Self Hosted Wallet - Self Hosted Digital Asset Management
Self-Hosted, Institutional-Grade Digital Asset Policy Wallet by Blockdaemon
By: Frank Wiener
Digital Asset Management requires advanced controls & policies, such as self-hosting (Self Hosted Wallet), quorums, checklists and operational controls.
Digital asset custodians, exchanges, brokers, institutional investors, and other organizations require an institutional-grade digital asset wallet that provides advanced levels of security and controls.
They often require more flexible and advanced levels of policy controls, complete control over how and where their wallet infrastructure is hosted, and the ability to comply with any applicable regulation, license, and insurance mandates. This article reviews these market requirements and describes how the recently introduced Blockdaemon Wallet satisfies those requirements and more.
Advanced Digital Asset Wallet Policies for Financial Institutions and Crypto-Natives
Organizations dealing in large amounts of cryptocurrencies, NFTs and other digital assets require advanced levels of control over how those assets are transferred to another party. Many organizations require a combination of nested and overlapping policies, with different flows depending on the asset type, value, or other criteria.
Digital Asset Policy Wallet Controls – Quorums
For certain wallet applications and transactions, it may be appropriate to require multiple parties to approve a transaction before it is submitted to the blockchain for execution.
This policy may be as simple as a two-party approval scheme where both a requestor and an approver must approve, or it could be a more advanced quorum model where at least two parties of the three members of group A and at least three parties of the five members of group C must approve.
Digital Asset Policy Wallet Controls – Checklists
Certain wallets may be used as gateways between other wallets to provide layers of security and control.
For example, a cold wallet, which is offline, may only be authorized to transfer digital assets to only a whitelist of pre-approved warm wallet addresses. An attempt to transfer assets directly to any other wallet would be blocked by the checklist policies.
Digital Asset Policy Wallet Controls – Conditional Controls
It can be very useful to have conditional controls, with “If, then, else” parameters that enforce other policies.
An example might be to allow for some minimal number of approvers from Group A to authorize a transaction if the value is below a certain value, but require either a larger number of approvers from Group A or also require a quorum of Group B approvers when the transaction value is above a certain level.
Digital Asset Policy Wallet Controls – Operational Controls
Service providers may also wish to put operational controls such as rate limits on the number of trades that a specific wallet may execute over a specified period of time, or throttling to prevent wallets from running beyond the capacity of other subsystems within the broader ecosystem.
Self-Hosting Policy Wallets for Complete Control
Many companies enter the digital asset market using widely available Wallet-as-a-Service (WaaS) offerings, which are hosted by the wallet provider.
These hosted wallet services are a convenient way to get started, however, regulators, major customers, insurers, and major shareholders prefer to see these wallets hosted by the service provider. Self-hosting gives the digital asset service provider complete control over their wallet’s performance, availability, roadmap, capacity expansions, geographic expansions, custody models, MPC security models and more.
Digital Asset Policy Wallet – Advanced Security
While flexible policies and hosting capabilities are increasingly critical, the first priority of any digital asset wallet is to protect the wallet and private keys from theft or misuse, which can result in stolen digital assets.
Digital Asset Policy Wallets - Key Protection Using Multiparty Computation (MPC)
Multiparty Computation (MPC) has emerged as the key management and protection technology of choice for digital assets.
MPC natively generates and uses private keys to generate transaction approval signatures in the form of distributed key shares, which are stored and used by different parties. This MPC wallet model eliminates the existence of a complete key on a single machine or known by any single party.
MPC also natively supports the ability to cryptographically enforce multiple party approval schemes, requiring 2 out of 3, or 3 out of 5 approvers similar to what was previously possible using MultiSig.
Digital Asset Policy Wallets – Increased Security, Flexibility, and Performance with Advanced MPC™
Advanced MPC™ builds upon the proven benefits of MPC and introduces purpose-built protocols that have been application optimized for securing private keys and digital assets.
Digital Asset Policy Wallets – Cryptographically Binding Policies with Key Shares
While MPC is highly useful at preventing private key theft or misuse, the risk of blind signing is still a concern.
One way to eliminate blind signing risk is to use MPC to cryptographically bind policies with MPC key shares. This can ensure that the policy criteria being used by one party is consistent with the policy criteria of all other signing parties, for a What You See Is What You Sign (WYSIWYS) signature generation model.
Blockdaemon Wallet
Blockdaemon has been providing Advanced MPC key management and protection technology to companies developing their own digital asset wallets and custody solutions since 2018.
Blockdaemon introduced the Blockdaemon Wallet in June of 2022 for companies that prefer to source a complete wallet rather than just the MPC key management technology. The Blockdaemon Wallet is an institutional-grade policy wallet supporting both custody and non-custody applications. It is a universal wallet that supports multiple asset types and supports all of the features and functional elements described above, and more.