Non-hosted cryptocurrency wallet

By leveraging existing credentials from financial institutions, a non-custodial access solution is provided, which solves the problem of seamless participation in business activities around the world by utilizing existing credentials from financial institutions, and achieves security and compliance of cryptocurrency wallets.

CN120112928APending Publication Date: 2025-06-06VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202280101387.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-17
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing cryptocurrency wallet systems have difficulty in seamlessly participating in business activities around the world, especially in the trust chain between financial institutions and cryptocurrency platforms.

Method used

By leveraging existing credentials from financial institutions, an unmanaged access solution is provided that allows user credentials, account identifiers and seed phrases to be transmitted and stored in trusted channels, ensuring the security and compliance of cryptocurrency wallets.

Benefits of technology

The seamless integration of the cryptocurrency system and financial institutions is achieved, ensuring the security and compliance of the cryptocurrency wallet, and providing a user-friendly non-custodial access solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120112928A_ABST
    Figure CN120112928A_ABST
Patent Text Reader

Abstract

The present disclosure describes an unhosted cryptocurrency wallet application, software development kit, method, and system that fuses the advantages of hosted and unhosted schemes. The system utilizes existing user credentials and user networks to generate seed phrases and encrypted safeguards for end users. The non-hosted cryptocurrency wallet application simulates a user interface hosting a cryptocurrency wallet and has the advantages and security of a non-hosted cryptocurrency wallet.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure allows cryptocurrency systems to leverage existing credentials of financial institutions to create non-custodial access solutions for cryptocurrency wallets. By leveraging existing issuer networks, financial institutions and cryptocurrency platform hosts can deliver mainstream crypto wallet solutions through trusted channels, allowing developed and underdeveloped financial systems to seamlessly and globally participate in commercial activities. Summary of the invention

[0002] In one aspect, the present disclosure provides a method, including: receiving, by a processor, user credentials and an account identifier from a user interface of a user device; transmitting, by the processor, the user credentials to an authentication server; receiving, by the processor, a refresh token based on authentication of the user credentials by the authentication server; generating, by the processor, a unique user identifier (UUID) based on the refresh token of the user credentials; generating, by the processor, a seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least n bits; determining, by the processor, a master private key, wherein the master private key is derived from the seed phrase, and wherein a first blockchain private key is associated with the master private key; converting, by the processor, the seed phrase to a string seed phrase based on a predetermined word list, the number of words in the string seed phrase being proportional to at least n bits; encrypting, by the processor, the string seed phrase using a UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting, by the processor, the encrypted string seed phrase and the account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; and deleting, by the processor, the UUID from a local cache.

[0003] In another aspect, the present disclosure provides a system, comprising: an account authentication server; an encryption platform server; a user device, the user device comprising one or more processors, wherein the user device is communicatively coupled to the account authentication server and the encryption platform server, and wherein the user device is configured to: receive user credentials and an account identifier from a user interface of the user device; transmit the user credentials to the authentication server; receive a refresh token based on authentication of the user credentials by the authentication server; generate a unique user identifier (UUID) based on the refresh token of the user credentials; generate a seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and ... the user authentication server. The phrase is at least 128 bits; determining a master private key, wherein the master private key is derived from the seed phrase, and wherein the first blockchain private key is associated with the master private key; converting the seed phrase to a string seed phrase based on a predetermined word list, wherein the string seed phrase is at least 12 words; encrypting the string seed phrase using a UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting the encrypted string seed phrase and an account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; and deleting the UUID from a local cache.

[0004] In yet another aspect, the present disclosure provides a non-transitory computer-readable medium having instructions stored thereon, which, when executed by one or more processors, cause the one or more processors to perform operations, the operations comprising: receiving user credentials and an account identifier from a user interface of a user device; transmitting the user credentials to an authentication server; receiving a refresh token based on authentication of the user credentials by the authentication server; generating, by the processor, a unique user identifier (UUID) based on the refresh token of the user credentials; generating, by the processor, a seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least n bits. ; determining a master private key, wherein the master private key is derived from a seed phrase, and wherein the first blockchain private key is associated with the master private key; converting the seed phrase to a string seed phrase based on a predetermined word list, the number of words in the string seed phrase being proportional to at least n bits; encrypting the string seed phrase using a UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting the encrypted string seed phrase and an account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; and deleting, by the processor, the UUID from a local cache. BRIEF DESCRIPTION OF THE DRAWINGS

[0005] In the description, for the purpose of explanation rather than limitation, specific details are set forth, such as particular aspects, procedures, techniques, etc., to provide a thorough understanding of the technology of the present invention. However, it will be apparent to one skilled in the art that the technology of the present invention can be practiced in other aspects other than these specific details.

[0006] The accompanying drawings, together with the detailed description below, are incorporated into and form a part of the specification and are used to further illustrate aspects of the concepts embodying the claimed disclosure and to explain various principles and advantages of those aspects. In the accompanying drawings, like reference numerals refer to the same or functionally similar elements throughout the different views.

[0007] The non-custodial cryptocurrency wallet devices, systems, and methods disclosed herein have been appropriately represented in the drawings by conventional symbols, showing only those specific details relevant to understanding the various aspects of the disclosure, so as not to obscure the disclosure with details that would be readily apparent to one of ordinary skill in the art having the benefit of the description herein.

[0008] Figure 1 A system architecture for a user device configurable to run a crypto wallet application in accordance with at least one aspect of the present disclosure is shown.

[0009] Figure 2 A system architecture for a user device configurable to run a crypto wallet application on a web browser hosted by an application server in accordance with at least one aspect of the present disclosure is shown.

[0010] Figure 3 A hierarchical deterministic (HD) wallet supported by most major blockchain networks (e.g., Bitcoin, Ethereum, etc.) in accordance with at least one aspect of the present disclosure is shown.

[0011] Figure 4 is a logic flow diagram for generating a seed phrase and cryptographic keys for a cryptographic wallet in accordance with at least one aspect of the present disclosure.

[0012] Figure 5 is a logic flow diagram for recovering an encrypted seed phrase from an external storage server and performing a blockchain transaction in accordance with at least one aspect of the present disclosure.

[0013] Figure 6 A diagram of a system for initializing and recovering an encrypted seed phrase in accordance with at least one aspect of the present disclosure is shown.

[0014] Figure 7 is a block diagram of a computer device having data processing subsystems or components according to at least one aspect of the present disclosure.

[0015] Figure 8is an illustration of an example system including a host within which a set of instructions for performing any one or more of the methodologies discussed herein may be executed in accordance with at least one aspect of the present disclosure. DETAILED DESCRIPTION

[0016] The following disclosure may provide exemplary systems, devices, and methods for conducting financial transactions and related activities. Although reference may be made to such financial transactions in the examples provided below, the various aspects are not limited thereto. That is, the systems, methods, and devices may be used for any suitable purpose.

[0017] Before discussing particular embodiments, aspects, or examples, some description of the terms used herein is provided below.

[0018] "Account credentials" may include any information that identifies an account and allows a payment processor to verify that a device, person, or entity has permission to access an account. For example, account credentials may include an account identifier (e.g., PAN), a token (e.g., an account identifier substitute), an expiration date, a password, a verification value (e.g., a card verification value (CVV)), personal information associated with an account (e.g., an address, etc.), an account alias, or any combination thereof. Account credentials may be static or dynamic, such that they change over time. In addition, in some embodiments or aspects, account credentials may include information that is both static and dynamic. For example, an account identifier and an expiration date may be static, but a password may be dynamic and change for each transaction. In addition, in some embodiments or aspects, some or all of the account credentials may be stored in a secure memory of a user device. The secure memory of a user device may be configured so that data stored in the secure memory is not directly accessible by an external application, and a payment application associated with the secure memory may be accessed to obtain credentials stored on the secure memory. Thus, a mobile application may interface with a payment application in order to obtain access to payment credentials stored on the secure memory.

[0019] An "application" may include any software module configured to perform one or more specific functions when executed by a processor of a computer. For example, a "mobile application" may include a software module configured to be operated by a mobile device. An application may be configured to perform many different functions. For example, a "payment application" may include a software module configured to store and provide account credentials for transactions. A "wallet application" may include a software module having similar functionality to a payment application, the payment application having multiple accounts that are pre-configured or registered so that it can be used by a wallet application. In addition, an "application" or "application program interface" (API) refers to computer code or other data classified on a computer-readable medium, which may be executed by a processor to facilitate interaction between software components, such as interaction between a client-side front end and / or a server-side back end for receiving data from a client. An "interface" refers to a generated display, such as one or more graphical user interfaces (GUIs) with which a user may interact directly or indirectly (e.g., via a keyboard, mouse, touch screen, etc.).

[0020] "Authentication" is the process by which the credentials of an endpoint (including but not limited to applications, people, devices, processes, and systems) can be verified to ensure that the endpoint is who it claims to be.

