Digital asset custodial system
A digital asset custodial system for maintaining custody of, and controlling access to, cryptocurrencies and/or other digital assets, is disclosed. The digital asset custodial system includes multiple layers of security to enable large volumes of digital assets to be maintained in a secure manner. The digital asset custodial system can include a combination of biometric-based multi-user validation, transaction risk analysis, and a hardware security module (HSM) that provides authentication/validation functionality and secure storage of private keys of digital assets.
1 . A method of authorizing a transaction involving a cryptoasset, the method comprising:
receiving, at an online server, a transaction request for a requested transaction involving the cryptoasset from a requestor via a public computer network;
transmitting one or more endorsement requests to one more mobile devices according to a stored policy in response to receipt of the requested transaction, the one or more mobile devices being associated with one or more users specified in the stored policy as one or more possible members of a quorum for approving the transaction;
receiving, at the online server, one or more endorsement messages from the one or more mobile devices associated with the one or more users in response to transmitting the one or more endorsement requests;
determining, by a hardware security module, that the one or more users have been authenticated according to the stored policy in connection with the one or more endorsement messages associated with the requested transaction;
receiving, by the hardware security module, an indication of the one or more endorsement messages from the one or more mobile devices;
determining, by the hardware security module, whether one or more valid endorsements have been received from the one or more users based on one or more public keys associated with the one or more users for which the one or more endorsement messages have been received;
determining, by the hardware security module, whether a quorum specified by the stored policy has been met based on a comparison by the hardware security module of a number of the one or more valid endorsements that have been received and a number of authorizations that must be received according to the stored policy;
based on the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum, authorizing, by the hardware security module, the requested transaction by using a private key associated with the cryptoasset to sign an approval of the requested transaction, wherein the private key associated with the cryptoasset is generated by the hardware security module for a blockchain address associated with the cryptoasset, and wherein the private key associated with the cryptoasset is inaccessible by devices external to the hardware security module and different from one or more private keys associated with the one or more users; and
in response to the transaction request, invoking a risk analysis of the requested transaction, wherein said authorizing the requested transaction is performed based on i) a result of the risk analysis indicating that a risk level associated with the requested transaction satisfies a risk criterion and ii) the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum.
2 . A method as recited in claim 1 , wherein the stored policy is stored within the hardware security module.
3 . A method as recited in claim 1 , further comprising using an authentication technique at the online server to authenticate the one or more users in connection with the one or more endorsement messages, the authentication technique including:
causing the one or more mobile devices to prompt the one or more users to record and upload to the online server one or more videos in which the one or more users perform a specified action or speak specified content;
receiving at the online server one or more videos uploaded responsive to the prompt; and
analyzing the one or more videos at the online server to authenticate the one or more users by performing at least one of:
verifying a biometric characteristic of the one or more users from the one or more videos, or
verifying that the one or more users performed the specified action or spoke the specified content in the video.
4 . A method as recited in claim 1 , further comprising:
causing the one or more mobile devices to output a deterministic authentication challenge to the one or more users, wherein a content of the deterministic authentication challenge is based on a context of the requested transaction.
5 . A method as recited in claim 1 , further comprising:
using the hardware security module to generate the private key associated with the cryptoasset as part of a public-private key pair associated with the cryptoasset.
6 . A method as recited in claim 1 , further comprising:
storing in the hardware security module the public key of a public-private key pair for the one or more mobile devices.
7 . A method as recited in claim 6 , wherein each received endorsement message has been signed by a corresponding mobile device with a respective private key of the public-private key pair associated with the corresponding mobile device.
8 . A method as recited in claim 6 , further comprising:
providing a data package to the hardware security module prior to said authorizing the requested transaction, the data package including data indicative of the quorum and the respective public key associated with each of the one or more mobile devices.
9 . A method as recited in claim 1 , wherein the hardware security module has no direct connection to any public computer network.
10 . A method as recited in claim 1 , further comprising:
storing, in the hardware security module, the private key associated with the cryptoasset, the private key being part of a public-private key pair associated with the cryptoasset.
11 . A method as recited in claim 1 , wherein the one or more endorsement requests transmitted to the one or more mobile devices are configured to cause each of the one or more mobile devices to prompt a corresponding user to endorse the requested transaction.
12 . A method as recited in claim 1 , wherein the determining whether the one or more valid endorsements have been received further comprises determining whether each of the one or more endorsement messages generated at a corresponding mobile device has been signed using a private key stored in a secure storage of the corresponding mobile device.
13 . A method as recited in claim 1 , further comprising:
transmitting to the hardware security module a data package that includes data specifying the policy, including the quorum, and the public key associated with each of the one or more mobile devices.
