System and method for signing transactions using air-gapped private keys

By designing a system including the first module, the second module and the bridge module, the labor-intensive problem of information transmission between the air gap computer and the remote entity and the equipment independence problem are solved, and the effect of convenient and safe signing of transactions on the virtual air gap is achieved.

CN112470159BActive Publication Date: 2025-05-13BITFORD CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN201980048828.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-07-21
Filing Date
2019-07-12
Publication Date
2025-05-13
Estimated Expiration
2039-07-12

AI Technical Summary

Technical Problem

The prior art is labor-intensive when transmitting information between an air gap computer and a remote entity, and requires two independent devices for operation and maintenance, which is inconvenient to use, especially in electronic wallet applications.

Method used

A system is designed, the system including a first module, a second module and a bridge module. The first module is connected to the public network, processes transaction requests and passes them to the second module. The second module is responsible for transaction authorization and signing, generating and storing private keys through a random number generator and a security controller, and signing transactions using the private keys. The bridge module selectively connects the first module and the second module through a switch to ensure that information is transmitted without connecting to the public network.

Benefits of technology

It realizes convenient signing of transactions on virtual air gaps without the need for two independent devices, improving the convenience and security of electronic wallets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112470159B_ABST
    Figure CN112470159B_ABST
Patent Text Reader

Abstract

A system for signing transactions. The system includes a first module having: a communication interface with a public network; a controller configured to process transactions with a blockchain network or a transaction server accessible on the public network. The system also includes a second module having: a random number generator; a security controller for generating seed words and private keys. The system also includes a bridge module having: a controller; and a switch for selectively connecting the data interface of the bridge module to the data interface of the first module or the data interface of the second module, so that the data interface of the first module is never connected to the data interface of the second module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to systems and methods for signing transactions. In particular, from a user's perspective, the present disclosure relates to a convenient method for forming an air gap in an electronic device when managing digitized assets such as cryptocurrency or content stored on a blockchain (or similar system). Background Art

[0002] "Air Gapping" is a known procedure that involves making a computing machine without any network connection, or at least without connecting to a public network, such as the Internet. In other words, air gaps, air walls, or air gapping are network security measures taken on one or more computers to ensure that a secure computer network is physically isolated from an unsecured network, such as the public Internet or an unsecured LAN.

[0003] As a result, an air-gapped computing machine is a closed system (in terms of information, signals, etc.) that is inaccessible to remote entities and can only be manually operated by a user (operator).

[0004] A disadvantage of forming an air gap is that transferring information between an air-gapped computing machine and a remote entity is labor intensive, typically involving manual security analysis of the intended software application or data to be entered onto the air-gapped machine, and possibly even manual re-entry of the data after the security analysis.

[0005] Furthermore, air-gapped machines are typically completely separate hardware systems that require operation and maintenance of two systems, which is inconvenient, particularly in the case of so-called electronic wallets, where a user must carry a separate air-gapped transaction signing device in addition to an electronic device or computer program that functions as a wallet (e.g., a code-generating token that lacks network connectivity, or a secure cold storage hardware wallet that stores private keys that allow access to blockchain-stored content or spending of digitized assets, such as cryptocurrencies).

[0006] US Patent No. 8984275B2 entitled "Virtual air gap - VAG system" discloses a system including a virtual air gap, an internal safety component, an external safety component, a message transmission mechanism for system components between the internal and external safety components, and a shared memory. The internal system is composed of the internal safety component and other components included in the system that connects the internal safety component to the internal network. The external system is composed of the external safety component and other components included in the system that connects the external safety component to the external network.