[0021] The terms "client device" and "user device" refer to any electronic device configured to communicate with one or more servers or remote devices and / or systems. Client devices or user devices may include mobile devices, network-enabled appliances (e.g., network-enabled televisions, refrigerators, thermostats, etc.), computers, POS systems, and / or any other device or system capable of communicating with a network. Client devices may also include desktop computers, laptop computers, mobile computers (e.g., smart phones), wearable computers (e.g., watches, glasses, lenses, clothing, etc.), cellular phones, networked appliances (e.g., networked televisions, refrigerators, thermostats, etc.), point-of-sale (POS) systems, and / or any other device, system, and / or software application configured to communicate with a remote device or system.

[0022] As used herein, the term "comprising" is not intended to be limiting, but may be a transitional term synonymous with "including," "containing," or "characterized by." Thus, the term "comprising" may be inclusive or open-ended, and does not exclude additional unstated elements or method steps when used in a claim. For example, when describing a method, "comprising" indicates that the claim is open-ended and allows for additional steps. When describing an apparatus, "comprising" may mean that the named elements may be necessary for an embodiment or aspect, but other elements may be added and still form a construction within the scope of the claim. In contrast, the transitional phrase "consisting of" excludes any element, step, or ingredient not specified in the claim. This is consistent with the usage of the term throughout the specification.

[0023] As used herein, the term "computing device" or "computer device" may refer to one or more electronic devices configured to communicate directly or indirectly with or on one or more networks. The computing device may be a mobile device, a desktop computer, or the like. As an example, the mobile device may include a cellular phone (e.g., a smartphone or a standard cellular phone), a portable computer, a wearable device (e.g., a watch, glasses, lenses, clothing, etc.), a personal digital assistant (PDA), and / or other similar devices. The computing device may not be a mobile device, such as a desktop computer. In addition, the term "computer" may refer to any computing device that includes the necessary components for sending, receiving, processing, and / or outputting data and typically includes a display device, a processor, a memory, an input device, and a network interface and / or the like.

[0024] A "credential" may be any suitable information that serves as reliable evidence of value, ownership, identity, or authority. A credential may be a string of numbers, letters, or any other suitable characters that may be presented or contained in any object or document that can serve as confirmation. Examples of credentials include value certificates, identification cards, authentication documents, access cards, passwords, and other login information.

[0025] A "cryptographic algorithm" may be an encryption algorithm that transforms original data into an alternative representation, or a decryption algorithm that transforms encrypted information back into original data. Examples of cryptographic algorithms may include Triple Data Encryption Standard (TDES), Data Encryption Standard (DES), Advanced Encryption Standard (AES), etc. Encryption techniques may include symmetric encryption techniques and asymmetric encryption techniques.

[0026] As used herein, references to "devices," "servers," "processors," and the like may refer to a previously stated device, server, or processor stated as performing a previous step or function, a different server or processor, and / or a combination of servers and / or processors. For example, as used in the specification and claims, a first server or first processor stated as performing a first step or a first function may refer to the same or different server or the same or different processor stated as performing a second step or a second function.

[0027] An "end user" may include any application, consumer, process, or system configured to interact with a requestor for tokenization / de-tokenization / token management services. For example, an end user may include a consumer, a merchant, a mobile device, or any other suitable entity that may be associated with a requestor in a network token system.

[0028] "Interface" can include any software module configured to process communication. For example, an interface can be configured to receive, process a specific entity and respond to a specific entity in a specific communication format. In addition, depending on the functions and capabilities of the computer, device and / or system, the computer, device and / or system may include any number of interfaces. In some embodiments or aspects, the interface may include an application programming interface (API) or other communication formats or protocols that may be provided to a third party or a specific entity to allow communication with the device. In addition, the interface may be designed based on function, a specified entity configured to communicate therewith, or any other variable. For example, an interface may be configured to allow the system to respond to a specific request or may be configured to allow a specific entity to communicate with the system.

[0029] As used herein, the term "merchant" may refer to one or more individuals or entities (e.g., a retail operator that provides goods and / or services to and / or obtains goods and / or services from users (e.g., clients, customers, customers of the merchant, and / or the like) based on a transaction (e.g., a payment transaction). As used herein, a "merchant system" may also refer to one or more computer systems operated by or on behalf of a merchant, such as a server computer that executes one or more software applications.

[0030] As used herein, a "mobile device" may include any electronic device that a user can transfer and operate, and the electronic device may also provide remote communication capabilities for a network. Examples of remote communication capabilities include the use of a mobile phone (wireless) network, a wireless data network (e.g., 3G, 4G or similar network), Wi-Fi, Wi-Max, or any other communication medium that can provide access to a network (such as the Internet or a private network). Examples of mobile devices include mobile phones (e.g., cellular phones), PDAs, tablet computers, netbooks, laptop computers, personal music players, handheld dedicated readers, etc. Other examples of mobile devices include wearable devices such as smart watches, fitness bracelets, anklets, rings, earrings, etc., and cars with remote communication capabilities. The mobile device may include any suitable hardware and software for performing such functions, and may also include multiple devices or components (e.g., when a device remotely accesses a network by sharing the network with another device (i.e., using the other device as a modem), two devices used together may be considered a single mobile device). The mobile device may also include a verification token in the form of, for example, a secure hardware or software component within the mobile device and / or one or more external components that may be coupled to the mobile device. A detailed description of an exemplary mobile device is provided below.

[0031] "Supply" can include the process of providing data for use. For example, supply can include providing, submitting or enabling tokens on a device. Supply can be completed by any entity within or outside the transaction processing system. For example, in some embodiments or aspects, the token can be provided by the issuer or the payment processing network to the mobile device of the consumer (e.g., account holder). The token supplied can have corresponding token data stored and maintained in a token library or a token registry. In some embodiments or aspects, the token library or the token registry can generate tokens that can be supplied or delivered to the device afterwards. In some embodiments or aspects, the issuer can specify a token range, from which token generation and supply can be performed. In addition, in some embodiments or aspects, the issuer can generate a token value and notify the token library of the token value, and provide token record information (e.g., token attributes) for storage in the token library.

[0032] As used herein, the term "server" may include one or more computing devices, which may be individual stand-alone machines located at the same or different locations, may be owned or operated by the same or different entities, and may further be one or more clusters of distributed computers or "virtual" machines housed in a data center. It should be understood and appreciated by those skilled in the art that the functions performed by a "server" may be spread across multiple different computing devices for various reasons. As used herein, "server" is intended to refer to all such scenarios and should not be interpreted as or limited to a specific configuration. In addition, the server as described herein may, but need not, reside at (or be operated by) an agent of any of a merchant, a payment network, a financial institution, a medical provider, a social media provider, a government agency, or any of the aforementioned entities. The term "server" may also refer to or include one or more processors or computers, storage devices, or similar computer arrangements that operate or facilitate communication and processing by multiple parties in a network environment such as the Internet, but it should be understood that communication may be facilitated by one or more public or private network environments, and various other arrangements are possible. In addition, multiple computers (e.g., servers) or other computerized devices (e.g., point of sale devices) communicating directly or indirectly in a network environment may constitute a "system" (e.g., a merchant's point of sale system). As used herein, references to a "server" or "processor" may refer to a previously stated server and / or processor stated as performing a previous step or function, a different server and / or processor, and / or a combination of servers and / or processors. For example, as used in the specification and claims, a first server and / or first processor stated as performing a first step or function may refer to the same or a different server and / or processor stated as performing a second step or function.

[0033] A "server computer" may generally be a powerful computer or a cluster of computers. For example, a server computer may be a mainframe, a small computer cluster, or a group of servers that function as a unit. A server computer may be associated with an entity such as a payment processing network, a wallet provider, a merchant, an authentication cloud, an acquirer, or an issuer. In one example, a server computer may be a database server coupled to a web server. The server computer may be coupled to a database and may include any hardware, software, other logic, or a combination of the foregoing for servicing requests from one or more client computers. The server computer may include one or more computing devices and may use any of a variety of computing structures, arrangements, and compilations for servicing requests from one or more client computers. In some embodiments or aspects, a server computer may provide and / or support payment network cloud services.

[0034] As used herein, the term "system" may refer to one or more computing devices or a combination of computing devices (eg, processors, servers, client devices, software applications, components of such devices, etc.).

[0035] Alternatively, the dynamic token may include a token with limited use (e.g., limited by time, amount threshold (total amount or single transaction amount), or number of uses). Thus, the dynamic token may be generated and delivered to the end user on a per-transaction basis or as needed to initiate a payment transaction through a registered and authenticated device and / or channel. For example, a one-time use dynamic token may be used at an e-commerce (e-commerce) website, and if the dynamic token is intercepted by a third party, the dynamic token may be useless because the dynamic token has already been used and therefore has no value for future transactions.

