KEY DERIVATION USING A BANK NOTE WITH PROCESSOR
Patent Information
- Application Number
- DE502022006091
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-24
- Filing Date
- 2022-03-22
- Publication Date
- 2025-12-04
- Estimated Expiration
- 2042-03-22
Description
[0001] The invention relates to a method for deriving a private cryptographic key for an anonymous account for a computer system using a banknote. The invention further relates to a corresponding banknote and a corresponding computer system, as well as a system comprising both.
[0002] With increasing digitalization, cashless payment instruments are becoming more and more prominent, especially those based on electronic payment processing. Cashless payments involve the transfer of funds without the actual exchange of cash. In cash payments, cash—that is, banknotes or coins—is exchanged between the payer and the payee, whereas in cashless payments, no such exchange of cash takes place.
[0003] Cash has the advantage of being readily available to everyone and can be used quickly and anywhere. For example, no bank account is required for cash-based payments. Furthermore, cash is often valued by its owners as a store of value.
[0004] The article "Banknote Validation through an Embedded RFID Chip and an NFC-Enabled Smartphone" by Mohamed Hamdy Eldefrawy and Muhammad Khurram Khan, published in *Mathematical Problems in Engineering*, Volume 2015, pages 1 to 8, describes a method for verifying a banknote using an RFID chip and an NFC-enabled smartphone. A consumer, using their smartphone and an internet connection, sends a banknote verification request to the Monetary Agency (MA). The MA responds by sending a random challenge to the consumer's smartphone. The RFID chip in the banknote receives the challenge via NFC and calculates an equivalent response to the MA's challenge. If any of the messages are incorrect, authentication is denied.This process allows consumers to verify the authenticity of banknotes with the MA using their smartphones and an internet connection.
[0005] In contrast, cashless payment methods have the advantage of enabling efficient payment processing, even when the payer and payee are located in distant places, as is the case with online purchases. Traditional banknotes cannot offer this.
[0006] The invention is therefore based on the objective of creating an improved payment method using a banknote.
[0007] The problem underlying the invention is solved by the features of the independent claims. Embodiments of the invention are specified in the dependent claims.
[0008] Embodiments include a method for deriving a first private cryptographic key of an anonymous account for a computer system using a banknote. The anonymous account of the computer system depends on an anonymous banknote account individually assigned to the banknote. The banknote comprises a security element with a processor and memory containing program instructions. The memory of the security element stores an identification number of the banknote, which identifies the anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote.
[0009] A second cryptographic key specific to each banknote is stored in a protected memory area of the security element's memory.
[0010] The procedure includes the following through the banknote: Receiving a derivation request to derive the first private cryptographic key for the dependent anonymous account from the computer system, initiating a derivation of the first private cryptographic key for the dependent anonymous account using a one-way function and the banknote-specific second cryptographic key, wherein the derived first private cryptographic key is used to generate cryptograms for releasing payment from the dependent account.
[0011] Some banknote designs offer the advantage that they can be used not only as a means of payment in the usual sense, but also for cashless payments. When used as a means of payment in the usual sense, the banknote is handed over by the payer to the payee during the payment process, or the payee hands the corresponding banknote over to the payer as change. Upon handover of the banknote, ownership of it passes from the transferor to the recipient. This transfer of ownership also includes ownership of the banknote's current face value, i.e., the face value assigned to the banknote account.
[0012] When used for cashless payment, i.e., without physical handover of the banknote or transfer of ownership, payment is effected by the banknote providing a payment-specific cryptogram. This cryptogram authorizes a transaction in which the amount to be paid is transferred from the banknote's account to the payee's account.
[0013] Deriving a private cryptographic key for an anonymous account on a computer system using a corresponding banknote allows the banknote's cashless payment functionality to be transferred to the computer system. The anonymous account on the computer system depends on an anonymous banknote account individually assigned to a banknote. The computer system's account depends on the banknote account in that the private cryptographic key used to access the account is derived from the banknote account's cryptographic key, for example, a private cryptographic key. Thus, control over the banknote account's cryptographic key also grants control over the account itself, since the banknote account's cryptographic key can be used to derive the account's private cryptographic key, which in turn grants control over the corresponding account.For example, having control over the cryptographic key of a banknote account allows the account to be revoked, i.e., closed. Furthermore, revoking the banknote account automatically results in the account itself being revoked.
[0014] Some implementations offer the advantage that a banknote can be used to set up an account for a computer system, particularly a mobile device such as a smartphone, or to derive an account from a banknote account. The banknote's cryptographic key serves as a master key. This key is securely stored on the banknote and can be kept independently of the computer system. If it becomes necessary to revoke the dependent account or to recover the computer system's private cryptographic key, the banknote's cryptographic key can be used. If the banknote is stored independently of the computer system, for example in a safe or safety deposit box, the probability of simultaneous compromise or damage to both the computer system and the banknote can be significantly reduced.The banknote thus serves as a security anchor and as a kind of backup for the private cryptographic key of the computer system.
[0015] Here, both the term "banknote account" and the term "account" generally refer to the same type of anonymous account, i.e., central data structures for processing payments and for accounting. The term "banknote account" indicates that the account in question is assigned to a banknote and cryptographically linked to that banknote.
[0016] These implementations can offer the advantage of enabling simple, convenient, and secure account access via a computer system, such as a smartphone: The derived anonymous account allows the computer system to execute anonymous payments. If the computer system is a mobile, portable device like a smartphone, such anonymous payments are possible anytime, anywhere. At the same time, a high level of security is offered, as the banknote itself serves as a backup. Even if the computer system is lost, access to the account remains possible via the banknote. Furthermore, the banknote, for example, with the implementation of a Level 3 security feature, offers a high level of security in case of damage, as it can be replaced even if damaged.For example, the central bank has access to the banknote account and thus the derived bank accounts, which means that in the event of damage to the banknote it can grant the user access to their money.
[0017] For example, a banknote with a processor can be used to derive an account or a private cryptographic key for a smartphone. Furthermore, the banknote with a processor allows for the reversal of the linked account, for instance, in the event of loss of the smartphone.
[0018] For example, a user withdraws a banknote with a processor from an ATM. The user opens an application on their smartphone to derive an account or a private cryptographic key for that account and initiates the process. For example, the user taps a "Derivatives" or "Derive" button in a graphical user interface. The user places the banknote against the smartphone. The smartphone sends a derivation request (REQUEST to DERIV) to the banknote. For example, the banknote derives a private cryptographic key and sends it to the smartphone in response to the derivation request. Using the private cryptographic key, the smartphone derives a public cryptographic key. The user can then use the private cryptographic key to make payments with the smartphone.The asymmetric key pairs can be used on the same smartphone or distributed across different computer systems, such as smartwatch, tablet, laptop or desktop PC.
[0019] If the user loses their smartphone, for example through loss or theft, they still possess the banknote. This is stored separately from the smartphone in a secure location. It is possible, for example, to derive multiple asymmetric key pairs for several bank accounts using one and the same banknote. The user can then use another smartphone or computer system to revoke the derived cryptographic keys. On the other smartphone or computer system, the user opens an app to revoke the accounts or derived cryptographic keys for the corresponding bank accounts. To initiate the process, the user taps a button in a graphical user interface, for example, "Revoke ALL derived accounts" or "Revoke ALL daughters." The user then attaches the banknote to the smartphone or computer system.The application, installed on the other smartphone or computer system, can then directly use the banknote or its cryptographic key for signing, or derive the derived private cryptographic key(s) again and use them for signing. This allows the derived bank accounts to be reversed and their balances transferred back to the parent account, i.e., the banknote account. Alternatively, the user can specify an IBAN, for example, to transfer the money from the derived bank accounts to that IBAN.
[0020] The banknote's cryptographic key, for example, a private cryptographic key, is securely stored in a security element of the banknote, making it impossible to read. Because the banknote's cryptographic key is unreadable, transactions from the banknote account can only be carried out directly by the banknote itself and not via a third-party application. Deriving an account or a private cryptographic key for a computer system, such as a smartphone, enables transactions without the direct involvement of the banknote. For this purpose, a third-party application on the smartphone can be used. Furthermore, the banknote itself, with its integrated processor, can be used as both a cash-based and a cashless payment method.
