IP Library Granted Patent US 12,401,498
Granted Patent B2
US 12,401,498 · App. 17/711,810 · Granted Aug 26, 2025

Custodial digital wallet management systems

Inventors: Kevin Osborn (Newton Highlands, MA); Srinivasa Chigurupati (Long Grove, IL)
Assignee: Capital One Services, LLC
H04L9/0825G06Q20/363G06Q20/367H04L9/14H04L9/3066H04L9/3234H04L9/3247G06Q20/3829H04L9/50H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,498
App. No.
17/711,810
Granted
Aug 26, 2025
Kind
B2
Abstract

Systems and methods, as described herein, relate to increasing the functionality and security of digital wallets. These methods, techniques, and infrastructure may use hardware security modules (HSMs) to manage a plurality of cryptocurrency wallets in a custodial capacity. The HSMs may have functionality incorporated therein improve the functionality and security of cryptocurrency wallets. The aspects discussed herein may also relate to methods, techniques, and infrastructure to securely manage signing keys and cryptocurrency addresses contained in cryptocurrency wallets for a plurality of accounts that may be associated with a user account or user account identifier without exposing the keys to being stolen or otherwise comprised.

Claims (43)

1. A computer-implemented method comprising:

receiving, by a computing device, a request from a user for a cryptocurrency transaction and an account identifier for a cryptocurrency account associated with the user;

retrieving, from a secure memory location associated with a hardware security module, a master key, wherein the master key is associated with a financial institution;

deriving, by the hardware security module and using the master key and the account identifier, a private key associated with the user;

deriving, based on the private key, a public key, wherein the hardware security module is configured to store the private key and the public key in a digital wallet associated with the account identifier;

generating, by the hardware security module and using the private key, a digital signature associated with the cryptocurrency transaction; and

storing the cryptocurrency transaction and the digital signature in a distributed ledger.

2. The computer-implemented method of claim 1 , further comprising:

receiving a second request from a second user for a second cryptocurrency transaction;

deriving, by the hardware security module and using the master key, a second private key associated with the second user;

deriving, based on the second private key, a second public key;

generating, by the hardware security module and using the second private key, a second digital signature associated with the second cryptocurrency transaction; and

storing the second cryptocurrency transaction and the second digital signature in the distributed ledger.

3. The method of claim 1 , wherein the storing the cryptocurrency transaction and the digital signature in the distributed ledger comprises transmitting the digital signature to the distributed ledger.

4. The method of claim 1 , wherein the deriving the private key further comprises deriving the private key using a value of a counter.

5. The method of claim 1 , further comprising deriving, by the hardware security module, the private key and the public key from the master key, the account identifier, and diversification data received with the request.

6. The method of claim 1 , wherein the private key and the public key are maintained securely within the hardware security module.

7. The method of claim 1 , wherein the private key and the public key from the master key are derived using elliptic curve cryptography.

8. A computing system comprising:

a hardware security module;

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the computing system to:

receive a request from a user for a cryptocurrency transaction and an account identifier for a cryptocurrency account associated with the user;

retrieve, by the hardware security module, from a secure memory location associated with the hardware security module, a master key, wherein the master key is associated with a financial institution;

derive, by the hardware security module and using the master key and the account identifier, a private key associated with the user;

derive, by the hardware security module, a public key based on the private key, wherein the hardware security module is configured to store the private key and the public key in a digital wallet associated with the account identifier;

generate, by the hardware security module, using the private key, a digital signature associated with the cryptocurrency transaction; and

store the cryptocurrency transaction and the digital signature in a distributed ledger by transmitting the digital signature to the distributed ledger.

9. The computing system of claim 8 , wherein the memory is further storing instructions that, when executed by the one or more processors, cause the computing system to derive, by the hardware security module, the private key based on a value of a counter.

10. The computing system of claim 8 , wherein the memory is further storing instructions that, when executed by the one or more processors, cause the computing system to derive, by the hardware security module, the private key and the public key from the master key and the public key from the master key, the account identifier, and diversification data received with the request.

11. The computing system of claim 8 , wherein the private key and the public key are maintained securely within the hardware security module.

12. The computing system of claim 8 , wherein the private key and the public key from the master key are derived using elliptic curve cryptography.

13. A non-transitory computer-readable storage medium comprising instructions that, when executed, cause a computing system to:

receive a request from a user for a cryptocurrency transaction, the request comprising an account identifier for a cryptocurrency account associated with the user;

retrieve, by a hardware security module, from a secure memory location associated with the hardware security module, a master key, wherein the master key is associated with a financial institution;

derive, by the hardware security module and using the master key and the account identifier, a private key associated with the user;

derive, by the hardware security module, a public key based on the private key, wherein the hardware security module is configured to store the private key and the public key in a digital wallet associated with the account identifier;

generate, by the hardware security module, using the private key, a digital signature associated with the cryptocurrency transaction; and

store the cryptocurrency transaction and the digital signature in a distributed ledger by transmitting the digital signature to the distributed ledger.

14. The non-transitory computer-readable storage medium of claim 13 , further comprising instructions that, when executed, cause the computing system to derive, by the hardware security module, the private key further based on a value of a counter.

15. The non-transitory computer-readable storage medium of claim 13 , further comprising instructions that, when executed, cause the computing system to derive, by the hardware security module, the private key and the public key from the master key and the public key from the master key, the account identifier, and diversification data received with the request.

16. The non-transitory computer-readable storage medium of claim 13 , further comprising instructions that, when executed, cause the computing system to derive the private key further based on a value of a counter.

17. The non-transitory computer-readable storage medium of claim 13 , further comprising instructions that, when executed, cause the computing system to maintain the private key and the public key securely within the hardware security module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2022
From: OSBORN, KEVIN; CHIGURUPATI, SRINIVASA
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 059487/0071 →
Continuity (1)
Related Publication 20230318808A1 · Oct 5, 2023
References Cited (11)
US 10615969B1 · Griffin · 2020 [cited by examiner]
US 10615970B1 · Griffin · 2020 [cited by examiner]
US 20050138374A1 · Zheng · 2005 [cited by examiner]
US 20110099367A1 · Thom · 2011 [cited by examiner]
US 20140074724A1 · Gordon · 2014 [cited by examiner]
US 20160364722A1 · Nair · 2016 [cited by examiner]
US 20180367316A1 · Cheng · 2018 [cited by examiner]
US 20190370790A1 · Spector · 2019 [cited by examiner]
US 20210056547A1 · Monica · 2021 [cited by examiner]
US 20210119807A1 · Chen · 2021 [cited by examiner]
US 20240330911A1 · Ghosh · 2024 [cited by examiner]