HSM-Based Digital Wallet Management for Blockchain Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to provide secure, centralized management of multiple blockchain wallets and their lifecycle, especially for large investors and organizations, as they lack effective security measures for key generation, distribution, and transaction validation in an isolated environment.

Innovation Solution

A hardware and software complex utilizing Hardware Security Modules (HSMs) for secure storage and management of digital wallets, with multi-factor authentication and multisignature rules, integrated with an API for compatibility with existing systems, ensuring secure transaction processing and lifecycle management across multiple blockchain networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware wallets are used to store private keys, then security is improved, but centralized management of multiple wallets and lifecycle control becomes difficult

Engineering Contradiction:
ImprovesecurityVSAvoidcentralized management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments wallet management into two distinct parts: (1) HSM devices that securely store private keys and perform cryptographic operations in isolation, and (2) a centralized management server that handles wallet lifecycle operations, transaction validation, and key distribution. This segmentation allows each component to specialize in its strength - security for HSM and manageability for the server.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a management server as an intermediary between users and HSM devices. This intermediary handles the complexity of centralized management by orchestrating wallet creation, key distribution, and transaction validation, while the HSM devices remain secure and isolated. The intermediary translates high-level management operations into secure cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cold storage is used for backup copies of keys, then security is improved, but the hardware cannot be used in the course of transactions

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the private key storage function into a separate secure environment (HSM/cold storage) while keeping the transaction processing function in the online system. The HSM devices store keys offline and only interact by signing transactions that are brought to them, never exposing the keys to the online environment. This extraction allows both secure storage and transaction capability to coexist.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system adds a spatial dimension to key management by separating key storage (offline/HSM) from transaction processing (online/server) in different physical and logical environments. Transactions are validated and signed in this new dimension - the HSM dimension - where security requirements are met, then the results are transferred back to the online dimension for completion.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If software wallets are used, then ease of operation is improved, but security against hacking and data leakage deteriorates

Engineering Contradiction:
Improvesoftware accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The HSM device acts as a secure intermediary between the software wallet and the private key. The software wallet maintains full functionality and ease of use, while the HSM intermediary handles all sensitive cryptographic operations in a secure, isolated environment. This intermediary protects against software-based attacks while preserving user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The critical security function of private key storage and cryptographic operations is extracted from the software environment into a dedicated hardware security module. This extraction removes the vulnerability to software hacking while leaving the software wallet interface intact and easy to use. The software handles user interactions, while the hardware handles security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11308484B2System and method for secure storage of digital currencies and making transactions in a blockchain network
Publication Date: 2022.04.19 SMIRNOV ALEKSEY SERGEEVICH
  • US11308484B2 patent drawing
  • US11308484B2 patent drawing
  • US11308484B2 patent drawing

AI summary

The claimed solution relates to a method of making transactions in the blockchain framework using a protected hardware and software complex to ensure secure storage of digital currencies (cryptocurrencies) and control the entire lifecycle of multiple wallets simultaneously to make transactions in the blockchain network. Basic features of the hardware and software complex include the effective control over the entire life cycle of cold wallets, generation of digital wallets and secure storage of their private keys in an isolated environment using the hardware security modules (HSM), as well as maintaining the multiple level authentication of blockchain transactions. It is possible to use all the features of the complex due to compatibility with the application programming interface (API), which enables to integrate the complex into the existing software solutions, for example, banking systems.