[0007] In view of the above, there is a need to design a system that is particularly useful for electronic wallet applications that will not require two separate devices and will be more convenient to use. There is also a need to provide an improved system and method for signing transactions over a virtual air gap. Summary of the invention

[0008] The present invention relates to a system for signing transactions. The system includes a first module, which includes: a communication interface to a public network; a controller configured to process transactions with a blockchain network or a transaction server accessible on the public network; and a data interface for communicating with the controller. The system also includes a second module, which includes: a random number generator for generating a random sequence; a security controller configured to generate a seed word and a private key based on the random sequence generated by the random number generator, and store the seed word and the private key, and sign a transaction request by generating a signed transaction; and a data interface for communicating with the security controller. The system also includes a bridge module, which includes: a controller; a data interface for communicating with the controller; and a switch, which is configured to selectively connect the data interface of the bridge module to the data interface of the first module or the data interface of the second module, so that the data interface of the first module is never connected to the data interface of the second module. The controller is configured to receive a transaction request from the first module, pass the transaction request to the second module, receive a signed transaction from the second module and pass the signed transaction to the first module.

[0009] The switch may be a single pole double throw (SPDT) switch.

[0010] The security controller of the second module may also be configured to store biometric data.

[0011] The second module may include a biometric sensor configured to convert a biometric trace of a person into an electrical signal for transaction authorization.

[0012] The switch may also be configured to supply power to the second module only when the data interface of the bridge module is connected to the data interface of the second module.

[0013] The system may further include an erase module configured to call an erase function at the second module to delete the stored seed words and private keys, and erase all transaction and financial data from the first module.

[0014] The second module may be integrated with the bridge module in a common housing.

[0015] The first module may be integrated with the second module and the bridge module in a common housing.

[0016] The data interface of the second module may include an input data buffer and an output data buffer.

[0017] The random number generator of the second module may be a hardware entropy generator.

[0018] The random number generator of the second module may be a software entropy generator.

[0019] The present invention also relates to a method for signing a transaction, the method using the system for signing a transaction described herein to sign a transaction. The method comprises the following steps: connecting the first module to the public network; establishing transaction details; receiving an acceptance that the transaction is to be authorized; sending the transaction request to the bridge module; disconnecting the first module from the bridge module; connecting the bridge module to the second module; sending the transaction request from the bridge module to the second module; authorizing the transaction through the second module; signing the transaction using the private key stored in the second module to generate a signed transaction; sending the signed transaction from the second module to the bridge module; disconnecting the second module from the bridge module; connecting the first module to the bridge module; sending the signed transaction from the bridge module to the first module; and sending the signed transaction from the first module to the blockchain network or to the transaction server.

[0020] The method may further include, when the user does not authorize a transaction during a predefined number of consecutive attempts at the second module, invoking an erase function at the second module to delete the stored seed words and private key and erase all transaction and financial data from the first module. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] These and other objects set forth herein are achieved by providing a system and method for signing transactions over a virtual air gap using an air gap private key. Further details and features of the present disclosure, its nature and various advantages will become more apparent from the following detailed description of preferred embodiments illustrated in the accompanying drawings, in which:

[0022] Figure 1 A schematic diagram showing a first module of the Internet connection of the system proposed herein;

[0023] Figure 2 A schematic diagram showing a second module of the system proposed in this paper;

[0024] Figure 3 A bridge module operating between a first module and a second module is shown;

[0025] Figure 4 An overview of a system including a first module, a second module and a bridge is shown;

[0026] Figure 5 Shows the configuration Figure 4 a systematic process; and

[0027] Figure 6 A method of transaction authentication is shown.

[0028] Symbols and terminology

[0029] Some portions of the detailed descriptions that follow are presented in terms of data processing flows, steps, or other symbolic representations of operations on data bits that can be performed on a computer memory. Accordingly, the computer performs such logical steps, which in turn require physical manipulations of physical quantities.

[0030] Typically, these quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, and otherwise manipulated in a computer system. Due to common usage, these signals are referred to as bits, packets, messages, values, elements, symbols, characters, terms, numbers, or the like.

[0031] Additionally, all of these and similar terms will be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. Terms such as "process" or "create" or "transmit" or "execute" or "determine" or "detect" or "obtain" or "select" or "compute" or "generate" refer to the actions and processes of a computer system that manipulates data represented as physical (electronic) quantities in computer registers and memories and transforms it into other data similarly represented as physical quantities in memories or registers or other such information storage devices.