[0036] A non-payment token may include a token that is not a substitute for a real account identifier (e.g., PAN). For example, a non-payment token may be used by a merchant / acquirer system for analytics, quotations, customer support, marketing, etc. However, a non-payment token may not be used to generate an original transaction and subsequent transactions using a real account identifier (e.g., PAN) or other account identifiers. Therefore, a non-payment token may include a low-value token that may be used by an entity within a transaction processing system for non-payment transactions or transaction services.

[0037] The token presentation mode may include any identifier or method for indicating the mode in which the token is presented. For example, the token presentation mode may include a number associated with a particular type of transaction (e.g., 5 for NFC transactions, 3 for QR codes, etc.). In addition, in some embodiments or aspects, the token presentation mode may be provided by a type of password or other dynamic data generated for the transaction. For example, each type of transaction presentation mode may have a different cryptographic algorithm associated with that type of presentation mode (e.g., NFC vs. QR code), and the type of password used is determined during verification of the password. In addition, the token presentation mode may be provided by a mobile device or may be populated by a merchant access device (e.g., a POS terminal) or other entity within a transaction processing system (e.g., an acquirer computer, a merchant processor, etc.).

[0038] “Token processing” refers to the processing of transactions where a token appears in place of a primary account number (PAN). Tokens are processed from points of interaction throughout the network. Token processing also includes the use of a token vault to detokenize the token in order to complete the transaction. Token processing can span the payment process including authorization, capture, clearing, and exception handling.

[0039] A "token request message" may be an electronic message for requesting a token. The token request message may include information that can be used to identify a payment account or digital wallet, and / or information for generating a payment token. For example, the token request message may include payment credentials, mobile device identification information (e.g., a phone number or MSISDN), a digital wallet identifier, information identifying a tokenization service provider, a merchant identifier, a password, and / or any other suitable information. The information included in the token request message may be encrypted (e.g., using an issuer-specific key). In some embodiments or aspects, the token request message may be formatted as an authorization request message (e.g., ISO 8583 message format). In some embodiments or aspects, the token request message may have a zero dollar amount in the authorization amount field. As another example, the token request message may include a flag or other indicator that specifies that the message is a token request message.

[0040] "Token request indicator" may refer to an indicator indicating that a message containing the indicator relates to a token request. The token request indicator may be passed to the issuer as part of an identification and verification (ID&V) method as needed to inform the issuer of the reason for performing an account status check.

[0041] A "token requester identifier (ID)" may include any characters, numbers, or other identifiers associated with an entity associated with a network token system. For example, a token requester identifier may be associated with an entity registered with the network token system. In some embodiments or aspects, for token requests associated with the same token requester, a unique token requester ID may be assigned for each domain. Thus, in some embodiments or aspects, if a token requester can request tokens for multiple domains, the token requester may have multiple token requester identifiers, one for each domain. For example, a token requester ID may identify a pairing of a token requester (e.g., a mobile device, a mobile wallet provider, etc.) with a token domain (e.g., e-commerce, contactless, etc.). The token requester ID may include information of any format or type. For example, in one embodiment or aspect, the token requester ID may include an alphanumeric value, such as ten or eleven digits of letters and / or numbers (e.g., 4678012345). In some embodiments or aspects, the token requestor ID may include a code (e.g., the first 3 digits) for a token service provider such as a network token system, and the remaining digits may be assigned by the token service provider for each requesting entity (e.g., mobile wallet provider) and token domain (e.g., contactless, e-commerce, etc.).

[0042] In some embodiments or aspects, a token requestor identifier may be used in a transaction during the authorization process. For example, a token requestor identifier may be passed through a transaction request message to verify that the entity initiating the transaction is the same entity that is requesting and managing the token. In some embodiments or aspects, an entity (e.g., a digital or mobile wallet provider, a merchant, a merchant of record, a payment enabler, etc.) may be assigned a token requestor identifier during an onboarding or registration process. In some embodiments or aspects, an acquirer / acquirer processor / payment enabler (e.g., a payment service provider) may populate the token requestor identifier for each merchant, mobile wallet provider, consumer, etc. into an authorization message field before submitting the authorization request message to the payment processing network.

[0043] A "user" may include an individual. In some embodiments or aspects, a user may be associated with one or more personal accounts and / or mobile devices. A user may also be referred to as a cardholder, account holder, or consumer.

[0044] "User device" is an electronic device that can be transferred and / or operated by a user. The user device can provide a network with a remote communication capability. The user device can be configured to transmit data or communication to other devices and receive data or communication from other devices. In some embodiments or aspects, the user device can be portable. Examples of user devices can include mobile phones (e.g., smart phones, cellular phones, etc.), PDAs, portable media players, wearable electronic devices (e.g., smart watches, fitness bands, ankle bracelets, rings, earrings, etc.), e-reader devices, and portable computing devices (e.g., laptop computers, netbooks, ultrabooks, etc.). Examples of user devices can also include cars with remote communication capabilities.

[0045] The present disclosure describes an improved cryptocurrency wallet architecture that resolves the tension between a custodial / non-custodial user interface and simplicity for custodial and government compliance. In a custodial crypto wallet, the crypto platform host is responsible for the user's seed phrase, while in a non-custodial crypto wallet, the user is responsible for their own seed phrase.

[0046] In a custodial solution, end users can log into their crypto wallets using end user credentials and a two-factor authentication code, and use their crypto wallets to participate in blockchain transactions. End users may not know that the crypto platform host has the custodial responsibility to store and retrieve their seed phrases or even know that they have a seed phrase. The seed phrase is generated by the crypto platform host, and the end user does not care to remember this information. The seed phrase is a master key used to recover the corresponding private keys for different blockchain networks. In a custodial wallet, end users do not need to remember a multi-word (e.g., 12 to 24 words) seed phrase, and are able to log into their crypto wallets even if they lose or forget their account passwords. Therefore, in a custodial solution, end users can reset or retrieve lost or forgotten passwords, compared to non-custodial wallets.

[0047] Despite the aforementioned advantages of the custodial wallet solution, there may also be disadvantages. For example, if the credentials of an end user are compromised by a malicious actor, the malicious actor will have access to the seed phrase and all blockchain assets associated with the seed phrase. Crypto platform hosts are also subject to additional government regulations due to their custodial responsibilities for blockchain assets. In this regard, crypto platform hosts must comply with blockchain and cryptocurrency trading government regulations. Specifically, financial institutions in a custodial relationship may need to account for their end users' crypto assets on their balance sheets. Unlike fiat currencies, most financial institutions do not want to assume the responsibility of volatile crypto assets (such as cryptocurrencies or non-fungible tokens) and the complex valuation issues that accompany these assets.

[0048] In contrast, in a non-custodial solution, the end user is responsible for custody of their seed phrase. Many end users prefer this solution because it provides an additional layer of security and anonymity for blockchain transactions. In a non-custodial solution, the end user does not worry about account hacks that could result in the liquidation of their blockchain assets. In addition, financial institutions do not have direct access to the end user's crypto assets and are therefore not responsible for reporting these assets on their balance sheets. However, non-custodial accounts are not immune to adverse factors. For example, many end users of non-custodial accounts have lost their seed phrases and have no means to recover or retrieve their blockchain assets. To avoid this problem, many end users keep physical copies of their seed phrases, making the seed phrases vulnerable to physical theft. Even in the best case, the end user must enter the multi-word phrase (e.g., 12, 24 words or more) through their crypto wallet using a cumbersome process for each blockchain transaction.

[0049] The present disclosure describes a non-custodial cryptocurrency wallet that utilizes the advantages of the custody and non-custodial solutions described above while minimizing or eliminating the disadvantages of the custody and non-custodial solutions. In one aspect, the non-custodial crypto wallet can be deployed by the crypto platform host as an on-behalf (OBO) software development kit (SDK), a white label mobile application, or a web solution for a web browser, or a combination thereof. In other aspects, the crypto wallet can be configured by a financial institution to use the existing account resources of these financial institutions for new crypto services. By using the existing account resources of the financial institution, an improved user experience is provided to the end user in a non-custodial platform that simulates a custody experience. In addition, the crypto platform host can assist the financial institution in managing the seed phrases of its end users. The SDK and white label application allow the crypto platform host to avoid the red tape and custody barriers associated with the custody solution, reduce the integration time for financial institutions, simplify the crypto listing (GTM) solution for the crypto platform host, and realize the basic technical capabilities for new capital flows, value-added services, and additional crypto solutions.

[0050] In various aspects, the crypto wallet application can be run locally on a user device such as a smart phone, or can be deployed through an application server to run on a web browser. The crypto wallet application can be configured to generate and / or retrieve an encryption key for an end-user seed phrase. In addition, the crypto wallet application can establish a storage profile (e.g., vProfileID) for a new storage entry at an external storage server to store the encrypted seed phrase. The storage profile can link the end user to their storage entry using a financial intuition credential and / or an account identifier (e.g., a phone number or email). The owner of the storage server (usually the encryption platform host) does not have access to the encryption key, so the seed phrase in the storage entry cannot be decrypted. This relationship is crucial to prevent the owner of the storage server from having custody responsibilities for the seed phrase and encrypted assets. The external storage server stores customer property in a locked safe like a bank. For example, as long as the customer has the key to the safe, the bank will never have control over the property.

