Security Shield and Verification Method for Stablecoin E-wallets Based on Dual-Chip Collaboration

By employing a dual-chip collaborative architecture, utilizing a quantum random number chip and a security chip to generate truly random numbers, and combining one-time private key destruction and a stablecoin compliance module, the security and compatibility issues of hardware wallets under the threat of quantum computing are resolved, enabling highly secure and compliant stablecoin transactions.

CN122089306APending Publication Date: 2026-05-26ZHONGKE WENTIAN QUANTUM TECHNOLOGY (WUHAN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHONGKE WENTIAN QUANTUM TECHNOLOGY (WUHAN) CO LTD
Filing Date
2026-01-23
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing hardware wallets are not secure enough in the face of quantum computing threats and lack deep adaptation to stablecoin trading features, resulting in poor user experience and compliance risks.

Method used

It adopts a dual-chip collaborative architecture, using a direct connection between a quantum random number chip and a security chip to generate truly random numbers and transmit them through a dedicated high-speed interface. Combined with the one-time private key instant destruction and a stablecoin-specific compliance module, it achieves unpredictable key source, resistance to quantum attacks in the transaction process, and compliant and controllable business logic.

Benefits of technology

It improves the security and compatibility of hardware wallets, effectively resists quantum attacks, meets the compliance requirements of stablecoin transactions, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122089306A_ABST
    Figure CN122089306A_ABST
Patent Text Reader

Abstract

This invention discloses a stablecoin e-wallet security shield and verification method based on dual-chip collaboration, belonging to the fields of information security and blockchain technology. The device includes a physically isolated quantum random number chip and a traditional random number chip, both directly connected to a security chip interface via dedicated hardware. The quantum random number chip and the traditional random number chip generate truly random numbers based on quantum physics processes and transmit them directly to the security chip for dynamically generating a one-time private key for transaction signing, which is then immediately destroyed after signing. The security chip has a built-in stablecoin compliance module that supports multi-chain, multi-currency, and amount threshold verification, and generates a replay protection check code for dual verification. This invention achieves unpredictable key sources, resistance to quantum attacks during transactions, and precise adaptation to stablecoin compliance, combining high security, strong compatibility, and low user learning costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of information security and blockchain technology, and in particular to a stablecoin e-wallet security shield and verification method based on dual-chip collaboration. Background Technology

[0002] With the rapid development of quantum computing technology, the mathematical problems (large number factorization, discrete logarithms) upon which traditional public-key encryption algorithms (such as RSA and ECDSA) rely may be efficiently cracked in the future, posing unprecedented security challenges to all digital assets, including stablecoins. Current security solutions on the market have significant shortcomings: On the one hand, while some hardware wallets integrate quantum true random number generators to improve the entropy quality of the key source, the random number source system is singular and its usage is rigid, making it prone to single-system failures, single points of failure, and external side-channel attacks. Furthermore, its core encryption and signature algorithms remain classical algorithms vulnerable to quantum attacks, failing to provide long-term security guarantees. On the other hand, while emerging post-quantum cryptography (PQC) hardware wallets employ quantum-resistant algorithms, they often retain traditional key storage methods, storing private keys permanently in the device. If the device is physically stolen or subjected to advanced side-channel attacks, the private key remains at risk of leakage. In addition, existing general-purpose blockchain hardware wallets generally lack deep adaptation to the characteristics of stablecoin transactions and fail to have built-in dedicated verification modules for different stablecoin types, on-chain address formats and regulatory compliance requirements (such as transaction amount thresholds), resulting in poor user experience and compliance risks.

[0003] To address the aforementioned issues, existing technologies attempt to enhance overall protection capabilities by strengthening hardware security modules. For example, CN112001714B discloses a method for implementing digital currency based on blockchain technology. This method deploys encryption chips at the client, verification center, and blockchain nodes, employing "vertical authentication" technology and a dynamic key generation mechanism to build a secure and efficient digital currency trading system. While this solution effectively improves transaction processing speed and system security, its underlying security foundation remains based on classical cryptographic algorithms such as SM2 and RSA, failing to proactively address the disruptive threats posed by quantum computing. Furthermore, this solution does not integrate truly random numbers generated by quantum physics processes as a high-entropy source for key generation and lacks refined compliance verification functions for specific digital asset classes and a mechanism for destroying private keys upon use. Therefore, a new hardware wallet technology solution is urgently needed. This solution should deeply integrate quantum true random number generation technology with post-quantum cryptographic algorithms to achieve a seamless and secure transaction mode with keys destroyed upon use, and embed a smart compliance module specific to stablecoins, thereby fundamentally solving the three core challenges of key security, resistance to quantum attacks, and scenario-based adaptation. Summary of the Invention

[0004] In view of this, the present invention proposes a stablecoin e-wallet security shield and verification method based on dual-chip collaboration. Through a dual-chip direct connection architecture of quantum random number chip and security chip, and through direct transmission of true random numbers, one-time instant destruction of private keys, and a stablecoin-specific compliance module, a three-in-one security protection is achieved, namely, unpredictable key source, resistance to quantum attacks in the transaction process, and compliant and controllable business logic.

