Concept for accessing a cryptocurrency wallet on a remote server

CN122826587APending Publication Date: 2026-09-25SONY GROUP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202580017804.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-07
Filing Date
2025-03-04
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

然而,智能合约钱包可能被认为仍然对人為错误相当敏感(因此钱包所有者需要组织良好)

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122826587A_ABST
    Figure CN122826587A_ABST
Patent Text Reader

Abstract

Traditionally, private wallet keys are stored at a remote server hosting a cryptocurrency wallet. However, this can be problematic even with a Trusted Execution Environment (TEE) or secure enclave, especially because the service should be upgradable. Upgrading a TEE or secure enclave can involve manual procedures to hand over the master key to a new version of the secure enclave code when a new version is needed or desired. If these procedures are not followed, the operator of the service can gain access to all wallet keys. Storing all wallet keys permanently in a TEE or secure enclave can also make the service more vulnerable to attack. Accordingly, the present disclosure proposes storing wallet keys outside of a TEE / secure enclave, such as in storage circuitry of a wallet control device (client) or in cloud storage associated with an owner of a cryptocurrency wallet.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a concept for accessing a cryptocurrency wallet on a remote server, and specifically to a wallet control device, a wallet control method and a wallet control computer program, as well as a wallet service device, a wallet service method and a wallet service computer program. Background Technology

[0002] Cryptocurrency, or money that exists digitally and uses cryptography to secure transactions (e.g., on a blockchain), is a field of research and development. Cryptocurrency transactions typically involve the use of a so-called wallet, a computer program used to store and manage cryptographic secrets that can be used to sign cryptocurrency transactions. A cryptocurrency transaction on a blockchain is a digital event recording the transfer of cryptocurrency units from one address to another. This process is facilitated by blockchain technology, which acts as a decentralized distributed ledger. Each transaction is securely encrypted and needs to be verified and confirmed by network participants known as nodes or miners before being permanently added to the blockchain.

[0003] There are different categories of cryptocurrency wallets. The first type is called a "self-custodial wallet." In a self-custodial wallet, the wallet owner does not rely on a third party to store and operate the private keys that control the assets in the wallet. Different types of self-custodial wallets exist, such as hardware wallets (also known as cold storage), web or mobile wallets, and desktop wallets. Recovery of lost, stolen, or damaged devices can often be done using a recovery phrase (usually 24 words), which can be used to regenerate the keys. This recovery phrase must be stored in a secure location. Self-custodial wallets may be considered to have a high risk of permanent loss due to human error. One study suggests that over 20% of Bitcoin (a cryptocurrency) is permanently lost, for example, due to lost devices or human error. This contradicts the goal of making highly complex tasks easier for humans without requiring excessive mental effort or living in fear of constant mistakes.

[0004] The second type of wallet is called a "custodial wallet." When using a custodial wallet, the wallet owner delegates the private keys that store and control the assets in the wallet to a third party. Typically, these third parties (such as large trading markets) do not store assets in separate wallets, but rather hold them in a large pool. In this respect, the wallet is more like an account at a bank. However, custodial wallets can be vulnerable to large-scale attacks on custodial wallet providers. Furthermore, the risk of custodial wallet providers going bankrupt (sometimes due to large-scale attacks) is not negligible.

[0005] The third type of wallet is called a "smart contract wallet." Assets in a smart contract-based wallet are controlled by (Ethereum) smart contracts. Such smart contract wallets offer a variety of features, such as multi-signature authorization, rate limiting, social recovery (friends can help recover the wallet), and temporary locking. However, smart contract wallets may still be considered quite sensitive to human error (therefore, wallet owners need to be well-organized). Adaptation to concepts like smart contracts is growing.

[0006] There may be a need for an improved cryptocurrency wallet concept that reduces the risk for wallet owners. Summary of the Invention

[0007] This need is addressed by the subject matter of the appended claims.

[0008] According to the first aspect, this disclosure proposes a wallet control device external to a cryptocurrency wallet. This wallet control device is associated with the owner of the cryptocurrency wallet hosted in a Trusted Execution Environment (TEE) on a remote server. The wallet control device can be implemented as a portable user device, such as a smartphone, tablet PC, laptop PC, desktop PC, etc. A TEE (sometimes also called a "secure enclave") refers to a secure enclave within a remote server, designed to ensure that sensitive data is stored, processed, and protected in a secure environment. The TEE provides a degree of protection against software attacks and provides a secure execution space for confidential and critical operations. This secure enclave can be isolated from the rest of the remote server's operating system and applications in terms of processing and storage, ensuring that code and data loaded into the TEE are protected in terms of confidentiality and integrity.

[0009] The wallet control device includes processing circuitry configured to store information about at least one cryptographic secret associated with the cryptocurrency wallet and used (by the TEE) to sign transactions on the cryptocurrency blockchain in a memory associated with the wallet control device. The cryptographic secret associated with the cryptocurrency wallet and used (by the TEE) to sign transactions on the cryptocurrency blockchain can be a (private) wallet key or entropy, the wallet key being derived from entropy. Transactions may involve the transfer of cryptocurrency units from one wallet address to another. This process can be facilitated by a blockchain, which acts as a decentralized ledger recording all transactions on a computer network. The memory storing information about at least one cryptographic secret (e.g., wallet key, entropy value) can be internal memory of the wallet control device or external memory (e.g., cloud storage). The processing circuitry of the wallet control device is also configured to send the cryptographic secret (e.g., wallet key) from the wallet control device to a remote server for signing transactions on the cryptocurrency blockchain using that cryptographic secret.

[0010] In other words, wallet keys do not need to be stored in the cryptocurrency wallet or the TEE itself, but can be stored externally on the wallet control device or in cloud storage associated with the user / owner of the cryptocurrency wallet hosted in the TEE. This simplifies things like upgrading the TEE to a new version.

[0011] In some implementations, a cryptographic secret is the private key of a cryptocurrency wallet used to execute transactions on a cryptocurrency blockchain, or an entropy value from which the wallet key can be derived. A private key can be viewed as cryptographic data that allows a user to access and manage their cryptocurrency holdings. A private key can be a long, secure, random alphanumeric code that can be used in cryptographic systems to sign transactions and prove ownership of a blockchain address. In the world of cryptocurrencies, it can act as a cryptography to unlock and use funds associated with a public address.

[0012] In some implementations, the processing circuitry of the wallet control device is further configured to receive, when generating a cryptocurrency wallet in the TEE, at least one cryptographic secret (e.g., wallet key, entropy value) for signing transactions on the cryptocurrency blockchain from a remote server. Therefore, when generating a cryptocurrency wallet in the TEE, the cryptographic secret (e.g., wallet key, entropy value) can be generated by the cryptocurrency wallet and then sent to the wallet control device.

[0013] In some implementations, the cryptographic secret (e.g., a wallet key, entropy value) is encrypted using the cryptocurrency wallet's first master key. Therefore, the cryptographic secret may not be transmitted unencrypted between devices. For example, the first master key could be a key for a symmetric encryption scheme.

