Dynamic MPC Node Provisioning for Secure Digital Asset Custody

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital asset custody systems face challenges in protecting sensitive data, configuring and managing components, and scaling to meet additional capacity needs.

Innovation Solution

A digital asset custody system utilizing multi-party computation (MPC) nodes, each operating in different computing environments, generates and deploys private key shares for secure digital asset transactions without storing full private keys, and employs an MPC controller to manage cluster configurations and communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional digital asset custody systems store full private keys, then transaction signing is simple and fast, but security is compromised and data theft becomes easier

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The private key is segmented into multiple secret shares distributed across different MPC nodes. Each node holds only a portion of the key material, and no single node can sign transactions alone. This segmentation prevents data theft while maintaining the ability to sign transactions through coordinated operation of multiple nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple MPC nodes are merged into a unified custody system where their individual secret shares are combined to form the complete private key for transaction signing. The nodes work together as a single secure unit, merging their computational capabilities to sign transactions without any single node having access to the full private key.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If the system uses fixed MPC node configurations, then deployment is simple, but scalability to meet additional capacity needs is limited

Engineering Contradiction:
ImprovescalabilityVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The MPC node configuration is made dynamic rather than fixed. The system can dynamically add, remove, or reconfigure MPC nodes based on capacity demands. The controller automatically adjusts the number and distribution of nodes across computing environments, allowing the system to adapt to changing scalability requirements without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

MPC nodes are designed as universal, multi-functional components that can be deployed across different computing environments and configured for various custody needs. The same node template can serve multiple purposes in different clusters, enabling flexible scalability without requiring specialized deployment procedures for each configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If MPC nodes are deployed across multiple computing environments, then system reliability and security are improved, but configuration management becomes more complex

Engineering Contradiction:
Improvesystem reliabilityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A centralized controller acts as an intermediary between the MPC node initializers and operators across different computing environments. The controller manages configuration generation, distribution, and coordination, simplifying the complexity of multi-environment deployment by providing a single point of control that automatically handles configurations across all environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Configuration templates and initial settings are prepared in advance by the controller before nodes are deployed to computing environments. This preliminary action includes pre-generating configuration files, establishing communication protocols, and preparing node initialization parameters, which reduces the complexity of actual deployment and ongoing management.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If the system dynamically provisions MPC nodes, then scalability is improved, but resource management and coordination becomes more complex

Engineering Contradiction:
Improvesystem capacityVSAvoidresource management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The controller implements feedback mechanisms that monitor system capacity, node performance, and computational resource availability. Based on this feedback, the controller automatically adjusts the number of MPC nodes being provisioned, optimizes resource allocation across environments, and coordinates node operations to maintain optimal system capacity without excessive resource management overhead.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260039457A1Systems and methods to dynamically provision multi-party computation (MPC) nodes
Publication Date: 2026.02.05 NASDAQ INC
  • US20260039457A1 patent drawing
  • US20260039457A1 patent drawing
  • US20260039457A1 patent drawing

AI summary

A digital asset custody system dynamically provisions clusters of multi-party computation (MPC) nodes to securely create different private key shares for signing digital asset transactions and generate blockchain addresses for digital asset owners (AOs). Each cluster of MPC nodes is configured for an AO and to operate in a plurality of computing environments. Each of the computing environments is associated with a respective different signing party, and each computing environment includes a respective one of plural MPC node initializers and a respective one of plural MPC node operators. An MPC controller and MPC node initializers perform operations to generate first configuration information for each MPC node in a first MPC cluster of MPC nodes. Each MPC node operator, based on the first configuration information, deploys one of the MPC nodes in the first MPC cluster in the computing environment corresponding to where the MPC node operator operates, such that the one MPC node in the first MPC cluster is deployed into a different one of the plurality of computing environments as compared to the computing environments into which the other MPC nodes in the first MPC cluster are deployed. Analogous operations are performed to generate second configuration information to deploy a second MPC cluster, third configuration information to deploy a third MPC cluster, etc. as desired.