[0051] Figure 1A system architecture for a user device 102 that can be configured to run a crypto wallet application according to at least one aspect of the present disclosure is shown. The user device 102 communicates with a crypto platform host server 104, an authentication server 108 of a financial institution, and one or more blockchain networks 106 via a wide area network (WAN) 110. The crypto platform host server 104 can assist the financial institution in managing end-user seed phrases. End users can log in to their crypto wallet application using their bank credentials from their financial institution. The authentication server 108 can authenticate the bank credentials and provide a multi-factor authentication (MFA) code to the user device 102. The private key can be encrypted and stored locally on the user device 102 or web browser 202 ( Figure 2 ). As previously discussed, the financial institution's authentication server 108 and the crypto platform host server 104 do not have access to the encryption keys or unencrypted private keys used to digitally sign transactions. In one aspect, the private key can be encrypted using a biometric token provided by the secure enclave of the user device 102. The financial institution will ensure that the end user's login is associated with the end user's institution's "Know Your Customer" (KYC) account. The crypto platform host server 104 and the risk assessment service provider (e.g., TRM Labs) will provide the financial institution with on-chain analysis to access the risk of KYC end users' activities on the relevant blockchain. If the end user engages in activities that trigger an anti-money laundering (AML) flag, the end user's fiat balance can be frozen, and the KYC details with the associated non-custodial wallet address and seed phrase can be provided to the appropriate financial crime authorities. The end user can link their fiat account and / or crypto platform credentials from the financial institution to their non-custodial wallet to fund crypto-related purchases. The crypto platform host server 104 may provide connectivity to crypto / decentralized finance (DeFi) services via a native protocol (Blocknative), but neither the crypto platform host server 104 nor the financial institution's authentication server 108 will be involved in the movement / exchange of crypto assets. The financial institution's crypto platform host server 104 and authentication server 108 will be involved in the business-as-usual fiat money flow between the exchange and merchants, who will deliver crypto assets or digital products directly to the end user's non-custodial wallet via the relevant blockchain.

[0052] Figure 2 A system architecture for a user device 202 that can be configured to run a crypto wallet application on a web browser hosted by an application server 212 is shown in accordance with at least one aspect of the present disclosure. The user device 202 communicates with a crypto platform host server 204, a financial institution's authentication server 208, and one or more blockchain networks 206 via a WAN 210.

[0053] Figure 3 A hierarchical deterministic (HD) wallet 300 supported by most major blockchain networks (e.g., Bitcoin, Ethereum, etc.) according to at least one aspect of the present disclosure is shown. In one example, the HD wallet 300 can be used to recover the private keys associated with each blockchain network 306 to 312 using a seed phrase 302. The HD wallet 300 is a cryptographic wallet that stores private keys and associated public addresses for different blockchain networks, rather than crypto assets. The seed phrase 302 and / or the master private key 304 are used to log into the HD wallet 300 and can be used to retrieve the private keys associated with a specific blockchain network 306 to 312. The master private key 304 is mathematically equivalent to the seed phrase 302. In various aspects, the master private key is a binary, binary coded decimal, or hexadecimal equivalent of a number of words including the seed phrase 302. The HD wallet 300 can include information associated with several different blockchain networks 306 to 312 associated with the seed phrase 302. In one example, the first blockchain wallet 304 includes a public address 314 associated with a private key 316 and a public address 318 associated with a private key 320 .

[0054] Figure 4 is a logic flow diagram 400 for generating a seed phrase and cryptographic keys for a cryptographic wallet in accordance with at least one aspect of the present disclosure. Figure 1 Reference together Figure 4In one aspect, a user device 102 receives 402 user credentials through a user interface of a crypto wallet application. The user credentials are associated with a financial institution of an end user. The user device 102 transmits 404 the user credentials to an authentication server 108 of the financial institution. Upon authenticating the user credentials, the authentication server 108 transmits 406 an oAuth access token and a refresh token to the user device 102. The user device 102 creates 408 a unique user identifier (UUID) used as an encryption key. The user device 102 determines 410 an account identifier (e.g., an email address or phone number) associated with the end user or the user device 102. The user device 102 generates 412 a seed phrase for the user. In one example, the seed phrase is generated using a pseudo-random number generator for a predetermined number of bits. In various aspects, the seed phrase is at least 128 bits. The user device 102 derives 414 a master private key associated with the seed phrase. The user device 102 converts 416 the seed phrase into a syntax-specific word string according to a predefined word list. In one example, the word list can be determined according to a Bitcoin Improvement Proposal (BIP) 32 or a BIP39 word list. The user device 102 utilizes the UUID to encrypt 418 the string seed phrase. In one example, the UUID encryption key is an oAuth refresh token received when authenticating the user credentials. The oAuth refresh token can be retrieved regardless of whether the end user accesses the crypto wallet through an application on the user device 102 or through a web browser. To refresh the access token after the access token expires, the oAuth refresh token is reused for the UUID encryption key from its original function. In another example, the user device 102 generates a UUID encryption key based on the refresh token. In either example, the UUID is no longer available outside the user device. The user device 102 transmits 420 the encrypted string seed phrase along with the account identifier to an external storage location of the encryption platform host server 104. The encryption platform host server 104 creates 422 a storage entry based on the account identifier.

[0055] Figure 5 is a logic flow diagram 500 for recovering an encrypted seed phrase from an external storage server and performing a blockchain transaction in accordance with at least one aspect of the present disclosure. Figure 1 Reference together Figure 5In one aspect, a user device 102 receives 502 user credentials through a user interface of a crypto wallet application. The user credentials are associated with a financial institution of an end user. The user device 102 transmits 504 the user credentials to an authentication server 108 of the financial institution. Upon authenticating the user credentials, the authentication server 108 transmits 506 an oAuth access token and a refresh token to the user device 102. The user device 102 creates 508 a unique user identifier for an encryption key. The user device 102 determines 510 an account identifier (e.g., an email address or phone number) associated with the end user or the user device 102 and transmits the account identifier in a get request. In various aspects, the get request is an API call to the crypto platform host server 104 to recover an encrypted string seed phrase. In various aspects, the API is authenticated through business-as-usual access to an crypto platform host API (e.g., a Visa API). The crypto platform host server 104 receives 512 the get request and retrieves 514 an encrypted seed phrase associated with the account identifier. The user device 102 receives 516 the encrypted string seed phrase from the crypto platform host server 104. The user device 102 utilizes the UUID (e.g., an oAuth refresh token or a biometric token) to decrypt the encrypted string seed phrase 518. The UUID can be used as the same encryption key for encrypting and decrypting the string seed phrase. The user device 102 recovers 520 a first blockchain private key associated with the first blockchain network through the HD wallet.

[0056] The user device 102 uses the first blockchain private key to sign 522 a transaction associated with the first blockchain. The first blockchain private key is not stored in a local cache or local storage of the user device 102, and a new private key is recovered from the HD wallet for subsequent transactions. However, as long as the session remains active, the seed phrase is retained in the local storage of the user device 102 to recover the new blockchain private key. The seed phrase is stored in an encrypted format and must be decrypted for each transaction in the session. Once the session is terminated, the encrypted seed phrase is deleted from the local storage on the user device 102. In various aspects, the session may be terminated when the end user closes the application, a lock screen is displayed on the user device, or a session times out (e.g., a predetermined amount of time has passed since the user device 102 received user input or executed a transaction). After the transaction is signed, the user device 102 deletes 524 the first blockchain private key from the local storage, and after the session is terminated, the user device 102 deletes 526 the seed phrase from the local storage.

[0057] Figure 6A diagram of a system 600 for initializing and recovering an encrypted seed phrase according to at least one aspect of the present disclosure is shown. In the initialization and recovery cycle, the mobile application 602 receives user credentials 612 and transmits these user credentials to the authentication server 608 through the authentication module 614. The mobile application 602 receives an access token from the authentication server 608, which allows the mobile application 602 to access a digital account 616 associated with the end user's financial institution. The end user is able to transfer fiat currency from their financial intuition digital account 616 to conduct blockchain transactions on the wallet SDK 610. Similarly, users can transfer fiat currency from the wallet SDK 610 to their digital account 616.

[0058] In the initialization loop, the wallet SDK 610 generates a seed phrase and determines the UUID encryption key. The seed phrase is encrypted and stored at the storage location 618 of the encryption platform host server 604.

[0059] In the recovery loop, the wallet SDK 610 makes an API call to the encryption platform host server 604 to retrieve the encrypted seed phrase. Once the wallet SDK 610 receives the encrypted seed phrase, it decrypts the seed phrase and recovers the blockchain private key from the corresponding blockchain network 606a-606c. The wallet SDK 610 can then perform blockchain transactions on the corresponding blockchain network 606a-606c.