[0014] In some implementations, the processing circuitry of the wallet control device is configured to store the (received) cryptographic secret (e.g., wallet key, entropy value) encrypted with the first master key of the cryptocurrency wallet in the memory of the wallet control device or in memory associated with the wallet control device. The processing circuitry of the wallet control device can also be configured to send the encrypted cryptographic secret from the wallet control device to a remote server to sign transactions on the cryptocurrency blockchain. Therefore, whenever a cryptocurrency transaction is to be executed, the cryptographic secret (e.g., wallet key) can be sent in encrypted form from the wallet control device to the TEE on the remote server.

[0015] In some implementations, the first master key can be the key of the symmetric encryption scheme of the cryptocurrency wallet, which can be generated on a remote server when the cryptocurrency wallet is generated in the TEE. The first master key may not be available outside the TEE.

[0016] In some implementations, the processing circuitry of the wallet control device is further configured to receive an encrypted cryptographic secret within a message encrypted with a second master key of the cryptocurrency wallet. The second master key may be a private master (secure enclave) key of the TEE.

[0017] In some implementations, the processing circuitry of the wallet control device is further configured to receive a second public master key for the cryptocurrency wallet from a remote server when generating the TEE. The second public master key can be the TEE's secure enclave public key. The secure enclave public key, along with its corresponding private key, can be generated as part of the TEE or secure enclave initialization process. The secure enclave public key can be understood as the public portion of a key pair used in the context of a TEE or a similarly secure enclave (such as Intel Software Protection Extensions (SGX) or AWS Nitro secure enclave). External applications can use the secure enclave public key to encrypt data before sending it to the secure enclave, ensuring the data remains confidential and can only be decrypted by the secure enclave. The secure enclave can use its private key to sign data as part of a proof process demonstrating that the secure enclave public key was indeed generated by a genuine secure enclave running specific code. Therefore, the second private key and the second public master key form a key pair.

[0018] In some implementations, the processing circuitry of the wallet control device is further configured to include a cryptographic secret (e.g., a wallet key) in the control instructions used for the cryptocurrency wallet. The processing circuitry is also configured to encrypt or sign the control instructions using a second (public) master key of the TEE (e.g., a secure enclave key), and send the encrypted / signed control instructions, including the cryptographic secret, from the wallet control device to a remote server hosting the cryptocurrency wallet. One purpose of the second (public) master key of the TEE may be to protect the messages / instructions sent from the wallet control device to the remote server / TEE. The wallet control device can then ensure that the message cannot be read outside the TEE.

[0019] In some implementations, the processing circuitry of the wallet control device is further configured to apply an authentication layer to control instructions used for the cryptocurrency wallet. For example, the control instructions may be signed using a (private) authorization key associated with the wallet control device.

[0020] According to another aspect, this disclosure proposes a mobile device including a wallet control device of any of the foregoing examples. A mobile device is a portable electronic device that allows a user to access, manage, and communicate data and information while on the move. These devices may have wireless connectivity capabilities, such as Wi-Fi and Bluetooth, and may include cellular connectivity for accessing the Internet and mobile networks. Examples of mobile user devices include smartphones, tablets, laptops, and notebooks.

[0021] According to another aspect, this disclosure proposes a method for controlling a cryptocurrency wallet hosted in a trusted execution environment on a remote server. This method can be computer-implemented. The proposed method includes: storing information related to at least one cryptographic secret (e.g., wallet key, entropy value) associated with the cryptocurrency wallet and used to sign transactions on a cryptocurrency blockchain in a memory associated with a wallet control device; and sending the cryptographic secret from the wallet control device to a remote server hosting the cryptocurrency wallet to sign transactions on the cryptocurrency blockchain using that cryptographic secret.

[0022] According to another aspect, this disclosure proposes a computer program having computer-readable instructions that, when executed by a processor, perform the methods described above.

[0023] According to another aspect, this disclosure proposes a wallet service device, including processing circuitry configured to: provide a Trusted Execution Environment (TEE); host a cryptocurrency wallet within the TEE; and host a wallet service application within the TEE. The wallet service application running on the processing circuitry of the wallet service device is configured to: receive a cryptographic secret (e.g., a wallet key) from a remote wallet control device associated with the owner of the cryptocurrency wallet, and use that cryptographic secret to sign transactions on a cryptocurrency blockchain.

[0024] In some implementations, the cryptographic secret received from the remote wallet control device is the private key (or entropy value) of the cryptocurrency wallet used to execute transactions on the cryptocurrency blockchain. The private key can be considered a type of cryptographic data that enables a user to access and manage their cryptocurrency holdings. The private key can be used in cryptographic systems to sign transactions and prove ownership of blockchain addresses.

[0025] In some implementations, the processing circuitry of the wallet service device is configured to send information about at least one cryptographic secret (e.g., wallet key, entropy value) used to sign transactions on the cryptocurrency blockchain to a remote wallet control device when a cryptocurrency wallet is generated in the TEE.

[0026] In some implementations, the processing circuitry of the wallet service device is configured to send a cryptographic secret encrypted with a first master key of the cryptocurrency wallet. The first master key may be a symmetric key used for encrypting / decrypting the cryptographic secret.

[0027] In some implementations, the processing circuitry of the wallet service device is configured to send an encrypted cryptographic secret in a message, which is encrypted with a second master key of the cryptocurrency wallet. The second master key may be a second private master key of the TEE. The second private master key may also be a secure enclave private key of the TEE.

[0028] In some implementations, the processing circuitry of the wallet service device is configured to send a second public master key of the TEE to a remote wallet control device when generating the TEE. The second master key may be the public key of a secure enclave of the TEE. The second public master key, together with its corresponding private key, may be generated as part of the initialization process of the TEE or secure enclave.

[0029] In some implementations, the processing circuitry of the wallet service device is configured to: receive (from a remote wallet control device) a cryptographic secret encrypted with a first master key of a cryptocurrency wallet; decrypt the encrypted cryptographic secret using the first master key of the cryptocurrency wallet; and sign transactions on the cryptocurrency blockchain using the decrypted cryptographic secret (e.g., a wallet key).

[0030] In some implementations, the processing circuitry of the wallet service device is configured to receive, (from a remote wallet control device) an encrypted cryptographic secret (e.g., a wallet key) in an encrypted control command for a cryptocurrency wallet. This control command is encrypted using a second public master key of the TEE. The processing circuitry of the wallet service device is also configured to decrypt the encrypted control command using a second private master key of the TEE.

[0031] In some implementations, the processing circuitry of the wallet service device is further configured to apply an authentication layer to control instructions used for the cryptocurrency wallet. For example, the control instructions can be decrypted using a (public) authorization key associated with the wallet control device.

