How to Back Up High-Value Secret Keys
Sanjam Garg, Noemi Glaeser, Abhishek Jain, Michael Lodder, Hart Montgomery
Abstract
Consider a cryptocurrency exchange that secures the bulk of its reserves under a small set of keys, each of which is only used to transfer cryptocurrency once a year; or the backup codes for an account login or a password manager, which are again rarely used but provide access to crucial systems or information. Securing such infrequently-used high-value secrets is crucial, but existing solutions, such as threshold wallets and 'cold' (offline) wallets, are unsatisfactory. In this work, we envision a system that allows users to conveniently back up their rarely-used, high-value keys. This new setting necessitates a novel set of design requirements. Specifically: • We allow user keys to be threshold secret-shared among a large number of custodians where each custodian wallet comprises of a hot (i.e., online) and a cold (i.e., offline) portion. The cold part of the wallet is not touched during the backup process (thus, it is independent of the number of system users) but must be accessed for recovery. • We provide a mechanism to continually assure users that their keys are safely stored. This feature is critical because our system is not designed for frequent key use. We also enable proactive key refresh. • Finally, in our approach, restoring a backed-up key is equivalent to generating a signature. Thus, signatures made by users of this system should look the same as "normal" signatures to avoid exposing holders of high-value keys to targeted attacks. Based on these requirements, we develop new security definitions and a UC-secure protocol that implements threshold BLS signatures in our new model. Our protocol is practically efficient for the envisioned large numbers of custodians: for a 67-out-of-100
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fe89ed55-e1ef-4283-b4ee-90df1f8a139eBuilds on10
- Marlin: Preprocessing zkSNARKs with Universal and Updatable SRSAlessandro Chiesa, Yuncong Hu, Mary Maller, Pratyush Mishra et al.EUROCRYPT 2020 · 356 citations
- Fast Multiparty Threshold ECDSA with Fast Trustless SetupRosario Gennaro, Steven GoldfederCCS 2018 · 264 citations
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 220 citations
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 171 citations
- UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable AbortsRan Canetti, Rosario Gennaro, Steven Goldfeder, Nikolaos Makriyannis et al.CCS 2020 · 135 citations
Related papers
- Refresh When You Wake Up: Proactive Threshold Wallets with Offline DevicesYashvanth Kondi, Bernardo Magri, Claudio Orlandi, Omer ShlomovitsS&P 2021 · 35 citations
- A Formal Treatment of Deterministic WalletsPoulami Das, Sebastian Faust, Julian LossCCS 2019 · 62 citations
- Threshold Cryptography as a Service (in the Multiserver and YOSO Models)Fabrice Benhamouda, Shai Halevi, Hugo Krawczyk, Alex Miao et al.CCS 2022 · 13 citations
- Stronger Security for Threshold Blind SignaturesAnja Lehmann, Phillip Nazarian, Cavit ÖzbayEUROCRYPT 2025 · 10 citations
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 2 citations
