UKey & Product Ecosystem
As the UKey official team, we always keep your Asset safety and correct operating practices Put it first. In the self-custody world of blockchain, absolute control of assets comes with equal security responsibilities.
In order to help users clearly understand and use UKey products correctly, This article will systematically elaborate on UKey's architecture design, core responsibilities, boundary demarcation, and security best practices from an official perspective.
1. UKey The three pillars and boundaries of responsibilities of the self-hosted system
UKey's self-hosted system consists of three irreplaceable parts with clear responsibilities: UKey Wallet, UKey Core with UKey Seed series of products.
Summarize it in the most concise sentence: Wallet is responsible for operation, Core is responsible for signing, and Seed is responsible for recovery.
1. Comparison table of core responsibilities of three products
product line | Core responsibilities | Whether to connect to the network | Whether to sign the transaction | Whether to use for recovery |
UKey Wallet | View accounts, prepare transactions, connect DApps, broadcast signed transactions | Yes | In hardware mode irresponsible Private key signature; signing can be done in the software environment in software mode | Ability to initiate supported import or restore processes |
UKey Core | Generate and protect private keys, display transaction information, confirm and complete signatures by users | Typically interacts indirectly via the client | Yes(in an isolated hardware environment) | Wallet can be rebuilt with correct recovery information |
UKey Seed (Card, Ring, Ti) | Save wallet recovery information offline | No | No | Yes |
Special tips: The above division of responsibilities is mainly based on UKey Wallet Hardware wallet mode for use with UKey Core. UKey Wallet At the same time, it supports independent software wallet mode. There are essential differences in the security boundaries of private keys in the two modes.
2. In-depth analysis: functions and security boundaries of each component
1. UKey Wallet: Account and network operation interface
UKey Wallet is the software client you come into contact with most every day. Its essence is an "operation console".
Main functions:View addresses and balances, enter transaction information, build requests to be signed, connect to Web3 services, broadcast signed transactions and manage device connections.
Security awareness: In hardware wallet mode, it is only responsible for organizing information and network communication. Critical private key signing must be done within the hardware security boundaries of the UKey Core.Never make decisions solely based on the transaction page on your computer or mobile phone screen, always check the hardware screen before signing.
Software wallet mode tips:
UKey Wallet can be used as an independent software wallet. At this time, the private key is saved in the software running environment such as mobile phone or computer. Although it is more convenient, its security boundary depends on the system security of your terminal device. Never mistake a software wallet account as automatically receiving the physical protection of a hardware wallet.
2. UKey Core: Private key boundary and signature device
UKey Core is your hardware wallet and transaction confirmation core, responsible for three key responsibilities:
Generate and protect private keys:The private key is generated and stored permanently within the device's secure chip environment, never leaving the device. The blockchain assets themselves are recorded on the chain and are not stored in a hardware shell.
Display transaction information independently: After the device receives the data to be signed, it will Separate physical screenParse and display the core content of the transaction. Users must rely on what is displayed on their device's screen, rather than blindly trusting an internet-connected phone or computer interface.
Execute signature after user confirmation:Only after the user physically presses the device confirmation key, UKey Core will call the internal private key to complete the signature and return the signature result to the client (rather than exporting the private key).
3. UKey Seed: Offline backup media for recovery information
Seed series products are designed for backup and recovery and are not involved in daily transactions:
Description of form: Includes NFC backup card (UKey Seed Card), wearable NFC backup media (UKey Seed Ring) and titanium physical backup plates for extreme durability and long-term storage (UKey Seed Ti).
Security awareness:Seed products do not connect to the network, initiate on-chain transactions, or perform private key signatures. It is your only physical path to reestablishing access to your wallet if your device is lost or damaged.
3. A complete closed loop of a hardware wallet transaction
In the standard hardware wallet mode, the flow process of an on-chain transaction is as follows:
Initiate:The user selects the account in UKey Wallet and enters transaction parameters.
Build:UKey Wallet constructs the transaction to be signed and sends it to UKey Core.
Analysis and display:UKey Core parses the transaction and displays key information (such as payment address, amount, network, etc.) on its physical screen.
Check:Users personally check various parameters on the device.
Signature:After the user confirms that it is correct on the UKey Core, the device completes the signing in the hardware security environment.
Return:UKey Core safely returns the signing result to UKey Wallet.
Broadcast:UKey Wallet Broadcast signed transactions to the blockchain network.
Note: Seed backup product does not intervene in this daily process.
4. Core Principles: Why can't the three be substituted for each other?
UKey Wallet $\neq$ UKey Core:The client cannot replace signing hardware with physical isolation capabilities. The security levels of software mode and hardware mode cannot be confused.
UKey Core $\neq$ Seed backup:Hardware devices present a physical risk of being lost, damaged, or reset. Having only one hardware device without offline backup still faces a single point of failure.
Seed product $\neq$ signature device:Backup media is for recovery only and cannot be used for day-to-day viewing of balances, constructing transactions, or direct signing.
5. Equipment loss and asset security guidelines
Crypto assets are always securely recorded on the blockchain distributed Ledger. The loss of hardware equipment does not mean the disappearance of assets on the chain.
How to recover:As long as you have correct, complete, and compatible recovery information (such as a mnemonic phrase/backup card data), you can regain access to your wallet on a supported, compatible hardware environment.
Red line warning (safety instructions):
NeverDisclose the mnemonic phrase or recovery information to anyone (including UKey official customer service).
NeverTake a photo, screenshot or upload the mnemonic phrase to any cloud storage.
NeverStore recovery information permanently in the same physical location as the device PIN or additional passwords.
When restoring your wallet, please prioritize doing so in a trusted and secure hardware environment. Importing hardware mnemonic phrases into networked software wallets will completely change the original security boundary.
Before resetting any hardware device,Must be confirmed repeatedlyRestore backup integrity and availability.
Conclusion
UKey The official team is always committed to providing you with safe and reliable self-hosted tools. keep in mind "Wallet checks accounts, Core signs transactions, and Seed makes backups. " division of responsibilities, carefully check each equipment prompt, and Always go through UKey official channels Obtaining software downloads and technical support is the best practice to protect the security of your digital assets.
