Cohort Threshold Signing for Secure Blockchain Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-party computation (MPC) based key operations in blockchain systems face issues such as loss of digital assets due to the loss of a single key and reduced efficiency when not all devices are online, as well as security risks from unauthorized access and key exposure.

Innovation Solution

The implementation of a cohort threshold signing policy and the use of partial private keys, where some keys are maintained online and others offline, with a predetermined threshold approval metric for secure operations, allowing flexible and dynamic digital signing processes even when not all devices are available.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MPC-based key operations use multiple parties holding private data, then security against unauthorized access is improved, but the system becomes vulnerable to asset loss when any single key is lost

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidrisk of digital asset loss
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the private key into multiple shares distributed among different parties. Each party holds a portion of the key material, and no single party has access to the complete private key. This segmentation prevents both unauthorized access (requiring multiple parties to collude) and total asset loss (since individual key shares can be recovered or replaced without compromising the entire system).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements key recovery mechanisms and backup procedures in advance. When a key share is lost or a party becomes unavailable, the system can reconstruct the private key using threshold cryptography and pre-established recovery protocols. This cushioning ensures that temporary unavailability or loss of individual key shares does not result in permanent asset loss.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If all devices in a cohort must be online to perform blockchain operations, then security is maintained, but operational efficiency decreases when devices are unavailable

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidblockchain operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic threshold cryptography that adjusts the number of required online parties based on operational context. The system can dynamically modify the threshold parameter, allowing operations to proceed with fewer online devices when necessary while maintaining adaptive security levels. This dynamic approach balances security requirements with operational efficiency in real-time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of key participation from fixed (all parties required) to variable (threshold-based). By modifying the threshold parameter, the system can accommodate different operational scenarios - requiring more parties for high-value transactions and fewer parties for routine operations. This parameter change enables flexible operation while maintaining appropriate security levels.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If a single private key is used for blockchain operations, then operational simplicity is maintained, but security risk increases from key exposure and loss

Engineering Contradiction:
Improveblockchain operation simplicityVSAvoidsecurity against key exposure
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single private key into multiple distributed shares, eliminating the security risks associated with holding one centralized key. Each party holds an encrypted portion that is useless alone but contributes to the whole when combined with sufficient other shares. This maintains operational simplicity through standardized cryptographic interfaces while dramatically improving security through distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries including secure enclaves, threshold cryptography protocols, and key management services that mediate between the user and the private key material. These intermediaries handle key generation, storage, and recovery operations, allowing users to maintain simple operations while the complex security mechanisms operate transparently in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12155750B2Systems and methods for generating secure, encrypted communications across distributed computer networks for authorizing use of cryptography-based digital repositories in order to perform blockchain operations in decentralized applications
Publication Date: 2024.11.26 COINBASE INC
  • US12155750B2 patent drawing
  • US12155750B2 patent drawing
  • US12155750B2 patent drawing

AI summary

Methods and systems for the use of multi-party computation (“MPC”) key systems that involve the use of multiple parties, each of which hold respective private data that may be used to evaluate a computation without ever revealing any of the private data held by each party to perform blockchain operations. Using the MPC key systems, the methods and systems generate secure, encrypted communications across distributed computer networks for authorizing use of cryptography-based digital repositories in order to perform blockchain operations in decentralized applications.