Licensing the Lokblok patent. Build on the method, under licence.
Phantom Secrets™ is protected by US Patent 12,438,716 B2 (issued 7 October 2025). If you want to implement the method in your own product, under your own brand, with your own engineering - that is a licence, and we would rather have the conversation early than late.
Most companies discover a patent at the worst possible moment - in a diligence questionnaire, in a customer's security review, or in a letter. We would rather you found it here, at the point where it is still a design decision.
Lokblok is an operating company. We build products on this method, we ship them, and they are in live deployment. The patent exists to protect that work, not to fund a litigation practice. So the offer on this page is simple and it is genuinely open: if the method is useful to you, licence it and build your own version.
You keep your architecture, your roadmap, your brand and your customer relationships. What you get from us is the right to practise the method, the assumption list that tells your cryptographers exactly what they are relying on, and a named counterparty who has already made every mistake there is to make in implementing it.
THE METHOD
Non-custodial enrolment and recovery of a secret
The patent's own title is the clearest description of it. The method lets a secret be enrolled and later brought back into existence without any party ever holding it, or a piece of it, at rest between operations. In outline:
01
Recovery agents are named
A set of recovery agents is identified, each holding their own Recovery Agent Credential - a persistent key pair on their own device. These credentials are not copies, fragments or backups of the secret being protected. They authorise their holder to take part in bringing it back.
02
The secret is cryptographically transformed
Private evaluation coordinates are derived as a function of the agents' public keys, a public nonce and an enrolment key. The secret is enrolled against those coordinates under a k-of-n threshold construction.
03
Only public values remain
What survives enrolment is a set of public values - Regen Tokens. They are cryptographically inert. They can live anywhere, including a public ledger. The private coordinates and the original secret are destroyed on-device.
04
Reconstruction is recomputation, not retrieval
When the required participants and policy conditions are satisfied, each approving agent's device regenerates its own private coordinate, the secret is recomputed on the owner's device for the operation, and it is destroyed again. Nothing is unsealed, decrypted or fetched from storage, because nothing was stored.
The Protected Key - the signing key, API key or credential - never exists at rest between operations. The stored-secret attack surface is eliminated.
Scope, stated precisely. This applies to the Protected Key being phantomised, not to all state everywhere. Participants hold their own device keys and recovery agents hold their Recovery Agent Credentials, sealed in hardware on their own devices. That is by design, and any implementation you build will have the same property.
One grant. Several applications. No implication beyond that.
Patent status is the one thing on a page like this that a reader will check in three minutes, so here it is at the level of detail that survives checking.
Status
US 12,438,716 B2 - “Non-custodial enrolment and recovery of a secret”
Granted, 7 October 2025. Assignee Lokblok Inc. Filed 31 May 2023; priority 31 May 2022.
Australia, Brazil, China, the European Union, Hong Kong, India, the United Arab Emirates
Applications pending. National-phase entries from the PCT. Pending means pending - none of these is granted, and we do not treat them as though they are.
Distributed-entropy method
Patent pending. Separate filing, separate status.
The enforceable right today is the US grant, and it is a method claim, which carries the territorial limits that method claims carry. We say that here because a counsel will work it out in the first meeting anyway, and a vendor who has already said it is a vendor who is not managing them.
Nominal term runs to 2043 on the twenty-year term from the 2023 filing date, subject to term adjustment and maintenance.
Patent status as at September 2026. Provided for evaluation, not as legal advice - your own counsel should form their own view.
SELF-ASSESSMENT
Two lists, and the second one matters as much as the first
A licence is worth discussing if your system does most of these things at once. Any one of them alone is ordinary prior art and nobody's property.
