Systems and methods for signing transactions using air gap private keys

By designing a system including the first module, the second module and the bridge module, the inconvenience of information transmission between the air gap computer and the remote entity is solved, safe and convenient transaction signing on the virtual air gap is realized, and the security and ease of use of the electronic wallet are improved.

CN120494826APending Publication Date: 2025-08-15BITFORD CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510571935.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2018-07-21
Filing Date
2019-07-12
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, information transmission between an air gap computer and a remote entity is labor-intensive and inconvenient, especially in electronic wallet applications, which requires two independent devices, which are inconvenient and inconvenient enough.

Method used

A system including a first module, a second module and a bridge module is designed. The first module is responsible for communicating with the public network, the second module is responsible for transaction authorization and generating a private key. The bridge module is used to selectively connect the two, ensure safe isolation through the SPDT switch, and generate seed words and private keys using biometric data and random number generators.

Benefits of technology

It realizes convenient and secure signing of transactions on virtual air gaps, avoids the need for independent devices, and improves the security and ease of use of electronic wallets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120494826A_ABST
    Figure CN120494826A_ABST
Patent Text Reader

Abstract

The invention relates to a system and method for signing transactions using an air gap private key. A system for signing a transaction, the system comprising a first module having: a communication interface with a public network; and a controller configured to process transactions with a blockchain network or a transaction server accessible at the public network. The system also includes a second module having: a random number generator; and a security controller for generating a seed word and a private key. The system also includes a bridge module having: a controller; and a switch for selectively connecting the data interface of the bridge module to the data interface of the first module or the data interface of the second module such that the data interface of the first module is never connected to the data interface of the second module.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application with the application date of July 12, 2019, application number 2019800488285, and invention name “System and method for signing transactions using air-gapped private keys”. Technical Field

[0002] The present disclosure relates to systems and methods for signing transactions. In particular, from a user's perspective, the present disclosure relates to methods for creating an air gap in electronic devices when managing digitized assets such as cryptocurrencies or content stored on a blockchain (or similar system). Background Art

[0003] Air Gapping is a known procedure that involves isolating a computer machine from any network connection, or at least from a public network such as the Internet. In other words, air gapping, air walling, or air gapping is a network security measure employed on one or more computers to ensure that a secure computer network is physically isolated from an unsecured network such as the public Internet or an unsafe global area network.

[0004] As a result, an air-gapped computing machine is a closed system (in terms of information, signals, etc.) that is inaccessible to remote entities and can only be manually operated by a user (operator).

[0005] A disadvantage of forming an air gap is that transferring information between the air-gapped computing machine and the remote entity is labor-intensive, typically involving manual security analysis of the intended software application or data to be entered into the air-gapped machine, and possibly even manual re-entry of the data after the security analysis.

[0006] Furthermore, air-gapped machines are typically completely separate hardware systems that require operation and maintenance of two systems, which is inconvenient, particularly in the case of so-called electronic wallets, where, in addition to an electronic device or computer program serving as a wallet, a user must carry a separate air-gapped transaction signing device (e.g., a code-generating token that lacks network connectivity, or a secure cold-storage hardware wallet that stores private keys allowing access to blockchain-stored content or spending digitized assets such as cryptocurrencies).

[0007] US Patent No. 8,984,275 B2, titled "Virtual Air Gap (VAG) System," discloses a system comprising a virtual air gap, an internal safety component, an external safety component, a messaging mechanism for system components between the internal and external safety components, and shared memory. The internal system consists of the internal safety component and other components within the system that connect it to an internal network. The external system consists of the external safety component and other components within the system that connect it to an external network.

[0008] In view of the above, there is a need to design a system that is particularly useful for electronic wallet applications that will not require two separate devices and will be more convenient to use. There is also a need to provide an improved system and method for signing transactions over a virtual air gap. Summary of the Invention

[0009] The present invention relates to a system for signing transactions. The system includes a first module comprising: a communication interface to a public network; a controller configured to process transactions with a blockchain network or a transaction server accessible on the public network; and a data interface for communicating with the controller. The system also includes a second module comprising: a random number generator for generating a random sequence; a security controller configured to generate a seed word and a private key based on the random sequence generated by the random number generator, store the seed word and the private key, and sign transaction requests by generating signed transactions; and a data interface for communicating with the security controller. The system also includes a bridge module comprising: a controller; a data interface for communicating with the controller; and a switch configured to selectively connect the data interface of the bridge module to the data interface of the first module or the data interface of the second module, such that the data interface of the first module is never connected to the data interface of the second module. The controller is configured to receive a transaction request from the first module, pass the transaction request to the second module, receive a signed transaction from the second module and pass the signed transaction to the first module.

[0010] The switch may be a single pole double throw (SPDT) switch.

[0011] The security controller of the second module may also be configured to store biometric data.

[0012] The second module may include a biometric sensor configured to convert a biometric trace of a person into an electrical signal for transaction authorization.

[0013] The switch may also be configured to supply power to the second module only when the data interface of the bridge module is connected to the data interface of the second module.

[0014] The system may further include an erase module configured to call an erase function at the second module to delete the stored seed word and private key, and erase all transaction and financial data from the first module.

[0015] The second module may be integrated with the bridge module in a common housing.

[0016] The first module may be integrated with the second module and the bridge module in a common housing.

[0017] The data interface of the second module may include an input data buffer and an output data buffer.

[0018] The random number generator of the second module may be a hardware entropy generator.

[0019] The random number generator of the second module may be a software entropy generator.

[0020] The present invention also relates to a method for signing a transaction using the system for signing a transaction described herein. The method comprises the following steps: connecting the first module to the public network; establishing transaction details; receiving an acceptance that the transaction is to be authorized; sending the transaction request to the bridge module; disconnecting the first module from the bridge module; connecting the bridge module to the second module; sending the transaction request from the bridge module to the second module; authorizing the transaction via the second module; signing the transaction using the private key stored in the second module to generate a signed transaction; sending the signed transaction from the second module to the bridge module; disconnecting the second module from the bridge module; connecting the first module to the bridge module; sending the signed transaction from the bridge module to the first module; and sending the signed transaction from the first module to the blockchain network or to the transaction server.

[0021] The method may further include, when the user fails to authorize a transaction during a predefined number of consecutive attempts at the second module, invoking an erase function at the second module to delete the stored seed word and private key and erase all transaction and financial data from the first module. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] These and other objects set forth herein are achieved by providing a system and method for signing transactions over a virtual air gap using an air gap private key. Further details and features of the present disclosure, its nature and various advantages will become more apparent from the following detailed description of preferred embodiments illustrated in the accompanying drawings, in which:

[0023] Figure 1 A schematic diagram showing a first module of the Internet connection of the system proposed herein;

[0024] Figure 2 A schematic diagram showing the second module of the system proposed in this paper;

[0025] Figure 3 A bridge module operating between a first module and a second module is shown;

[0026] Figure 4 An overview of a system including a first module, a second module and a bridge is shown;

[0027] Figure 5 Shows the configuration Figure 4 a systematic process; and

[0028] Figure 6 A method of transaction authentication is shown.

[0029] Symbols and terminology

[0030] Some portions of the detailed description that follows are presented in terms of data processing flows, steps, or other symbolic representations of operations on data bits that can be performed on a computer memory. Accordingly, the computer performs such logical steps, which in turn require physical manipulations of physical quantities.

[0031] Typically, these quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, and otherwise manipulated in a computer system. Due to common usage, these signals are referred to as bits, packets, messages, values, elements, symbols, characters, terms, numbers, or the like.

[0032] Additionally, all of these and similar terms will be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. Terms such as "process" or "create" or "transmit" or "execute" or "determine" or "detect" or "obtain" or "select" or "calculate" or "generate" refer to the actions and processes of a computer system that manipulates data represented as physical (electronic) quantities in computer registers and memories and transforms it into other data similarly represented as physical quantities in memories or registers or other such information storage devices.