[0032] According to another aspect, this disclosure proposes a wallet service method. This method can be a computer-implemented method. The proposed method includes: providing a TEE; hosting a cryptocurrency wallet within the TEE; and receiving a cryptographic secret from a remote wallet control device associated with the owner of the cryptocurrency wallet, using the cryptographic secret to sign transactions on a cryptocurrency blockchain.

[0033] Instead of placing full responsibility for storing and operating wallet keys on the wallet service device, it is proposed that the wallet key, or the entropy value used to generate the wallet key, be stored on the wallet control device or cloud storage of the wallet owner (end user). The wallet key can still be encrypted with a master secret known only to the wallet support service, and can be decrypted within the wallet service device's TEE / secure enclave. However, the wallet service device may only need to temporarily decrypt and operate the key when executing a transaction. Therefore, it can receive the encrypted wallet key again from the wallet owner's device each time a transaction needs to be executed. Upgrading the TEE / secure enclave code is no longer an issue, as the wallet service device cannot access any (encrypted) wallet key outside the TEE / secure enclave at any time. Operators cannot obtain any wallet key, even if they do not comply with the procedure. Attached Figure Description

[0034] The following will describe some examples of apparatus and / or methods by way of example and with reference to the accompanying drawings, wherein: Figure 1A A block diagram illustrating an example of a wallet control device is shown; Figure 1B A flowchart illustrating an example of a wallet control method is shown; Figure 2A A block diagram showing an example of a wallet service device and an example of a system including the wallet service device and a wallet control device is provided. Figure 2B A flowchart illustrating an example of a wallet service method is shown; Figure 3A first schematic diagram of a system including a wallet control device and a remote server hosting cryptocurrency wallets is shown; Figure 4 A second schematic diagram shows a system including a wallet control device and a remote server hosting the cryptocurrency wallet; and Figure 5 A third schematic diagram of a system including a wallet control device and a remote server hosting the cryptocurrency wallet is shown. Detailed Implementation

[0035] Some examples will now be described in more detail with reference to the accompanying drawings. However, other possible examples are not limited to the features of these detailed embodiments. Other examples may include modifications, equivalents, and substitutions of these features. Furthermore, the terminology used herein to describe certain examples should not limit other possible examples.

[0036] Throughout the description of the accompanying drawings, the same or similar reference numerals refer to the same or similar elements and / or features, which may be implemented identically or in modified form while providing the same or similar functions. The thickness of lines, layers, and / or regions in the drawings may also be exaggerated for clarity.

[0037] When two elements A and B are combined using "or", this should be understood to disclose all possible combinations, i.e., only A, only B, and A and B, unless otherwise explicitly defined in individual cases. As alternative wording for the same combination, "at least one of A and B" or "A and / or B" can be used. The same applies to combinations with more than two elements.

[0038] If the singular form, such as "a," "an," and "the," is used, and the use of a single element is not explicitly or implicitly defined as mandatory, other examples may also use multiple elements to achieve the same functionality. If a function is described below as being implemented using multiple elements, other examples may use a single element or a single processing entity to achieve the same functionality. It should also be understood that the terms "comprising," "including," "containing," and / or "encompassing," when used, describe the presence of the stated feature, whole, step, operation, process, element, component, and / or group thereof, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, processes, elements, components, and / or groups thereof.

[0039] exist Figures 1A to 2BThe present disclosure illustrates two components: a wallet control device 110 (and a corresponding wallet control method, a wallet control computer program, and a mobile device 100 including the wallet control device 110) and a wallet service device 210 (and a corresponding wallet service method, a wallet service computer program, and a remote server 200 including the wallet service device 210). As will become apparent, these two components interact with each other. Therefore, the main part of the following description will focus on the interaction between these two components.

[0040] Figure 1A A block diagram of an example wallet control device 110 associated with the owner of a cryptocurrency wallet hosted in a Trusted Execution Environment (TEE) on a remote server 200 is shown. The wallet control device 110 includes processing circuitry 114 configured to provide the functionality of the wallet control device 110. Optionally, the wallet control device 110 also includes interfaces for communication with other entities (such as the remote server 200, e.g., [example of other interfaces]). Figure 2A (as shown) a communication interface 112 (e.g., an interface circuit), and / or a storage circuit 116 for storing information. Figure 1A The processing circuitry 114 shown is coupled to an optional interface 112 and an optional storage circuitry 116. For example, the processing circuitry 114 can be configured to combine the interface 112 (for communication) and / or the storage circuitry 116 (for storing and retrieving information) to provide the functionality of the wallet control device 110. For example, the wallet control device 110 can be part of a computer system such as a personal computer, tablet computer, or smartphone. Specifically, the wallet control device can be part of a mobile device 100 such as a tablet computer or smartphone. The functionality of the wallet control device can be provided as software, for example, as a wallet control application executed by the corresponding computer system.

[0041] The processing circuitry 114 of the wallet control device 110 is configured to store information about at least one cryptographic secret associated with the cryptocurrency wallet and used for signing transactions on the cryptocurrency blockchain in a memory associated with the wallet control device 110 (or with the owner of the cryptocurrency wallet). The memory storing the cryptographic secret for signing cryptocurrency transactions may be the storage circuitry 116 of the wallet control device 110. In other embodiments, it may also be the memory of another remote server (e.g., cloud storage) associated with the owner of the wallet control device 110. According to embodiments of this disclosure, the memory storing the cryptographic secret for signing cryptocurrency transactions is located outside the TEE of the remote server 200.

[0042] The cryptographic secret used to sign transactions on a cryptocurrency blockchain can be a wallet key or entropy, with the key derived from entropy. In the context of cryptocurrency, a wallet key refers to a cryptographic key that allows a user to access and manage their cryptocurrency holdings within a digital cryptocurrency wallet. Wallet keys are fundamental to the operation of a cryptocurrency wallet, as they provide a secure mechanism for authenticating transactions and controlling access to cryptocurrency assets. A private wallet key can be a secret alphanumeric code used to sign transactions, proving ownership of the cryptocurrency in a specific wallet. The private key can be used to generate digital signatures for transactions. These signatures verify that the transaction has been authorized by the wallet's owner. A public wallet key, derived from the private wallet key using cryptographic algorithms, can be shared with others. It can be used to create a wallet address (a hashed version of the public key) to which others can send cryptocurrency. The relationship between the public and private wallet keys ensures that only the holder of the private wallet key can access funds sent to the wallet address. The public wallet key can be used in the transaction verification process. When a digital signature is created using the private wallet key, the corresponding public wallet key can be used by the network to verify that the transaction was indeed authorized by the owner of the private wallet key.

[0043] Traditionally, private wallet keys are stored on a remote server 200 hosting the cryptocurrency wallet. However, this can be problematic even with a TEE or secure enclave, especially since the service must be upgradeable. Upgrading a TEE or secure enclave may involve manual procedures to transfer the master key to a new version of the secure enclave code when a new version is needed or expected. Failure to comply with these procedures could allow the service operator to gain access to all wallet keys. Permanently storing all wallet keys in a TEE or secure enclave could also make the service more vulnerable to attack. Therefore, this disclosure proposes storing wallet keys outside the TEE / secure enclave, for example, in the storage circuitry 116 of the wallet control device 110 or in cloud storage associated with the cryptocurrency wallet owner.