[0060] Figure 7 is a block diagram of a computer device 3000 having data processing subsystems or components according to at least one aspect of the present disclosure. Figure 7 The subsystems shown in the system are interconnected via a system bus 3010. Additional subsystems such as a printer 3018, a keyboard 3026, a fixed disk 3028 (or other memory containing computer readable media), a monitor 3022 coupled to a display adapter 3020, and the like are shown. Peripheral devices and input / output (I / O) devices coupled to an I / O controller 3012 (which may be a processor or other suitable controller) may be connected to the computer system by any number of means known in the art, such as a serial port 3024. For example, a serial port 3024 or an external interface 3030 may be used to connect a computer device to a wide area network (such as the Internet), a mouse input device, or a scanner. The interconnection through the system bus allows the central processor 3016 to communicate with each subsystem and allows control of the execution of instructions from the system memory 3014 or the fixed disk 3028, as well as the exchange of information between subsystems. The system memory 3014 and / or the fixed disk 3028 may be embodied as a computer readable medium.

[0061] Figure 84000 is a diagram of an example system 4000 including a host 4002 in accordance with at least one aspect of the present disclosure, within which a set of instructions for performing any one or more of the methods discussed herein may be executed. In various aspects, the host 4002 operates as a standalone device, or may be connected (e.g., networked) to other machines. In a network deployment, the host 4002 may operate as a server or client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The host 4002 may be a computer or computing device, a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a cellular phone, a portable music player (e.g., a portable hard disk audio device, such as a Moving Picture Experts Group Audio Layer 3 (MP3) player), a network appliance, a network router, a switch or a bridge, or any machine capable of executing a set of instructions (in sequence or otherwise) specifying actions to be taken by the machine. Further, while a single machine is illustrated, the term "machine" shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.

[0062] The example system 4000 includes a host 4002, running a main operating system (OS) 4004 on one or more processors / processor cores 4006 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), or both) and various memory nodes 4008. The main OS 4004 may include a hypervisor 4010 that is capable of controlling functions and / or communicating with virtual machines (“VMs”) 4012 running on machine-readable media. The VMs 4012 may also include virtual CPUs or vCPUs 4014. The memory nodes 4008 may be linked or pinned to virtual memory nodes or vNodes 4016. When a memory node 4008 is linked or pinned to a corresponding vNode 4016, data may then be mapped directly from the memory node 4008 to its corresponding vNode 4016.

[0063] All the various components shown in the host 4002 can be connected to each other and connected to each other, or communicate with each other through a bus (not shown) or through other coupling or communication channels or mechanisms. The host 4002 may further include a video display, an audio device or other peripherals 4018 (e.g., a liquid crystal display (LCD), an alphanumeric input device (including, for example, a keyboard), a cursor control device (e.g., a mouse), a voice recognition or biometric verification unit, an external drive, a signal generating device (e.g., a speaker)), a permanent storage device 4020 (also referred to as a disk drive unit) and a network interface device 4022. The host 4002 may further include a data encryption module (not shown) for encrypting data. The components provided in the host 4002 are components that are typically present in a computer system that can be suitable for use with aspects of the present disclosure, and are intended to represent a wide range of such computer components known in the art. Therefore, the system 4000 may be a server, a minicomputer, a mainframe computer, or any other computer system. The computer may also include different bus configurations, networking platforms, multi-processor platforms, etc. Various operating systems may be used, including UNIX, LINUX, WINDOWS, QNX ANDROID, IOS, CHROME, TIZEN, and other suitable operating systems.

[0064] The disk drive unit 4024 may also be a solid state drive (SSD), a hard disk drive (HDD), or other drive including a computer or machine readable medium on which is stored one or more sets of instructions and data structures (e.g., data / instructions 4026) embodying or utilizing any one or more of the methods or functions described herein. The data / instructions 4026 may also reside completely or at least partially within the main memory node 4008 and / or within the processor(s) 4006 during execution by the host 4002. The data / instructions 4026 may be further transmitted or received over the network 4028 via a network interface device 4022 utilizing any of a number of well-known transmission protocols (e.g., Hyper Text Transfer Protocol (HTTP)).

[0065] Processor 4006 and memory node 4008 may also include machine-readable media. The term "computer-readable medium" or "machine-readable medium" should be considered to include a single medium or multiple media (e.g., a centralized or distributed database and / or associated cache and server) storing one or more sets of instructions. The term "computer-readable medium" should also be considered to include any medium capable of storing, encoding, or carrying a set of instructions for execution by host 4002 and causing host 4002 to execute any one or more of the methods of the present application, or any medium capable of storing, encoding, or carrying a data structure utilized by this set of instructions or a data structure associated with this set of instructions. Therefore, the term "computer-readable medium" should be considered to include, but is not limited to, solid-state memory, optical and magnetic media, and carrier signals. Such media may also include, but are not limited to, hard disks, floppy disks, flash memory cards, digital video discs, random access memories (RAM), read-only memories (ROM), etc. The example aspects described herein may be implemented in an operating environment that includes software installed on a computer, installed in hardware, or a combination of software and hardware.

[0066] Those skilled in the art will recognize that an Internet service may be configured to provide Internet access to one or more computing devices coupled to the Internet service, and that the computing devices may include one or more processors, buses, memory devices, display devices, input / output devices, etc. In addition, those skilled in the art will appreciate that an Internet service may be coupled to one or more databases, repositories, servers, etc., which may be used to implement any of the various aspects of the present disclosure as described herein.

[0067] The computer program instructions may also be loaded onto a computer, server, other programmable data processing device or other apparatus so that a series of operating steps are executed on the computer, other programmable device or other apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide a process for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram.

[0068] For example, a suitable network may include or be interfaced with any one or more of the following: a local intranet; a PAN (personal area network); a LAN (local area network); a WAN (wide area network); a MAN (metropolitan area network); a virtual private network (VPN); a storage area network (SAN); a frame relay connection; an advanced intelligent network (AIN) connection; a synchronous optical network (SONET) connection; a digital T1, T3, E1, or E3 line; a digital data service (DDS) connection; a DSL (digital subscriber line) connection; an Ethernet connection; an ISDN (integrated services digital network) line; a dial-up port (such as a V.90, V.34, or V.34bis analog modem connection); a cable modem; an ATM (asynchronous transfer mode) connection; or an FDDI (fiber distributed data interface) or CDDI (copper distributed data interface) connection. In addition, communications may also include links to any of a variety of wireless networks, including WAP (Wireless Application Protocol), GPRS (General Packet Radio Service), GSM (Global System for Mobile Communications), CDMA (Code Division Multiple Access) or TDMA (Time Division Multiple Access), cellular telephone networks, GPS (Global Positioning System), CDPD (Cellular Digital Packet Data), RIM (Room Environment Photo) duplex paging networks, Bluetooth radios, or IEEE 802.11-based radio frequency networks. Network 4030 may further include or interface with any one or more of the following: an RS-232 serial connection, an IEEE-1394 (FireWire) connection, a Fiber Channel connection, an IrDA (infrared) port, a SCSI (Small Computer System Interface) connection, a USB (Universal Serial Bus) connection, or other wired or wireless, digital or analog interface or connection, mesh or Network connection.

[0069] Generally speaking, a cloud-based computing environment is a resource that typically combines the computing power of large groups of processors (e.g., within a web server) and / or the storage capacity of large groups of computer memory or storage devices. Systems that provide cloud-based resources may be utilized only by their owners, or such systems may be accessed by external users who deploy applications within the computing infrastructure to gain the benefits of large computing or storage resources.

[0070] For example, a cloud is formed by a network of web servers including multiple computing devices (such as host 4002), where each server 4030 (or at least a plurality thereof) provides processor and / or storage resources. These servers manage workloads provided by multiple users (e.g., cloud resource clients or other users). Typically, each user's workload requirements for the cloud change in real time, sometimes greatly. The nature and extent of these changes typically depend on the type of business associated with the user.

[0071] It is noteworthy that any hardware platform suitable for performing the processing described herein is suitable for use with the technology. As used herein, the terms "computer-readable storage medium" and "computer-readable storage medium" refer to any one or more media that participate in providing instructions to the CPU for execution. Such media can take a variety of forms, including but not limited to non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical disks or disks, such as fixed disks. Volatile media include dynamic memory, such as system RAM. Transmission media include coaxial cables, copper wires, and optical fibers, etc., which include wires that include one aspect of the bus. Transmission media can also take the form of sound waves or light waves, such as sound waves or light waves generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer readable media include, for example, floppy disks, hard disks, magnetic tape, any other magnetic media, CD-ROMs, digital video disks (DVDs), any other optical media, any other physical media with markings or patterns of holes, RAM, PROM, EPROM, EEPROM, FLASH EPROM, any other memory chip or data exchange adapter, carrier wave, or any other medium from which a computer can read.

[0072] Various forms of computer readable media may be involved in carrying one or more sequences of one or more instructions to the CPU for execution. The bus carries the data to the system RAM, from which the CPU retrieves the instructions and executes them. The instructions received by the system RAM may optionally be stored on a fixed disk before or after execution by the CPU.

