High-anonymity and high-security fixed-denomination stable currency card system and method
By issuing fixed-denomination stablecoin cards through diversified institutions, integrating quantum-resistant hybrid encryption and self-service management, the security and user experience issues of digital currency cards in a quantum computing environment are solved, enabling efficient cross-chain asset transfer and self-service recovery, thereby improving system security and user experience.
Patent Information
- Application Number
- CN202511380938.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2026-01-30
AI Technical Summary
Existing digital currency cards are vulnerable to security issues in the face of the global growth in quantum computing capabilities. They are prone to private key leakage, have poor user experience, lack convenient self-service recovery mechanisms, face difficulties in cross-chain asset transfer, have inefficient integration of traditional finance and digital currency, and lack physical carriers for stablecoins with fixed denominations.
It adopts stablecoin cards with fixed face value issued by diversified institutions, integrates contactless high-security hardware modules, uses quantum-resistant hybrid encryption algorithms, supports dynamic generation and storage of private keys, provides self-service management throughout the card's life cycle, generates a unique master private key through a multi-factor key derivation algorithm, and supports online face value top-up and self-service balance migration.
It achieves high security against quantum attacks, enables users to conduct transactions and recover data independently, improves business continuity and data security management efficiency, reduces the risk of data leakage, and enhances the overall security and resource utilization of the system.
Smart Images

Figure CN121436985A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of stable coin management, blockchain technology and data encryption technology, in particular to a highly anonymous and highly secure fixed denomination stable coin card system and method thereof, and especially focuses on the deep integration of financial institutions, digital asset service providers and large payment service institutions with stable coin applications, which are issued in the form of fixed denomination cards, combining the convenience of traditional prepaid cards, the advantages of blockchain assets and the scalability for the future. BACKGROUND
[0002] With the rapid development of blockchain technology and digital currency, stable coins have become a key bridge connecting traditional finance and digital economy, and their application scenarios are becoming increasingly widespread, especially in the micro-payment scenarios that pursue transaction anonymity, convenience and fixed denomination payments.
[0003] However, existing digital asset management and decentralized transactions still face a series of deep problems to be solved: 1. Security and quantum threat: Traditional encryption algorithms face potential vulnerability in the context of rapid global quantum computing power growth, which may lead to large-scale private key leakage and asset loss. Existing digital currency cards generally lack sufficient consideration and defense mechanisms for post-quantum era threats in terms of private key storage and encryption.
[0004] 2. User experience and ease of use: Existing digital currency cards have limited capabilities in directly supporting decentralized transactions, and users still need to rely on complex software wallet operations to participate in DeFi ecosystems. Private key management, backup and card recovery mechanisms have high barriers for non-professionals, and there is generally a lack of convenient, secure and user-friendly innovative solutions, especially a lack of intuitive payment experience and completely self-service recovery path in highly anonymous scenarios.
[0005] 3. Disconnection with traditional finance and inefficient fund transfer: Although existing digital currency cards enable convenient conversion of digital assets to fiat currency, they still lack a smart and low-cost fund bridging mechanism that closely integrates with diversified issuer fund sources to support decentralized transactions with efficient, automatic and on-chain stable coins. In addition, there is a lack of physical carriers for fixed denomination stable coins on the market, which affects their promotion in certain consumption scenarios.
[0006] 4. Interoperability and ecological fragmentation: The fragmentation of the blockchain ecosystem makes cross-chain asset transfer difficult, and there is a lack of a unified and secure solution that can support on-chain native transactions of stable coins, brand issuance by diversified institutions, and effectively address the needs of cross-chain and complex smart contract interactions.
[0007] Therefore, although there are digital currency hardware wallet cards in the existing technology, there is still no comprehensive solution that can fully integrate quantum security, direct card interaction, highly anonymous payment, fully self-service recovery mode for users, and fixed-denomination stablecoin cards with face value recharge provided by the issuing institution. Summary of the Invention
[0008] To address the various shortcomings of existing technologies, this invention provides a highly anonymous and secure fixed-denomination stablecoin card system and method, which can achieve secure storage of stablecoins, convenient and efficient highly anonymous decentralized transactions, and provide a card lifecycle security recovery mechanism based on card information and user self-operation, with face value top-ups by the issuing institution.
[0009] The present invention achieves the above objectives through the following technical solutions: A highly anonymous and secure fixed-denomination stablecoin card system includes: The fixed-denomination stablecoin card issued by diversified institutions integrates a contactless high-security hardware module. The hardware module is an embedded hardware security module or security element that meets international high-security level certification. The quantum-resistant hybrid encryption algorithm module is used to perform hardware-level secure writing and storage of the user's stablecoin private key and associated distributed ledger address. The quantum-resistant hybrid encryption algorithm adopts a dual-envelope encryption mechanism. This mechanism first uses the SM4 algorithm to encrypt the stablecoin master private key, and then uses at least one PQC algorithm and the SM2 algorithm to serially encrypt and encapsulate the session key used for SM4 symmetric encryption. The private key generation and storage module dynamically generates and stores a unique stablecoin master private key within the secure element through a multi-factor key derivation algorithm. The multi-factors include at least the master seed key generated by a hardware random number generator, the session key randomly generated within the secure element, and the transaction password set by the user. The card lifecycle management module supports users to migrate their account balances independently without the need for the card issuer to intervene. It allows for instant reconstruction of the private key and migration of the old account balance to the new account through a local terminal application.
[0010] A method for implementing a highly anonymous and highly secure fixed-denomination stablecoin card system, comprising the following steps: Card production steps: The issuing institution selects a card manufacturer to produce the cards, and writes the issuing institution's proprietary application logic into the card's secure element. During this stage, no stablecoins are pre-charged into the card. Multi-level key generation and secure distribution steps: During the card production process, a high-entropy master seed key is generated using a hardware random number generator or a true random number generator; at the same time, the transaction password is randomly generated by the card's internal security element according to a preset algorithm; subsequently, the master seed key and the transaction password are encrypted and securely printed inside the signature envelope provided with the card through a coating, and provided to the user along with the card. Master private key generation steps: The security element inside the card uses a preset multi-factor key derivation algorithm to dynamically generate and store a unique stablecoin master private key within the security element; Information carrying steps: Complete the design of the card's physical characteristics and enable it to carry stablecoin account information and session key information; Encryption and Layered Storage Steps: The generated stablecoin master private key is encapsulated and encrypted in multiple layers using a quantum-resistant hybrid encryption algorithm before being written into the non-volatile persistent storage area of the card's security element.
[0011] Fixed denomination top-up steps: After the card is produced, the issuing institution tops up the stablecoin account printed on the card with a fixed amount of on-chain stablecoins according to the preset face value.
[0012] Purchase steps: Users purchase fixed-denomination stablecoin cards from the issuing institution or authorized resellers and verify the validity of the denomination through the app.
[0013] According to the present invention, a method for implementing a highly anonymous and highly secure fixed-denomination stablecoin card system includes the following implementation methods for the multi-factor key derivation algorithm in the master private key generation step: Master Seed Key Acquisition: During the card production process, a high-entropy master seed key is generated using a hardware random number generator or a true random number generator. This master seed key is encrypted and securely printed inside the signature envelope provided with the card by means of a coating. After the user receives the card, the master seed key is obtained from the envelope and decrypted according to the specified security process, which serves as the first key input to the multi-factor key derivation algorithm. Session key generation and delivery: The security element inside the card generates a one-time session key based on a random number generation algorithm after the card is manufactured but before it is delivered to the user. This session key is printed on a hidden area of the card surface using laser engraving technology and covered with multiple layers of special coating. The obtained session key serves as the second key input to the multi-factor key derivation algorithm. Transaction password generation and distribution: During card production, the internal security element of the card randomly generates a transaction password according to a preset algorithm. This transaction password is also encrypted and securely printed inside the signature envelope provided with the card through a coating. It is provided to the user along with the master seed key. After the user decrypts and obtains the transaction password, it serves as the third key input to the multi-factor key derivation algorithm.