[0044] The processing circuitry 114 of the wallet control device 110 is configured to send or transmit (e.g., via interface 112) cryptographic secrets used to sign transactions on the cryptocurrency blockchain from the wallet control device 110 to the remote server 200 to sign the transaction. That is, whenever a cryptocurrency transaction is to be executed, one or more wallet keys can be provided from the wallet control device 110 to the TEE on the remote server 200 hosting the cryptocurrency wallet as needed.

[0045] Figure 1BA flowchart illustrating an example of a wallet control method 10 for controlling a cryptocurrency wallet hosted in a TEE on a remote server 200 is shown. Method 10 includes: storing 11 a cryptographic secret associated with the cryptocurrency wallet and used to sign transactions on a cryptocurrency blockchain in a memory 116 associated with a wallet control device 110 (or its owner). Method 10 also includes: sending 12 (e.g., via interface 112) from the wallet control device 110 to the remote server 200 hosting the cryptocurrency wallet to sign transactions on the cryptocurrency blockchain using that cryptographic secret.

[0046] Figure 2A A block diagram of an example wallet service device 210 is shown. The wallet service device 210 includes processing circuitry 214 configured to provide the functionality of the wallet service device 210. Optionally, the wallet service device 210 also includes an interface 212 (e.g., interface circuitry) for communicating with other entities (e.g., wallet control device 110 or mobile device 100), and / or storage circuitry 216 for storing information. Figure 2A The processing circuitry 214 shown is coupled to an optional interface 212 and an optional storage circuitry 216. For example, the processing circuitry 214 can be configured to provide the functionality of the wallet service device 210 in conjunction with the interface 212 (for communication) and / or with the storage circuitry 216 (for storing and retrieving information). For example, the wallet service device 210 can be part of a computer system, such as server 200. The functionality of the wallet service device 210 can be provided or controlled via software, such as through a wallet service application and / or an application for controlling the TEE.

[0047] The processing circuit 214 of the wallet service device 210 is configured to provide a TEE 220. The processing circuit 214 is also configured to host a cryptocurrency wallet within the TEE 220. Furthermore, the processing circuit 214 is configured to host a wallet service application 230 within the TEE 220. The wallet service application 230 is configured to receive at least one cryptographic secret (e.g., a private wallet key) from a remote wallet control device 110 associated with the owner of the cryptocurrency wallet for signing transactions on the cryptocurrency blockchain. The wallet service application 230 can also be configured to sign transactions on the cryptocurrency blockchain using the received cryptographic secret.

[0048] Figure 2A A server 200 including a wallet service device 210 is also shown. Figure 2A A system including a wallet service device 210 and a wallet control device 110 is also shown, such as a server 200 including the wallet service device 210 and a mobile device 100 including the wallet control device 110.

[0049] Figure 2B A flowchart illustrating an example of the corresponding wallet service method 20 is shown. Wallet service method 20 includes: providing 21 a TEE (Telecommunications Equipment). Wallet service method 20 includes: hosting 22 a cryptocurrency wallet within the TEE. Wallet service method 20 includes: hosting 23 a wallet service application within the TEE. The wallet service application performs the action 24 of receiving a cryptographic secret (e.g., a private wallet key) for signing transactions on the cryptocurrency blockchain from a remote wallet control device 110 associated with the owner of the cryptocurrency wallet. The wallet service application can also perform the action of signing transactions on the cryptocurrency blockchain using the received cryptographic secret.

[0050] The features of wallet control device 110, wallet control method 10, wallet control computer program, and mobile device 100 will now be described in more detail with reference to wallet control device 110 and wallet service device 210, as well as the features of wallet service device 210, wallet service method 20, wallet service computer program, and server 200. The features described in conjunction with wallet control device 110 and wallet service device 210 can also be included in wallet control method 10, wallet control computer program, and mobile device 100, and wallet service method 20, wallet service computer program, and server 200, respectively.

[0051] The proposed concept aims to store the cryptographic secrets (e.g., private wallet keys) used to sign transactions on a cryptocurrency blockchain outside the cryptocurrency wallet hosted by the TEE 220. For example, during the initialization of the cryptocurrency wallet, the corresponding cryptographic secrets (e.g., private wallet keys) can be generated at the wallet service device 210 and then transmitted to the remote wallet control device 110 for storage in the storage circuit 116 or another storage device associated with the wallet control device 110.

[0052] In the proposed concept, the cryptocurrency wallet is stored in a TEE 220 of server 200. Therefore, wallet service device 210 is configured to provide (e.g., make available, control, or make accessible) such a TEE. Various implementations of TEEs exist. A TEE can also be referred to as a secure enclave, for example. Generally, a TEE is an execution environment that is encapsulated and isolated (i.e., shielded) from other processes executing on the processing circuitry providing the TEE. Specifically, processes executing outside a particular TEE may not be able to read or write data or code contained within the TEE. In the proposed concept, in particular, the wallet's content and wallet service application may be inaccessible from outside the TEE, for example, except for the interface used to update the wallet service application. For example, the software code of the wallet service application 230 executing in TEE 220 can be audited by a third party. It can be updated using the aforementioned interface, which can be password-protected. The wallet's content can remain shielded within TEE 220 at any time.

[0053] In the various examples disclosed herein, public-private-key cryptography is used. In other words, the private key of a cryptographic key pair is used to sign something (such as an instruction or identity certificate), and the corresponding public key can be used to verify the signature. Conversely, the public key of a cryptographic key pair can be used to encrypt a message, while the private key can be used to decrypt that message. For example, the cryptographic secret used to sign transactions on a cryptocurrency blockchain could be the private wallet key of the cryptographic key pair.

[0054] The interfaces 112, 212 of the wallet control device 110 and / or wallet service device 210 may correspond to one or more inputs and / or outputs for receiving and / or transmitting information, which may be digital (bit) values ​​based on specified codes, within a module, between modules, or between modules of different entities. For example, the interfaces 112, 212 of the wallet control device 110 and / or wallet service device 210 may include interface circuitry configured to receive and / or transmit information.

[0055] For example, the processing circuitry 114, 214 of wallet control device 110 and / or wallet service device 210 can be implemented using one or more processing units, one or more processing devices, or any means for processing (e.g., processors, computers, or programmable hardware components) that can operate using appropriately adapted software. In other words, the described functions of 114, 214 of wallet control device 110 and / or wallet service device 210 can also be implemented in software, which is then executed on one or more programmable hardware components. Such hardware components may include general-purpose processors, digital signal processors (DSPs), microcontrollers, etc. For example, at least the processing circuitry 214 of wallet service device 210 may be suitable (e.g., configured to) provide a trusted execution environment, such as Intel Software Protection Extensions, AMD Platform Security Processors or Secure Cryptographic Virtualization, ARM TrustZone or RISC-V MultiZone, or AWS Nitro Secure Enclave.