[0073] The computer program code for performing operations on aspects of the present technology can be written in any combination of one or more programming languages, including object-oriented programming languages ​​(such as Java, Smalltalk, C++, etc.) and conventional procedural programming languages ​​(such as "C" programming language, Go, Python, or other programming languages ​​including assembly language). The program code can be executed entirely on the user's computer, partially on the user's computer; as a stand-alone software package, partially on the user's computer and partially on a remote computer, or completely on a remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network including a local area network (LAN) or a wide area network (WAN), or an external computer can be connected (for example, using an Internet service provider to connect through the Internet).

[0074] Examples of methods according to various aspects of the present disclosure are provided in the following numbered clauses. One aspect of the method may include any one or more than one numbered clause and any combination of numbered clauses described below.

[0075] Clause 1. A method comprising: receiving, by a processor, user credentials and an account identifier from a user interface of a user device; transmitting, by the processor, the user credentials to an authentication server; receiving, by the processor, a refresh token based on authentication of the user credentials by the authentication server; generating, by the processor, a unique user identifier (UUID) based on the refresh token of the user credentials; generating, by the processor, a seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least n bits; determining, by the processor, a master private key, wherein the master private key is derived from the seed phrase, and wherein a first blockchain private key is related to the master private key association; converting, by the processor, the seed phrase into a string seed phrase based on a predetermined word list, the number of words in the string seed phrase being proportional to the at least n bits; encrypting, by the processor, the string seed phrase using the UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting, by the processor, the encrypted string seed phrase and the account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; and deleting, by the processor, the UUID from a local cache.

[0076] Clause 2. The method as described in Clause 1 also includes: receiving a request to perform a first blockchain transaction by the processor; determining the UUID by the processor based on the refresh token of the user credential and the account identifier; transmitting a request for the encrypted string seed phrase by the processor to the external storage location, wherein the request includes the account identifier; receiving the encrypted string seed phrase by the processor; establishing a blockchain session by the processor; storing the encrypted string seed phrase by the processor in a local storage device of the user device; decrypting the encrypted string seed phrase by the processor using the UUID as a decryption key and generating the string seed phrase; recovering the first blockchain private key on the blockchain by the processor using the string seed phrase; and signing the first blockchain transaction on the blockchain by the processor using the first blockchain private key.

[0077] Clause 3. The method of clause 2 further comprises: determining, by the processor, a state of the blockchain session, wherein the state of the blockchain session is terminated; and deleting, by the processor, the encrypted string seed phrase from the local storage device on the user device.

[0078] Clause 4. The method of clause 3, wherein the blockchain session is terminated by closing the user interface, displaying a lock screen on the user device, or expiration of a predetermined timeout period associated with the blockchain session.

[0079] Clause 5. The method of clauses 2 to 4, wherein recovering the first blockchain private key further comprises: requesting, by the processor, the first blockchain private key having the string seed phrase from a hierarchical deterministic wallet associated with the blockchain; and receiving, by the processor, the first blockchain private key from the hierarchical deterministic wallet.

[0080] Clause 6. The method of clauses 1 to 5, wherein the seed phrase is at least 128 bits and the string seed phrase is at least 12 words.

[0081] Clause 7. The method of clauses 1 to 6, wherein the seed phrase is at least 256 bits and the string seed phrase is at least 24 words.

[0082] Clause 8. The method of clauses 1 to 7 further comprises: limiting, by the processor, the UUID to local transmission within a software development kit on the user device, wherein the UUID is blocked from transmission to an external device.

[0083] Clause 9. A system comprising: an account authentication server; an encryption platform server; a user device, the user device comprising one or more processors, wherein the user device is communicatively coupled to the account authentication server and the encryption platform server, and wherein the user device is configured to: receive user credentials and an account identifier from a user interface of the user device; transmit the user credentials to the authentication server; receive a refresh token based on the authentication of the user credentials by the authentication server; generate a unique user identifier (UUID) based on the refresh token of the user credentials; generate a seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least 128 digits; determining a master private key, wherein the master private key is derived from the seed phrase, and wherein a first blockchain private key is associated with the master private key; converting the seed phrase to a string seed phrase based on a predetermined word list, wherein the string seed phrase is at least 12 words; encrypting the string seed phrase using the UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting the encrypted string seed phrase and the account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; and deleting the UUID from a local cache.

[0084] Clause 10. A system as described in clause 9, wherein the user device is further configured to: receive a request to perform a first blockchain transaction; determine the UUID based on the refresh token of the user credential and the account identifier; transmit a request for the encrypted string seed phrase to the external storage location, wherein the request includes the account identifier; receive the encrypted string seed phrase; establish a blockchain session; store the encrypted string seed phrase in a local storage device of the user device; use the UUID as a decryption key to decrypt the encrypted string seed phrase and generate the string seed phrase; request the first blockchain private key with the string seed phrase from a hierarchical deterministic wallet associated with a blockchain; recover the first blockchain private key from the hierarchical deterministic wallet; and use the first blockchain private key to sign the first blockchain transaction on the blockchain.

[0085] Clause 11. The system of clause 10, wherein the user device is further configured to: determine a state of the blockchain session, wherein the state of the blockchain session is terminated; and delete the encrypted string seed phrase from a local storage device on the user device.

[0086] Clause 12. The system of clause 11, wherein the blockchain session is terminated by closing the user interface, displaying a lock screen on the user device, or expiration of a predetermined timeout period associated with the blockchain session.

[0087] Clause 13. The system of clauses 10 to 12, wherein the user device is further configured to: receive a request to perform a second blockchain transaction, wherein the second blockchain transaction is performed in the blockchain session and wherein the blockchain session is still active from the first blockchain transaction; decrypt the encrypted string seed phrase using the UUID as the decryption key and generate the string seed phrase; request the first blockchain private key with the string seed phrase from the hierarchical deterministic wallet associated with the blockchain; recover the first blockchain private key from the hierarchical deterministic wallet; sign the first blockchain transaction on the blockchain using the first blockchain private key; and delete the first blockchain private key after signing the second blockchain transaction.

[0088] Clause 14. The system of clause 13, wherein a value of the first blockchain private key recovered from the hierarchical deterministic wallet for the first blockchain transaction is different from a value of the first blockchain private key recovered from the hierarchical deterministic wallet for the second blockchain transaction.

[0089] Clause 15. The system of clauses 9 to 14, wherein the user device is further configured to restrict the UUID to local transmission within a software development kit on the user device, wherein the UUID is blocked from transmission to external devices.

[0090] Clause 16. A non-transitory computer-readable medium having instructions stored thereon, which, when executed by one or more processors, cause the one or more processors to perform operations, the operations comprising: receiving user credentials and an account identifier from a user interface of a user device; transmitting the user credentials to an authentication server; receiving a refresh token based on authentication of the user credentials by the authentication server; generating a unique user identifier (UUID) based on the refresh token of the user credentials; generating a seed phrase by the processor, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least n bits; determining a master private key, wherein the master private key is derived from the seed phrase, and wherein a first blockchain private key is associated with the master private key; converting the seed phrase into a string seed phrase based on a predetermined word list, the number of words in the string seed phrase being proportional to the at least n bits; encrypting the string seed phrase using the UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting the encrypted string seed phrase and the account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; and deleting, by the processor, the UUID from a local cache.

[0091] Clause 17. The non-transitory computer-readable medium of Clause 16, when executed by one or more processors, is further configured to perform operations, the operations comprising: receiving a request to perform a first blockchain transaction on a first blockchain; determining the UUID based on the refresh token of the user credential and the account identifier; transmitting a request for the encrypted string seed phrase to the external storage location, wherein the request includes the account identifier; receiving the encrypted string seed phrase; establishing a blockchain session; storing the encrypted string seed phrase in a local storage device of the user device; decrypting the encrypted string seed phrase using the UUID as a decryption key and generating the string seed phrase; recovering the first blockchain private key on the first blockchain using the string seed phrase; signing the first blockchain transaction on the first blockchain using the first blockchain private key; and deleting the first blockchain private key after signing the first blockchain transaction.

[0092] Clause 18. The non-transitory computer-readable medium of clause 17, which, when executed by one or more processors, is further configured to perform operations comprising: determining a state of the blockchain session, wherein the state of the blockchain session is terminated; and deleting the encrypted string seed phrase from a local storage device on the user device.

[0093] Clause 19. The non-transitory computer-readable medium of Clause 18, wherein the blockchain session is terminated by closing the user interface, displaying a lock screen on the user device, or expiration of a predetermined timeout period associated with the blockchain session.

