IP Library Granted Patent US 11,689,366
Granted Patent B2
US 11,689,366 · App. 17/855,227 · Granted Jun 27, 2023

Cryptoasset custodial system with vault-specific rules governing different actions allowed for different vaults

Inventors: Diogo Monica (San Francisco, CA); Nathan P. McCauley (San Francisco, CA); Boaz Avital (San Francisco, CA); Riyaz D. Faizullabhoy (Los Altos, CA)
Assignee: Anchor Labs, Inc.
H04L9/14G06F21/602H04L9/0637H04L9/088H04L9/0822H04L9/0825H04L9/0877H04L9/0897H04L9/3239H04L9/3247H04L9/3255G06F21/6209G06Q20/0658H04L9/50H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,366
App. No.
17/855,227
Granted
Jun 27, 2023
Kind
B2
Abstract

Methods, and systems for secure storage and retrieval of information, such as private keys, useable to control access to a blockchain, include: receiving a request to take an action with respect to a vault of multiple different vaults in a cryptoasset custodial system, and each of the multiple different vaults has an associated policy map that defines vault control rules; authenticating, by a hardware security module, a policy map for the vault on which the action is requested based on a cryptographic key controlled by the hardware security module; checking the action against the policy map for the vault when the policy map for the vault is authenticated based on the cryptographic key controlled by the hardware security module; and effecting the action when the action is confirmed to be in accordance with the policy map for the vault.

Claims (48)

1. A method comprising:

receiving a request to take an action with respect to a vault in a cryptoasset custodial system, wherein the action comprises a change to a policy map associated with the vault, wherein the associated policy map defines vault control rules governing which actions are allowed for the vault;

authenticating, by a hardware security module managing private keys of cryptographic key pairs usable to control access to cryptoassets associated with a customer account of the cryptoasset custodial system, the policy map for the vault on which the action is requested based on a cryptographic key controlled by the hardware security module;

checking, by the hardware security module, the action against the policy map for the vault when the policy map for the vault is authenticated based on the cryptographic key controlled by the hardware security module; and

effecting, by the hardware security module, the action when the action is confirmed to be in accordance with the policy map for the vault by:

generating an updated version of the policy map including the requested change;

digitally signing the updated version of the policy map using the cryptographic key controlled by the hardware security module; and

storing resulting digital signature data for future use by the hardware security module,

wherein the action comprising the change to the policy map includes at least one of: adding a new user to the customer account, removing an existing user from the customer account, updating a user access level of one or more existing users of the customer account, or modifying a threshold number of users of the cryptoasset custodial system required to approve the action.

2. The method of claim 1 , wherein the hardware security module comprises at least one secure storage device and at least one physical computing device coupled to the at least one secure storage device, the at least one physical computing device being configured to provide cryptographic processing to manage, for the customer account, the private keys of the cryptographic key pairs.

3. The method of claim 1 , wherein the vault control rules of the policy map for the vault specify, for the action, a plurality of users of the cryptoasset custodial system and the threshold number of the plurality of users required to approve the action.

4. The method of claim 3 , wherein checking the action against the policy map for the vault comprises:

validating a plurality of endorsement messages from at least a subset of the specified plurality of users, and

confirming that the action is in accordance with the vault control rules of the policy map when the plurality of endorsement messages have been validated for the threshold number of the specified plurality of users.

5. The method of claim 4 , wherein validating the plurality of endorsement messages comprises checking cryptographic digital signatures using public keys corresponding to the subset of the specified plurality of users.

6. The method of claim 1 , wherein effecting the action further comprises transmitting the resulting digital signature data to at least one blockchain.

7. A system comprising:

a hardware security module configured to execute instructions to perform operations comprising:

receiving a request to take an action with respect to a vault in a cryptoasset custodial system, wherein the action comprises a change to a policy map associated with the vault, wherein the associated policy map defines vault control rules governing which actions are allowed for the vault;

authenticating the policy map for the vault on which the action is requested based on a cryptographic key controlled by the hardware security module, the hardware security module managing private keys of cryptographic key pairs usable to control access to cryptoassets associated with a customer account of the cryptoasset custodial system;

checking the action against the policy map for the vault when the policy map for the vault is authenticated based on the cryptographic key controlled by the hardware security module; and

effecting the action when the action is confirmed to be in accordance with the policy map for the vault by:

generating an updated version of the policy map including the requested change;

digitally signing the updated version of the policy map using the cryptographic key controlled by the hardware security module; and

storing resulting digital signature data for future use by the hardware security module,

wherein the action comprising the change to the policy map includes at least one of: adding a new user to the customer account, removing an existing user from the customer account, updating a user access level of one or more existing users of the customer account, or modifying a threshold number of users of the cryptoasset custodial system required to approve the action.

