IP Library Granted Patent US 12,614,158
Granted Patent B2
US 12,614,158 · App. 16/011,529 · Granted Apr 28, 2026

Digital asset custodial system

Inventors: Nathan P. McCauley (San Francisco, CA); Diogo Monica (San Francisco, CA); Boaz Avital (San Francisco, CA); Riyaz D. Faizullabhoy (San Francisco, CA); Kristen B. Howard (San Francisco, CA); João M. P. Peixoto (San Francisco, CA); Viktor P. Stanchev (San Francisco, CA)
Assignee: Anchor Labs, Inc.
G06Q20/065G06F21/32G06F21/645G06Q20/3829G06Q20/40145G06Q20/42H04L9/3236H04L63/126G06Q2220/00H04L9/50H04L2209/56H04W12/069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,614,158
App. No.
16/011,529
Filed
Jun 18, 2018
Granted
Apr 28, 2026
Kind
B2
Art Unit
3697
USPC
705/71
Abstract

A digital asset custodial system for maintaining custody of, and controlling access to, cryptocurrencies and/or other digital assets, is disclosed. The digital asset custodial system includes multiple layers of security to enable large volumes of digital assets to be maintained in a secure manner. The digital asset custodial system can include a combination of biometric-based multi-user validation, transaction risk analysis, and a hardware security module (HSM) that provides authentication/validation functionality and secure storage of private keys of digital assets.

Claims (80)

1 . A method of authorizing a transaction involving a cryptoasset, the method comprising:

receiving, at an online server, a transaction request for a requested transaction involving the cryptoasset from a requestor via a public computer network;

transmitting one or more endorsement requests to one more mobile devices according to a stored policy in response to receipt of the requested transaction, the one or more mobile devices being associated with one or more users specified in the stored policy as one or more possible members of a quorum for approving the transaction;

receiving, at the online server, one or more endorsement messages from the one or more mobile devices associated with the one or more users in response to transmitting the one or more endorsement requests;

determining, by a hardware security module, that the one or more users have been authenticated according to the stored policy in connection with the one or more endorsement messages associated with the requested transaction;

receiving, by the hardware security module, an indication of the one or more endorsement messages from the one or more mobile devices;

determining, by the hardware security module, whether one or more valid endorsements have been received from the one or more users based on one or more public keys associated with the one or more users for which the one or more endorsement messages have been received;

determining, by the hardware security module, whether a quorum specified by the stored policy has been met based on a comparison by the hardware security module of a number of the one or more valid endorsements that have been received and a number of authorizations that must be received according to the stored policy;

based on the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum, authorizing, by the hardware security module, the requested transaction by using a private key associated with the cryptoasset to sign an approval of the requested transaction, wherein the private key associated with the cryptoasset is generated by the hardware security module for a blockchain address associated with the cryptoasset, and wherein the private key associated with the cryptoasset is inaccessible by devices external to the hardware security module and different from one or more private keys associated with the one or more users; and

in response to the transaction request, invoking a risk analysis of the requested transaction, wherein said authorizing the requested transaction is performed based on i) a result of the risk analysis indicating that a risk level associated with the requested transaction satisfies a risk criterion and ii) the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum.

2 . A method as recited in claim 1 , wherein the stored policy is stored within the hardware security module.

3 . A method as recited in claim 1 , further comprising using an authentication technique at the online server to authenticate the one or more users in connection with the one or more endorsement messages, the authentication technique including:

causing the one or more mobile devices to prompt the one or more users to record and upload to the online server one or more videos in which the one or more users perform a specified action or speak specified content;

receiving at the online server one or more videos uploaded responsive to the prompt; and

analyzing the one or more videos at the online server to authenticate the one or more users by performing at least one of:

verifying a biometric characteristic of the one or more users from the one or more videos, or

verifying that the one or more users performed the specified action or spoke the specified content in the video.

4 . A method as recited in claim 1 , further comprising:

causing the one or more mobile devices to output a deterministic authentication challenge to the one or more users, wherein a content of the deterministic authentication challenge is based on a context of the requested transaction.

5 . A method as recited in claim 1 , further comprising:

using the hardware security module to generate the private key associated with the cryptoasset as part of a public-private key pair associated with the cryptoasset.

6 . A method as recited in claim 1 , further comprising:

storing in the hardware security module the public key of a public-private key pair for the one or more mobile devices.

7 . A method as recited in claim 6 , wherein each received endorsement message has been signed by a corresponding mobile device with a respective private key of the public-private key pair associated with the corresponding mobile device.

8 . A method as recited in claim 6 , further comprising:

providing a data package to the hardware security module prior to said authorizing the requested transaction, the data package including data indicative of the quorum and the respective public key associated with each of the one or more mobile devices.

