System and method for securing access, recovery, and management of cryptographic keys and digital identities
A decentralized key management system using TSUK and PSUK addresses the risks of key loss and theft by ensuring secure, decentralized cryptographic operations and flexible access management, maintaining system integrity without central points of failure.
Patent Information
- Application Number
- PCT/US2025/040823
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-11
- Filing Date
- 2025-08-06
- Publication Date
- 2026-02-19
AI Technical Summary
Existing digital security systems face risks of irreversible asset loss due to private key loss or theft, and custodial solutions introduce additional vulnerabilities such as internal compromise and central points of failure, while traditional key recovery methods pose risks of loss, theft, coercion, or legal exposure.
A decentralized key management system using Temporary Secret User Keys (TSUK) and Permanent Secret User Keys (PSUK) is implemented, where TSUK operates as a locally-stored authentication credential for command instructions, and PSUK is cryptographically partitioned across multiple processing nodes, enabling secure, decentralized cryptographic operations without central storage or reconstruction, and allowing programmable replacement and consensus-based authorization.
The system provides secure, decentralized access and management of cryptographic keys, maintaining system integrity even in the event of key loss or theft, with no single point of failure, and enabling flexible access management through trustless, decentralized operations.
Smart Images

Figure US2025040823_19022026_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR SECURING ACCESS, RECOVERY, ANDMANAGEMENT OF CRYPTOGRAPHIC KEYS AND DIGITAL IDENTITIESFIELD OF THE INVENTION
[0001] The present invention relates to decentralized digital security systems, particularly to methods and systems for secure access, recovery, and management of cryptographic keys and digital identities.BACKGROUND OF THE INVENTION
[0002] Secure access to digital assets and systems typically relies on secret keys or passwords. In Web2 and Web3 ecosystems, this introduces significant risks. Loss or theft of private keys in blockchain systems often results in irreversible asset loss. Custodial solutions introduce additional attack vectors, including internal compromise and central points of failure. Traditional key recovery methods require backing up secrets or involving trusted parties, both of which create risks of loss, theft, coercion, or legal exposure.SUMMARY OF THE INVENTION
[0003] The term Temporary Secret User Key (TSUK) refers herein to a temporary cryptographic key comprising a locally-stored secret key element that serves as an authentication credential for a user device. The temporary key:
[0004] (a) is configured to digitally sign command instructions directed to a distributed or centralized permanent key system, the instructions commanding the generation of cryptographic signatures, decryption operations, or other cryptographic functions without the temporary key containing, deriving, or reconstructing the permanent key;
[0005] (b) operates as a cryptographic authentication mechanism for signing instruction sets that are transmitted to multiple distributed or single processing nodes holding shares of a permanent key, wherein the processing nodes cooperatively execute the commanded cryptographic operations;
[0006] (c) functions in conjunction with user configuration data and associated metadata to verify the authenticity and authorization of cryptographic operation requests, wherein the combination of the temporary key signature and user-specific configuration parameters provides multi-factor authentication for command validation;
[0007] (d) is stored in local memory of a user computing device and does not require centralized registration, backup, or recovery mechanisms;
[0008] (e) may be implemented within secure hardware enclaves, mobile devices, or trusted execution environments with access controlled through user authentication methods including biometric verification or passcode entry;
[0009] (f) is subject to programmable replacement logic enabling substitution under predefined conditions including but not limited to:•
[0010] timeout-based replacement following periods of inactivity;•
[0011] helper-authorized replacement through pre-approved third-party authorization;•
[0012] consensus-based replacement requiring approval from multiple predetermined entities;
[0013] (g) maintains system security integrity such that loss, theft, or compromise of the temporary key does not result in unauthorized access to underlying permanent cryptographic assets or compromise of the distributed permanent key system;
[0014] (h) may be configured with hierarchical permission structures enabling designation of subordinate temporary keys with restricted operational authority; and
[0015] (i) operates independently of traditional centralized recovery vectors including passwords, security questions, registered communication channels, or centrally-stored biometric data.