[0021] In particular, the advantages of cashless payments using banknotes can be transferred to a computer system, such as a smartphone, by deriving the data. Both the banknote account and the dependent or derived account of the computer system are anonymous and can, in principle, be shared with anyone.
[0022] Furthermore, some implementations provide a backup mechanism in case the computer system is lost, using the derived private cryptographic key. For example, a smartphone could be lost, severely damaged, destroyed, or fall into the wrong hands. While modern smartphones, and especially their security features, are protected against unauthorized access with PINs and biometric authentication methods such as FaceID, a residual risk still remains.
[0023] For example, payment via banknote can be based on a blockchain, where the banknote account and the dependent account are each represented by blockchain addresses. For instance, a smartphone application sends a derivation request to the banknote to generate a private cryptographic key for the smartphone derived from the banknote's asymmetric key pair. The banknote then derives this private cryptographic key for the smartphone. The smartphone, or rather the application installed on the smartphone, receives the derived private cryptographic key directly from the banknote, for example, via NFC. The derived private cryptographic key is then forwarded by the application to a security element on the smartphone.For example, the smartphone itself derives a corresponding blockchain address, perhaps based on an associated public cryptographic key, or a corresponding serial number. This blockchain address or serial number is then used for payments. Subsequently, for example, by making a payment, particularly a one-time payment, from the banknote account to its counterpart, i.e., the smartphone's account. For instance, the money is transferred from a blockchain address of the banknote (i.e., the banknote account) to a blockchain address of the smartphone (i.e., the smartphone's account). With the money in the account, the smartphone is now able to independently make payments and transactions without needing the banknote or its cryptographic key.
[0024] According to some embodiments, for example, further derivation of additional private cryptographic keys is permitted, for example up to a specified maximum number.
[0025] If the derived cryptographic key is lost or compromised, the user can use the banknote, or rather the cryptographic key securely stored within it, to revoke (i.e., withdraw) the derived key. For example, the user can regain possession of or access to the banknote and the cryptographic key stored within it by re-deriving the lost or compromised private cryptographic key. The recovered private cryptographic key can then be used, for instance, for a transaction from the smartphone account to themselves. This transaction proves possession of the corresponding private cryptographic key to a managing authority, such as a central bank. For example, payment processing is based on a blockchain, in which the transaction is recorded.Another possibility is that by signing a banknote transaction, for example to oneself, the entire banknote, including its dependent accounts, is dissolved, and all funds in the banknote accounts and dependent accounts are sent to a registered IBAN or SEPA address by a managing entity, such as a central bank. The central bank is able to dissolve the banknote account and its dependent accounts by means of an entry signed with its private cryptographic key. These are, for example, blockchain addresses whose chain can be broken or terminated. This approach corresponds to a complete revocation.
[0026] According to embodiments, the banknote derives the first private cryptographic key for the dependent anonymous account using the banknote-specific second cryptographic key and sends the derived first private cryptographic key to the computer system in response to the derivation request.
[0027] Some designs offer the advantage that the key derivation is printed directly onto the banknote. Only the derived key is visible externally. Therefore, without the banknote, there is no way to access the derived key.
[0028] The one-way function is a key derivation function (KDF). It performs a cryptographic operation that takes a cryptographic key as input and generates one or more additional cryptographic keys as outputs. Using a derived cryptographic key can have the advantage that an attacker who gains access to the derived key will not obtain any useful information about the original cryptographic key or any of the other derived cryptographic keys.
[0029] According to embodiments, the banknote additionally derives a first public cryptographic key belonging to the derived first private cryptographic key and sends the derived first private cryptographic key to the computer system as part of a resulting first asymmetric key pair.