[0014] The present invention provides a method for implementing a highly anonymous and highly secure fixed-denomination stablecoin card system, wherein the execution of a multi-factor key derivation algorithm includes: Within the secure area of the secure element, the obtained master seed key, session key, and transaction password are used as input parameters and fed into a multi-factor key derivation algorithm. This algorithm is then used to perform multiple rounds of mixing and processing on the three key inputs. During algorithm execution, the master seed key is first hashed to generate a fixed-length hash value. Then, the session key is XORed with the hash value to obtain an intermediate result. Next, the transaction password is concatenated with the intermediate result, and the concatenated data is encrypted using a symmetric encryption algorithm to generate an encrypted data block. The encrypted data block is then subjected to multiple hash operations and bit operations. Finally, by filtering and extracting the data after multiple rounds of calculations and processing, a unique stablecoin master private key is generated.
[0015] The present invention provides a method for implementing a highly anonymous and highly secure fixed-denomination stablecoin card system, the design of which includes the physical characteristics of the card: The card body can be equipped with an integrated micro keyboard, which adopts a 4×4 or 5×3 matrix key layout; at the same time, the keys have an anti-accidental touch design, which prevents users from accidentally touching the keys and causing unnecessary operations during daily carrying or operation by setting the key spacing and key pressure threshold. The card is optionally equipped with an integrated small display screen. The card is powered through a contactless interface and uses NFC inductive power generation technology. When the card is close to an NFC-enabled card reader, it can obtain power from the electromagnetic field emitted by the device to provide power for the micro keyboard, small display screen and internal security components on the card.
[0016] According to the present invention, a method for implementing a highly anonymous and secure fixed-denomination stablecoin card system is provided. During the account derivation process, the security element inside the card generates a corresponding unique stablecoin account based on the pre-derived stablecoin master private key, using a hash algorithm and blockchain address generation rules. This stablecoin account serves as a blockchain address for storing and trading stablecoins in the blockchain network.
[0017] The present invention provides a method for implementing a highly anonymous and secure fixed-denomination stablecoin card system. The quantum-resistant hybrid encryption algorithm employs a dual-envelope encryption method to securely encrypt and store the stablecoin master private key, comprising the following steps: Session key generation: Inside the stablecoin card chip, a hardware random number generator is used to generate a session key for SM4 symmetric encryption. After the session key is generated, it is stored only in the secure storage area inside the chip. Access to the key is strictly restricted by the chip's internal access control mechanism to prevent unauthorized reading and tampering. Stablecoin master private key encryption: Using the generated session key, the stablecoin master private key is encrypted using the SM4 algorithm. The SM4 algorithm employs a 32-round non-linear iterative structure, transforming the stablecoin master private key into ciphertext through a series of round function transformations, generating the SM4-encrypted master private key ciphertext. Session key double encryption encapsulation: Select at least one PQC algorithm for session key encapsulation encryption, and use the selected PQC algorithm to encapsulate and encrypt the session key used by the SM4 algorithm.
[0018] The present invention provides a method for implementing a highly anonymous and highly secure fixed-denomination stablecoin card system, which, after encapsulating and encrypting the session key using the PQC algorithm, further encapsulates and encrypts it again using the SM2 algorithm, including the following steps: SM2 key pair generation: Inside the stablecoin card chip, a hardware random number generator is used again to randomly generate a key pair of the SM2 algorithm, including a public key and a private key, and the key pair is stored in the secure storage area inside the chip. Secondary encapsulation encryption operation: The generated SM2 public key is used to encapsulate and encrypt the session key after it has been encapsulated and encrypted by the PQC algorithm. The SM2 algorithm is based on elliptic curve cryptography and uses an asymmetric encryption method. It further encrypts the session key after it has been encapsulated by the PQC algorithm through operations such as dot multiplication on the elliptic curve and hash function, generating the final double-encapsulated session key ciphertext. Ciphertext storage: The master private key ciphertext encrypted with the SM4 algorithm and the session key ciphertext encapsulated by the PQC algorithm and the SM2 algorithm respectively are persistently stored in the non-volatile storage medium of the stablecoin card.
[0019] The present invention provides a method for implementing a highly anonymous and highly secure fixed-denomination stablecoin card system, which further includes highly anonymous transaction initiation and card security authentication, comprising the following steps: Device touch and communication channel establishment: When the stablecoin card is touched to a smart terminal device that supports NFC, the stablecoin card and the smart terminal device establish a secure and low-power communication channel according to the NFC data exchange format protocol that conforms to the ISO / IEC 14443 standard. Transaction Request Parsing and Data Packet Transmission: The application running on the smart terminal device intelligently parses the on-chain transaction requests initiated by the user, and converts the parsed transaction requests into structured signature intent data packets. Then, the signature intent data packets are transmitted to the stablecoin card through an established secure channel. After receiving the signature intent data packets, the stablecoin card displays a transaction password input prompt to the user through a small display screen that is optionally integrated on the card. If the card is not equipped with a display screen, the user is prompted to enter the transaction password through the application interface of the smart terminal device. Local password verification: Enter the preset transaction password on the card body, and the terminal application will encrypt and transmit the password to the card. The security element inside the card uses a hash algorithm to perform a hash operation on the transaction password entered by the user, and compares the result with the password hash value pre-stored in the security element. Offline signing of on-chain transactions: After local password verification, the card security element performs offline signing of transaction data in a completely isolated and physically tamper-proof environment. Transaction Broadcasting and Atomic Execution: Signed and verified transaction data is securely returned to the terminal application via the NFC channel. The terminal application or a decentralized relay network then broadcasts the transaction to the corresponding blockchain network to achieve on-chain atomic transfer or consumption of stablecoins.
[0020] The present invention provides a method for implementing a highly anonymous and secure fixed-denomination stablecoin card system, which further includes fully self-service transfer of stablecoin account balances, specifically comprising the following steps: User self-service application submission and information retrieval steps: If a stablecoin card is damaged or lost, the user must scratch off the coating inside the delivery envelope provided with the card. The original master seed key and transaction password can be obtained from the scratched-off area. Simultaneously, the stablecoin account and session key can be obtained from the printed area on the old card. The stablecoin account is the unique account identifier corresponding to this card on the blockchain network. Self-service recovery and balance migration via terminal application: In the selected terminal application, the user manually enters the old card's stablecoin account, session key, master seed key, transaction password, and the receiving ID of the new card or other on-chain address specified by the user, i.e., the target receiving address; the terminal application uses the same multi-factor key derivation algorithm as inside the card to instantly reconstruct the stablecoin private key corresponding to the old card locally; Steps for atomic balance retrieval, secure transfer, and old card cancellation: The reconstructed stablecoin private key is used only for one-time authorized transactions. The terminal application uses the reconstructed private key to generate a transaction signature and initiates a request to the blockchain network to securely and atomically obtain all stablecoin balances from the on-chain address associated with the old card. The system then atomically transfers the obtained stablecoin balances to the new on-chain address associated with the user's newly issued stablecoin card through a secure on-chain transaction. After the transfer operation is completed, the original card and its associated original private key account are permanently cancelled and invalidated at the logical level.
[0021] Therefore, compared with the prior art, the highly anonymous and highly secure fixed-denomination stablecoin card system and method proposed in this invention have the following beneficial effects: 1. This invention automates the entire process of "source data decryption - encryption upgrade - secure storage - anomaly monitoring" by processing data update tasks in parallel through distributed computing nodes. Compared to traditional solutions that require nighttime cutovers or partial encryption leading to business interruptions, this invention supports real-time secure upgrades of all data, ensuring continuous operation of business systems 24 / 7 with no user disruption, significantly improving business continuity and user experience.
