Serial number-specific blockchain support for mobile portable devices

DE502022004291D1Active Publication Date: 2025-07-10BUNDESDRUCKEREI GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502022004291
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-03-24
Filing Date
2022-03-22
Publication Date
2025-07-10
Estimated Expiration
2042-03-22

AI Technical Summary

Technical Problem

Existing payment methods lack an efficient and secure way to process cashless payments using mobile portable terminals, particularly in scenarios where traditional banknotes cannot facilitate distant transactions.

Method used

A method utilizing a blockchain system with multiple blockchains, each managing payments from banknotes with specific serial numbers, allowing for parallel processing of payments across different blockchains based on serial number ranges.

Benefits of technology

Enables efficient and secure cashless payments by parallelizing payment processing across multiple blockchains, reducing transaction time and increasing system throughput.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to payment methods using mobile portable terminals, in particular banknotes, with serial number-specific blockchain support, as well as a computer system and system for carrying out the method.

[0002] With increasing digitalization, cashless payment instruments are increasingly gaining traction, particularly those based on electronic payment processing methods. Cashless payments involve the transfer of payment instruments without the transfer of cash. Cash payments involve the exchange of cash, i.e., banknotes or coins, between the payer and the payee, whereas cashless payments do not involve such an exchange of cash.

[0003] Cash, for example, has the advantage of being available to everyone and can be used quickly and anywhere. For example, cash-based payment processing doesn't require a bank account. Furthermore, cash is often valued by its owners as a store of value.

[0004] Cashless payment methods, on the other hand, have the advantage of enabling efficient payment processing even when the payer and payee are located far away, as is the case with online purchases, for example. This is something that conventional banknotes cannot achieve.

[0005] WO 2021 / 245244 A2 describes a banknote with a security element comprising a processor and a memory. A private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address in a blockchain. A payment method executed with the banknote comprises receiving a payment request for a payment with the banknote in the form of a transaction of an amount to be paid from the banknote's blockchain address to a blockchain address of a payment recipient, signing a transaction authorization with the banknote's private cryptographic key, and sending the signed transaction authorization.

[0006] WO 2017 / 182601 A1 describes an electronic method for the cryptographically secure transfer of a cryptocurrency amount by means of a transaction of the amount from a source address assigned to a first client to a destination address assigned to a second client. A plurality of clients is provided, comprising at least the first and second clients. A wallet program for implementing a client node of the cryptocurrency is installed on each client. Furthermore, a transaction server is provided on which a transaction program for implementing a server node of the cryptocurrency is installed. The transaction program is configured to generate blockchain blocks with transaction data.The transaction server comprises a private and a public server key of an asymmetric server key pair as well as a server certificate of a hierarchical PKI with a central root certification authority, which is configured to serve as proof of the authenticity of the public server key and the authorization of the transaction server to generate blocks of the blockchain.

[0007] The invention is therefore based on the object of creating an improved payment method with a mobile portable terminal.

[0008] The problem underlying the invention is solved by the features of the independent patent claims. Embodiments of the invention are specified in the dependent patent claims.

[0009] Embodiments include a method for executing a payment using a first mobile portable terminal of a plurality of mobile portable terminals and a blockchain system. The blockchain system comprises a plurality of blockchains. Each of the blockchains is assigned one or more blockchain servers, which manage the corresponding blockchain. Each of the mobile portable terminals of the plurality of mobile portable terminals is assigned a serial number from a space of serial numbers. The space of serial numbers is divided into a plurality of ranges of serial numbers. Each of the ranges of serial numbers is assigned one of the blockchains of the blockchain system, which logs payments from banknote-specific blockchain addresses assigned to mobile portable terminals with serial numbers from the corresponding range of serial numbers.

[0010] The procedure includes:Receiving a message from the first mobile portable terminal with a transaction authorization, wherein the transaction authorization is signed using a banknote-specific private cryptographic key of an asymmetric key pair of the first mobile portable terminal, wherein the asymmetric key pair is assigned to a banknote-specific first blockchain address of the first mobile portable terminal, wherein the transaction authorization comprises the first blockchain address of the first banknote, a second blockchain address of the payee, and an amount to be paid. Determining, using a first serial number of the first banknote comprising the message, a first blockchain of the plurality of blockchains that is assigned to the range of serial numbers that includes the first serial number. Forwarding the message to a first blockchain server that manages the determined first blockchain.to verify and enter the transaction released by the transaction release into the first blockchain. ,

[0011] Embodiments may have the advantage of enabling cashless payment using the mobile portable terminal. When used for cashless payment, i.e., without handing over a banknote or transferring ownership of the banknote, the payment is made by providing a signed transaction release, i.e., a transaction authorization, by the mobile portable terminal. This signed transaction release of the mobile portable terminal authorizes a transaction or releases the transaction, in which the amount to be paid is transferred from a blockchain address of the mobile portable terminal to the blockchain address of the payment recipient.

[0012] Even in the case of a mobile, portable device in the form of a banknote, this is a cashless payment, since the banknote itself authorizes the payment but is not handed over. Serial numbers can be any type of ordered number, i.e., sequences of numbers and / or letters.

[0013] Payment processing is carried out in a cryptographically secure manner using blockchain technology. However, this does not involve a single blockchain; rather, a blockchain system is used that comprises several blockchains. Each of these blockchains is responsible for processing payments from specific mobile devices. For this purpose, the mobile devices used are divided into quotas based on their assigned serial numbers. A separate blockchain is responsible for each of these quotas. This can have the advantage that payments with back notes that belong to different quotas and are therefore assigned to different blockchains can be processed simultaneously, i.e. in parallel, by the corresponding blockchains. This means that the processing of payments with the mobile devices can be parallelized.Each blockchain is assigned one or more blockchain servers that manage the corresponding blockchain. In other words, the blockchain servers of different blockchains are independent of each other and can manage their respective blockchains in parallel.

[0014] Such parallelization can increase the efficiency of payment processing, in particular, throughput time, i.e. the time required to process a payment, can be shortened.

[0015] The mobile devices are divided into quotas based on their assigned serial numbers. For this purpose, the range of serial numbers assigned to the mobile devices in use is divided into ranges. Each of these serial number ranges corresponds to a quota of banknotes whose serial numbers are included in the corresponding range. Each of the serial number ranges is assigned to one of the blockchains of the blockchain system. Payments are entered into this blockchain from banknote-specific blockchain addresses assigned to mobile devices with serial numbers from the corresponding serial number range.

[0016] For effective parallelization, the transaction approvals from each mobile portable device must be routed to the blockchain server responsible for the blockchain that manages the range of serial numbers that includes the serial number of the respective mobile portable device generating the transaction approval. For this purpose, the message from the mobile portable device containing the transaction approval includes the serial number of the corresponding banknote. The serial number can be part of the transaction approval information, for example, if the serial number is used as the blockchain address of the mobile portable device. Likewise, the message can include the serial number of the mobile portable device in addition to the transaction approval. For example, the serial number of the mobile portable device can be provided in a message header.This is advantageous, for example, if the content of the message, in particular the transaction approval, is encrypted. Using the serial number provided by the message, the blockchain of the plurality of blockchains is determined which is assigned to the range of serial numbers that includes the specified serial number. This blockchain is managed by one or more blockchain servers. The message is then forwarded to a blockchain server for verification and entry of the transaction approved by the transaction approval into the specific blockchain. If the specific blockchain is managed by multiple blockchain servers, the message can, for example, be forwarded to the nearest blockchain server.

[0017] Based on the serial number, the message is then forwarded to the responsible blockchain server. The message can be forwarded, for example, directly on site by a terminal computer system, such as a point of sale, or by a server to which the terminal computer system sends a received message for forwarding. Alternatively, a payment can be made via a network, such as the Internet, where a user sends the message to a server for further payment processing using a user computer system. The corresponding server then forwards the message. Forwarding can also be done by a blockchain server of the blockchain system, which first checks, for example, whether it itself or the blockchain it manages is responsible for the serial number provided by the message.If the responsible blockchain is not responsible, the responsible blockchain is identified and the message is forwarded to one of the blockchain servers of the responsible blockchain.

[0018] The payment can be made, for example, on-site at a point of sale, such as at a terminal, or online, for example, via the user's computer system that communicates over the Internet and sends the message authorizing the transaction to a server, such as a service server. The service server can, for example, be a server that provides a service that the user wishes to use for a fee. The service can also be a payment service server that processes a payment in the form of a transaction for a third party.

[0019] According to embodiments, the blockchain servers check other blockchains of the majority of blockchains for consistency in their free time, ie when they are not busy checking and entering transactions into their own blockchain.

[0020] According to embodiments, the blockchains are managed by a central bank issuing the banknotes. For example, the blockchains can be regionally or nationally assigned, particularly if the serial number ranges are regionally or nationally assigned. If banknotes with specific serial numbers are issued in specific regions or countries, this can have the advantage that, for example, payments are made statistically more frequently between banknotes or using banknotes that are assigned to the same serial number range and are therefore processed using the same blockchain. In this case, for example, the blockchain address of the banknote and the blockchain address of the payment recipient can with a high probability be assigned to the same blockchain.

[0021] According to embodiments, the first mobile portable terminal is a first banknote issued by a central bank. The first blockchain address is a banknote-specific blockchain address. The private cryptographic key is a banknote-specific private cryptographic key of a banknote-specific asymmetric key pair. Embodiments may have the advantage that the mobile portable terminal can be a banknote.

[0022] According to embodiments, the private cryptographic key of the first mobile portable terminal is a derived private cryptographic key of a blockchain address, which is dependent on a blockchain address of a second banknote. The second banknote comprises a security element with a processor and a memory with program instructions. The blockchain address of the second banknote is stored in the memory of the security element. A banknote-specific cryptographic key of the second banknote is stored in a protected memory area of ​​the memory of the security element of the second banknote.

[0023] Deriving the private cryptographic key of the first mobile portable terminal includes: Receiving a derivation request for deriving the private cryptographic key for the first mobile portable terminal by the second banknote, initiating a derivation of the private cryptographic key for the first mobile portable terminal using a one-way function and the banknote-specific cryptographic key of the second banknote, sending the first serial number to the first mobile portable terminal by the second banknote.

[0024] For example, mobile portable devices that are not banknotes are each based on at least one banknote, which provides the private cryptographic key of the corresponding mobile portable device. For example, the serial number of the mobile portable device is each derived from a serial number of a banknote. For example, the derived serial number is the serial number of the banknote with an additional number. For example, this derived serial number is assigned to the same range of serial numbers as the serial number of the banknote. For example, additional serial numbers are stored in the banknote memories, which are issued to the mobile portable devices during the derivation process. Thus, for example, a banknote can only derive private cryptographic keys for as many mobile portable devices as it contains serial numbers.

[0025] According to embodiments, the second banknote derives the private cryptographic key for mobile portable terminal using the banknote-specific cryptographic key of the second banknote and sends the derived private cryptographic key to the first mobile terminal in response to the derivation request.

[0026] Embodiments can have the advantage that the key is derived on the second banknote. Only the derived key is visible to the outside world. Without the second banknote, there is therefore no way to access the derived key.

[0027] The one-way function is a key derivation function, a so-called "key derivation function" (KDF). This performs a cryptographic operation that generates one or more additional cryptographic keys as output values ​​from a cryptographic key as input. Using a derived cryptographic key can have the advantage that an attacker who gains access to the derived key cannot obtain any useful information about the original cryptographic key or any of the other derived cryptographic keys.

[0028] According to embodiments, the second banknote additionally derives a public cryptographic key associated with the derived private cryptographic key for the first mobile portable terminal and sends the derived private cryptographic key to the first mobile portable terminal as part of a resulting first asymmetric key pair.

[0029] Embodiments may have the advantage that, in addition to the private cryptographic key from the banknote, an associated derived public cryptographic key is provided. The first mobile portable terminal thus receives, for example, a derived asymmetric key pair. The derived public key can be used to generate the blockchain address of the first mobile portable terminal. Deriving a blockchain address comprises, for example, applying a hash function to the public cryptographic key, which serves as the input value.

[0030] According to embodiments, the first mobile portable terminal uses the derived private cryptographic key to calculate the associated public cryptographic key. Embodiments may have the advantage that the first mobile portable terminal has full control over the use of the derived private cryptographic key. The public cryptographic key is generated from the private cryptographic key, for example, using elliptic curves.

[0031] According to embodiments, the banknote calculates an input value for the one-way function for deriving the private cryptographic key for the first mobile portable terminal from the banknote-specific cryptographic key and sends the resulting input value for deriving the first private cryptographic key by the first mobile portable terminal to the first mobile portable terminal in response to the derivation request.

[0032] Embodiments may have the advantage of enabling the first mobile, portable terminal to derive the private cryptographic key. The banknote provides a derived input value for this purpose. The banknote's cryptographic key thus remains securely stored on the banknote.

[0033] According to embodiments, the method further comprises deriving the private cryptographic key for the first mobile portable terminal by the first mobile portable terminal using the one-way function and the received input value. Embodiments may have the advantage that the derivation of the private cryptographic key is performed by the first mobile portable terminal.

[0034] According to embodiments, the first mobile portable terminal derives the private cryptographic key together with an associated public cryptographic key as an asymmetric key pair for the first mobile portable terminal. Embodiments may have the advantage that, in addition to the private cryptographic key, an associated derived public cryptographic key is provided by the first mobile portable terminal. The computer system thus has, for example, a derived asymmetric key pair.

[0035] According to embodiments, the banknote-specific cryptographic key of the second banknote is a private cryptographic key of an asymmetric key pair of the second banknote.

[0036] According to embodiments, the message includes the first serial number of the first mobile portable terminal in a header. Embodiments may have the advantage that the serial number is easily accessible for addressing the message, particularly if, for example, the remainder of the message, in particular the transaction authorization, is encrypted. For example, the transaction authorization may be a cryptogram, i.e., an encrypted data element, or a signed payload.

[0037] According to some embodiments, the first blockchain address is the first serial number of the first banknote. Some embodiments may have the advantage that the information necessary for forwarding the message is already available by specifying the blockchain address.

[0038] According to embodiments, the first blockchain address is derived from the first serial number of the first mobile portable terminal.

[0039] According to embodiments, a public cryptographic key of the asymmetric key pair of the first mobile portable terminal is assigned to the first blockchain address by a transaction initializing the first blockchain address, with which the public cryptographic key of the asymmetric key pair of the first mobile portable terminal is entered into the first blockchain.

[0040] Embodiments may have the advantage that a blockchain address, which serves as an account ID in the blockchain to identify the payer and payee of a transaction, does not have to correspond to or be derived from the public cryptographic key of the mobile portable device. For example, the serial numbers of the mobile portable device can also serve as blockchain addresses. Thus, the transactions entered into a blockchain of the plurality of blockchains would, for example, each specify serial numbers as originating or output addresses, which lie within the range of serial numbers to which the corresponding blockchain is assigned.

[0041] For a cryptographic binding of the blockchain address or serial number of a mobile device to the asymmetric key pair of the corresponding mobile device, an initializing transaction to the corresponding blockchain address can be used, for example, which includes the public cryptographic key of the corresponding asymmetric key pair. Upon entry of the initializing transaction, the blockchain address or serial number is assigned to the asymmetric key pair. For example, the initializing transaction is initiated from a blockchain address or serial number assigned to a central bank that manages the corresponding blockchain.

[0042] According to embodiments, the first blockchain address is the public cryptographic key of the asymmetric key pair of the first banknote. According to embodiments, the first blockchain address is derived from the public cryptographic key of the asymmetric key pair of the first mobile portable terminal.

[0043] According to embodiments, the first serial number is assigned to the first blockchain address by an initial transaction to the first blockchain address, with which the first serial number is entered into the first blockchain.

[0044] In this case, the blockchain address is cryptographically bound to the asymmetric key pair of the corresponding banknote, but not to the serial number. For an additional cryptographic binding of the blockchain address to the serial number assigned to the mobile device, an initializing transaction to the corresponding blockchain address containing the serial number can be used, for example. Upon entry of the initializing transaction, the blockchain address is assigned to the serial number. For example, the initializing transaction originates from a blockchain address or serial number assigned to a central bank that manages the corresponding blockchain.

[0045] According to embodiments, the message is forwarded to the first blockchain server using a routing table which identifies, for each of the plurality of serial number ranges, one or more associated blockchain servers which manage the blockchain associated with the corresponding serial number range.

[0046] Embodiments may have the advantage of providing a routing table that identifies the different ranges into which the space of serial numbers is divided. For example, the corresponding ranges can be delimited as intervals by a smallest and largest serial number encompassed by the corresponding range. For example, a smallest serial number can be specified for each range, wherein the respective range includes all serial numbers that are greater than or equal to the corresponding smallest serial number and at the same time smaller than the smallest serial number of the next following range. For example, a largest serial number can be specified for each range, wherein the respective range includes all serial numbers that are less than or equal to the corresponding largest serial number and at the same time larger than the largest serial number of the immediately preceding range.For example, ranges can be specified by the beginning of the serial numbers. All serial numbers with a beginning identical to one specified in the routing table belong to this range.

[0047] Using the routing table, it is possible to determine which range of serial numbers or blockchain the serial number of a message belongs to. Furthermore, the routing table can specify one or more blockchain servers for each of the ranges, which manage the blockchain responsible for the corresponding range. Using the routing table, it is possible to determine the blockchain server to which the message should be forwarded for verification and entry.

[0048] According to embodiments, the routing table further identifies a network address of each blockchain server. Embodiments may have the advantage that, using the routing table, the message can be addressed during forwarding to the appropriate blockchain server.

[0049] According to embodiments, the routing table identifies a metric for each blockchain server. This metric defines, for example, a path length or number of forwardings until reaching the respective blockchain server. Additionally or alternatively, the metric can also consider other factors that influence the quality of the connection to the respective blockchain server. For example, these can be an available data transmission rate or connection quality. In addition to a hop count or alternatively, the metric can also consider, for example, a delay, a load, a maximum packet size (Maximum Transmission Unit / MTU), and / or the reliability of the respective connection.

[0050] In this context, a metric is generally understood to be a numerical measure of the quality of a connection when using a specific route. This measure can be determined, for example, by evaluation or measurement. Based on this value, depending on the assessment basis, the shortest route with the fewest redirects, i.e., hops, can be selected. If several blockchain servers manage the same blockchain, the blockchain server with the highest connection quality can be selected as the forwarding destination. For example, this could be the nearest blockchain server, i.e., the blockchain server with the fewest redirects.

[0051] According to embodiments, the routing table further identifies, for each of the blockchain servers, one or more next network addresses to which a message is to be forwarded for transmission to the corresponding responsible blockchain server. Embodiments may have the advantage that, based on the routing table, a next network address for forwarding the message can be identified. According to embodiments, the routing table further identifies a metric for each of the next network addresses, i.e., for each of the possible routes.

[0052] According to embodiments, the message is received and forwarded by a terminal computer system or a server. Embodiments can have the advantage that, for example, a computer system independent of the blockchain system receives the message and, using the routing table, determines to which of the blockchain servers of the blockchain system the message is to be forwarded for further processing. Furthermore, using the routing table, for example, a route can be determined along which the message is to be forwarded to the corresponding blockchain server. The corresponding computer system can be, for example, a terminal computer system. Such a terminal computer system receives the message, for example, when paying with the mobile, portable device on site at a point of sale. According to embodiments, the routing with the routing table is carried out, for example, by the terminal computer system.Using the routing table, the terminal computer system can, for example, determine where the message should be forwarded. The corresponding computer system can, for example, be a server. The corresponding server receives the message, for example, from a terminal computer system. The terminal computer system receives corresponding messages from mobile, portable devices, for example, in the course of payments at an on-site point of sale, and forwards all received messages to the server regardless of their content or the serial numbers they contain. According to embodiments, the routing is carried out using the routing table, for example, by the server. Using the routing table, the server can, for example, determine where the message should be forwarded.The server receives the messages, determines a responsible blockchain server based on the serial numbers specified therein, and forwards the messages to the specific blockchain server.

[0053] For example, the server receives the message from a user's computer system. For example, when making a purchase over the Internet, a user uses a mobile, portable device to generate a transaction authorization to authorize a transaction. The corresponding transaction is used, for example, to pay for a service used over the Internet, such as an online purchase. The user's computer system receives a message from the mobile, portable device with the corresponding transaction authorization and forwards it to the server. The server is, for example, a service server of the service used or a payment service server of a payment service provider commissioned to process the payment.The server receives the messages, determines a responsible blockchain server based on the serial numbers specified therein, and forwards the messages to the specific blockchain server.

[0054] According to embodiments, the message is received and forwarded by a blockchain server of the blockchain system. For example, the messages are first sent to the blockchain system and only then forwarded by the receiving blockchain server to the responsible blockchain server based on the serial number they contain. For example, a terminal computer system or a server that receives a message with a transaction approval from a mobile portable device always forwards the corresponding message to the same blockchain server(s) regardless of the serial number. In this case, routing is first performed, for example, by the blockchain server of the blockchain system that receives the message.

[0055] According to embodiments, routing is performed using the routing table, for example, by the blockchain server. First, the receiving blockchain server checks, for example, whether the serial number of the banknote from which the message with the transaction approval originates lies within the range of serial numbers for which the blockchain managed by the receiving blockchain server is responsible. If this is the case, the receiving blockchain server checks and enters the transaction approved by the transaction approval into the corresponding blockchain. Therefore, if the receiving blockchain server is the responsible blockchain server that manages the responsible blockchain, no forwarding occurs by the receiving blockchain server.Rather, the blockchain server checks the transaction approval and, upon successful verification, enters the transaction approved by the transaction approval into the blockchain it manages.