[0005] This invention provides a stablecoin e-wallet security shield based on dual-chip collaboration, including a quantum random number chip and a traditional random number chip, configured to generate true random numbers in real time based on quantum physics and traditional thermal noise processes, and transmit the true random numbers directly to the security chip via a dedicated high-speed interface without going through an external general bus;

[0006] The security chip is directly connected to the quantum random number chip and the traditional random number chip via a dedicated high-speed interface; the security chip integrates:

[0007] The main control module is used for system scheduling and communication control;

[0008] The random number module uses a mechanism different from that of external random number chips to generate random numbers;

[0009] The cryptographic algorithm module supports post-quantum cryptography, national cryptographic algorithms, and traditional cryptographic algorithms; it configures a private key generated based on the true random number during transactions and uses the private key to digitally sign transaction data.

[0010] The stablecoin compliance module is used to verify the legality of stablecoin transaction parameters according to a preset strategy, which includes the target blockchain network identifier, stablecoin type, receiving address format, and transaction amount threshold.

[0011] The verification output module is configured to generate a dynamic verification code based on the true random number after the transaction signature is completed, and combine the digital signature with the dynamic verification code into composite verification information, which is then output to an external terminal through a secure communication channel to prevent replay attacks and man-in-the-middle tampering.

[0012] Furthermore, the security shield also includes:

[0013] The storage module is used to store private keys, public keys, device keys, certificates, system programs, and configuration information.

[0014] Communication interfaces include USB, NFC, and Bluetooth;

[0015] The human-computer interaction module includes buttons, a display screen, and biometric sensors, which are used to collect user input and output transaction status.

[0016] The security protection structure includes an electromagnetic shielding shell and an anti-tampering circuit, wherein the anti-tampering circuit triggers key destruction when physical intrusion is detected.

[0017] Furthermore, the cryptographic algorithm module includes at least one of the CRYSTALS-KYBER key encapsulation algorithm, Dilithium, SPHINCS+, or Rainbow digital signature algorithm.

[0018] Furthermore, the quantum random number chip integrates at least two non-quantum physical random sources, including an external thermal noise source and a chaotic noise source; at the same time, the security chip also integrates an independent physical true random number source; finally, the true random number is jointly input to the CSPRNG module by the external multi-source fusion output and the internal true random number source output, and is reseeded before each transaction to ensure forward security.

[0019] Furthermore, the transaction amount threshold is dynamically set according to the stablecoin type, with a single transaction limit of 1 million units for USDT and USDC, a single transaction limit of 500,000 units for DAI, and a single transaction limit for digital RMB that is dynamically updated according to regulatory policies.

[0020] Furthermore, the biometric sensor is used to collect the user's fingerprint or vein information; when the transaction amount is less than 1,000 yuan or equivalent, only PIN code verification is required; when the transaction amount is greater than or equal to 1,000 yuan or equivalent, biometric verification is required to execute the transaction.

[0021] Furthermore, the dedicated high-speed interface adopts a hardware isolation design with a bandwidth of no less than 2Mbps, and is designed to prevent bus eavesdropping and side-channel attacks.

[0022] Furthermore, the national cryptographic algorithms include SM2, SM3, SM4, SM7, and SM9; the traditional cryptographic algorithms include RSA, AES, and SHA2.

[0023] Furthermore, the anti-tampering circuit in the security protection structure is configured such that once physical disassembly or abnormal electromagnetic interference is detected, a key destruction command is immediately triggered to clear all sensitive data.

[0024] This invention also provides a stablecoin e-wallet security verification method based on dual-chip collaboration, comprising the following steps:

[0025] S1. A quantum random number chip generates true random numbers in real time based on quantum physics processes and transmits them directly to a security chip through a dedicated hardware interface;

[0026] S2. The security chip verifies the legality of stablecoin transaction parameters according to a preset strategy, the strategy including the target blockchain network identifier, stablecoin type, receiving address format, and transaction amount threshold;

[0027] S3. If the verification passes, the identity and transaction content are signed using the identity private key and the one-time transaction private key. The identity private key is associated with the CA digital certificate, and the transaction object can verify the identity of the transacting party through the public key in the digital certificate. Based on the private key dynamically generated by the true random number, the transaction data is digitally signed using the post-quantum cryptography algorithm, and the private key is destroyed immediately after signing is completed.

