Digital Wallet Key Restoration via Server Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital asset management systems are vulnerable to unauthorized access due to network connectivity between servers, allowing hackers to gain access to multiple cryptographic keys and compromise user financial information and digital assets.

Innovation Solution

Implementing a system where a company's first server is not network-connected to a second server, and the second server is disconnected from the internet, using visual representations and cryptographic algorithms to securely restore access to digital assets using a multi-key approach with N-out-of-M keys, where N is less than M, and the second server is only accessible by trusted personnel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If servers are network-connected to enable asset management operations, then ease of operation is improved, but security vulnerability increases allowing unauthorized access to cryptographic keys

Engineering Contradiction:
Improveasset management operationVSAvoidunauthorized access to cryptographic keys
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system divides cryptographic key management across multiple separated servers. The first server handles asset management operations while the second server stores backup cryptographic keys in complete network isolation. This segmentation allows operational convenience on the first server while preventing unauthorized access to keys on the isolated second server.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary process that transfers cryptographic key information between the networked first server and the isolated second server through secure, controlled channels. This intermediary mechanism enables necessary key management operations while maintaining the network isolation barrier that prevents unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic keys are stored on network-connected servers for accessibility, then ease of operation is improved, but reliability of security decreases due to potential network breaches

Engineering Contradiction:
Improvekey accessibilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments cryptographic key storage across two separate servers with different network connectivity statuses. The first server provides key accessibility for operations, while the second server provides secure backup storage isolated from network threats, thereby improving overall security reliability without completely sacrificing accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a preemptive security measure by maintaining backup cryptographic keys on an offline server before any potential security breach occurs. This prior cushioning ensures that even if the networked server is compromised, the cryptographic keys remain protected on the isolated server, maintaining security reliability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Productivity

If multiple cryptographic keys are stored on accessible servers, then productivity of asset management is improved, but loss of information increases due to potential hacker acquisition of keys

Engineering Contradiction:
Improveasset management efficiencyVSAvoidcryptographic key compromise
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments cryptographic key information across multiple servers, with the second server completely isolated from the network. This segmentation allows the system to maintain multiple keys for productive asset management operations while preventing hackers from acquiring all keys through network breaches, as the isolated server's keys remain protected.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent converts the potential harm of having multiple accessible keys (increased attack surface) into a benefit by implementing network isolation. The isolation transforms what would be a vulnerability into a security feature, allowing the system to maintain productivity through multiple keys while preventing information loss through the offline protection mechanism.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP3507701B1Method and apparatus for restoring access to digital assets
Publication Date: 2022.05.18 CONIO INC
  • EP3507701B1 patent drawingFigure 1
  • EP3507701B1 patent drawingFigure 2
  • EP3507701B1 patent drawingFigure 3

AI summary

A method and apparatus may include receiving a request to restore access to digital assets of a digital wallet. The digital assets are accessed via M-number of cryptographic keys. Access to at least N-out-of-M keys is necessary in order to access the digital assets at a given time. N is a number less than M. The M-number of keys include at least a first key, a second key, and a third key. One of the M keys is stored on a first server. One of the M keys is stored on a second server. The key stored on the first server corresponds to the second key. The key stored on the second server corresponds to the third key. The second server is separated from the first server. With certain embodiments, the second server is totally disconnected from any network.