AI 中文总结
本文对加密资产托管与金融技术中的加密密钥恢复相关研究进行知识体系梳理,构建分类框架与通用模型,揭示恢复语义异质性等六项研究缺口,为相关技术研究提供方向。
AI 中文摘要
加密资产系统通常将加密密钥控制权与金融控制权绑定:丢失钱包种子、托管份额、硬件设备或智能账户凭证会丧失支出权限,而受损的恢复机制则可能导致盗窃。现有研究通过不同术语处理恢复——密钥备份、秘密共享、账户恢复、凭证重新发行、社交恢复和资产迁移——使得机制和权衡难以比较。本文提出一项针对加密资产托管与金融技术中加密密钥恢复的知识体系(Systematization of Knowledge, SoK)。从包含118篇论文的系统综述发现语料库出发,我们衍生出包含77篇论文的综合语料库,并在主矩阵中对每篇保留的系统进行编码,涵盖恢复对象、恢复语义、机制、注册与存储、授权、信任放置、故障事件、恢复后状态、验证证据、部署状态、隐私、可用性及局限性。该矩阵支持以轴为基础的分类,将恢复分为秘密恢复型、混合型、控制恢复型、取证/提取型及框架导向型。我们的核心观察是恢复并非单一操作:系统可重构原始秘密、重新生成种子、恢复份额、重新发行凭证、迁移签名权限、恢复账户控制权、转移资产或提取取证工件。我们推导了通用构建模型,将其与面向生产的设计进行比对,并确定六项发现:恢复语义具有异质性;恢复会转移信任;可用性提升会产生滥用路径;恢复后生命周期管理不均衡;协议证据领先于用户证据;恢复元数据保护不足。这些缺口为面向恢复感知的金融技术研究议程提供了动力。
英文摘要
Cryptoasset systems often bind cryptographic key control to financial control: losing a wallet seed, custody share, hardware device, or smart-account credential can remove spend authority, while compromised recovery can enable theft. Existing work treats recovery through separate vocabularies--key backup, secret sharing, account recovery, credential re-issuance, social recovery, and asset migration--making mechanisms and tradeoffs difficult to compare. This paper presents a Systematization of Knowledge (SoK) on cryptographic key recovery for cryptoasset custody and financial technologies. Starting from a 118-paper systematic-review discovery corpus, we derive a 77-paper synthesis corpus and code each retained system in a master matrix covering recovered objects, recovery semantics, mechanisms, enrollment and storage, authorization, trust placement, failure events, post-recovery state, validation evidence, deployment status, privacy, usability, and limitations. The matrix supports an axis-first taxonomy that separates secret-restoring, hybrid, control-restoring, forensic/extractive, and framework-oriented recovery. Our central observation is that recovery is not a single operation: systems may reconstruct an original secret, regenerate a seed, restore a share, reissue a credential, migrate signing authority, restore account control, move assets, or extract forensic artifacts. We derive a generalized construction model, check it against production-facing designs, and identify six findings: recovery semantics are heterogeneous; recovery shifts trust; liveness improvements create abuse paths; post-recovery lifecycle management is uneven; protocol evidence outpaces user evidence; and recovery metadata remains underprotected. These gaps motivate a research agenda for recovery-aware financial technologies.
Comments72 pages, 2 figures, 18 tables. Full version of the paper accepted at the International Conference on Advances in Financial Technologies (AFT 2026). Includes the complete 77-system master matrix and seven-stage recovery walkthroughs. Reproducibility package: https://github.com/franciscobecerra97/Cryptographic-Key-Recovery-for-Financial-Technologies/tree/aft-2026-artifacts