MPC Transaction Authorization with HSM Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-party computation (MPC) technologies for blockchain transactions face challenges in administering, managing, and controlling secure transactions, leading to potential security vulnerabilities and lack of granular control over authorization processes.

Innovation Solution

A modular MPC architecture utilizing hardware security modules (HSMs) to distribute and manage cryptographic operations across multiple parties, ensuring secure key generation and transaction authorization without central server control, using multi-layer authentication and user-defined policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MPC technology is used to distribute computation across multiple parties, then security is improved, but administrative control and management become more difficult

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a policy engine as an intermediary component that mediates between multiple MPC parties and the transaction system. This policy engine centralizes the administrative control and management functions, allowing for easier oversight and control while maintaining the distributed secure computation architecture. The policy engine evaluates policies and makes decisions on behalf of the distributed system, resolving the contradiction between distributed security and centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional MPC architecture is used, then decentralization is achieved, but granular control over authorization is lost

Engineering Contradiction:
ImprovedecentralizationVSAvoidgranular control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the authorization control into fine-grained policy rules that can be independently evaluated and enforced. The policy engine processes individual policy statements that specify exact authorization conditions, allowing for granular control over different aspects of transaction authorization while maintaining the decentralized MPC architecture. Each policy can be independently configured and enforced, providing precise control without centralizing the entire system.

Inventive Principle:
Principle #1Segmentation

3Reliability

If more parties are involved in MPC transactions, then security is enhanced, but transaction complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the policy engine continuously evaluates policy conditions based on transaction state and party actions. This automated feedback loop simplifies the coordination complexity by automatically enforcing authorization rules and providing real-time validation, allowing more parties to participate in MPC transactions without proportionally increasing manual coordination complexity. The system self-regulates through policy evaluation feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12457123B2Secure key and transaction management for multi-party computation systems
Publication Date: 2025.10.28 MPC HOLDING INC
  • US12457123B2 patent drawing
  • US12457123B2 patent drawing
  • US12457123B2 patent drawing

AI summary

The disclosed technology provides for managing, authenticating, and authorizing transactions utilizing multi-party-computation (“MPC”) across a network. A method includes receiving, by a server, policy data defining a transaction signing policy, receiving, from an initiator node, a transaction request, in response to receiving the transaction request: (i) determining, based on the transaction signing policy, a threshold number of virtual nodes in a cloud environment that are included in a transaction signing group and that are required to authorize the transaction request, and (ii) sending, to each of the virtual nodes, an authorization request to authorize the transaction request, receiving, from at least a subset of the virtual nodes, authorization data indicating that the transaction request has been authorized, and returning, to a hardware security module (HSM), a transaction payload based on processing the authorization data.