Secure Module Multisignature for Crypto-Asset Transaction Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Crypto-asset transactions are vulnerable to security risks such as theft due to compromised private keys, attacks on trading platforms, and man-in-the-middle attacks during transfers, with trading platforms often not providing liability for stolen assets.
Innovation Solution
A system utilizing secure modules with Trusted Execution Environment (TEE) technology and cryptographic algorithms to protect trading platform credentials and private keys, implementing a multisignature scheme and secure multiparty computation to verify transactions across multiple secure modules before recording on the blockchain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If crypto-assets are held in trading platform wallets for trading operations, then trading functionality is enabled, but security risk increases due to potential attacks and unauthorized access
Solution Approach 1:
The system segments the signing process into multiple independent secure modules, each holding a portion of the signing authority. No single module or the trading platform itself can compromise the private key, as multiple modules must collaborate to authorize transactions. This segmentation prevents unauthorized access even if the platform is attacked.
Solution Approach 2:
The patent introduces secure modules as intermediaries between the trading platform and the blockchain network. These modules act as trusted mediators that verify and sign transactions without exposing private keys to the platform, thereby enabling trading functionality while maintaining security through a trusted intermediary layer.
2Reliability
If traders withdraw assets to personal wallets frequently, then security risk is reduced, but trading efficiency decreases due to transaction delays
Solution Approach 1:
By segmenting signing authority across multiple secure modules, the system enables the trading platform to hold assets securely without requiring frequent withdrawals. The segmented architecture allows efficient trading operations while maintaining security, as the distributed key management prevents single-point compromises.
3Reliability
If private keys are protected using traditional encryption methods, then security is improved, but vulnerability to sophisticated attacks remains
Solution Approach 1:
The patent divides the private key into multiple shares distributed across independent secure modules. This segmentation ensures that even if sophisticated attacks compromise one module or the trading platform, the attacker cannot reconstruct the private key without accessing multiple modules simultaneously, thereby resisting sophisticated attacks.
Solution Approach 2:
The system prepares security defenses in advance by distributing key shares to multiple secure modules before any attack occurs. This prior cushioning creates multiple barriers that attackers must overcome, preventing successful compromises even against sophisticated threats.
4Ease of operation
If trading platforms provide liability for stolen assets, then trader confidence increases, but security burden on platforms increases
Solution Approach 1:
By implementing segmented key management across multiple secure modules, the platform enhances security without bearing the full burden alone. The distributed architecture inherently provides stronger protection, enabling the platform to offer liability coverage while the segmented system shares the security burden across multiple independent components.
Data Source
AI summary
In some implementations, the device may include receiving a command to initiate a crypto-asset transaction by each secure module of a plurality of secure modules. In addition, the device may include calculating by each secure module, a destination address of a trading platform using a respective secure trading platform connector included in each secure module. The device may include signing the crypto-asset transaction using a respective secure wallet with an environment-specific key, thereby enabling execution the a crypto-asset transaction by a trading platform addressed by the calculated destination address.