[0030] Implementations can have the advantage that, in addition to the banknote's private cryptographic key, a corresponding derived public cryptographic key is provided. The computer system thus receives, for example, a derived asymmetric key pair. The derived public key can be used to validate cryptograms generated by the computer system using the derived private cryptographic key. Furthermore, the derived public cryptographic key can serve, for example, as the identification number of the dependent account. For instance, the account might be a blockchain-based account, and its blockchain address could be the derived public cryptographic key, or its blockchain address could be derived from the derived public cryptographic key.Deriving a blockchain address involves, for example, applying a hash function to the public cryptographic key, which serves as the input value.
[0031] In some embodiments, the computer system uses the derived first private cryptographic key to compute the corresponding first public cryptographic key. These embodiments offer the advantage that the computer system retains full control over the use of the derived first private cryptographic key. The first public cryptographic key is generated, for example, from the private cryptographic key using elliptic curves.
[0032] According to embodiments, the banknote calculates an input value for the one-way function for deriving the first private cryptographic key for the dependent anonymous account from the banknote-specific second cryptographic key and sends the resulting input value for deriving the first private cryptographic key through the computer system in response to the derivation request to the computer system.
[0033] Some implementations offer the advantage of enabling the computer system to derive the first private cryptographic key. The banknote provides a derived input value for this purpose. The banknote's cryptographic key thus remains securely stored on the banknote itself.
[0034] According to embodiments, the method further comprises deriving the first private cryptographic key for the dependent anonymous account by the computer system using the one-way function and the received input value. Embodiments may have the advantage that the derivation of the first private cryptographic key is performed by the computer system.
[0035] In some embodiments, the computer system derives the first private cryptographic key together with a corresponding first public cryptographic key as the first asymmetric key pair. These embodiments can have the advantage that, in addition to the private cryptographic key, the computer system provides a corresponding derived public cryptographic key. The computer system thus has, for example, a derived asymmetric key pair. The derived public key can be used to validate cryptograms generated by the computer system using the derived private cryptographic key. Furthermore, the derived public cryptographic key can, for example, serve as the identification number of the dependent account.For example, the account is a blockchain-based account, and its blockchain address uses the derived public cryptographic key, or its blockchain address is derived from the derived public cryptographic key. Deriving a blockchain address involves, for example, applying a hash function to the public cryptographic key, which serves as the input value.
[0036] According to some embodiments, the banknote-specific second cryptographic key is a second private cryptographic key of a second asymmetric key pair of the banknote.
[0037] In some embodiments, a maximum number of cryptographic key derivations for dependent anonymous bank accounts are defined for the banknote. These embodiments offer the advantage of allowing multiple derivations while simultaneously limiting the number of possible derivations. The derivations provide flexibility, for example, with regard to different computer systems for which dependent or derived accounts can be created using one and the same banknote. For instance, one or more computer systems can each create multiple dependent accounts. These accounts are all anonymous. By using multiple anonymous accounts, the overall anonymity of transactions can be further enhanced.By using different anonymous accounts for different transactions, it's possible to prevent these transactions from being linked to one another. For example, it prevents transactions from being attributed to a common origin. Furthermore, limiting the maximum number of dependent accounts prevents dependencies from becoming too numerous and / or complex. If, for instance, a banknote is revoked, all dependent accounts could also become invalid, i.e., be revoked as well. Limiting the number of dependent accounts per banknote prevents too many derived accounts from becoming invalid when a single banknote is revised or invalidated.If more dependent accounts are to be made available, one or more additional banknotes can be used to derive further accounts, for example, without exceeding the maximum permissible number of derivations for any of the banknotes used.
[0038] In some embodiments, the banknote includes a counter. The counter starts at zero and increases by one with each derivative until it reaches the maximum number of derivatives. In other embodiments, the counter starts at the maximum number and decreases by one with each derivative until it reaches zero.
[0039] According to embodiments, the method further comprises: Generating a payment-specific first cryptogram to release an initial payment from the banknote account to the dependent account, wherein the first cryptogram is generated from the banknote identification number and a first payment-specific code as input values using the banknote-specific second cryptographic key, and sending a first payment release comprising the payment-specific first cryptogram to the computer system.
