SSITWS Cloud HSM Partitioning for Crypto Wallet Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security encryption and management systems lack dedicated hardware security modules for individual crypto wallets, leading to inadequate security and management of cryptographic assets, addresses, and access privileges.

Innovation Solution

The Security Secret Interface and Token Wrap Structure Apparatuses, Methods, and Systems (SSITWS) provide a cloud-based, scalable dedicated hardware security module for each crypto wallet, using asymmetric keys, multi-signature processes, and advanced authentication methods to ensure secure access and management of cryptographic assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated hardware security modules are implemented for each crypto wallet, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security resources by creating dedicated HSM partitions for each crypto wallet within the cloud-based HSM. Each partition isolates cryptographic operations and keys for a specific wallet, ensuring that security is enhanced through dedicated resources without requiring separate physical HSM devices for each wallet. This segmentation approach resolves the contradiction by providing wallet-specific security while managing complexity through virtualization and partitioning.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multi-layered security with dedicated HSM partitions is implemented, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer between users and the complex HSM infrastructure. This intermediary manages the multi-layered security operations, handling key generation, storage, and cryptographic operations transparently. Users interact with simplified interfaces while the intermediary orchestrates the complex security protocols, thus maintaining ease of operation despite the underlying multi-layered security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cloud-based scalable dedicated HSM is provided for each wallet, then security and management capability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud-based HSM is designed with universal functionality to serve multiple wallets through a single infrastructure. The system provides scalable dedicated partitions that can be dynamically allocated to different wallets, eliminating the need for separate physical HSM devices for each wallet. This multi-functional approach enhances security and management capability while reducing overall device complexity by consolidating resources in a shared cloud environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20200111080A1Security Secret Interface and Token Wrap Structure Apparatuses, Methods and Systems
Publication Date: 2020.04.09 BITGO HOLDINGS INC
  • US20200111080A1 patent drawing
  • US20200111080A1 patent drawing
  • US20200111080A1 patent drawing

AI summary

The Security Secret Interface and Token Wrap Structure Apparatuses, Methods and Systems (“SSITWS”) transforms cryptographic assets, cryptographic asset addresses, user names, workflow names, workflow conditions, workflow access privileges, wallet conditions, wallet access privileges, transaction signing request inputs via SSITWS components into HSM partition, cryptographic shards, workflow access privileges, wallet access privileges, transaction signing response outputs. A workflow creation request datastructure associated with a cryptographic wallet datastructure is obtained. A selection of rules for accessing cryptographic assets associated with the cryptographic wallet datastructure, a selection of a minimum number of approval signatures, and a selection of signing groups are obtained. A set of asymmetric keys associated with the signing groups is generated. Access to an HSM partition associated with the cryptographic wallet datastructure is configured using the generated set of asymmetric keys. Asymmetric keys data for accessing the individual HSM partition is stored in encrypted security vault data structures.