Daily Mail PH

Tuesday, July 25, 2023

[New post] Part 1: Genesis of Ledger Recover – Self Custody Without Compromise

Site logo image Crypto Breaking News posted: "Ledger's objective has always been to deliver uncompromising security and usability to anyone exploring the world of digital assets. Of all the self-custody solutions to keep your private keys safe and accessible, our hardware devices are second to none. " Crypto Breaking News

Part 1: Genesis of Ledger Recover – Self Custody Without Compromise

Crypto Breaking News

Jul 26

Ledger's objective has always been to deliver uncompromising security and usability to anyone exploring the world of digital assets. Of all the self-custody solutions to keep your private keys safe and accessible, our hardware devices are second to none.

When using a Ledger device, you are guaranteed that no one can interact with your private keys without your consent. Ever. Any interaction with the secrets held by your device will always require a manual action on your end: it's the core principle behind your hardware wallet's security.

But pure technical security is only part of the equation, and the user experience in crypto has much room for improvement. The first question every newcomer asks when going down the self-custody path and generating their Secret Recovery Phrase is: "What the heck do I do with these 24 words?".

While some people may memorize their Secret Recovery Phrase, I don't have this kind of trusting relationship with my brain. The standard advice so far has been to write them down on a piece of paper or in a metal store, and to keep it in a secure location. These options are not ideal, and make it harder to increase crypto-adoption.

In order to make self-custody more easily accessible, Ledger has brought forward a new answer: Ledger Recover.

In short, Ledger Recover is a self-custody solution to securely back up your Secret Recovery Phrase to the cloud, allowing you – and only you – to restore it to your hardware device in the future.

Reading this, your crypto-spidey senses should be tingling: Cloud and Secret Recovery Phrase backup don't usually go well together. But the reality is that a cloud backup can be a perfect solution, as long as it is well-designed and entirely secure.

There are several reasons why other cloud backups solutions have a bad reputation: the Secret Recovery Phrase is at some point unencrypted (whether on your computer, browser, or server), the backup is usually held by a single entity, and it's too easy to access it.

While designing Ledger Recover, we carefully considered these objections (and more) and succeeded in building the most secure solution for crypto users looking for a simpler yet robust personal OpSec.

Ledger Recover's flow: Maybe a bit much to take all at once

To understand its rather complex design, let's rebuild it together from scratch over the course of a few blog posts. Our starting point will be this simple idea:

I have a Secret Recovery Phrase on a bulletproof hardware wallet and would like to back it up online, without compromising security or control.

First, let's look at how you could do this yourself, moving away from having your Secret Recovery Phrase written on a piece of paper. Then, we'll dig a little deeper into how Ledger Recover does the same, or even better, online.

The Entropy, the Seed, and the Secret Recovery Phrase

In this blog post and various Ledger publications, we often mention the 'Secret Recovery Phrase', the 'seed' and the 'entropy', somewhat interchangeably.
While not being strictly equivalent, these three concepts are tightly linked, and their usage depends on the technical context.

Want to learn more about this? Ledger Academy has got you covered!

Splitting the Secret Recovery Phrase: A key way to keep control

The first thing you want to avoid is giving your entire Secret Recovery Phrase to any single entity, as secure or trustful as they might be. Once again, self-custody is critical for effective fund management, so giving your entire Secret Recovery Phrase to anyone is never acceptable. 

Any weakness in the system, whether human or machine, would compromise all your funds, or make you lose your backed-up Secret Recovery Phrase. This is why cloud backups have such a bad reputation in Web3, and why any standard cloud backup system is unsuitable for handling Secret Recovery Phrases.

The classic way to avoid this loss of control is to distribute the risk by splitting your Secret Recovery Phrase into multiple parts, also called shares or fragments. Each share is only a part of your secret, so they will need to be combined to obtain the original Secret Recovery Phrase. Individually, they are useless. Therefore, these shares can be given separately to different people such that no single entity can recombine the Secret Recovery Phrase.

If you need to recover your Secret Recovery Phrase – maybe because you've lost your hardware device and need to initialize a new one – you would ask each 'backup friend' for their share.

Now, what's the best way to split your Secret Recovery Phrase?

One option is to write your 24-words on a piece of paper, then cut it into three parts, for example, which are each given to different people to hold safely. In this setup, all three of your friends would have to collude to steal your hard-earned crypto.

The Secret Recovery Phrase split into three parts

This kind of naive split is easy to perform, but is far from ideal. While it does not readily submit control of your funds, each share reveals a big part of your Secret Recovery Phrase, which heavily reduces the difficulty of guessing the rest of it. The situation is even worse if any two of your backup friends collude because they have enough information to perform a brute-force attack to find the remaining part. Finally, if even a single one of your friends has genuinely lost their share, then the only way for you to recover it is to' brute-force it' yourself.

There is also a question of how the split is done: You don't want anyone eavesdropping while you process your most valuable secret. It must be done in a secure and safe environment.

How Ledger Recover does it: Shamir Secret Sharing

Luckily, in the case of digital secrets, cryptography has a better way of splitting than the method above in the form of the Shamir Secret Sharing scheme (abbreviated SSS later).

Using SSS to split your Secret Recovery Phrase guarantees that each share provides no extra information on the rest of the Secret Recovery Phrase. In other words, the difficulty of guessing the entire Secret Recovery Phrase remains the same whether you have prior knowledge of one of the shares or not.

On top of that, SSS easily supports m-of-n setups, which means you can generate n shares to be distributed but only need m shares to rebuild your Secret Recovery Phrase. In other words you can afford to lose some parts of your backup without impacting its restoring capabilities. This added redundancy is very important to create a resilient system.

In Ledger Recover, we have chosen to use a 2-of-3 scheme. It means at least two shares are required to rebuild the original Secret Recovery Phrase. In this way, no single backup provider has control of your secret, but the backup is resilient to the loss of one provider.

The initial three backup providers are:
– Coincover, a company based in the UK,
– EscrowTec, a company based in the US,
– And us, Ledger, based in France.

In the future, we also intend to have more backup providers to choose from. This will allow users to build the best setup for themselves.

You can find an excellent introduction to SSS here, but let us give you a feel of how it works for a simple 2-of-n scheme.

Using our elementary school math courses, we know that only one straight line goes through two distinct points, but an infinite number of straight lines go through a single point.

We'll be using this to generate the shares of your secret:

  • Let's say the secret is the value s
  • We then pick a random straight line that goes through the point (0,s)
  • We can define the n shares as the points of the random line at indices {x=1, x=2, x=3, …, x=n} 
Share generation in Shamir Secret Sharing scheme

Now, if you have any two shares, you can easily reconstruct the only straight line that goes through them. You will have retrieved your initial secret by intersecting this line with the y-axis (x=0).

But if you only have a single share, an infinite number of straight lines go through it, so the secret could be any number, and guessing the right line is as difficult as guessing the secret in the first place!

Pedersen Verifiable Secret Sharing

In this blog post and various Ledger publications, we often mention the 'Secret Recovery Phrase', the 'seed' and the 'entropy', somewhat interchangeably.
While not being strictly equivalent, these three concepts are tightly linked, and their usage depends on the technical context.

Want to learn more about this? Ledger Academy has got you covered!

As mentioned before, this cryptographic process needs to be done in a protected environment so no part of the secret is ever revealed to potential attackers. When using Ledger hardware wallets, the share computation is entirely done inside the Secure Element, under the strict control of the user pin code. This ensures that no external software or machine can ever access the Secret Recovery Phrase during the backup process. More on this in the next blog posts of the series!

Ok, let's back up a bit

We've learned that when designing a backup, it is good practice to split your secret into multiple shares and distribute them to different backup providers (friends, trusted entities, etc.). This is compatible with self-custody, as you remain the only person able to retrieve the entire seed phrase without depending on third-party approval to use your funds. However, the split scheme cannot be left to chance, as it can drastically reduce your overall security if chosen incorrectly.

Thanks to a 2-of-3 setup using Pedersen Verifiable Secret Sharing scheme, we have made Ledger Recover more resilient to backup provider failures. By performing the share split entirely inside your hardware wallet's Secure Element, the user's Secret Recovery Phrase is not vulnerable to malicious parties. In addition, we can safely verify that backups are correctly generated, which is crucial if we want to restore them in the future!

Now it's time for Part 2 to address the next elephant in the room: How can you securely generate and distribute the shares over an open network, without compromising your Secret Recovery Phrase?

Source: Ledger.com


Unsubscribe to no longer receive posts from Crypto Breaking News.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://www.cryptobreaking.com/part-1-genesis-of-ledger-recover-self-custody-without-compromise/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at July 25, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

A warning from the future

Download The Nerve's new report, 'First 100 days of Trump 2.0: Narrative warfare and the breakdown of reality'   26 January 2026...

  • [New post] Achieve Data Sovereignty through Omnisphere
    Crypto Breaking News posted: "Web 3.0 is one of the biggest buzzwords flying around the world of social media this year. An...
  • [New post] Tuesday’s politics thread is trying to stay positive.
    SheleetaHam posted: " Even though I just finished the latest Opening Arguments podcast about how Roe v. Wade is toast, and ...
  • [New post] Is XRP going to take the Crypto market by storm
    admin posted: "Is XRP going to take the Crypto market by storm While the SEC has been going after Ripple in court the XRP b...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • January 2026 (7)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.