Currently, one of the most widely used protocols to secure cryptocurrency assets in centralized exchanges is categorizing wallets into cold and hot. While cold wallets hold user deposits, hot} wallets are responsible for addressing withdrawal requests. However, this method has some shortcomings such as: 1) availability of private keys in at least one cold device, and~2) exposure of all private keys to one trusted cold wallet admin. To overcome such issues, we design a new protocol for managing cold wallet assets by employing native multi-signature schemes. The proposed cold wallet system, involves at least two distinct devices and their corresponding admins for both wallet creation and signature generation. The method ensures that no final private key is stored on any device. To this end, no individual authority can spend from exchange assets. Moreover, we provide details regarding practical implementation of the proposed method and compare it against state-of-the-art. Furthermore, we extend the application of the proposed method to an scalable scenario where users are directly involved in wallet generation and signing process of cold wallets in an MPC manner.
翻译:目前,在中央交易所确保加密货币资产最广泛使用的协议之一是将钱包分类为冷热的。虽然冷钱包持有用户存款,但热气钱包负责处理提款请求。然而,这种方法有一些缺点,例如:(1) 至少有一个冷藏装置中可以找到私人钥匙,以及~(2)所有私人钥匙暴露在一个可信赖的冷藏钱包管理员手中。为了克服这些问题,我们设计了一个新的协议,通过使用本地多签名办法管理冷藏钱包资产。提议的冷藏钱包系统涉及至少两个不同的设备及其相应的管理员,用于钱包的创建和签名生成。这种方法确保了任何设备中不储存任何最后的私人钥匙。为此,任何个别当局都无法从交换资产中支出。此外,我们提供了拟议方法的实际实施细节,并将其与最新工艺进行比较。此外,我们将拟议方法的应用扩大到一个可扩展的情景,即用户直接参与钱包生成和以MPC方式签署冷钱包的过程。