9 . A method as recited in claim 1 , wherein the hardware security module has no direct connection to any public computer network.

10 . A method as recited in claim 1 , further comprising:

storing, in the hardware security module, the private key associated with the cryptoasset, the private key being part of a public-private key pair associated with the cryptoasset.

11 . A method as recited in claim 1 , wherein the one or more endorsement requests transmitted to the one or more mobile devices are configured to cause each of the one or more mobile devices to prompt a corresponding user to endorse the requested transaction.

12 . A method as recited in claim 1 , wherein the determining whether the one or more valid endorsements have been received further comprises determining whether each of the one or more endorsement messages generated at a corresponding mobile device has been signed using a private key stored in a secure storage of the corresponding mobile device.

13 . A method as recited in claim 1 , further comprising:

transmitting to the hardware security module a data package that includes data specifying the policy, including the quorum, and the public key associated with each of the one or more mobile devices.

14 . A system for authorizing a transaction involving a cryptoasset, the system comprising:

one or more processors; and

one or more non-transitory computer readable media storing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, at an online server, a transaction request for a requested transaction involving the cryptoasset from a requestor via a public computer network;

transmitting one or more endorsement requests to one more mobile devices according to a stored policy in response to receipt of the requested transaction, the one or more mobile devices being associated with one or more users specified in the stored policy as one or more possible members of a quorum for approving the transaction;

receiving, at the online server, one or more endorsement messages from the one or more mobile devices associated with the one or more users in response to transmitting the one or more endorsement requests;

determining, by a hardware security module, that the one or more users have been authenticated according to the stored policy in connection with the one or more endorsement messages associated with the requested transaction;

receiving, by the hardware security module, an indication of the one or more endorsement messages from the one or more mobile devices;

determining, by the hardware security module, whether one or more valid endorsements have been received from the one or more users based on one or more public keys associated with the one or more users for which the one or more endorsement messages have been received;

determining, by the hardware security module, whether a quorum specified by the stored policy has been met based on a comparison by the hardware security module of a number of the one or more valid endorsements that have been received and a number of authorizations that must be received according to the stored policy;

based on the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum, authorizing, by the hardware security module, the requested transaction by using a private key associated with the cryptoasset to sign an approval of the requested transaction, wherein the private key associated with the cryptoasset is generated by the hardware security module for a blockchain address associated with the cryptoasset, and wherein the private key associated with the cryptoasset is inaccessible by devices external to the hardware security module and different from one or more private keys associated with the one or more users; and

in response to the transaction request, invoking a risk analysis of the requested transaction, wherein said authorizing the requested transaction is performed based on i) a result of the risk analysis indicating that a risk level associated with the requested transaction satisfies a risk criterion and ii) the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum.

15 . A digital asset custodial system comprising:

an online server configured to:

receive a requested transaction relating to a digital asset from a requestor via a public computer network;

transmit one or more endorsement requests to one or more mobile devices according to a stored policy in response to receipt of the requested transaction, the one or more mobile devices being associated with one or more users specified in the policy as possible members of a quorum for approving the transaction;

receive one or more endorsement messages from the one or more mobile devices in response to transmitting the one or more endorsement requests; and

determine that the one or more users have been authenticated in connection with the one or more endorsement messages associated with the requested transaction;

in response to the receiving the requested transaction, invoke a risk analysis of the requested transaction, wherein authorizing the requested transaction is performed based on i) a result of the risk analysis indicating that a risk level associated with the requested transaction satisfies a risk criterion and ii) one or more valid endorsements having been received from the one or more users in satisfaction of the quorum; and

a hardware security module configured to:

determine whether one or more valid endorsements have been received from the one or more users based on one or more public keys associated with the one or more users for which the one or more endorsement messages have been received;

determine whether the quorum specified by the stored policy has been met based on a comparison of a number of the one or more valid endorsements that have been received and a number of authorizations that must be received according to the stored policy; and

authorize the transaction by signing an approval of the requested transaction using a private key associated with the digital asset based on the one or more valid endorsements of the requested transaction having been received from the one or more users in satisfaction of the quorum, wherein the private key associated with the digital asset is generated by the hardware security module for a blockchain address associated with the digital asset, and wherein the private key associated with the digital asset is inaccessible by devices external to the hardware security module and different from one or more private keys associated with the one or more users.

16 . A digital asset custodial system as recited in claim 15 , further comprising a relay server to isolate the hardware security module from an Internet.

17 . A digital asset custodial system as recited in claim 15 , further comprising a risk analysis module to assign a risk score to the requested transaction.

