Core Architectural Matrix

Hierarchical Key Management Framework

An open, battle-tested classification model and operational standard for managing cryptographic access credentials, signing keys, and validator stakes in the Dime ecosystem.

Security Lifecycle

The 5 Stages of Key Lifecycle Governance

Cryptographic custody requires disciplined procedural controls across all operational stages. Our framework provides strict guidelines for generation entropy, secure key derivation, threshold authorization, periodic rotation, and secure decommissioning.

Hierarchical Key Management and Security Lifecycle Framework
Operational Taxonomy

Key Classification & Storage Matrix

Compare threat vectors, operational constraints, and recommended physical controls across all four tiers.

Tier LevelPrimary Use CaseStorage MechanismSigning MechanismDisaster Recovery
Tier 1: Ephemeral HotDaily testnet transactions, micro-relays, automated botsEncrypted local keystore, memory-only daemonSoftware API automated signersRegenerated from root derivation path
Tier 2: Hardware AirgapIndividual operational custody, treasury operator accessDedicated secure element hardware wallet (Ledger, Trezor, Keystone)Manual physical confirmation / QR code optical airgap24-word BIP-39 mnemonic engraved on 316-grade stainless steel plate
Tier 3: Multi-Sig QuorumProtocol governance, project treasuries, validator upgrade keysDistributed M-of-N hardware signing keys held by distinct keyholdersThreshold signature scheme (e.g. 3-of-5 or 4-of-7 quorum)Geographically dispersed independent backup sets with dual-custody verification
Tier 4: Deep Cold VaultMaster root keys, validator withdrawal credentials, long-term reservesAir-gapped HSMs or Shamir's Secret Sharing (SLIP-0039) steel platesMulti-party offline ceremony with biometric witness logSplit seed shards stored across multiple biometric bank safe deposit vaults

Key Generation Golden Rules

  • 1. True Entropy: Never generate seed phrases in browser tabs, web extensions, or internet-connected operating systems.
  • 2. Camera & Microphone Isolation: Perform key generation ceremonies in rooms without internet cameras, smart speakers, or recording devices.
  • 3. Never Digitize Seed Words: Never photograph, screenshot, print over wireless printers, or store seed phrases in cloud notes.
  • 4. Stainless Steel Stamping: Store backups on fireproof, floodproof stainless steel plates rather than paper notebooks.

Validator Key Separation Principles

  • 1. Consensus Signer vs. Withdrawal Key: Keep high-frequency block voting keys strictly isolated from capital withdrawal credentials.
  • 2. Remote Signer Daemons: Run validator signers on dedicated, hardened Linux hosts or HSMs behind strict firewall ingress rules.
  • 3. Slashing Protection Databases: Maintain atomic double-signing prevention databases across all validator failover instances.
  • 4. Controlled Key Rotation: Schedule simulated key migration drills quarterly without taking nodes offline.