8. The system of claim 7 , wherein the hardware security module comprises at least one secure storage device and at least one physical computing device coupled to the at least one secure storage device, the at least one physical computing device being configured to provide cryptographic processing to manage, for the customer account, the private keys of the cryptographic key pairs.

9. The system of claim 7 , wherein the vault control rules of the policy map for the vault specify, for the action, a plurality of users of the cryptoasset custodial system and the threshold number of the plurality of users required to approve the action.

10. The system of claim 9 , wherein checking the action against the policy map for the vault comprises:

validating a plurality of endorsement messages from at least a subset of the specified plurality of users, and

confirming that the action is in accordance with the vault control rules of the policy map when the plurality of endorsement messages have been validated for the threshold number of the specified plurality of users.

11. The system of claim 10 , wherein validating the plurality of endorsement messages comprises checking cryptographic digital signatures using public keys corresponding to the subset of the specified plurality of users.

12. The system of claim 7 , wherein effecting the action further comprises transmitting the resulting digital signature data to at least one blockchain.

13. A non-transitory computer-readable medium storing computer-executable instructions, which, when executed by a hardware security module, cause the hardware security module to perform operations comprising:

receiving a request to take an action with respect to a vault in a cryptoasset custodial system, wherein the action comprises a change to a policy map associated with the vault, wherein the associated policy map defines vault control rules governing which actions are allowed for the vault;

authenticating the policy map for the vault on which the action is requested based on a cryptographic key controlled by the hardware security module, the hardware security module managing private keys of cryptographic key pairs usable to control access to cryptoassets associated with a customer account of the cryptoasset custodial system;

checking the action against the policy map for the vault when the policy map for the vault is authenticated based on the cryptographic key controlled by the hardware security module; and

effecting the action when the action is confirmed to be in accordance with the policy map for the vault by:

generating an updated version of the policy map including the requested change;

digitally signing the updated version of the policy map using the cryptographic key controlled by the hardware security module; and

storing resulting digital signature data for future use by the hardware security module,

wherein the action comprising the change to the policy map includes at least one of: adding a new user to the customer account, removing an existing user from the customer account, updating a user access level of one or more existing users of the customer account, or modifying a threshold number of users of the cryptoasset custodial system required to approve the action.

14. The computer-readable medium of claim 13 , wherein the hardware security module comprises at least one secure storage device and at least one physical computing device coupled to the at least one secure storage device, the at least one physical computing device being configured to provide cryptographic processing to manage, for the customer account, the private keys of the cryptographic key pairs.

15. The computer-readable medium of claim 14 , wherein the vault control rules of the policy map for the vault specify, for the action, a plurality of users of the cryptoasset custodial system and the threshold number of the plurality of users required to approve the action.

16. The computer-readable medium of claim 15 , wherein checking the action against the policy map for the vault comprises:

validating a plurality of endorsement messages from at least a subset of the specified plurality of users, and

confirming that the action is in accordance with the vault control rules of the policy map when the plurality of endorsement messages have been validated for the threshold number of the specified plurality of users.

17. The computer-readable medium of claim 16 , wherein validating the plurality of endorsement messages comprises checking cryptographic digital signatures using public keys corresponding to the subset of the specified plurality of users.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MONICA, DIOGO; MCCAULEY, NATHAN P.; AVITAL, BOAZ; FAIZULLABHOY, RIYAZ D.
To: ANCHOR LABS, INC.
Reel/Frame 060418/0742 →
Continuity (7)
Continuation 17366424 · Jul 2, 2021
Continuation 16544740 · Aug 19, 2019
Continuation In Part 16255666 · Jan 23, 2019
Continuation In Part 16011529 · Jun 18, 2018
Provisional Application 62640429 · Mar 8, 2018
Provisional Application 62636106 · Feb 27, 2018
Related Publication 20220337411A1 · Oct 20, 2022
Cited By (1)
US 12,284,290