[0016] The term Permanent Secret User Key (PSUK) refers herein to: A cryptographic key architecture comprising a permanent cryptographic key that is cryptographically partitioned into multiple distinct shares or fragments, wherein the shares are distributed across and stored within a plurality of independent processing nodes or computing entities, and wherein:
[0017] (a) no single processing node possesses sufficient information to independently reconstruct, derive, or access the complete permanent cryptographic key;
[0018] (b) the distributed shares are configured to cooperatively execute cryptographic operations including but not limited to digital signature generation, message decryption, and authentication functions through distributed computation protocols such as threshold cryptography, multi-party computation (MPC), or other cryptographic sharing schemes;
[0019] (c) the execution of cryptographic operations occurs without requiring reconstruction, transmission, or storage of the complete permanent cryptographic key in any single location or memory space;
[0020] (d) the processing nodes operate in a trustless manner such that no individual node needs be trusted with the security of the overall cryptographic system;
[0021] (e) the distributed key architecture maintains cryptographic security properties such that compromise of a subset of processing nodes below a predetermined threshold does not result in compromise of the permanent cryptographic key or unauthorized access to protected cryptographic operations;
[0022] (f) The system is configured to respond to authenticated command instructions received from the temporary keys (TSUK) to perform requested cryptographic operations using the distributed key shares of the PSUK; and
[0023] (g) The distributed processing nodes may comprise hardware security modules, trusted execution environments, blockchain validators, or other computing entities capable of secure cryptographic computation and communication.
[0024] The system provides a trustless, decentralized key management system comprising distributed processing units (e g., MPC nodes or other decentralized signers), a user device holding a temporary secret key (TSUK), and a consensus-based replacement protocol. A permanent user secret key (PSUK) is split or created in a split form and stored across multiple computing entities, none of which can reconstruct the full key independently. Users interact with the system using a temporary key, which can be replaced under programmable conditions such as timeout, helper intervention, or consensus approval. Optional components include delegated TSUKs with restricted permissions, remote revocation via external signals, and Al-based behavioral filtering to evaluate transaction risk.THE BRIEF DESCRIPTION OF SEVERAL VIEWS OFTHE DRAWINGS
[0025] The present disclosed subject matter will be understood and appreciated more fully from the following detailed description taken in conjunction with the drawings in which corresponding or like numerals or characters indicate corresponding or like components. Unless indicated otherwise, the drawings provide exemplary embodiments or aspects of the disclosure and do not limit the scope of the disclosure. Tn the drawings: FIG. 1 shows a block diagram of an environment for securing access, recovery, and management of cryptographic keys and digital identities, in accordance with some exemplary embodiments of the subject matter;FIG. 2 shows a flow chart diagram of a scenario for securing access, recovery, and management of cryptographic keys and digital identities in accordance with some exemplary embodiments of the disclosed subject matter;FIG. 3 shows a flowchart diagram of a method for recovering a temporary secret user key, in accordance with some exemplary embodiments of the disclosed subject matter; andFIG. 4 depicts a transaction validation flowchart , in accordance with some exemplary embodiments of the disclosed subject matter.DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] The following embodiments describe various implementations of the claimed invention. These examples are provided to aid understanding of the invention and should not be construed as limiting.
[0027] Referring to FIG. 1, there is shown a block diagram of an environment for securing access, recovery, and management of cryptographic keys and digital identities, designated generally as environment 100, in accordance with exemplary embodiments of the disclosed subject matter.
[0028] The system comprises a personal computing device 101 operatively configured to store and execute cryptographic operations. The personal computing device 101 contains a temporary key 1011 and an authenticator 1012 that is capable of generating cryptographic signatures, as integral functional components.
[0029] The temporary key 1011 comprises a locally-stored cryptographic key element configured to generate digitally signed command instructions for transmission to external distributed processing entities. The temporary key 1011 is implemented as a cryptographic secret stored within the memory subsystem of personal computing device 101, wherein the secret enables the generation of digital signatures for authenticating command instructions without containing, deriving, or reconstructing any portion of a permanent cryptographic key.
[0030] The authenticator 1012 comprises a software or hardware module configured to validate user authorization and manage cryptographic signing operations using the temporary key 1011. In exemplary embodiments, authenticator 1012 may be implemented as a secure software application, a hardware security module (HSM), a trusted execution environment (TEE), or a secure enclave within personal computing device 101. The authenticator 1012 is configured to receive user authentication credentials including but not limited to biometric data, passcodes, or multi-factor authentication tokens, and upon successful validation, authorize the temporary key 1011 to perform cryptographic signing operations.A decentralized permanent key 102 is illustrated within a cloud formation, representing the distributed nature of the permanent key across multiple independent processing nodesor computing entities, wherein no single node possesses sufficient information to reconstruct the complete permanent key. The decentralized permanent key 102 comprises a cryptographic key architecture wherein a permanent secret key has been mathematically partitioned using cryptographic sharing schemes such as Shamir's Secret Sharing, threshold cryptography, or multi-party computation protocols into a plurality of distinct cryptographic shares.