[0056] If the serial number is not within the range of serial numbers for which the blockchain managed by the receiving blockchain server is responsible, the receiving blockchain server uses the routing table to determine which range of serial numbers, and thus which blockchain, the serial number contained in the message belongs to. Furthermore, the routing table can be used to determine which blockchain server the message should be sent to and / or via which route. Based on this information determined by the routing table, the message is forwarded, for example, from the receiving blockchain server to the blockchain server responsible for it.

[0057] For example, a terminal computer system forwards transaction approval to a predetermined blockchain server, and only the predetermined blockchain server executes routing unless it is itself the responsible blockchain server that manages the responsible blockchain. For example, the predetermined blockchain server is a blockchain server for which there is a high or highest probability that banknotes used for payments via the corresponding terminal computer system contain serial numbers assigned to the blockchain managed by the predetermined blockchain server. Highest probability means that the probability for the corresponding blockchain server is the highest of all blockchain servers in the blockchain system, or among the highest if there are multiple blockchain servers with the same highest probability.For example, the specified blockchain server is therefore with high or highest probability the responsible blockchain server.

[0058] According to embodiments, the message is received and forwarded by a distribution server of the blockchain system. For example, the blockchain system comprises a plurality of distribution servers configured to receive and forward messages containing transaction approvals. For example, the distribution servers receive all corresponding messages and determine the responsible blockchain server for them based on the serial number they contain. According to embodiments, routing with the routing table is performed, for example, by a corresponding distribution server.

[0059] According to embodiments, the blockchain server is further configured to split one of the blockchains of the blockchain system if a predefined criterion is met. Splitting the blockchain comprises dividing the range of serial numbers assigned to the blockchain to be split into two or more sub-ranges. Each of the sub-ranges is assigned an independent blockchain during the splitting process.

[0060] Embodiments can have the advantage that the number of blockchains can be increased if necessary. This can, for example, increase the performance of the blockchains. If a blockchain is split, the resulting blockchains are each responsible for a sub-range of serial numbers that is smaller than the split range of serial numbers, i.e., comprises fewer serial numbers than this. This can, for example, reduce the load on a blockchain. Load is defined, for example, as the number of transaction approvals to be entered per unit of time. The load can also take into account, for example, a number of queries directed to the blockchain per unit of time. The queries are, for example, queries about balances assigned to serial numbers of the range to which the corresponding blockchain is assigned.Reducing the number of serial numbers for which a blockchain is responsible can reduce the load and thus, for example, increase the speed of entry for transaction approvals and / or the speed of response to queries. For example, a hint is distributed to the routing tables regarding the blockchain's division and the corresponding range of serial numbers.

[0061] For example, each blockchain of the plurality of blockchains can be split if necessary. For example, the range of serial numbers to be split is divided into two sub-ranges and the blockchain to be split is divided into two blockchains, each of which is assigned to one of the sub-ranges. For example, the range of serial numbers to be split is divided into more than two sub-ranges and the blockchain to be split is divided into a corresponding number of blockchains, each of which is assigned to one of the sub-ranges. The ranges of serial numbers, for example, each comprise a contiguous range of serial numbers, i.e., the corresponding range includes all serial numbers from a range-specific smallest serial number up to and including a range-specific largest serial number. The sub-ranges of serial numbers, for example, each comprise a contiguous sub-range of serial numbers, i.e.,the corresponding sub-ranges include all serial numbers from a sub-range-specific smallest serial number up to and including a sub-range-specific largest serial number.

[0062] According to embodiments, the blockchain server monitors a load on the blockchain. The predefined criterion is the exceeding of a predefined load threshold by a current load detected during monitoring. Embodiments can have the advantage that, during load monitoring, a dynamic decision can be made as to whether a split of the blockchain is necessary to reduce the load. For example, the predefined criterion specifies that a split occurs if the predefined threshold is already exceeded once by the current load detected during monitoring or if the corresponding threshold is constantly exceeded for a predefined period of time.For example, two thresholds are predefined. A smaller threshold must be consistently exceeded for a predefined period of time for a split to occur. A split is initiated even if the larger threshold is exceeded once. Load is defined, for example, as the number of transaction approvals to be entered per time. The load can also consider, for example, the number of queries directed to the blockchain per time. These queries are, for example, queries about balances assigned to serial numbers of the area to which the corresponding blockchain is assigned.

[0063] According to embodiments, the predefined criterion is the exceeding of a predefined threshold of a sum of credits assigned to the serial numbers of the range of serial numbers of the corresponding blockchain. Embodiments can have the advantage that, for a large sum of credits, there is a high probability that numerous transaction approvals will have to be entered in the future, thus resulting in a large load. For example, the predefined criterion specifies that a split occurs if the predefined threshold is already exceeded once by the sum of credits or if the corresponding threshold is constantly exceeded for a predefined period of time.For example, two thresholds are predefined, whereby a smaller of the two thresholds must be constantly exceeded for a predefined time for a division to occur; a division is initiated even if the larger threshold is exceeded once.

[0064] According to embodiments, for each of the sub-areas, it is determined which share of the recorded current load is attributable to the corresponding sub-area, and the division into the sub-areas is adjusted such that the difference between the sub-areas attributable to the sub-areas is less than or equal to a predefined first maximum value. Embodiments can have the advantage of being able to implement the most even load distribution possible between the resulting blockchains. For example, the division is performed such that the difference is minimized. For example, the division is performed such that the difference disappears, i.e., the first maximum value is zero.

[0065] According to embodiments, for each of the sub-areas, a sum of the credits assigned to the serial numbers of the corresponding sub-area is determined, and the division into the sub-areas is adjusted such that a difference between the sums of the credits of the sub-areas is less than or equal to a predefined second maximum value. Embodiments can have the advantage that the most even credit distribution possible can be implemented between the resulting blockchains. This can, for example, increase the probability of the most even future load distribution possible between the resulting blockchains. For example, the division is carried out such that the difference is minimized. For example, the division is carried out such that the difference disappears, i.e., the second maximum value is zero.

[0066] According to embodiments, the range of serial numbers to be divided is divided such that size differences between the sub-ranges with respect to the number of serial numbers each encompassed by the sub-ranges are less than or equal to a predefined third maximum value. Embodiments can have the advantage of being able to implement the most even distribution of serial numbers possible between the resulting blockchains. For example, the division is carried out such that the difference is minimized. For example, the division is carried out such that the difference disappears, i.e., the third maximum value is zero and each of the sub-ranges encompasses the same number of serial numbers.

[0067] According to embodiments, the blockchain to be split is assigned to a first of the sub-areas and further used to log payments from blockchain addresses of serial numbers of the first sub-area. A separate additional blockchain is generated for each of the additional sub-areas. The generation of the additional blockchains comprises: Entering a division note for each blockchain address of serial numbers of the further sub-area into the blockchain to be divided, entering a genesis block for each blockchain address of serial numbers of the further sub-area into the additional blockchain, wherein the genesis blocks each include an indication of a current balance which is assigned to the corresponding serial number at the time of the division in the blockchain to be divided.

[0068] Embodiments can have the advantage that the blockchain to be split is reused and the number of serial numbers for which it is responsible is reduced. Additional blockchains are created only for the additional sub-areas. The splitting notes, for example, mean that no more payments from the corresponding blockchain addresses can be logged in the blockchain to be split. For example, the splitting notes and / or the genesis blocks are each signed with a private cryptographic key of an authority managing the blockchains, such as a central bank.

[0069] According to embodiments, the blockchain to be split is terminated, and a separate additional blockchain is created for each of the sub-areas. Creating the additional blockchains includes: Entering a division note for each blockchain address of serial numbers of the further sub-area into the blockchain to be divided, entering a genesis block for each blockchain address of serial numbers of the further sub-area into the additional blockchain, wherein the genesis blocks each include an indication of a current balance which is assigned to the corresponding serial number at the time of the division in the blockchain to be divided.

[0070] Embodiments can have the advantage that the blockchain to be split is terminated and an additional blockchain is created for each of the further sub-areas. The splitting notes have the effect, for example, that no more payments from the corresponding blockchain addresses can be logged in the blockchain to be split. For example, the blockchain to be split is terminated when a splitting note has been entered for each of the blockchain addresses it contains. For example, the splitting notes and / or the genesis blocks are each signed with a private cryptographic key of an authority managing the blockchains, such as a central bank.

[0071] According to embodiments, the blockchain server is further configured to merge two or more of the blockchains of the blockchain system if a predefined criterion is met. Merging the blockchains comprises merging the serial number ranges associated with the blockchains to be merged and adjacent to each other. A common blockchain is assigned to the merged range. Embodiments may have the advantage that the number of blockchains can be reduced if necessary. For example, a hint is distributed to the routing tables regarding the merger of the blockchains and the associated serial number ranges.

[0072] According to embodiments, the blockchain server monitors blockchain loads. The predefined criterion is when the sum of the current load recorded during monitoring falls below a predefined threshold. For example, the predefined criterion includes when the sum of the current load recorded during monitoring falls below the predefined threshold for a predefined period of time.

[0073] According to embodiments, the predefined criterion is the sum of credits assigned to the serial numbers of the serial number ranges of the corresponding blockchains falling below a predefined threshold. For example, the predefined criterion includes the sum of credits falling below the predefined threshold for a predefined period of time.

[0074] According to embodiments, the method further comprises checking the validity of the transaction approval. The checking comprises a validity check of a signature of the transaction approval. This check determines whether the signature was actually signed with the private cryptographic key assigned to the blockchain address of the mobile, portable terminal, for example, the banknote-specific blockchain address of a banknote, as the signature key. In other words, it is checked whether the banknote that issued the transaction approval is actually authorized to do so.

[0075] According to embodiments, checking the validity of the transaction approval further comprises checking whether the banknote-specific first blockchain address is assigned a sufficient credit balance to pay the amount to be paid. This ensures that sufficient money is actually available to settle the amount to be paid. According to embodiments, a credit balance assigned to the banknote-specific first blockchain address is sufficient to pay the amount to be paid if it is greater than or equal to the amount to be paid. According to embodiments, a credit balance assigned to the banknote-specific first blockchain address is sufficient to pay the amount to be paid if it is greater than or equal to a minimum amount plus the amount to be paid.

[0076] According to embodiments, upon successfully checking the validity of the transaction approval, the method further comprises entering the transaction approved by the transaction approval into the determined first blockchain.

[0077] According to embodiments, the method further comprises, upon entering the approved transaction, creating and sending a first transaction confirmation by the first blockchain server. Embodiments may have the advantage of confirming the transaction entry. This confirmation may, for example, be sent to a terminal computer system or to a server that received the message from the mobile portable device or initiated the generation of the corresponding message by the mobile portable device. The terminal computer system or the server may also forward the transaction confirmation to the mobile portable device itself.

[0078] According to embodiments, for banknote-specific blockchain addresses, the balance of received and made payments recorded in the blockchain to which the serial number of the corresponding mobile portable device is assigned forms the valid overall balance. For example, the valid overall balance for a mobile portable device results from those transactions recorded in the blockchain that is responsible for the serial number of the corresponding mobile portable device. For example, all transactions with the banknote-specific blockchain address of the corresponding mobile portable device as the source address are entered into the blockchain considered here.Transactions with banknote-specific blockchain addresses of the corresponding mobile portable device as the destination address are, for example, entered in the blockchain responsible for the range of serial numbers into which the serial number of the mobile portable device of the source address of the corresponding transaction falls. If the corresponding blockchain is a different blockchain than the one considered here, a copy of the corresponding transaction is created and additionally entered into the blockchain considered here. For an additional entry into the blockchain considered here, for example, an entry confirmation of an entry in the other blockchain is required by a blockchain server managing the other blockchain. The corresponding entry confirmation is, for example, signed by the corresponding blockchain server.Thus, the blockchain considered here also includes all transactions with the banknote-specific blockchain address of the corresponding mobile portable device as the destination address.

[0079] According to embodiments, the second blockchain address of the payee is a banknote-independent blockchain address intended exclusively for receiving payments from banknote-specific blockchain addresses. The second blockchain address of the payee is assigned a blockchain-specific balance of received payments in each blockchain of the plurality of blockchains in which it is used to receive one or more payments.

[0080] Embodiments may have the advantage that blockchain addresses can be used that are not assigned to a mobile, portable device and are not used as source addresses for banknote-based payment transactions. For example, these blockchain addresses are used exclusively as destination addresses. For example, these banknote-independent blockchain addresses can be authorized for payment transfers from the blockchain system to other systems, such as the GIRO-SEPA system. To transfer money from the blockchain, these banknote-independent blockchain addresses could, for example, only be intended for receiving payments, while it is not possible to send payments from them within the blockchain system. For example, these could be blockchain addresses created by the central bank, which are assigned to the central bank or other legal or natural persons.For example, the central bank creates the corresponding blockchain addresses but destroys or deletes the associated private cryptographic keys, whose signatures would be required for transactions from the corresponding blockchain addresses. For example, such a blockchain address is associated with an account in another system. If money is transferred to the corresponding blockchain address, the central bank transfers an identical amount to the corresponding account in the other system.

[0081] According to the implementation, the sum of all blockchain-specific balances of the banknote-independent second blockchain address forms the valid overall balance of the corresponding blockchain address. If the amount of money transferred via the blockchain system to the corresponding banknote-independent second blockchain address is to be determined, for example, the sum of the balances of all blockchains for the corresponding blockchain address must be calculated. For example, the banknote-independent blockchain address is not assigned a serial number due to the lack of a banknote, which is why these blockchain addresses are not assigned to a specific blockchain.

[0082] According to embodiments, the second blockchain address of the payee is a second blockchain address of a second mobile portable terminal of the payee, in particular a banknote-specific second blockchain address of a second banknote. The message comprises a second serial number of the second mobile portable terminal of the payee. For example, all blockchain addresses are exclusively blockchain addresses, in particular banknote-specific blockchain addresses, each of which is assigned to a mobile portable terminal and thus to a serial number. Due to the serial number, the blockchain addresses are also each assigned to a specific blockchain, which is responsible for transactions with the corresponding blockchain address as the source address.Embodiments may have the advantage that each blockchain address is assigned to one of the blockchains of the blockchain system via a serial number of a mobile portable terminal, in particular a banknote.

[0083] According to embodiments, the message includes the second serial number of the second mobile portable device in the header. Embodiments can have the advantage that the header already indicates which blockchain is responsible for the mobile portable device at the destination address. If this blockchain is different from the blockchain responsible for the mobile portable device at the source address, a copy can be created, for example, when forwarding the message and sent in advance to a blockchain server that manages the blockchain responsible for the mobile portable device at the destination address. This allows the server to be notified in advance of the upcoming transaction.If, in addition, an entry confirmation of the entry of the announced transaction in the blockchain responsible for the mobile portable device of the source address is received, a copy of the transaction will also be entered in the blockchain responsible for the mobile portable device of the destination address.

[0084] According to embodiments, the method further comprises: upon entering the transaction released by the transaction release into the first blockchain, checking whether the second serial number is comprised by a range of serial numbers which is assigned to a different, second blockchain of the plurality of blockchains than the first blockchain, if the second serial number is assigned to a different, second blockchain, determining the second blockchain to which the second serial number is assigned, generating an entry confirmation of the released transaction in the first blockchain which includes the transaction release, sending the entry confirmation to a second blockchain server which manages the second blockchain for additionally entering the transaction released by the transaction release into the second blockchain.

[0085] Embodiments may have the advantage that the transaction is additionally entered into the second blockchain if it is responsible for the serial number of the mobile portable device at the destination address. Thus, each of the blockchains can provide a complete record of blockchain addresses of those mobile portable devices whose serial numbers fall within the range of serial numbers for which the corresponding blockchain is responsible.

[0086] According to embodiments, the registration confirmation includes the second serial number in a header. Embodiments may have the advantage that the second serial number can be used to determine the blockchain of the plurality of blockchains that is assigned to the range of serial numbers that includes the second serial number and is therefore responsible for the second serial number. The registration confirmation is then forwarded to a second blockchain server that manages the specific second blockchain. A routing table, for example, is used to forward or route the registration confirmation.

[0087] According to embodiments, the entry confirmation is signed by the first blockchain server. Embodiments may have the advantage that the entry confirmation can thus provide cryptographically secured proof of the entry of the transaction in the first blockchain.

[0088] According to embodiments, the method further comprises verifying the entry confirmation by the second blockchain server. Upon successful verification, the second blockchain server additionally enters the transaction approved by the transaction approval into the second blockchain. For this purpose, the second blockchain server has, for example, a signature verification key, such as a public cryptographic key of an asymmetric key pair of the first blockchain server. To create the signature of the entry confirmation, the first blockchain server uses, for example, a public cryptographic key of the asymmetric key pair of the first blockchain server as the signature key.

[0089] According to embodiments, a copy of the message with the transaction release is sent to the second blockchain server as advance information about the upcoming entry of a transaction.

[0090] According to embodiments, the method further comprises: upon an unsuccessful check of the validity of the transaction release, refusing to enter the transaction released by the transaction release into the first blockchain, upon a refusal of the entry, checking whether the second serial number is comprised by a range of serial numbers which is assigned to a different, second blockchain of the plurality of blockchains than the first blockchain, if the second serial number is assigned to a different, second blockchain, determining the second blockchain to which the second serial number is assigned, generating an entry error message which includes the transaction release, sending the entry error message to a second blockchain server which manages the second blockchain, in order to prevent the transaction released by the transaction release from being entered into the second blockchain.

[0091] Embodiments may have the advantage that if the transaction fails to be entered into the first blockchain, the transaction is also not entered into the second blockchain. Successful entry of the transaction into the first blockchain is therefore a necessary prerequisite for additional entry of the transaction into the second blockchain. According to embodiments, if entry of the released transaction is refused, the method further comprises generating and sending a transaction error message by the second blockchain server.

[0092] According to embodiments, the method further comprises, upon entering the approved transaction into the second blockchain, creating and sending a second transaction confirmation by the second blockchain server. This second transaction confirmation is sent, for example, to a recipient of the transaction, such as the second mobile portable device. Embodiments may have the advantage that the transaction is additionally confirmed upon entry of the transaction into the blockchain for which the mobile portable device of the destination address is responsible.

[0093] Embodiments further include a computer system for executing a payment using a mobile portable terminal of a plurality of mobile portable terminals and a blockchain system. The blockchain system comprises a plurality of blockchains. Each of the blockchains is assigned one or more blockchain servers, which manage the corresponding blockchain. Each mobile portable terminal of the plurality of mobile portable terminals is assigned a serial number from a space of serial numbers. The space of serial numbers is divided into a plurality of ranges of serial numbers. Each of the ranges of serial numbers is assigned one of the blockchains of the blockchain system, which logs payments from banknote-specific blockchain addresses assigned to mobile portable terminals with serial numbers from the corresponding range of serial numbers.

[0094] The computer system includes a processor, a memory with program instructions, and a communication interface. The processor is configured to perform the following when executing the program instructions: Receiving a message from the mobile portable terminal with a transaction authorization via the communication interface, wherein the transaction authorization is signed using a banknote-specific private cryptographic key of an asymmetric key pair of the mobile portable terminal, wherein the asymmetric key pair is assigned to a banknote-specific blockchain address of the mobile portable terminal, wherein the transaction authorization comprises the blockchain address of the banknote, a blockchain address of the payee, and an amount to be paid. Determining, using a serial number of the banknote comprising the message, a blockchain of the plurality of blockchains that is assigned to the range of serial numbers comprising the serial number. Forwarding the message via the communication interface to a blockchain server that manages the specific blockchain.to verify and enter the transaction released by the transaction release into the specific blockchain. ,

[0095] According to embodiments, the computer system is configured to perform any of the previously described embodiments of the method for making a payment.

[0096] According to embodiments, the computer system is a terminal computer system or a server. According to embodiments, the computer system is a blockchain server of the blockchain system. According to embodiments, the computer system is a distribution server of the blockchain system.

[0097] Embodiments further include a system comprising a computer system according to any one of the embodiments described herein and a banknote. The mobile portable terminal comprises a security element with a processor and a memory with program instructions. The banknote-specific private cryptographic key of the mobile portable terminal is stored in a protected memory area of ​​the memory. The processor is configured to perform the following upon execution of the program instructions: Receiving a payment request for a payment with the mobile portable device in the form of a transaction of the amount to be paid from the blockchain address of the mobile portable device to the blockchain address of the payee, wherein the payment request specifies the amount to be paid and the blockchain address of the payee, signing the transaction authorization with the private cryptographic key of the banknote, sending the message with the signed transaction authorization.

[0098] According to embodiments, the system is configured to perform any of the previously described embodiments of the method for making a payment.

[0099] According to embodiments, the system further comprises a blockchain system. The blockchain system comprises a plurality of blockchains. Each of the blockchains is assigned one or more blockchain servers, which manage the corresponding blockchain. A space of serial numbers of mobile portable devices in use is divided into a plurality of serial number ranges. Each of the serial number ranges is assigned one of the blockchains of the blockchain system, which logs payments from banknote-specific blockchain addresses assigned to mobile portable devices with serial numbers from the corresponding serial number range.

[0100] According to embodiments, the banknotes of the plurality of banknotes each comprise a security element with a processor and a memory with program instructions. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address in a blockchain managed by a central bank issuing the banknote.