[0056] For example, the storage circuitry 116, 216 of the wallet control device 110 and / or wallet service device 210 may include at least one element from the group of computer-readable storage media, such as magnetic or optical storage media, such as hard disk drives, flash memory, floppy disks, random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or network storage.

[0057] Further details and aspects regarding the wallet control device 110, wallet service device 210, remote server 200, wallet control method 10, wallet service method 20, system, and computer program, in conjunction with the proposed concepts or one or more examples described above or below (e.g., Figures 3 to 5 The wallet control device, wallet service device, remote server, wallet control method, wallet service method, system, and computer program may include one or more additional optional features corresponding to one or more aspects of the proposed concept or one or more examples described above or below.

[0058] exist Figures 1A to 2B The core functionality introduced here is the concept of a "protected (cryptographic) wallet." This type of wallet is a new wallet type that may be suitable for ordinary, non-technically proficient, and poorly organized users. For example, it can be set up as a (paid) service to relieve users of worries about lost keys. It can provide a simple, uncomplicated user experience, for example, with minimal user configuration for recovery. If possible, it can be implemented as a self-hosted wallet while having reduced security risks from (large-scale) attacks.

[0059] The proposed concept comprises three components: a remote server 200, which can be a cloud service that uses secure enclave technology (such as Intel SGX or AWS Nitro secure enclave) to receive wallet assets (private keys) in a manner inaccessible to the cloud provider. This makes the proposed concept self-hosted. The wallet can be operated by the user from a wallet control device 110 (the second component), which can be hosted by a mobile phone 100. Signed wallet instructions, including the wallet key, are sent from the mobile phone 100 to the wallet in the cloud, where the wallet instructions are executed.

[0060] Optionally, an external authentication infrastructure outside the control of the cloud service can be used for wallet access and / or recovery. For example, an SSI (Self-Sovereign Identity) infrastructure can be used. This could be an SSI key for which the user has registered with a government agency and received verifiable credentials. Alternatively, other forms of authentication infrastructure can be used for accessing government websites, banking services, etc. To verify the verifiable certificates used for authentication, the cloud service can configure trust anchors, ideally within a secure enclave. These can be updated via software updates.

[0061] Figure 3 A schematic diagram of system 300 is shown, which includes a wallet control device 110 for a custodial wallet control application 310 and a remote wallet service device 210 for a custodial cryptocurrency wallet 320. Figure 3 This demonstrates wallet support services with a Secure Enclave 330 (TEE). The Secure Enclave 330 shields the cloud owner 340 from operations within the secure enclave (thus enabling self-hosted cryptocurrency wallets). A Secure Enclave 330 (or multiple secure enclaves) isolates a small kernel of security-sensitive code (such as wallet service applications) from the operating system and the main software stack. It provides robust protection against attacks.

[0062] Wallet control device 110 stores information about one or more private keys (or entropy values) 350 of cryptocurrency wallet 320 used to execute transactions on cryptocurrency blockchain 360. Alternatively, information about one or more private keys (or entropy values) 350 of cryptocurrency wallet 320 may also be stored in the personal cloud storage (not shown) of wallet owner 340. Information about one or more private wallet keys 350 may be the one or more private keys themselves. Alternatively, information about one or more private wallet keys 350 may be one or more entropy values ​​from which several wallet keys can be derived, each wallet key being usable for signing blockchain transactions according to the concept of HD (Hierarchical Deterministic) wallets.

[0063] Entropy is a measure of randomness. In an HD wallet, a high entropy value (typically 128 bits, 256 bits, or longer) serves as a seed from which all subsequent keys are derived. The entropy value can be generated from random physical motion (such as mouse movements or key presses) or by a secure random number generator provided by the operating system. The entropy value should be truly random to ensure the security of the derived keys. The entropy can then be converted into a mnemonic phrase (a series of easy-to-remember words) that allows users to back up and restore their wallet. This mnemonic, through a deterministic process, generates a master private key and chaincode for the HD wallet. From the master private key and chaincode, a virtually unlimited number of sub-wallet keys can be generated. These wallet keys are organized in a tree structure with various branches, allowing the organization and management of multiple cryptocurrency addresses and accounts within a single wallet.

[0064] The entropy value or private wallet key 350 can be created / generated at several points in the lifecycle of the cryptocurrency wallet 320, depending on the type of wallet and the method used to generate the key. For example, a common time to generate the entropy value or private wallet key 350 is during the initial setup of the cryptocurrency wallet 320. Therefore, the entropy value or private wallet key 350 can be generated as part of the wallet creation process. Thus, when the cryptocurrency wallet 320 is created at the remote server 200, the entropy value or private wallet key 350 can be generated by the cryptocurrency wallet and then sent or transmitted from the server 200 to the wallet control device 110. Compared to traditional cryptocurrency wallet concepts, the proposed concept does not store the entropy value or wallet key 350 at the server 200 hosting the cryptocurrency wallet 320, but rather stores it outside the server, i.e., in the wallet control device 110 or in the personal cloud storage (not shown) of the wallet owner 340.

[0065] The wallet control device 110 can be configured to receive an entropy value and / or a private wallet key 350 from a remote server 200 when generating a cryptocurrency wallet 320. The received entropy value and / or private wallet key 350 can then be stored in the wallet control device 110 or in the personal cloud storage (not shown) of the wallet owner 340.

[0066] To transmit the entropy value and / or private wallet key 350 from server 200 to wallet control device 110, the entropy value and / or private wallet key 350 can be encrypted using the first master key 370 of cryptocurrency wallet 320. The first master key 370 can be used to encrypt the entropy value and / or private wallet key 350 of cryptocurrency wallet 320. Therefore, the entropy value and / or private wallet key 350 may not be transmitted unencrypted between devices 110 and 200. For example, the first master key 370 associated with cryptocurrency wallet 320 can be a (symmetric) key of a symmetric encryption scheme. A symmetric encryption scheme is a type of cryptographic system where the same key is used for both plaintext encryption and ciphertext decryption. This means that the sender and receiver can share the same secret key (first master key 370), which must be kept confidential. For example, the symmetric key (first master key 370) is not shared but remains on the remote server side.

[0067] Specifically, the wallet control device 110 can be configured to store the encrypted entropy value and / or the encrypted private wallet key 350 (which is encrypted with the first master key 370 of the cryptocurrency wallet) in the storage circuit 116 of the wallet control device 110 or in the personal cloud storage (not shown) of the wallet owner 340.

[0068] Wallet service device 210 can send an encrypted cryptographic secret 350, encrypted with a first master key 370, to wallet control device 110 in a secure message. This secure message is encrypted or signed by a second master key of cryptocurrency wallet 320. The second master key can be a private enclave key of secure enclave 330. At wallet control device 110, the secure message carrying the encrypted cryptographic secret can be decrypted using the second public master key of cryptocurrency wallet 320. The second public master key can be a public enclave key of secure enclave 330.