[0031] Validators 103 comprise a plurality of distributed processing nodes, each configured to store a cryptographic share of the decentralized permanent key 102 and to cooperatively execute cryptographic operations through distributed computation protocols. In exemplary embodiments, validators 103 may comprise hardware security modules, blockchain validator nodes, secure multi-party computation nodes, or other computing entities capable of secure cryptographic processing and inter-node communication. Each validator within validators 103 maintains a cryptographic share that is insufficient alone to reconstruct the complete decentralized permanent key 102, thereby ensuring that no single point of failure or compromise can result in unauthorized access to the complete permanent key.The personal computing device 101 is communicatively coupled to the decentralized permanent key system 102 through network communication channels, enabling bidirectional data transmission between the temporary key 1011 and the validators 103. The network communication channels may comprise secure internet protocols, blockchain networks, peer-to-peer networks, or other cryptographically secured communication methods suitable for transmitting sensitive cryptographic data.
[0032] The personal computing device 101 is a device that includes a processing unit. Examples for such device are a personal computer, a laptop, a server, a wearable device, a tablet a cellular device and IOT (internet of things) device.
[0033] In operation, the authenticator 1012 receives user authentication credentials and, upon successful validation, authorizes the temporary key 1011 to generate digitally signed command instructions. The authentication process may involve multiple factorsincluding biometric verification, knowledge-based authentication, or possession-based authentication tokens. Upon successful authentication, the authenticator 1012 enables the temporary key 1011 to access its stored cryptographic secret for the purpose of signing command instructions.
[0034] The command instructions are transmitted from the personal computing device 101 to the validators 103 via secure communication protocols. The command instructions comprise digitally signed messages that specify the requested cryptographic operation, such as digital signature generation for a transaction, message decryption, or authentication token generation. Each command instruction is cryptographically signed using the temporary key 1011, providing authentication of the command origin and ensuring non-repudiation of the request.
[0035] The validators 103, upon receiving and verifying the digitally signed command instructions, cooperatively execute the requested cryptographic operations using their respective shares of the decentralized permanent key 102 through distributed computation methods such as threshold cryptography or multi-party computation (MPC). The verification process includes validating the digital signature generated by temporary key 1011, confirming the authorization level of the requesting device, and ensuring compliance with any predefined operational constraints or security policies.
[0036] During the cooperative execution phase, validators 103 engage in a distributed cryptographic protocol wherein each validator contributes its share of the decentralized permanent key 102 to collectively perform the requested operation. This distributed computation occurs without any single validator having access to the complete decentralized permanent key 102, maintaining the security properties of the distributed key architecture throughout the operation.
[0037] The cryptographic operation results, including digital signatures or decrypted data, are transmitted back to the personal computing device 101 without requiring reconstruction or transmission of the complete decentralized permanent key 102, thereby maintaining the security and integrity of the distributed key architecture throughout the operational process. The result transmission may include cryptographic proofs of correct execution, enabling the personal computing device 101 to verify that the requested operation was performed correctly by the validators 103.
[0038] The distributed architecture illustrated in FIG. 1 provides enhanced security properties compared to centralized key storage systems. The decentralized permanent key 102 cannot be compromised through attack on any single validator within validators 103, as no individual validator possesses sufficient information to reconstruct the complete key. The system maintains operational availability even in the event of failure or compromise of a subset of validators 103, provided that a sufficient threshold of honest validators remains operational.
[0039] The temporary key 1011 serves as a revocable authentication credential that does not compromise the security of the decentralized permanent key 102 in the event of loss, theft, or compromise. The separation of authentication responsibilities between the temporary key 1011 and the decentralized permanent key 102 enables flexible access management while maintaining the highest level of security for the underlying cryptographic assets.FIG. 2 shows a flow chart diagram of a scenario for securing access, recovery, and management of cryptographic keys and digital identities in accordance with some exemplary embodiments of the disclosed subject matter.