[0028] S4. Generate a dynamic verification code based on the true random number, combine the digital signature with the dynamic verification code generated based on the true random number into composite verification information, and output it to an external terminal through a secure communication channel, wherein the dynamic verification code is used to prevent replay attacks and man-in-the-middle tampering.

[0029] The present invention has the following advantages over the prior art:

[0030] First, security is significantly improved. The true random numbers generated in real time by the quantum random number chip based on quantum physical processes (such as quantum tunneling effect) have randomness that originates from the intrinsic uncertainty of the microscopic world. They are unpredictable, unreproducible, and resistant to external interference, which fundamentally eliminates the risk of key derivability caused by pseudo-true random numbers or weak entropy sources.

[0031] Secondly, the truly random number is transmitted directly to the security chip via a dedicated hardware interface, bypassing the general-purpose bus or main control processor, effectively blocking man-in-the-middle eavesdropping and side-channel attack paths. Building on this, the security chip uses a standardized post-quantum algorithm to digitally sign transactions, ensuring the confidentiality and integrity of transaction data even in the face of future large-scale quantum computer algorithm attacks.

[0032] This invention integrates multiple systems, multiple chips, and built-in and external random number sources, avoiding the problems of single random number source system, rigid usage, and easy occurrence of single system failure, single point of failure, and external side-channel attacks in previous security systems.

[0033] Crucially, the system employs a "one-time private key" mechanism—the private key is dynamically generated and immediately destroyed at the moment of signing, ensuring that no static private key remains in the device. Combined with a dual-chip physical isolation architecture and anti-tampering circuitry (which triggers key clearing upon detection of anomalies), this significantly enhances the device's resistance to physical disassembly and reverse engineering, forming a secure closed loop across the entire chain from the key source and transmission channel to computation and execution. The flexible combination of authentication private keys and one-time private keys used in this invention is more convenient for offline signature transactions via NFC / Bluetooth communication in situations without a network connection.

[0034] Furthermore, this invention boasts outstanding adaptability. Unlike general-purpose blockchain wallets, it integrates a dedicated stablecoin compliance module within its security chip. This module performs multi-dimensional legality verification of transaction parameters based on preset strategies, including the target blockchain network identifier, stablecoin type (USDT, USDC, DAI, digital RMB, etc.), receiving address format, and dynamic transaction amount thresholds. This design not only effectively prevents financial losses due to incorrect addresses or chain mismatches but also proactively responds to regulatory requirements for stablecoin transactions in major global jurisdictions (such as large transaction restrictions), filling a market gap. Simultaneously, the device is compatible with national cryptographic standards (SM2, SM3, SM4, SM7, SM9), traditional (RSA, AES), and post-quantum algorithms. It supports multiple communication interfaces such as USB, NFC, and Bluetooth, allowing seamless integration with wallet apps and trading platforms across different ecosystems. This achieves true "one shield for multiple chains, one shield for multiple coins," significantly enhancing the product's applicability and scalability in complex financial scenarios.

[0035] Finally, this invention is highly practical, balancing high security with ease of use and reducing user migration costs. Specifically, it is implemented in the form of a security shield, making it compact, portable, and compatible with the usage habits of mobile financial terminals. Through low-power design and an intelligent sleep mechanism, it effectively extends battery life, making it suitable for extended outdoor or travel scenarios. At the interaction level, it retains the familiar button confirmation and screen display operation process, and innovatively introduces a tiered verification strategy combining biometrics (fingerprint / vein) and PIN codes—convenient and fast for small transactions, and multiple layers of protection for large transactions, improving security without sacrificing user experience. The overall operating logic is highly consistent with traditional USB tokens, allowing financial institutions and individual users to get started without additional training, significantly reducing the learning costs and deployment resistance of migrating from traditional security devices to quantum-resistant security devices. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0037] Figure 1 This is a schematic diagram of the overall module structure of an embodiment of the present invention;

[0038] Figure 2 This is a diagram of the hybrid true random number generation architecture of an embodiment of the present invention;

[0039] Figure 3 This is an application of true random number generation and post-quantum algorithms in embodiments of the present invention. Detailed Implementation

[0040] The technical solutions of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0041] like Figure 1 The diagram shown is a schematic representation of the overall module structure of an embodiment of the present invention, illustrating the physical connection relationship between the quantum random number chip, the dedicated high-speed interface, and the security chip. Figure 1 It is understood that the present invention provides a stablecoin e-wallet security shield based on dual-chip collaboration, comprising:

[0042] The quantum random number chip and the traditional random number chip are configured to generate true random numbers in real time based on quantum physics and traditional thermal noise processes. The true random numbers are directly transmitted to the security chip via a dedicated high-speed interface without going through an external general-purpose bus. The dedicated high-speed interface adopts a hardware isolation design with a bandwidth of not less than 2Mbps to prevent bus eavesdropping and side-channel attacks.

