Custody Server Trusted Execution Environment Private Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in enabling users to maintain control of their digital identities while providing service providers with confidence in the veracity of those identities, particularly in high-value cryptocurrency transactions, where managing and securely using private cryptographic keys is complex and difficult.
Innovation Solution
A computer system comprising a custody server that provides a trusted execution environment for securely storing and using a user's private transaction-signing key, with an encrypted enclave storing the key and associated policy data, allowing the server to authenticate and sign transactions on behalf of the user based on received authentication data and access policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manage their own private cryptographic keys, then they maintain control of their digital identities, but the complexity and security risk of handling private keys increases
Solution Approach 1:
The patent introduces a custody server as an intermediary between the user and the private key. The server stores the private key in an encrypted enclave and provides a trusted execution environment for transaction signing. This mediator handles the complex security tasks while maintaining user control through authentication mechanisms, thus reducing the complexity burden on users while preserving security.
Solution Approach 2:
The system enables users to authenticate themselves to the custody server using their digital identities. Once authenticated, users can authorize transactions without directly handling private keys. The system automatically performs key usage based on user authentication, providing self-service functionality that maintains user control while simplifying the process.
2Reliability
If service providers need to verify user identities with high confidence, then transaction security improves, but the complexity of identity verification increases
Solution Approach 1:
The custody server acts as a trusted intermediary that holds encrypted copies of user digital identities and provides authentication services. Service providers can verify user identities by interacting with the custody server's trusted execution environment, which handles the complex verification logic securely without requiring providers to store or process sensitive user data directly.
Solution Approach 2:
The custody server provides multiple functions including private key storage, user authentication, and transaction signing through a single unified system. This multi-functional approach consolidates what would otherwise be separate complex verification processes into one centralized service that service providers can reliably use.
3Reliability
If private keys are stored securely, then security is improved, but the ease of operation for users decreases
Solution Approach 1:
The custody server securely stores private keys in encrypted enclaves while providing user-friendly authentication interfaces. Users interact with the system through simple authentication processes rather than key management, maintaining security through the server's secure storage while preserving ease of operation through automated transaction signing based on user authentication.
Solution Approach 2:
The system enables users to authorize transactions through straightforward authentication processes. Once authenticated, the system automatically handles the complex key signing operations, making the process simple for users while maintaining secure key storage. Users service themselves through authentication without needing to understand or interact with the underlying cryptographic key management.
Data Source
AI summary
A computer system comprises a networked custody server for signing transactions on behalf of a plurality of users. The custody server includes a processor that provides a trusted execution environment for securely decrypting and executing software instructions stored in an encrypted enclave of the custody server. A plurality of users' private keys are stored in the encrypted enclave with a respective access policy. The custody server receives a request to sign a transaction on behalf of a user, and user-authentication data for the user, and determines within the trusted execution environment whether the user-authentication data satisfies the access policy associated with the user. If so, it uses the user's private key to sign the transaction within the trusted execution environment.