[0101] The processor is configured to execute a payment procedure with the banknote upon execution of the program instructions. The payment procedure includes: Receiving a payment request for a payment with the banknote in the form of a transaction of an amount to be paid from the blockchain address of the banknote to a blockchain address of a payee, wherein the payment request specifies the amount to be paid and the blockchain address of the payee, Signing a transaction approval with the private cryptographic key of the banknote, wherein the transaction approval comprises the blockchain address of the banknote, the blockchain address of the payee and the amount to be paid, Sending a message with the signed transaction approval, wherein the message comprises the serial number of the banknote.

[0102] According to embodiments, a further transaction-specific value is also sent along with the signed transaction release. For example, the further transaction-specific value is included in the signature of the transaction release and / or attached to the signed transaction release. The further transaction-specific value is, for example, a timestamp and / or a random number.

[0103] According to embodiments, the banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. According to embodiments, the banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.

[0104] Embodiments can have the advantage that the banknote can not only be used as a cash payment method in the usual sense, but can also be used to make a cashless payment. When used as a cash payment method in the usual sense, the banknote is handed over by the payer to the payee during the payment processing, or the payee hands over the corresponding banknote to the payer as change during the payment processing. Upon handing over the banknote, ownership of the banknote is transferred from the transferor to the recipient. With ownership of the banknote, ownership of the current nominal value of the banknote, i.e. the nominal value assigned to the blockchain address of the banknote, is also transferred to the recipient.

[0105] When used for a cashless payment, i.e., without handing over the banknote or transferring ownership of the banknote, the payment is made by providing a signed transaction authorization, i.e., a transaction authorization, through the banknote. This signed transaction authorization of the banknote authorizes a transaction in which the amount to be paid is transferred from the banknote's blockchain address to the payee's blockchain address.

[0106] For example, the money supply in circulation, which can be transferred both cash-based and cashless, is defined by the money supply or the sum of the nominal values ​​assigned to blockchain addresses of banknotes in the blockchains managed by the central bank. For example, the money supply in circulation remains the same if the banknotes in circulation are maintained. This means, for example, that banknotes in circulation can remain the same, but the nominal values ​​assigned to individual banknotes can change as a result of transactions. For example, it would also be possible to change the money supply assigned to banknotes without changing the banknotes in circulation if the central bank were to allow payment transfers from the blockchains of the blockchain system to other systems, such as the GIRO SEPA system.For example, special blockchain addresses could be provided to transfer money from the blockchain system, to which payments can only be sent and from which it is not possible to send payments. For example, these could be blockchain addresses created by the central bank and assigned to the central bank. The corresponding blockchain address could also be assigned to other legal or natural persons. For example, the central bank creates the corresponding blockchain addresses but destroys or deletes the associated private cryptographic keys, whose signatures would be required for transactions from the corresponding blockchain addresses. For example, an account in another system is assigned to such a blockchain address.If money is transferred to the corresponding blockchain address, the central bank, for example, transfers an identical amount to the corresponding account of the other system.

[0107] Money can be added to the blockchain system, for example, by the central bank initializing additional banknotes or blockchain addresses assigned to the additional banknotes. Furthermore, the central bank could, for example, have one or more blockchain addresses assigned to it, which are not subject to restrictions regarding the amount of money that can be transferred, for sending payments to other blockchain addresses. For example, the central bank sends money to a blockchain address if another system has sent an identical amount to a designated central bank account, perhaps with the corresponding blockchain address as the intended purpose.

[0108] Since neither the banknote nor its blockchain address are assigned to a legal or natural person, the banknote enables both cash-based and cashless anonymous payments, which are currently only possible with cash. To prevent misuse, additional restrictions could be implemented in the blockchains or the underlying blockchain system, limiting transferable amounts of money and / or providing additional verification mechanisms for certain amounts. Such verification mechanisms could, for example, require the central bank to confirm the transaction based on a review of additional information determined as necessary for the transaction.

[0109] The banknote and thus its nominal value according to the blockchain responsible for it can, for example, be passed on by manual physical handover, i.e. a digital currency can be transferred. This does not require an account in the classic sense, i.e. an account assigned to a legal or natural person. For example, material and effort can be saved by reducing the purely analog currency. In particular, the effort involved in the physical transfer and transport of banknotes can be reduced. Such a banknote can, for example, be upgraded and used for direct contactless payment with no or only limited control or tracking, since an individual banknote can be passed on at any time, just like with classic cash.

[0110] For example, the current nominal value of the banknote is also stored in the security element's memory. The actual nominal value of the banknote is determined by its nominal value according to the blockchain. For example, the nominal value stored in the banknote can be used to determine the current nominal value offline. For example, the nominal value stored in the banknote is updated when a transaction confirmation and / or registration confirmation signed by the central bank is forwarded to the banknote to complete a transaction. For example, the security element contains a signature verification key for verifying digital signatures from the central bank.

[0111] The banknote can, for example, be paper- and / or plastic-based. For example, the banknote comprises one or more material layers. Materials used for the material layers can, for example, be paper, plastics, and / or metal foils. A material layer can also comprise combinations of several of these materials. For example, the material layers are laminated together. The material layers can, in particular, comprise electronic components, such as a security element with a processor and memory, an antenna, a display, an input device, and / or sensors, or form them in combination with one another. The banknote is, for example, flexible.

[0112] For example, the banknote comprises a plurality of security features that make it possible to verify the authenticity and validity of the banknotes. The plurality of security features can, for example, comprise one or more Level 1, Level 2 and / or Level 3 security features. Level 1 security features are security features that can be directly recognized by humans and verified without additional tools. Level 2 security features are machine-readable security features that are used, for example, for commercial requirements to verify the authenticity of banknotes. Level 3 security features are security features that are only known to the issuing central bank. Central banks use such secret machine-readable security features to ensure the integrity of the cash cycle and to guarantee that only genuine banknotes are put back into circulation.Furthermore, central banks use such Level 3 security features to remove genuine banknotes from circulation and destroy them in a controlled manner if the corresponding banknotes are no longer fit for circulation, for example due to soiling and / or wear.

[0113] The security features can include, for example, tactile, acoustic, or visible features. For example, materials such as security paper with a characteristic haptic impression and / or a characteristic sound when rubbed and / or crumpled are used to produce the banknote. For example, haptically detectable embossing is incorporated into the banknote. For example, visually detectable security features such as watermarks, see-through windows, see-through registers, registration printing elements, foil elements, guilloches, iris printing elements, anti-copy screens, mottled fibers, micro-perforations, micro-lettering, optically variable printing inks, pearlescent stripes, security thread, and / or special colors are used. For example, security elements such as metamerism color combinations, fluorescent colors, diffractive optical elements, and / or scrambled indicia microprint patterns are used.

[0114] For example, machine-readable security elements are used, such as infrared properties of the printing ink, phosphorescent inks, magnetic elements, elements with characteristic electrical conductivity and / or copy protection elements, such as a digital watermark and / or standardised patterns, for example a EURion constellation or Omron rings.

[0115] For example, the banknote contains one or more security features that are only known and / or verifiable by the issuing central bank, i.e. Level 3 security features, such as the ECB's M-Feature.

[0116] Security features, particularly Level 1 and Level 2 security features, can have the advantage of allowing parties to easily verify a banknote's authenticity, i.e., its authenticity and validity. This allows the banknote to be used for cash payments that involve the transfer of the banknote from a payer to a payee.

[0117] A "blockchain" is understood here and below to be an ordered data structure comprising a plurality of interconnected data blocks. In particular, a blockchain is understood to be an ordered data structure in which each block (except the first block) contains a check value, such as a hash value, of its predecessor block. Thus, the validity of all its predecessor blocks can be checked and, if necessary, confirmed using each block. For examples of a blockchain, see https: / / en.wikipedia.org / wiki / Block_chain_(database) and "Mastering Bitcoin," Chapter 7, The Blockchain, page 161 ff. The blockchain concept was described, for example, in a 2008 white paper on Bitcoin under the pseudonym Satoshi Nakamoto ("Bitcoin: Peer-to-Peer Electronic Cash System" (https: / / bitcoin.org / bitcoin.pdf)).The blockchain described therein consists of a series of data blocks, each containing one or more entries or transactions and provided with a checksum in the form of a hash value. Additional blocks of the blockchain are generated, for example, in a computationally intensive process known as mining. These additional blocks are then added to the blockchain and distributed via a network to all participants, or nodes, in the network.

[0118] Embodiments can have the advantage that the blockchain offers a high degree of security against subsequent manipulation by storing cryptographic checksums, i.e. hash values, of the previous block in each subsequent block. The chaining of the blocks can then be verified using these root hash values. Each block of the blockchain contains the hash of the entire previous block header in its header. This clearly defines the order of the blocks and creates a chain structure. By chaining the individual blocks together in this way, it is practically impossible to subsequently modify previous blocks or individual entries, since this would require the hash values ​​of all subsequent blocks to be recalculated within a short period of time.

[0119] A blockchain can, for example, also be implemented in the form of a blockchain, where only a select group of participants has the authority to add valid blocks. This authority can be proven, for example, by means of a signature using a private cryptographic key. The private cryptographic key can belong to an asymmetric key pair, which also includes a public cryptographic key with which the signature can be verified. The asymmetric key pair can also be assigned, for example, a certificate that proves the authority to create a valid block of the blockchain. This certificate can also be assigned to a PKI, which proves the authenticity of the certificate.According to another embodiment, a public key can be stored in the blockchain in an initialization entry for additional participants to be added to the selected group. These public keys can be used to verify whether block signatures, and thus the corresponding blocks themselves, are valid. Public keys of original participants in the selected group can, for example, be stored in a genesis block of the blockchain.

[0120] For example, the blockchain managed by a central bank is a public blockchain that is managed on the central bank's blockchain servers. For example, new blocks are added exclusively by these blockchain servers managed by the central bank. In this case, computationally intensive processes for adding additional blocks can be eliminated. For example, adding additional blocks requires only a signature with a signature key assigned to the central bank.

[0121] Consensus can also be implemented in a blockchain in other ways. For example, consensus can be reached by voting on the inclusion of proposed entries in the blockchain. For example, each participant or blockchain server maintains a unique list of other participants whom they trust as a group. Each participant can suggest additional entries to be included in an additional block of the blockchain. The inclusion and thus the recognition of the validity of the proposed entries is voted on. For example, each participant only votes on those proposals that originate from participants on their list. In other words, the decision as to whether a proposal for an additional entry is recognized as valid, i.e.whether there is consensus among the participants regarding the validity of this entry, only the votes of those participants who are included in the list of the participant making the corresponding proposal are taken into account. For a proposal for an entry to be accepted as valid, a certain minimum proportion of voting participants must vote yes, for example 80%, 90%, 95% or 100%. All proposed entries that meet this criterion are included in the blockchain. Such a vote can consist of several rounds. All other proposals that do not meet the aforementioned criterion are discarded or put up for a vote again in the next block of the blockchain.The aforementioned lists represent subgroups of the blockchain network that the participant maintaining the respective list trusts as a group, without requiring that they trust each individual participant in the list. An example of such a consensus process is the Ripple Protocol Consensus Algorithm (David Schwartz et al.: "The Ripple Protocol Consensus Algorithm", Ripple Labs Inc., 2014, https: / / ripple.com / files / ripple_consensus_whitepaper.pdf).

[0122] A "communication interface" is understood here, for example, to be an interface via which data can be received and sent, whereby the communication interface can be configured as contact-based or contactless.

[0123] Communication can, for example, take place via a network. A "network" is understood here to mean any transmission medium with a connection for communication, in particular a local connection or a local network, in particular a local area network (LAN), a private network, in particular an intranet, and a digital private network (Virtual Private Network - VPN). For example, a computer system can have a standard radio interface for connecting to a WLAN. Furthermore, it can be a public network, such as the Internet. Depending on the embodiment, this connection can also be established via a mobile network.

[0124] Contactless communication with the banknote is possible, for example, using Near Field Communication (NFC). This is a communication technology based on RFID technology for the contactless exchange of data via electromagnetic induction using loosely coupled coils over short distances, for example, a few centimeters. NFC can be implemented according to one of the standards ISO 14443, 18092, 21481, ECMA 340, 352, 356, 362, or ETSI TS 102 190.

[0125] The banknote's communication interface includes, for example, an antenna for contactless communication. The antenna includes, for example, an induction coil. The induction coil can also be configured to supply external energy to the banknote, for example, using energy harvesting. For example, the induction coil is configured to allow a terminal to couple energy into the banknote.

[0126] A "processor" is understood here and below to mean a logic circuit used to execute program instructions. The logic circuit can be implemented on one or more discrete components, in particular on a chip. A processor comprises, for example, an arithmetic unit, a control unit, registers, and data lines for communication with other components. In particular, a "processor" is understood to mean a microprocessor or a microprocessor system comprising multiple processor cores and / or multiple microprocessors.

[0127] The term "memory" refers specifically to non-volatile memory. "Non-volatile memory" refers, for example, to electronic memory for the permanent storage of data. Non-volatile memory can be configured as non-modifiable memory, also known as read-only memory (ROM), or as modifiable memory, also known as non-volatile memory (NVM). In particular, this can be an EEPROM, such as a flash EEPROM, also known as flash. Non-volatile memory is characterized by the fact that the data stored on it is retained even after the power supply is switched off.

[0128] A "protected memory area" is understood here to be an area of ​​an electronic memory to which access, i.e., read or write access, is only possible via a processor of the security element. For example, no external access is possible to the protected memory area, i.e., data can neither be input from the outside nor output to the outside. For example, data can be read out from the protected memory area via the processor. For example, data can be input from the outside into the protected memory area via the processor. According to embodiments, access from or via the processor coupled to the memory is only possible if a necessary condition is met. This can be, for example, a cryptographic condition, in particular, successful authentication and / or successful authorization verification.Such a check can, for example, be based on an electronic signature with a signature key.

[0129] Asymmetric key pairs are used in a variety of cryptosystems and also play an important role in signing electronic documents. An asymmetric key pair consists of a public key, which is used to encrypt and / or decrypt data and may be passed on to third parties, and a private key, which is used to encrypt and / or decrypt data and must generally be kept secret. The public key allows anyone to encrypt data for the owner of the private key and to verify digital signatures created with the private key. A private key allows its owner to decrypt data encrypted with the public key or to create digital signatures. A signature created with a private key can be verified with the corresponding public key.

[0130] The creation of a digital signature, also referred to simply as a "signature," is a cryptographic process in which an additional data value, referred to as a "signature," is calculated for any given piece of data. A signature can, for example, be a hash value of the source data encrypted with a private cryptographic key.

[0131] A security element is understood here, for example, to be an electronic component that includes a processor and a memory, and to which only certain predefined accesses are permitted. For example, only certain data values ​​that are stored in certain areas of the memory can be read. For example, data values ​​stored in a protected memory area cannot be read. For example, writing a data value to the memory of the security element requires a digital signature, the verification key for which is stored in the security element. For example, only the processor has write permissions to write data to a protected memory area.

[0132] The security element further provides, for example, cryptographic core routines in the form of cryptographic program instructions with cryptographic algorithms for signature creation and / or verification, key generation, and / or random number generation and can further serve as a secure storage for cryptographic keys.

[0133] For example, at least parts of the security element are signed. Before the security element is used, it is checked whether the signature(s) are valid. If one of the signatures is invalid, the use of the security element is blocked, for example.

[0134] For example, the security element has physically restricted access options. In addition, the security element I can have additional measures against misuse, in particular against unauthorized access to data in the memory of the security element. For example, a security element comprises sensors for monitoring the state of the security element and its environment in order to detect deviations from normal operation that could indicate attempts at manipulation. Corresponding sensor types include, for example, a clock frequency sensor, a voltage sensor and / or a light sensor. Clock frequency sensors and voltage sensors detect, for example, deviations in the clock frequency, temperature and / or voltage upwards or downwards from a predefined normal range. In particular, a security element can comprise non-volatile memory with a protected memory area.

[0135] For example, the means for protecting the security element against unauthorized manipulation include mechanical means intended, for example, to prevent the opening of the security element or its parts, or to render the security element unusable in the event of an attempted tampering with the security element, for example, by causing data loss. For example, at least parts of the security element can be encased, cast, and / or laminated in a material whose attempted removal leads to the inevitable destruction of the corresponding parts of the security element.

[0136] Visual information includes, for example, information incorporated into the banknote in an optically readable form. For example, this information is printed, embossed, engraved, punched, cut out, or incorporated in another optically detectable manner onto the banknote and / or a material layer of the banknote. These visual features can be captured, for example, using an optical sensor such as a camera.

[0137] For example, during a payment transaction the current nominal value of the banknote can first be checked. This involves using a blockchain query for the current nominal value of the banknote's blockchain address, for example. A g of the banknote's blockchain address is received in response to the query. To create the query the banknote's serial number can be recorded electronically, i.e. read from the banknote's memory, and / or a visual indication of the serial number can be recorded using an optical sensor. For example, both can be done, i.e. reading from the memory and scanning the visual indication, with a subsequent comparison of the results from both recording methods. If the read serial number matches the scanned serial number, the banknote is accepted; otherwise it is not. This can offer protection against tampering with the banknote.In particular, this could prevent a counterfeit banknote with a visual indication of a serial number whose blockchain address is assigned a high current nominal value from being embodied with a security element from another banknote with a different serial number, whose blockchain address is assigned a much lower current nominal value. Otherwise, when making a cash payment with such a manipulated banknote, there would be a risk that the payee, upon receipt of the banknote, would assume that the bank's current nominal value is significantly higher than the banknote's actual nominal value. The banknote's serial number is assigned to the banknote's blockchain address, for example, in an initialization entry of the blockchain address in the blockchain, which is responsible for the range of serial numbers into which the corresponding serial number falls.

[0138] Instead of the serial number, another identifier of the banknote's blockchain address can also be recorded and used in the manner described above. This identifier could, for example, be the banknote's public cryptographic key, from which the blockchain address can be derived, for example, using a hash function. This identifier could, for example, be the corresponding blockchain address itself.

[0139] For example, the actual face value of a banknote is determined solely by the face value of the blockchain address assigned to the banknote. To access the face value assigned to the corresponding blockchain address, one must possess a genuine banknote with a private cryptographic key assigned to the corresponding blockchain address.

[0140] In a payment procedure using a banknote, one or more security features of the banknote can also be checked before a payment request is sent in order to ensure that the banknote is a genuine, i.e. authentic and valid, banknote.

[0141] For example, based on the determined current nominal value, a decision can be made as to whether a cash payment or a cashless payment should be made with the banknote. If the current nominal value is identical to the amount to be paid, a cash payment is made, for example, in which the banknote is handed over to the payee and ownership of it is transferred to the payee. If the current nominal value is greater than the amount to be paid, a cashless payment is made, for example. In a cashless payment, for example, a corresponding payment request is sent to the banknote for a payment in the form of a transaction of an amount to be paid from the banknote's blockchain address to a payee's blockchain address. The banknote can authorize this transaction with a signed transaction release.

[0142] If the current nominal value is greater than the amount to be paid, it would also be possible for a cash payment to be made and for the excess amount to be repaid by the payee as change, for example in the form of cash, such as banknotes with a matching nominal value.

[0143] For example, the current nominal value can be any positive value, including zero. For example, the current nominal value can be any value between zero and a specified maximum nominal value. For example, the current nominal value can be any value greater than or equal to a specified minimum nominal value. For example, the current nominal value can be any value from a specified minimum nominal value up to and including a specified maximum nominal value.

[0144] For example, the nominal value of the banknote can comprise a guaranteed minimum nominal value and a variable additional nominal value component. The minimum nominal value can, for example, only be paid in the form of a cash payment upon handover of the banknote, whereas the variable additional nominal value component can be used in the course of a cash-based or cashless payment transaction. In other words, the banknote can only be used for cashless payments where the remaining nominal value of the banknote is greater than or equal to the minimum nominal value. If an amount is to be paid with the banknote that would result in a remaining nominal value that is less than the minimum nominal value, a cashless payment is blocked via the blockchain system, i.e. the relevant blockchain. Therefore, a cash-based payment must be made, for example, in which the banknote is handed over.If the current nominal value of the banknote is greater than the amount to be paid, the difference can be refunded by the payee, for example in the form of change.

[0145] For example, the initial nominal value for the banknote or its blockchain address is entered in the blockchain responsible for the serial number of the corresponding banknote. For example, the visual design, the security features incorporated, and / or the format of the banknote depend on its initial nominal value. Thus, banknotes with different initial nominal values ​​differ from one another, for example, in terms of their visual design, the security features incorporated, and / or the format. Banknotes with identical initial nominal values, for example, have an identical visual design, identical security features, and / or format, apart from one or more banknote-specific details, such as the serial number, information on the year of issue, etc.

[0146] For example, the banknote includes a visual indication of the minimum nominal value. For example, the minimum nominal value for the banknote or its blockchain address is entered in the blockchain responsible for the serial number of the corresponding banknote. For example, the visual design, the security features incorporated, and / or the format of the banknote depend on its minimum nominal value. Thus, banknotes with different minimum nominal values ​​differ from one another, for example, in terms of their visual design, the security features incorporated, and / or the format. Banknotes with identical minimum nominal values, for example, have an identical visual design, identical security features, and / or format, apart from one or more banknote-specific details, such as the serial number, information on the year of issue, etc.

