Skip to content
Back to articles

Modern Digital Asset Custody Solution with a Hybrid Approach: ColdShield

Category: Articles

Security is undoubtedly one of the most crucial aspects of the digital asset ecosystem. As the need for individuals and institutions to protect their digital assets continues to grow, the demand for innovative technologies is increasing rapidly. Traditionally, Hardware Security Modules (HSM) have been considered the gold standard solution for physical security. However, in recent years, a groundbreaking innovation has emerged: Multi-Party Computation (MPC), which offers a transformative approach to asset protection.

MPC offers a revolutionary approach by splitting digital key management and signing processes across multiple independent security layers. When integrated with HSM in a hybrid structure, MPC redefines the standards for digital asset protection. In this article, we, as the Paribu Custody team, will demonstrate that MPC is not only as secure as HSM but, when implemented correctly, can provide even enhanced security and operational flexibility.

Furthermore, we will explore our hybrid solution, ColdShield, which combines MPC, HSM, and SGX technologies. we will analyze why this multi-layered approach is more secure, flexible, and sustainable than single-layer systems, supported with concrete examples.

An Overview of Key Concepts

Understanding key concepts is essential when exploring digital asset custody technologies. Let's examine the roles of HSM, MPC, and SGX in this context.

HSM (Hardware Security Module)

An HSM is a specialized hardware device that securely stores digital keys and performs cryptographic operations such as signing and encryption. Typically certified with international standards like FIPS 140-2, HSMs provide robust protection against physical attacks and unauthorized access.

However, HSMs have a significant limitation: all key materials are stored in a single device, creating a single point of failure (SPoF). Think of an HSM as a highly secure, encrypted vault. If a malicious actor gains access to this vault, they can potentially compromise all its contents. For this reason, systems that rely solely on HSMs may not be sufficiently resilient against advanced threat scenarios.

MPC (Multi-Party Computation)

MPC offers a distributed alternative to traditional single-point key storage methods. Rather than being stored in a single device, private keys are divided into cryptographically secure fragments (shards) and distributed across multiple locations or systems. These shards can perform cryptographic operations without ever being recombined, ensuring that the compromise of a single device does not threaten the system's integrity.

By eliminating the concept of a single-point attack, MPC requires a malicious actor to breach multiple independent systems, significantly enhancing security and resilience.

SGX (Software Guard Extensions)

SGX, developed by Intel, is a security technology that enables software to run within an isolated environment called an "enclave". This isolation protects critical components and sensitive data from both the operating system and other applications. SGX provides an additional hardware-based layer of defence against external attacks and insider threats.

SGX can be envisioned as a "secure room" completely isolated from all other layers, including the operating system. Even if an attacker attempts to access this room through physical or software-based methods, SGX ensures that critical data remains protected and inaccessible. However, SGX alone cannot provide comprehensive protection. To defend against advanced attacks, it must be combined with multi-layered security approaches, such as those combining MPC and HSM.

Hybrid Approach: The Power of ColdShield

ColdShield is a hybrid solution designed to combine the best strengths of MPC, SGX, and HSM technologies to deliver a robust security framework.

Distributed Key Management

With ColdShield, digital keys are split into multiple cryptographic shards using MPC technology and stored across different locations. The key advantages of this approach include:

1. Physical Protection and Distribution

Each shard is encrypted and stored in HSM devices across locations. Even if one device is compromised, the entire system remains secure.

Example: If an attacker physically breaches one HSM, the encryption mechanism in the image of the captured shard is useless. Moreover, the remaining shards are stored securely in separate locations, maintaining operational continuity.

2. Unusable Shards

No single shard holds meaningful data on its own and even reconstructing them would not suffice to compromise the system without the MPC protocol.

Example: A malicious actor who obtains one shard cannot exploit it due to encryption. Unless the attacker gains access to all shards, no meaningful information can be derived.

3. Secure Transfer and Protocols

MPC protocols ensure shards are encrypted during transfers, preventing encryption keys from leaving their secure environments.

Example: When shards are transferred to a remote data centre, MPC protocols maintain their split and encryption, protecting them from unauthorized access.

This distributed architecture ensures the security of digital assets both physically and virtually. By combining MPC's distributed nature, HSM's physical protection, and SGX's secure enclaves, ColdShield creates an exceptional security structure.

Advantages of ColdShield

ColdShield is specifically designed and implemented to address current and future security challenges comprehensively.

1. Layered Protection

ColdShield integrates multiple security technologies, creating a multi-layered defence structure. By combining the physical protection of HSMs, the distributed nature of MPC, and the secure environment of SGX, it constructs multiple barriers that attackers must overcome. Each layer serves unique security functions, making it extremely difficult for attackers to compromise the entire system.

2. Disaster Resilience

By distributing MPC shards across geographically diverse locations, ColdShield remains resilient to physical and digital disasters. Even in the face of region-specific disruptions like earthquakes, fires, or infrastructure failures, digital assets remain secure. This distributed design also supports rapid recovery and ensures business continuity in the aftermath of disruptions.

3. Independent Audits

Each component of ColdShield can be independently audited and certified to meet international standards, offering significant advantages in regulatory compliance and transparency. These independent certifications verify that the system is secure in practice, not just in theory.

Conclusion: A Secure Step Toward the Future

With ColdShield, we prioritize the security and resilience of digital assets. Our hybrid approach eliminates reliance on single-point systems, offering a distributed, multi-layered infrastructure that addresses both current and emerging threats. At Paribu Custody, we are committed to innovation in digital finance by providing solutions that are not only secure but also sustainable and dynamic.

Our mission is to protect digital assets while shaping the future of digital finance. ColdShield represents a major step forward in achieving this goal.