The Cryptnox Shamir cards set splits a single high-value secret — a Bitcoin treasury key, an HSM wrapping key, a master recovery seed — across a set of tamper-resistant smart cards using Shamir’s Secret Sharing. Any k of the n cards reconstruct it; fewer reveal nothing at all. No single card, and no single person, ever holds the secret.
Any k of n cards rebuild the secret; k−1 reveal nothing — a mathematical guarantee, not just computational hardness.
The seed is generated, split, and reconstructed inside the orchestrator card. The host computer only relays encrypted data.
Every share lives inside a PIN-protected, Swiss-made smart card. Three wrong PIN attempts lock the card.
Protected by granted patents US 11,791,996 B2, US 12,101,400 B2 and US 12,132,824 B2.
Performs all cryptography: generates the seed, splits it into shares, and reconstructs it during recovery. Holds no share at rest — one per set.
Each securely stores exactly one encrypted share behind a PIN. Two to twelve per set, distributed across custodians and locations.
Resets a forgotten storage-card PIN under its own PIN, so personnel changes never force a full recovery.
A one-time guided event generates the seed, splits it, and writes the shares to the storage cards — then the cards go into safes.
Periodically prove every share still reconstructs the seed — without the seed ever leaving the cards.
Gather k storage cards, rebuild the seed inside the orchestrator, and re-wrap it for the recipient — a new HSM, AWS KMS, or a Cryptnox Hardware Wallet card.
The live key stays in your HSM or in a cloud KMS such as AWS KMS. The Shamir cards are its offline, geographically distributed backup: whenever the seed leaves the orchestrator it is wrapped (encrypted) with a public key provided by the recipient — your HSM, AWS KMS, or a Cryptnox Hardware Wallet card — so the ceremony host can never read it. If the key is lost, k cards restore the seed to a new HSM, back into AWS KMS, or straight onto a Cryptnox Hardware Wallet card.
From 2-of-3 for a small treasury to 4-of-7 spread across sites: a larger n adds redundancy against loss, a larger k raises the bar an attacker must clear. Set the quorum so that no single person or site can ever assemble k cards.
Every real share read during a recovery increments a non-volatile counter inside the card. A count higher than your custody log expects means a share was read outside a sanctioned recovery — and routine backup tests never touch it.
An orchestrator only accepts storage cards provisioned into its own set and rejects any outside card — no rogue card can be slipped into a ceremony or recovery.
Per-card PINs protect every share. The admin card restores access when a PIN is forgotten — under its own PIN, with a hard lock after too many attempts.
A guided command-line tool walks your operators card by card through ceremony, backup test, and recovery — every step in a fixed, auditable order.
Printable checklists and custody-log templates keep the k-of-n scheme, share numbers, and sign-offs off the cards and in your records.
One storage card without its PIN: nothing — the share inside is encrypted and PIN-gated.
One card with its PIN: a single share, useless on its own.
Even k−1 cards with every PIN: still nothing about the secret. That is Shamir’s guarantee.
FAQ
One orchestrator card, two to twelve storage cards — you choose the total n and the threshold k — plus an admin card for PIN recovery. Sets are delivered provisioned and matched: the orchestrator rejects any card that does not belong to its set.
A Bitcoin (secp256k1) private key, NIST P-256, P-384 or P-521 keys, or any random secret from 16 to 128 bytes — such as an HSM wrapping key, AWS KMS key material, or an AES master key.
No. The seed is generated, split, and reconstructed inside the orchestrator card. Shares travel card-to-card over an encrypted channel, and the seed only ever leaves the set wrapped with a public key provided by the recipient — your HSM, AWS KMS, or a Cryptnox Hardware Wallet card.
No — by design. The Shamir applets operate over the contact interface only and reject contactless connections; any standard PC/SC contact smart card reader works.
Yes. The system builds on granted patents US 11,791,996 B2 — Shamir Secret Sharing Key Generation, US 12,101,400 B2 — Secure Key Injection & Recovery and US 12,132,824 B2 — Seedless Wallet Initialization. See all Cryptnox patented technology.
Corporate Bitcoin treasuries protecting cold-storage keys. Funds and exchanges that need quorum-based control over a master key. Any organisation with a “no single person can move the funds” requirement. Sets are delivered pre-provisioned and work with any standard PC/SC contact smart card reader.