Skip to main content

Securing digital assets in AWS Nitro Enclaves with Fireblocks MPC Cosigner

Learn how Fireblocks uses AWS confidential computing capabilities to help secure its customers’ sensitive financial operations.

Benefits

(approximately) of MPC cosigner customers using AWS
50%
increase in confidential computing code commits
2x

Overview

Managing high volumes of digital asset transactions for over 2,400 enterprise customers, Fireblocks wanted to expand its confidential computing options for workloads that handle highly sensitive data. Fireblocks built multiparty computation (MPC) cosigners to secure customers’ digital wallets, and then worked alongside Amazon Web Services (AWS) to make the technology simpler for customers to deploy and engineers to maintain. Now, half of Fireblocks’ MPC cosigner customers use the solution on AWS.

 

About Fireblocks

Fireblocks is a digital asset infrastructure company that empowers organizations to build, manage, and grow their businesses on the blockchain. The secure platform powers institutional finance and consumer-facing digital experiences.

Opportunity | Using MPC technology to secure workloads for Fireblocks

The digital asset and crypto custody industry faces a fundamental tension between security and usability when managing cryptographic keys. The security of such keys is critical because they unlock billions of dollars in digital assets for customers. Proven approaches like hardware security modules and cold storage, although effective, can be operationally complex and difficult to scale for customers that need responsive, production-ready transaction signing within their existing cloud environments.

Fireblocks, an AWS Partner, identified virtual machine-level isolation as a strong and efficient implementation for customers. To implement this change and extend its toolset and techniques to secure high-sensitivity workloads, the company created infrastructure around AWS Nitro Enclaves, which made it possible for Fireblocks to create isolated compute environments for internal use. This powers products like the Nitro MPC Cosigner, which adds a layer of security to digital wallets by splitting private keys into multiple key shards. Fireblocks wanted more customers to be able to access its MPC cosigner easily, and it also wanted an easier on-ramp for its engineering teams to build with confidential computing. Both goals pointed to the same solution: AWS Nitro Enclaves.

Solution | Securing critical data using AWS Nitro Enclaves

Fireblocks has long worked alongside AWS to help build and maintain its digital asset architecture. Many of the company’s customers also run on AWS, and internal engineers are familiar with using AWS products.

Fireblocks worked closely alongside AWS confidential computing specialists to architect the solution. “The AWS team helped us stress test the architecture against our threat model,” says Ben Liderman, system architect at Fireblocks, who led the Fireblocks transition to AWS Nitro Enclaves. “That kind of technical depth gives us confidence.”

Fireblocks uses MPC algorithms to generate key shards, with two held in Fireblocks servers—called cosigners—and one by the customer. The parties can then collectively sign transactions without reconstructing the full private key in one place.

AWS Nitro Enclaves provides an isolated, hardened, and highly constrained environment for Fireblocks to process its security-critical data. It uses cryptographic attestation documents that are signed by the Nitro Hypervisor to verify that the request is coming from approved Fireblocks code running in a valid enclave.

In addition, Fireblocks’ solution integrates AWS Nitro Enclaves with AWS Key Management Service (AWS KMS), which encrypts data across the company’s AWS workloads and applications. The cloud-based system is designed to prevent access to AWS Nitro Enclave workloads’ plaintext secrets, including by the most privileged AWS administrators. AWS KMS can verify AWS Nitro Enclaves attestation and help restrict decrypt permissions to approved Fireblocks workloads running in trusted enclaves.

Outcome | Expanding confidential computing to developers

Since launch, Fireblocks’ AWS-run MPC cosigner has seen strong adoption, with approximately 50 percent of cosigner customers using the AWS Nitro Enclaves–based solution. Along with improved security for their transactions, customers can operate Fireblocks cosigners in their own AWS environments.

Meanwhile, most of Fireblocks’ developers now have the ability to contribute to confidential computing. The number of developers who committed code to confidential computing–based services has increased by two to three times. “The entire engineering organization can contribute code to such sensitive services. They don’t need to know C++ or specialize in low-level details such as communication with the operating system,” says Liderman.

Using AWS Nitro Enclaves as a primary confidential computing solution, Fireblocks expects to migrate additional internal confidential compute workloads to the service in the future, helping further protect customers’ data and improve the efficiency with which they can access it. “In financial infrastructure, downtime means customers can’t move funds when they need to,” says Liderman. “Using AWS Nitro Enclaves has helped us reduce that downtime and build a more resilient platform for our customers.”

An architecture diagram detailing Fireblocks’ MPC wallet solution

An architecture diagram depicting a Fireblocks’ MPC cosigner implementation

Missing alt text value
In financial infrastructure, downtime means customers can’t move funds when they need to. Using AWS Nitro Enclaves has helped us reduce that downtime and build a more resilient platform for our customers.

Ben Liderman

System Architect, Fireblocks

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages