Digital wallet system
The digital wallet system empowers users to securely distribute and manage private key splits across servers, ensuring non-custodial control and security through user-selected storage, addressing the custodial risks in existing methods.
Patent Information
- Application Number
- JP2024003231
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-07-25
AI Technical Summary
Non-custodial digital wallets face challenges in securely backing up private keys without engaging in custodial services, as existing methods may allow service providers to restore the key through server collusion, necessitating registration as a cryptocurrency exchange dealer.
A digital wallet system that allows users to select and distribute split pieces of a private key across multiple servers using secret sharing technology, ensuring user authority over storage destinations and employing an All or Nothing Transform (AONT) method to prevent key restoration without all pieces.
Enables a non-custodial wallet service where users have full control over storage, enhancing security and avoiding custodial responsibilities, while maintaining convenience and simplicity.
Smart Images

Figure 2025109381000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to digital wallet technology, and more particularly to a technology effective for application to a digital wallet system that ensures the security related to the storage of private keys.
Background Art
[0002] In the so-called Web3.0 (Web3) environment, by using blockchain technology, the Internet is further decentralized, and a token economy is created that conducts "co-creation, possession, and exchange of value" using tokens such as cryptocurrency. As one of the key technologies in this Web3, there is a digital wallet (electronic wallet) that can hold and manage various types of cryptocurrency, etc., and venture companies, etc., including free software, are providing various services and solutions.
[0003] Digital wallets are broadly classified into cold wallets and hot wallets. Cold wallets are used in an environment not connected to the network and thus have high security, but many are provided as hardware and are inferior in terms of convenience and simplicity. On the other hand, hot wallets have better convenience and simplicity compared to cold wallets, but since they are used while connected to the network, it is necessary to ensure security so that the private key does not leak.
[0004] Hot wallets are broadly divided into custodial wallets and non-custodial wallets depending on the private key management method. In a custodial wallet, the service provider side such as a cryptocurrency exchange stores the private key (i.e., conducts "custody (storage and management) services" related to cryptocurrency, etc.). Users can use the wallet by opening their own accounts at the exchange. Although users do not need to manage the private key themselves, there is a risk of losing the deposited assets if the exchange is hacked, etc.
[0005] On the one hand, in a non-custodial wallet, the user stores and uses their own private key. Since the private key is not managed by a third party such as an exchange, the user has all decision-making authority regarding encrypted assets and the like. On the other hand, since all information such as the private key is held on the user (client) side, for example, if the seed phrase for accessing the private key leaks, all the user's information (assets) can leak. Therefore, the user needs to ensure security on their own.
[0006] There is a so-called secret sharing technology known as a security technology for anonymizing important data such as private keys. For example, in the conventionally used (k,n) threshold secret sharing method, the target data is dispersed (encoded) into n meaningless share pieces. However, to restore the original data from the share pieces, at least k of the n share pieces need to be gathered (the original data cannot be restored from less than k share pieces). By dispersedly storing the share pieces generated by this secret sharing technology on the network, for example, the risk that a plurality of holders of the share pieces collude and gather more than k share pieces to restore the private key can be reduced.
[0007] As a related technology, for example, Japanese Patent No. 4860779 (Patent Document 1) describes that in a client terminal, n partial data (k≤n) that cannot restore important data unless k or more are collected from the important data instructed by the user for storage by the secret sharing technology are generated, and the generated n partial data are sequentially rotated for each important data to be stored among n or more servers and stored in n selected servers respectively. Also, m partial data (k≤m≤n) for restoring the important data are collected from m servers respectively, and the important data is restored from the obtained m partial data by the secret sharing technology.
Prior Art Documents
Patent Documents
[0008]
Patent Document 1
[0009] In a non-custodial wallet, the private key managed on the user (client) side needs to be backed up in case of loss, damage, etc. By using the prior art as described in Patent Document 1 when backing up the private key, the user can use the digital wallet without being conscious of the security of the backed-up private key.
[0010] However, the digital wallet in such a configuration can be treated as a custodial wallet. That is, the system side (service provider side such as a cryptocurrency exchange) selects and determines all the shards generated from the private key by a predetermined method. For example, by making an intentional selection and determination such as selecting a specific server, it can be said that it is possible to restore the private key by gathering k or more shards without the cooperation of the user, and it can also be said that storing the shards is equivalent to the custodial business of storing the private key. When conducting the custodial business, it is necessary to register as a cryptocurrency exchange dealer, so the hurdle for the service provider becomes high.
[0011] Therefore, an object of the present invention is to provide a digital wallet system that realizes a non-custodial wallet in which shards obtained from a private key using a secret sharing technique are distributed and stored in a plurality of servers.
[0012] The above and other objects and novel features of the present invention will become apparent from the description of this specification and the accompanying drawings. MEANS FOR SOLVING THE PROBLEM
[0013] Among the inventions disclosed in the present application, the outline of typical ones will be briefly described as follows.
[0014] A digital wallet system, which is a representative embodiment of the present invention, is a digital wallet system that realizes a non-custodial wallet, and includes a wallet application and a user terminal having a private key, a backup management server that manages a backup of the private key, and n (n≧2) or more storage servers.
[0015] The wallet application of the user terminal has a secret sharing processing unit that generates n (k≦n) split pieces from the private key, and k or more split pieces are required to restore the private key by secret sharing technology, and a backup processing unit that stores the n split pieces in the n storage servers. The backup management server has a storage management unit that manages information on the storage servers capable of storing the split pieces, and a storage destination management unit that manages information on the storage servers storing the split pieces.
[0016] The backup processing unit of the user terminal acquires a list of the storage servers capable of storing the split pieces from the storage management unit of the backup management server, stores the n split pieces in the n storage servers selected by the user from the list, and passes the information on the n storage servers to the storage destination management unit of the backup management server for recording, thereby backing up the private key. Also, the backup processing unit acquires information on m (k≦m≦n) storage servers storing the split pieces from the storage destination management unit of the backup management server, acquires the m split pieces from the m storage servers respectively, and restores the private key from the m split pieces by secret sharing technology.
Advantages of the Invention
[0017] Among the inventions disclosed in the present application, the effects obtained by representative ones will be briefly described as follows.
[0018] That is, according to a typical embodiment of the present invention, it is possible to realize a non-custodial digital wallet that dispersedly stores the split pieces obtained from a secret key using a secret sharing technique in a plurality of servers.
Brief Description of the Drawings
[0019]
Figure 1
Figure 2
Figure 3
Figure 4
Modes for Carrying Out the Invention
[0020] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all the drawings for explaining the embodiments, the same parts are generally denoted by the same reference numerals, and repeated explanations thereof are omitted. On the other hand, for the parts described with reference numerals in a certain drawing, they will not be shown again in the explanations of other drawings, but may be referred to with the same reference numerals.
[0021] <Overview> As described above, it is necessary to keep a backup of the secret key managed on the user (client) side in a non-custodial digital wallet in case of loss, damage, etc. (the same applies when the secret key becomes unusable due to loss or damage of the terminal holding the secret key).
[0022] Here, when the service provider stores the private key, if the private key itself is stored and kept, the service provider will be engaged in the custody business, and registration as a cryptocurrency exchange operator will be required. On the other hand, even when the split pieces obtained using the secret sharing technique from the private key are stored in multiple servers in a distributed manner, if the service provider (system side) selects and determines all of the storage servers, in the event of collusion among these servers (their administrators), the private key can be restored. Therefore, the service provider may still be regarded as engaging in the custody business. Thus, in order to provide a non-custodial wallet service, when selecting and determining the storage servers for the split pieces, it is required to adopt a configuration in which the user has all the authority.
[0023] Therefore, the digital wallet system according to an embodiment of the present invention has a configuration in which the user can select, from among candidates, the server (storage) that will be the storage destination for the split pieces in the backup of the private key. It is also possible to enable the specification of the number of storage destinations (that is, the number of split pieces obtained by the secret sharing technique).
[0024] In this embodiment, from the viewpoints of user convenience and simplicity, and the data capacity of the split pieces, as the secret sharing technique used for splitting the private key, an encoding method (AONT (All or Nothing Transform) method) in which k = n in the (k, n) threshold secret sharing method, that is, the original data cannot be restored unless all of the n generated split pieces are assembled, will be described. However, it is also possible to adopt a configuration in which the availability is improved by setting k < n and enabling restoration when k or more pieces are assembled.
[0025] <System Configuration> FIG. 1 is a diagram showing an outline of a configuration example of a digital wallet system according to an embodiment of the present invention. The digital wallet system 1 includes, for example, a user terminal 4 such as a smartphone used by a user, a backup management server 10, and a plurality of storage servers 30 that can be storage destinations for split pieces (in the example in the figure, x storage destination servers A (30a) to X (30x) (x>n)), which are interconnected via a network 2 such as the Internet. Each of the storage servers 30 is provided with a storage 31 (storage A (31a) to storage X (31x) in the example in the figure) for actually storing and managing the split pieces.
[0026] A wallet application 40 that realizes a non-custodial digital wallet for holding and managing cryptographic assets and the like is introduced into the user terminal 4. The wallet application 40 has a private key 43 necessary for handling cryptographic assets and the like, and includes components such as a secret sharing processing unit 41 and a backup processing unit 42 implemented as software.
[0027] As described above, the secret sharing processing unit 41 has a function of performing secret sharing processing on the private key 42 by the AONT method to generate n split pieces. The number of n may be a fixed number of 2 or more, or may be specified by the user in advance or each time within a predetermined range. For the secret sharing process, a known library or the like can be appropriately used.
[0028] The backup processing unit 42 has a function of storing the n split pieces generated by the secret sharing processing unit 41 in different n storage servers 30 out of the x storage servers 30 while cooperating with the backup management server 10. Further, it has a function of acquiring the split pieces from the n storage servers 30 respectively and restoring the original secret key 43 from these split pieces. In this embodiment, secret sharing by the AONT method is used, but when using secret sharing that enables restoration of the secret key 43 if k or more split pieces (k < n) are collected, it is sufficient to acquire the split pieces from m storage servers 30 (k ≤ m ≤ n) respectively.
[0029] The backup management server 10 is composed of, for example, a server device or a virtual server constructed on a cloud computing service, etc., and by a CPU (Central Processing Unit) (not shown), an OS (Operating System) expanded from a recording device such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive) onto a memory, a DBMS (DataBase Management System), middleware such as a Web server program, and executing software operating thereon, it has a function of managing the backup related to the secret key 43 on the user terminal 4, that is, the distributed storage of the n split pieces generated from the secret key 43 by the secret sharing technique to n different storage servers 30.
[0030] The backup management server 10 has each unit such as an authentication processing unit 11, a storage management unit 12, and a storage destination management unit 13 implemented as software, for example. It also has data stores such as storage information 14 and storage destination information 15 implemented by a database, a file table, etc.
[0031] The authentication processing unit 11 has a function of performing authentication processing when the user terminal 4 backs up the private key 43. For example, it can be configured to perform user authentication and terminal authentication by so-called SMS (Short Message Service) authentication or social authentication. The storage management unit 12 has a function of managing, as a list, information on storage servers 30 (storage 31) that can be candidates for the storage destination of the split pieces. For example, this function is realized by registering and managing in the storage information 14 information such as the server name, address, URL (Uniform Resource Locator), name identifying the operator of the operating entity, and service name for accessing these storage servers 30 and storage 31. The storage destination management unit 13 has a function of registering and managing in the storage destination information 15 information regarding which storage server 30 each user terminal 4 stores the split pieces of the private key 43 in.
[0032] <Backup of Private Key> FIG. 2 is a diagram showing an overview of an example of secret sharing and distributed storage of the private key 43 in an embodiment of the present invention. When the user acquires a backup of the private key 43 on the user terminal 4, the user selects from a list a storage server 30 (storage 31) to which n split pieces (two in the example in the figure) generated from the private key 43 by the secret sharing technique are to be distributed and stored via a screen (in the example in the figure, the "storage selection" screen) displayed by the wallet application 40 on the user terminal 4. The information in this list is registered, for example, in the storage information 14 of the backup management server 10. In the example in the figure, it shows that the user has selected two, "Server A" and "Server B", as the storage destinations from among the candidates of "Server A" to "Server X".
[0033] In this embodiment, as described above, a list of storage servers 30 capable of storing the split pieces is presented to the user, and the user selects n storage servers 30 based on their own judgment and authority, so that the service provider does not perform the custody service. As long as it does not become a custody service, for example, information such as the operator of the operation entity of each storage server 30, information related to the service, specifications related to the data storage function, and achievements, etc., which can be used as a reference when the user makes a selection, may be provided. Also, by making the number n of split pieces generated by secret sharing variable within a predetermined range so that the user can specify it each time, the configuration may be such that the degree of user involvement is further increased.
[0034] In the wallet application 40 of the user terminal 4, the secret key 43 is split into n split pieces (two split pieces, split piece 1 (431) and split piece 2 (432) in the example in the figure) by the secret sharing processing unit 41, and these split pieces are stored in the selected n storage servers 30 (two storage servers, storage server A (30a) and storage server B (30b) in the example in the figure) by the backup processing unit 42. Regarding which split piece is stored in which storage server 30, the user may specify it themselves, or it may be set randomly or according to a predetermined rule by the backup processing unit 42. Information on which storage server 30 each split piece is actually stored in is registered in the storage destination information 15 of the backup management server 10.
[0035] In the example in the figure, split piece 1 (431) is sent to storage server A (30a) and is shown to be stored in storage A (31a) managed by storage server A (30a). Similarly, split piece 2 (432) is sent to storage server B (30b) and is shown to be stored in storage B (31b) managed by storage server B (30b). This information is registered in the storage destination information 15 of the backup management server 10.
[0036] <Flow of processing> FIG. 3 is a diagram showing an outline of an example of the process flow of backing up a private key in an embodiment of the present invention. First, the wallet application 40 of the user terminal 4 makes an authentication request to the backup management server 10 (S01), and the authentication processing unit 11 of the backup management server 10 performs authentication processing (S02). Here, as described above, for example, user authentication and terminal authentication are performed by SMS authentication or social authentication.
[0037] Thereafter, in the user terminal 4, the backup processing unit 42 requests a list of storage servers 30 that are candidates for the storage destination of the split pieces from the backup management server 10 (S03). In the storage management unit 12 of the backup management server 10, a list of storage servers 30 capable of storing the split pieces registered in the storage information 14 is acquired and responded to the user terminal 4 (S04). In the user terminal 4, the wallet application 40 displays the list of storage servers 30 on the screen, and the user selects n storage servers 30 to be the storage destination from among them (S05). Then, triggered by an instruction from the user to perform backup or the like, the secret key 43 is dispersed into n split pieces by the secret dispersion processing unit 41 by secret dispersion (AONT method in this embodiment) (S06).
[0038] Thereafter, the backup processing unit 42 makes an authentication request to the storage server 30 selected as the storage destination (S07), and the storage server 30 performs authentication processing such as social authentication (S08). By performing authentication processing not only in the backup management server 10 in step S02 described above but also in the storage server 30 serving as the storage destination, the security can be made stronger.
[0039] After authentication, the backup processing unit 42 transmits the dispersible tablets to the storage server 30 at the storage destination (S09). When transmitting, for example, the data of the dispersible tablets is encoded into data in JSON (JavaScript Object Notation) format and transmitted. At the storage server 30 that has acquired the JSON data of the dispersible tablets, this is decoded to acquire the dispersible tablets (S10), and a request is made to the storage 31 that it manages for storage thereof (S11), and the storage 31 stores this (S12). Having received the completion of storage, the backup processing unit 42 of the user terminal 4 requests the backup management server 10 to register the information of the storage server 30 that has become the storage destination (S13), and the storage destination management unit 13 of the backup management server 10 registers this information in the storage destination information 15 (S14). Thereafter, the user terminal 4 notifies the user of the completion of backup (S15) and ends the process.
[0040] Note that the series of processes from step S07 to step S14 described above are repeated (or performed in parallel) for each of the n storage servers 30 that store n dispersible tablets. At that time, the processes of steps S13 and S14 may be performed collectively after the storage of the dispersible tablets in all n storage servers 30 is completed.
[0041] FIG. 4 is a diagram schematically showing an example of the flow of the secret key restoration process in an embodiment of the present invention. First, in the same manner as step S01 of the backup process shown in the example of FIG. 3 described above, the wallet application 40 of the user terminal 4 makes an authentication request to the backup management server 10 (S21), and the authentication processing unit 11 of the backup management server 10 performs an authentication process (S22). Thereafter, the backup processing unit 42 requests the backup management server 10 to acquire the information of the storage destination of the dispersible tablets (S23), and the storage destination management unit 13 of the backup management server 10 acquires the information of the storage server 30 that is the storage destination from the storage destination information 15 and responds to the user terminal 4 (S24).
[0042] Thereafter, the backup processing unit 42 of the user terminal 4 makes an authentication request to the storage server 30 serving as the storage destination (S25) in the same manner as step S07 of the backup processing shown in the example of FIG. 3 described above, and the storage server 30 performs an authentication process (S26).