[0022] 2. This invention overcomes the limitations of traditional solutions that can only encrypt partial fields or rely on offline upgrades, supporting online replacement of storage key versions and encryption algorithms (such as upgrading from AES-128 to SM4). Through automated batch key replacement and algorithm upgrades, it ensures that all data is always protected by the latest security standards, effectively resisting modern network attack methods and reducing the risk of data leakage.
[0023] 3. Traditional solutions require downtime maintenance or phased implementation during security upgrades, resulting in long security cycles and low efficiency. This invention eliminates the impact of security upgrades on business operations through real-time online encryption upgrades, while supporting full real-time processing of tens of millions of data points, significantly improving the efficiency and flexibility of data security management.
[0024] 4. This invention supports configuring independent and dedicated storage keys for distributed business nodes such as provincial banks and government systems, achieving strict physical isolation of "one key per node." Even if the key of one node is leaked, it will not affect the data security of other nodes, effectively avoiding the problem of "single point leakage leading to global risk" in traditional solutions, and significantly improving the overall security of the system. The same node can simultaneously call multiple types of storage keys to meet the security needs of different business modules. For example, sensitive data uses high-strength encryption keys, while public data uses regular keys. This differentiated storage management mechanism enhances data security while reducing management complexity and improving resource utilization.
[0025] 5. This invention constructs a multi-module collaborative system, including a key management module, a data refresh module, an encryption machine, and a data buffer module, through standardized interfaces. This achieves modular linkage of the entire process from "task scheduling to key invocation to data processing to anomaly feedback," simplifying system integration, improving fault location and handling efficiency, and ensuring the stability and reliability of the data update process.
[0026] 6. The data buffer module in this invention serves as an intermediate temporary storage area between the database and the system, employing a timestamp sorting mechanism to orderly store massive amounts of data. By scheduling data into the encryption / decryption process according to "acquisition order - processing priority," it avoids duplicate storage or chaos caused by concurrent processing, significantly improving the processing efficiency for security upgrades of tens of millions of data points. Traditional solutions directly operate on the database during data refresh, easily leading to excessive real-time read / write pressure and affecting the stability of the business system. This invention, by temporarily storing data to be processed through the data buffer module, distributes the database load, ensuring the stable operation of the business system in high-concurrency scenarios and extending the lifespan of hardware. The buffer mechanism provides fault tolerance during the data refresh process; even if an anomaly occurs in a certain step (such as decryption failure), the system can reprocess the data using buffered data, avoiding data loss or business interruption, enhancing the system's fault tolerance and reliability, and is particularly suitable for fields with extremely high data integrity requirements, such as finance and government.
[0027] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments. Attached Figure Description
[0028] Figure 1 This is a schematic diagram of an embodiment of a highly anonymous and highly secure fixed-denomination stablecoin card system according to the present invention.
[0029] Figure 2 This is a flowchart of an embodiment of the implementation method of a highly anonymous and highly secure fixed-denomination stablecoin card system according to the present invention. Detailed Implementation
[0030] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0031] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0032] An embodiment of a highly anonymous and secure fixed-denomination stablecoin card system See Figure 1 This embodiment provides a highly anonymous and secure fixed-denomination stablecoin card system, including: The fixed-denomination stablecoin card issued by diversified institutions integrates a contactless high-security hardware module. The hardware module is an embedded hardware security module eHSM or a security element SE that meets international high-security level certification. The quantum-resistant hybrid encryption algorithm module is used to perform hardware-level secure writing and storage of the user's stablecoin private key and associated distributed ledger address. The quantum-resistant hybrid encryption algorithm adopts a double-envelope encryption mechanism. This mechanism first uses the SM4 symmetric encryption algorithm approved by the State Cryptography Administration to encrypt the stablecoin master private key. Then, it uses at least one PQC algorithm selected in the NIST post-quantum cryptography standardization competition and the national cryptographic SM2 algorithm to serially encrypt and encapsulate the session key used for SM4 symmetric encryption. The private key generation and storage module dynamically generates and stores a unique stablecoin master private key within the secure element through a multi-factor key derivation algorithm. The multi-factors include at least the master seed key generated by a hardware random number generator, the session key randomly generated within the secure element, and the transaction password set by the user. The card lifecycle management module supports users to migrate their account balances independently without the need for the card issuer to intervene. It allows for instant reconstruction of the private key and migration of the old account balance to the new account through a local terminal application.
[0033] In this embodiment, the fixed-denomination stablecoin card is typically presented as a chip card, deeply integrating an embedded hardware security module (eHSM) or secure element (SE) that meets international high-security standards (such as CC EAL6+ certification). This secure element provides a physically isolated, tamper-proof, and side-channel attack-proof execution environment, ensuring the security of sensitive operations such as key generation, storage, and signing. It also handles the initialization and writing of the stablecoin private key and its associated distributed ledger address, as well as the generation and storage of the card's unique "stablecoin account," "session key," "master seed key," and "transaction password (PIN)."
[0034] An Implementation Method of a Highly Anonymous and Highly Secure Fixed-Denomination Stablecoin Card System like Figure 2 As shown in the figure, this embodiment provides a method for implementing a highly anonymous and highly secure fixed-denomination stablecoin card system. The system employs the aforementioned highly anonymous and highly secure fixed-denomination stablecoin card system, and the method includes the following steps: Card production steps: The issuing institution selects a card manufacturer to produce the cards, and writes the issuing institution's proprietary application logic into the card's secure element. During this stage, no stablecoins are pre-charged into the card. Multi-level key generation and secure distribution steps: During card production, a high-entropy master seed key is generated using a hardware random number generator (HRNG) or a true random number generator (TRNG); simultaneously, a transaction password (PIN) is randomly generated by the card's internal security element according to a preset algorithm; subsequently, the master seed key and transaction password are encrypted and securely printed inside the delivery envelope provided with the card through a coating, and provided to the user along with the card; Master private key generation steps: The security element inside the card uses a preset multi-factor key derivation function (MF-KDF) to dynamically generate and store a unique stablecoin master private key within the security element; Information carrying steps: Complete the design of the card's physical characteristics and enable it to carry stablecoin account information and session key information; Encryption and Layered Storage Steps: The generated stablecoin master private key is encapsulated and encrypted in multiple layers using a quantum-resistant hybrid encryption algorithm before being written into the non-volatile persistent storage area of the card's security element.
[0035] Fixed denomination top-up steps: After the card is produced, the issuing institution tops up the stablecoin account printed on the card with a fixed amount of on-chain stablecoins according to the preset face value.
[0036] Purchase steps: Users purchase fixed-denomination stablecoin cards from the issuing institution or authorized resellers and verify the validity of the denomination through the app.
[0037] In the master private key generation step, the implementation methods of the multi-factor key derivation algorithm include: Master Seed Key Acquisition: During card production, a high-entropy master seed key is generated using a hardware random number generator or a true random number generator. This master seed key is encrypted and securely printed inside the delivery envelope provided with the card through a coating. After the user receives the card, the master seed key is obtained from the envelope and decrypted according to a specified security procedure. This decryption serves as the first key input to the multi-factor key derivation algorithm.
[0038] Session key generation and delivery: The security element inside the card generates a one-time session key based on a random number generation algorithm after the card is manufactured but before it is delivered to the user. This session key is printed on a hidden area of the card surface using laser engraving technology and covered with multiple layers of special coating. The user needs to use the matching scratch-off tool to scratch off the coating in a specific way to obtain the key. The obtained session key serves as the second key input to the multi-factor key derivation algorithm (MF-KDF).