[0069] A secure enclave public key can be understood as the public portion of a key pair used within the context of a TEE secure enclave, such as Intel Software Protection Extensions (SGX) or AWS Nitro secure enclave. External applications (such as wallet application 310) can use the secure enclave public key to encrypt data before sending it to the secure enclave, ensuring the data remains confidential and can only be decrypted by the secure enclave. The secure enclave can use its private key to sign data as part of a proof process, demonstrating to external entities that the data was securely processed within the secure enclave. External entities can use the secure enclave public key to verify these signatures.

[0070] The wallet service device 210 can send the secure enclave public key to the wallet control device 110 when generating the secure enclave 330. Therefore, the wallet control device 110 can receive the secure enclave public key of the secure enclave 330 from the wallet service device 210 when generating the secure enclave 330. The secure enclave public key, together with its corresponding private key, can be generated as part of the initialization process of the secure enclave 330.

[0071] While not a preferred option, wallet service device 210 may send the first master key 370 of cryptocurrency wallet 320 to remote wallet control device 110 when cryptocurrency wallet 320 is generated. This can be accomplished, for example, using a secure message signed, for example, with the private key of the secure enclave 330. Correspondingly, wallet control device 110 may be configured to receive the first master key 370 from wallet service device 210 when cryptocurrency wallet 320 is generated. For example, wallet control device 110 may read the secure message carrying the first master key 370 using the public key of the secure enclave 330. The secure enclave public key may have been communicated to wallet control device 110 prior to wallet service device 210. Therefore, while not preferred, the first master key 370 may also be available outside the secure enclave, for example, in storage circuitry 116 or in the personal cloud storage of wallet owner 340, so that the first master key 370 can be backed up. In a preferred embodiment, the first master key 370 is not shared outside of wallet service device 210.

[0072] Whenever a cryptocurrency transaction needs to be executed, the wallet control device 110 can send one or more encrypted private wallet keys 350 to the wallet service device 210 for signing the transaction on the cryptocurrency blockchain 360. At the wallet service device 210, the wallet support service can use a first master key 370 to decrypt the encrypted private wallet keys 350 received from the wallet control device 110. The wallet service device 210 can then use the decrypted private wallet keys 350 to sign one or more transactions on the cryptocurrency blockchain 360.

[0073] For example, wallet control device 110 can be configured to include an encrypted private wallet key 350 in control instructions (messages) for cryptocurrency wallet 320. For instance, wallet control device 110 can encrypt or sign control instructions using the secure enclave public key of secure enclave 330, and send the encrypted / signed control instructions including the encrypted private wallet key 350 from wallet control device 110 to wallet service device 210. One purpose of the secure enclave key is to protect messages / instructions sent from wallet control device 110 to wallet service device 210.

[0074] Wallet service device 210 can receive encrypted / signed control instructions, including an encrypted private wallet key 350, from wallet control device 110. Wallet service device 210 can decrypt the encrypted / signed control instructions using its secure enclave private key. As a result, wallet service device 210 can read transaction-related instructions and the encrypted private wallet key 350. Then, wallet service device 210 can decrypt the encrypted private wallet key 350 using the first master key 370 of the cryptocurrency wallet and use the decrypted private wallet key 350 to sign transactions on the cryptocurrency blockchain 360.

[0075] Figure 4 An implementation of system 300 is shown, wherein control commands / messages from wallet control device 110 to wallet service device 210 are encrypted / signed using a secure enclave public key 410.

[0076] The REST controller 420 in the wallet service device 210 can process control commands / messages and their responses according to the principles of REST (Representative State Transition). REST is an architectural style that defines a set of constraints and principles for creating web services. The REST controller 420 can be responsible for handling incoming HTTP request messages, executing appropriate logic, and returning corresponding HTTP response messages. The REST controller 420 can request the secure enclave 330 to sign a transaction based on the encrypted private wallet key 350. The secure enclave 330 can decrypt the private wallet key 350 using the first master key 370 and sign the transaction. The signed transaction can then be forwarded from the secure enclave 330 to the REST controller 420, and from the REST controller 420 to the blockchain client 430 that executes the transaction on the blockchain 360.

[0077] like Figure 5 As shown, the REST controller 420 can implement other optional features of layered security, such as an authentication layer, to allow multiple wallet control devices 110 associated with the wallet owner 340 to access the cryptocurrency wallet 320. For this purpose, the wallet service device 210 can also be configured to authenticate the cryptocurrency wallet owner 340 relative to the wallet service application 230 based on an authorization key, where the authorization key for each device 110 (from which the cloud wallet can be accessed) can be different. The cloud wallet 320 can sign transactions only when it receives instructions signed by that device key (or authorization key) from the wallet application.

[0078] For example, wallet service application 230 can be configured to obtain control instructions from wallet control device 110 for registering a (new) authorization key at cryptocurrency wallet 320. Wallet service device 210 can be configured to register a (new) authorization key at cryptocurrency wallet 320. Wallet service device 210 can be configured to execute cryptographically protected instructions based on the (new) authorization key for controlling cryptocurrency wallet 320. Therefore, after wallet control device 110 is authenticated, a (new) authorization key is installed at wallet service device 210 for the owner 340 of the cryptocurrency wallet. The (new) authorization key registered at wallet 320 can be a (new) public key of a (new) device authorization key pair. For example, control instructions from one of multiple wallet control devices 110 can be additionally signed with a private authorization key associated with the owner 340 and / or the respective wallet control device 110. Control instructions can be decrypted using a public authorization key associated with wallet control device 110.

[0079] The proposed protected wallet 320 can also offer more advanced features, such as rate limiting and other usage controls. Rate limiting (e.g., the maximum daily transaction amount) and other usage controls can be configured by the user (and imposed by the wallet). Exceeding the configured limits can be permitted after authentication. For example, this authentication can be completed outside a secure enclave.

[0080] For example, a subset of instructions for controlling cryptocurrency wallet 320 requires a signed identity certificate of the cryptocurrency wallet owner 340 (e.g., the instructions can be signed using the private key that signed the authentication request). Therefore, processing circuitry 214 can be configured to authenticate the cryptocurrency wallet owner 340 relative to the wallet service application executing in the TEE 330 of server 200, as a secondary security measure of the subset of instructions for controlling the cryptocurrency wallet. For example, the subset of instructions may include: instructions for setting rate limits; instructions for removing or changing rate limits; instructions for setting usage controls; instructions for removing or changing usage controls; and control instructions for registering (new) authorization keys. The processing circuitry 214 of wallet control device 210 can be configured to include a signed identity certificate (e.g., the corresponding instructions are signed using the private key that signed the authentication request) in the subset of instructions for controlling the cryptocurrency wallet. For example, the wallet service application can be configured to execute the subset of instructions after authenticating the cryptocurrency wallet owner. For example, a wallet service application can be configured to verify a subset of instructions based on information about a signed identity certificate, information about the identity of the cryptocurrency wallet owner (and the public key of the trust anchor).