Worth a conversation
A secret is enrolled once and then does not exist at rest between uses
Recovery depends on a threshold of named agents, each holding their own persistent credential rather than a stored piece of the secret
The values you retain and synchronise are public and inert on their own
Reconstruction recomputes the secret rather than decrypting or retrieving it
The coordinates used in the threshold construction are derived from participant public keys rather than being random and stored
Agents can approve at different times, without being online together
Probably not this patent
Conventional Shamir secret sharing where the pieces are stored, wherever they are stored
MPC and threshold signature schemes that never assemble a key at all - a different construction solving a different problem
Key wrapping, envelope encryption, or an HSM that holds a key and gates access to it
Passkeys, WebAuthn and FIDO2 as specified
Social recovery where guardians hold stored material
Backup and escrow, however well encrypted
Anything you were demonstrably practising before 31 May 2022
Whether a specific implementation reads on a specific claim is a question for your counsel and ours, not for a web page. What this page can honestly offer is the shape of the thing, so you can decide in an afternoon whether the call is worth booking.
THE GRANT
The right to practise it, and the things that make practising it survivable
01
The right itself
A licence to practise the claimed method in your own product, within an agreed field of use. Your implementation, your codebase, your release schedule. We do not review your code, gate your roadmap or take a position in your stack.
02
The assumption list
The construction rests on a new, construction-specific security assumption - the Hidden Coordinate Assumption - rather than a reduction to a long-studied problem. Licensees get that assumption list in writing, named and unhedged, along with the constructions where it bites hardest. Your cryptographers will find it in an afternoon whether we hand it over or not. Handing it over is how the afternoon ends well.
03
The right to say so
Licensees may state that their implementation is licensed under US Patent 12,438,716 B2. In a customer security review, that line is worth having. Where a licensee wants a visible trust mark rather than a footnote, the “Shielded by Lokblok” endorsement route exists as a separate agreement.
04
An upgrade path
If, six months in, you would rather not maintain a cryptographic implementation at all, the licence converts. The Wallet SDK, Toughkey™ hardware and the rest of the platform are available to licensees on the same commercial relationship rather than a new one.
THE HONEST PART
A licence is a right, not a product
We would rather lose the deal here than in month four. A patent licence gives you permission. It does not give you any of the following, and none of them is included by implication.
No implementation. No source, no reference code, no SDK. You are building it. Licensees who want built software want a different agreement, and it exists.
No hardware. Toughkey™ and the secure-element supply chain are separate. Where any Lokblok product refers to hardware certification: Lokblok uses a FIPS 140-3 Level 3 and Common Criteria EAL6+ certified security chip - that certification is the chip's, and it does not transfer to your build.
No security assurance for your implementation. The method being sound says nothing about whether you have implemented it soundly. Derivation quality, destruction of intermediate values, device attestation and policy enforcement are all yours to get right, and all of them are places where a correct method becomes an incorrect product.
No certification. No certification, listing or audit finding of ours attaches to your build.
No freedom-to-operate opinion. A licence under our patent is a licence under ours. It says nothing about anyone else's.
No exclusivity by default. Licences are non-exclusive unless exclusivity is separately agreed and separately priced.
No claim you may repeat. Licensees may state the licence. Licensees may not describe their product using Lokblok's own product claims, or as being secured, verified or endorsed by Lokblok.
STRUCTURES WE WORK WITH
Four shapes, and the fourth is the one most people need
01
Non-exclusive, field-of-use
The default and the fastest. You practise the method within a defined application area. Others may license the same method for theirs.
02
Exclusive within a field or territory
Available where a licensee is making a category-defining commitment and wants the field closed behind them. Exclusivity is priced as exclusivity and carries performance conditions - an exclusive licence that sits unused helps neither of us.
03
Platform and sublicensing
For infrastructure vendors whose own customers would be practising the method downstream - HSM manufacturers, wallet infrastructure providers, identity platforms. The licence runs to your customers through you.
04
Evaluation
A short, low-friction, time-boxed right to build and test an implementation before committing to anything. Most conversations should start here, and most do.
Commercial terms are set per licence, not published. They are shaped by the field of use, whether exclusivity is involved, whether sublicensing runs downstream, and the term. We will talk about structure openly on the first call and put numbers in writing after the second, once we both understand what is actually being built.