[0094] Clause 20. The non-transitory computer-readable medium of clauses 17 to 19, which, when executed by one or more processors, is further configured to perform operations comprising: recovering the first blockchain private key by requesting the first blockchain private key with the string seed phrase from a hierarchical deterministic wallet, wherein the hierarchical deterministic wallet is associated with at least the first blockchain and a second blockchain; and requesting a second blockchain private key with the string seed phrase from the hierarchical deterministic wallet associated with the second blockchain, wherein the second blockchain private key is associated with the master private key, and wherein the first blockchain is different from the second blockchain.

[0095] The foregoing detailed description has been described by using block diagrams, flow charts and / or examples to illustrate various forms of systems and / or processes. To the extent that such block diagrams, flow charts and / or examples contain one or more functions and / or operations, those skilled in the art will understand that each function and / or operation within such block diagrams, flow charts and / or examples can be implemented individually and / or collectively by a wide range of hardware, software, firmware or virtually any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein can be equivalently implemented in whole or in part in an integrated circuit as one or more computer programs running on one or more computers (e.g., one or more programs running on one or more computer systems), one or more programs running on one or more processors (e.g., one or more programs running on one or more microprocessors), firmware or almost any combination thereof, and that according to the present disclosure, designing circuit systems and / or writing software and / or firmware codes will be completely within the skills of those skilled in the art. In addition, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed in various forms as one or more program products, and that the illustrative forms of the subject matter described herein are applicable regardless of the specific type of signal-bearing media used to actually perform the distribution.

[0096] Instructions for programming logic to perform various disclosed aspects can be stored in a memory in the system, such as a dynamic random access memory (DRAM), a cache, a flash memory, or other storage device. In addition, instructions can be distributed over a network or by means of other computer-readable media. Therefore, a machine-readable medium may include any mechanism for storing or transmitting information in a machine (e.g., computer) readable form, but is not limited to a floppy disk, an optical disk, a read-only compact disk memory (CD-ROM) and a magneto-optical disk, a read-only memory (ROM), a random access memory (RAM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic card or an optical card, a flash memory, or a tangible machine-readable storage device for transmitting information on the Internet via electrical, optical, acoustic, or other forms of propagation signals (e.g., carrier waves, infrared signals, digital signals, etc.). Therefore, a non-transitory computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a machine (e.g., computer) readable form.

[0097] Any software component or function described in this application can be implemented as a software code executed by a processor using any suitable computer language (e.g., Python, Java, C++, or Perl), using, for example, conventional or object-oriented techniques. The software code can be stored as a series of instructions or commands on a computer-readable medium, such as RAM, ROM, magnetic media (e.g., hard disk or floppy disk), or optical media (e.g., CD-ROM). Any such computer-readable medium can reside on or within a single computing device, and can exist on or within different computing devices within a system or network.

[0098] As used in any aspect of this document, the term "logic" may refer to an application, software, firmware, and / or circuitry configured to perform any of the foregoing operations. Software may be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-transitory computer-readable storage medium. Firmware may be embodied as code, instructions, instruction sets, and / or data hard-coded (e.g., non-volatile) in a memory device.

[0099] As used in any aspect of this document, the terms "component," "system," "module" and the like may refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution.

[0100] As used in any aspect of this document, an "algorithm" refers to a self-consistent sequence of steps leading to a desired result, where a "step" refers to manipulations of physical quantities and / or logical states, which may (but need not necessarily) take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, and otherwise manipulated. Common usage refers to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. These and similar terms may be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.

[0101] The network may include a packet switching network. The communication devices may be able to communicate with each other using a selected packet switching network communication protocol. An exemplary communication protocol may include an Ethernet communication protocol, which may allow communication using a transmission control protocol / Internet protocol (TCP / IP). The Ethernet protocol may conform to or be compatible with the Ethernet standard entitled "IEEE 802.3 Standard (IEEE 802.3Standard)" issued by the Institute of Electrical and Electronics Engineers (IEEE) in December 2008 and / or subsequent versions of this standard. Alternatively or additionally, the communication devices may be able to communicate with each other using an X.25 communication protocol. The X.25 communication protocol may conform to or be compatible with a standard promulgated by the International Telecommunication Union-Telecommunication Standardization Sector (ITU-T). Alternatively or additionally, the communication devices may be able to communicate with each other using a frame relay communication protocol. The frame relay communication protocol may conform to or be compatible with standards promulgated by the Consultative Committee for International Telegraph and Telephone (CCITT) and / or the American National Standards Institute (ANSI). Alternatively or additionally, the transceivers may be capable of communicating with each other using an asynchronous transfer mode (ATM) communication protocol. The ATM communication protocol may conform to or be compatible with the ATM standard entitled "ATM-MPLS Network Interworking 2.0" issued by the ATM Forum in August 2001 and / or subsequent versions of this standard. Of course, different and / or developed connection-oriented network communication protocols are also contemplated herein.

[0102] Unless expressly noted in the foregoing disclosure, it should be understood that throughout this disclosure, discussions using terms such as "processing," "computing," "calculating," "determining," "displaying," etc. refer to actions and processes of a computer system or similar electronic computing device that manipulates data represented as physical (electronic) quantities within the computer system registers and memories and transforms it into other data similarly represented as physical quantities within the computer system memories or registers or other such information storage, transmission, or display devices.

[0103] One or more components may be referred to herein as "configured to," "configurable to," "operable / operable," "suitable / adaptable to," "capable of," "compliant / compliant with," etc. Unless the context requires otherwise, those skilled in the art will recognize that "configured to" may generally encompass active state components and / or inactive state components and / or standby state components.

[0104] Those skilled in the art will recognize that, in general, the terms used herein, and especially in the appended claims (e.g., the bodies of the appended claims) are generally intended to be "open-ended" terms (e.g., the term "including" should be interpreted as "including but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "including but not limited to," etc.). Those skilled in the art will further understand that if a specific number of an introduced claim recitation is intended, such intent will be explicitly recited in the claim, and in the absence of such recitation, no such intent is present. For example, to aid understanding, the following appended claims may contain the use of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be interpreted as implying that introducing a claim recitation by the indefinite article "a" or "an" limits any particular claim containing such introduced claim recitation to claims containing only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" and an indefinite article such as "a" or "an" (e.g., "a" and / or "an" should generally be interpreted as meaning "at least one" or "one or more"); the same holds true for the use of definite articles used to introduce claim recitations.

[0105] In addition, even if a specific number of an introduced claim recitation is explicitly recited, one skilled in the art will recognize that such recitation should generally be interpreted as meaning at least the recited number (e.g., the simple recitation "two recitations" without other modifiers generally means at least two recitations, or two or more recitations). In addition, where a convention similar to "at least one of A, B, and C, etc." is used, generally, such a structure is intended to be presented in a manner that one skilled in the art will understand the meaning of the convention (e.g., "a system having at least one of A, B, and C" will include, but is not limited to, systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). Where a convention similar to "at least one of A, B, or C, etc." is used, generally, such a structure is intended to be presented in a manner that one skilled in the art will understand the meaning of the convention (e.g., "a system having at least one of A, B, or C" will include, but is not limited to, systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). Those skilled in the art will further understand that, generally, unless the context indicates otherwise, separate words and / or phrases presenting two or more alternative terms, whether in the specification, claims or drawings, should be understood to include the possibility of one of the terms, any of the terms, or both of the terms. For example, the phrase "A or B" will generally be understood to include the possibility of "A" or "B" or "A and B".

[0106] With respect to the appended claims, it will be understood by those skilled in the art that the operations described therein may be performed in any order in general. Moreover, although various operational flow charts are presented in order, it should be understood that various operations may be performed in other orders than those shown, or various operations may be performed simultaneously. Unless the context otherwise provides, examples of such alternative orderings may include overlapping, interlaced, interrupted, reordered, incremental, preparatory, supplementary, simultaneous, inverted, or other variant orderings. In addition, unless the context otherwise provides, terms such as "in response to," "related to," or other past tense adjectives are generally not intended to exclude such variants.

[0107] It is worth noting that any reference to "one aspect," "an aspect," "an example," "an example," etc. means that a particular feature, structure, or characteristic described in conjunction with the aspect is included in at least one aspect. Thus, the phrases "in one aspect," "in an aspect," "in an example," and "in an example" appearing in various places throughout the specification are not necessarily all referring to the same aspect. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.

[0108] As used herein, the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise.

[0109] Any patent application, patent, non-patent disclosure or other public material cited in this specification and / or listed in any application data sheet is incorporated herein by reference so that the incorporated material is not inconsistent therewith. As such, and to the extent necessary, the disclosure as explicitly set forth herein supersedes any conflicting material incorporated herein by reference. Any material or portion thereof that is referred to as incorporated herein by reference but conflicts with existing definitions, statements or other public materials set forth herein will be incorporated only to the extent that there is no conflict between the incorporated material and the existing public materials. It is not an admission that they are prior art.

[0110] In summary, many benefits have been described that result from adopting the concepts described herein. The foregoing description of one or more forms has been presented for the purpose of illustration and description. It is not intended to be exhaustive or limited to the exact form disclosed. In view of the above teachings, modifications or variations may be made. The one or more forms have been selected and described to illustrate the principles and practical applications, thereby enabling a person of ordinary skill in the art to utilize various forms and make various modifications suitable for the particular use under consideration. The claims submitted herein are intended to define the overall scope.