[0032] Computer-readable (storage) media referred to herein may generally be and / or include non-transient devices. In this context, non-transient storage media may include devices that may be tangible, meaning that the device has a specific physical form, although the device may change its physical state. Thus, for example, non-transient refers to a device that remains tangible despite changes in state.

[0033] As used herein, the term "example" means serving as a non-limiting example, instance or illustration. As used herein, the terms "for example" and "such as" introduce one or more non-limiting examples, instances or illustrations. DETAILED DESCRIPTION

[0034] The system proposed in this paper has the following features: Figure 4The general structure shown can be specifically configured to provide efficient, convenient and fast real-time payments using cryptocurrencies (electronic wallets for cryptocurrencies), or can be configured to sign, upload or access content stored on a distributed leader based on blockchain (or similar systems), such as without the need for external devices to sign transactions while providing security measures typical of air-gapped machines.

[0035] The system is particularly suitable for cryptocurrencies, but can also be used in electronic wallets for ordinary currencies (such as euros, dollars), especially when marked as a blockchain-based ledger or similar system.

[0036] The system may be implemented using dedicated components or custom FPGA (field programmable gate array) or ASIC (application specific integrated circuit) circuits.

[0037] Figure 1 A schematic diagram of a first module 100 of the system is shown, which is connected to the Internet (or generally, any public network). The first module 100 is responsible for communication with any external service related to processing payments or transactions using cryptocurrencies or other services based on blockchain (or similar systems). In other words, it is a communication module.

[0038] The first module 100 includes a data bus 101 communicatively coupled to a flash memory 104. In addition, other components of the system are communicatively coupled to the data bus 101 so that they can be efficiently managed by a controller 105.

[0039] The flash memory 104 may store one or more computer programs executed by the controller 105 in order to perform the steps of the method described below. In addition, the flash memory 104 may store configuration parameters of the first module 100 .

[0040] The communication interface module(s) 102 (eg, Wi-Fi, GSM, 3G, LTE, NFC, etc.) are configured to manage communications with external public networks. The communication module 102 may have a dedicated on / off switch so that the user can personally control its operation.

[0041] The controller 105 can be a system-on-chip, which includes: a graphics processing unit (GPU) 105A, which is a dedicated electronic circuit designed to quickly manipulate and change memory to accelerate the creation of images in a frame buffer, which are intended to be output to a display device; a random access memory (RAM) 105B, a central processing unit (CPU) 105C, which is an electronic circuit within a computer that executes instructions of a computer program by performing basic arithmetic, logic, control, and input / output (I / O) operations specified by the instructions; a data interface 105D, which is responsible for sending data to other components of the first module 100 and / or receiving data from other components of the first module 100.

[0042] Typically, the first module 100 is configured to establish communication with a remote server (e.g., a server of an electronic service provider), an electronic banking system, or a distributed leadership and network based on blockchain (or similar systems) via a communication interface 102 to allow users to establish transactions that are securely confirmed once the transaction is ready.

[0043] Optionally, the first module may include a camera 103 configured to obtain and process an image, such as an image of a QR code that may be used as a container for specifying transaction data, so that the user does not have to manually insert or otherwise define specific variables for the transaction. The camera 103 may have a dedicated on / off switch so that the user can personally control its operation.

[0044] Data may be transmitted in encrypted form between the modules 100 and 300 via I2C (Inter-Integrated Circuit) or SPI (Serial Peripheral Interface) or another proprietary interface through a data interface 106 allowing access to the data bus 101 .

[0045] The first module 100 may be implemented by creating a dedicated device. Alternatively, the components of the first module 100 may be implemented by adapting a typical smart phone or similar device to configure its modules to operate as described above.

[0046] Figure 2 A schematic diagram of a second module 200 of the system proposed herein is shown. The second module 200 is responsible for transaction authorization and is never connected to a public network (such as the Internet, or even to any network).

