account. The first GUI 132 may display that the local verification fails when the first information is not verified to be a true information by the network of computing devices 130. The first GUI 132 may display that the remote verification fails when the first information is not verified to be a true information by the server 140, and / or the nonce is not generated by the server 140, and / or the signed message is not returned to the server within a predetermined time duration from the time stamp. The first GUI 132 may be included in the first application 1 10 and the second GUI 134 may be included in the second application 120. The graphical user interface (GUI) used herein may refer to a digital interface in which a user interacts with graphical components such as icons, buttons, and menus. In a GUI, the visuals displayed in the user interface may convey information relevant to the user, as well as actions that the user can take.

[0113] According to some non-limiting embodiments, the user may have more than one web2 account, e.g., a first account and a further first account. The linking system may be configured to link each of the first account and the further first account with a same second account using the method described herein. The user may log into the same second account (i.e., web3 wallet account) to sign a respective message (e.g., a message and a further message, respectively) for linking the second account with the first account and the further first account respectively. The message for linking the second account with the first account may include an identification associated with the first account, a nonce and a time stamp. The further message for linking the second account with the further first account may include an identification associated with the further first account which is different from the identification associated with the first account, a further nonce which is different from the nonce and a further time stamp which is different from the time stamp. The further message is therefore different from the message, thereby a further second account signature generated upon the user signing the further message using the second account is different from a second account signature generated upon the user signing the message using the second account. A further public key derived from the further second account signature may be the same as a public key derived from the second account signature. A further second information associated with the second account derived from the further public key may be the same as a second information associated with the second account derived from the public key.

[0114] According to some non-limiting embodiments, the user may have more than one web3 wallet account, e.g., a second account and a further second account. The linking system may be configured to link each of the second account and the further second account with a same first account using the method described herein. The user may log into the second account and the further second account to sign a respective message (e.g., a second message and a further second message, respectively) for linking the first account with the second account and the further second account respectively. The second message for linking the first account with the second account may include a first information associated with the second account, a nonce and a time stamp. The further second message for linking the first account with the further second account may include a first information associated with the further second account which i different from the first information associated with the second account, a further nonce which is different from the nonce in the second message, a further time stamp which is different from the time stamp in the second message. The further second message is therefore different from the second message. A further second account signature generated upon the user signing the further second message using the further second account is different from the second account signature generated upon the user signing the second message using the second account. A further second public key derived from the further second account signature obtained using the further second account is different from a second public key derived from the second account signature obtained using the second account. A further second information associated with the further second account derived from the further second public key is different from a second information associated with the second account derived from the second public key.

[0115] The present disclosure provides a method 800 for linking a first account of a user with a second account of the user by a linking system described above, the linking system comprising a network of computing devices where the first application and the second application are operated and a server that the network of computing devices is connected to. FIG. 6 is a flow chart depicting a method 800 for linking a first account of a user with a second account of the user according to some embodiments. The method 800 may include: i) a step 810 of receiving, by the first application, a first information associated with the second account from the second application; ii) a step 820 of generating, by the second application, a signed message comprising a message and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein themessage comprises an identification associated with the first account, and the first information associated with the second account; iii) a step 830 of verifying, by at least one of the network of computing devices and the server, if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message; iv) a step 840 of linking, by the server, the first account with the second account when the first information is verified to be a true information. rooii6] In order for a gamer (or referred to as the user) to show / read all the digital assets (e.g., non-fungible tokens (NFTs)) he owns and play web3 games easier, it is important to link / associate a first account (e.g., a web2 account) of the user with a second account (e.g., a web3 account) of the user. When the first account is linked with the second account, the user is able to read all the digital assets (e.g., NFTs) he owns in the second account without logging into the second account, after the user logs into the first account. Most of the time a gamer does not need to login the second account (e.g., wcb3 account), only when the gamer wants to initiate a new transaction, he needs to log in the second account (e.g., web3 account) and prove the transaction.

[0117] The linking / association of the first account with the second account help to improve user experience and wallet security.

[0118] The nonce may be generated randomly by the server 140, the server 140 can validate the nonce against database. This may help to prevent replay attacks. A replay attack occurs when an attacker is able to capture data-in-transit in cleartext form. Replay attacks may capture various forms of authentication data, such as passwords, session tokens, or cryptographic authentication hashes.

[0119] The time stamp may be used to measure a time taken for the signing process. This may help to eliminate a lot of time-consuming attacks.

[0120] While the disclosure has been particularly shown and described with reference to specific embodiments, it should be understood by those skilled in the art that various changes in form and detail may be made therein without departing from the spirit and scope of the disclosure as defined by the appended claims. The scope of the disclosure is thus indicated by the appended claims and all changes which come within the meaning and range of equivalency of the claims are therefore intended to be embraced.