[0039] Transaction Password (PIN) Generation and Distribution: During card production, the internal security element of the card randomly generates a transaction password (PIN) according to a preset algorithm. This transaction password (PIN) is also encrypted and securely printed inside the signature envelope provided with the card through a coating. It is provided to the user along with the master seed key. After the user decrypts and obtains the transaction password (PIN), it serves as the third key input to the multi-factor key derivation algorithm (MF-KDF).
[0040] As can be seen, the Multi-Factor Key Derivation Algorithm (MF-KDF) in this embodiment ensures a high level of security for the stablecoin master private key. Its generation process is completed entirely within the secure element, ensuring the source security and randomness of the private key, and the private key itself never leaves the secure element.
[0041] The security element inside the card has an independent hardware security area. This area uses physical isolation technology to completely isolate it from other functional modules of the card, ensuring that it is not subject to any unauthorized access or interference from the outside during the key derivation and private key generation process.
[0042] The secure element integrates a highly secure encryption processing unit that supports various international and domestic standard encryption algorithms, such as AES and SM4, and provides strong encryption operation support for the multi-factor key derivation algorithm (MF-KDF).
[0043] The secure element has a strict access control mechanism. Only authorized operation commands and legal input data can enter the secure area to perform key derivation and private key generation operations. Any unauthorized access attempt will trigger the secure element's alarm mechanism and record detailed access logs.
[0044] In this embodiment, the execution of the multi-factor key derivation algorithm (MF-KDF) includes: Within the secure area of the secure element, the acquired master seed key, session key, and transaction password (PIN) are input parameters into a preset multi-factor key derivation algorithm (MF-KDF). This algorithm employs complex mathematical operations and cryptographic transformations, combining hash functions, symmetric encryption algorithms, and asymmetric encryption algorithms to perform multiple rounds of mixed operations and processing on the three key inputs.
[0045] During algorithm execution, the master seed key is first hashed to generate a fixed-length hash value, which serves as the basis for subsequent calculations. Then, the session key is XORed with the hash value to obtain an intermediate result. Next, the transaction password (PIN) is concatenated with the intermediate result, and the concatenated data is encrypted using a symmetric encryption algorithm to generate an encrypted data block. The encrypted data block is then subjected to multiple hash operations and bit manipulations to further enhance the randomness and security of the data. Finally, by filtering and extracting the data after multiple rounds of calculations and processing, a unique stablecoin master private key is generated.
[0046] The generated stablecoin master private key is stored in a secure area within the secure element. The storage method adopts hardware-level secure storage technology, such as dividing the private key into multiple parts and storing them in different physical storage units of the secure element. Specific encryption algorithms and access control mechanisms are used to ensure the security and integrity of each part of the private key.
[0047] The secure element strictly manages the stablecoin's master private key, prohibiting any external device or program from directly reading or modifying its contents. When stablecoin-related transactions are required, the secure element internally uses the private key for digital signatures and other operations according to preset rules and authorization mechanisms, ensuring that the use of the private key is secure and controllable, and that the private key itself never leaves the secure element.
[0048] In this embodiment, the design of the card's physical characteristics includes: Depending on actual usage needs, an integrated microkeypad can be optionally installed on the card body, employing a 4×4 or 5×3 matrix key layout. The keys are wear-resistant, with a wear-resistant coating to ensure clear and legible key markings even after long-term use. Simultaneously, the keys feature an anti-accidental touch design, using appropriately spaced keys and pressure thresholds to prevent accidental presses during daily use or operation. This microkeypad supports both numeric and alphanumeric input to meet diverse input needs in scenarios such as transaction verification and password entry.
[0049] The card features an integrated small display screen, utilizing a low-power, high-contrast LCD or OLED screen. This screen clearly displays operational prompts, including but not limited to transaction operation instructions and password input hints; it displays the transaction amount in real-time, accurately showing the specific amount when the user is trading stablecoins; it displays account balance information, allowing users to easily check the remaining amount of stablecoins in their card; and it displays error messages, promptly informing the user of the cause of errors such as network connection failure or insufficient balance when abnormalities occur during the transaction. The card is powered via a contactless interface using NFC inductive power technology. When the card is near an NFC-enabled card reader, it draws power from the electromagnetic field emitted by the device, providing a stable power supply to the micro-keyboard, small display screen, and internal security components, ensuring the card functions correctly in various usage scenarios.
[0050] During account creation, the security element inside the card generates a unique stablecoin account based on a pre-derived stablecoin master private key, using a specific hash algorithm and blockchain address generation rules. This stablecoin account serves as the blockchain address for storing and trading stablecoins on the blockchain network. During account creation, the security element employs hardware-level encryption to ensure the randomness and security of the creation process, preventing malicious prediction or forgery of the account.
[0051] Next, the derived stablecoin account number is printed clearly and accurately on a specific area of the card surface using a high-definition printing process. The printed font uses an anti-counterfeiting font with unique character shapes and stroke characteristics, making it difficult to copy and forge. Simultaneously, special fluorescent materials or invisible inks are added during the printing process, allowing the hidden information of the account number to be displayed under specific lighting conditions (such as ultraviolet light), further enhancing the account's anti-counterfeiting and security. This stablecoin account number serves as the card's public identifier, allowing users to easily provide account information to other parties during transactions, while also facilitating the issuing institution's management and tracking of the card.
[0052] During the printing and coating process of the session key, the session key is randomly generated by the security element inside the card. High-precision printing equipment is used to print the session key clearly and legibly on a designated location on the card surface. The printed content includes the key's character sequence and related usage instructions, such as a prompt to scratch off the coating to obtain the key.
[0053] After the session key is printed, it is completely covered with a special coating. This coating has the following characteristics: First, it is scratch-resistant, able to withstand a certain degree of scratching without damaging the key information underneath. Second, it is privacy-protecting; the coating surface uses special texture or optical processing technology, making the key content underneath invisible when viewed from the side or at a certain angle. The key can only be obtained by the user facing the coating directly and scratching it off with the accompanying scratch-off tool. Third, it is self-destructive; once the coating is scratched off, the key information underneath is exposed, and the coating undergoes irreversible physical or chemical changes, making it impossible to restore to its original state, preventing others from stealing the key by reapplying the coating. This coating method effectively enhances the physical security and privacy protection of the session key, preventing the key from being stolen by others during card use.
[0054] The information to be printed on the card surface is strictly screened, retaining only three key pieces of information: the issuing institution information, the "stablecoin account," and the fixed-denomination stablecoin amount. The issuing institution information includes the institution's name and logo, used to identify the card's issuer; the stablecoin account serves as the card's public identifier, facilitating user transactions; and the fixed-denomination stablecoin amount clearly displays the amount of stablecoins pre-loaded into the card, allowing users to clearly understand the card's initial value.
[0055] High-quality printing technology ensures clear, vibrant, and fade-resistant card information. In terms of layout, the issuing institution information is typically located in the upper left or right corner, occupying a smaller area; the stablecoin account number is printed in a prominent position on the card, such as in the center or bottom, for easy viewing and identification; the fixed-denomination stablecoin amount is printed in larger font in a prominent position, such as the lower front or side, highlighting the card's value. Furthermore, anti-counterfeiting elements such as security features and security threads are added during printing to further enhance the card's anti-counterfeiting capabilities and prevent counterfeiting and misuse.
[0056] In this embodiment, the quantum-resistant hybrid encryption algorithm employs a dual-envelope encryption method to securely encrypt and store the stablecoin master private key, specifically including the following steps: Session key generation: Inside the stablecoin card chip, a hardware random number generator is used to generate a session key for SM4 symmetric encryption. After generation, the session key is stored only in a secure storage area inside the chip. Access to the key is strictly restricted through the chip's internal access control mechanism to prevent unauthorized reading and tampering.
