Private Key Recovery in Distributed Ledger Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional private key management methods in blockchain systems are susceptible to hacking and loss, lacking secure recovery options, which limits user control and introduces risks of asset irrecoverability and cybersecurity breaches.
Innovation Solution
A key recovery computing system that generates and stores supplemental recovery information, using a recovery seed derived from user-provided data, and employs universal second-factor authentication to ensure secure private key recovery, maintaining user control and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional non-custodial wallets are used where users manage their own private keys, then user control over digital assets is improved, but security risk increases due to susceptibility to hacking and loss without recovery options
Solution Approach 1:
The patent introduces a recovery agent as an intermediary between the user and the private key recovery process. The recovery agent holds encrypted recovery information that can restore access to lost private keys without allowing direct access to the keys themselves. This mediator enables secure recovery while maintaining user control, resolving the contradiction between ease of operation and reliability.
Solution Approach 2:
The private key management system is segmented into multiple components: the user's private key, encrypted recovery information stored by the recovery agent, and authentication mechanisms. This segmentation allows the system to provide recovery capabilities without consolidating control, thereby maintaining security while enabling reliability through distributed key management.
2Ease of repair
If private key recovery phrases are used to enable recovery, then ease of recovery is improved, but security is worsened because the phrases are essentially alternative representations of the private key that can be compromised
Solution Approach 1:
The recovery agent serves as an intermediary that holds encrypted recovery information rather than plain-text recovery phrases. The encryption layer acts as a mediator that enables recovery capability while protecting against the security vulnerabilities of traditional recovery phrases, as the encrypted data cannot be directly used to compromise the private key.
Solution Approach 2:
The system changes the parameter of recovery information from plain-text or simple mnemonic phrases to cryptographically encrypted data. This parameter change maintains the ease of recovery function while fundamentally improving security by ensuring that the recovery information cannot be exploited as an alternative representation of the private key.
3Reliability
If custodial wallets are used where a third party manages the private key, then security against user loss is improved, but user control deteriorates and the system becomes susceptible to custodian breaches
Solution Approach 1:
The private key management is segmented so that the user retains the private key while the recovery agent holds only encrypted recovery information. This segmentation prevents the custodian from accessing or misusing the private key, thereby maintaining user control while still providing protection from loss through the recovery mechanism.
Solution Approach 2:
The recovery agent acts as a limited intermediary that can assist with recovery but does not have access to the private key itself. This intermediary structure provides protection from loss while preserving user control, as the custodian's capabilities are constrained to holding encrypted recovery data rather than the actual private key.
4Object-affected harmful factors
If users are required to remember long private keys and multi-word mnemonics, then security against unauthorized access is improved, but ease of operation deteriorates due to the high degree of sophistication required
Solution Approach 1:
The recovery agent serves as an intermediary that handles the complexity of private key management. Users interact with a simplified interface for key recovery without needing to understand or remember complex cryptographic details, thereby reducing the sophistication required while maintaining security through the intermediary's encrypted recovery process.
Solution Approach 2:
Instead of requiring users to directly manage and remember complex private keys and mnemonics, the system creates a simplified copy or representation through the recovery agent's encrypted recovery information. This copying mechanism allows users to recover access without needing to retain complex security credentials in memory, reducing operational complexity while preserving security.
Data Source
AI summary
In an example system for private key recovery performed by a processor of a key recovery computing system, a key recovery computing system is configured to provide an original private key. The original private key is associated with a storage location of a blockchain-based asset. The key recovery computing system is configured to receive supplemental recovery information provided by a user via a user computing device. A recovery seed is derived from at least a subset of the supplemental recovery information, wherein the recovery seed is non-invertible. The original private key and the recovery seed are stored relationally to the supplemental recovery information. In some embodiments, the processor is further configured to cryptographically protect at least one of the original private key and the recovery seed via a universal second-factor authentication (U2F) device.