OTHER ROUTES
Some companies want the capability, not the right to build it
You want it working next quarter, not next year. The Wallet SDK on Windows, Android, macOS and iOS gives you the capability without the cryptographic build. → Products
You want it under your own brand. White-label and co-branded arrangements exist, including the “Shielded by Lokblok” trust mark. → Partner portal
You are evaluating whether the architecture holds up at all. Start with the architecture page and its four stated trust assumptions, then talk to our engineers. → Architecture
THE PROCESS
Four steps, and you can stop after any of them
01
A scoping call, mutual NDA
Forty-five minutes. You describe what you are building; we tell you plainly whether we think it comes near the claims. Some of these calls end with us saying it does not. That is a good outcome and it costs you a Tuesday afternoon.
02
Claim mapping
Our counsel and yours map the granted claims against your architecture. You get a written view of where the overlap is and where it is not. This is where most of the real work happens.
03
Term sheet
Field of use, exclusivity or not, sublicensing or not, term, and the commercial structure. Short document, plain terms.
04
Licence and assumption pack
Execution, and the assumption list and supporting technical material go to your engineering team. From that point you are building, and we are available but not in the way.
PRIOR ART
Tell us. Genuinely.
The priority date is 31 May 2022. If you were practising something within the claims before then, or you know of art we have not seen, we want to hear about it - and we would rather hear it from you in a scoping call than from a tribunal.
We do not think this is a common situation, or the patent would not have granted. But an operating company that only wants to hear confirming evidence about its own IP is one that eventually finds out expensively. Send it to info@lokblok.co and we will look at it properly.
BEFORE YOU ASK
The questions that come up every time
Are you a patent troll?
No, and the check is easy. Lokblok builds and ships products on this method - Phantom Secrets™, Phantom Gate™, Toughkey™, ToughID™, Secure Terminal™ - and there are live deployments running on them. The patent protects an operating business. Licensing exists because we would rather have companies building on the method than around it.
Can we design around it?
Possibly. The claims are public, your engineers can read them, and design-around is a legitimate thing to attempt. What a licence gives you instead is certainty, the named assumption list, the attribution right and an upgrade path - and it removes an item from every diligence questionnaire and customer security review you will face for the next fifteen years. Some companies will still design around, and we would rather they did that with their eyes open than discover the question later.
Do we need a licence if we only operate outside the United States?
That is a question for your counsel, and the answer depends on where the method is practised and where your product is made available. What we can say plainly is what the status section says: the grant is US, the other filings are applications, and we do not present pending applications as granted rights.
Is the patent the whole moat?
No, and a page that claimed it was would be overselling. The patent is a granted method claim. The rest of it is the years of implementation experience that sit between the claims and a product that actually works - derivation quality, destruction discipline, attestation, policy enforcement, hardware integration. That is why the licence includes the assumption list, and why the upgrade path exists.
Does a licence make our product secure?
No. It makes your implementation licensed. Whether it is secure depends entirely on how you build it, and the section on what a licence does not give you is not boilerplate - it is the part of this page we most want you to have read.
What about post-quantum?
The construction is designed to accept the NIST post-quantum KEMs, and adopts them without changing the construction once certified secure elements supporting them ship. Today's ECDH configuration is not quantum-resistant. The honest description is post-quantum-ready, not post-quantum.
Which blockchains does it work with?
Phantom Secrets is blockchain agnostic. Chain support is a property of the wallet or custody software you build on top, not of the method. So long as your software logic supports a chain, the method does not stand in the way.
How long does a licence take to agree?
The scoping call happens within a week of asking. Claim mapping is typically two to four weeks depending on how quickly counsel on both sides can move. Straightforward non-exclusive licences have gone from first call to signature inside a quarter; exclusive and sublicensing arrangements take longer, because they should.
START HERE
Start with the call that might end in "no"
Forty-five minutes under NDA, with an engineer and someone who can make a commercial decision in the room. If what you are building does not come near the claims, we will tell you so and you will have lost an afternoon.