[0057] Stablecoin master private key encryption: Using the session key generated above, the stablecoin master private key is encrypted using the SM4 symmetric encryption algorithm approved by the State Cryptography Administration. The SM4 algorithm employs a 32-round nonlinear iterative structure, transforming the stablecoin master private key into ciphertext form through a series of round function transformations, generating SM4-encrypted master private key ciphertext, ensuring the confidentiality of the master private key during storage and transmission.
[0058] Session key double-encrypted encapsulation PQC Algorithm Selection: Select an algorithm for session key encapsulation encryption from at least one PQC algorithm selected in the NIST post-quantum cryptography standardization competition. For example, select the lattice-based Kyber algorithm for key encapsulation mechanism (KEM), or select the hash-based Dilithium algorithm for digital signature (if digital signature is used for encapsulation, the corresponding key encapsulation process must be used to ensure the secure transmission of session keys).
[0059] Encapsulation and Encryption Operation: The selected PQC algorithm is used to encapsulate and encrypt the session key used for SM4 symmetric encryption. Taking the Kyber algorithm as an example, the sender (i.e., the internal encryption module of the chip) generates a random public-private key pair, uses the public key to encapsulate the session key, and generates the encapsulated ciphertext and related authentication tags to ensure the integrity and confidentiality of the session key during the encapsulation process.
[0060] After encapsulating and encrypting the session key using the PQC algorithm, the SM2 algorithm is executed again for encapsulation and encryption, including the following steps: SM2 Key Pair Generation: Inside the stablecoin card chip, a hardware random number generator is used to randomly generate a key pair using the SM2 algorithm, including a public key and a private key. This key pair is then stored in a secure storage area inside the chip, and its security is protected by a strict access control mechanism.
[0061] Secondary Encapsulation Encryption: The generated SM2 public key is used to re-encapsulate and encrypt the session key, which has already been encapsulated and encrypted using the PQC algorithm. The SM2 algorithm is based on elliptic curve cryptography and employs asymmetric encryption. Through operations such as dot product on the elliptic curve and hash functions, the session key encapsulated by PQC is further encrypted, generating the final double-encapsulated ciphertext of the session key.
[0062] Ciphertext Storage: The SM4-encrypted master private key ciphertext and the session key ciphertext, encapsulated successively by PQC and SM2, are persistently stored in the stablecoin card's non-volatile storage medium, such as flash memory chips. During storage, data verification and error correction coding technologies are employed to ensure the integrity and reliability of the ciphertext during storage, preventing corruption due to storage medium failure or external interference.
[0063] Specifically, firstly, the stablecoin's master private key is encrypted using the SM4 symmetric encryption algorithm approved by the State Cryptography Administration. The session key used for this SM4 symmetric encryption is randomly generated and stored within the chip.
[0064] Secondly, the session key used for this SM4 symmetric encryption will be encrypted and encapsulated in two independent and serial methods: First, the session key is encapsulated and encrypted using at least one PQC algorithm selected in the NIST post-quantum cryptography standardization competition (e.g., lattice-based Kyber for the key encapsulation mechanism KEM, or hash-based Dilithium for digital signatures); second, the session key encrypted in the first step is encapsulated and encrypted again using the national standard SM2 algorithm. The key pair for this SM2 algorithm is randomly generated and stored internally within the chip.
[0065] Ultimately, the card persistently stores the SM4-encrypted master private key ciphertext and the session key encapsulated successively by PQC and SM2. This "redundant encryption" and "double-envelope encryption" mechanism ensures that even if future quantum computing capabilities break one of the public-key encryption algorithms, the other algorithm can still provide security, thus achieving a double-redundant security barrier that ensures "quantum security and compatibility with the State Cryptography Administration's standards."
[0066] This embodiment constructs a dual-redundancy security barrier that ensures both quantum security and compatibility with the State Cryptography Administration standards through "redundant encryption" and "double-envelope encryption" mechanisms. Even if future advancements in quantum computing capabilities break one of the public-key encryption algorithms (such as the PQC or SM2 algorithm), the other unbroken algorithm will still provide security guarantees, ensuring the security of the stablecoin master private key and session key, and preventing stablecoin asset losses and security risks caused by private key leakage.
[0067] The fixed-denomination stablecoin card in this embodiment also features a decentralized transaction process and high anonymity: the fixed-denomination stablecoin card supports the initiation and confirmation of decentralized stablecoin transactions based on contactless communication and card interaction, mainly used in highly anonymous transaction scenarios, and only supports consumption and transfer functions.
[0068] Specifically, the highly anonymous transaction initiation and card security authentication in this embodiment includes the following steps: Device Touch and Communication Channel Establishment: The user touches their stablecoin card against an NFC-enabled smart terminal device, including but not limited to smartphones, smart POS machines, and Web3 payment terminals. During the touch, the stablecoin card and the smart terminal device establish a secure and low-power communication channel according to the NFC Data Exchange Format (NDEF) protocol conforming to the ISO / IEC 14443 standard. This communication channel uses a specific encryption algorithm to encrypt the transmitted data. The encryption algorithm uses high-strength encryption algorithms such as AES-256 to ensure the confidentiality and integrity of the data during communication, preventing data theft or tampering.
[0069] Transaction Request Parsing and Data Packet Transmission: The application running on the smart terminal device intelligently parses the on-chain transaction requests initiated by the user. These requests cover various transaction types, including fixed-denomination stablecoin spending and peer-to-peer transfers. The application converts the parsed transaction requests into a structured "Signing Intent" data packet, which contains key information such as the transaction type, transaction amount, and counterparty address (in the case of peer-to-peer transfers). Then, the "Signing Intent" data packet is transmitted to the stablecoin card through an established secure channel.
[0070] Card PIN Input and Local Verification: Upon receiving the "signature intent" data packet, the stablecoin card displays a PIN input prompt to the user via a small integrated display screen (such as an LCD or OLED screen) on the card itself. If the card does not have a display screen, the user is prompted to enter the PIN through the application interface of a smart terminal device. The user can directly enter the preset PIN on the card itself. If the card is equipped with a micro-keyboard (usually a 4×4 or 5×3 matrix keypad supporting numeric or alphanumeric input), the PIN is entered via the keyboard. If no keyboard is provided, the PIN can be entered through the application interface of the smart terminal device, and the application will then encrypt and transmit the PIN to the card. The card's internal security element uses a specific hash algorithm (such as SHA-256) to hash the user-entered PIN and compares the result with the PIN hash value pre-stored in the security element. If the comparison is successful, the user's identity is verified, and subsequent transaction operations are allowed. If the comparison fails, the transaction request is rejected, and the user is prompted with an incorrect PIN message via the display screen or the terminal application. After a successful transaction, if the card has a display screen, confirmation information, including transaction type, transaction amount, and transaction time, will be displayed on the screen. Users can input specific commands (such as pressing a specific function key combination) at any time via the card's keypad to trigger the card's internal security element to query the current stablecoin balance and display the balance information to the user on the screen. If the card does not have a keypad and display screen, the user can initiate a balance query request through the application interface of the smart terminal device. The card will encrypt the balance information and return it to the terminal application for display.
[0071] Offline Signature for On-Chain Transactions: After successful verification using the local transaction password, the card's secure element internally constructs a completely isolated and physically tamper-proof environment. This environment employs a multi-layered security mechanism, including hardware isolation, software protection, and physical encapsulation. For hardware isolation, the secure element uses an independent processor and memory, electrically isolated from other components of the card. For software protection, the secure element runs a dedicated secure operating system, implementing strict access control over internal programs and data. For physical encapsulation, the secure element uses special encapsulation materials and technologies to prevent external physical attacks and tampering.
