Hybrid Digital-Physical Security System for Digital Asset Custody

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital assets are vulnerable to cybersecurity threats due to their technical design and infrastructure, particularly during transfer and storage, which can lead to high loss potential from successful cyberattacks.

Innovation Solution

A hybrid digital/physical security system is proposed, comprising an internet-connected 'portal' system and an air-gapped, offline 'vault' system. This system uses increased levels of encryption, air-gap segregation, and redundancy, with physical communication pathways like QR codes and digital signatures to validate messages, thereby reducing attack vectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital assets are transferred using digital instructions through API or CLI, then convenience and ease of operation are improved, but vulnerability to cyberattacks and loss potential increase

Engineering Contradiction:
Improveconvenience of transferVSAvoidcybersecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system divides the digital asset custody function into two separate systems: a portal system for user interaction and a vault system for secure asset storage. The vault system is air-gapped from the internet, creating physical segmentation that prevents remote cyberattacks while the portal system maintains ease of operation for users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Physical intermediaries (QR codes, printed messages) are introduced as mediators between the portal system and vault system. These physical carriers transfer authentication data and withdrawal requests without electronic communication, eliminating network-based attack vectors while preserving operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If air-gap segregation is implemented between portal and vault systems, then cybersecurity is improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improveattack vectorsVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system uses QR codes as optical copies of authentication data and withdrawal requests. Instead of complex electronic communication protocols, simple visual copies are transferred physically between systems, reducing technological complexity while maintaining security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The communication mode changes from electronic/digital parameters to optical/physical parameters. By encoding data in QR codes and using optical scanning instead of network protocols, the system simplifies the interaction mechanism between air-gapped systems.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If digital signatures and QR codes are used for validation, then security against man-in-the-middle attacks is improved, but ease of operation decreases

Engineering Contradiction:
Improveman-in-the-middle attacksVSAvoidoperational simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

Complex electronic verification mechanisms are replaced with optical scanning of QR codes. The mechanical/optical action of scanning and comparing codes is simpler for users than managing cryptographic keys or verifying digital signatures manually, while providing equivalent or superior security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If portal system is internet-connected for accessibility, then ease of operation is improved, but exposure to cybersecurity threats increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidcybersecurity exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments connectivity requirements: the portal system remains internet-connected for user accessibility and interface operations, while the vault system is air-gapped for security. This division allows the connected component to provide ease of operation while the isolated component prevents cybersecurity exposure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250125974A1Systems and methods for digital data object secure custody
Publication Date: 2025.04.17 ROYAL BANK OF CANADA
  • US20250125974A1 patent drawing
  • US20250125974A1 patent drawing
  • US20250125974A1 patent drawing

AI summary

An improved approach for the securement of digital objects is proposed, that, as described in various embodiments, can include increased levels of encryption, air-gap segregation, and redundancy for interaction with secure approved client withdrawal addresses. A combination of computational and physical securement approaches are described that provide a practical mechanism for improving security of transactions that are conducted using cryptographic systems that addresses security vulnerabilities related to uncontrolled transaction flow. Specifically, methods are proposed for implementation on computing devices which interact with a two-part air-gapped system that is adapted to control both a secure address approval process, and a withdrawal process to the approved address. These processes operate in combination.