[0040] At block 200, a new user initiates the system by randomly generating a secret key. The block generates a Temporary Secret User Key (TSUK) using the user's computing device. The block produces a cryptographic secret key stored locally on the user's device.The purpose of the block is to establish initial user authentication credentials.
[0041] At block 210, the computing device sends a request to the validators. The block transmits a digitally signed request using the TSUK to the validator network to generate a Permanent Secret User Key (PSUK). The block delivers cryptographically authenticated command instructions to the distributed validator network. The purpose of the block is to initiate the creation of the distributed permanent key system.
[0042] At block 215, the validators receive a request to generate a signature. The block accepts incoming cryptographic operation requests and performs validation of the digitally signed command instructions from the TSUK. The block produces a validated command for cryptographic processing. The purpose of the block is to interface with signature generation requests requiring cryptographic validation.
[0043] At block 220, the validators perform request validity checking and signature creation. The block validates the legitimacy of the incoming request from the TSUK and creates a cryptographic signature using the distributed PSUK shares through cooperative computation. On the validator's side, the system checks request validity, then validators create signature using PSUK as a permanent decentralized key. The block produces a valid cryptographic signature without reconstructing the complete permanent key. The purpose of the block is to execute secure distributed cryptographic operations.
[0044] At block 225, the system transmits the completed transaction with the generated signature. The block sends the transaction containing the PSUK's cryptographic signature to the requesting entity. The block delivers the final cryptographically signed transaction or record. The purpose of the block is to complete the cryptographic operation and return the signed result to the user.FIG. 3 shows a flowchart diagram of a method for recovering a temporary secret user key, in accordance with some exemplary embodiments of the disclosed subject matter;
[0045] At block 300, the system detects that TSUK A is lost. The block determines that the primary temporary secret user key has become unavailable or inaccessible. The block produces a loss detection signal indicating the compromise or unavailability of the original temporary key. The block delivers a trigger mechanism for initiating the key replacement process. The purpose of the block is to detect and respond to situations where the original TSUK becomes inaccessible due to device loss, hardware failure, or other circumstances.
[0046] At block 310, a new TSUK B is randomly generated in the user's computing device. The block creates a replacement temporary secret user key using cryptographic random number generation processes within the user's computing device. The block produces a new cryptographic secret key with equivalent functional capabilities to the lost TSUK A. The block delivers a fresh TSUK B stored locally within the memory subsystem of the computing device. The purpose of the block is to establish a new authentication credential for the user to replace the lost temporary key.
[0047] At block 320, helpers and / or algorithm authorize the replacement process. The block validates the legitimacy of the TSUK replacement request through predetermined authorization mechanisms, which may include approval from designated helper entities or execution of automated validation algorithms. The block produces authorization approval for key substitution based on predefined security policies and authentication criteria. The block delivers authenticated permission to proceed with the replacement operation. The purpose of the block is to ensure secure and authorized key replacement through trusted third-party entities or automated validation logic, preventing unauthorized key replacement attempts.
[0048] At block 330, the system revokes TSUK A and declares TSUK B to control PSUK (decentralized permanent user key). The block terminates the authorization and operational authority of the lost temporary key TSUK A and establishes the new temporary key TSUK B as the active controller for the distributed permanent key system. The block produces updated key association records and authorization mappings withinthe distributed validator network. The block delivers control transfer from the revoked TSUK A to the newly authorized TSUK B for accessing and commanding operations involving the decentralized permanent user key. The purpose of the block is to complete the key replacement process and restore user access to the distributed cryptographic system while ensuring that the compromised TSUK A can no longer authorize cryptographic operations.FIG. 4 depicts a transaction validation flowchart wherein personal computing device requests TSUK signing, Al evaluates risk, voting occurs, validators confirm votes, and PSUK generates cryptographic signature in accordance with some exemplary embodiments of the disclosed subject matter.
[0049] At block 400, the user's computing device requests signature generation with TSUK. The block receives a transaction request requiring cryptographic authentication. The block produces a digitally signed command instruction using the temporary secret user key. The block delivers an authenticated signature request to the distributed validation system. The purpose of the block is to initiate cryptographic signing operations through the temporary key authentication mechanism.
[0050] At block 410, Al advises on the transaction. The block analyzes the transaction request for risk factors and behavioral anomalies. The block produces a risk assessment score and recommendation. The block delivers a transaction advisory signal for further processing. The purpose of the block is to provide automated risk evaluation and transaction filtering capabilities.