[0043] The quantum random number chip integrates at least two non-quantum physical random sources, including thermal noise and chaotic noise sources; at the same time, the security chip also integrates an independent physical true random number source; finally, the true random number is jointly input into the CSPRNG module by the external multi-source fusion output and the internal true random number source output, and is reseeded before each transaction to ensure forward security.

[0044] In one implementation, such as Figure 2 The diagram illustrates the hybrid true random number generation architecture of this invention, showcasing the fusion process of quantum source, thermal noise source, and chaotic noise source. The quantum random number chip of this invention utilizes a silicon-based quantum dot structure to achieve the quantum tunneling effect, serving as the core entropy source for real-time generation of true random numbers. The chip integrates three random sources: a quantum tunneling circuit, a thermal noise source circuit, and a chaotic circuit. All data processing is completed at the hardware level, ensuring real-time performance and security without software intervention.

[0045] Specifically, the quantum tunneling effect is achieved using a 5nm×5nm gallium phosphide (GaP) quantum dot array (density). (points / cm²). When a bias voltage of 3.3V is applied, the electron tunneling probability follows a Boltzmann distribution, with a mean tunneling current μ=2.1μA and a standard deviation σ=0.3μA. The output raw bitstream rate reaches 20Mbps, and the entropy value is stable at 0.995bit / byte as verified by NIST SP 800-90B testing.

[0046] The hybrid entropy data stream is verified in real time by a true random number detection circuit, which strictly adheres to the GB / T 33133-2016 standard: the frequency test pass condition is 0 / 1 distribution deviation ≤ 0.01% (measured value 0.008%), the run test pass condition is longest run ≤ 12 (measured value 11.2), and the autocorrelation test pass condition is absolute value of correlation coefficient ≤ 0.005 (measured value 0.003). If the detection passes, the hybrid entropy data stream is directly output as the CSPRNG seed; if the detection fails (e.g., instantaneous fluctuations in the quantum source cause the entropy value to drop to 0.97), the hardware automatically resamples. After 100,000 transaction tests, the entropy value compliance rate of this fusion mechanism is 99.8%, and all failure scenarios are adaptively handled by the system.

[0047] The quantum random number chip communicates with the security chip via a dedicated interface. The interface circuitry is physically isolated from the external bus (PCIe / USB) and is wrapped with a 0.5mm copper foil electromagnetic shielding layer, achieving a shielding effectiveness of ≥60dB to ensure no external signal leakage. The interface incorporates a clock randomization circuit (clock frequency randomly jittered within 100~110MHz ±5MHz) and a signal shielding layer (differential line spacing ≥0.5mm). Having passed IEC 61000-4-3 Level 3 electromagnetic interference testing (3V / m), the side-channel attack success rate is reduced to 0.001%. The measured data transmission bandwidth is 25Mbps (≥20Mbps requirement), with a 1000-byte data transmission latency of 8.2μs, meeting the real-time requirements of transactions. The transmission process does not involve any external general-purpose bus.

[0048] This embodiment of the quantum random number chip is implemented at the hardware level through the quantum tunneling effect. Combined with random number quality detection and an LVDS isolation interface, it solves the problems of entropy fluctuation, transmission security, and real-time performance in quantum true random number generation. All technical parameters have been verified through chip-level testing: entropy compliance rate of 99.8% (100,000 tests), transmission latency of 8.2μs, and side-channel attack success rate of 0.001%. This invention achieves high-entropy, high-security true random number generation through deep collaboration between the quantum random number chip and the security chip, combining multi-source entropy fusion, hardware-isolated transmission, and a dynamic reseeding mechanism. It can effectively resist quantum computing attacks and traditional side-channel threats, meeting the needs of cryptographic applications in the post-quantum era.

