IP Library › Granted Patent US 12,506,619
Granted Patent B1
US 12,506,619 · App. 19/287,737 · Granted Dec 23, 2025

Controlling access to cryptographic resources using double encryption

Inventors: Biser Dimitrov (New York, NY); Boaz Bechar (Tel Aviv, IL)
Assignee: Citibank, N.A.
H04L9/3247H04L9/0866H04L9/0894H04L9/50H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,619
App. No.
19/287,737
Granted
Dec 23, 2025
Kind
B1
Abstract

A system for controlling access to cryptographic resources is disclosed. The system may receive a request to transfer cryptographic resources between users, including a user identifier and a first cryptographic signature. The system may verify the signature and retrieve an encrypted private key from a key vault using the user identifier. A command to sign the request may be transmitted over a private network to a signature device, which may generate a second cryptographic signature using the decrypted private key. The system may receive the second signature, generate a blockchain operation based on the request and signature, and transmit the operation to a blockchain node for commitment. The system may also handle new account generation, storing encrypted keys in jurisdiction-specific databases, and validating blockchain operations against request parameters.

Claims (85)

1 . A system for controlling access to cryptographic resources, the system comprising:

one or more processors; and

one or more non-transitory computer-readable storage media storing instructions, which when executed by the one or more processors cause the one or more processors to perform operations comprising:

receiving a request to transfer control of a number of cryptographic resources from a first user to a second user;

retrieving, from a key vault using a user identifier associated with the first user, an encrypted key object that represents a private key, wherein the encrypted key object comprises a plurality of encrypted key shards, and wherein each key shard of the plurality of encrypted key shards, when decrypted, is used to generate a corresponding portion of a cryptographic signature for a blockchain operation to transfer control of the number of cryptographic resources to the second user;

transmitting, to a first security device, a decryption command to decrypt the encrypted key object, wherein the first security device decrypts the encrypted key object into the plurality of encrypted key shards;

receiving, from the first security device, the plurality of encrypted key shards representing the private key;

transmitting, to a second security device, the plurality of encrypted key shards and a command to generate the cryptographic signature for signing the blockchain operation, wherein the second security device transmits each encrypted key shard of the plurality of encrypted key shards to a corresponding node that encrypted each shard, and wherein each corresponding node generates the corresponding portion of the cryptographic signature corresponding to an encrypted shard of the plurality of encrypted key shards;

generating the cryptographic signature from each corresponding portion of the cryptographic signature;

generating the blockchain operation based on the request and the cryptographic signature, wherein the cryptographic signature is used by a blockchain node of a blockchain to authorize the blockchain operation; and

transmitting the blockchain operation to the blockchain node.

2 . The system of claim 1 , wherein the instructions further cause the one or more processors to perform operations comprising:

receiving a new account generation request for a new user;

transmitting a key generation request to the second security device, wherein the second security device generates a new private key and a new public key for the new user, the new private key comprising a new plurality of key shards, sends each new key shard to the corresponding node, wherein each corresponding node encrypts a corresponding new keys shard, each corresponding node generating a new encrypted plurality of key shards using a corresponding first encryption key generated at each node;

receiving the new encrypted plurality of key shards and the new public key from the second security device;

transmitting the new encrypted plurality of key shards to the first security device with an encryption command to encrypt the new encrypted plurality of key shards into a new encrypted private key, wherein the first security device encrypts the new plurality of key shards into the new encrypted private key using a second encryption key that is generated on the first security device; and

transmitting the new encrypted private key to a database server that stores the new encrypted private key in the key vault.

3 . The system of claim 2 , wherein the instructions for transmitting the new encrypted private key to the database server further cause the one or more processors to perform operations comprising:

retrieving user data associated with the new user;

determining based on the user data associated with user a user's location, wherein the user's location comprises a jurisdiction of the user;

identifying, based on the user's location, the database server within the jurisdiction of the user, wherein the database server is one of a plurality of database servers active in a plurality of different jurisdictions; and

transmitting the new encrypted private key to the database server identified based on the jurisdiction corresponding to the user.

4 . The system of claim 1 , wherein the instructions for retrieving, from the key vault using the user identifier, the encrypted key object associated with the first user further cause the one or more processors to perform operations comprising:

retrieving, from the request, the user identifier associated with the first user;

transmitting, to the key vault, the user identifier associated with the first user; and

receiving, from the key vault, the encrypted key object associated with the first user.