[0147] For example, the initial nominal value assigned to the banknote, which the banknote includes as a visual indication, is the total nominal value assigned to the banknote during its initialization in the relevant blockchain. For example, the total nominal value initially assigned to the banknote is the guaranteed minimum nominal value and an initial additional nominal value portion. The additional nominal value portion is, for example, variable depending on the transactions executed using the banknote's blockchain address. For example, the visually indicated initial nominal value is a portion of the total nominal value assigned to the banknote during its initialization in the relevant blockchain. For example, the corresponding portion is the minimum nominal value, whereby the actual total nominal value may initially be higher, i.e.can include an additional initial nominal value component. For example, the total nominal value assigned to the banknote during its initialization in the relevant blockchain is a minimum nominal value of the banknote, which is, for example, visually indicated on the banknote. In this case, the visual indication of the initial nominal value is, for example, also a visual indication of the minimum nominal value of the banknote. For example, the minimum nominal value differs from the initial nominal value. In this case, the banknote includes, for example, a visual indication of the minimum nominal value in addition to the visual indication of the initial nominal value.

[0148] Adding a variable additional nominal value component or increasing an existing variable additional nominal value component is done, for example, by a transaction of a corresponding amount to the banknote's blockchain address. The transaction can originate from another blockchain address, such as a blockchain address of another banknote or the central bank. For example, the variable additional nominal value component can be increased indefinitely. For example, the variable additional nominal value component can be increased depending on the minimum nominal value and / or the initial nominal value. For example, a maximum permissible variable additional nominal value component is entered in the relevant blockchain for the blockchain address of the corresponding banknote. For example, the maximum permissible variable additional nominal value component of the banknote is 100%, 200%, 300%, 400%, 500%, 600%, 700%, 800%, 900%, or 1000% of the banknote's minimum nominal value.For example, when a transaction is made to a banknote's blockchain address, a prerequisite for executing the transaction is whether the transaction exceeds the maximum permissible variable additional nominal value. If the maximum permissible variable additional nominal value is not exceeded, the transaction is executed, i.e., entered into the relevant blockchain. If the maximum permissible variable additional nominal value is exceeded, the transaction is not executed, i.e., not entered into the relevant blockchain.

[0149] According to embodiments, the banknote includes the visual indication of the serial number distributed multiple times across the banknote. Embodiments may have the advantage that even if the banknote is partially damaged, the serial number can be detected. For example, the serial number information is incorporated into the banknote in combination with and / or as a component of several security features. This could have the advantage that, as long as sufficient security features are present to confirm the authenticity and validity of the banknote, the banknote's serial number can be detected.

[0150] According to embodiments, the banknote also includes the visual indication of the initial nominal value and / or the minimum nominal value distributed multiple times across the banknote. For example, information about the initial nominal value and / or the minimum nominal value is incorporated into the banknote in combination with and / or as a component of several security features of the banknote. For example, one or more of the security features of the banknote are dependent on the initial nominal value and / or the minimum nominal value of the banknote.

[0151] According to embodiments, the majority of serial number details are distributed across the banknote in such a way that it can be ensured that the banknote's serial number can be determined as long as more than 50% of the banknote is present. Embodiments can have the advantage that, in the event of a loss of part of the banknote, it can be ensured that, as long as more than 50% of the banknote is present, which is, for example, a prerequisite for replacing the banknote, the more than 50% present include the banknote's serial number. Thus, even in the event of a partial loss of the banknote, it can be ensured that, as long as the remaining part(s) of the banknote are valid, the serial number can be recorded and the current nominal value of the banknote can be determined according to the banknote's blockchain address.

[0152] According to embodiments, the memory further stores a banknote-specific public cryptographic key of the banknote's asymmetric key pair, from which the banknote's blockchain address can be derived. According to embodiments, the memory further stores the banknote's blockchain address.

[0153] According to embodiments, the banknote further comprises a visual indication of the banknote-specific public cryptographic key. According to embodiments, the banknote further comprises a visual indication of the banknote's blockchain address.

[0154] According to embodiments, the banknote comprises a plurality of security features. Embodiments can have the advantage that, using the security features, which are, for example, Level 1, Level 2, and / or Level 3 security features, it can be possible to verify the authenticity and validity of the banknote. According to embodiments, one or more security features of the plurality of security features include an indication of the serial number, the banknote-specific public cryptographic key, and / or the blockchain address of the banknote. Embodiments can have the advantage that, when the corresponding one or more security features are detected, the serial number, the banknote-specific public cryptographic key, and / or the blockchain address of the banknote can also be detected.As part of the corresponding security features, the security features can be used to verify not only the authenticity and validity of the banknote itself, but also the authenticity and validity of the serial number of the banknote-specific public cryptographic key and / or the banknote's blockchain address. Thus, for example, a connection or assignment between the physical banknote and the banknote's blockchain address can be provided, secured by the corresponding security features, which can be identified, for example, using the serial number of the banknote-specific public cryptographic key and / or the banknote's blockchain address.According to embodiments, the one or more security features, which include an indication of the serial number of the banknote-specific public cryptographic key and / or the blockchain address of the banknote, are, for example, Level 1, Level 2 and / or Level 3 security features.

[0155] According to embodiments, the banknote includes the visual indication of the public cryptographic key and / or the blockchain address distributed multiple times across the banknote. Embodiments may have the advantage that even if the banknote is partially damaged, the public cryptographic key and / or the blockchain address can be captured. For example, information about the public cryptographic key and / or the blockchain address is incorporated into the banknote in combination with and / or as part of several security features of the banknote. This could have the advantage that as long as sufficient security features are present to confirm the authenticity and validity of the banknote, the public cryptographic key and / or the blockchain address of the banknote can be captured.

[0156] According to embodiments, the majority of details of the public cryptographic key and / or the blockchain address are distributed across the banknote in such a way that it can be ensured that the public cryptographic key and / or the blockchain address of the banknote can be determined as long as more than 50% of the banknote is present. Embodiments can have the advantage that if part of the banknote is lost, it can be ensured that as long as more than 50% of the banknote is present, which is a prerequisite for replacing the banknote, for example, the more than 50% present includes the public cryptographic key and / or the blockchain address of the banknote. Thus, even if the banknote is partially lost, it can be ensured that as long as the remaining part orthe remaining parts of the banknote are valid, the public cryptographic key and / or the blockchain address are recorded and the current nominal value of the banknote can be determined according to the banknote's blockchain address.

[0157] According to some embodiments, the banknote generates the transaction authorization using the information from the payment request. Some embodiments may have the advantage that the banknote can adopt the corresponding information directly from the payment request. According to some embodiments, the payment request includes the complete transaction details, which the banknote signs as a transaction authorization. In addition to the amount to be paid and the blockchain address of the payee, the complete transaction details include, for example, the blockchain address of the banknote.

[0158] According to embodiments, the banknote provides the banknote's public cryptographic key to derive the banknote's blockchain address for the payment request. According to embodiments, the banknote's public cryptographic key is provided as a visual indication for reading, in particular machine reading. For example, the visual indication comprises an alphanumeric character string, a barcode, or a QR code of the public cryptographic key. According to embodiments, the public cryptographic key is sent from the banknote to create the payment request. The sending occurs, for example, in response to a request for the public cryptographic key.Embodiments may have the advantage that the blockchain address of the banknote, which can be derived from the public cryptographic key, can be provided to create the payment request without the need for any other entity than the banknote.

[0159] According to embodiments, the banknote provides the blockchain address of the banknote for the payment request. According to embodiments, the blockchain address of the banknote is provided as a visual indication for reading, in particular machine reading. For example, the visual indication comprises an alphanumeric character string, a barcode, or a QR code of the blockchain address of the banknote. According to embodiments, the blockchain address of the banknote is sent from the banknote to create the payment request. The sending occurs, for example, in response to a request for the blockchain address of the banknote. Embodiments can have the advantage that the blockchain address of the banknote can be provided to create the payment request without requiring any entity other than the banknote.

[0160] According to embodiments, the banknote comprises a communication interface for communicating with a terminal. The banknote receives the payment request from the terminal via the communication interface and / or sends the signed transaction authorization to the terminal via the communication interface. The terminal can, for example, be a vendor's terminal at a point of sale (PoS), i.e., the location where a sale is completed. The terminal can also be a terminal connected to a user computer system via which a payment is to be processed with the banknote. For example, this involves payment processing via a network, such as the Internet, to a service provider, be it a vendor or a payment service provider.Likewise, the terminal could be provided in the form of a user's mobile, portable communications device, such as a smartphone. The user could use the mobile, portable communications device, for example, to process a payment via a network, such as the Internet, with a service provider, be it a retailer or a payment service provider.

[0161] According to embodiments, the banknote comprises a user interface for communicating with a user of the banknote, wherein the banknote receives the payment request from a user via an input device of the user interface and / or sends the signed transaction authorization to the user interface for output via a display device of the user interface. Embodiments may have the advantage that the user can see and / or control which data is input into the banknote and which data the banknote outputs.

[0162] The input device can, for example, comprise a touchpad. The display device can, for example, comprise a display. The input device can, for example, be combined with the display device, for example in the form of a touch display. The user enters the payment request data, for example, using the input device in banknotes.

[0163] For example, the payment request and / or transaction approval is displayed to the user on the banknote's display device. Confirmation of the displayed payment request and / or transaction approval by the user using the banknote's input device is a prerequisite for generating and / or signing the transaction approval.

[0164] For example, the signed transaction authorization is sent to the banknote's display device for display, such as an alphanumeric string, barcode, or QR code. The signed transaction authorization displayed on the display device can be scanned or read, for example, using an optical sensor, such as a terminal sensor.

[0165] According to embodiments, a current nominal value of the banknote is also stored in the memory of the security element. Embodiments can have the advantage that the current nominal value can be read from the banknote. For example, the blockchain responsible for the serial number of the corresponding banknote determines the actually binding nominal value of the banknote using the current nominal value stored under the banknote's blockchain address, i.e., the current nominal value resulting from the balance of transactions stored in the relevant blockchain, including the banknote's blockchain address.

[0166] For example, the current nominal value is stored in the protected memory area of ​​the security element's memory. For example, the current nominal value is not stored in the protected memory area of ​​the security element's memory. For example, the current nominal value of the banknote stored in the security element's memory can be read from the outside. For example, the current nominal value of the banknote stored in the security element's memory is not read from the outside. For example, the current nominal value of the banknote stored in the security element's memory is only used for internal checks, for example to determine whether an amount to be paid is less than or equal to the current nominal value of the banknote.

[0167] According to embodiments, the serial number of the banknote is further stored in the memory of the security element.

[0168] According to some embodiments, the initial nominal value of the banknote is initially stored in the memory of the security element as the current nominal value. Some embodiments may have the advantage that, based on this initial nominal value, the stored nominal value is adjusted for each successfully processed payment, thus allowing the current nominal value to be tracked on the banknote side.

[0169] According to embodiments, the processor is further configured, upon execution of the program instructions, to compare the amount to be paid with the stored current nominal value of the banknote and to create the signed transaction authorization for authorizing the transaction only under the condition that the stored current nominal value is greater than or equal to the amount to be paid. Embodiments may have the advantage of ensuring that the current nominal value is sufficient for the payment to be executed.

[0170] According to embodiments, the processor is further configured to execute an update method for updating the stored current denomination of the banknote upon execution of the program instructions. The update method comprises: Receiving an update request to update the current nominal value of the banknote stored in the memory of the security element, wherein the update request comprises an updated nominal value of the banknote together with a cryptographically secured confirmation from the issuing central bank for the updated nominal value, checking the cryptographically secured confirmation using a cryptographic verification key stored in the memory of the security element, in the event of a successful check, replacing the current nominal value of the banknote stored in the memory of the security element with the received updated nominal value.

[0171] Embodiments can have the advantage of ensuring that the stored nominal value is updated. According to embodiments, the cryptographic verification key is an additional cryptographic verification key stored in the memory of the security element in addition to the asymmetric key pair of the banknote, for example, a public cryptographic key of an asymmetric key pair assigned to the central bank. The signature verification key is stored in the security element, for example, during the production of the banknote.

[0172] According to embodiments, the update request is received in response to the sending of the signed transaction approval. For example, the central bank's confirmation of the updated nominal value is a transaction confirmation from the central bank, in particular a confirmation of the entry of the transaction in the blockchain. For example, the updated nominal value is the previous nominal value of the banknote less the amount paid.

[0173] According to embodiments, the update request is made in response to a transaction of an additional amount to the banknote's blockchain address. For example, the updated nominal value is the banknote's previous nominal value plus the additional amount. Embodiments may have the advantage of also taking into account changes to the nominal value during a transaction of an additional amount to the banknote's blockchain address.

[0174] According to embodiments, the method further comprises an issuing method for issuing a banknote. The issuing method comprises: Producing the banknote, wherein the banknote further comprises a security element with a processor and a memory with program instructions, generating a banknote-specific asymmetric key pair with a private and a public cryptographic key by the banknote, storing the generated banknote-specific asymmetric key pair in the memory by the banknote, wherein the private cryptographic key is stored in a protected memory area of ​​the memory, issuing the generated public cryptographic key by the banknote for initializing a banknote-specific blockchain address derived from the public cryptographic key by a central bank issuing the banknote in a blockchain, wherein the initial nominal value is assigned to the blockchain address of the banknote during the initialization.

[0175] According to embodiments, the produced banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. According to embodiments, the produced banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.

[0176] Embodiments can have the advantage that the banknote or banknote body is manufactured or printed. In addition to visual information and security elements, such as those found on known banknotes, the banknote also comprises, for example, a security element with a processor and a memory with program instructions. These program instructions include, for example, cryptographic program instructions for generating a banknote-specific asymmetric key pair with a private and a public cryptographic key by the banknote. In order for the banknote to be valid, it must, for example, be entered into the blockchain responsible for the serial number of the corresponding banknote. For this purpose, a banknote-specific blockchain address is derived from the public cryptographic key.This derivation can be carried out by the banknote itself and / or by an external computer system, for example, a computer system of the central bank that manages the blockchain. During the initialization of the banknote's blockchain address by the issuing central bank, for example, an initial nominal value assigned to the banknote or the banknote's serial number is entered into the relevant blockchain. This entry can, for example, take the form of a transaction with the corresponding amount and, if necessary, further information from a blockchain address of the central bank to the banknote's blockchain address. The further information includes, for example, the banknote's serial number, a minimum nominal value of the banknote and / or an additional nominal value component of the banknote. Alternatively, the assignment of the initial nominal value to the blockchain address could also be made by an entry from the central bank, e.g.An entry signed by the central bank, which includes the blockchain address, the initial nominal value, and / or other information regarding the banknote initialized by the entry. The additional information includes, for example, the banknote's serial number, a minimum nominal value of the banknote, and / or an additional nominal value component of the banknote.

[0177] According to embodiments, the issuing method is configured to issue or produce each of the previously described embodiments of the banknote. According to embodiments, the banknote issued using the issuing method is a banknote according to one of the previously described embodiments.

[0178] According to embodiments, the method further comprises sending a production confirmation to the issuing central bank to confirm the production of the banknote. The production confirmation comprises the serial number and the public cryptographic key of the produced banknote for initializing a banknote-specific blockchain address derived from the public cryptographic key by the issuing central bank in the blockchain. According to embodiments, the production confirmation further comprises an indication of an initial nominal value and / or a minimum nominal value of the banknote.

[0179] Embodiments can have the advantage that the production confirmation provides the central bank with all the information necessary to initialize the banknote in the blockchain responsible for the corresponding banknote or the serial number of the corresponding banknote. Alternatively or additionally, the production confirmation confirms to the central bank information characterizing the banknote. For example, the central bank specifies in an order to a banknote manufacturer which serial numbers are to be used to produce banknotes with which initial nominal values ​​and / or minimum nominal values. The production confirmation confirms to the central bank which banknotes with which serial numbers and which initial nominal values ​​and / or minimum nominal values ​​were actually produced.

[0180] According to embodiments, initialization comprises registering the blockchain address of the banknote through an initialization or registration entry of the issuing central bank in the blockchain. According to embodiments, the registration entry comprises the blockchain address of the banknote and the initial nominal value assigned to the banknote. According to embodiments, the registration entry is signed using a private cryptographic key of the issuing central bank. According to embodiments, the registration entry takes the form of a transaction of the initial nominal value from the issuing central bank, for example, from a blockchain address assigned to the central bank, to the blockchain address of the banknote. According to embodiments, the registration entry comprises the serial number of the banknote.According to embodiments, an assignment of the serial number of the banknote to the blockchain address of the banknote and / or the public key of the banknote is stored in an additional register of the issuing central bank, wherein the serial number serves as a database access key for reading the blockchain address and / or the public key of the banknote.

[0181] According to embodiments, the banknote is produced upon receipt of an order from a central bank issuing the banknote. According to embodiments, an indication of the predefined range of serial numbers is received. According to embodiments, an indication of the initial nominal value and / or minimum nominal value intended for the banknote is received.

[0182] According to embodiments, the method further comprises using a banknote. The banknote comprises a security element with a processor and a memory. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address of a blockchain of the blockchain system managed by a central bank issuing the banknote.

[0183] The processor is configured to execute a payment procedure with the banknote upon execution of the program instructions. The payment procedure includes: Receiving a payment request for a payment with the banknote in the form of a transaction of an amount to be paid from the blockchain address of the banknote to a blockchain address of a payee, wherein the payment request specifies the amount to be paid and the blockchain address of the payee, Signing a transaction release with the private cryptographic key of the banknote, wherein the transaction release includes the blockchain address of the banknote, the blockchain address of the payee and the amount to be paid, Sending the signed transaction release.

[0184] According to embodiments, a further transaction-specific value is also sent along with the signed transaction release. For example, the further transaction-specific value is included in the signature of the transaction release and / or attached to the signed transaction release. The further transaction-specific value is, for example, a timestamp and / or a random number.

[0185] According to embodiments, the banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. According to embodiments, the banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.

[0186] Embodiments may have the advantage that the banknote, as already described above, can be used not only for cash payments but also for cashless payments.

[0187] According to embodiments, the banknote used for payment is a banknote according to one of the previously described embodiments.

[0188] According to embodiments, the memory further stores a banknote-specific public cryptographic key of the banknote's asymmetric key pair, from which the banknote's blockchain address can be derived. According to embodiments, the memory further stores the banknote's blockchain address. Embodiments may have the advantage that the banknote has the blockchain address and / or can derive it.

[0189] According to embodiments, the banknote further comprises a visual indication of the banknote-specific public cryptographic key. According to embodiments, the banknote further comprises a visual indication of the banknote's blockchain address. If the banknote comprises a visual indication of the banknote-specific public cryptographic key and / or the banknote's blockchain address, the banknote-specific asymmetric key pair is generated, for example, during the production of the banknote, so that the banknote-specific public cryptographic key and / or the banknote's blockchain address can be printed on the banknote or otherwise incorporated into the banknote during production.Alternatively or additionally, the banknote may comprise a display device on which the banknote-specific public cryptographic key stored in the memory of the security element and / or the blockchain address of the banknote can be displayed as a visual indication.

[0190] According to embodiments, the banknote generates the transaction authorization using the details of the payment request. According to embodiments, the payment request includes the complete transaction details, which the banknote signs as the transaction authorization.

[0191] According to embodiments, the banknote provides the banknote's public cryptographic key to derive the banknote's blockchain address for the payment request. According to embodiments, the banknote's public cryptographic key is provided as a visual indication for reading. According to embodiments, the banknote's public cryptographic key is broadcast.

[0192] According to embodiments, the banknote provides the banknote's blockchain address for the payment request. According to embodiments, the banknote's blockchain address is provided as a visual indication for reading. According to embodiments, the banknote's blockchain address is sent by the banknote.

[0193] According to embodiments, the banknote comprises a communication interface for communicating with a terminal. The banknote receives the payment request from the terminal via the communication interface and / or sends the signed transaction authorization to the terminal via the communication interface.

[0194] According to embodiments, the banknote comprises a user interface for communicating with a user of the banknote, wherein the banknote receives the payment request from a user via an input device of the user interface and / or sends the signed transaction approval to the user interface for output via a display device of the user interface.

[0195] According to embodiments, the method further comprises payment processing using a terminal. The payment is made with a banknote, which comprises a communication interface for communication with the terminal and a security element with a processor and a memory. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address of a blockchain of the blockchain system managed by a central bank issuing the banknote. The terminal comprises a processor, a memory, and a communication interface for communication with the banknote.

[0196] The procedure for processing a payment transfer through the terminal includes: Sending a payment request to the banknote in the form of a transaction of an amount to be paid from the blockchain address of the banknote to a blockchain address of a payee, wherein the payment request specifies the amount to be paid and the blockchain address of the payee, receiving a transaction approval signed with the private cryptographic key of the banknote, wherein the transaction approval comprises the blockchain address of the banknote, the blockchain address of the payee and the amount to be paid, forwarding the signed transaction approval of the banknote to a blockchain server of the blockchain which is assigned to the range of serial numbers into which the serial number of the corresponding banknote falls, for checking and entering the transaction in the blockchain, upon successful verification of the signed transaction approval, receiving a first transaction confirmation.

[0197] According to embodiments, a further transaction-specific value is also received along with the signed transaction release. For example, the further transaction-specific value is included in the signature of the transaction release and / or attached to the signed transaction release. The further transaction-specific value is, for example, a timestamp and / or a random number.

[0198] According to embodiments, the banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. According to embodiments, the banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.

[0199] Embodiments may have the advantage of enabling cashless payment processing via a terminal. According to embodiments, the banknote used for payment processing is a banknote according to one of the previously described embodiments.

[0200] Embodiments may have the advantage that the central bank, in addition to its role as the institution issuing the banknote, also provides services in the area of ​​payment transactions or payment processing to the banknote and / or the terminal or a payee using it and thus acts as a classic bank or a commercial bank.

