Cohort Threshold Signing for Secure Blockchain Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multi-party computation (MPC) based key operations in blockchain systems face issues such as loss of digital assets due to the loss of a single key and reduced efficiency when not all devices are online, as well as security risks from unauthorized access and key exposure.
Innovation Solution
The implementation of a cohort threshold signing policy and the use of partial private keys, where some keys are maintained online and others offline, with a predetermined threshold approval metric for secure operations, allowing flexible and dynamic digital signing processes even when not all devices are available.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MPC-based key operations use multiple parties holding private data, then security against unauthorized access is improved, but the system becomes vulnerable to asset loss when any single key is lost
Solution Approach 1:
The patent segments the private key into multiple shares distributed among different parties. Each party holds a portion of the key material, and no single party has access to the complete private key. This segmentation prevents both unauthorized access (requiring multiple parties to collude) and total asset loss (since individual key shares can be recovered or replaced without compromising the entire system).
Solution Approach 2:
The patent implements key recovery mechanisms and backup procedures in advance. When a key share is lost or a party becomes unavailable, the system can reconstruct the private key using threshold cryptography and pre-established recovery protocols. This cushioning ensures that temporary unavailability or loss of individual key shares does not result in permanent asset loss.
2Reliability
If all devices in a cohort must be online to perform blockchain operations, then security is maintained, but operational efficiency decreases when devices are unavailable
Solution Approach 1:
The patent implements dynamic threshold cryptography that adjusts the number of required online parties based on operational context. The system can dynamically modify the threshold parameter, allowing operations to proceed with fewer online devices when necessary while maintaining adaptive security levels. This dynamic approach balances security requirements with operational efficiency in real-time.
Solution Approach 2:
The patent changes the parameter of key participation from fixed (all parties required) to variable (threshold-based). By modifying the threshold parameter, the system can accommodate different operational scenarios - requiring more parties for high-value transactions and fewer parties for routine operations. This parameter change enables flexible operation while maintaining appropriate security levels.
3Ease of operation
If a single private key is used for blockchain operations, then operational simplicity is maintained, but security risk increases from key exposure and loss
Solution Approach 1:
The patent segments the single private key into multiple distributed shares, eliminating the security risks associated with holding one centralized key. Each party holds an encrypted portion that is useless alone but contributes to the whole when combined with sufficient other shares. This maintains operational simplicity through standardized cryptographic interfaces while dramatically improving security through distribution.
Solution Approach 2:
The patent introduces cryptographic intermediaries including secure enclaves, threshold cryptography protocols, and key management services that mediate between the user and the private key material. These intermediaries handle key generation, storage, and recovery operations, allowing users to maintain simple operations while the complex security mechanisms operate transparently in the background.
Data Source
AI summary
Methods and systems for the use of multi-party computation (“MPC”) key systems that involve the use of multiple parties, each of which hold respective private data that may be used to evaluate a computation without ever revealing any of the private data held by each party to perform blockchain operations. Using the MPC key systems, the methods and systems generate secure, encrypted communications across distributed computer networks for authorizing use of cryptography-based digital repositories in order to perform blockchain operations in decentralized applications.