5 . The system of claim 1 , wherein the instructions further cause the one or more processors to perform operations comprising:

receiving, from the second security device, a plurality of portions of the cryptographic signature generated based on the plurality of encrypted key shards, wherein the cryptographic signature is used to cryptographically sign the blockchain operation; and

combining the plurality of portions of the cryptographic signature into the cryptographic signature.

6 . The system of claim 1 , wherein the instructions for transmitting, to the second security device, the plurality of encrypted key shards and the command to generate the cryptographic signature for signing the blockchain operation further cause the one or more processors to perform operations comprising:

generating a hash of the blockchain operation, wherein the hash comprises one or more of a source blockchain address associated with the first user, a target blockchain address associated with the second user, or the number of cryptographic resources; and

transmit the hash together with the command, wherein the command instructs the second security device to generate a plurality of portions of the cryptographic signature using the hash.

7 . A method for controlling access to cryptographic resources using double encryption, the method comprising:

receiving a request to transfer control of a first number of cryptographic resources from a first user to a second user;

retrieving, from a key vault using a user identifier associated with the first user, an encrypted key object that represents a private key, wherein the encrypted key object comprises a plurality of encrypted key shards;

transmitting, to a first security device, a decryption command to decrypt the encrypted key object, wherein the first security device decrypts the encrypted key object into the plurality of encrypted key shards;

receiving, from the first security device, the plurality of encrypted key shards representing the private key;

transmitting, to a second security device, the plurality of encrypted key shards and a command to generate a cryptographic signature for signing a blockchain operation;

generating the blockchain operation based on the request and the cryptographic signature, wherein the cryptographic signature is used by a blockchain node of a blockchain to authorize the blockchain operation; and

transmitting the blockchain operation to the blockchain node.

8 . The method of claim 7 , wherein each key shard of the plurality of encrypted key shards, when decrypted, is used to generate a corresponding portion of the cryptographic signature for the blockchain operation to transfer control of the first number of cryptographic resources to be controlled by the second user.

9 . The method of claim 7 , wherein the second security device transmits each encrypted key shard of the plurality of encrypted key shards to a corresponding node that encrypted each shard, and wherein each corresponding node generates a corresponding portion of the cryptographic signature corresponding to an encrypted shard of the plurality of encrypted key shards.

10 . The method of claim 7 , further comprising:

receiving a new account generation request for a new user;

transmitting a key generation request to the second security device, wherein the second security device generates a new private key and a new public key for the new user, the new private key comprising a new plurality of key shards, sends each new key shard to a corresponding node, wherein each corresponding node encrypts a corresponding new keys shard, each corresponding node generating a new encrypted plurality of key shards using a corresponding first encryption key generated at each node;

receiving the new encrypted plurality of key shards and the new public key from the second security device;

transmitting the new encrypted plurality of key shards to the first security device with an encryption command to encrypt the new encrypted plurality of key shards into a new encrypted private key, wherein the first security device encrypts the new plurality of key shards into the new encrypted private key using a second encryption key that is generated on the first security device; and

transmitting the new encrypted private key to a database server that stores the new encrypted private key in the key vault.

11 . The method of claim 10 , wherein transmitting the new encrypted private key to the database server comprises:

retrieving user data associated with the new user;

determining based on the user data associated with user a user's location, wherein the user's location comprises a jurisdiction of the user;

identifying, based on the user's location, the database server within the jurisdiction of the user, wherein the database server is one of a plurality of database servers active in a plurality of different jurisdictions; and

transmitting the new encrypted private key to the database server identified based on the jurisdiction corresponding to the user.

12 . The method of claim 7 , wherein for retrieving, from the key vault using the user identifier, the encrypted key object associated with the first user further comprises:

retrieving, from the request, the user identifier associated with the first user;

transmitting, to the key vault, the user identifier associated with the first user; and

receiving, from the key vault, the encrypted key object associated with the first user.

13 . The method of claim 7 , further comprising:

receiving, from the second security device, a plurality of portions of the cryptographic signature generated based on the plurality of encrypted key shards, wherein the cryptographic signature is used to cryptographically sign the blockchain operation; and

combining the plurality of portions of the cryptographic signature into the cryptographic signature.