[0072] In a secure environment, the card's secure element signs transaction data offline. The private key used for signing is always stored within the secure element and never leaves this secure environment. The secure element uses an asymmetric encryption algorithm (such as ECDSA) to sign the transaction data, generating a digital signature. During the signing process, the secure element verifies the integrity of the transaction data to ensure it has not been tampered with. Through this seamless integration of "hardware cold storage" of the private key with "online transactions," the user's personal identity information is not disclosed during the transaction process, ensuring a high degree of anonymity.
[0073] Transaction Broadcasting and Atomic Execution: Signed and verified transaction data is securely returned to the application on the smart terminal device via the NFC channel. During the return process, the transaction data is encrypted using the same encryption algorithm used when the communication channel was established, ensuring the security of data transmission. The application on the smart terminal device can choose two methods to broadcast the transaction to the corresponding blockchain network. One method is to broadcast the transaction directly to the blockchain network; the other method is to broadcast the transaction to the blockchain network through an optimized decentralized relay network. The decentralized relay network consists of multiple distributed relay nodes, which communicate with each other in a peer-to-peer manner, providing high availability and resistance to attacks. After receiving the transaction, the blockchain network verifies and processes it, enabling the on-chain atomic transfer or consumption of stablecoins. Atomic execution means that the transaction either succeeds completely or fails completely, preventing partial execution and ensuring the reliability and consistency of the transaction. Blockchain networks include, but are not limited to, Ethereum, BNB Chain, Polygon, and Arbitrum.
[0074] Funds Bridging and Insufficient Funds Handling: Fixed-denomination stablecoin cards only support spending and transfer functions and do not support insufficient funds handling processes or DeFi-TradFi smart funds bridging modules. Their design philosophy is to serve as a pre-charged, fixed-denomination digital cash alternative, simplifying the usage process.
[0075] This embodiment also provides a fully self-service method for transferring stablecoin account balances. This method strictly adheres to the principle of "never revealing or storing the private key in any system (only on the card or in the user's local reconstruction)", and is suitable for scenarios requiring high anonymity and user self-recovery. Specifically, it includes the following steps: User Self-Service Application Submission and Information Acquisition Steps When a stablecoin card is damaged or lost, the user must scratch off the coating inside the delivery envelope provided with the card. This coating is made of a special material and has anti-counterfeiting and single-use properties; once scratched off, it cannot be restored. The user obtains the original "Master Seed Key" and "Transaction Password (PIN)" from the scratched-off area. Simultaneously, the user obtains the "Stablecoin Account" and "Session Key" from the printed area on the old card. The "Stablecoin Account" is the unique account identifier corresponding to the card on the blockchain network; the "Session Key" is used for encryption and verification during specific communications or data processing; the "Master Seed Key" is the basic data for generating key keys such as the private key; and the "Transaction Password (PIN)" is used for user authentication.
[0076] Self-service recovery and balance migration via terminal application Users select a designated and secure terminal application to operate the system. This application can be a dedicated application provided by the card issuer or a general-purpose application such as a Web3 browser plugin. These terminal applications must undergo rigorous security certification and auditing to ensure they have secure data processing and transmission capabilities.
[0077] In the selected terminal application, the user manually enters the old card's "stablecoin account," "session key," "master seed key," "transaction password (PIN)," and the new card's (or another on-chain address specified by the user) "delivery ID" (i.e., the target receiving address). The terminal application locally verifies the validity of the entered information, including but not limited to whether the information format is correct, whether the information length meets the requirements, and whether the information is within its validity period. If the information verification fails, the terminal application prompts the user with an error message and asks the user to re-enter the information; if the information verification passes, the user proceeds to the next step.
[0078] The terminal application takes the "stablecoin account," "session key," "master seed key," and "transaction password (PIN)" as inputs and uses the same multi-factor key derivation algorithm (MF-KDF) as the card's internal key to instantly reconstruct the stablecoin private key corresponding to the old card locally. This multi-factor key derivation algorithm combines multiple input factors and generates a unique private key through complex mathematical operations and hash functions. The reconstructed private key only exists temporarily in the local terminal application's memory. The terminal application takes strict security measures to ensure that the private key is not uploaded to any server or persistent storage, preventing private key leakage.
[0079] Atomized balance retrieval, secure transfer, and old card cancellation steps The reconstructed private key is used only for one-time authorized transactions. The end application uses the reconstructed private key to generate a transaction signature and initiates a request to the blockchain network to securely and atomically retrieve all stablecoin balances from the on-chain address associated with the old card. Atomic retrieval means that during the balance retrieval process, either the entire balance is successfully retrieved, or no action is taken, ensuring the integrity and accuracy of the balance.
[0080] The system atomically transfers the acquired stablecoin balance to a new on-chain address associated with the user's newly issued stablecoin card via secure on-chain transactions. During the transfer, high-strength encryption algorithms are used to encrypt the transaction data, ensuring its security during transmission and storage. Simultaneously, the blockchain network's consensus mechanism and smart contract technologies guarantee the immutability and traceability of the transactions.
[0081] Once the transfer is complete, the system immediately and logically permanently cancels and invalidates the original card and its associated private key account. The cancellation process includes marking the original card as invalid in the relevant records on the blockchain network, clearing all temporary data and cached information related to the original card, ensuring the uniqueness and irreversible security of the assets, and preventing the original card from being reused and resulting in asset loss.
[0082] As can be seen, the entire process design ensures that the private key is always under strict security protection during card production and account retrieval, and is neither disclosed in plaintext nor persistently stored in any centralized system. The private key is only securely stored inside the card, or instantly reconstructed locally by the terminal application during user self-recovery, thus meeting the requirements of high anonymity and high security.
[0083] In summary, the fixed-denomination stablecoin card system and its implementation method provided in this embodiment have the following advantages: I. Robust security protection system (I) Post-quantum defense system This system integrates a dual security paradigm of national cryptographic algorithms and PQC (Physical Quantum Cryptography): It deeply integrates national cryptographic algorithms (SM2 / SM3 / SM4) approved by the State Cryptography Administration with internationally leading NIST post-quantum cryptographic algorithms (such as Kyber based on lattices and Dilithium / Falcon based on hash signatures). Employing "double-envelope encryption" and "redundant encryption" mechanisms, it constructs a dual security barrier to ensure the absolute security of user private keys even under future quantum computing attacks, while simultaneously meeting national cryptographic security compliance requirements.
[0084] Hardware-level security-in-depth: Utilizing CC EAL6+ level secure elements (SE) to provide a physically isolated, tamper-proof, and side-channel attack-proof environment for private key generation, storage, and signing. Combined with other security technologies, a multi-layered, defense-in-depth security system is constructed to effectively resist high-level attacks and provide solid protection for private key security.
[0085] (II) Distributed key management and advanced resilience By introducing Threshold Signature (TSS) / Multi-Party Computation (MPC) private key management technology, private keys are generated and managed in a distributed manner, eliminating the risk of single points of failure. For example, the private key is divided into multiple shares, which are jointly held by the stablecoin card security element and multiple smart devices authorized by the user (such as the TEE or SE of a mobile phone or PC). Transaction signing requires authorization from a preset threshold number of shares (such as 2 of 3 or 3 of 5), significantly improving key redundancy, resistance to single points of failure, and asset security.
[0086] II. Innovative Key Management and Recovery Mechanism A fully self-help recovery paradigm driven by "multi-factor keys" Three-Factor Private Key Derivation and Recovery: The system uses a "Master Seed Key" (under the inner coating of the envelope), a "Session Key" (under the card surface coating), and a "Transaction Password (PIN)" (under the inner coating of the envelope) as the three core factors. A multi-factor key derivation algorithm (MF-KDF) is used to generate the stablecoin master private key inside the card. This design introduces multiple factors during private key generation, enabling fully autonomous and highly secure balance migration for users in the event of card damage and recovery.