[0049] In one implementation, the security chip is directly connected to the quantum random number chip and the traditional random number chip via a dedicated high-speed interface. The security chip integrates: a main control module for system scheduling and communication control; a random number module that generates random numbers using a mechanism different from that of external random number chips; a cryptographic algorithm module that supports post-quantum cryptography, national cryptographic algorithms, and traditional cryptographic algorithms; a private key generated based on the true random number during transaction configuration, which is used to digitally sign the transaction data, and the private key is destroyed immediately after signing; the cryptographic algorithm module includes at least one of the CRYSTALS-KYBER key encapsulation algorithm, Dilithium, SPHINCS+, or Rainbow digital signature algorithm; national cryptographic algorithms include SM2, SM3, SM4, SM7, and SM9; and traditional cryptographic algorithms include RSA, AES, and SHA2.

[0050] Specifically, such as Figure 3 The illustration shows the application of true random numbers in post-quantum algorithms according to an embodiment of the present invention, demonstrating how the CSPRNG provides true random numbers for the Kyber and Dilithium algorithms. The quantum random number chip is used to generate true random numbers (Seeds), which serve as the seed input for the Cryptographically Secure Pseudo-Random Number Generator (CSPRNG). The CSPRNG uses the Seeds as an entropy source to generate cryptographically strong true random numbers for the randomness requirements of post-quantum cryptographic algorithms and other processes.

[0051] In post-quantum cryptography algorithms, (Key encapsulation mechanism based on the module learning difficulty problem, KEM) and (Taking a digital signature algorithm based on the module learning difficulty and small integer solution problem) as an example:

[0052] Kyber Key Generation: The true random numbers output by CSPRNG are used to construct the matrix A required by the algorithm, ensuring the randomness and security of the key pair (public key and private key).

[0053] Kyber encryption: True random numbers generated by CSPRNG are used to generate error vector r. By randomly perturbing the same plaintext, different ciphertexts are generated after encryption, thus resisting known plaintext attacks.

[0054] Dilithium signature: CSPRNG generates a random vector y, which is used to hide the real value of the private key during signing, ensuring that the signature cannot be forged.

[0055] This true random number usage mode is universal: for other post-quantum algorithms (such as Rainbow), national cryptographic algorithms (such as SM2 signatures which require a true random number k), and traditional cryptographic algorithms (such as RSA key generation which requires a random large prime number, and AES-CTR mode which requires a random initial vector, etc.) supported by the cryptographic algorithm module in the security chip, the Seed generated by the quantum random number chip drives the CSPRNG, providing a high-quality entropy source for each algorithm, ensuring the reliability of the randomness of cryptographic operations, and resisting attacks of true random number prediction type.

[0056] The integrated security chip also includes a stablecoin compliance module, used to verify the legality of stablecoin transaction parameters according to a preset strategy. This strategy includes the target blockchain network identifier, stablecoin type, receiving address format, and transaction amount threshold. The transaction amount threshold is dynamically set based on the stablecoin type, with a single transaction limit of 1 million units for USDT and USDC, 500,000 units for DAI, and the single transaction limit for digital RMB is dynamically updated according to regulatory policies. As the core verification unit of the security chip, the stablecoin compliance module is integrated into the instruction scheduling layer of the main control module. It performs real-time verification of transaction parameters through hardware-level logic circuits, ensuring that each transaction complies with the preset security strategy. This module has a built-in dynamic strategy database containing a target blockchain network identifier mapping table, a stablecoin type-threshold mapping table, and an address format rule set. All verification logic is implemented at the hardware level, avoiding software-level latency and tampering risks.

[0057] Specifically, the system initiates the verification process upon receiving a transaction request. First, it parses the blockchain network identifier in the transaction data and compares it against a pre-stored list of network IDs. If the network identifier does not match the allowed list, a transaction termination command is immediately triggered and a security log is recorded, with a response time of ≤5μs. Stablecoin type identification is based on hardware-level hash mapping of the token contract address: the system pre-stores a standard address library. When a transaction carries a token contract address, the module quickly matches the type using a hardware hash comparator (using the SHA-3-256 algorithm), with the identification process taking ≤3μs, ensuring 100% accuracy in distinguishing between USDT / USDC and DAI. The receive address format verification uses a configurable hardware regular expression engine with pre-defined format rules for different blockchain networks: Ethereum addresses must meet the regular expression format "^0x[0-9a-fA-F]{40}$", which requires 42 characters, starts with 0x, and is in hexadecimal. The same applies to BSC addresses. The system completes address string parsing and rule matching within 10μs. If the address format is invalid (such as length not being 42 characters or containing illegal characters), the transaction is rejected and error code 0x02 is returned. The dynamic loading mechanism for transaction amount thresholds is implemented through a secure storage area: the single transaction limit of 1 million units for USDT and USDC, and 500,000 units for DAI, are hard-coded in the chip ROM and stored in an encrypted partition (AES-256 encryption), readable only by the main control module. The digital RMB thresholds are dynamically updated according to regulatory policies. The system downloads the latest threshold configuration file from the central bank's security server every 24 hours via a secure communication interface (USB 2.0 encrypted channel). The configuration file is verified by an SM9 digital signature (the signature verification module is built into the security chip). Upon successful verification, it automatically overwrites the threshold parameters in the ROM. The update process is completed within 200ms, and the system maintains continuous operation of the transaction verification function during the update to avoid service interruption. In a test of 100,000 real transactions, the module achieved a verification pass rate of 99.995%, an average processing latency of 12.3μs, and successfully intercepted 99.98% of abnormal transactions (such as transactions with incorrect network identifiers, invalid address transactions, and transactions exceeding the threshold). The dynamic update mechanism for digital RMB thresholds has passed the central bank's security testing and certification, ensuring regulatory compliance. All verification logic is implemented through a hardware state machine, with no software dependency, completely eliminating the risk of strategy bypass due to operating system vulnerabilities, and providing a real-time and reliable security barrier for stablecoin transactions.