[0201] A central bank is defined here as a national or supranational institution that has the monopoly right to issue coins and banknotes as legal tender. Furthermore, a central bank can perform monetary and exchange-rate policy functions. For example, a central bank holds the currency reserves of a currency area, regulates the money supply, influences money creation through lending by commercial banks, and / or refinances these commercial banks and the government. For example, the central bank issues banknotes and puts them into circulation.

[0202] The terminal can, for example, be a vendor's terminal at a point of sale (PoS), i.e., the location where a sale is made. The terminal can also be a terminal connected to a user's computer system through which a payment is to be processed using the banknote. For example, this could involve a payment being processed via a network, such as the Internet, to a service provider, be it a vendor or a payment service provider. The terminal could also be provided in the form of a user's mobile, portable communications device, such as a smartphone. The user could use the mobile, portable communications device, for example, to process a payment via a network, such as the Internet, to a service provider, be it a vendor or a payment service provider.

[0203] According to embodiments, the verification of the signed transaction authorization includes verifying the signature of the transaction authorization and checking whether a current nominal value of the banknote assigned to the blockchain address of the banknote is greater than or equal to the amount to be paid. Embodiments can have the advantage of allowing an effective verification. For example, the transaction can be confirmed even before the transaction is entered into the blockchain responsible for the serial number of the banknote authorizing the transaction.This may be the case, for example, if it is ensured that no other previous transactions from the banknote's blockchain address are waiting to be entered into the relevant blockchain and / or the confirmation is made subject to the proviso that other previous transactions from the banknote's blockchain address may be waiting to be entered into the relevant blockchain.

[0204] According to embodiments, the first transaction confirmation is a preliminary transaction confirmation, in which the current nominal value of the banknote is verified using a register that is updated at regular intervals and that contains a current nominal value for the blockchain addresses of a blockchain of the plurality of blockchains assigned to the register, which results from the balances of the transactions stored in the corresponding blockchain using the corresponding blockchain addresses. The first transaction confirmation is accepted as sufficient transaction confirmation if the amount to be paid does not exceed a threshold. Like the corresponding blockchain, the associated register is also assigned to the same range of serial numbers. Thus, the blockchain system comprises, for example, a plurality of corresponding registers.According to embodiments, the blockchain system comprises a register for each of the blockchains of the plurality of blockchains and thus for each of the ranges of serial numbers into which the space of serial numbers is divided.

[0205] Embodiments may have the advantage that the current nominal value of the banknote can be quickly verified without first having to calculate the complete balance of the transactions stored in the associated blockchain using the corresponding blockchain addresses.

[0206] For example, based on the determined current nominal value, a decision can be made as to whether a cash or cashless payment should be made with the banknote. If the current nominal value is identical to the amount to be paid, a cash payment is made, for example, in which the banknote is handed over to the payee and ownership of it is transferred to the payee. If the current nominal value is greater than the amount to be paid, a cashless payment is made, for example, in which a corresponding payment request for a payment in the form of a transaction of an amount to be paid is sent from the banknote's blockchain address to a payee's blockchain address on the banknote. The banknote can authorize this transaction with a signed transaction release.

[0207] If the current nominal value is greater than the amount to be paid, it would also be possible for a cash payment to be made and the excess amount to be repaid by the payee as change, for example in the form of cash.

[0208] For example, the nominal value of the banknote can also include a guaranteed minimum nominal value and a variable additional nominal value component. The minimum nominal value can, for example, only be paid in the form of a cash payment upon handover of the banknote, while the variable additional nominal value component can be used in the course of a cash-based or cashless payment transaction. In other words, the banknote can only be used for cashless payments where the remaining nominal value of the banknote is greater than or equal to the minimum nominal value. If an amount is to be paid with the banknote that would result in a remaining nominal value that is less than the minimum nominal value, a cashless payment is blocked via the relevant blockchain, for example. Therefore, a cash-based payment must be made, for example, in which the banknote is handed over.If the current nominal value of the banknote is greater than the amount to be paid, the difference can be refunded by the payee, for example in the form of change.

[0209] For example, the register used for preliminary transaction confirmation also includes an indication of the minimum nominal value of the banknote with the corresponding blockchain address.

[0210] According to some embodiments, the first transaction confirmation is not accepted as sufficient if the amount to be paid exceeds the threshold. A second transaction confirmation is received, which confirms the entry of the transaction in the relevant blockchain, which is accepted as sufficient. Some embodiments may have the advantage that it can be safely assumed that the transaction was successful if the transaction has actually been entered into the relevant blockchain.

[0211] According to embodiments, the public cryptographic key is further received. For example, the public cryptographic key is received before sending the payment request. For example, the public cryptographic key is scanned or read as visual information provided by the banknote. For example, the public cryptographic key is received from the banknote in response to a request sent to the banknote. Embodiments may have the advantage that the public cryptographic key can be used by the terminal to derive the banknote's blockchain address. The derived banknote's blockchain address or the public cryptographic key can be sent to the banknote as part of the payment request.For example, the payment request can include the complete transaction details, which only need to be signed by the banknote to generate the signed transaction confirmation.

[0212] According to embodiments, receiving the public cryptographic key comprises reading the visual indication of the public cryptographic key using a sensor of the terminal. For example, the visual indication comprises an alphanumeric character string, a barcode, or a QR code of the public cryptographic key. According to embodiments, receiving the public cryptographic key comprises receiving the public cryptographic key sent using the communication interface of the banknote using the communication interface of the terminal.

[0213] According to embodiments, the payment processing method further comprises deriving the blockchain address of the banknote from the banknote's public cryptographic key. For example, the payment request includes the complete transaction details with the blockchain address derived from the banknote's public cryptographic key, which the banknote signs as a transaction authorization.

[0214] According to embodiments, the banknote comprises a plurality of security features. For example, the method comprises, as a prerequisite for sending the payment request, the successful capture and validation of one or more predefined security features of the banknote's multiple security features. For example, the method comprises, as a prerequisite for forwarding the signed transaction approval of the banknote, the successful capture and validation of one or more predefined security features of the banknote's multiple security features. Embodiments can have the advantage that the authenticity and validity of the banknote can be verified based on the security features.

[0215] According to embodiments, the method includes, as a prerequisite for sending the payment request: Capturing an identifier that uniquely identifies the blockchain address of the banknote, where the captured identifier is one of the following: the serial number of the banknote, the public cryptographic key of the banknote, the blockchain address of the banknote, sending a blockchain query for the current nominal value of the blockchain address of the banknote, receiving the current nominal value of the blockchain address of the banknote, checking whether the received current nominal value is greater than or equal to the amount to be paid, whereby the payment request is sent to the banknote upon a successful check.

[0216] Embodiments may have the advantage of ensuring that the current nominal value assigned to the banknote is greater than or equal to the amount to be paid. In other words, it can be ensured that the banknote actually has sufficient value to pay the amount to be paid.

[0217] According to embodiments, detecting the identifier comprises reading a visual indication of the identifier contained in the banknote using a sensor of the terminal. The sensor is, for example, an optical sensor. According to embodiments, detecting the identifier comprises receiving the identifier sent using the communication interface of the banknote using the communication interface of the terminal. For example, the identifier is stored in the memory of the security element.

[0218] According to embodiments, the received current nominal value of the banknote is a nominal value of the banknote's blockchain address read from the register. The register is updated at regular intervals and contains a current nominal value for each blockchain address of the associated blockchain, which is derived from the balances of the transactions stored in the associated blockchain using the corresponding blockchain addresses. According to embodiments, the received current nominal value of the banknote is a nominal value of the banknote's blockchain address read from the blockchain responsible for the serial number of the corresponding banknote. The read current nominal value of the banknote results, for example, from the balance of the transactions stored in the corresponding blockchain, including the banknote's blockchain address.

[0219] Embodiments may have the advantage of efficiently determining a current nominal value. For example, it is not necessary to first calculate the complete balance sheets of the transactions stored in the associated blockchain using the corresponding blockchain addresses.

[0220] According to embodiments, a plurality of banknotes are received. The identifiers of the blockchain addresses of the banknotes are recorded, for example, serial numbers, public cryptographic keys, and / or the blockchain addresses themselves, and for each of the banknotes, a current nominal value is determined using a blockchain query for the banknotes according to the assigned blockchain addresses. From the plurality of received banknotes, a set of banknotes is selected and retained whose summed current nominal values ​​result in an amount that is less than an amount to be paid. A remaining difference between the amount to be paid and the summed amount of the set of selected banknotes is less than a current nominal value of another banknote of the plurality of banknotes that is not included in the set of selected banknotes.The payment request is sent to the other banknote to pay the difference.

[0221] Embodiments may have the advantage of enabling a combination of cash-based and cashless payment. For the retained set of banknotes, there is no need for transaction approvals and / or entries of corresponding transactions in the blockchain. Instead, payment with these banknotes is made by handing over the banknotes, as is usual for cash payments. If the amount to be paid does not add up, i.e., the sum of the nominal values ​​of the banknotes in the retained set of banknotes is less than the amount to be paid and no further banknote is available whose nominal value corresponds to the difference, the difference is paid cashlessly using another banknote whose nominal value is greater than the corresponding difference. Alternatively, the difference can be paid by retaining the additional banknote, and the excess amount paid is refunded.For example, through a transaction from a blockchain address of the payee to a blockchain address of a non-retained banknote, which remains the property of the payer. According to the implementation, all non-retained banknotes are returned.

[0222] According to embodiments, the banknotes of the plurality of banknotes each comprise a plurality of security features. The method comprises, for example, a validity check for each of the banknotes. The validity check of the banknotes comprises, for example, a successful detection and validation of one or more predefined security features of the plurality of security features of the corresponding banknote. Embodiments can have the advantage that the authenticity and validity of all banknotes can be ensured, in particular of the retained banknotes.

[0223] According to embodiments, the method further comprises determining a current nominal value of a banknote using a terminal. The banknote comprises a communication interface for communicating with the terminal and a security element having a processor and a memory. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address of the banknote. The terminal comprises a processor, a memory, and a communication interface for communicating with the banknote.

[0224] Determining the current nominal value by the terminal includes: Capturing an identifier that uniquely identifies the blockchain address of the banknote, wherein the captured identifier is one of the following: the serial number of the banknote, the public cryptographic key of the banknote, the blockchain address of the banknote, Sending a message with a blockchain query for the current nominal value of the blockchain address of the banknote, wherein the message includes the serial number of the banknote, Receiving the current nominal value of the blockchain address of the banknote.

[0225] For example, using the banknote's serial number, a blockchain of the plurality of blockchains is determined that is associated with the range of serial numbers that includes the corresponding serial number. For example, the message containing the blockchain query is sent to a blockchain server that manages the specific blockchain.

[0226] For example, the method further comprises: Receiving the message of the message with the blockchain query, determining, using the serial number of the banknote comprising the message, a blockchain of the plurality of blockchains which is associated with the range of serial numbers comprising the corresponding serial number, forwarding the message to a blockchain server which manages the particular blockchain to determine the current nominal value of the blockchain address of the banknote.

[0227] According to embodiments, the banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. According to embodiments, the banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.

[0228] Embodiments may have the advantage that the terminal can determine the current nominal value of the banknote based on the identifier, such as the serial number, the public cryptographic key, or the blockchain address itself. To this end, the banknote, for example, contains visual information of the corresponding identifier and / or reads it from the security element. Using the serial number may have the advantage that the serial number can be available independently of the generation of the banknote's public cryptographic key and thus the banknote's blockchain address. Thus, the serial number can be printed on the banknote and / or otherwise incorporated into the banknote before the banknote's asymmetric cryptographic key pair is generated. This makes it possible to first complete the banknote's production and then generate the banknote's asymmetric cryptographic key pair.Otherwise, for example, before or at the beginning of banknote production, the asymmetric cryptographic key pair of the banknote is generated by the security element, and the public cryptographic key and / or the blockchain address derived therefrom are made available for use in banknote production. For example, the public cryptographic key is issued by the security element before or at the beginning of banknote production. The issued public cryptographic key is assigned, for example, to the serial number of the banknote to be produced, thus assigning the security model to the serial number of the banknote to be produced.

[0229] According to embodiments, detecting the identifier comprises reading a visual indication of the identifier using a sensor of the terminal. According to embodiments, detecting the identifier comprises receiving the identifier transmitted using the communication interface of the banknote using the communication interface of the terminal.

[0230] For example, the current nominal value is determined during a cash-based payment transaction by handing over the corresponding banknote in order to determine the actual value and thus the amount of money actually handed over in cash.

[0231] According to embodiments, the received current nominal value of the banknote is a nominal value of the blockchain address of the banknote read from the register assigned to the range of serial numbers with the serial number of the banknote. The register is updated at regular intervals and includes a current nominal value for each blockchain address of the associated blockchain, which results from the balances of the transactions stored in the associated blockchain using the corresponding blockchain addresses. According to embodiments, the received current nominal value of the banknote is a nominal value of the blockchain address of the banknote read from the blockchain assigned to the range of serial numbers with the serial number of the banknote.The current nominal value of the banknote is derived, for example, from the balance of transactions stored in the corresponding blockchain, including the banknote's blockchain address.

[0232] According to embodiments, the banknote whose current nominal value is determined is a banknote according to one of the previously described embodiments.

[0233] According to embodiments, the method further comprises replacing a banknote. The banknote comprises a visual indication of a serial number that uniquely identifies the banknote and an initial nominal value assigned to the banknote. The banknote comprises the visual indication of the serial number distributed multiple times across the banknote. The banknote comprises a plurality of security features distributed across the banknote. The banknote comprises a security element with a processor and a memory with program instructions. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address of the banknote. Furthermore, the banknote exhibits damage.

[0234] The replacement of the banknote by the central bank issuing the damaged banknote includes: Checking the degree of damage of the banknote if the degree of damage of the banknote does not exceed a predefined permissible maximum degree of damage, Capturing an identifier that uniquely identifies the blockchain address of the damaged banknote, wherein the captured identifier is one of the following: the serial number of the damaged banknote, the public cryptographic key of the damaged banknote, the blockchain address of the damaged banknote, Initiating a block of the blockchain address of the banknote using the captured identifier, Sending a message with a blockchain query for the current nominal value of the blockchain address of the damaged banknote, wherein the message includes the serial number of the banknote, Receiving the current nominal value of the blockchain address of the damaged banknote, Paying out the current nominal value of the damaged banknote.

[0235] For example, using the banknote's serial number, a blockchain of the plurality of blockchains is determined that is associated with the range of serial numbers that includes the corresponding serial number. For example, the message containing the blockchain query is sent to a blockchain server that manages the specific blockchain.

[0236] For example, the method further comprises: Receiving the message of the message with the blockchain query, determining, using the serial number of the banknote comprising the message, a blockchain of the plurality of blockchains which is associated with the range of serial numbers comprising the corresponding serial number, forwarding the message to a blockchain server which manages the particular blockchain to determine the current nominal value of the blockchain address of the banknote.

[0237] Embodiments may have the advantage that, in the event of damage, the actual nominal value of the banknote can be replaced. This actual nominal value may differ significantly from the initial nominal value of the banknote and / or a minimum nominal value of the banknote. According to embodiments, in order to ensure that the degree of damage to the banknote does not exceed a predefined permissible maximum degree of damage, it is necessary that more than 50% of the banknote is present and / or that the banknote includes one or more valid security features necessary for replacement.

[0238] According to some embodiments, the replaced banknote is a banknote according to one of the previously described embodiments. According to some embodiments, the damaged banknote is retained.

[0239] According to embodiments, paying out the current nominal value of the damaged banknote comprises providing one or more banknotes as replacements, the current nominal values ​​of which in sum correspond to the current nominal value of the damaged banknote. According to embodiments, the one or more banknotes as replacements are banknotes according to one of the previously described embodiments. According to embodiments, paying out the current nominal value of the damaged banknote comprises entering a transaction of an amount equal to the current nominal value from a blockchain address of the central bank issuing the damaged banknote to a blockchain address specified by an owner of the damaged banknote. For example, the specified blockchain address of another banknote of the owner, i.e.owner of the damaged banknotes, the owner of the damaged banknote personally or another institution chosen by the owner of the damaged banknotes.

[0240] According to embodiments, the corruption comprises corruption of the security element such that the security element can no longer provide signed transaction authorizations. For example, the processor, memory, and / or a communication interface of the security element is corrupted. For example, the security element is missing.

[0241] According to embodiments, the majority of identifier details are distributed across the banknote in such a way that it can be ensured that the identifier and thus the blockchain address of the banknote can be determined as long as more than 50% of the banknote is present. According to embodiments, the majority of security elements are distributed across the banknote in such a way that it can be ensured that the valid security features necessary for replacement are present as long as more than 50% of the banknote is undamaged.

[0242] According to embodiments, the replacement of the banknote by the central bank issuing the damaged banknote further comprises a blocking entry in the blockchain, which is assigned to the range of serial numbers with the serial number of the banknote to be replaced, by the central bank managing the blockchain and issuing the banknote. For example, a corresponding blocking entry is entered into all blockchains of the plurality of blockchains. The blocking entry blocks the corresponding blockchain address. The blocking entry indicates, for example, that the blockchain address of the banknote is invalid. In the case of a blocking entry for the blockchain address of the banknote by the central bank, it can be ensured, for example, that no money can be transferred from the invalid blockchain address to another blockchain address, i.e.that no payments can be sent, and / or that no money can be transferred from another blockchain address to the invalid blockchain address, i.e. that no payments can be received.

[0243] Embodiments could have the advantage that, when the banknote is replaced, the processor and / or the security element of the damaged banknote are not retained, allowing payments to continue to be made, i.e., signed transaction confirmations, after the (last) current nominal value of the damaged banknote has been paid out. Furthermore, it can be prevented, for example, that payments are accidentally made to the blockchain address of the damaged banknote after the (last) current nominal value has already been paid out and the damaged banknote has been retained. In this case, there would be no way to access the inadvertently transferred money.

[0244] For example, when executing a transaction from a banknote's blockchain address, a prerequisite for executing the transaction is whether the corresponding blockchain address is locked. If the blockchain address is unlocked, the transaction is executed, i.e., it is entered into the blockchain responsible for the serial number of the paying banknote. If the blockchain address is locked, the transaction is not executed, i.e., it is not entered into the corresponding blockchain.

[0245] For example, when a transaction is made to a banknote's blockchain address, a prerequisite for executing the transaction is whether the corresponding blockchain address is blocked. If the blockchain address is not blocked, the transaction is executed, i.e., it is entered into the blockchain responsible for the serial number of the paying banknote. If the blockchain address is blocked, the transaction is not executed, i.e., it is not entered into the corresponding blockchain. The same applies, for example, to an additional entry of the transaction in the blockchain responsible for the serial number of the receiving banknote.

[0246] Embodiments of the invention will be explained in more detail below with reference to the drawings. They show: Figures 1 schematic block diagrams of exemplary banknotes, Figure 2 a schematic block diagram of an exemplary system with an exemplary banknote, Figure 3 a schematic flow diagram of an exemplary method for issuing banknotes, Figure 4 a schematic flow diagram of an exemplary method for payment processing with a terminal, Figure 5 a schematic flow diagram of an exemplary method for determining a current nominal value, Figure 6 a schematic flow diagram of an exemplary method for payment processing with a mobile portable communication device, Figure 7 a schematic flow diagram of an exemplary method for replacing a banknote, Figure 8 a schematic flow diagram of an exemplary method for using a banknote, Figure 9 a schematic flow diagram of an exemplary method for issuing a banknote,Figure 10 shows a schematic flow diagram of an exemplary method for payment processing with a terminal. Figure 11 shows a schematic flow diagram of an exemplary method for payment processing with a plurality of banknotes. Figure 12 shows a schematic flow diagram of an exemplary method for determining a current nominal value. Figure 13 shows a schematic flow diagram of an exemplary method for replacing a banknote. Figure 14 shows a schematic flow diagram of an exemplary method for forwarding a transaction approval. Figure 15 shows a schematic flow diagram of an exemplary method for splitting the blockchain. Figure 16 shows a schematic flow diagram of an exemplary method for deriving a private cryptographic key. Figure 17 shows a schematic flow diagram of an exemplary method for deriving a private cryptographic key.Figure 18 shows a schematic flow diagram of an exemplary method for deriving a private cryptographic key. Figure 19 shows a schematic flow diagram of an exemplary method for deriving a private cryptographic key.

[0247] Elements of the following embodiments that correspond to one another are identified by the same reference numerals.

[0248] Figures 1 , i.e. Figures 1A to 1D , show exemplary mobile portable devices in the form of banknotes 100. The Figure 1AThe banknote 100 shown comprises a plurality of security features 110 which prove the authenticity and validity of the banknote 100. The security features 110 are arranged distributed across the banknote 100. For example, the security features 110 are arranged distributed across the banknote 100 in such a way that as long as more than 50% of the banknote is in an undamaged state, the authenticity and validity of the banknote 100 can be proven. The banknote 100 further comprises a visual indication of the serial number 106 of the banknote 100, which is printed on the banknote 100, for example. For example, the banknote 100 comprises a plurality of visual indications of the serial number 106 which are arranged distributed across the banknote 100, for example in microprint.For example, the serial number 106 is distributed across the banknote 100 in such a way that, as long as more than 50% of the banknote is in an undamaged condition, the serial number 106 of the banknote 100 can be determined. The serial number 106 of the banknote 100 is assigned, for example, to a public cryptographic key from which the blockchain address of the banknote 100 can be derived, and / or a blockchain address of the banknote 100. Thus, using the serial number 106 of the banknote 100, for example, the public cryptographic key from which the blockchain address of the banknote 100 can be derived and / or a blockchain address of the banknote 100 can be determined.