[0040] Some implementations offer the advantage that the initial payment can initialize or register the dependent account. Furthermore, the initial payment can, for example, transfer an initial sum of money from the banknote account to the derived account. The computer system can then forward the cryptogram to record the transaction in a register, which is managed, for example, by the central bank that issued the banknote. This register could, for instance, be a blockchain. In this case, the banknote account or the banknote's identification number would be, for example, a blockchain address for the banknote, and the cryptogram would be, for example, a signature of the transaction using the banknote's cryptographic key as the signature key.
[0041] For example, this initial payment or transaction serves to initialize or register the dependent account. With the entry of the corresponding transaction into a central payment register, such as by a central bank issuing the banknote, the dependent account is registered and thus recognized for further use in transactions, in particular for executing transactions from the dependent account to other accounts. The computer system is therefore provided with an anonymous account, which gives it a functionality comparable to a banknote for cashless payments. In the case of a blockchain, an entry with the first cryptogram, for example, represents a genesis block or genesis entry for the dependent account, or a blockchain address of the dependent account. For example, the dependent account itself is registered by the genesis block or genesis entry.For example, the genesis block or genesis entry registers the banknote account of the corresponding banknote, or an associated blockchain address, as the banknote account on which the dependent account depends. For example, in the central payment register, such as a blockchain, only banknote accounts and accounts dependent on banknote accounts are registered. For example, a prerequisite for registering an additional account is the identification of a banknote account on which the corresponding additional account depends. For example, in the central payment register, such as a blockchain, in addition to banknote accounts and accounts dependent on banknote accounts, only one or more accounts are registered that are assigned to an entity managing the central register, such as a central bank.
[0042] Such registration of the banknote account of the corresponding banknote, or a related blockchain address for the dependent account, allows the banknote to have access to both the banknote account and the dependent account. For example, in addition to the computer system that holds the first private cryptographic key for the dependent anonymous account, the banknote can also use its banknote-specific second cryptographic key to create cryptograms for authorizing transactions from the dependent account. Thus, the banknote-specific second cryptographic key acts as a master key, which, as a result of the banknote's registration for the dependent account, also grants access to the dependent account. For example, the banknote-specific second cryptographic key can also be used to revoke the dependent account.For example, in the event of a reversal of the dependent account, any current balance of the corresponding account at the time of the reversal will be transferred to the banknote account of the banknote on which the dependent account is dependent.
[0043] For example, the payment authorization is entered into a central register along with the first cryptogram. This register is managed, for instance, by the central bank that issues the banknote. The first cryptogram is, for example, a signature created using the banknote-specific second cryptographic key as the signature key. In addition to the signature, the payment authorization includes the data signed with the signature. For example, the payment authorization includes the signed data in plaintext. Access to a central register in which the payment authorization is stored with the first cryptogram and / or the signed data is restricted. For example, only an administrative authority, such as the central bank that issues the banknotes, is authorized to access it. In this case, even data in plaintext can be protected from unauthorized access.For example, some of the signed data included in the payment authorization is encrypted. For example, all of the signed data included in the payment authorization is encrypted. Encryption of the signed data can be done, for example, using a public cryptographic key of the central bank managing the central register. For example, the central register is a blockchain, where the first cryptogram in the form of a signature and / or additional data signed by means of the cryptogram are recorded as an entry. For example, the complete payment authorization is recorded in the blockchain.
[0044] For the registration of the banknote account and / or the dependent account, the payment release includes, for example, the identification number of the banknote account and / or the dependent account. For the registration of the respective associated cryptographic key, the payment release includes, for example, the first public cryptographic key of the dependent account and / or a second public cryptographic key of the banknote account. For example, in the case of a blockchain as a central ledger, the payment release includes a blockchain address of the dependent account and / or the banknote account. The blockchain address of the dependent account and / or the banknote account could, for example, be the first or second public cryptographic key of the dependent account or the banknote account, respectively.For example, the identification number of the dependent account and / or the banknote account could be the blockchain address of the dependent account and / or the banknote account.