14 . A system for authorizing a transaction involving a cryptoasset, the system comprising:
one or more processors; and
one or more non-transitory computer readable media storing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
receiving, at an online server, a transaction request for a requested transaction involving the cryptoasset from a requestor via a public computer network;
transmitting one or more endorsement requests to one more mobile devices according to a stored policy in response to receipt of the requested transaction, the one or more mobile devices being associated with one or more users specified in the stored policy as one or more possible members of a quorum for approving the transaction;
receiving, at the online server, one or more endorsement messages from the one or more mobile devices associated with the one or more users in response to transmitting the one or more endorsement requests;
determining, by a hardware security module, that the one or more users have been authenticated according to the stored policy in connection with the one or more endorsement messages associated with the requested transaction;
receiving, by the hardware security module, an indication of the one or more endorsement messages from the one or more mobile devices;
determining, by the hardware security module, whether one or more valid endorsements have been received from the one or more users based on one or more public keys associated with the one or more users for which the one or more endorsement messages have been received;
determining, by the hardware security module, whether a quorum specified by the stored policy has been met based on a comparison by the hardware security module of a number of the one or more valid endorsements that have been received and a number of authorizations that must be received according to the stored policy;
based on the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum, authorizing, by the hardware security module, the requested transaction by using a private key associated with the cryptoasset to sign an approval of the requested transaction, wherein the private key associated with the cryptoasset is generated by the hardware security module for a blockchain address associated with the cryptoasset, and wherein the private key associated with the cryptoasset is inaccessible by devices external to the hardware security module and different from one or more private keys associated with the one or more users; and
in response to the transaction request, invoking a risk analysis of the requested transaction, wherein said authorizing the requested transaction is performed based on i) a result of the risk analysis indicating that a risk level associated with the requested transaction satisfies a risk criterion and ii) the one or more valid endorsements having been received from the one or more users in satisfaction of the quorum.
15 . A digital asset custodial system comprising:
an online server configured to:
receive a requested transaction relating to a digital asset from a requestor via a public computer network;
transmit one or more endorsement requests to one or more mobile devices according to a stored policy in response to receipt of the requested transaction, the one or more mobile devices being associated with one or more users specified in the policy as possible members of a quorum for approving the transaction;
receive one or more endorsement messages from the one or more mobile devices in response to transmitting the one or more endorsement requests; and
determine that the one or more users have been authenticated in connection with the one or more endorsement messages associated with the requested transaction;
in response to the receiving the requested transaction, invoke a risk analysis of the requested transaction, wherein authorizing the requested transaction is performed based on i) a result of the risk analysis indicating that a risk level associated with the requested transaction satisfies a risk criterion and ii) one or more valid endorsements having been received from the one or more users in satisfaction of the quorum; and
a hardware security module configured to:
determine whether one or more valid endorsements have been received from the one or more users based on one or more public keys associated with the one or more users for which the one or more endorsement messages have been received;
determine whether the quorum specified by the stored policy has been met based on a comparison of a number of the one or more valid endorsements that have been received and a number of authorizations that must be received according to the stored policy; and
authorize the transaction by signing an approval of the requested transaction using a private key associated with the digital asset based on the one or more valid endorsements of the requested transaction having been received from the one or more users in satisfaction of the quorum, wherein the private key associated with the digital asset is generated by the hardware security module for a blockchain address associated with the digital asset, and wherein the private key associated with the digital asset is inaccessible by devices external to the hardware security module and different from one or more private keys associated with the one or more users.
16 . A digital asset custodial system as recited in claim 15 , further comprising a relay server to isolate the hardware security module from an Internet.
17 . A digital asset custodial system as recited in claim 15 , further comprising a risk analysis module to assign a risk score to the requested transaction.
18 . A digital asset custodial system as recited in claim 15 , wherein each of the one or more mobile devices is configured to prompt a corresponding user to endorse the requested transaction based on a respective endorsement request.
19 . A digital asset custodial system as recited in claim 15 , wherein the hardware security module is further configured to:
generate the private key associated with the digital asset as part of a public- private key pair associated with the digital asset;
provide a public key of the public-private key pair associated with the digital asset to a computer system that is external to the hardware security module; and
maintain the private key of the public-private key pair associated with the digital asset in a storage within the hardware security module and prevent the private key of the public-private key pair associated with the digital asset from being read by any entity that is external to the hardware security module.
20 . A digital asset custodial system as recited in claim 15 , wherein the online server is further configured to use a biometric authentication technique to authenticate the one or more users in connection with the one or more endorsement requests.
21 . A digital asset custodial system as recited in claim 15 , further configured to authenticate the one or more users in connection with the endorsements by:
causing the one or more mobile devices to prompt the one or more users to record and upload to the online server one or more videos in which the one or more users perform a specified action or speak specified content;
receiving the one or more videos uploaded responsive to the prompt; and
analyzing the one or more videos to authenticate the one or more users by performing at least one of:
verifying a biometric characteristic of the one or more users from the one or more videos, or
verifying that the one or more users performed the specified action or spoke the specified content in the one or more videos.
22 . A digital asset custodial system as recited in claim 15 , and configured to cause the one or more mobile devices to output a deterministic authentication challenge to the one or more users, wherein a content of the deterministic authentication challenge is based on a context of the requested transaction.
23 . A method as recited in claim 1 , further comprising receiving, by the hardware security module, an operation description, wherein said determining whether one or more valid endorsements have been received from the one or more users comprises:
determining, by the hardware security module, whether each of the one or more users is in an organization specified in the operation description;
determining, by the hardware security module, whether each of the one or more endorsement messages is signed using a correct public key; and
determining, by the hardware security module, whether each of the one or more endorsements messages approves the requested transaction.
24 . A digital asset custodial system as recited in claim 15 , wherein the hardware security module is configured to store, in an internal storage:
the stored policy, which comprises one policy for each action for each possible action;
an identifier of each user specified in the stored policy as a possible member of the quorum for approving the transaction;
an identifier of an organization to which each user specified in the stored policy belongs; and
a public key of the organization.