[0033] Computer-readable (storage) media as referred to herein may generally be and / or include non-transient devices. In this context, non-transient storage media may include devices that may be tangible, meaning that the device has a specific physical form, although the device may change its physical state. Thus, for example, non-transient refers to a device that remains tangible despite changes in state.

[0034] As used herein, the term "example" means serving as a non-limiting example, instance, or illustration. As used herein, the terms "for example" and "eg" introduce one or more non-limiting examples, instances, or illustrations. DETAILED DESCRIPTION

[0035] The system proposed in this paper has the following features: Figure 4 The general structure shown can be specifically configured to provide efficient, convenient and fast real-time payments using cryptocurrencies (electronic wallets for cryptocurrencies), or can be configured to sign, upload or access content stored on a distributed leader based on blockchain (or similar systems), for example without the need for external devices to sign transactions while providing security measures typical of air-gapped machines.

[0036] The system is particularly suitable for cryptocurrencies, but can also be used in e-wallets for ordinary currencies (such as euros, dollars), especially when tokenized on a blockchain-based ledger or similar system.

[0037] The system can be implemented using dedicated components or custom FPGA (field programmable gate array) or ASIC (application-specific integrated circuit) circuits.

[0038] Figure 1 A schematic diagram of the system's first module 100 is shown, connected to the internet (or, more generally, any public network). This module is responsible for communicating with any external services involved in processing payments or transactions using cryptocurrencies or other services based on blockchain (or similar systems). In other words, it is a communication module.

[0039] The first module 100 includes a data bus 101 communicatively coupled to a flash memory 104. Additionally, other components of the system are communicatively coupled to the data bus 101 so that they can be efficiently managed by a controller 105.

[0040] The flash memory 104 may store one or more computer programs executed by the controller 105 to perform the steps of the method described below. In addition, the flash memory 104 may store configuration parameters of the first module 100.

[0041] The communication interface module(s) 102 (eg, Wi-Fi, GSM, 3G, LTE, NFC, etc.) is configured to manage communications with external public networks. The communication module 102 may have a dedicated on / off switch so that the user can personally control its operation.

[0042] The controller 105 can be a system-on-chip, which includes: a graphics processing unit (GPU) 105A, which is a dedicated electronic circuit designed to quickly manipulate and change memory to accelerate the creation of images in a frame buffer, which are intended to be output to a display device; a random access memory (RAM) 105B, a central processing unit (CPU) 105C, which is an electronic circuit within a computer that executes the instructions of a computer program by performing basic arithmetic, logic, control, and input / output (I / O) operations specified by the instructions; and a data interface 105D, which is responsible for sending data to and / or receiving data from other components of the first module 100.

[0043] Typically, the first module 100 is configured to establish communication with a remote server (e.g., a server of an electronic service provider), an electronic banking system, or a distributed leadership and network based on blockchain (or similar systems) via the communication interface 102 to allow users to establish transactions that are securely confirmed once the transaction is ready.

[0044] Optionally, the first module may include a camera 103 configured to obtain and process an image, such as an image of a QR code that can serve as a container for specifying transaction data, so that the user does not have to manually insert or otherwise define specific variables for the transaction. The camera 103 may have a dedicated on / off switch so that the user can personally control its operation.

[0045] Data may be transferred in encrypted form between the modules 100 and 300 via I2C (Inter-Integrated Circuit) or SPI (Serial Peripheral Interface) or another proprietary interface through the data interface 106 allowing access to the data bus 101 .

[0046] The first module 100 may be implemented by creating a dedicated device. Alternatively, the components of the first module 100 may be implemented by adapting a typical smartphone or similar device to configure its modules to operate as described above.

[0047] Figure 2 A schematic diagram of the second module 200 of the system proposed herein is shown. The second module 200 is responsible for transaction authorization and is never connected to a public network (such as the Internet, or even to any network at all).