[0249] Furthermore, the banknote comprises one or more visual indications of an initial nominal value 108 of the banknote 100. The initial nominal value 108 is, for example, a minimum nominal value of the banknote 100. For example, the banknote 100 comprises one or more visual indications of a minimum nominal value different from the initial nominal value 108 in addition to the indication of the initial nominal value 108. For example, the banknote 100 comprises the one or more visual indications of the minimum nominal value instead of visual indications of an initial nominal value 108 different from the minimum nominal value. In addition, the banknote comprises a security element 102 with a processor and a memory. A private cryptographic key for signing transaction releases, i.e., for releasing or authorizing transactions from a blockchain address assigned to the banknote 100, is stored in a protected memory area of ​​the memory.Furthermore, the banknote 100 comprises a communication interface 104 for communicating with a terminal, in particular for contactless communication. Via the communication interface 104, the banknote 100 receives, for example, payment requests and sends, for example, signed transaction approvals.

[0250] Figure 1B shows an exemplary banknote 100, which corresponds to the exemplary banknote 100 from Figure 1A In addition, the banknote includes 100 in Figure 1Ba user interface 112. The user interface 112 comprises, for example, an input and / or output device of the banknote 100. For example, the user interface 112 comprises a touchpad for entering data, such as transaction data, into the banknote 100 and / or a display for displaying data, such as transaction data, that the banknote 100 is to process or has processed. For example, the user interface 112 comprises a touch display with which data can be entered by the user and data can be displayed to the user.

[0251] Figure 1C shows an exemplary banknote 100, which corresponds to the exemplary banknote 100 from Figure 1A In addition, the banknote includes 100 in Figure 1CIn addition to the visual indication of the serial number 106, a visual indication that identifies the blockchain address of the banknote 100. The additional information is, for example, a public cryptographic key 116 from which the blockchain address of the banknote 100 can be derived, and / or the blockchain address of the banknote 100. Figure 1D shows an exemplary banknote 100, which corresponds to the exemplary banknote 100 from Figure 1C In the case of the banknote in Figure 1DThe banknote 100 includes a plurality of additional visual indicia that identify a blockchain address of the banknote 100, such as the public cryptographic key 116. These additional visual indicia are distributed, for example, across the banknote 100, such as in microprint. For example, the additional visual indicia are distributed across the banknote 100 such that, as long as more than 50% of the banknote is in an undamaged state, the blockchain address of the banknote 100 can be identified.

[0252] Figure 2shows an exemplary system 157 with an exemplary mobile portable terminal in the form of a banknote 100. The banknote 100 comprises a security element 102 with a processor 124 and a memory 120. The processor 124 is configured for program instructions 128. These program instructions 128 include, for example, cryptographic program instructions for generating an asymmetric key pair 116, 118 of the banknote 100 and for signing transaction releases with a private cryptographic key 118 of the asymmetric key pair. Furthermore, the cryptographic program instructions can be configured, for example, to derive a blockchain address of the banknote 110 from the public cryptographic key 116. The public cryptographic key 116 of the asymmetric key pair is stored in the memory 120. Furthermore, the memory 120 stores, for example, the serial number 106 of the banknote 100.The private cryptographic key 118 of the asymmetric key pair is stored in a protected storage area 122 of the memory 120. Furthermore, the banknote 100 comprises, for example, a communication interface 104 for communication with external devices, such as a terminal 130. The communication interface 104 is configured, for example, for contactless communication. In addition, the banknote 100 comprises visual information 107, such as the serial number 106 and / or the public cryptographic key 116. Furthermore, the banknote 100 can, for example, further comprise a user interface with an input and / or output device for entering and / or displaying data, such as transaction data.

[0253] Banknote 100 communicates, for example, with a terminal 130 using communication interface 104. Terminal 130 is, for example, a payment terminal of a PoS. Terminal 130 comprises a processor 134 for executing program instructions 136 and a memory 132. Terminal 130 further comprises a communication interface 137 for communicating with banknote 100. In addition, terminal 130 comprises a communication interface 139 for communicating via a network 160, such as the Internet. Terminal 130 is configured, for example, to process payments with banknote 100.For this purpose, the terminal 130 sends, for example, a payment request to the banknote 100 and receives a message with a signed transaction authorization from the banknote 100, which the terminal 130 forwards via the network 160 to a blockchain server 140, 141, 161 of the blockchain system 156 responsible for the serial number 106 of the corresponding banknote 100 for entering the transaction authorized by the signed transaction authorization into a blockchain 148, 149, 167 managed by the corresponding blockchain server 140, 141, 161. The serial number 106 of the banknote 100 included in the message is used to determine the responsible blockchain 148, 149, 167 and thus the responsible blockchain server 140, 141, 161. The blockchain servers 140, 141, 161 belong, for example, to a blockchain network 154 of the blockchain system 156. Furthermore, the terminal can comprise, for example, sensor 139.The sensor 139 is configured, for example, to detect visual information 107 of the banknote 100, such as the serial number 106 and / or the public cryptographic key 116. Furthermore, the sensor 139 can be configured, for example, to detect security features of the banknote 100 in order to verify its authenticity and validity. For example, a blockchain address is stored in the memory 132, which the terminal 130 uses as a recipient address for receiving payments.

[0254] The terminal 130 communicates, for example, with the blockchain servers 140, 141 via a remote server 170. The server 170 includes, for example, a memory 172, a processor 174 for executing program instructions 176, and a communication interface 178 for communication via the network 160. For example, the server 170 provides the terminal 130 with the blockchain address to be used as the recipient address. For example, the server 170 forwards signed transaction approvals received via the terminal 130 to the blockchain servers 140, 141. For example, the server 170 forwards transaction confirmations and / or entry confirmations received from the blockchain servers 140, 141 to the terminal 130.

[0255] The system 157 further comprises a blockchain system 156. The blockchain system 156 comprises a plurality of blockchains 148, 149, 167. Each of the blockchains 148, 149, 167 is assigned one or more blockchain servers 140, 141, 161, which manage the corresponding blockchain 148, 149, 167. Each banknote 100 of a plurality of issued banknotes is assigned a serial number 106 from a range of serial numbers. The range of serial numbers is divided into a plurality of ranges of serial numbers. Each of the ranges of serial numbers is assigned one of the blockchains 148, 149, 167 of the blockchain system 156, which logs payments from banknote-specific blockchain addresses assigned to banknotes with serial numbers from the corresponding range of serial numbers.

[0256] The blockchain servers 140, 141, 161 are, for example, part of a blockchain network 154 or form blockchain nodes of a blockchain network 154. The blockchain servers 140, 141, 161 and / or the blockchain network 154 are managed, for example, by a central bank issuing the banknote. If the central bank is a central bank to which several countries belong, the blockchain network 154 comprises, for example, one or more blockchain servers 140, 141, 161 per country. For example, the blockchain servers 140, 141 and / or the blockchain network 154 are comprised of a blockchain system 156, which is managed, for example, by a responsible central bank. The blockchain server 140 comprises, for example, a memory, a processor 142 for executing program instructions 144, and a communication interface 152 for communication via the network 160.For example, a copy of the blockchain 148 and / or a register 150, which is managed by the corresponding blockchain server 140, is stored in the memory 146. The register 150 is, for example, a register updated at regular intervals, which contains a current nominal value for each blockchain address of the associated blockchain 148. The current nominal values ​​are calculated from the balances of the transactions stored in the blockchain 148 for the corresponding blockchain addresses. The register 150 provides, for example, a "fast blockchain," in which the precalculated balance results for the blockchain addresses are provided as current nominal values ​​of the corresponding blockchain addresses. Using such a register 150 can have the advantage that current nominal values ​​can be determined more quickly, since they are already available and do not have to be calculated first.The register 150 can, for example, be managed by a virtual machine (VM) of the blockchain server 140.

[0257] The blockchain server 140 can be configured to register and / or block banknotes or blockchain addresses of banknotes with serial numbers that fall within the range of serial numbers assigned to the blockchain 148 in the blockchain 148 upon request from the central bank. The blockchain server 140 can be configured to provide, upon request, information about current nominal values ​​of banknotes according to the transactions stored in the blockchain 148 using the blockchain addresses of the corresponding banknotes. For example, the blockchain server 140 uses the associated register 150 to provide corresponding information. The blockchain system 156 comprises one or more further blockchain servers 141, 161 for each of the further blockchains 149, 167, which manage the further blockchains 149, 167.The blockchain servers 141, 161 each comprise, for example, a memory 147, 166, a processor 143, 163 for executing program instructions 145, and a communication interface 153, 169 for communication via the network 160. For example, a copy of the blockchain 149, 167 managed by the respective blockchain servers 141, 161 is stored in the memories 147, 166. Furthermore, a copy of a register 151, 168 belonging to the corresponding blockchain 149, 167 managed by the respective blockchain server 141, 161 is stored in the memories 147, 166. The blockchain servers 141, 161 are configured, for example, to register and / or block banknotes or blockchain addresses of banknotes with serial numbers that fall within the range of serial numbers assigned to the respective blockchain 149, 167 in the corresponding blockchain 149, 167 upon request from the central bank.

[0258] Instead of terminal 130, a mobile, portable communication device 180 or a user computer system 190, for example, for payment processing via the Internet, can also be used for payment processing. The mobile communication device 180 or the user computer system 190 can serve, for example, as a local PoS. For example, payment processing takes place using remote server 170. For example, payment processing takes place using a server 200 of a payment service provider or a financial service provider.

[0259] The mobile communication device 180, such as a smartphone, comprises, for example, a memory 182 and a processor 184 for executing program instructions 186. Furthermore, the mobile communication device 180 comprises, for example, a communication interface 187 for communicating with the banknote 100 and a communication interface 188 for communicating via the network 160. For example, the mobile communication device 180 comprises a camera for capturing visual information 107 of the banknote 100, such as the serial number 106 or the public cryptographic key 116 of the banknote 100. The mobile communication device 180 is configured, for example, to forward a payment request, such as from the server 170 or the payment service server 200, to the banknote 100 and a transaction approval signed by the banknote 100 to the server 170 or the payment service server 200.For example, the mobile communication device 180 is further configured, for example using the camera 189, to determine the blockchain address of the banknote 100 and to supplement the payment request to the banknote 100 with the blockchain address as the payment originating address. Furthermore, the mobile communication device 180 can be configured to determine, directly or through a server such as the server 170 or the payment service server 200, the current nominal value of the banknote 100 according to the blockchain 148 responsible for the serial number 106 of the corresponding banknote 100 and to display it to a user using a user interface 181. The user interface 181 comprises, for example, an input and an output device for communication between the user and the mobile communication device 180. The input device comprises, for example, a keyboard. The output device comprises, for example, a display.For example, input and output devices are combined in the form of a touch display.

[0260] The user computer system 190 comprises, for example, a memory 192 and a processor 194 for executing program instructions 196. Furthermore, the user computer system 190 comprises, for example, a communication interface 197 for communicating with the banknote 100 and a communication interface 198 for communicating via the network 160. For example, the user computer system 190 comprises a sensor, such as a camera, for capturing visual information 107 of the banknote 100, such as the serial number 106 or the public cryptographic key 116 of the banknote 100. The user computer system 190 is configured, for example, to forward a payment request, for example from the server 170 or the payment service server 200, to the banknote 100 and a transaction approval signed by the banknote to the server 170 or the payment service server 200.For example, the user computer system 190 is further configured, for example using the sensor 199, to determine the blockchain address of the banknote 100 and to supplement the payment request to the banknote 100 with the blockchain address as the payment originating address. Furthermore, the user computer system 190 can be configured to determine, directly or through a server such as the server 170 or the payment service server 200, the current nominal value of the banknote 100 according to the blockchain 148 responsible for the serial number 106 of the corresponding banknote 100 and to display it to a user using a user interface 191. The user interface 191 comprises, for example, an input and an output device for communication between the user and the mobile communication device 190. The input device comprises, for example, a keyboard and / or mouse. The output device comprises, for example, a display.For example, input and output devices are combined in the form of a touch display.

[0261] The payment service provider's server 200 is configured, for example, to enable payment processing using the banknote 100 and a local device for communicating with the banknote 100, such as the mobile communication device 180 or the user computer system 190. The payment service server 200 comprises, for example, a memory 202, a processor 204 for executing program instructions 206, and a communication interface 208 for communicating via the network 160. For example, the payment service server 200 provides the local device with transaction data for a transaction to be executed, such as a blockchain address to be used as the recipient address and / or information on the amount to be paid. For example, the payment service server 200 forwards signed transaction approvals received via the local device to the blockchain servers 140, 141.For example, the payment service server 200 forwards transaction confirmations and / or entry confirmations received from the blockchain servers 140, 141 to the local device.

[0262] The system 157 comprises, for example, a manufacturer computer system 210, which is used during the production of the banknote 100. The manufacturer computer system 210 comprises, for example, a memory 212 and a processor 214 for executing program instructions 216. The manufacturer computer system 210 further comprises, for example, a communication interface 221 for communicating with the banknote 100. For example, the manufacturer computer system 210 reads the public cryptographic key 116 of the banknote 100 using the communication interface 217. For example, the manufacturer computer system 210 sends data for storage to the banknote 100, such as the serial number 106 of the banknote 100, using the communication interface 217. The manufacturer computer system 210 further comprises, for example, a sensor 219 for checking the banknote 100.For example, a quality control of banknote 100 is performed using sensor 219. If banknote 100 passes the quality control, a manufacturing confirmation is sent to the central bank, for example, from manufacturer computer system 210 using a communication interface 218 for communicating with a central bank computer system, such as central bank computer system 220. The manufacturing confirmation includes, for example, the serial number 106 and / or the public cryptographic key 116 of banknote 100 for initializing banknote 100 in the blockchain 148 responsible for the serial number 106 of the corresponding banknote 100.

[0263] The system 157 further comprises, for example, a central bank computer system 220 with a memory 222 and a processor 224 for executing program instructions 226. The central bank computer system 220 further comprises, for example, a communication interface 228 for communicating with the manufacturer computer system 210 and / or with the blockchain servers 140, 141, for example via the network 160. The central bank computer system 220 is configured, for example, to register and / or block banknotes or blockchain addresses of banknotes in the blockchains 148, 149, 167 responsible for the serial numbers of the corresponding banknotes. In other words, the central bank computer system 220 is configured, for example, to send an initialization request and / or a blocking request for initializing or blocking the banknote 100 to one of the blockchain servers 140, 141.To create the initialization request, the central bank computer system 220 uses, for example, data provided by the manufacturer's computer system in the form of the manufacturing confirmation. Furthermore, the central bank computer system 220 can, for example, include a sensor for checking the security features of a damaged banknote. If the check of the security features and the degree of damage to the banknote reveals that it is a valid banknote, the central bank replaces the damaged banknote. To do so, the central bank computer system 220 determines, for example, the current nominal value of the damaged banknote using a corresponding request to one of the blockchain servers 140, 141, pays out the current nominal value, and sends a blocking request to block the blockchain address of the damaged banknote to one of the blockchain servers 140, 141.

[0264] Figure 3shows a schematic flow diagram of an exemplary method for issuing banknotes 100. In step 300, the central bank 220 sends an order for the production of banknotes 100 to a manufacturer 210, e.g., a printing company. The order specifies, for example, a range of serial numbers. The range of serial numbers specifies serial numbers to be used for the banknotes 100 to be produced. For example, the order further specifies initial nominal values ​​for the banknotes 100 to be produced. For example, the order specifies a minimum nominal value and / or a variable additional nominal value component. In step 302, the manufacturer 210 produces the banknotes 100 according to the received order. The produced banknotes 100 each comprise, for example, a security element with a processor. In step 304, the security elements of the banknotes 100 each generate a banknote-specific asymmetric key pair.A public cryptographic key of the asymmetric key pair is stored in a memory of the corresponding security element. The private cryptographic key of the asymmetric key pair is stored in a protected memory area of ​​the corresponding memory. In step 306, the manufacturer 210 reads the public cryptographic key from the memories of the banknotes 100. For example, the banknotes 100 each include a visual indication of one of the serial numbers from the predetermined range of serial numbers that was assigned to the respective banknote 100 during the manufacturing process. For example, the visual indications of the serial numbers of the manufactured banknotes 100 are read. For example, the serial numbers of the banknotes 100 are also stored in the memories of the banknotes 100.

[0265] For example, the manufacturer 210 additionally reads the serial number from the memories of the banknotes 100.

[0266] In step 308, for example, a visual indication of the read public cryptographic key and / or a blockchain address of the banknote derived from the public cryptographic key is added to the respective banknote, for example, printed on it. In step 310, a production confirmation is sent to the central bank 220, which identifies the produced banknotes 100. For example, the production confirmation indicates the serial numbers of the produced banknotes 100. For example, the production confirmation indicates the public cryptographic keys and / or the blockchain addresses of the produced banknotes 100 derived from the public cryptographic key. For example, the production confirmation indicates the initial nominal values ​​of the produced banknotes 100.For example, the production confirmation specifies minimum nominal values ​​and / or variable additional nominal value components of the initial nominal values. In step 312, the blockchain addresses of the produced banknotes 100 are initialized by the central bank 220 in the blockchain 148, which is responsible for the range of serial numbers in which the serial numbers of the produced banknotes 100 lie. To this end, the central bank 220 determines the responsible blockchain 148 using serial numbers of the produced banknotes 100. For example, the central bank 220 adds an initialization entry to the corresponding blockchain 148. For example, the initialization entry specifies the public cryptographic keys and / or the blockchain addresses of the produced banknotes 100 derived from the public cryptographic key. For example, the initialization entry further specifies the serial numbers of the produced banknotes 100.For example, the initialization entry further specifies the initial nominal values ​​of the banknotes 100. For example, the initialization entry further specifies the minimum nominal values ​​of the banknotes 100. In step 314, the produced banknotes 100 are delivered and reach users 162. For example, the banknotes reach users 162 as cash in the course of cash-based payment transactions.

[0267] Figure 4shows a schematic flow diagram of an exemplary method for payment processing with a terminal of a PoS ("Point of Sale") 164. In step 320, the PoS 164 or the terminal receives a public cryptographic key of a blockchain address or a blockchain address that the PoS 164 uses as a payment recipient to receive payments via the blockchain system with the blockchain 148. In step 322, the user 162 presents a banknote 100 for a cashless payment. In step 324, the PoS 164 reads a visual indication of a public cryptographic key of the banknote 100 or a blockchain address of the banknote 100 derived from the public cryptographic key. In step 326, the PoS 164 creates a payment request and sends the payment request to the banknote 100.For example, the payment request defines a transaction of an amount to be paid from a blockchain address of banknote 100 to the blockchain address of the PoS 164 as the payment recipient. Alternatively, the PoS 164 could also read the serial number of banknote 100 and send a query to the blockchain 148 responsible for the corresponding serial number or a register 150 responsible for the corresponding serial number, which queries the blockchain address assigned to the corresponding serial number. If the corresponding blockchain 148 or the corresponding register 150 contains an entry that assigns a blockchain address of banknote 100 to the serial number of banknote 100, the PoS 164 receives, for example, the blockchain address of banknote 100 or a public key of banknote 100, from which the blockchain address can be derived, in response to the request.

[0268] In step 328, the banknote 100 creates a transaction release, signs the transaction release with the private cryptographic key of the banknote 100, and sends a message with the transaction release to the PoS 164. The transaction release includes, for example, the blockchain address of the banknote 100, the blockchain address of the payee, i.e., the PoS 164, and the amount to be paid. The signature also includes, for example, a timestamp. In step 330, the PoS 164 forwards the message, which includes the serial number of the banknote 100, to the blockchain system. For example, based on the serial number of the banknote, the message is forwarded to the register 150 of the plurality of registers of the blockchain system, which is responsible for the range of serial numbers with the serial number of the corresponding banknote 100.Register 150, for example, is a register updated at regular intervals, which contains a current nominal value for each blockchain address of the blockchain 148 responsible for the serial number of the corresponding banknote. The current nominal values ​​are calculated from the balance sheets of the transactions stored in the responsible blockchain 148 for the corresponding blockchain addresses. Register 150, for example, provides a "fast blockchain," in which the pre-calculated balance sheet results for the blockchain addresses are provided as current nominal values ​​of the corresponding blockchain addresses. Using such a register can have the advantage that current nominal values ​​can be determined more quickly, since they are already available and do not have to be calculated first. Register 150 can, for example, be used by a virtual machine (VM) of a blockchain server orBlockchain nodes of the blockchain network. For example, the PoS 164 can also send the message with the signed transaction approval to the blockchain 148 responsible for the serial number of the corresponding banknote, or the message can be forwarded to the corresponding blockchain 148 without using a register 150.