14 . The method of claim 7 , wherein transmitting, to the second security device, the plurality of encrypted key shards and the command to generate the cryptographic signature for signing the blockchain operation further comprises:

generating a hash of the blockchain operation, wherein the hash comprises one or more of a source blockchain address associated with the first user, a target blockchain address associated with the second user, or a number of cryptographic resources; and

transmit the hash together with the command, wherein the command instructs the second security device to generate a plurality of portions of the cryptographic signature using the hash.

15 . One or more non-transitory, computer-readable storage media storing instructions that when executed by one or more processors cause the one or more processors to perform operations comprising:

receiving a request to transfer control of a first number of cryptographic resources from a first user to a second user;

retrieving, from a key vault using a user identifier associated with the first user, an encrypted key object that represents a private key, wherein the encrypted key object comprises a plurality of encrypted key shards;

transmitting, to a first security device, a decryption command to decrypt the encrypted key object, wherein the first security device decrypts the encrypted key object into the plurality of encrypted key shards;

receiving, from the first security device, the plurality of encrypted key shards representing the private key;

transmitting, to a second security device, the plurality of encrypted key shards and a command to generate a cryptographic signature for signing a blockchain operation;

generating the blockchain operation based on the request and the cryptographic signature, wherein the cryptographic signature is used by a blockchain node of a blockchain to authorize the blockchain operation; and

transmitting the blockchain operation to the blockchain node.

16 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein each key shard of the plurality of encrypted key shards, when decrypted, is used to generate a corresponding portion of the cryptographic signature for the blockchain operation to transfer control of the first number of cryptographic resources to be controlled by the second user.

17 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein the second security device transmits each encrypted key shard of the plurality of encrypted key shards to a corresponding node that encrypted each shard, and wherein each corresponding node generates a corresponding portion of the cryptographic signature corresponding to an encrypted shard of the plurality of encrypted key shards.

18 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein the instructions further cause the one or more processors to perform operations comprising:

receiving a new account generation request for a new user;

transmitting a key generation request to the second security device, wherein the second security device generates a new private key and a new public key for the new user, the new private key comprising a new plurality of key shards, sends each new key shard to a corresponding node, wherein each corresponding node encrypts a corresponding new keys shard, each corresponding node generating a new encrypted plurality of key shards using a corresponding first encryption key generated at each node;

receiving the new encrypted plurality of key shards and the new public key from the second security device;

transmitting the new encrypted plurality of key shards to the first security device with an encryption command to encrypt the new encrypted plurality of key shards into a new encrypted private key, wherein the first security device encrypts the new plurality of key shards into the new encrypted private key using a second encryption key that is generated on the first security device; and

transmitting the new encrypted private key to a database server that stores the new encrypted private key in the key vault.

19 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein the instructions further cause the one or more processors to perform operations comprising:

receiving, from the second security device, a plurality of portions of the cryptographic signature generated based on the plurality of encrypted key shards, wherein the cryptographic signature is used to cryptographically sign the blockchain operation; and

combining the plurality of portions of the cryptographic signature into the cryptographic signature.

20 . The one or more non-transitory, computer-readable storage media of claim 15 , wherein the instructions for transmitting, to the second security device, the plurality of encrypted key shards and the command to generate the cryptographic signature for signing the blockchain operation further cause the one or more processors to perform operations comprising:

generating a hash of the blockchain operation, wherein the hash comprises one or more of a source blockchain address associated with the first user, a target blockchain address associated with the second user, or a number of cryptographic resources; and

transmit the hash together with the command, wherein the command instructs the second security device to generate a plurality of portions of the cryptographic signature using the hash.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2025
From: DIMITROV, BISER; BECHAR, BOAZ
To: CITIBANK, N.A.
Reel/Frame 072101/0304 →
References Cited (8)
US 20210182422A1 · Basu · 2021 [cited by examiner]
US 20220027348A1 · Manevich · 2022 [cited by examiner]
US 20220141014A1 · Britto · 2022 [cited by examiner]
US 20230412393A1 · Williams · 2023 [cited by examiner]
US 20240372731A1 · Kobel · 2024 [cited by examiner]
US 20240403869A1 · Huussin · 2024 [cited by examiner]
U.S. Appl. No. 19/287,718, filed Jul. 31, 2025, Biser Dimitrov Boaz Bechar, Controlling access to Cryptographic Resources. [cited by applicant]
U.S. Appl. No. 19/287,749, filed Jul. 31, 2025, Biser Dimitrov Boaz Bechar, Controlling access to Cryptographic Resources Using Offline Storage. [cited by applicant]
Cited By (1)
US 12,712,753