Claims

1. A method, include: receiving, by a processor, user credentials and an account identifier from a user interface of a user device; transmitting, by the processor, the user credentials to an authentication server; receiving, by the processor, a refresh token based on authentication of the user credentials by the authentication server; generating, by the processor, a unique user identifier (UUID) based on the refresh token for the user credentials; generating, by the processor, a seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least n bits; determining, by the processor, a master private key, wherein the master private key is derived from the seed phrase, and wherein a first blockchain private key is associated with the master private key; converting, by the processor, the seed phrase based on a predetermined word list, into a string seed phrase, the number of words in the string seed phrase being proportional to the at least n bits; encrypting, by the processor, the string seed phrase using the UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting, by the processor, the encrypted string seed phrase and the account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; as well as The UUID is deleted from the local cache by the processor.

2. The method according to claim 1, further comprising: include: Receiving, by the processor, a request to execute a first blockchain transaction; determining, by the processor, the UUID based on the refresh token and the account identifier of the user credential; transmitting, by the processor, a request for the encrypted string seed phrase to the external storage location, wherein the request includes the account identifier; receiving, by the processor, the encrypted string seed phrase; Establishing, by the processor, a blockchain session; storing, by the processor, the encrypted string seed phrase in a local storage device of the user device; decrypting the encrypted string seed phrase by the processor using the UUID as a decryption key and generating the string seed phrase; Recovering, by the processor, the first blockchain private key on the first blockchain using the string seed phrase; as well as The processor signs the first blockchain transaction on the blockchain using the first blockchain private key.

3. The method according to claim 2, further comprising: include: determining, by the processor, a state of the blockchain session, wherein the state of the blockchain session is terminated; as well as The encrypted string seed phrase is deleted, by the processor, from the local storage on the user device.

4. The method of claim 3, wherein the blockchain session is terminated by closing the user interface, displaying a lock screen on the user device, or expiration of a predetermined timeout period associated with the blockchain session.

5. The method of claim 2, wherein recovering the first blockchain private key is include: requesting, by the processor, the first blockchain private key having the string seed phrase from a hierarchical deterministic wallet associated with the blockchain; as well as The first blockchain private key is received, by the processor, from the hierarchical deterministic wallet.

6. The method of claim 1, wherein the seed phrase is at least 128 bits and the string seed phrase is at least 12 words.

7. The method of claim 1, wherein the seed phrase is at least 256 bits and the string seed phrase is at least 24 words.

8. The method of claim 1, further comprising: include: The UUID is restricted, by the processor, to local transmission within a software development kit on the user device, wherein the UUID is blocked from transmission to external devices.

9. A system, include: Account authentication server; Encryption platform server; A user device comprising one or more processors, wherein the user device is communicatively coupled to the account authentication server and the cryptographic platform server, and wherein the user device is configured to: receiving user credentials and an account identifier from a user interface of a user device; transmitting the user credentials to an authentication server; receiving a refresh token based on authentication of the user credentials by the authentication server; generating a unique user identifier (UUID) based on the refresh token of the user credentials; generating a seed phrase, the seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least 128 bits; determining a master private key, wherein the master private key is derived from the seed phrase, and wherein a first blockchain private key is associated with the master private key; converting the seed phrase into a string seed phrase based on a predetermined word list, wherein the string seed phrase is at least 12 words; encrypting the string seed phrase using the UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting the encrypted string seed phrase and the account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; and Delete the UUID from the local cache.

10. The system of claim 9, wherein the user device is further configured to: Receiving a request to execute a first blockchain transaction; determining the UUID based on the refresh token and the account identifier of the user credentials; transmitting a request for the encrypted string seed phrase to the external storage location, wherein the request includes the account identifier; Receiving the encrypted string seed phrase; Establish a blockchain session; storing the encrypted string seed phrase in a local storage device of the user device; Decrypting the encrypted string seed phrase using the UUID as a decryption key and generating the string seed phrase; requesting the first blockchain private key having the string seed phrase from a hierarchical deterministic wallet associated with a blockchain; Recovering the first blockchain private key from the hierarchical deterministic wallet; and The first blockchain transaction on the blockchain is signed using the first blockchain private key.

11. The system of claim 10, wherein the user device is further configured to: determining a state of the blockchain session, wherein the state of the blockchain session is terminated; and The encrypted string seed phrase is deleted from local storage on the user device.

12. The system of claim 11, wherein the blockchain session is terminated by closing the user interface, displaying a lock screen on the user device, or expiration of a predetermined timeout period associated with the blockchain session.

13. The system of claim 10, wherein the user device is further configured to: receiving a request to execute a second blockchain transaction, wherein the second blockchain transaction is executed in the blockchain session and wherein the blockchain session is still active from the first blockchain transaction; Decrypting the encrypted string seed phrase using the UUID as the decryption key and generating the string seed phrase; requesting the first blockchain private key having the string seed phrase from the hierarchical deterministic wallet associated with the blockchain; Recovering the first blockchain private key from the hierarchical deterministic wallet; Using the first blockchain private key to sign the first blockchain transaction on the blockchain; and The first blockchain private key is deleted after signing the second blockchain transaction.

14. The system of claim 13, wherein a value of the first blockchain private key recovered from the hierarchical deterministic wallet for the first blockchain transaction is different from a value of the first blockchain private key recovered from the hierarchical deterministic wallet for the second blockchain transaction.

15. The system of claim 9, wherein the user device is further configured to: The UUID is restricted to local transmission within a software development kit on the user device, wherein the UUID is blocked from transmission to external devices.

16. A non-transitory computer readable medium having instructions stored thereon, the instructions, when executed by one or more processors, causing the one or more processors to perform operations, the operations include: receiving user credentials and an account identifier from a user interface of a user device; transmitting the user credentials to an authentication server; receiving a refresh token based on authentication of the user credentials by the authentication server; generating a unique user identifier (UUID) based on the refresh token of the user credentials; generating, by the processor, a seed phrase, wherein the seed phrase is randomly generated by a pseudo-random number generator, and wherein the seed phrase is at least n bits; determining a master private key, wherein the master private key is derived from the seed phrase, and wherein a first blockchain private key is associated with the master private key; converting the seed phrase into a string seed phrase based on a predetermined word list, the number of words in the string seed phrase being proportional to the at least n bits; encrypting the string seed phrase using the UUID, wherein the UUID is an encryption key used to generate an encrypted string seed phrase from the string seed phrase; transmitting the encrypted string seed phrase and the account identifier to an external storage location, wherein the external storage location stores the encrypted string seed phrase and the account identifier associated with the user; as well as The UUID is deleted from the local cache by the processor.

17. The non-transitory computer readable medium of claim 16, which when executed by one or more processors is further configured to perform operations, the operations include: Receiving a request to execute a first blockchain transaction on a first blockchain; determining the UUID based on the refresh token and the account identifier of the user credentials; transmitting a request for the encrypted string seed phrase to the external storage location, wherein the request includes the account identifier; Receiving the encrypted string seed phrase; Establish a blockchain session; storing the encrypted string seed phrase in a local storage device of the user device; Decrypting the encrypted string seed phrase using the UUID as a decryption key and generating the string seed phrase; Recovering the first blockchain private key on the first blockchain using the string seed phrase; Using the first blockchain private key to sign the first blockchain transaction on the first blockchain; and The first blockchain private key is deleted after signing the first blockchain transaction.

18. The non-transitory computer readable medium of claim 17, which when executed by one or more processors is further configured to perform operations, the operations include: determining a state of the blockchain session, wherein the state of the blockchain session is terminated; as well as The encrypted string seed phrase is deleted from local storage on the user device.

19. The non-transitory computer-readable medium of claim 18, wherein the blockchain session is terminated by closing the user interface, displaying a lock screen on the user device, or expiration of a predetermined timeout period associated with the blockchain session.

20. The non-transitory computer readable medium of claim 17, which when executed by one or more processors is further configured to perform operations, the operations include: recovering the first blockchain private key by requesting the first blockchain private key having the string seed phrase from a hierarchical deterministic wallet, wherein the hierarchical deterministic wallet is associated with at least the first blockchain and a second blockchain; as well as Requesting a second blockchain private key having the string seed phrase from the hierarchical deterministic wallet associated with the second blockchain, wherein the second blockchain private key is associated with the master private key, and wherein the first blockchain is different from the second blockchain.

Citation Information

Patent Citations

  • Migrating authenticated content towards content consumer

    CN106375321A

  • Film card with blockchain digital currency wallet function

    CN110633778A

  • Security authentication method and device based on two-dimensional code, and storage medium

    CN113515738A

  • System and method for improving electron transfer of resources via blockchain

    CN114793455A

  • Symmetrical key establishing using public key encryption

    CN1507733A