18 . A digital asset custodial system as recited in claim 15 , wherein each of the one or more mobile devices is configured to prompt a corresponding user to endorse the requested transaction based on a respective endorsement request.

19 . A digital asset custodial system as recited in claim 15 , wherein the hardware security module is further configured to:

generate the private key associated with the digital asset as part of a public- private key pair associated with the digital asset;

provide a public key of the public-private key pair associated with the digital asset to a computer system that is external to the hardware security module; and

maintain the private key of the public-private key pair associated with the digital asset in a storage within the hardware security module and prevent the private key of the public-private key pair associated with the digital asset from being read by any entity that is external to the hardware security module.

20 . A digital asset custodial system as recited in claim 15 , wherein the online server is further configured to use a biometric authentication technique to authenticate the one or more users in connection with the one or more endorsement requests.

21 . A digital asset custodial system as recited in claim 15 , further configured to authenticate the one or more users in connection with the endorsements by:

causing the one or more mobile devices to prompt the one or more users to record and upload to the online server one or more videos in which the one or more users perform a specified action or speak specified content;

receiving the one or more videos uploaded responsive to the prompt; and

analyzing the one or more videos to authenticate the one or more users by performing at least one of:

verifying a biometric characteristic of the one or more users from the one or more videos, or

verifying that the one or more users performed the specified action or spoke the specified content in the one or more videos.

22 . A digital asset custodial system as recited in claim 15 , and configured to cause the one or more mobile devices to output a deterministic authentication challenge to the one or more users, wherein a content of the deterministic authentication challenge is based on a context of the requested transaction.

23 . A method as recited in claim 1 , further comprising receiving, by the hardware security module, an operation description, wherein said determining whether one or more valid endorsements have been received from the one or more users comprises:

determining, by the hardware security module, whether each of the one or more users is in an organization specified in the operation description;

determining, by the hardware security module, whether each of the one or more endorsement messages is signed using a correct public key; and

determining, by the hardware security module, whether each of the one or more endorsements messages approves the requested transaction.

24 . A digital asset custodial system as recited in claim 15 , wherein the hardware security module is configured to store, in an internal storage:

the stored policy, which comprises one policy for each action for each possible action;

an identifier of each user specified in the stored policy as a possible member of the quorum for approving the transaction;

an identifier of an organization to which each user specified in the stored policy belongs; and

a public key of the organization.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE FIRST PAGE OF ASSIGNMENT BY ADDING APPLICATION NUMBER AND FILING DATE TO ASSIGNMENT DOCUMENT PREVIOUSLY RECORDED ON REEL 046123 FRAME 0462. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 10, 2019
From: MCCAULEY, NATHAN P.; MONICA, DIOGO; AVITAL, BOAZ; FAIZULLABHOY, RIYAZ D.; HOWARD, KRISTEN B.; PEIXOTO, JOAO M. P.; STANCHEV, VIKTOR P.
To: ANCHOR LABS, INC.
Reel/Frame 048854/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2018
From: MCCAULEY, NATHAN P.; MONICA, DIOGO; AVITAL, BOAZ; FAIZULLABHOY, RIYAZ D.; HOWARD, KRISTEN B.; PEIXOTO, JOAO M. P.; STANCHEV, VIKTOR P.
To: ANCHOR LABS, INC.
Reel/Frame 046123/0462 →
Continuity (3)
Provisional Application 62640429 · Mar 8, 2018
Provisional Application 62636106 · Feb 27, 2018
Related Publication 20190266576A1 · Aug 29, 2019
References Cited (102)
US 6950523B1 · Brickell et al. · 2005 [cited by applicant]
US 8401968B1 · Schattauer · 2013 [cited by examiner]
US 9892460B1 · Winklevoss et al. · 2018 [cited by applicant]
US 9916581B2 · Dorsey et al. · 2018 [cited by applicant]
US 9942211B1 · Campagna · 2018 [cited by examiner]
US 10068228B1 · Winklevoss et al. · 2018 [cited by applicant]
US 10373158B1 · James et al. · 2019 [cited by applicant]
US 10439811B2 · Norton · 2019 [cited by applicant]
US 10523716B1 · Stickle · 2019 [cited by examiner]
US 10693638B1 · Cignetti · 2020 [cited by examiner]
US 10937069B2 · Narasimhan · 2021 [cited by examiner]
US 20040128504A1 · Kivinen · 2004 [cited by applicant]
US 20040236694A1 · Tattan · 2004 [cited by applicant]
US 20050273442A1 · Bennett · 2005 [cited by applicant]
US 20070282756A1 · Dravenstott · 2007 [cited by examiner]
US 20080031460A1 · Brookner et al. · 2008 [cited by applicant]
US 20080208758A1 · Spiker · 2008 [cited by examiner]
US 20080285939A1 · Baum · 2008 [cited by examiner]
US 20080313226A1 · Bowden · 2008 [cited by examiner]
US 20090228707A1 · Linsky · 2009 [cited by examiner]
US 20100024017A1 · Ashfield et al. · 2010 [cited by applicant]
US 20100119061A1 · Kawale · 2010 [cited by applicant]
US 20110106707A1 · Hwang · 2011 [cited by examiner]
US 20110154025A1 · Spalka · 2011 [cited by applicant]
US 20120192260A1 · Kontsevich · 2012 [cited by applicant]
US 20140040051A1 · Ovick · 2014 [cited by examiner]
US 20140046842A1 · Irudayam · 2014 [cited by applicant]
US 20140156534A1 · Quigley et al. · 2014 [cited by applicant]
US 20140289528A1 · Baghdasaryan · 2014 [cited by examiner]
US 20150154584A1 · Prashant · 2015 [cited by examiner]
US 20150170112A1 · DeCastro · 2015 [cited by applicant]
US 20150287026A1 · Yang et al. · 2015 [cited by applicant]
US 20150363778A1 · Ronca · 2015 [cited by examiner]
US 20150373122A1 · Steel et al. · 2015 [cited by applicant]
US 20150381602A1 · Grim · 2015 [cited by examiner]
US 20160162897A1 · Feeney · 2016 [cited by examiner]
US 20160189134A1 · Voege et al. · 2016 [cited by applicant]
US 20160283920A1 · Fisher et al. · 2016 [cited by applicant]
US 20160285872A1 · Polar · 2016 [cited by applicant]
US 20170006018A1 · Campagna · 2017 [cited by applicant]
US 20170076518A1 · Patterson · 2017 [cited by examiner]
US 20170103385A1 · Wilson, Jr. · 2017 [cited by examiner]
US 20170154331A1 · Voorhees · 2017 [cited by applicant]
US 20170230375A1 · Kurian · 2017 [cited by applicant]
US 20170250972A1 · Ronda · 2017 [cited by examiner]
US 20170373849A1 · Donner et al. · 2017 [cited by applicant]
US 20170374033A1 · Kovacs · 2017 [cited by applicant]
US 20180004930A1 · Csinger · 2018 [cited by examiner]
US 20180034800A1 · Pistauer · 2018 [cited by examiner]
US 20180075536A1 · Jayaram · 2018 [cited by examiner]
US 20180130158A1 · Atkinson et al. · 2018 [cited by applicant]
US 20180181737A1 · Tussy · 2018 [cited by applicant]
US 20180189100A1 · Nemoto · 2018 [cited by examiner]
US 20180330342A1 · Prakash · 2018 [cited by examiner]
US 20180335928A1 · Van Os · 2018 [cited by examiner]
US 20180349909A1 · Allen · 2018 [cited by examiner]
US 20180367311A1 · Stahlberg · 2018 [cited by applicant]
US 20180367316A1 · Cheng et al. · 2018 [cited by applicant]
US 20190034920A1 · Nolan · 2019 [cited by examiner]
US 20190036678A1 · Ahmed · 2019 [cited by examiner]
US 20190043022A1 · Fosmark et al. · 2019 [cited by applicant]
US 20190081796A1 · Chow · 2019 [cited by examiner]
US 20190164156A1 · Lindemann · 2019 [cited by examiner]
US 20190197513A1 · Rodriguez · 2019 [cited by examiner]
US 20190207915A1 · Schaap · 2019 [cited by applicant]
US 20190236594A1 · Ehrloch-Quinn et al. · 2019 [cited by applicant]
US 20190251524A1 · Sadrizadeh et al. · 2019 [cited by applicant]