[0045] In some embodiments, the first cryptogram further includes a specification indicating where the balance of the dependent account is to be transferred in the event of a reversal of the transaction. These embodiments offer the advantage of defining, with the initial payment or transaction, the destination of the current balance of the corresponding account in the event of a reversal. This transfer can, for example, occur automatically in the event of a reversal. For instance, the transfer is executed by an entity managing the central ledger, such as a central bank issuing banknotes. In the case of a blockchain, for example, the managing entity, such as the central bank, uses a smart contract for this purpose.
[0046] In some embodiments, the information includes an identification number of a banknote account. This banknote account is, for example, the banknote account of the banknote on which the dependent account depends. Alternatively, the banknote account could be another banknote account of a different banknote. Some embodiments offer the advantage that, in the event of a reversal of the dependent account, the current balance of the account being reversed is transferred to the banknote account and is available there.
[0047] In some embodiments, the information includes an identification number of a further dependent account. This further dependent account is, for example, an account that is dependent on the same banknote account. It is also, for example, an account that is dependent on a different banknote. Some embodiments offer the advantage that, in the event of a chargeback of the dependent account, the current balance of the account being charged is transferred to the further dependent account and is available there.
[0048] In some embodiments, the information includes a banknote-independent bank account number. This banknote-independent bank account number identifies, for example, a bank account that is independent of banknotes, i.e., neither a banknote account nor a dependent account, and is not, for example, part of the central register that records transactions, balances of banknote accounts and dependent accounts. The bank account number can be, for example, an International Bank Account Number (IBAN) as described, for instance, in ISO standard ISO 13616-1:2007 Part 1. Some embodiments offer the advantage that, in the event of a chargeback of the dependent account, the current balance of the account to be charged at the time of the chargeback is transferred to a bank account identified by the banknote-independent bank account number and is available there.For example, the transfer to the bank account identified by the banknote-independent bank account number is carried out by an entity managing the central register, such as the central bank that issued the banknote. For instance, the funds to be transferred are first transferred to an account at the central bank, which then initiates a payment of the same amount to the bank account identified by the banknote-independent bank account number, for example, without the involvement of the central register. The central bank then offsets the received funds against the payment of the same amount.
[0049] In some embodiments, the initial payment from the banknote account to the dependent account involves a payment amount of zero. These embodiments can have the advantage that the initial payment, being zero, can be clearly identified as such, its sole purpose being the initialization or registration of the dependent account.
[0050] In some embodiments, the initial payment from the banknote account to the dependent account involves a payment amount greater than zero. These embodiments can have the advantage that the initial payment not only initializes or registers the dependent account, but also provides an initial amount in the dependent account.
[0051] In some embodiments, the computer system is a mobile portable device. Such a device could be, for example, a smartphone or another type of mobile portable device, such as a smartwatch, smartglasses, a tablet, or a laptop. Providing one or more dependent accounts for a mobile portable device can have the advantage that the user can carry the device with them and thus execute transactions at any time using the dependent accounts. For example, the user carries the device regardless of whether they intend to execute transactions. Additionally, using the device for anonymous transactions can have the advantage that the user does not need any additional physical device for these transactions.Furthermore, such transactions serve, for example, to pay amounts due in connection with actions involving a mobile portable device. For instance, these devices are used to access paid services over the internet, such as ordering goods or downloading files. They are also used, for example, to authenticate the user of the mobile device when accessing paid services locally or via a network, such as the internet. Using the same mobile portable device for the transaction simplifies the entire process for the user.
[0052] In some embodiments, the computer system includes a security element that provides a protected memory area in which the derived first private cryptographic key for the dependent anonymous account is stored. These embodiments offer the advantage that the derived private cryptographic key can be securely stored on the computer system.
[0053] According to some embodiments, the method further includes providing an identification number for the dependent account. The dependent account can be identified using this identification number. At the same time, the account is anonymous; that is, the identity of the account holder or the user of the computer system cannot be derived from the identification number. For example, no other personal data of the account holder or the user of the computer system is associated with the account.