[0048] The system includes a data bus 201 communicatively coupled to a ROM memory 202, which stores an operating system for the second module 200 (which cannot be easily modified because it is stored in ROM) and, optionally, an authorization key for verifying the authenticity of the software in the bridge module 300, for example, to prevent hacker attack attempts based on modification of the software in the bridge module 300. In addition, other components of the system are communicatively coupled to the data bus 201 so that they can be managed by a security controller 205.

[0049] The second module 200 may also include (optionally) a biometric sensor 203 configured to convert a person's biometric traces into electrical signals. Biometric traces primarily include biometric fingerprint data, iris data, facial images, voice samples, etc. This data can serve as an additional transaction authorization mechanism.

[0050] The random number generator 204 is a true random number generator that is configured to generate a statistically random sequence of random numbers, i.e., without any specific or distinguishable features, and without a generation scheme. These random sequences are used to encrypt data and generate seed words (dictionary words) used to generate private keys. Preferably, the random number generator 204 is a hardware entropy generator. Random numbers can also be generated by a computer program rather than a separate chip (i.e., a software entropy generator).

[0051] The security controller 205 is configured to manage the components of the second module 200, particularly authorizing secure transactions. The security controller 205 includes a processor 205A, flash memory 205B, and operating RAM 205C. It stores private keys and biometric data—all the elements required to authorize secure transactions. The private key may be encrypted, with decryption requiring biometric authentication using reference biometric data stored in the flash memory 205B and biometric data read from a biometric sensor, such as the biometric sensor 203. The data interface 205D is responsible for sending and / or receiving data to and from the other components of the second module 200.

[0052] Data can be transferred between modules 200 and 300 via a data interface, preferably in the form of data buffers 206, 207 configured to communicate with an interface 309 of the bridge module 300 via an SPDT switch 310. The input buffer 206 is accessible by the second module to read data therefrom and by the bridge module to store data therein. The output buffer 207 is accessible by the second module to store data therein and by the bridge module to read data therefrom. Each of the data buffers 206, 207 may include its own internal processing unit, flash memory, and a data interface for handling communications with the data bus 201 and the safety controller 205, as well as with the data interface 309 of the bridge module 300 via the SPDT switch 310.

[0053] The second module 200 can be implemented using dedicated components or customized FPGA or ASIC circuits. The second module 200 and the bridge module 300 are preferably integrated in a common housing to form a dedicated device that can be connected to the first module (only via the bridge module) via an external interface (e.g., a USB interface) (in this case, the first module functionality can be provided by an application installed on a general-purpose device such as a smartphone or laptop). Alternatively, all modules 100, 200, 300 can be integrated in a common housing to form a fully functional device.

[0054] Figure 3 A bridge module 300 is shown operating between the first module 100 and the second module 200. The purpose of the bridge module 300 is to formulate and pass transaction requests from the first module 100 to the second module 200, and to receive signed transactions or rejections of transactions.

[0055] The bridge module 300 integrated with the second module 200 may be implemented using dedicated components or custom FPGA or ASIC circuits. The modules 200, 300 may constitute additional modules connectable to the first module 100 or may be integrated with the first module 100.

[0056] The bridge module 300 includes a data bus 301 communicatively coupled to a memory 303. Additionally, other components of the system are communicatively coupled to the data bus 301 so that they can be managed by a controller 305.

[0057] Data may be transferred at a given time between the first module 100 and the bridge 300 or between the second module 200 and the bridge 300. For maximum safety, the system is configured so that it is not possible to have all three modules 100, 200, 300 active at any one time, using a SPDT switch 310 that controls the data transfer and optionally also the power supply.

[0058] Controller 305 may be a system on a chip that includes the same or similar subcomponents as controller 105 .

[0059] An on / off switch 304 is configured to switch the device on or off when operated by a user.Other typical components include a display 306, which is preferably a touch sensitive display, and a speaker 302, which forms part of the means for communicating with the user.