Claims

CLAIMS1. A method for linking a first account of a user with a second account of the user by a linking system comprising a network of computing devices where a first application and a second application are operated and a server that the network of computing devices is connected to, the method comprising: receiving, by the first application, a first information associated with the second account from the second application; generating, by the second application, a signed message comprising a message and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein the message comprises an identification associated with the first account, and the first information associated with the second account; verifying, by at least one of the network of computing devices and the server, if the first information associated with the second account is a true information based on a second information associated with the second account derived from the second account signature in the signed message; and linking, by the server, the first account with the second account when the first information is verified to be a true information.

2. The method of claim 1, wherein the first information is verified to be a true information when the second information is the same as the first information.

3. The method of claim 1, further comprising: obtaining, by the first application, prior to generating the signed message by the second application, at least one server parameter from the server by sending the first information associated with the second account to the server; wherein the message further comprises the at least one server parameter, wherein the at least one server parameter comprises a nonce and a time stamp, wherein the linking of the first account with the second account occurs when(i) the second information is the same as the first information,(ii) the nonce in the signed message is generated by the server, and(iii) the signed message is returned to the server within a predetermined time duration from the time stamp.

4. The method of claim 3, wherein the identification associated with the first account and a first account signature signed using a private key of the first account are sent to the server by the first application for obtaining the at least one server parameter from the server.

5. The method of claim 1, further comprising: checking, by the first application, whether the first account is linked with the second account; and requesting, by the first application, the first information associated with the second account from the second application when the first account is unlinked with the second account.

6. The method of claim 1, further comprising creating, by the first application, the message for the user to sign.

7. The method of claim 1, further comprising: generating a public key from the second account signature in the signed message by the first application; and deriving the second information from the public key by the first application.

8. The method of claim 1 , further comprising: receiving the signed message from the network of computing devices by the server; generating a public key from the second account signature in the signed message by the server; and deriving the second information from the public key by the server.

9. The method of claim 1, further comprising informing the user, by an output interface of the network of computing devices, that a local verification fails when the first and second information arc determined to be different by the network of computing devices.

10. The method of claim 1, further comprising storing, by the server, the linking of the first account with the second account in a database.

11. The method of claim 1, further comprising informing the user, by an output interface of the network of computing devices, that the linking is successful when the first account is linked with the second account.

12. The method of claim 1, wherein the second account is a web3 wallet account.

13. The method of claim 1, wherein the first account is a web2 account managed by a centralized server.

14. A linking system for linking a first account of a user with a second account of the user, the linking system comprising: a network of computing devices where a first application and a second application are operated; and a server that the network of computing devices is connected to, wherein the network of computing devices is configured to: - receive, by the first application, a first information associated with the second account from the second application; generate, by the second application, a signed message comprising a message and a second account signature, wherein the second account signature is generated upon the user signing the message using the second account, wherein the message comprises an identification associated with the first account and the first information associated with the second account, wherein the at least one of the network of computing devices and the server is configured to verify if the first information associated with the second account is a tine information based on a second information associated with the second account derived from the second account signature in the signed message, wherein the server is configured to link the first account with the second account when the first information is verified to be a true information.

15. The linking system of claim 14, wherein the first information is verified to be a true information when the second information is the same as the first information.

16. The linking system of claim 14, wherein the network of computing devices is configured to obtain, by the first application, prior to generating the signed message by the secondapplication, at least one server parameter from the server by sending the first information associated with the second account to the server. wherein the message further comprises the at least one server parameter, wherein the at least one server parameter comprises a nonce and a time stamp, wherein the linking of the first account with the second account occurs when(i) the second information is the same as the first information,(ii) the nonce in the signed message is generated by the server, and(iii) the signed message is returned to the server within a predetermined time duration from the time stamp.

17. The linking system of claim 16, wherein the identification associated with the first account and a first account signature signed using a private key of the first account are sent to the server by the first application for obtaining the at least one server parameter from the server.

18. The linking system of claim 14, wherein the network of computing devices is configured to: - check, by the first application, whether the first account is linked with the second account; and request, by the first application, the first information associated with the second account from the second application when the first account is unlinked with the second account.

19. The linking system of claim 14, wherein the network of computing devices is configured to create, by the first application, the message for the user to sign.

20. The linking system of claim 14, wherein the network of computing devices is configured to: - generate a public key from the second account signature in the signed message by the first application; and derive the second information from the public key by the first application.

21. The linking system of claim 14, wherein the server is configured to: - receive the signed message from the network of computing devices;generate a public key from the second account signature in the signed message; and derive the second information from the public key.

22. The linking system of claim 14, wherein the second account is a web3 wallet account.

23. The linking system of claim 14, wherein the first account is a web2 account managed by a centralized server.

Citation Information

Patent Citations

  • Cross chain access granting to applications

    US20230421399A1