[0087] The "zero-leakage" private key design maximizes user autonomy: Users can instantly reconstruct their private key in their local terminal application using only the information on the physical envelope and card coating, combined with their transaction password, without the need for card issuer intervention. This private key is used only for one-time balance transfers and is never uploaded or persistently stored, fundamentally solving the pain points of lost or stolen private keys and pushing user autonomy and transaction anonymity to the extreme.
[0088] III. Convenient and intuitive card interaction and anonymous transaction experience (a) Intuitive and interactive design of the card body The card integrates a micro keypad and optional display screen, allowing users to directly enter their transaction password and check their balance on the card. This provides an intuitive operating experience similar to traditional prepaid cards, enhancing the convenience and anonymity of transactions without relying on external terminals for identity verification or information input.
[0089] (II) Optimization of highly anonymous transaction experience Focusing on fixed-amount payments and anonymous transfers, the card optimizes the transaction process and minimizes unnecessary identity information interaction, making it particularly suitable for micro-payments and privacy protection scenarios that do not require real-name authentication.
[0090] IV. Unique Fixed-Denomination Card Design and Issuance Model (a) Prepaid fixed denomination The cards do not contain stablecoins during production. Instead, the issuing institution tops up the cards with a fixed face value to the on-chain address associated with the cards before they are sold, simplifying the understanding and management of the card's value, similar to traditional gift cards or prepaid cards.
[0091] (ii) Simplified function set It only supports consumption and transfer functions, eliminating complex processes such as handling insufficient funds, making the product positioning clearer and focusing more on achieving the core anonymous payment and transfer experience.
[0092] V. Advantages of Cross-Chain and Interoperability Protocol-level cross-chain support It explicitly supports deep integration with mainstream cross-chain interoperability protocols (such as LayerZero and Axelar based on message passing, or Cosmos IBC, Polkadot Substrate, and Chainlink CCIP based on relay chains). This enables stablecoin cards to go beyond a single blockchain, achieving atomic cross-chain transfers and transactions of stablecoin assets across multiple heterogeneous blockchain networks, effectively solving the fragmentation problem of the blockchain ecosystem and promoting the global flow of assets.
[0093] VI. User Experience Revolution Brought About by Account Abstraction (a) Gas fee stablecoin payment It fully supports account abstraction standards such as ERC-4337, and innovatively allows users to directly pay transaction gas fees with stablecoins without having to manage native chain tokens (such as ETH), greatly reducing the entry barrier and operational complexity of Web3 applications and improving user-friendliness.
[0094] (ii) Programmable Accounts and Advanced Features Account abstraction brings programmability to stablecoin cards, including advanced features such as multi-signature integration, social recovery, batch transactions, and preset automated operations, making wallets more powerful and flexible.
[0095] VII. Integrating and Innovating Decentralized Identity with Privacy Protection (a) Hardware-anchored DID carrier Stablecoin cards can serve as hardware anchors for decentralized identities (DIDs), securely storing users' verifiable credentials (VCs) to ensure the authenticity and unforgeability of on-chain identities.
[0096] (ii) Privacy compliance driven by zero-knowledge proof Integrating zero-knowledge proof (ZKP) technology enables users to prove to decentralized exchanges (DEXs) or Web3 applications that they meet specific conditions without disclosing underlying sensitive personal information (such as KYC data and transaction history details). This protects user privacy while meeting on-chain compliance requirements, achieving "verifiable privacy".
[0097] 8. Transaction models adapted to micro-payment scenarios (a) Limited offline transaction capabilities For areas with unstable networks or for small-amount, high-frequency payment scenarios, an offline transaction limit is preset in the card's security element. Limited offline stablecoin payments are achieved through pre-signed transaction batch processing or atomic swaps, providing a smooth experience close to traditional payments.
[0098] (ii) Asynchronous batch on-chain settlement Offline transaction data is encrypted and timestamped before being securely stored on the card. Once the card reconnects to the network, multiple offline transactions are simultaneously confirmed on the blockchain through an efficient asynchronous batch on-chain settlement mechanism, effectively reducing transaction costs and improving efficiency.
[0099] IX. Full Lifecycle Intelligent Risk Assessment and Proactive Compliance Framework (I) AI / ML-driven on-chain analytics Integrating advanced on-chain data analytics and machine learning models, the system conducts real-time and continuous risk assessments of user transaction behavior. It proactively identifies abnormal transaction patterns (such as large fluctuations, frequent interactions with high-risk addresses, and characteristics of organized crime) and provides intelligent risk alerts, transaction delays, or automatic blocking based on preset rules or user preferences.
[0100] (ii) Integration of Anti-fraud and Anti-money Laundering (AML) We will build a forward-looking anti-fraud and anti-money laundering (AML) compliance system to enhance the protection of users' stablecoin assets through behavioral profiling and risk scoring, while also assisting joint institutions in fulfilling their regulatory obligations.
[0101] 10. Programmability and Open Ecosystem Expansion Potential (a) Hardwareization of DApp Interaction Interfaces Emphasizing that stablecoin cards serve as the physical interaction interface for Web3 applications (DApps), users can not only make preset stablecoin transfers, but also securely interact with any complex smart contracts through secure elements, providing a solid hardware foundation and trust anchor for the broad scenarios of Web3 applications.
[0102] (ii) Modularization and API openness The entire system is designed with high modularity and API openness, which will facilitate the integration of more DeFi protocols, Web3 services and innovative applications in the future, building a continuously evolving stablecoin payment ecosystem.
[0103] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0104] The above embodiments are merely preferred embodiments of the present invention and should not be construed as limiting the scope of protection of the present invention. Any non-substantial changes and substitutions made by those skilled in the art based on the present invention shall fall within the scope of protection claimed by the present invention.
Claims
1. A highly anonymous, highly secure, fixed denomination stable coin card system, characterized by, Comprise: A multi-agency issued fixed denomination stable coin card, the card body is integrated with a non-contact high security hardware module, which is an embedded hardware security module or a secure element that meets international high security level certification; A quantum-resistant hybrid encryption algorithm module for securely writing and storing user stable coin private keys and associated distributed ledger addresses at the hardware level, wherein the quantum-resistant hybrid encryption algorithm uses a double envelope encryption mechanism that first encrypts the stable coin master private key using the SM4 algorithm, and then serially encrypts and packages the session key used for SM4 symmetric encryption using at least one PQC algorithm and the SM2 algorithm; A private key generation and storage module that dynamically generates and stores a unique stable coin master private key inside the secure element using a multi-factor key derivation algorithm, the multi-factor at least including a master seed key generated by a hardware random number generator, a session key randomly generated inside the secure element, and a transaction password set by the user; A card life cycle management module that supports user self-service account balance migration without the need for card issuing agencies to intervene, and through local terminal application, the private key is reconfigured instantaneously and the old account balance is migrated to the new account.
2. A method for implementing a highly anonymous, highly secure, fixed-denomination stable coin card system, characterized by, The system is a highly anonymous and highly secure fixed denomination stable coin card system as claimed in claim 1, the method comprising the following steps: Card production step: selected by the issuing agency, the card producer produces the card, writes the exclusive application logic of the issuing agency into the secure element inside the card, and the card does not pre-charge any stable coin inside at this stage; Multi-level key generation and secure distribution step: in the card production process, a high-entropy master seed key is generated using a hardware random number generator or a true random number generator; at the same time, a transaction password is randomly generated by the card internal secure element according to a preset algorithm; then, the master seed key and the transaction password are printed in encrypted form inside the signing envelope provided with the card through the coating method, and are provided to the user together with the card; Master private key generation step: the secure element inside the card uses a preset multi-factor key derivation algorithm to dynamically generate and store a unique stable coin master private key inside the secure element; Information bearing step: complete the design of the physical characteristics of the card, and make it bear the stable coin account information and the session key information; Encryption and layered storage step: the generated stable coin master private key is encrypted and packaged by the quantum-resistant hybrid encryption algorithm before being written into the non-volatile persistent storage area of the card secure element; Fixed denomination recharging step: after the card production is completed, the issuing agency recharges the stable coin account printed on the card with a fixed amount of on-chain stable coin according to the preset denomination; Purchase step: the user purchases the fixed denomination stable coin card at the issuing agency or the sales point, and verifies the validity of the denomination through the app.