[0269] In step 332, the responsible register 150 or the server / virtual machine on which the register 150 is managed checks the transaction released or authorized by the banknote 100. For example, the register 150 checks whether the current nominal value of the banknote 100 is sufficient to pay the amount to be paid using the responsible blockchain 148. For example, the register 150 checks whether the current nominal value of the banknote 100 is greater than or equal to the amount to be paid. For example, the register 150 checks whether the current nominal value includes an additional nominal value portion that is sufficient to pay the amount to be paid, i.e., that the guaranteed minimum nominal value remains after payment of the amount to be paid. Furthermore, the register 150 or the server / virtual machine on which the register 150 is managed checks, for example, the signature of the transaction release.Furthermore, it is checked, for example, that an identical transaction, e.g., with an identical timestamp of the transaction approval, has not already been entered into the associated blockchain 148. If the check is successful, the register 150 sends a transaction confirmation, which confirms a positive verification of the signed transaction approval, to the PoS 164. Furthermore, the register 150 or the server / virtual machine on which the register 150 is managed forwards the signed transaction approval to the associated blockchain 148 for entry in step 334. Alternatively or additionally, the server on which the register 150 is managed can enter the transaction upon a positive verification of the signed transaction approval and forward the entry to other servers in a blockchain network. In step 336, the PoS 164 confirms the payment to the user 164 upon receipt of the transaction confirmation in step 332.For example, payment confirmation in step 336 only occurs if the amount to be paid is less than a threshold. If the amount to be paid is greater than or equal to the threshold, confirmation of the payment also requires receipt of an entry confirmation, which confirms the actual entry of the transaction in the associated blockchain 148. In step 338, the PoS 164 receives an entry confirmation from the associated blockchain 148 or a blockchain server managing the associated blockchain 148 after the transaction has been entered into the associated blockchain 148. If the amount to be paid is greater than or equal to the threshold, confirmation of the payment to the user 164 only occurs in step 340.

[0270] Figure 5shows a schematic flow diagram of an exemplary method for determining a current nominal value of a banknote 100. In step 350, the user 162 presents the banknote 100 to a reading device, such as a mobile portable communication device 180, e.g., a smartphone. In step 352, the mobile communication device 180 reads a visual indication of a public cryptographic key of the banknote 100 or a blockchain address of the banknote 100 derived from the public cryptographic key, as well as the serial number of the banknote 100. Alternatively, the communication device 180 could also only read the serial number of the banknote 100. In step 354, the communication device 180 sends a message to the blockchain system with a request for the current nominal value associated with the blockchain address of the banknote 100.This message is forwarded to the register 150 responsible for this serial number based on the serial number of the banknote 100 it contains. Alternatively, such a request could also be forwarded to the responsible blockchain or a server managing the blockchain. The request includes, for example, the public cryptographic key of the banknote 100, from which the blockchain address of the banknote 100 can be derived, in order to identify the banknote 100 whose current nominal value is to be determined. For example, the request to identify the banknote 100 includes the blockchain address of the banknote 100. For example, the request includes the serial number of the banknote 100 if the blockchain 148 or the register 150 includes an entry that assigns a blockchain address of the banknote 100 to the serial number of the banknote 100. In step 356, the responsible register 150 or the responsible blockchain 148 ora server managing the relevant register 150 or the relevant blockchain 148 sends the current nominal value to the mobile communication device 180 in response to the request. In step 358, the mobile communication device 180 displays the current nominal value of the banknote 100 to the user 162.

[0271] Figure 6shows a schematic flow diagram of an exemplary method for payment processing with a mobile portable communication device 180. The mobile portable communication device 180 is, for example, a smartphone. For example, payment processing takes place with the mobile portable communication device 180 using a server 170. The mobile portable communication device 180 serves, for example, as a PoS for a purchase via the Internet using the server 170. In step 360, the server 170 receives a public cryptographic key of a blockchain address or a blockchain address that the server 170 uses as a payment recipient to receive payments via the blockchain 148. In step 362, the server 170 sends a payment request to the mobile communication device 180 to process a payment.For example, server 170 is a service server and the payment is a payment for a service provided by the service server and used by user 162. For example, server 170 is a server of a financial service provider that processes a payment for user 162. The payment request includes, for example, an indication of the public cryptographic key or the blockchain address of server 170 as the payment recipient and an indication of the amount to be paid. Furthermore, the payment request includes, for example, an indication of a serial number of a banknote of the payment recipient. In step 364, user 162 provides a banknote 100 for a cashless payment.In step 366, the mobile communication device 180 reads a visual indication of a public cryptographic key of the banknote 100 or a blockchain address of the banknote 100 derived from the public cryptographic key. In step 368, the mobile communication device 180 supplements the payment request received in step 362 and sends the supplemented payment request to the banknote 100. For example, the mobile communication device 180 supplements the payment request with the blockchain address of the banknote 100. Alternatively, the mobile communication device 180 could also read the serial number of the banknote 100 and send a request to the blockchain 148 responsible for this serial number or to a responsible register 150, which queries the blockchain address assigned to the corresponding serial number.If the relevant blockchain 148 or the relevant register 150 includes an entry that assigns a blockchain address of the banknote 100 to the serial number of the banknote 100, the mobile communication device 180 receives, in response to the request, for example, the blockchain address of the banknote 100 or a public key of the banknote 100 from which the blockchain address can be derived.

[0272] In step 370, the banknote 100 creates a transaction authorization, signs the transaction authorization with the private cryptographic key of the banknote 100, and sends a message with the signed transaction authorization to the mobile communication device 180. The transaction authorization includes, for example, the blockchain address of the banknote 100, the blockchain address of the payment recipient, i.e., the server 170, and the amount to be paid. The signature also includes, for example, a timestamp. The message includes the serial number of the banknote 100, for example, in a header. In step 372, the mobile communication device 180 forwards the message with the signed transaction authorization to the server 170, which forwards the message in step 374 to the register 150 responsible for the serial number of the corresponding banknote 100.Register 150 is, for example, a register updated at regular intervals, which contains a current nominal value for the blockchain addresses of an associated blockchain 148 of the plurality of blockchains. The current nominal values ​​are calculated from the balances of the transactions stored in the associated blockchain 148 for the blockchain addresses of those banknotes for whose serial numbers the blockchain 148 is responsible. Register 150 provides, for example, a "fast blockchain," in which the precalculated balance results for the blockchain addresses are provided as current nominal values ​​of the corresponding blockchain addresses. For example, server 170 can also forward the message with the signed transaction approval to the responsible blockchain 148 without using a register 150. In step 376, the responsible register 150 checks orThe server / virtual machine on which the register 150 is managed checks the transaction released or authorized by the banknote 100. For example, the register 150 checks whether the current nominal value of the banknote 100 is sufficient to pay the amount to be paid using the associated blockchain 148.

[0273] For example, register 150 checks whether the current nominal value of the 100 banknote is greater than or equal to the amount to be paid. For example, the responsible register 150 checks whether the current nominal value includes an additional nominal value portion that is sufficient to pay the amount to be paid, i.e. that the guaranteed minimum nominal value remains after payment of the amount to be paid. Furthermore, register 150 or the server / virtual machine on which register 150 is managed checks, for example, the signature of the transaction release. Furthermore, a check is carried out, for example, to ensure that an identical transaction, e.g. with an identical timestamp of the transaction release, has not already been entered into the associated blockchain. If the check is successful, register 150 sends a transaction confirmation, which confirms a positive check of the signed transaction release, to server 170. Furthermore, register 150 orThe server / virtual machine on which the register 150 is managed forwards the signed transaction approval in step 378 for entry to the associated blockchain 148. Alternatively or additionally, the server on which the register 150 is managed can enter the transaction upon positive verification of the signed transaction approval and forward the entry to other servers of a blockchain network. In step 380, the server 170 forwards the transaction confirmation to the mobile communication device 180. In step 382, ​​the mobile communication device 180 confirms the payment to the user 164. For example, the payment confirmation in step 382 only occurs under the condition that the amount to be paid is less than a threshold value.If the amount to be paid is greater than or equal to the threshold, confirmation of the payment also requires receipt of an entry confirmation, which confirms the actual entry of the transaction in the relevant blockchain. In step 384, the server 170 receives an entry confirmation from the corresponding blockchain 148 or a blockchain server managing the corresponding blockchain 148 after the transaction has been entered into the blockchain 148. In step 386, the server 170 forwards the entry confirmation to the mobile communication device 180. If the amount to be paid is greater than or equal to the threshold, confirmation of the payment to the user 164 does not occur until step 388.

[0274] Figure 7shows a schematic flow diagram of an exemplary method for replacing a banknote 100. In step 390, the user 162 provides the central bank 220 with a damaged banknote 100. In step 392, the central bank 220 checks the security features of the damaged banknote 100 to determine whether the damaged banknote 100 is a valid banknote 100 that has been damaged. Furthermore, the central bank 220 checks, for example, whether more than 50% of the present banknote 100 is undamaged. If the examination by the central bank 220 shows that the damaged banknote is a valid banknote, the central bank 220 reads a visual indication of a public cryptographic key of the banknote 100 or a blockchain address of the banknote 100 derived from the public cryptographic key in step 394. Alternatively, the central bank 220 could also read the serial number of the banknote 100.In step 396, the central bank 220 sends a message to the blockchain system with a request for the current nominal value assigned to the blockchain address of the banknote 100. Based on the serial number of the banknote to be replaced contained in the message, the message is forwarded to the register 150 responsible for the corresponding serial number. Alternatively, such a message could also be forwarded to the responsible blockchain or a server managing the responsible blockchain. To identify the banknote 100 whose current nominal value is to be determined, the request includes, for example, the public cryptographic key of the banknote 100, from which the blockchain address of the banknote 100 can be derived. For example, the request to identify the banknote 100 includes the blockchain address of the banknote 100.For example, the blockchain address of banknote 100 is identified by the serial number of banknote 100 if blockchain 148 or register 150 includes an entry that assigns a blockchain address of banknote 100 to the serial number of banknote 100. In step 398, the relevant register 150 or blockchain 148, or a server managing the corresponding register 150 or blockchain 148, sends the current nominal value to central bank 220 in response to the request.

[0275] In step 400, the central bank 220 pays out the current nominal value of the damaged banknote 100. For example, paying out the current nominal value of the damaged banknote 100 comprises providing one or more banknotes as a replacement for the damaged banknote 100, the current nominal values ​​of which in sum correspond to the current nominal value of the damaged banknote 100. For example, the one or more banknotes as a replacement for the damaged banknote 100 are banknotes according to one of the previously described embodiments. For example, paying out the current nominal value of the damaged banknote 100 comprises entering a transaction of an amount equal to the current nominal value from a blockchain address of the central bank 220 issuing the damaged banknote to a blockchain address specified by an owner of the damaged banknote 100.For example, the specified blockchain address of another banknote of the owner, i.e., the owner, of the damaged banknote 100, is assigned to the owner of the damaged banknote personally, or to another institution selected by the owner of the damaged banknote. In step 402, the central bank 220 sends a blocking entry to the blockchain system with the blockchain 148. By entering the blocking entry into the blockchain 148, the blockchain address of the damaged banknote 100 is blocked. For example, the blocking entry is also entered into all other blockchains of the blockchain system. As a result of the blocking, it is not possible, for example, to execute a transaction with the blockchain address of the damaged banknote 100 as the source address, i.e., to enter it into the blockchain 148. Furthermore, it is no longer possible, for example, to execute a transaction with the blockchain address of the damaged banknote 100 as the destination address, i.e.,to be entered into a blockchain of the blockchain system, which is responsible for the banknote serial number of the source gas address of the corresponding transaction. For example, as a prerequisite for entering a transaction into the relevant blockchain 148, it is checked whether a blocking entry exists for the source address or the destination address of the transaction. If the source address or destination address of the transaction is blocked, the entry is rejected, for example. Otherwise, the entry is made, for example.

[0276] Figure 8shows a schematic flow diagram of an exemplary method for using a banknote. The banknote comprises, for example, a security element with a processor and a memory. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address, which is managed by a central bank issuing the banknote. The processor is configured to execute a payment method with the banknote using the program instructions.

[0277] In block 500, the banknote receives a payment request for a payment in the form of a transaction of an amount to be paid from the banknote's blockchain address to a payee's blockchain address. The payment request specifies the amount to be paid and the payee's blockchain address. In block 502, a transaction authorization is signed with the banknote's private cryptographic key. The transaction authorization includes the banknote's blockchain address, the payee's blockchain address, and the amount to be paid. The signature also includes a timestamp. In block 504, a message is sent with the signed transaction authorization, which includes the banknote's serial number.

[0278] Figure 9shows a schematic flow diagram of an exemplary method for issuing a banknote. In block 510, the banknote is produced. The banknote includes a visual indication of a banknote serial number from a predefined range of serial numbers that uniquely identifies the banknote, and an initial nominal value of the banknote. The banknote further includes a security element with a processor and a memory. In block 512, the banknote generates a banknote-specific asymmetric key pair with a private and a public cryptographic key. In block 514, the banknote stores the generated banknote-specific asymmetric key pair in the memory. The private cryptographic key is stored in a protected memory area of ​​the memory.In block 516, the banknote issues the generated public cryptographic key for initializing a banknote-specific blockchain address derived from the public cryptographic key in a blockchain by a central bank issuing the banknote. The initial nominal value is assigned to the banknote's blockchain address during initialization.

[0279] Figure 10A schematic flow diagram of an exemplary method for payment processing with a terminal. The payment is made with a banknote, which, for example, comprises a visual indication of an identifier that uniquely identifies a blockchain address of the banknote. The banknote comprises a communication interface for communication with the terminal and a security element with a processor and a memory. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address, which is managed by a central bank issuing the banknote. For example, the identifier of the blockchain address of the banknote is also stored in the memory.The identifier can be, for example, the banknote's serial number, the banknote's public cryptographic key, or the blockchain address of the banknote itself. The terminal includes a processor, a memory, and a communication interface for communicating with the banknote.

[0280] In block 520, the terminal captures the identifier of the banknote's blockchain address, which uniquely identifies the banknote's blockchain address. The captured identifier is, for example, the banknote's serial number, the banknote's public cryptographic key, or the banknote's blockchain address itself. Capture may include optically capturing a visual indication of the identifier with an optical sensor and / or reading the identifier stored in memory via the banknote's communication interface. In block 522, the terminal sends a blockchain query for the current nominal value of the banknote's blockchain address identified by the captured identifier.The corresponding message with the blockchain query includes the serial number of the banknote, using which the message is forwarded to the blockchain of a plurality of blockchains responsible for the corresponding serial number and thus for the corresponding message. In block 524, the terminal receives the current nominal value of the blockchain address of the banknote. In block 526, the terminal checks whether the received current nominal value is greater than or equal to the amount to be paid. If the current nominal value is not greater than or equal to the amount to be paid, i.e., the check is unsuccessful, the process continues with block 528. In block 528, the process is aborted. If the current nominal value is greater than or equal to the amount to be paid, i.e., the check is successful, the process continues with block 530.In block 530, the terminal sends a payment request to the banknote in the form of a transaction of an amount to be paid from the banknote's blockchain address to a payee's blockchain address. The payment request specifies the amount to be paid and the payee's blockchain address. In block 532, the terminal receives a signed transaction approval from the banknote. The transaction approval is signed with a private cryptographic key of the banknote. The transaction approval includes the banknote's blockchain address, the payee's blockchain address, and the amount to be paid. The signature also includes, for example, a timestamp. In block 534, the terminal forwards the signed transaction approval of the banknote to a blockchain server of the blockchain for verification and entry of the transaction into the blockchain.In block 536, the terminal receives a transaction confirmation upon successful verification of the signed transaction authorization.

[0281] Figure 11shows a schematic flow diagram of an exemplary method for payment processing with a plurality of banknotes. In block 540, a plurality of banknotes are received. In block 542, the identifiers of the blockchain addresses of the received banknotes are recorded, e.g., the serial numbers, public cryptographic keys, and / or blockchain addresses of the corresponding banknotes. In block 544, a current nominal value stored under the corresponding blockchain address is determined for each of the recorded identifiers. For this purpose, a blockchain query for the corresponding nominal value is used. For example, a message is created with the blockchain query, which includes the serial number of the corresponding banknote.Using the serial number, the message can be routed to the blockchain of a plurality of blockchains responsible for the corresponding serial number and thus for the corresponding message. In block 546, a set of banknotes is selected from the plurality of received banknotes and retained, the total current nominal values ​​of which result in an amount that is less than an amount to be paid. A remaining difference between the amount to be paid and the total amount of the set of selected banknotes is less than a current nominal value of another banknote of the plurality of banknotes that is not included in the set of selected banknotes. In block 548, a payment request for payment of the difference is sent to the additional banknote.

[0282] Figure 12shows a schematic flow diagram of an exemplary method for determining a current nominal value. The banknote includes a visual indication of an identifier that uniquely identifies the banknote's blockchain address. The banknote includes a communication interface for communication with the terminal and a security element with a processor and a memory. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address, which is managed by a central bank issuing the banknote. The identifier is, for example, the serial number, the public cryptographic key, and / or the blockchain address of the banknote.

[0283] The terminal comprises a processor, a memory, and a communication interface for communicating with the banknote. In block 550, the terminal captures an identifier of the banknote's blockchain address, which uniquely identifies the banknote's blockchain address. The captured identifier can be, for example, the banknote's serial number, the banknote's public cryptographic key, or the banknote's blockchain address itself. In block 552, the terminal creates and sends a message with a blockchain query for the current nominal value of the banknote's blockchain address, which is identified by the captured identifier. The corresponding message with the blockchain query includes the banknote's serial number, which is used to route the message to the blockchain of a plurality of blockchains responsible for the corresponding serial number and thus for the corresponding message.In block 554, the terminal receives the current nominal value of the banknote's blockchain address.

[0284] Figure 13shows a schematic flow diagram of an exemplary method for replacing a banknote. The banknote comprises, for example, a visual indication of an identifier of a blockchain address of the banknote. The banknote comprises the visual indication of the identifier, for example, distributed multiple times across the banknote. Furthermore, the banknote further comprises a plurality of security features distributed across the banknote. The banknote comprises a security element with a processor and a memory with program instructions. A banknote-specific private cryptographic key of an asymmetric key pair of the banknote is stored in a protected memory area of ​​the memory. The asymmetric key pair is assigned to a banknote-specific blockchain address in a blockchain managed by a central bank issuing the banknote.

[0285] The banknote is damaged. In block 560, the degree of damage of the banknote is determined. In block 562, it is checked whether the degree of damage of the banknote exceeds a predefined permissible maximum degree of damage. If the degree of damage of the banknote exceeds the predefined permissible maximum degree of damage, the method is aborted in block 564. If the degree of damage of the banknote does not exceed a predefined permissible maximum degree of damage, the method continues in block 566 with the detection of the identifier of the blockchain address of the damaged banknote, which uniquely identifies the blockchain address of the damaged banknote. The detected identifier is, for example, the serial number of the damaged banknote, the public cryptographic key of the damaged banknote, or the blockchain address of the damaged banknote itself.In block 568, a block of the blockchain address of the damaged banknote is initialized using the captured identifier. In block 570, a message with a blockchain query for the current nominal value of the blockchain address of the damaged banknote is sent. The corresponding message with the blockchain query includes the serial number of the banknote to be replaced, using which the message is routed to the blockchain of a plurality of blockchains responsible for the corresponding serial number and thus for the corresponding message. In block 572, the current nominal value of the corresponding blockchain address is received and paid out in block 574. Block 568 can, for example, occur before block 570 or after block 572.

[0286] Figure 14shows an exemplary method for executing a payment using a mobile portable terminal of a plurality of mobile portable terminals and a blockchain system or forwarding a transaction approval. The blockchain system comprises a plurality of blockchains. Each of the blockchains is assigned one or more blockchain servers, which manage the corresponding blockchain. Each mobile portable terminal of the plurality of mobile portable terminals is assigned a serial number from a range of serial numbers. The range of serial numbers is divided into a plurality of ranges of serial numbers. Each of the ranges of serial numbers is assigned one of the blockchains of the blockchain system, which logs payments from banknote-specific blockchain addresses to which mobile portable terminals with serial numbers from the corresponding range of serial numbers are assigned.

[0287] In block 600, a message from the mobile portable terminal is received with a transaction authorization signed using a banknote-specific private cryptographic key of an asymmetric key pair of the mobile portable terminal. The asymmetric key pair is associated with a banknote-specific blockchain address of the mobile portable terminal, and the transaction authorization includes, for example, the blockchain address of the banknote, a blockchain address of the payee, and an amount to be paid. In block 602, using a serial number of the banknote comprising the message, a blockchain of the plurality of blockchains is determined that is associated with the range of serial numbers comprising the serial number. This determination of the blockchain orAssigning the serial number of the mobile portable terminal to a range of serial numbers is performed, for example, using a routing table. In block 604, the message is forwarded to a blockchain server that manages the specific blockchain for verification and entry of the transaction approved by the transaction approval into the specific blockchain. The selection of the responsible blockchain server and / or addressing of the selected blockchain server is performed, for example, using the routing table.

[0288] Figure 15shows an exemplary method for splitting a blockchain, for example, by a blockchain server of a blockchain system managing the blockchain. In block 620, it is monitored whether the blockchain meets a predefined criterion for splitting. As long as the blockchain does not meet the splitting criterion, there is no need for a split. During the monitoring, it is checked whether the blockchain meets the criterion. If the check in block 622 shows that the blockchain does not meet the criterion, the monitoring continues. If the check in block 622 shows that the blockchain does not meet the criterion, in block 624 the area assigned to the blockchain to be split is divided into two or more sub-areas. Furthermore, in block 626, the blockchain is split, and each of the sub-areas is assigned an independent blockchain during the splitting process.