[0060] The bridge module 300 is preferably powered by a battery 307, as it is intended to operate as a mobile device. Typical battery charging means, such as wireless charging (e.g., according to the Qi standard) as well as a typical plug charger connection, may also be present in the power supply 307 of the bridge module 300. A BMS (Battery Management System) module 308 is configured to manage battery charging, discharging, and overall operation in order to maintain a long battery life.

[0061] The bridge module 300 comprises a data interface 309 configured to communicate with the interface 106 of the first module 100 or with the data buffers 206 , 207 of the second module 200 via a SPDT switch 310 .

[0062] The SPDT (single pole double throw) switch module 310 is configured to provide power and data transmission capabilities to only one of the modules at a time, either the first module 100 or the second module 200. Module 310 may include two SPDT switches, one for power and the other for data transmission, which are always switched together by a single actuator. Fully disconnecting the first module, or at least its communication interface(s) 102, from the power supply via a hardware switch provides an additional level of security from intruders or malware, as intruders or malware cannot access the second module and cannot tamper with transaction requests to be signed by the second module.

[0063] Other types of switch modules may be used instead of the SPDT switch as long as they provide the function that the data interface 106 of the first module 100 is never connected to the data interfaces 206 , 207 of the second module 200 .

[0064] Figure 4 An overview of a system comprising a first module 100, a second module 200 and a bridge module 300 is shown, wherein the bridge module 300 is selectively connected to either the first module 100 or the second module 200 at any given time via a SPDT switch 310. The SPDT switch 310 controls the transmission of data and the supply of power (at least to the second module).

[0065] A wipe module 401 may also optionally be present in the system and configured to immediately invoke a "wipe device" function for security reasons. Once the wipe module 401 is activated, the second module is activated and a command is sent to the second module to delete the private key, seed word, and biometric data from it, thereby restoring its factory settings without personalized data. Next, the first module is activated, and the transaction history, contact addresses, and any other address or financial data are removed. The wipe module 401 can take the form of a dedicated "panic button." Alternatively, the wipe module 401 can be activated by the user pressing a specific sequence of other buttons.

[0066] Therefore, the system 400 is able to solve the transaction security problem by being divided into at least three modules: a first module 100, a second module 200, and a bridge module 300. The bridge module 300 allows information to be transferred between the modules 100 and 200 and allows them to operate independently of each other. The second module 200 is configured to use a private key (specifically by providing a password or PIN code or biometric data, etc.) to authorize and sign transactions when never connected to a public network (such as the Internet).

[0067] In particular, the second module 200 is never connected to the public network, because the bridge module 300 can be connected to either the first module 100 or the second module 200 at any given time. Therefore, it is impossible for a remote entity (a hacker or a machine operating spyware) to capture authorized data from the device proposed herein. The first module 100 also does not have any form of access to the data and content of the second module 200.

[0068] Figure 5The configuration process of system 400 is shown. In step 501, when the first module is shut down, system 400 remains disconnected from the public network. Next, in step 502, a method for authenticating the user is selected, such as a PIN, password, biometric scan, etc. The authentication parameters and associated response are stored in the security controller 205 of the second module 200. Subsequently, in step 503, a keyword (seed) sequence is generated according to known methods, particularly those related to handling deterministic wallets for cryptocurrency. This seed can be used to restore access to the device when the private key has been reset. For example, the second module 200 may include a dictionary within the ROM memory 202, such as in accordance with the BIP-39 standard, which allows for random generation of keyword sequences. The keyword sequence can include up to 24 or 36 keywords, mitigating the risk of two devices having the same random keyword sequence. Next, in step 504, a private key or key set is generated based on the seed. The private key(s) and keyword sequence are stored 505 in the flash memory of the security controller 205 of the second module 200. They may be additionally encrypted using a password, PIN, or biometric trace to ensure an increased level of device security. In the implementation Figure 5 After the process, the system 400 can configure and start the connection of the first module 100 and the communication module 102 with an external public network such as the Internet.

