Secure VASP Data Exchange via Asymmetric Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure data exchange between Virtual Asset Service Providers (VASPs) in a computer network, compliant with the Financial Action Task Force (FATF) Travel Rule, require trusted third parties or central authorities, which is not feasible in all environments.

Innovation Solution

A method utilizing asymmetric key encryption for secure information transfer between VASPs without the need for a trusted third party or central authority, where each VASP can prove its identity and ownership of the information being exchanged.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric key encryption is used for secure data exchange between VASPs, then security is improved and reliance on trusted intermediaries is eliminated, but device complexity increases due to key management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-distributing public keys to all VASPs before the actual data exchange occurs. Each VASP receives and stores the public keys of other VASPs in advance, so that when a transfer occurs, the encryption can immediately use these pre-available keys without requiring real-time key exchange or trusted intermediaries. This resolves the contradiction by preparing the cryptographic infrastructure beforehand, maintaining high security while reducing operational complexity during actual transactions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If proof of ownership validation is performed for each transaction, then security is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing the public key infrastructure and validating ownership credentials before actual transactions occur. The digital signature verification process uses pre-distributed public keys to quickly validate ownership without requiring time-consuming real-time validation of key chains or trusted intermediary verification. This allows each transaction to perform lightweight signature verification rather than full ownership validation, significantly reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If public keys are pre-distributed to all VASPs, then ease of operation is improved by eliminating trusted intermediaries, but information security risks increase due to broader key exposure

Engineering Contradiction:
Improveoperational simplicityVSAvoidsecurity risks from key exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the cryptographic identity system into two distinct components: public keys for encryption and verification, and private keys for signing and decryption. Public keys are freely distributed to all VASPs to enable easy operation and direct communication without intermediaries. Private keys remain securely stored locally at each VASP and never leave the originating system. This segmentation allows broad key exposure (public keys) to enable operational simplicity while the protected private keys maintain security, resolving the contradiction between ease of operation and security risks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3799352B1A method for secure transferring of information through a network between an origin virtual asset service provider and a destination virtual asset service provider
Publication Date: 2025.04.16 LUKKA INC US
  • EP3799352B1 patent drawingFigure 1
  • EP3799352B1 patent drawingFigure 2
  • EP3799352B1 patent drawingFigure 3

AI summary

The invention is related to a method for secure transferring of information through a network between an origin Virtual Asset Service Provider and a destination Virtual Asset Service Provider, in a hostile environment, where every entity (party member, network node) must proof its entitlement of the information being exchanged. Hostile environment means that neither any entity/network node nor the network as a whole can be trusted. The present method doesn't require other party member/network node or database to secure information transfer. Neither it requires any other trusted entity or server to guarantee or provide proof of ownership of exchange information. The present method for communicating securely between electronic devices uses asymmetric key encryption. The invention comprises also a computer program product comprising program code stored on a computer readable medium, said program code comprising computer instructions for performing the inventive method. The invention relates also to a system configured and programmed for performing the inventive method.