US 20190268165A1 · Monica et al. · 2019 [cited by applicant]
US 20190305956A1 · Irani, III · 2019 [cited by applicant]
US 20190347666A1 · Bermudez-Cisneros et al. · 2019 [cited by applicant]
US 20190356491A1 · Herder, III et al. · 2019 [cited by applicant]
US 20190372779A1 · Monica et al. · 2019 [cited by applicant]
US 20200167338A1 · Brock et al. · 2020 [cited by applicant]
US 20200266997A1 · Monica et al. · 2020 [cited by applicant]
US 20200320488A1 · Feng · 2020 [cited by examiner]
US 20200380523A1 · Agrawal et al. · 2020 [cited by applicant]
CN 107533501A · 2018 [cited by applicant]
JP 2008130052A · 2008 [cited by examiner]
WO WO2019168792 · 2019 [cited by applicant]
WO WO2022027026A1 · 2022 [cited by examiner]
“Transaction Immutability and Reputation Traceability: Blockchain as a Platform for Access-controlled IoT and Human Interactivity”; David W. Kravitz; 2017 15th Annual Conference on Privacy, Security and Trust; (Year: 20… [cited by examiner]
“An Endorsement-based Mobile Payment System for a Disaster Area”; Babatunde Ojetunde, Naoki Shibata, Juntao Gao, Minoru Ito; 2015 IEEE 29th International Conference on Advanced Information Networking and Applications; (… [cited by examiner]
“Strengthening SMS-Based Authentication through Usability”; Mohammed AlZomai, Audun Jøsang, Adrian McCullagh, Ernest Foo; 2008 International Symposium on Parallel and Distributed Processing with Applications; (Year: 200… [cited by examiner]
“E-Commerce Trust Metrics and Models”; Daniel W. Manchala; (Year: 2000). [cited by examiner]
Anonymous: “Hierarchical Deterministic: Wallets—BIP32”, Feb. 2017, Retrieved from the Internet: URL:https://github.com/bitcoin/bips/blob(11b0fa37bee4eac40c3albe059107868$bcc3392/bip-0032.mediawiki [retrieved on Jun. 20,… [cited by applicant]
Anonymous: “How to properly secure cryptocurrencies exchanges—Ledger”, Aug. 2016, Retrieved from the Internet: URL:https://www.ledger.fr/2016/08/08/hcpw-to-properly-secure-cryptocurrencies-exchanges/ [retrieved on Jun. … [cited by applicant]
International Search Report and Written Opinion in Application No. PCT/US2019/019414, dated May 15, 2019, 12 pages. [cited by applicant]
International Search Report and Written Opinion in Application No. PCT/US2019/019425, dated May 9, 2019, 12 pages. [cited by applicant]
Anonymous: “Casp Solution Overview, ”and “Installing Casp” Mar. 2019, retrieved from the Internet: URL: https://www.unboundtech.com/docs/CASP/Versions/1.0.1902/CASP User GuideHTML/Content/Products/CASP/CASP_Offering_Des… [cited by applicant]
PCT International Search Report and Written Opinion in International Appln. No. PCT/US2020/043882, dated Nov. 2, 2020. 12 pages. [cited by applicant]
PCT International Search Report and Written Opinion in International Appln. No. PCT/US2020/045737, dated Nov. 11, 2020. 12 pages. [cited by applicant]
Sato et al., “General Security Considerations for Cryptoassets Custodians draft-vcgtf-crypto-assets-security-considerations-04,” Apr. 2019, retrieved from the Internet: URL:https://tools.ietf.org/html/draft-vegtf-crypto… [cited by applicant]
Cryptomathic.com [online], “Understanding Hardware Security Modules,” Sep. 13, 2017, retrieved on Dec. 31, 2018, retrieved from: URL<https:www.cryptomathic.com/news-events/blog/understanding-hardware-security-modules-hs… [cited by applicant]
Wired.com [online], “Crypto anchors' might stop the next Equifax-style megabreach,” Oct. 11, 2017, retrieved from: URLhttps://www.wired.com/story/crypto-anchors-breach-security/>, 11 pages. [cited by applicant]
U.S. Appl. No. 16/276,567, Monica et al. [cited by applicant]
Monica, “Crypto Anchors: Exfiltration Resistant Infrastructure,” 11 pages, dated Oct. 8, 2017. [cited by applicant]
Monica, “Increasing Attacker Cost Using Immutable Infrastructure,” 8 pages, dated Nov. 19, 2016. [cited by applicant]
Monica, “The two metrics that matter for host security,” 6 pages, dated Aug. 31, 2017. [cited by applicant]
Bonneau et al., “SoK: Research Perspectives and Challenges for Bitcoin and Cryptocurrencies,” 2015 IEEE Symposium on Security and Privacy, May 17-21, 2015, San Jose, CA, USA, 104-121. [cited by applicant]
Liu et al., “Security Analysis of Electronic Payment Protocols Based on Quantum Cryptography,” 2017 4th International Conference on Information Science and Control Engineering, Jul. 21-23, 2017, Changsha, China, 1709-17… [cited by applicant]
PCT International Search Report and Written Opinion in International Appln. No. PCT/US2020/017411, dated Apr. 15, 2020, 19 pages. [cited by applicant]
Chinese Office Action with Search report in corresponding Chinese Application No. 201980028214.0, dated Feb. 27, 2024 (13 pages). [cited by applicant]