[0058] In addition, the security chip integration also includes a verification output module, configured to generate a dynamic checksum based on the true random number after the transaction signature is completed, and combine the digital signature and the dynamic checksum into composite verification information, which is then output to an external terminal through a secure communication channel to prevent replay attacks and man-in-the-middle tampering. As the terminal output unit of the security chip, the verification output module generates a 64-bit dynamic checksum in real time after the transaction signature is completed through hardware-level logic circuitry, ensuring the non-replayability and tamper-proof nature of the composite verification information.

[0059] Specifically, this module is directly integrated into the output interface layer of the security chip, requiring no external software; all operations are completed at the hardware level. When a transaction signature is complete, the module immediately obtains the current true random number (entropy ≥ 0.995 bit / byte) from the CSPRNG module, processes it using the built-in SM3 hash engine, and extracts the first 64 bits as a dynamic checksum. Verified by NIST SP800-22, the randomness deviation is ≤ 0.001%. Checksum generation takes ≤ 5μs and is concatenated with the digital signature at the hardware level to form a 320-bit composite verification message, formatted as a 64-bit checksum of the signature data. The composite message is output through a hardware-encrypted USB 2.0 secure communication channel. The channel incorporates an AES-256 encryption engine (with a dynamically generated key from the PUF) and an HMAC-SM3 message authentication code to ensure confidentiality and integrity during transmission. The system generates a unique dynamic checksum for each transaction, based on the transaction hash value and a millisecond-level timestamp. In a test of 100,000 transactions, the checksum repetition rate was only [percentage missing]. The success rate of replay attacks is close to zero. In stablecoin transactions, the external terminal receives the data and simultaneously verifies the HMAC and compares the checksum. If they do not match, the transaction is automatically rejected, effectively blocking 99.999% of man-in-the-middle attacks. The module's end-to-end processing latency is ≤15μs (from signature completion to output), and it has passed financial-grade security certification. All operations are completed within the secure chip, with no external dependencies, fully meeting the technical requirements for replay and tamper-proof protection.

[0060] In one embodiment, the safety shield further includes:

[0061] The storage module is used to store private keys, public keys, device keys, certificates, system programs, and configuration information.

[0062] Specifically, the storage module uses hardware-encrypted eMMC 5.1 flash memory, integrated into the on-chip storage area of ​​the secure chip. The public key is stored in an AES-256 encrypted secure partition; the key is seeded by a random number source and dynamically generated using a Physically Unclonable Function (PUF). The system program is stored in a read-only ROM partition (with hash values ​​verified via a secure boot mechanism), and configuration information is stored in an OTP one-time programmable area. All storage operations are processed through a built-in SM4 hardware encryption engine, with read / write latency ≤10μs. In 100,000 stress tests, the data integrity error rate was 0.0001%, meeting financial-grade security requirements.

[0063] Communication interfaces include USB, NFC, and Bluetooth;

[0064] The random number module uses a mechanism different from that of external random number chips to generate random numbers;

[0065] Specifically, the communication interface integrates USB 2.0, NFC, and Bluetooth 5.0 hardware units. The USB 2.0 interface uses hardware-encrypted transmission, with the AES-256 key seeded by a random number source and generated by a PUF function; the NFC interface operates at a frequency of 13.56MHz, with a transmission distance of ≤10cm, used for near-field transactions (such as mobile phone touch), and a transmission latency of ≤30ms; the Bluetooth interface supports BLE 5.0, operates on a frequency band of 2.4GHz, has a transmission distance of 10m, and a connection establishment time of ≤100ms. All interfaces have built-in hardware security channels to prevent man-in-the-middle attacks (data integrity is verified via SM3-HMAC), and no data leakage was detected in 100,000 communications.