[0047] The system includes a data bus 201 communicatively coupled to a ROM memory 202, which stores an operating system of the second module 200 (not easily modifiable because stored in ROM) and optionally an authorization key for verifying the authenticity of the software in the bridge module 300, for example to prevent hacker attack attempts based on modification of the software of the bridge module 300. In addition, other components of the system are communicatively coupled to the data bus 201 so that they can be managed by a security controller 205.

[0048] The second module 200 may also include (as an option) a biometric sensor 203 configured to convert a person's biometric trace into an electrical signal. The biometric trace mainly includes biometric fingerprint data, iris data, face image, voice sample, etc. These data can be used as an additional transaction authorization mechanism.

[0049] The random number generator 204 is a true random number generator, which is configured to generate a statistically random sequence of random numbers, i.e., without any characteristics and distinguishable features, and without a generation scheme. These random sequences are used to encrypt data and generate seed words (dictionary words) used for the generation of private keys. Preferably, the random number generator 204 is a hardware entropy generator. Random numbers can also be generated by a computer program instead of a separate chip (i.e., a software entropy generator).

[0050] The security controller 205 is configured to manage the components of the second module 200, in particular to authorize secure transactions. The security controller 205 includes a processor 205A, a flash memory 205B and an operating RAM memory 205C. It stores private keys and biometric data, i.e., all the elements required to authorize secure transactions. The private key may be encrypted, wherein the decryption of the private key requires biometric authentication using reference biometric data stored in the flash memory 205B and biometric data read from a biometric sensor such as the biometric sensor 203. The data interface 205D is responsible for sending data to and / or receiving data from other components of the second module 200.

[0051] Data may be transferred between the modules 200 and 300 via a data interface, preferably in the form of data buffers 206, 207, which are configured to communicate with an interface 309 of the bridge module 300 via a SPDT switch 310. The input buffer 206 is accessible by the second module to read data therefrom and is accessible by the bridge module to store data therein. The output buffer 207 is accessible by the second module to store data therein and is accessible by the bridge module to read data therefrom. Each of the data buffers 206, 207 may include its own internal processing unit, flash memory and a data interface for handling communications with the data bus 201 and the safety controller 205 and with the data interface 309 of the bridge module 300 via the SPDT switch 310.

[0052] The second module 200 can be implemented using dedicated components or customized FPGA or ASIC circuits. The second module 200 and the bridge module 300 are preferably integrated in a common housing to form a dedicated device that can be connected to the first module (only via the bridge module) via an external interface (e.g., a USB interface) (in this case, the first module functionality can be provided by an application installed on a general-purpose device such as a smartphone or laptop). Alternatively, all modules 100, 200, 300 can be integrated in a common housing to form a fully functional device.

[0053] Figure 3 A bridge module 300 is shown operating between the first module 100 and the second module 200. The purpose of the bridge module 300 is to formulate and pass transaction requests from the first module 100 to the second module 200, and to receive signed transactions or rejections of transactions.

[0054] The bridge module 300 integrated with the second module 200 may be implemented using dedicated components or custom FPGA or ASIC circuits. The modules 200, 300 may constitute additional modules connectable to the first module 100 or may be integrated with the first module 100.

[0055] The bridge module 300 includes a data bus 301 communicatively coupled to a memory 303. Additionally, other components of the system are communicatively coupled to the data bus 301 so that they can be managed by a controller 305.

[0056] Data may be transferred at a given time between the first module 100 and the bridge 300 or between the second module 200 and the bridge 300. For maximum safety, the system is configured so that it is not possible to have all three modules 100, 200, 300 active at the same time at any one time, by using a SPDT switch 310 that controls data transfer and optionally also controls power.

[0057] Controller 305 may be a system on a chip that includes the same or similar subcomponents as controller 105 .

[0058] The on / off switch 304 is configured to switch the device on or off when operated by a user.Other typical components include a display 306, which is preferably a touch sensitive display, and a speaker 302 which forms a means for communicating with a user.

