Air-Gapped Cryptocurrency Keystore with Distributed Key Sharding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptocurrencies face challenges in secure storage and management of private spending keys, as existing solutions are vulnerable to loss, theft, and internal risks, particularly in third-party custody services where a single employee's compromise can lead to fund loss.

Innovation Solution

A secure hardware cryptographic keystore system that distributes spending power across a group of key holders using multisignature wallets or sharding, ensuring that no single individual can unilaterally move funds, and employs layered encryption and air-gapped key generation to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single employee holds the private key for cryptocurrency custody, then the operation is simple and fast, but the security is compromised as the employee can unilaterally move funds or the key may be lost

Engineering Contradiction:
Improvesecurity of fund custodyVSAvoidkey management structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the private key into multiple distinct key parts and distributes them to different key holders. No single key holder possesses the complete private key, making it impossible for any one individual to unilaterally access or move funds. This segmentation directly resolves the contradiction by improving security through distributed key custody while maintaining a manageable structure through defined access protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple key parts from different key holders to reconstruct the complete private key only when a quorum is present. This merging mechanism ensures that funds can be accessed legitimately when authorized, while the requirement for multiple parties prevents single-point compromise. The combination approach resolves the contradiction by enabling secure multi-party control without excessive operational complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If cryptographic keys are frequently rotated and re-encrypted with staff changes, then security is maintained against internal risks, but operational efficiency decreases due to constant key management overhead

Engineering Contradiction:
Improveprotection against internal risksVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent establishes key parts and access policies in advance during system setup, before any staff changes occur. The quorum-based access structure and key distribution framework are pre-configured to handle future personnel changes without requiring key rotation. This preliminary action resolves the contradiction by providing ongoing security against internal risks while eliminating the operational overhead of frequent key management interventions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically manages key reconstruction and transaction authorization through predefined quorum rules and cryptographic protocols, without requiring manual key rotation or re-encryption procedures. When staff changes occur, the system self-adjusts by simply updating key holder registrations rather than requiring cryptographic key changes. This self-service mechanism maintains security while preserving operational efficiency.

Inventive Principle:
Principle #25Self-service

3Reliability

If a quorum of key holders is required to access funds, then the risk of unilateral fund movement is reduced, but the access process becomes more complex and slower

Engineering Contradiction:
Improveprevention of unauthorized accessVSAvoidfund access process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a transaction coordinator as an intermediary that manages the quorum verification process. The coordinator collects key parts from participating key holders, verifies the quorum is met, and facilitates the reconstruction and use of the private key for transaction signing. This intermediary simplifies the access process by providing a centralized coordination point, reducing the operational complexity that would otherwise arise from direct peer-to-peer key management among multiple holders.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230396456A1Secure hardware cryptocurrency keystore and key generation ceremony
Publication Date: 2023.12.07 SALT BLOCKCHAIN INC
  • US20230396456A1 patent drawing
  • US20230396456A1 patent drawing
  • US20230396456A1 patent drawing

AI summary

A method and apparatus for a secure hardware cryptographic keystore for custody of cryptocurrency funds (and other digital such as NFTs) which ensures no individual participant in key generation or transaction signing ever has access to the full key or even a complete key-part, thereby eliminating the traditional need to rotate keys and re-encrypt data when authorized key-holders change. The system includes an air-gapped key generator machine and an air-gapped transaction signing machine that lack network communications capabilities. The key generator machine receives an entropy source and produces sets of public/private key pairs for use on a cryptocurrency blockchain.