3. The method of claim 2, wherein, In the master private key generation step, the implementation of the multi-factor key derivation algorithm includes: Master seed key acquisition: During the card production process, a high-entropy master seed key is generated using a hardware random number generator or a true random number generator. The master seed key is securely printed in encrypted form inside the signing envelope provided with the card, covered by a coating. After the user obtains the card, the master seed key is obtained from the envelope and decrypted according to the specified security process, serving as the first key input for the multi-factor key derivation algorithm. Session key generation and bearing: The secure element inside the card randomly generates a one-time session key using a random number generation algorithm after the card production is completed and before it is delivered to the user. The session key is printed on the hidden area of the card surface through laser engraving technology and covered by multiple special coatings. The obtained session key serves as the second key input for the multi-factor key derivation algorithm. Transaction password generation and distribution: During card production, the secure element inside the card randomly generates a transaction password according to a pre-set algorithm. The transaction password is also securely printed in encrypted form inside the signing envelope provided with the card, covered by a coating. The user is provided with the master seed key and the transaction password, and after decrypting and obtaining the transaction password, it serves as the third key input for the multi-factor key derivation algorithm.
4. The method of claim 3, wherein, The execution of the multi-factor key derivation algorithm includes: In the secure area inside the secure element, the obtained master seed key, session key, and transaction password are input into the multi-factor key derivation algorithm as input parameters. The algorithm performs multiple rounds of mixing operations and processing on the three key inputs. During the algorithm execution, the master seed key is first hashed to generate a fixed-length hash value. Then, the session key is XORed with the hash value to obtain an intermediate result. Next, the transaction password is concatenated with the intermediate result, and the concatenated data is encrypted using a symmetric encryption algorithm to generate an encrypted data block. The encrypted data block is then subjected to multiple hash operations and bit operations. Finally, the unique stable coin master private key is generated by filtering and extracting the data after multiple rounds of operations and processing.
5. The method of claim 2, wherein, The design of the card physical characteristics includes: An integrated micro keyboard is selected and arranged on the card body. The micro keyboard adopts a 4x4 or 5x3 matrix key layout. At the same time, the keys have an anti-misoperation design, which prevents unnecessary operations caused by misoperation during daily carrying or operation by setting the key spacing and key pressure threshold. An integrated small display screen is selected and arranged on the card body. The card power supply is powered through a non-contact interface, using NFC induction power supply technology. When the card is close to a card reading device supporting NFC function, it can obtain electric energy from the electromagnetic field emitted by the device, providing working power for the micro keyboard, small display screen, and internal secure element components on the card body.
6. The method of claim 5, wherein: In the account derivation process, the secure element inside the card generates a unique stable coin account based on the pre-derived stable coin master private key, using a hash algorithm and a blockchain address generation rule. The stable coin account serves as a blockchain address for storing and trading stable coins in the blockchain network.
7. The method of claim 2, wherein, The anti-quantum mixing encryption algorithm realizes the secure encryption and storage of the stable currency master private key by using double envelope encryption, including the following steps: Session key generation: In the stable currency card chip, a session key for SM4 symmetric encryption is generated using a hardware random number generator. The session key is stored only in the secure storage area inside the chip, and its access is strictly limited by the access control mechanism inside the chip to prevent unauthorized reading and tampering. Stable currency master private key encryption: The generated session key is used to encrypt the stable currency master private key using the SM4 algorithm. The SM4 algorithm uses a 32-round nonlinear iteration structure to convert the stable currency master private key into ciphertext form by a series of round function transformations, generating an SM4-encrypted master private key ciphertext: Double encryption of session key: At least one PQC algorithm is selected for the encryption algorithm of the session key. The selected PQC algorithm is used to encrypt the session key used by the SM4 algorithm.
8. The method of claim 7, wherein, After encrypting the session key using the PQC algorithm, the SM2 algorithm is used for further encryption, including the following steps: SM2 key pair generation: Inside the stable currency card chip, a pair of SM2 algorithm keys, including a public key and a private key, is randomly generated using a hardware random number generator, and the key pair is stored in the secure storage area inside the chip. Second encryption operation: The SM2 public key is used to further encrypt the session key encrypted by the PQC algorithm. The SM2 algorithm is based on the elliptic curve cryptography system and uses asymmetric encryption. Through point multiplication operations on the elliptic curve and hash functions, the session key encrypted by the PQC algorithm is further encrypted to generate the final double-encrypted session key ciphertext. Ciphertext storage: The SM4-encrypted master private key ciphertext and the session key ciphertext encrypted by the PQC algorithm and the SM2 algorithm are stored in the non-volatile storage medium of the stable currency card.
9. The method according to any one of claims 2 to 8, characterized in that, Highly anonymous transaction initiation and card body security authentication, including the following steps: Device touch and communication channel establishment: The stable currency card is touched with a smart terminal device supporting NFC function. During the touch process, the stable currency card and the smart terminal device establish a secure and low-power communication channel based on the NFC data exchange format protocol conforming to ISO / IEC 14443 standard. Transaction request analysis and data packet transmission: The application program running on the smart terminal device intelligently analyzes the user-initiated on-chain transaction request. The application program converts the analyzed transaction request into a structured signature intent data packet. Then, the signature intent data packet is transmitted to the stable currency card through the established secure channel. After receiving the signature intent data packet, the stable currency card displays the transaction password input prompt information to the user through the small display screen integrated on the card body. If the card body does not have a display screen, the application program interface of the smart terminal device prompts the user to input the transaction password. Local password verification: input the preset transaction password on the card body, and transmit the password to the card by the terminal application; the secure element inside the card uses a hash algorithm to perform a hash operation on the user-input transaction password, and compares the operation result with the pre-stored password hash value in the secure element; Offline signature of on-chain transaction: after passing the local password verification, the secure element of the card performs offline signature on the transaction data in a completely isolated and physically tamper-proof environment; Transaction broadcast and atomic execution: return the signed and verified transaction data to the terminal application through the NFC channel, and then broadcast the transaction to the corresponding blockchain network by the terminal application or through a decentralized relay network to realize the on-chain atomic transfer or consumption of stable coins.
10. The method according to any one of claims 2 to 8, characterized in that, It also includes complete self-service transfer of stable coin account balance, including the following steps: User self-service application submission and information acquisition step: When the stable coin card is damaged or lost, the user needs to manually scratch the coating in the signing envelope provided with the card; obtain the original master seed key and transaction password from the scratched coating area; at the same time, obtain the stable coin account number and session key from the printed area of the old card; the stable coin account number is the unique account identifier of the card on the blockchain network; Through the terminal application self-service recovery and balance migration step: The user manually inputs the stable coin account number, session key, master seed key, transaction password of the old card, and the deposit ID of the new card or other on-chain address specified by the user, i.e. the target receiving address, in the selected terminal application; the terminal application uses the same multi-factor key derivation algorithm as the card inside to locally reconstruct the stable coin private key corresponding to the old card; Balance atomic acquisition, secure transfer and old card cancellation step: The reconstructed stable coin private key is only used for one-time authorized transaction, and the terminal application generates a transaction signature using the reconstructed private key to initiate a request to the blockchain network to securely and atomically obtain all stable coin balances from the old card associated on-chain address; the system securely transfers the obtained stable coin balance to the new address associated with the new stable coin card handled by the user through a secure on-chain transaction; after the transfer operation is completed, the original card and its associated original private key account are permanently cancelled and invalidated at the logical level.