[0066] The human-computer interaction module includes buttons, a display screen, and biometric sensors, which are used to collect user input and output transaction status.

[0067] The biometric sensor is used to collect the user's fingerprint or vein information; when the transaction amount is less than 1,000 yuan, only PIN code verification is required; when the transaction amount is greater than or equal to 1,000 yuan, biometric verification is required before the transaction can be executed.

[0068] Specifically, the human-computer interaction module includes five capacitive touch buttons (with anti-accidental touch circuitry), a 128×64 pixel OLED display, and biometric sensors (fingerprint sensor: FPC1020, vein recognition: HID-VEIN 2.0). For transactions less than 1000 RMB, only a 4-6 digit PIN code is required; for transactions 1000 RMB or more, biometric recognition is triggered: the fingerprint sensor acquires a 500dpi image with a matching accuracy of ≥95%, and the vein sensor acquires a 300dpi vein image with a matching accuracy of ≥96%. The biometric response time is ≤300ms, with a 99.5% pass rate after 100,000 tests. All user input is transmitted encrypted via a secure channel (AES-256) to prevent side-channel eavesdropping.

[0069] The security protection structure includes an electromagnetic shielding shell and an anti-tampering circuit, wherein the anti-tampering circuit triggers key destruction when physical intrusion is detected.

[0070] The anti-tampering circuit in the security protection structure is configured such that once physical disassembly or abnormal electromagnetic interference is detected, a key destruction command is immediately triggered to clear all sensitive data.

[0071] Specifically, the security protection structure includes a 0.5mm copper foil electromagnetic shielding shell (shielding effectiveness ≥60dB) and hardware-level anti-tampering circuitry. The anti-tampering circuitry integrates physical intrusion sensors and electromagnetic interference sensors. Once triggered, it immediately erases sensitive data via hardware commands: AES keys and private keys in the secure storage area are erased via a write-to-zero operation, taking ≤1ms. In 1000 simulated physical attack tests, including shell prying and electromagnetic pulse interference, the key destruction success rate was 100%, with no residual data leakage, meeting the physical security specifications for financial devices.

[0072] This invention also provides a stablecoin e-wallet security verification method based on dual-chip collaboration, comprising the following steps:

[0073] S1. A quantum random number chip generates true random numbers in real time based on quantum physics processes and transmits them directly to a security chip through a dedicated hardware interface;

[0074] S2. The security chip verifies the legality of stablecoin transaction parameters according to a preset strategy, the strategy including the target blockchain network identifier, stablecoin type, receiving address format, and transaction amount threshold;

[0075] S3. If the verification passes, the identity and transaction content are signed using the identity private key and the one-time transaction private key. The identity private key is associated with the CA digital certificate, and the transaction object can verify the identity of the transacting party through the public key in the digital certificate. Based on the private key dynamically generated by the true random number, the transaction data is digitally signed using the post-quantum cryptography algorithm, and the private key is destroyed immediately after signing is completed.

[0076] S4. Generate a dynamic verification code based on the true random number, combine the digital signature with the dynamic verification code generated based on the true random number into composite verification information, and output it to an external terminal through a secure communication channel, wherein the dynamic verification code is used to prevent replay attacks and man-in-the-middle tampering.

[0077] This invention is based on a dual-chip collaborative architecture: a quantum random number chip generates truly random numbers by fusing three physical random sources—silicon-based quantum dot tunneling effect, thermal noise source, and chaotic circuit—and after hardware-level SM3 detection, transmits the data directly to the security chip via a dedicated LVDS high-speed interface, without passing through an external bus. The security chip's CSPRNG module uses this truly random number as a seed to dynamically generate a private key, which is used for signing transaction data using a post-quantum cryptographic algorithm. Immediately after signing, a hardware zeroing command is triggered to destroy the private key. Simultaneously, a stablecoin compliance module verifies the target blockchain network identifier, stablecoin type, receiving address format, and transaction amount threshold in real time. The verification output module uses the truly random number input SM3 hash algorithm to extract the first 64 bits to generate a dynamic checksum, which is combined with the digital signature to form a 320-bit composite verification message. This message is output to an external terminal via a hardware-encrypted USB 2.0 channel, ensuring anti-replay and anti-tampering protection. All operations are completed at the hardware level, with an end-to-end processing latency of ≤15ms, meeting financial-grade security requirements.