[0081] Alternatively, a multi-signature scheme can be used to protect large operations. In this case, the wallet in Secure Enclave 330 only proceeds with the transaction if the request to execute the transaction is signed by multiple parties. One party could be another person, or another device belonging to the wallet owner.

[0082] Using the architecture proposed in this paper, users can still engage a vault service to retain a second copy of the wallet key (or the entropy value as described above), which can then be used to recover the wallet key in the event of a device problem (device loss or loss of the encrypted wallet key).

[0083] The following text presents some examples of the proposed concepts: Examples (such as Example 1) relate to a wallet control device associated with the owner of a cryptocurrency wallet hosted in a trusted execution environment on a remote server, wherein the wallet control device includes processing circuitry configured to: store information about at least one cryptographic secret associated with the cryptocurrency wallet and used to sign transactions on a cryptocurrency blockchain in a memory associated with the wallet control device; and send the cryptographic secret from the wallet control device to the remote server to sign transactions on the cryptocurrency blockchain using the cryptographic secret.

[0084] Another example (e.g., Example 2) relates to the foregoing examples (e.g., Example 1) or any other example, and also includes: a cryptographic secret is the private key or entropy of a cryptocurrency wallet used to execute transactions on a cryptocurrency blockchain.

[0085] Another example (e.g., Example 3) relates to the foregoing examples (e.g., one of Example 1 or 2) or any other example, and further includes: the processing circuitry is also configured to: when generating a cryptocurrency wallet in a trusted execution environment, receive from a remote server a cryptographic secret for signing transactions on a cryptocurrency blockchain.

[0086] Another example (e.g., Example 4) involves the aforementioned examples (e.g., one of Examples 1 to 3) or any other example, and also includes: cryptographic secrets encrypted with the first master key of a cryptocurrency wallet.

[0087] Another example (e.g., Example 5) relates to the foregoing example (e.g., Example 4) or any other example, and further includes: the processing circuitry is configured to: store a cryptographic secret encrypted with a first master key of a cryptocurrency wallet; and send the encrypted cryptographic secret from the wallet control device to a remote server.

[0088] Another example (e.g., Example 6) involves the aforementioned examples (e.g., one of Example 4 or 5) or any other example, and also includes: the first master key is a symmetric key used to encrypt / decrypt the cryptographic secret.

[0089] Another example (e.g., Example 7) involves the foregoing examples (e.g., one of Examples 4 to 6) or any other example, and further includes: the processing circuitry is also configured to receive an encrypted cryptographic secret in a message encrypted with a second master key of a cryptocurrency wallet.

[0090] Another example (e.g., Example 8) relates to the aforementioned example (e.g., Example 7) or any other example, and also includes: the second master key is a secure enclave private key of a trusted execution environment.

[0091] Another example (e.g., Example 9) relates to the foregoing example (e.g., Example 8) or any other example, and further includes: the processing circuitry is also configured to: receive a second public master key of the trusted execution environment from a remote server when the trusted execution environment is generated.

[0092] Another example (e.g., Example 10) relates to the foregoing examples (e.g., one of Examples 1 to 9) or any other example, and further includes: the processing circuitry is also configured to: include a cryptographic secret in the control instructions for the cryptocurrency wallet; sign the control instructions using a key generated by the wallet control device; and send the signed control instructions, including the cryptographic secret, from the wallet control device to a remote server hosting the cryptocurrency wallet.

[0093] Another example (e.g., Example 11) relates to a mobile device that includes a wallet control device of any of Examples 1 to 10.

[0094] Examples (such as Example 12) relate to a method for controlling a cryptocurrency wallet hosted in a trusted execution environment on a remote server, the method comprising: storing information about at least one cryptographic secret associated with the cryptocurrency wallet and used for signing transactions on a cryptocurrency blockchain in a memory associated with a wallet control device; and sending the cryptographic secret from the wallet control device to a remote server hosting the cryptocurrency wallet for signing transactions on the cryptocurrency blockchain using the cryptographic secret.

[0095] Examples (such as Example 13) relate to a wallet service apparatus including processing circuitry configured to: provide a trusted execution environment; host a cryptocurrency wallet within the trusted execution environment; and host a wallet service application within the trusted execution environment, the wallet service application being configured to: receive a cryptographic secret from a remote wallet control device associated with the owner of the cryptocurrency wallet, and use the cryptographic secret to sign transactions on a cryptocurrency blockchain.

[0096] Another example (e.g., Example 14) relates to the foregoing examples (e.g., Example 13) or any other example, and also includes: a cryptographic secret is the private key or entropy of a cryptocurrency wallet used to execute transactions on a cryptocurrency blockchain.

[0097] Another example (e.g., Example 15) relates to the foregoing examples (e.g., one of Examples 13 or 14) or any other example, and further includes: the processing circuitry is configured to: when a cryptocurrency wallet is generated in a trusted execution environment, send the cryptographic secret used to sign transactions on the cryptocurrency blockchain to a remote wallet control device.

[0098] Another example (e.g., Example 16) relates to the foregoing example (e.g., Example 15) or any other example, and further includes: the processing circuitry is configured to: send a cryptographic secret encrypted with the first master key of a cryptocurrency wallet.

[0099] Another example (e.g., Example 17) relates to the aforementioned example (e.g., Example 16) or any other example, and further includes: the first master key is a symmetric key used to encrypt / decrypt cryptographic secrets.

[0100] Another example (e.g., Example 18) relates to the foregoing examples (e.g., one of Examples 16 to 17) or any other example, and further includes: the processing circuitry is also configured to: send an encrypted cryptographic secret in a message, which is encrypted with a second master key of a cryptocurrency wallet.

[0101] Another example (e.g., Example 19) relates to the foregoing example (e.g., Example 18) or any other example, and also includes: the second master key is a second private master key of the trusted execution environment.

[0102] Another example (e.g., Example 20) relates to the foregoing example (e.g., Example 19) or any other example, and further includes: the processing circuitry is also configured to: send a second public master key of the trusted execution environment to a remote wallet control device when the trusted execution environment is generated.

[0103] Another example (e.g., Example 21) relates to the foregoing examples (e.g., one of Examples 16 to 20) or any other example, and further includes: the processing circuitry is configured to: receive a cryptographic secret encrypted with a first master key of a cryptocurrency wallet; decrypt the encrypted cryptographic secret using the first master key of the cryptocurrency wallet; and sign a transaction on a cryptocurrency blockchain using the decrypted cryptographic secret.

[0104] Another example (e.g., Example 22) relates to the foregoing example (e.g., Example 21) or any other example, and further includes: the processing circuitry is configured to: receive an encrypted cryptographic secret in an encrypted control instruction for a cryptocurrency wallet, the control instruction being encrypted using a second public master key of a trusted execution environment; and decrypt the encrypted control instruction using a second private master key of the trusted execution environment.

[0105] One example (e.g., Example 23) relates to a wallet service method comprising: providing a trusted execution environment; hosting a cryptocurrency wallet within the trusted execution environment; hosting a wallet service application within the trusted execution environment; and receiving a cryptographic secret from a remote wallet control device associated with the owner of the cryptocurrency wallet, to use the cryptographic secret to sign transactions on a cryptocurrency blockchain.

[0106] The aspects and features described by a particular example in the foregoing examples can also be combined with one or more examples in other examples to replace the same or similar features in those other examples, or to introduce features into those other examples.

[0107] Examples may also be or relate to a (computer) program, including program code, for performing one or more of the methods described above when the program is executed on a computer, processor, or other programmable hardware component. Therefore, the steps, operations, or processes of the different methods described above may also be performed by a programmed computer, processor, or other programmable hardware component. Examples may also encompass program storage devices, such as digital data storage media, which are machine-readable, processor-readable, or computer-readable and encode and / or contain machine-executable, processor-executable, or computer-executable programs and instructions. Program storage devices may include, for example, digital storage devices, magnetic storage media (e.g., disks and tapes), hard disk drives, or optically readable digital data storage media. Other examples may also include computers, processors, control units, (field)programmable logic arrays ((F)PLAs), (field)programmable gate arrays ((F)PGAs), graphics processing units (GPUs), application-specific integrated circuits (ASICs), integrated circuits (ICs), or system-on-a-chip (SoC) systems programmed to perform the steps of the methods described above.

[0108] It should also be understood that the disclosure of steps, processes, operations, or functions in the specification or claims should not be construed as implying that these operations necessarily depend on the described order, unless expressly stated in individual cases or necessary for technical reasons. Therefore, the foregoing description does not limit the execution of steps or functions to a particular order. Furthermore, in other examples, a single step, function, process, or operation may include and / or be decomposed into several sub-steps, sub-functions, sub-processes, or sub-operations.

[0109] If aspects have been described with reference to a device or system, these aspects should also be understood as descriptions of the corresponding methods. For example, a block, device, or functional aspect of a device or system may correspond to a feature (e.g., method steps) of the corresponding method. Therefore, aspects described with reference to a method should also be understood as descriptions of corresponding blocks, elements, attributes, or functional features of the corresponding device or system.

[0110] The following claims are incorporated herein by reference in the detailed description, wherein each claim may stand alone as a separate example. It should also be noted that while in the claims, dependent claims refer to a specific combination with one or more other claims, other examples may also include combinations of the subject matter of that dependent claim with the subject matter of any other dependent or independent claim. Such combinations are expressly stated herein unless, in individual cases, it is stated that a particular combination is not intended. Furthermore, the features of the claims should also be included for use in any other independent claim, even if that claim is not directly defined as dependent on that other independent claim.

Claims

1. A wallet control device associated with the owner of a cryptocurrency wallet hosted in a trusted execution environment on a remote server, wherein, The wallet control device includes a processing circuit, which is configured to: Information concerning at least one cryptographic secret associated with the cryptocurrency wallet and used to sign transactions on the cryptocurrency blockchain is stored in a memory associated with the wallet control device; and The cryptographic secret is sent from the wallet control device to the remote server to sign transactions on the cryptocurrency blockchain using the cryptographic secret.

2. The wallet control device according to claim 1, wherein, The cryptographic secret is the private key or entropy of the cryptocurrency wallet used to execute transactions on the cryptocurrency blockchain.

3. The wallet control device according to claim 1, wherein, The processing circuit is further configured to: When the cryptocurrency wallet is generated in the trusted execution environment, the cryptographic secret used to sign transactions on the cryptocurrency blockchain is received from the remote server.

4. The wallet control device according to claim 1, wherein, The cryptographic secret is encrypted using the first master key of the cryptocurrency wallet.

5. The wallet control device according to claim 4, wherein, The processing circuit is configured as follows: The cryptographic secret is stored using the first master key of the cryptocurrency wallet; and The encrypted cryptographic secret is sent from the wallet control device to the remote server.

6. The wallet control device according to claim 4, wherein, The first master key is a symmetric key used to encrypt / decrypt the cryptographic secret.

7. The wallet control device according to claim 4, wherein, The processing circuit is further configured to: Receive the encrypted cryptographic secret in a message encrypted with the second master key of the cryptocurrency wallet.

8. The wallet control device according to claim 7, wherein, The second master key is the secure enclave private key of the trusted execution environment.

9. The wallet control device according to claim 8, wherein, The processing circuit is further configured to: When generating the trusted execution environment, the second public master key of the trusted execution environment is received from the remote server.

10. The wallet control device according to claim 1, wherein, The processing circuit is further configured to: The cryptographic secret is included in the control instructions used for the cryptocurrency wallet; The control command is signed using a key generated by the wallet control device; and A signed control command, including the cryptographic secret, is sent from the wallet control device to the remote server hosting the cryptocurrency wallet.

11. A mobile device comprising a wallet control device according to claim 1.

12. A wallet service device, comprising processing circuitry configured to: Provide a trusted execution environment; Hosting a cryptocurrency wallet within the trusted execution environment; A wallet service application is hosted within the trusted execution environment, and the wallet service application is configured to: Receive cryptographic secrets from a remote wallet control device associated with the owner of the cryptocurrency wallet, and use the cryptographic secrets to sign transactions on the cryptocurrency blockchain.

13. The wallet service device according to claim 12, wherein, The cryptographic secret is the private key or entropy of the cryptocurrency wallet used to execute transactions on the cryptocurrency blockchain.

14. The wallet service device according to claim 12, wherein, The processing circuit is configured as follows: When the cryptocurrency wallet is generated in the trusted execution environment, the cryptographic secret used to sign transactions on the cryptocurrency blockchain is sent to the remote wallet control device.

15. The wallet service device according to claim 14, wherein, The processing circuit is configured as follows: Send the cryptographic secret encrypted with the first master key of the cryptocurrency wallet.

16. The wallet service device according to claim 15, wherein, The first master key is a symmetric key used to encrypt / decrypt the cryptographic secret.

17. The wallet service device according to claim 15, wherein, The processing circuit is further configured to: The message contains an encrypted cryptographic secret, which is encrypted with the second master key of the cryptocurrency wallet.

18. The wallet service device according to claim 17, wherein, The second master key is the second private master key of the trusted execution environment.

19. The wallet service device according to claim 18, wherein, The processing circuit is further configured to: When generating the trusted execution environment, the second public master key of the trusted execution environment is sent to the remote wallet control device.

20. The wallet service device according to claim 15, wherein, The processing circuit is configured as follows: Receive the cryptographic secret encrypted with the first master key of the cryptocurrency wallet; Decrypt the encrypted cryptographic secret using the first master key of the cryptocurrency wallet; as well as Transactions on the cryptocurrency blockchain are signed using decrypted cryptographic secrets.