[0059] The bridge module 300 is preferably powered by a battery 307, as it is intended to operate as a mobile device. Typical battery charging means, such as wireless charging (e.g. according to the Qi standard) as well as a typical plug charger connection, may also be present in the power supply 307 of the bridge module 300. A BMS (Battery Management System) module 308 is configured to manage battery charging, discharging and overall operation in order to maintain a long life of the battery.

[0060] The bridge module 300 comprises a data interface 309 configured to communicate with the interface 106 of the first module 100 or with the data buffers 206 , 207 of the second module 200 via a SPDT switch 310 .

[0061] The SPDT (Single Pole Double Throw) switch module 310 is configured to provide power and data transmission capability to only one of the modules at a time, either to the first module 100 or to the second module 200. The module 310 may include two SPDT switches, one for power and the other for data transmission, which are always switched together by a single actuator. By completely disconnecting the first module or at least its communication interface(s) 102 from the power supply via a hardware switch, an additional level of security from intruders or malware is provided, since intruders or malware cannot access the second module and cannot possibly tamper with the transaction request to be signed by the second module.

[0062] Other types of switch modules may be used instead of the SPDT switch as long as they provide the function that the data interface 106 of the first module 100 is never connected to the data interfaces 206 , 207 of the second module 200 .

[0063] Figure 4 An overview of a system comprising a first module 100, a second module 200 and a bridge module 300 is shown, wherein the bridge module 300 is selectively connected to the first module 100 or the second module 200 at any given time via a SPDT switch 310. The SPDT switch 310 controls the transmission of data and the supply of power (at least to the second module).

[0064] The wipe module 401 may also optionally be present in the system and configured to immediately invoke the "wipe device" function for security reasons. Once the wipe module 401 is activated, the second module is activated and a command is sent to the second module to delete the private key, seed words and biometric data from it so that it can be restored to its factory settings without personalized data. Next, the first module is activated and the transaction history, contact addresses and any other address or financial data are removed. The wipe module 401 can be in the form of a dedicated "panic button". Alternatively, the wipe module 401 can be activated by the user pressing a specific sequence of other buttons.

[0065] Therefore, the system 400 is able to solve the transaction security problem by being divided into at least three modules: a first module 100, a second module 200 and a bridge module 300, the bridge module 300 allowing information to be transferred between the module 100 and the module 200 and allowing them to operate independently of each other. The second module 200 is configured to authorize and sign transactions using a private key (specifically by providing a password or PIN code or biometric data, etc.) when never connected to a public network (such as the Internet).

[0066] In particular, the second module 200 is never connected to the public network, since the bridge module 300 can be connected to either the first module 100 or the second module 200 in any given situation. Therefore, it is not possible for a remote entity (a hacker or machine operating spyware) to capture authorized data from the device proposed herein. The first module 100 also does not have any form of access to the data and content of the second module 200.

[0067] Figure 5The configuration process of the system 400 is shown. In step 501, when the first module is turned off, the system 400 remains disconnected from the public network. Next, in step 502, a method for authenticating the user is selected, such as a PIN, password, biometric scan, etc. The parameters of the authentication and the related response are stored in the security controller 205 of the second module 200. Subsequently, in step 503, a keyword (seed) sequence is generated according to known methods, in particular methods related to processing deterministic wallets for cryptocurrency. The seed can be used to restore access to the device when the private key has been reset. For example, the second module 200 may include a dictionary in the ROM memory 202, for example according to the BIP-39 standard, which allows the keyword sequence to be generated in a random manner. The keyword sequence may include up to 24 or 36 keywords, which mitigates the risk of two devices having the same random keyword sequence. Next, in step 504, a private key or key set is generated based on the seed. (Multiple) private keys and keyword sequences are stored 505 in the flash memory of the security controller 205 of the second module 200, which can be additionally encrypted using a password, PIN or biometric trace to ensure an increased security level for the device. In execution Figure 5 After the process, the system 400 can configure and start the connection of the first module 100 and the communication module 102 with an external public network such as the Internet.

