Secure Module Multisignature for Crypto-Asset Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Crypto-asset transactions are vulnerable to security risks such as theft due to compromised private keys, attacks on trading platforms, and man-in-the-middle attacks during transfers, with trading platforms often not providing liability for stolen assets.

Innovation Solution

A system utilizing secure modules with Trusted Execution Environment (TEE) technology and cryptographic algorithms to protect trading platform credentials and private keys, implementing a multisignature scheme and secure multiparty computation to verify transactions across multiple secure modules before recording on the blockchain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If crypto-assets are held in trading platform wallets for trading operations, then trading functionality is enabled, but security risk increases due to potential attacks and unauthorized access

Engineering Contradiction:
Improvetrading functionalityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the signing process into multiple independent secure modules, each holding a portion of the signing authority. No single module or the trading platform itself can compromise the private key, as multiple modules must collaborate to authorize transactions. This segmentation prevents unauthorized access even if the platform is attacked.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces secure modules as intermediaries between the trading platform and the blockchain network. These modules act as trusted mediators that verify and sign transactions without exposing private keys to the platform, thereby enabling trading functionality while maintaining security through a trusted intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traders withdraw assets to personal wallets frequently, then security risk is reduced, but trading efficiency decreases due to transaction delays

Engineering Contradiction:
Improvesecurity riskVSAvoidtrading efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting signing authority across multiple secure modules, the system enables the trading platform to hold assets securely without requiring frequent withdrawals. The segmented architecture allows efficient trading operations while maintaining security, as the distributed key management prevents single-point compromises.

Inventive Principle:
Principle #1Segmentation

3Reliability

If private keys are protected using traditional encryption methods, then security is improved, but vulnerability to sophisticated attacks remains

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the private key into multiple shares distributed across independent secure modules. This segmentation ensures that even if sophisticated attacks compromise one module or the trading platform, the attacker cannot reconstruct the private key without accessing multiple modules simultaneously, thereby resisting sophisticated attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system prepares security defenses in advance by distributing key shares to multiple secure modules before any attack occurs. This prior cushioning creates multiple barriers that attackers must overcome, preventing successful compromises even against sophisticated threats.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Ease of operation

If trading platforms provide liability for stolen assets, then trader confidence increases, but security burden on platforms increases

Engineering Contradiction:
Improvetrader confidenceVSAvoidsecurity burden
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

By implementing segmented key management across multiple secure modules, the platform enhances security without bearing the full burden alone. The distributed architecture inherently provides stronger protection, enabling the platform to offer liability coverage while the segmented system shares the security burden across multiple independent components.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12481988B2System and method for securing crypto-asset transactions
Publication Date: 2025.11.25 FIREBLOCKS LTD
  • US12481988B2 patent drawing
  • US12481988B2 patent drawing
  • US12481988B2 patent drawing

AI summary

In some implementations, the device may include receiving a command to initiate a crypto-asset transaction by each secure module of a plurality of secure modules. In addition, the device may include calculating by each secure module, a destination address of a trading platform using a respective secure trading platform connector included in each secure module. The device may include signing the crypto-asset transaction using a respective secure wallet with an environment-specific key, thereby enabling execution the a crypto-asset transaction by a trading platform addressed by the calculated destination address.