[0069] Figure 6 The method for performing transaction authentication using the device proposed herein is shown. First, in step 601, the second module 200 is turned on, and in step 602, the user authorizes access to the device by entering a password, PIN, or biometric data to allow further access to the device. If the entered password is approved, the second module 200 is turned off and the first module 100 is turned on.

[0070] Next, at step 604, the first module 100 connects to a public network (e.g., an online service, a bank, a currency exchange service, a blockchain network, an Internet network), and establishes transaction details (e.g., recipient data, purpose, etc.) at step 605, and gives the transaction amount at step 606. To this end, a remote server of the external public network or an application installed at the first module 100 will typically provide a suitable user interface that allows input of any relevant information required to establish the transaction.

[0071] Next, in step 607, the so-called mining fee, which is typical in cryptocurrencies (in the case of conventional currencies, other transaction fees may be determined at this step) may be determined. Subsequently, in step 608, the user may confirm (the first module 100 receives confirmation from the user) that the transaction has been correctly defined and that the transaction will be authorized.

[0072] If the user wishes to authorize the transaction, the first module 100, having the transaction details, sends a transaction request to the bridge module at step 609 and disconnects from the public network at step 610. The first module 100 is then also communicatively disconnected from the bridge via the SPDT switch 310.

[0073] Next, the second module 200 is turned on in step 611 (using the SPDT switch 310) and receives the transaction request from the bridge module in step 612. In step 613, the user authorizes the transaction via the second module 200 using input data such as a password, PIN, and / or biometric data. Before providing their credentials, the user will have the opportunity to review the transaction details again in the second module mode, as they will be displayed on the screen. This is therefore an additional layer of security that can be summarized as "what you see (sign) is what you get (transaction)." As already discussed, authorization occurs when the device is disconnected from the external public network and the first module cannot access any data.

[0074] Furthermore, the transaction is signed using the private key stored in the security controller 205 of the second module at step 614. Next, at step 615, the second module 200 sends the signed transaction to the bridge module 300.

[0075] Then, in step 616, the second module 200 is turned off, and the first module 100 is turned on and connected to the public network via the communication interface 102. The bridge module 300 sends the signed transaction to the first module 100 in step 617, and in step 618, the first module 100 sends the signed transaction to the blockchain network or a remote server.

[0076] Optionally, when the user fails to authorize the transaction during a predefined number of consecutive attempts (e.g., 3 or 5 attempts), the second module may perform an erase operation as discussed with respect to the functionality of the erase module 401 and await a new activation using the aforementioned keyword sequence (see Figure 5 ).

[0077] The proposed method and system allow to improve the security of electronic wallets without compromising the ease of use. Thus, they provide a useful, concrete and tangible result.

[0078] According to the present disclosure, a device is proposed that is responsible for the secure storage of private keys for accessing and performing transactions with electronic currencies (e.g., cryptocurrencies and other blockchain-based or stored content). Thus, a machine or conversion test is completed, and this idea is not abstract.

[0079] At least a portion of the methods disclosed herein can be computer-implemented. Thus, the system can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, which are generally referred to herein as "circuits," "modules," or "systems."

[0080] Furthermore, the present system may take the form of a computer program product embodied in any tangible medium of expression having computer usable program code embodied in the medium.

[0081] Those skilled in the art will readily appreciate that the aforementioned method for signing transactions via a virtual air gap can be executed and / or controlled by one or more computer programs. Such computer programs are typically executed by utilizing computing resources in a computing device. The application is stored on non-transitory media. An example of a non-transitory medium is non-volatile memory, such as flash memory, while an example of a volatile memory is RAM. The computer instructions are executed by a processor. These memories are exemplary recording media for storing computer programs containing computer-executable instructions that perform all steps of the computer-implemented method according to the technical concepts presented herein.

[0082] Although the systems and methods presented herein have been depicted, described, and defined with reference to certain preferred embodiments, such references and examples in the foregoing description do not imply any limitation upon the methods or systems. However, it will be apparent that various modifications and variations may be made thereto without departing from the broader scope of the technical concepts presented herein. The preferred embodiments presented are merely exemplary and do not exhaust the scope of the technical concepts presented herein.