[0068] Figure 6 A method for transaction authentication using the device proposed herein is shown. First, the second module 200 is switched on in step 601, and in step 602, the user authorizes access to the device by entering a password, PIN or biometric data to allow further access to the device. If the password entered is approved, the second module 200 is switched off and the first module 100 is switched on.

[0069] Next, at step 604, the first module 100 connects to a public network (e.g., an online service, a bank, a currency exchange service, a blockchain network, an Internet network), and establishes transaction details (e.g., recipient data, purpose, etc.) at step 605, and gives the transaction amount at step 606. To this end, a remote server of the external public network or an application installed at the first module 100 will typically provide a suitable user interface that allows input of any relevant information required to establish the transaction.

[0070] Next, at step 607, the so-called mining fee may be determined, which is typical in cryptocurrencies (in the case of conventional currencies, other transaction fees may be determined at this step). Subsequently, at step 608, the user may confirm (the first module 100 receives confirmation from the user) that the transaction has been correctly defined and that the transaction will be authorized.

[0071] If the user wishes to authorize the transaction, the first module 100, which already has the transaction details, sends a transaction request to the bridge module at step 609 and disconnects from the public network at step 610. The first module 100 then also communicatively disconnects from the bridge via the SPDT switch 310.

[0072] Next, the second module 200 is switched on in step 611 (using the SPDT switch 310) and receives the transaction request from the bridge module in step 612. In step 613, the user authorizes the transaction via the second module 200 using input data such as a password, PIN and / or biometric data. Before providing their credentials, the user will have the possibility to check the transaction details again in the second module mode as they will be displayed on the screen. This is therefore another layer of security that can be summarized as "what you see (sign) is what you get (transaction)". As already discussed, authorization occurs when the device is disconnected from the external public network and the first module cannot access any data.

[0073] In addition, the transaction is signed using a private key stored in the security controller 205 of the second module at step 614. Next, at step 615, the second module 200 sends the signed transaction to the bridge module 300.

[0074] Then, in step 616, the second module 200 is turned off, and the first module 100 is turned on and connected to the public network via the communication interface 102. The bridge module 300 sends the signed transaction to the first module 100 in step 617, and in step 618, the first module 100 sends the signed transaction to the blockchain network or a remote server.

[0075] Optionally, when the user fails to authorize the transaction during a predefined number of consecutive attempts (e.g., 3 or 5 attempts), the second module may perform an erase operation as discussed with respect to the functionality of the erase module 401 and wait for a new activation using the above-mentioned keyword sequence (see Figure 5 ).

[0076] The proposed method and system allow to improve the security of electronic wallets without compromising the ease of use. Therefore, they provide a useful, concrete and tangible result.

[0077] According to the present disclosure, a device is proposed that is responsible for the secure storage of private keys to access and perform transactions with electronic currencies (e.g., cryptocurrencies and other blockchain-based or stored content). Thus, a machine or conversion test is completed, and the idea is not abstract.

[0078] At least part of the method disclosed herein can be implemented by a computer. Therefore, the system can take the form of a complete hardware embodiment, a complete software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, which are generally referred to as "circuits", "modules" or "systems" in this article.

[0079] Furthermore, the present system may take the form of a computer program product embodied in any tangible medium of expression having computer usable program code embodied in the medium.

[0080] Those skilled in the art can easily recognize that the above-mentioned method for signing transactions through a virtual air gap can be performed and / or controlled by one or more computer programs. Such computer programs are usually executed by utilizing computing resources in a computing device. The application is stored on a non-transitory medium. An example of a non-transitory medium is a non-volatile memory, such as a flash memory, and an example of a volatile memory is a RAM. The computer instructions are executed by a processor. These memories are exemplary recording media for storing a computer program including computer executable instructions that perform all steps of a computer-implemented method according to the technical concepts proposed herein.

