IBM Unveils Air-Gapped Cold Storage Solution for Digital Assets

In a landmark move toward fortifying the security of digital assets, IBM has unveiled the IBM Hyper Protect Offline Signing Orchestrator (OSO), an innovative air-gapped cold storage solution. Launched on December 5, this collaborative effort between IBM, digital asset manager Metaco, and tier-1 banks seeks to overcome common vulnerabilities inherent in traditional cold storage solutions.

Traditional offline or air-gapped cold storage solutions often grapple with limitations such as privileged administrator access, operational costs, errors, and challenges related to scalability—all linked to human interaction. IBM OSO has been meticulously designed to tackle these vulnerabilities by streamlining and automating processes, eliminating the potential for human error.


Taking inspiration from the concept of a time-release safe for physical assets, OSO introduces a novel approach to transaction authorization. Transactions from cold storage to the blockchain, and vice versa, can only occur at predefined times or through the approval of a multibody governance scheme. This strategic configuration significantly reduces the risk of insider attacks, including those involving physical access, administrative manipulation, or coercion.


A noteworthy feature of OSO is its configuration, which mandates a potential bad actor to wait until approved transaction times for execution. This deliberate delay adds a layer of security, diminishing the likelihood of unauthorized access and providing robust protection against theft or other malicious activities.

OSO further strengthens its resilience against potential breaches by allowing digital assets to be stored in “air-gapped” containers. This state of air-gapped storage, where the storage is not connected to the internet or any device capable of connecting to the internet, ensures that assets remain secure and impervious to remote attacks while at rest.

Unlike traditional air-gapped paradigms that often involve manual processes susceptible to human error, OSO introduces a policy engine. This engine facilitates communication between two different applications without simultaneous connection to both, mitigating the risk of non-malicious errors that can be as detrimental as intentional exploits. Furthermore, OSO operates through a virtual, partitioned server via IBM’s Confidential Computing service, eliminating direct external network connectivity and fortifying the system against remote access during transactions.


IBM’s Hyper Protect Offline Signing Orchestrator marks a significant advancement in securing digital assets by addressing the inherent vulnerabilities in traditional cold storage solutions. By incorporating cutting-edge technologies and innovative concepts, OSO sets a new standard in the landscape of cold storage for digital assets. As blockchain technology continues to evolve, solutions like OSO become increasingly vital, ensuring the integrity and security of digital transactions within the rapidly changing financial landscape. This groundbreaking development from IBM paves the way for a more secure and resilient future for the handling of digital assets.