[0043] After authentication, the backup processing unit 42 requests the storage server 30 serving as the storage destination of the split pieces to acquire the split pieces (S27). In the storage server 30 that has received the request, the split pieces are acquired from the storage 31 (S28, S29), encoded into JSON format data, and transmitted to the user terminal 4 (S30). In the user terminal 4 that has acquired the JSON data of the split pieces, the backup processing unit 42 decodes this to acquire the split pieces (S31).
[0044] The above series of processes from step S25 to step S31 are repeated (or performed in parallel) for each of the n storage servers 30 where the split pieces are stored to acquire n split pieces. Thereafter, the secret sharing processing unit 41 of the user terminal 4 restores the original secret key 43 from the n split pieces (S32), notifies the user of the completion of restoration (S33), and ends the process.
[0045] As described above, according to the digital wallet system 1 which is an embodiment of the present invention, by adopting a configuration in which the user himself / herself selects the storage server 30 (storage 31) serving as the storage destination of the split pieces generated by the secret sharing technique in the backup of the secret key 43 from among the candidates, it becomes possible to realize the service of a non-custodial digital wallet in which the user has all the authority when selecting and determining the storage destination of the split pieces.
[0046] As described above, the invention made by the present inventor has been specifically described based on the embodiments. However, the present invention is not limited to the above embodiments, and it goes without saying that various modifications can be made without departing from the gist thereof. Further, the above embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, it is possible to add, delete, or replace a part of the configuration of the above embodiments with other configurations.
[0047] In addition, each of the above configurations, functions, processing units, processing means, etc. may be realized in hardware by designing part or all of them, for example, by using an integrated circuit. Also, each of the above configurations, functions, etc. may be realized in software by a processor interpreting and executing a program for realizing each function. Information such as a program, table, file, etc. for realizing each function can be stored in a recording device such as a memory, hard disk, SSD, or a recording medium such as an IC card, SD card, DVD.
[0048] Also, in each of the above figures, control lines and information lines show those considered necessary for explanation, and do not necessarily show all the control lines and information lines in actual implementation. In reality, it may be considered that almost all configurations are interconnected.
Industrial Applicability
[0049] The present invention can be used in a digital wallet system that ensures the security related to the storage of a private key.
Explanation of Signs
[0050] 1... Digital wallet system, 2... Network, 4... User terminal, 10... Backup management server, 11... Authentication processing unit, 12... Storage management unit, 13... Storage destination management unit, 14... Storage information, 15... Storage destination information, 30... Storage Server, 30a... Storage Server A, 30b... Storage Server B, 30x... Storage Server X, 31... Storage, 31a... Storage A, 31b... Storage B, 31x... Storage X, 40... Wallet Application, 41... Secret Sharing Processing Unit, 42... Backup Processing Unit, 43... Secret Key, 431... Split Secret 1, 432... Split Secret 2
Claims
1. A digital wallet system for realizing a non-custodial digital wallet, comprising a wallet application and a user terminal having a private key, a backup management server for managing a backup of the private key, and n (n≥2) or more storage servers, and having the wallet application of the user terminal a secret sharing processing unit that generates n (k≤n) share pieces that cannot restore the private key unless k or more are collected from the private key by a secret sharing technique, and a backup processing unit that stores the n share pieces in the n storage servers, and having the backup management server a storage management unit that manages information on the storage servers capable of storing the share pieces, and a storage destination management unit that manages information on the storage servers storing the share pieces, and having the backup processing unit of the user terminal acquires a list of the storage servers capable of storing the share pieces from the storage management unit of the backup management server, stores the n share pieces in the n storage servers selected by the user from the list, and passes information on the n storage servers to the storage destination management unit of the backup management server for recording, thereby backing up the private key, acquires information on m (k≤m≤n) storage servers storing the share pieces from the storage destination management unit of the backup management server, respectively acquires the m share pieces from the m storage servers, and restores the private key from the m share pieces by a secret sharing technique. A digital wallet system.
2. In the digital wallet system according to claim 1, when accessing from the backup processing unit of the user terminal, the backup management server performs a predetermined authentication related to the user or the user terminal, and each of the storage servers performs a predetermined authentication related to the user or the user terminal when receiving a request for storing or acquiring the share piece from the user terminal. A digital wallet system.
3. In the digital wallet system according to claim 1, when generating the share pieces from the private key in the secret sharing processing unit of the user terminal, the digital wallet system accepts from the user a designation of the value of n that is the number of share pieces to be generated.
Citation Information
Patent Citations
JP1973060779A