[0054] In some embodiments, the identification number for the dependent account is derived from the identification number of the banknote. For example, the function used for derivation can be a one-way function. For instance, in addition to the banknote identification number, other values can be used as inputs for deriving the identification number for the dependent account. For example, the derivations can be numbered, with each derivation number used as an additional input. These embodiments offer the advantage that, based on the banknote identification number, it can be verified whether the dependent account is indeed dependent on the banknote account. Conversely, the identification number of the dependent account cannot be used to infer the identification number of the banknote.
[0055] According to some embodiments, the identification number for the dependent account is the first public cryptographic key of the first derived asymmetric key pair.
[0056] According to some embodiments, the identification number for the dependent account is derived from the first public cryptographic key of the first derived asymmetric key pair.
[0057] According to some implementations, the identification number for the dependent account is a blockchain address.
[0058] In some embodiments, the identification number for the dependent account is derived from the banknote, and the derived identification number is sent to the computer system. For example, the identification number for the dependent account is derived together with the private cryptographic key for the computer system.
[0059] In some embodiments, the identification number is derived by the computer system. These embodiments can have the advantage that, although the private cryptographic key for the computer system is derived from the banknote, the further setup of the account is carried out by the corresponding computer system.
[0060] According to embodiments, the method further comprises a numbering system using a computer. The numbering system using a computer includes: Receiving a payment request for a payment with the computer system, generating a payment-specific second cryptogram to release the payment with the computer system, wherein the second cryptogram is generated from the identification number of the dependent account and a second payment-specific code as input values using the derived first cryptographic key of the dependent anonymous account, sending a second payment release comprising the payment-specific second cryptogram.
[0061] Some implementations offer the advantage that the computer system can be used to execute transactions independently. In particular, the banknote is not required. After deriving the private cryptographic key for the computer system, the banknote can be securely stored. To execute the payment, the transaction, authorized by the payment release, must be entered into a register, which is managed, for example, by the central bank that issued the banknote. The computer system then sends the generated cryptogram to a server at the central bank or to a server of a payment service provider, which processes the payment. This register could, for example, be a blockchain.In this case, the anonymous account of the computer system is, for example, a blockchain address, and the cryptogram is, for example, a signature of the transaction with the derived cryptographic key as the signature key. The computer system can use the anonymous account for cashless payments. The computer system with the anonymous account can thus be used as a substitute for the banknote with the banknote account, with the banknote, for example, being kept as a security anchor.
[0062] According to various embodiments, the method further includes payment with the banknote. Payment with the banknote includes: Receiving a payment request for a payment with the banknote, generating a payment-specific third cryptogram to release the payment with the banknote, wherein the third cryptogram is generated from the banknote identification number and a third payment-specific code as input values using the banknote-specific second cryptographic key, sending a third payment release comprising the payment-specific third cryptogram.
[0063] Some implementations offer the advantage that the banknote can still be used to execute transactions independently. In particular, the banknote can be used for payments independently of the computer system and the dependent account. To execute the payment, the transaction, authorized by the payment release, must be entered into a register, which is managed, for example, by the central bank that issued the banknote. For instance, the banknote sends the cryptogram it generates to a terminal or a user computer system acting as a terminal, which then forwards the corresponding cryptogram to a server of the central bank or to a server of a payment service provider that processes the payment. The register could, for example, be a blockchain.In this case, the anonymous banknote account is, for example, a blockchain address, and the cryptogram is, for example, a signature of the transaction using the cryptographic key of the banknote as the signature key.
[0064] According to embodiments, the method further comprises revoking the dependent account. According to embodiments, revoking the dependent account involves repeatedly deriving the derived first private cryptographic key of the account to be revoked and using the derived first private cryptographic key to revoke the account.
[0065] Implementation methods can offer the advantage that, in the event of a compromise of the computer system, particularly in the case of loss, the banknote remains available. Its cryptographic key allows the derivation of the derived first private cryptographic key to be repeated. Thus, even if the owner of the banknote no longer has access to the computer system, they still retain access to the dependent anonymous account of the computer system or to its derived private cryptographic key.