[0289] For example, in block 620, the blockchain server monitors a load on the blockchain. The predefined criterion is, for example, an exceeding of a predefined threshold of the load by a current load recorded during monitoring. For example, the predefined criterion specifies that a split occurs if the predefined threshold is already exceeded once by the current load recorded during monitoring or if the corresponding threshold is constantly exceeded for a predefined period of time. For example, two thresholds are predefined, whereby a smaller of the two thresholds must be constantly exceeded for a predefined period of time for a split to occur; a single exceedance of the larger threshold already initiates a split. Load is defined, for example, as the number of transaction releases to be entered per time.The load can also include, for example, the number of queries directed to the blockchain at any given time. These queries could be, for example, queries about balances assigned to serial numbers of the area to which the corresponding blockchain is assigned.

[0290] During the division in block 624, for example, it is determined for each of the potential sub-areas which share of the detected current load is attributable to the corresponding sub-area, and the division into the sub-areas is adjusted such that the difference between the sub-areas attributable to the sub-areas is less than or equal to a predefined first maximum value. For example, the division is performed such that the difference is minimized. For example, the division is performed such that the difference disappears, i.e., the first maximum value is zero.

[0291] For example, in block 620, the blockchain server monitors a sum of credits assigned to the serial numbers of the range of serial numbers of the corresponding blockchain. For example, the predefined criterion is the sum of the credits exceeding a predefined threshold. For example, the predefined criterion specifies that a split occurs if the sum of the credits exceeds the predefined threshold once or if the corresponding threshold is constantly exceeded for a predefined period of time. For example, two thresholds are predefined, whereby a smaller of the two thresholds must be constantly exceeded for a predefined period of time for a split to occur; a split is initiated even if the larger threshold is exceeded once.

[0292] During the division in block 624, for example, a sum of the credits assigned to the serial numbers of the corresponding sub-area is determined for each of the potential sub-areas, and the division into the sub-areas is adjusted such that any difference between the sums of the credits of the sub-areas is less than or equal to a predefined second maximum value. This can, for example, increase the probability of the most even future load distribution between the resulting blockchains. For example, the division is carried out in such a way that the difference is minimized. For example, the division is carried out in such a way that the difference disappears, i.e., the second maximum value is zero.

[0293] For example, in block 624, the range of serial numbers to be divided is divided such that size differences between the sub-ranges with respect to the number of serial numbers each encompassed by the sub-ranges are less than or equal to a predefined third maximum value. For example, the division is performed such that the difference is minimized. For example, the division is performed such that the difference disappears, ie, the third maximum value is zero and each of the sub-ranges encompasses the same number of serial numbers.

[0294] For example, splitting the blockchain in block 624 comprises assigning the blockchain to be split to a first of the sub-areas. The blockchain to be split is, for example, further used to log payments from blockchain addresses of serial numbers of the first sub-area. For each additional sub-area, for example, an independent additional blockchain is created. Creating the additional blockchains comprises entering a splitting note for each blockchain address of serial numbers of the additional sub-area into the blockchain to be split. Furthermore, a genesis block for each blockchain address of serial numbers of the additional sub-area is entered into the additional blockchain. The genesis blocks each comprise an indication of a current balance assigned to the corresponding serial number at the time of the split in the blockchain to be split.

[0295] The split notes, for example, mean that no more payments from the corresponding blockchain addresses can be recorded in the blockchain being split. For example, the split notes and / or the genesis blocks are each signed with a private cryptographic key of an authority managing the blockchain, such as a central bank.

[0296] For example, splitting the blockchain in block 624 includes terminating the blockchain to be split and creating a separate additional blockchain for each of the sub-areas. Creating the additional blockchains includes, for example, entering a splitting note for each blockchain address of serial numbers of the additional sub-area into the blockchain to be split and entering a genesis block for each blockchain address of serial numbers of the additional sub-area into the additional blockchain. The genesis blocks each include an indication of a current balance assigned to the corresponding serial number at the time of the split in the blockchain to be split.

[0297] The split notes, for example, mean that no more payments from the corresponding blockchain addresses can be recorded in the blockchain to be split. For example, the blockchain to be split is complete when a split note has been entered for all of the blockchain addresses it contains. For example, the split notes and / or the genesis blocks are each signed with a private cryptographic key of an authority managing the blockchains, such as a central bank.

[0298] Figure 16shows an exemplary method for deriving a private cryptographic key of a blockchain address for a mobile portable terminal using a banknote. The blockchain address of the mobile portable terminal depends on a blockchain address of a banknote, or a private cryptographic key assigned to the banknote of the mobile portable terminal depends on a private cryptographic key assigned to a blockchain address of the banknote. The banknote comprises, for example, a security element with a processor and a memory with program instructions. A blockchain address of the banknote is stored in the memory of the security element. A banknote-specific private cryptographic key is stored in a protected memory area of ​​the memory of the security element.

[0299] In block 700, the banknote receives a derivation request for deriving the private cryptographic key from the mobile portable terminal. In block 702, the banknote derives the private cryptographic key for the mobile portable terminal using a one-way function and the banknote-specific private cryptographic key. In block 704, the banknote sends the derived private cryptographic key to the mobile portable terminal in response to the derivation request. The derived private cryptographic key is used by the mobile portable terminal to sign transaction authorizations. For example, the banknote calculates a public cryptographic key in addition to the private cryptographic key and sends the resulting first asymmetric key pair to the mobile portable terminal.For example, the public cryptographic key for the private cryptographic key is calculated by the mobile portable device. Furthermore, the banknote response includes, for example, a serial number for creating transaction authorizations. The serial number is derived, for example, from a serial number of the banknote. For example, the banknote includes a plurality of additional serial numbers for assignment to mobile portable devices in the course of deriving private cryptographic keys for the corresponding mobile portable device.

[0300] Figure 17shows another exemplary method for deriving the private cryptographic key of the blockchain address for the mobile portable terminal using the banknote. In block 710, the banknote receives a derivation request for deriving the private cryptographic key for the mobile portable terminal. In block 712, the banknote calculates from the banknote-specific private cryptographic key an input value for the one-way function for deriving the private cryptographic key for the mobile portable terminal. In block 714, the banknote sends the calculated input value to the mobile portable terminal in response to the derivation request. The mobile portable terminal can then use the sent input value to derive the private cryptographic key using the one-way function.Furthermore, the mobile portable device can calculate a public cryptographic key for the private cryptographic key. Furthermore, the banknote's response includes, for example, a serial number for creating transaction authorizations. The serial number is derived, for example, from a serial number of the banknote. For example, the banknote includes a plurality of additional serial numbers for assignment to mobile portable devices in the course of deriving private cryptographic keys for the corresponding mobile portable device.

[0301] Figure 18 shows an exemplary method for deriving the private cryptographic key for the mobile portable terminal. For example, the method according to Figure 18 the procedure Figure 16from the perspective of the mobile portable terminal. In block 720, the mobile portable terminal sends a derivation request to the banknote to derive the private cryptographic key. In block 722, the mobile portable terminal receives the derived private cryptographic key in response to the derivation request. This private cryptographic key is derived, for example, using a one-way function and the banknote-specific private cryptographic key of the banknote. In block 724, the mobile portable terminal stores the derived private cryptographic key for further use. For example, the private cryptographic key is stored in a protected memory area of ​​the mobile portable terminal. The derived private cryptographic key is used by the mobile portable terminal to sign payment authorizations.For example, in block 722, the mobile portable terminal receives a public cryptographic key along with the private cryptographic key. For example, the public cryptographic key is calculated for the private cryptographic key by the mobile portable terminal. Furthermore, the banknote response in block 722 includes, for example, a serial number for creating transaction authorizations. The serial number is derived, for example, from a serial number of the banknote. For example, the banknote includes a plurality of additional serial numbers for assignment to mobile portable terminals in the course of deriving private cryptographic keys for the corresponding mobile portable terminal.

[0302] Figure 19 shows an exemplary method for deriving the private cryptographic key of the mobile portable terminal. For example, the method according to Figure 19the procedure Figure 17 from the perspective of the mobile portable terminal. In block 730, the mobile portable terminal sends a derivation request to the banknote to derive the private cryptographic key for the dependent anonymous account.

[0303] In block 732, in response to the derivation request, the mobile portable terminal receives from the banknote an input value for the one-way function for deriving the private cryptographic key, calculated from the banknote-specific private cryptographic key. In block 734, the mobile portable terminal derives the private cryptographic key using the one-way function and the received input value. Furthermore, the mobile portable terminal can calculate a public cryptographic key for the private cryptographic key. In block 736, the mobile portable terminal stores the derived private cryptographic key for further use. For example, the private cryptographic key is stored in a protected memory area of ​​the mobile portable terminal.The derived private cryptographic key serves the mobile portable device, for example, to sign transaction authorizations. Furthermore, the banknote's response in block 732 includes, for example, a serial number for creating transaction authorizations. The serial number is derived, for example, from a serial number of the banknote. For example, the banknote includes a plurality of additional serial numbers for assignment to mobile portable devices in the course of deriving private cryptographic keys for the corresponding mobile portable device. List of reference symbols

[0304] 100Banknote 102Security element 104Communication interface 106Serial number 107Visual indication 108Nominal value 110Security feature 112User interface 116Public key 118Private Key 120 Memory 122 Protected memory area 124 Processor 128 Program instructions 130 Terminal 132 Memory 134 Processor 136 Program instructions 137 Communication interface 138 Communication interface 139 Sensor 140 Blockchain server 141 Blockchain server 142 Processor 143 Processor 144 Program instructions 145 Program instructions 146 Memory 147 Memory 148 Blockchain 149 Blockchain 150 Register 151 Register 152 Communication interface 153 Communication interface 154 Blockchain network 156 Blockchain system 157 System 160 Network 161 Blockchain server 162 User 163 Processor 164 PoS 165 Program instructions 166 Memory 167Blockchain 168Register 169Interface 170Server 172Memory 174Processor 176Program instructions 178Communication interface 180Mobile portable communication device181User interface 182Memory 184Processor 186Program instructions 187Communication interface 188Communication interface 189Camera 190User computer system 191User interface 192Memory 194Processor 196Program instructions 197Communication interface 198Communication interface 199Sensor 200Payment service server 202Memory 204Processor 206Program instructions 208Communication interface 210Manufacturer computer system 212Memory 214Processor 216Program instructions 217Communication interface 218Communication interface 219Sensor 220Central computer system 222Memory 224Processor 226Program instructions 228Communication interface 229Sensor

Claims

1. A method for executing a payment using a first mobile portable terminal (100) of a plurality of mobile portable terminals and a blockchain system (156), wherein the blockchain system (156) comprises a plurality of blockchains (148, 149, 167), wherein each of the blockchains (148, 149, 167) is assigned to one or more blockchain servers (140, 141, 161), which manage the corresponding blockchain (148, 149, 167), wherein each mobile portable terminal of the plurality of mobile portable terminals is assigned a respective serial number from a space of serial numbers, wherein the space of serial numbers is divided into a plurality of ranges of serial numbers, wherein each of the ranges of serial numbers is assigned a respective one of the blockchains (148, 149, 167) of the blockchain system (156) which logs payments from blockchain addresses assigned to mobile portable terminals with serial numbers from the corresponding range of serial numbers, wherein the method comprises: • receiving a message of the first mobile portable terminal (100) with a transaction release, wherein the transaction release is signed using a private cryptographic key (118) of an asymmetric key pair of the first mobile portable terminal (100), wherein the asymmetric key pair is assigned to a first blockchain address of the first mobile portable terminal (100), wherein the transaction release comprises the first blockchain address of the first mobile portable terminal (100), a second blockchain address of the payee and an amount to be paid, • determining, using a first serial number (106) of the first mobile portable terminal (100) comprising the message, a first blockchain (148) of the plurality of blockchains (148, 149, 167) associated with the range of serial numbers comprising the first serial number (106), • forwarding the message to a first blockchain server (140), which manages the particular first blockchain (148), for checking and entering the transaction released by the transaction release into the first blockchain (148).

2. The method according to claim 1, wherein the first mobile portable terminal (100) is a first banknote issued by a central bank, wherein the first blockchain address is a banknote-specific blockchain address, wherein the private cryptographic key (118) is a banknote-specific private cryptographic key of a banknote-specific asymmetric key pair, or wherein the private cryptographic key of the first mobile portable terminal (100) is a derived private cryptographic key of a blockchain address which is dependent on a blockchain address of a second banknote (100), wherein the second banknote (100) comprises a security element (102) with a processor (124) and a memory (120) with program instructions (128), wherein the blockchain address of the second banknote (100) is stored in the memory (120) of the security element (102), wherein a banknote-specific cryptographic key of the second banknote (100) is stored in a protected memory area (122) of the memory (120) of the security element (102) of the second banknote (100), wherein deriving the private cryptographic key of the first mobile portable terminal (100) comprises: • receiving a derivation request for deriving the private cryptographic key for the first mobile portable terminal (100) by the second banknote (100), • initiating a derivation of the private cryptographic key for the first mobile portable terminal (100) using a one-way function and the banknote-specific cryptographic key of the second banknote (100), • sending the first serial number (106) to the first mobile portable terminal (100) by the second banknote (100).

3. The method according any to one of the preceding claims, wherein the first blockchain address is the first serial number (106) of the first mobile portable terminal (100) or the first blockchain address is derived from the first serial number (106) of the first mobile portable terminal (100), wherein, for example, a public cryptographic key (116) of the asymmetric key pair of the first mobile portable terminal (100) is assigned to the first blockchain address by a transaction, initialising the first blockchain address, to the first blockchain address, with which the public cryptographic key (116) of the asymmetric key pair of the first mobile portable terminal (100) is entered into the first blockchain (148), or wherein the first blockchain address is the public cryptographic key (116) of the asymmetric key pair of the first mobile portable terminal (100) or the first blockchain address is derived from the public cryptographic key (116) of the asymmetric key pair of the first mobile portable terminal (100), wherein, for example, the first serial number (106) is assigned to the first blockchain address by an initial transaction to the first blockchain address, with which the first serial number (106) is entered into the first blockchain (148).

4. The method according to any one of the preceding claims, wherein the message is forwarded to the first blockchain server (140) using a routing table which identifies, for each of the ranges of the plurality of serial numbers, one or more assigned blockchain servers which manage the blockchain assigned to the corresponding range of serial numbers, wherein the routing table further identifies, for example, a respective network address of the blockchain servers (140, 141, 161).

5. The method according to any one of the preceding claims, wherein the receiving and forwarding of the message is carried out by a terminal computer system (130, 180, 190) or a server (170, 200).

6. The method according to any one of claims 1 to 4, wherein the receiving and forwarding of the message is performed by a blockchain server (141, 161) of the blockchain system (156).

7. The method according to claim 6, wherein the blockchain server (141, 161) is further configured to split one of the blockchains (148, 149, 167) of the blockchain system (156) if a predefined criterion is met, wherein the splitting of the blockchain comprises splitting the range of serial numbers assigned to the blockchain to be split into two or more sub-ranges, wherein each of the sub-ranges is assigned to an independent blockchain in the course of the splitting.

8. The method according to claim 7, wherein the blockchain server (141, 161) monitors a load of the blockchain, wherein the predefined criterion is an exceeding of a predefined threshold value of the load by a current load detected in the course of the monitoring, wherein, for example, it is determined for each of the sub-ranges in each case what proportion of the detected current load is attributable to the corresponding sub-range, and the division into the sub-ranges is adapted such that a difference between the sub-ranges attributable to the sub-ranges is less than or equal to a predefined first maximum value.

9. The method according to claim 7, wherein the predefined criterion is an exceeding of a predefined threshold value of a sum of balances associated with the serial numbers of the range of serial numbers of the corresponding blockchain, wherein, for example, for each of the sub-ranges, a sum of the balances assigned to the serial numbers of the corresponding sub-range is determined, and the splitting into the sub-ranges is adjusted such that a difference between the sums of the balances of the sub-ranges are less than or equal to a predefined second maximum value.

10. The method according to any one of claims 7 to 9, wherein the range of serial numbers to be divided is divided in such a way that differences in size of the sub-ranges with respect to the number of serial numbers comprised by the sub-ranges are smaller than or equal to a predefined third maximum value.

11. The method according to any one of claims 7 to 10, wherein the blockchain to be divided is assigned to a first of the sub-ranges and is further used for logging payments of blockchain addresses of serial numbers of the first sub-range, wherein for each further of the sub-ranges an independent additional blockchain is generated in each case, wherein the generation of the additional blockchains comprises in each case: • entering a division note for each blockchain address of serial numbers of the further sub-range into the blockchain to be divided, • entering a genesis block for each blockchain address of serial numbers of the further sub-range into the additional blockchain, wherein the genesis blocks each comprise an indication of a current balance which is assigned to the corresponding serial number at the time of the division in the blockchain to be divided, or wherein the blockchain to be divided is terminated and an independent additional blockchain is created for each of the sub-ranges, wherein the creation of the additional blockchains comprises in each case: • entering a division note for each blockchain address of serial numbers of the further sub-range into the blockchain to be divided, • entering a genesis block for each blockchain address of serial numbers of the further sub-range into the additional blockchain, wherein the genesis blocks each comprise an indication of a current balance which is assigned to the corresponding serial number at the time of the division in the blockchain to be divided.

12. The method according to any of the preceding claims, wherein the second blockchain address of the payee is a second blockchain address of a second mobile portable terminal of the payee, wherein the message comprises a second serial number of the second mobile portable terminal of the payee, wherein the method further comprises: • upon an entry of the transaction released by the transaction release into the first blockchain (148), checking whether the second serial number is included in a range of serial numbers which is assigned to a different, second blockchain of the plurality of blockchains (148, 149, 167) than the first blockchain, • if the second serial number is assigned to another, second blockchain (149, 167), determining the second blockchain (149, 167) to which the second serial number is assigned, • generating a confirmation entry of the released transaction in the first blockchain, which includes the transaction release, • sending the entry confirmation to a second blockchain server (141, 161), which manages the second blockchain (149, 167), for additional entry of the transaction released by the transaction release into the second blockchain (149, 167), wherein, for example, the entry confirmation comprises the second serial number in a header, and / or wherein, for example, the entry confirmation is signed by the first blockchain server (140), and / or wherein, for example, the method further comprises checking the entry confirmation by the second blockchain server (141, 161), wherein the second blockchain server (141, 161) additionally enters the transaction released by the transaction release into the second blockchain (149, 167) upon a successful check.

13. A computer system (130, 141, 161, 170, 180, 190, 200) for executing a payment using a mobile portable terminal (100) of a plurality of mobile portable terminals and a blockchain system (156), wherein the blockchain system (156) comprises a plurality of blockchains (148, 149, 167), wherein each of the blockchains (148, 149, 167) is associated with one or more blockchain servers (140, 141, 161) which manage the corresponding blockchain (148, 149, 167), wherein each mobile portable terminal (100) of the plurality of mobile portable terminals is assigned a respective serial number from a space of serial numbers, wherein the space of serial numbers is divided into a plurality of ranges of serial numbers, wherein each of the ranges of serial numbers is assigned a respective one of the blockchains (148, 149, 167) of the blockchain system (156) which logs payments from blockchain addresses assigned to mobile portable terminals with serial numbers from the corresponding range of serial numbers, wherein the computer system (130, 141, 161, 170, 180, 190, 200) comprises a processor (134, 143, 163, 174, 184, 194, 204), a memory (132, 147, 167, 172, 182, 192, 202) with program instructions (136, 145, 165, 176, 186, 196, 206) and a communication interface (138, 153, 169, 178, 188, 198, 208), wherein the processor (134, 143, 163, 174, 184, 194, 204) is configured to perform the following upon execution of the program instructions (136, 145, 165, 176, 186, 196, 206): • receiving a message of the mobile portable terminal (100) with a transaction release via the communication interface (138, 153, 169, 178, 188, 198, 208), wherein the transaction release is signed using a private cryptographic key (118) of an asymmetric key pair of the mobile portable terminal (100), wherein the asymmetric key pair is assigned to a blockchain address of the mobile portable terminal (100), wherein the transaction release comprises the blockchain address of the mobile portable terminal (100), a blockchain address of the payee and an amount to be paid, • determining, using a serial number (106) of the mobile portable terminal (100) comprising the message, a blockchain (148) of the plurality of blockchains (148, 149, 167) assigned to the range of serial numbers comprising the serial number (106), • forwarding the message via the communication interface (138, 153, 169, 178, 188, 198, 208) to a blockchain server (140), which manages the particular blockchain (148), for checking and entering the transaction released by the transaction release into the particular blockchain (148).

14. A system (157) comprising a computer system according to claim 13 and a mobile portable terminal (100), wherein the mobile portable terminal (100) comprises a security element (102) with a processor (124) and a memory (120) with program instructions (128), wherein private cryptographic keys (118) of the mobile portable terminal (100) are stored in a protected memory area (122) of the memory (120), wherein the processor (124) is configured to execute the following when executing the program instructions (128): • receiving a payment request for a payment with the mobile portable terminal (100) in the form of the transaction of the amount to be paid from the blockchain address of the mobile portable terminal (100) to the blockchain address of the payee, wherein the payment request specifies the amount to be paid and the blockchain address of the payee, • signing the transaction release with the private cryptographic key (118) of the mobile portable terminal (100), • sending the message with the signed transaction release.

15. The system (157) according to claim 14, further comprising a blockchain system (156) having a plurality of blockchains (148, 149, 167), wherein each of the blockchains (148, 149, 167) is associated with one or more blockchain servers (140, 141, 161) that manage the corresponding blockchain (148, 149, 167), wherein a space of serial numbers of mobile portable terminals used is divided into a plurality of ranges of serial numbers, wherein each of the ranges of serial numbers is associated with one of the blockchains (148, 149, 167) of the blockchain system (156), which logs payments from blockchain addresses associated with mobile portable terminals with serial numbers from the corresponding range of serial numbers.