[0081] Although the system and method proposed herein have been depicted, described and defined with reference to certain preferred embodiments, such references and embodiments in the foregoing description do not imply any limitation to the method or system. However, it is apparent that various modifications and changes may be made thereto without departing from the broader scope of the technical concepts. The proposed preferred embodiments are merely exemplary and do not exhaust the scope of the technical concepts proposed herein.

[0082] Therefore, the scope of protection is not limited to the preferred embodiments described in the specification, but only by the appended claims.

Claims

1. A system for signing a transaction, the system comprising: - A first module (100) comprising: - a communication interface (102) with a public network; - a first controller configured to process transactions with the blockchain network or a transaction server accessible on the public network; and - a first data interface, which is used to communicate with the first controller; - A second module (200) comprising: - a random number generator (204) for generating a random sequence; - a security controller (205) configured to generate a seed word and a private key based on the random sequence generated by the random number generator, store the seed word and the private key, and sign the transaction request by generating a signed transaction; and - a second data interface for communicating with the safety controller (205); - A bridging module (300) comprising: - a third controller; - a third data interface for communicating with said third controller; and - a switch configured to selectively connect the third data interface of the bridge module (300) to the first data interface of the first module (100) or the second data interface of the second module (200), so that the first data interface of the first module (100) is never connected to the second data interface of the second module (200); - wherein the third controller is configured to receive a transaction request from the first module (100), pass the transaction request to the second module (200), receive a signed transaction from the second module (200) and pass the signed transaction to the first module (100).

2. The system according to claim 1, wherein: The switch is a single-pole double-throw SPDT switch.

3. The system according to claim 1, wherein: The security controller (205) of the second module (200) is also configured to store biometric data.

4. The system according to claim 1, wherein: The second module (200) includes a biometric sensor (203) configured to convert a person's biometric trace into an electrical signal for transaction authorization.

5. The system according to claim 1, wherein: The switch is also configured to supply power to the second module (200) only when the third data interface of the bridge module (300) is connected to the second data interface of the second module (200).

6. The system according to claim 1 further comprises an erase module (401) configured to call an erase function at the second module (200) to delete the stored seed words and private keys, and erase all transaction and financial data from the first module (100).

7. The system according to claim 1, wherein: The second module (200) and the bridge module (300) are integrated in a common housing.

8. The system according to claim 1, wherein: The first module (100) is integrated with the second module (200) and the bridge module (300) in a common housing.

9. The system according to claim 1, wherein: The second data interface of the second module (200) comprises an input data buffer (206) and an output data buffer (207).

10. The system according to claim 1, wherein: The random number generator (204) of the second module is a hardware entropy generator.

11. The system according to claim 1, wherein: The random number generator (204) of the second module is a software entropy generator.

12. A method for signing a transaction, the method using a system according to any one of the preceding claims to sign a transaction, the method comprising the steps of: - connecting said first module (100) to said public network; - Establish transaction details; - receiving acceptance that the transaction is to be authorized; - sending the transaction request to the bridge module (300); - disconnecting the first module (100) from the bridge module (300); - connecting the bridge module (300) to the second module (200); - sending the transaction request from the bridge module (300) to the second module (200); - authorizing said transaction through said second module (200); - signing the transaction using the private key stored in the second module (200) to generate a signed transaction; - sending the signed transaction from the second module (200) to the bridge module (300); - disconnecting the second module (200) from the bridge module (300); - connecting the first module (100) to the bridge module (300); - sending the signed transaction from the bridge module (300) to the first module (100); and - Sending the signed transaction from the first module (100) to the blockchain network or to the transaction server.

13. The method according to claim 12 further includes, when the user does not authorize a transaction during a predefined number of consecutive attempts at the second module (200), calling an erase function at the second module (200) to delete the stored seed words and private keys, and erase all transaction and financial data from the first module (100).

Citation Information

Patent Citations

  • Virtual air gap—VAG system

    US8984275B2

  • Mobile phone earphone interface-based block chain digital currency wallet

    CN106779636A

  • System and method for communication in a semiconductor device

    CN108205393A