[0083] Therefore, the scope of protection is not limited to the preferred embodiments described in the specification, but only by the appended claims.

Claims

1. A system for signing a transaction, the system comprising: - A first module (100) comprising: - a communication interface (102) with a public network; - a controller (105) configured to process transactions with the blockchain network or a transaction server accessible on said public network; and - a data interface (106) for communicating with the controller (105); - A second module (200) comprising: - a random number generator (204) for generating a random sequence; - a security controller (205) configured to generate a seed word and a private key based on the random sequence generated by the random number generator, store the seed word and the private key, and sign the transaction request by generating a signed transaction; and - a data interface (206, 207) for communicating with the safety controller (205); - a bridging module (300) comprising: - a controller (305); - a data interface (309) for communicating with the controller (305); and a switch (210) configured to selectively connect the data interface (309) of the bridge module (300) to the data interface (106) of the first module (100) or the data interface (206, 207) of the second module (200), such that the data interface (106) of the first module (100) is never connected to the data interface (206, 207) of the second module (200); - wherein the controller (305) is configured to receive a transaction request from the first module (100), pass the transaction request to the second module (200), receive a signed transaction from the second module (200) and pass the signed transaction to the first module (100).

2. The system according to claim 1, wherein: The switch (310) is a single-pole double-throw (SPDT) switch.

3. A system according to any one of the preceding claims, wherein: The security controller (205) of the second module (200) is further configured to store biometric data.

4. A system according to any one of the preceding claims, wherein: The second module (200) includes a biometric sensor (203) configured to convert a person's biometric trace into an electrical signal for transaction authorization.

5. A system according to any one of the preceding claims, wherein: The switch (310) is further configured to supply power to the second module (200) only when the data interface (309) of the bridge module (300) is connected to the data interface (206, 207) of the second module (200).

6. The system according to any one of the preceding claims, further comprising an erase module (401) configured to call an erase function at the second module (200) to delete the stored seed words and private keys, and erase all transaction and financial data from the first module (100).

7. A system according to any one of the preceding claims, wherein: The second module (200) and the bridge module (300) are integrated in a common housing.

8. A system according to any one of the preceding claims, wherein: The first module (100), the second module (200) and the bridge module (300) are integrated in a common housing.

9. A system according to any one of the preceding claims, wherein: The data interface (206, 207) of the second module (200) includes an input data buffer (206) and an output data buffer (207).

10. The system according to any one of claims 1 to 9, wherein: The random number generator (204) of the second module is a hardware entropy generator.

11. The system according to any one of claims 1 to 9, wherein: The random number generator (204) of the second module is a software entropy generator.

12. A method for signing a transaction using a system according to any one of the preceding claims, the method comprising the steps of: - connecting (604) said first module (100) to said public network; - Establish (605, 606) transaction details; - receiving an acceptance that the transaction is to be authorized (608); - sending (609) the transaction request to the bridge module (300); - disconnecting (610) the first module (100) from the bridge module (300); - connecting (611) the bridge module (300) to the second module (200); - sending (612) the transaction request from the bridge module (300) to the second module (200); - authorizing (613) said transaction by said second module (200); - signing (614) the transaction using the private key stored in the second module (200) to generate a signed transaction; - sending (615) the signed transaction from the second module (200) to the bridge module (300); - disconnecting (616) the second module (200) from the bridge module (300); - connecting (616) said first module (100) to said bridge module (300); - sending (617) the signed transaction from the bridge module (300) to the first module (100); and - Sending (618) the signed transaction from the first module (100) to the blockchain network or to the transaction server.

13. The method according to claim 12 further includes, when the user does not authorize a transaction during a predefined number of consecutive attempts at the second module (200), calling an erase function at the second module (200) to delete the stored seed word and private key and erase all transaction and financial data from the first module (100).

Citation Information

Patent Citations

  • Virtual air gap—VAG system

    US8984275B2