Digital Wallet Key Restoration via Server Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital asset management systems are vulnerable to unauthorized access due to network connectivity between servers, allowing hackers to gain access to multiple cryptographic keys and compromise user financial information and digital assets.
Innovation Solution
Implementing a system where a company's first server is not network-connected to a second server, and the second server is disconnected from the internet, using visual representations and cryptographic algorithms to securely restore access to digital assets using a multi-key approach with N-out-of-M keys, where N is less than M, and the second server is only accessible by trusted personnel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If servers are network-connected to enable asset management operations, then ease of operation is improved, but security vulnerability increases allowing unauthorized access to cryptographic keys
Solution Approach 1:
The system divides cryptographic key management across multiple separated servers. The first server handles asset management operations while the second server stores backup cryptographic keys in complete network isolation. This segmentation allows operational convenience on the first server while preventing unauthorized access to keys on the isolated second server.
Solution Approach 2:
The patent introduces an intermediary process that transfers cryptographic key information between the networked first server and the isolated second server through secure, controlled channels. This intermediary mechanism enables necessary key management operations while maintaining the network isolation barrier that prevents unauthorized access.
2Ease of operation
If cryptographic keys are stored on network-connected servers for accessibility, then ease of operation is improved, but reliability of security decreases due to potential network breaches
Solution Approach 1:
The system segments cryptographic key storage across two separate servers with different network connectivity statuses. The first server provides key accessibility for operations, while the second server provides secure backup storage isolated from network threats, thereby improving overall security reliability without completely sacrificing accessibility.
Solution Approach 2:
The patent implements a preemptive security measure by maintaining backup cryptographic keys on an offline server before any potential security breach occurs. This prior cushioning ensures that even if the networked server is compromised, the cryptographic keys remain protected on the isolated server, maintaining security reliability.
3Productivity
If multiple cryptographic keys are stored on accessible servers, then productivity of asset management is improved, but loss of information increases due to potential hacker acquisition of keys
Solution Approach 1:
The patent segments cryptographic key information across multiple servers, with the second server completely isolated from the network. This segmentation allows the system to maintain multiple keys for productive asset management operations while preventing hackers from acquiring all keys through network breaches, as the isolated server's keys remain protected.
Solution Approach 2:
The patent converts the potential harm of having multiple accessible keys (increased attack surface) into a benefit by implementing network isolation. The isolation transforms what would be a vulnerability into a security feature, allowing the system to maintain productivity through multiple keys while preventing information loss through the offline protection mechanism.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and apparatus may include receiving a request to restore access to digital assets of a digital wallet. The digital assets are accessed via M-number of cryptographic keys. Access to at least N-out-of-M keys is necessary in order to access the digital assets at a given time. N is a number less than M. The M-number of keys include at least a first key, a second key, and a third key. One of the M keys is stored on a first server. One of the M keys is stored on a second server. The key stored on the first server corresponds to the second key. The key stored on the second server corresponds to the third key. The second server is separated from the first server. With certain embodiments, the second server is totally disconnected from any network.