[0051] At block 420, Al and / or voters notify on the transaction request and vote on the transaction. The block collects risk assessment data and stakeholder input regarding transaction authorization. The block produces voting results and consensus decisions regarding the transaction request. The block delivers vote validation data to the decentralized validators. The purpose of the block is to implement consensus-basedtransaction approval mechanisms.
[0052] At block 430, voters send vote to validators. The block transmits the collected voting data and consensus results from the voting entities to the distributed validator network. The block produces authenticated vote transmission to the validator nodes. The block delivers vote validation data for processing by the decentralized validators. The purpose of the block is to ensure secure transmission of voting decisions to the validation infrastructure.
[0053] At block 440, validators validate votes. The block verifies the authenticity and legitimacy of received voting data from the voting entities. The block produces validated consensus results confirming transaction approval. The block delivers authorization confirmation to the PSUK signature generation system. The purpose of the block is to ensure secure and authenticated transaction approval through distributed validation.
[0054] At block 450, PSUK generates signature. The block executes cryptographic signature generation using distributed permanent key shares following successful vote validation. The block produces a cryptographic signature for the requested transaction using the distributed permanent secret user key. The block delivers the completed cryptographic signature to the requesting system. The purpose of the block is to perform secure distributed cryptographic operations without reconstructing the complete permanent key.
Claims
CLAIMS1. A trustless key control system comprising:(a) a user device configured to store a temporary secret user key (TSUK) used to generate digitally signed command instructions;(b) a permanent user secret key (PSUK) that is stored in cryptographically distributed form across multiple processing nodes, wherein no single node possesses sufficient information to reconstruct the full PSUK;(c) a cryptographic operation protocol in which commands signed by the TSUK initiate cryptographic operations involving the PSUK, wherein the operations are executed without reconstructing or revealing the PSUK; and(d) a programmable logic for replacing the TSUK based on one or more predefined conditions, the conditions including: (i) a timeout following a period of user inactivity;(ii) third-party authorization; or (iii) consensus approval among predefined entities; wherein the system performs cryptographic operations without relying on centralized secrets, backup mechanisms, or password-based recovery.
2. The system of claim 1, further comprising: an optional artificial intelligence (Al) module configured to evaluate the behavioral context of a transaction request; wherein the Al module is further configured to block, delay, or flag the transaction based on a computed risk score.
3. The system of claim 2, wherein: the Al risk filtering logic is executed locally on the user computing device that stores the TSUK; and optionally aggregates decentralized telemetry for enhanced decision-making.
4. The system of claim 1, wherein: in the event of user incapacity or death, one or more designated helpers or agents are authorized to initiate transfer of control of the TSUK; wherein the authorization is based on public key -based credentials.
5. The system of claim 4, wherein: the inheritance mechanism permits TSUK replacement only after receiving threshold approval from multiple helper keys.
6. The system of claim 1, wherein: the primary TSUK is configured to designate one or more subordinate TSUKs with limited authority; wherein the subordinate TSUKs operate according to predefined rules, including: (a) transaction amount limits; (b) address restrictions; or (c) operational scope constraints.
7. The system of claim 6, wherein: the subordinate TSUKs are assigned to family members, employees, or automated agents, and are configured with constrained access rights as defined by the primary TSUK.
8. The system of claim 1, wherein: the user device is configured to monitor for an external signal, the signal comprising at least one of: (a) an SMS message; (b) an email; or (c) a blockchain event; and upon detection, the system is configured to revoke and destroy the TSUK and initiate its replacement automatically.
9. The system of claim 1, further comprising: a tamper-evident ledger on which all cryptographic operations performed using the PSUK are recorded, wherein the ledger enables future audit and traceability of authorized operations.
10. The system of claim 1, wherein: neither the TSUK nor the PSUK requires for operation or recovery any of the following: (a) biometric data; (b) passwords; (c) security questions; or (d) centralized personal information.
Citation Information
Patent Citations
Methods and Systems For Cryptographic Private Key Management For Secure Multiparty Storage And Transfer Of Information
US20200162246A1
Device behavior analytics
US20220030022A1
Mobile device transaction credential lending
US20230169501A1
System and method for distributed custody access token management
US20230327859A1
Generating shared cryptographic keys
WO2023036534A1