[0078] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A stablecoin e-wallet security shield based on dual-chip collaboration, characterized in that, include: Quantum random number chip, traditional random number chip, is configured to generate true random numbers in real time based on quantum physics and traditional thermal noise processes, and transmit the true random numbers directly to the security chip via a dedicated high-speed interface without going through an external general bus; The security chip is directly connected to the quantum random number chip and the traditional random number chip via a dedicated high-speed interface; the security chip integrates: The main control module is used for system scheduling and communication control; The random number module uses a mechanism different from that of external random number chips to generate random numbers; The cryptographic algorithm module supports post-quantum cryptography, national cryptographic algorithms, and traditional cryptographic algorithms; it configures a private key generated based on the true random number during transactions and uses the private key to digitally sign transaction data. The stablecoin compliance module is used to verify the legality of stablecoin transaction parameters according to a preset strategy, which includes the target blockchain network identifier, stablecoin type, receiving address format, and transaction amount threshold. The verification output module is configured to generate a dynamic verification code based on the true random number after the transaction signature is completed, and combine the digital signature with the dynamic verification code into composite verification information, which is then output to an external terminal through a secure communication channel to prevent replay attacks and man-in-the-middle tampering.

2. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 1, characterized in that, The security shield also includes: The storage module is used to store private keys, public keys, device keys, certificates, system programs, and configuration information. Communication interfaces include USB, NFC, and Bluetooth; The human-computer interaction module includes buttons, a display screen, and biometric sensors, which are used to collect user input and output transaction status. The security protection structure includes an electromagnetic shielding shell and an anti-tampering circuit, wherein the anti-tampering circuit triggers key destruction when physical intrusion is detected.

3. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 1, characterized in that, The cryptographic algorithm module includes at least one of the following: CRYSTALS-KYBER key encapsulation algorithm, Dilithium, SPHINCS+, or Rainbow digital signature algorithm.

4. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 1, characterized in that, The quantum random number chip integrates at least two non-quantum physical random sources, including thermal noise and chaotic noise sources; at the same time, the security chip also integrates an independent physical true random number source; finally, the true random number is jointly input into the CSPRNG module by the external multi-source fusion output and the internal true random number source output, and is reseeded before each transaction to ensure forward security.

5. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 1, characterized in that, The transaction amount thresholds are dynamically set according to the type of stablecoin. The single transaction limit for USDT and USDC is 1 million units, the single transaction limit for DAI is 500,000 units, and the single transaction limit for digital RMB is dynamically updated according to regulatory policies.

6. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 2, characterized in that, The biometric sensor is used to collect the user's fingerprint or vein information; when the transaction amount is less than 1,000 yuan, only PIN code verification is required; when the transaction amount is greater than or equal to 1,000 yuan, biometric verification is required before the transaction can be executed.

7. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 1, characterized in that, The dedicated high-speed interface adopts a hardware isolation design with a bandwidth of no less than 2Mbps to prevent bus eavesdropping and side-channel attacks.

8. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 1, characterized in that, The national cryptographic algorithms include SM2, SM3, SM4, SM7, and SM9; the traditional cryptographic algorithms include RSA, AES, and SHA2.

9. The stablecoin e-wallet security shield based on dual-chip collaboration as described in claim 2, characterized in that, The anti-tampering circuit in the security protection structure is configured such that once physical disassembly or abnormal electromagnetic interference is detected, a key destruction command is immediately triggered to clear all sensitive data.

10. A stablecoin e-wallet security verification method based on dual-chip collaboration, applied to the security shield as described in any one of claims 1-9, characterized in that, Includes the following steps: S1. A quantum random number chip generates true random numbers in real time based on quantum physics processes and transmits them directly to a security chip through a dedicated hardware interface; S2. The security chip verifies the legality of stablecoin transaction parameters according to a preset strategy, the strategy including the target blockchain network identifier, stablecoin type, receiving address format, and transaction amount threshold; S3. If the verification passes, the identity and transaction content are signed using the identity private key and the one-time transaction private key. The identity private key is associated with the CA digital certificate, and the transaction object can verify the identity of the transacting party through the public key in the digital certificate. Based on the private key dynamically generated by the true random number, the transaction data is digitally signed using the post-quantum cryptography algorithm, and the private key is destroyed immediately after signing is completed. S4. Generate a dynamic verification code based on the true random number, combine the digital signature with the dynamic verification code generated based on the true random number into composite verification information, and output it to an external terminal through a secure communication channel, wherein the dynamic verification code is used to prevent replay attacks and man-in-the-middle tampering.