[0066] According to some embodiments, revoking the dependent account further includes: Generating a payment-specific fourth cryptogram to release a payment from the account to be revoked to an account designated for revoking the corresponding account, wherein the payment from the account to itself indicates a revocation of the corresponding account, sending a fourth payment release comprising the payment-specific fourth cryptogram.
[0067] The corresponding payment-specific fourth cryptogram can be generated, for example, using the first private cryptographic key. If this first private cryptographic key is no longer available, it can be recovered, for example, by repeating the derivation process using the banknote. Alternatively, the payment-specific fourth cryptogram can be generated using the banknote-specific second cryptographic key. If the first private cryptographic key is no longer available, the corresponding payment can be released, for example, by the banknote.For example, this requires the registration of a banknote-specific second public cryptographic key, which, together with the banknote-specific second public cryptographic key in the form of a private cryptographic key, forms an asymmetric key pair in the central register. The central register could be, for example, a blockchain.
[0068] For example, in the case of a blockchain, a smart contract is used for reversals, which specifies that a corresponding payment initiates a reversal.
[0069] According to some embodiments, the account provided for revoking the account to be revoked is either the account to be revoked itself or an account provided and managed for revocation purposes by the central bank issuing the banknote.
[0070] Implementations can offer the advantage that a payment from the dependent account to itself can signal a revocation of the corresponding dependent account by the account holder, who possesses the first private cryptographic key. Furthermore, by recording the corresponding transaction in a ledger, such as a blockchain, the revocation of the account can be logged in the ledger. Thus, using the banknote, which allows the derivation of the first private cryptographic key, everything necessary for revoking the dependent account can be provided. Such a revocation can occur, for example, if the dependent account has been compromised and / or if the corresponding computer system has been compromised, such as stolen.Furthermore, such a payment from the dependent account to itself can initiate a transaction of the current balance of the corresponding account at the time of the reversal to the banknote account of the banknote on which the account to be reversed is dependent, to a banknote account of another banknote, to another dependent account dependent on the same banknote, or to another account dependent on yet another banknote. For example, such a payment from the dependent account to itself can initiate the transfer of the current balance of the corresponding account at the time of the reversal to a banknote-independent bank account, for example, outside the register. For example, the corresponding transfer is carried out by an entity managing the central register, such as the central bank that issues the banknote.For example, in the case of a blockchain, the managing entity, such as the central bank, uses a smart contract for this purpose.
[0071] For example, the payment from the dependent account itself includes a payment amount of zero. For example, the payment from the dependent account itself includes a payment amount greater than zero.
[0072] Alternatively, the fourth cryptogram can authorize a payment from the account to be revoked to a predetermined account at the central bank. This payment revokes the account to be revoked, and the payment, which may include the entire balance of the account to be revoked at the time of revocation, can then be forwarded by the central bank to another account. For example, the balance could be forwarded to a registered IBAN or SEPA address.
[0073] According to some embodiments, reversing the dependent account further includes using the banknote: Generating a payment-specific fifth cryptogram to release a payment from the anonymous banknote account to the account to be revoked, wherein the payment from the banknote account to the account to be revoked includes a payment amount of zero, and sending a fourth payment release comprising the payment-specific fifth cryptogram.
[0074] Implementations can have the advantage that a payment of zero from the anonymous banknote account of the banknote on which the account to be revoked depends can initiate the revocation of the corresponding dependent account. For example, the banknote's unique second cryptographic key is sufficient for this purpose. In the case of a blockchain, for instance, a smart contract is used for revocation, specifying that a corresponding payment initiates a revocation.
[0075] According to some embodiments, the method further includes revoking the anonymous banknote account individually assigned to the banknote using the banknote itself. Some embodiments have the advantage that the banknote account can also be revoked.
[0076] According to various embodiments, revoking the anonymous banknote account individually assigned to the banknote using the banknote includes: Generating a payment-specific sixth cryptogram to release a payment from the anonymous banknote account to be revoked to oneself, wherein the payment from the banknote account to oneself indicates a revocation of the corresponding banknote account, sending a fifth payment release comprising the payment-specific sixth cryptogram.
[0077] A banknote account can be revoked by making a corresponding payment from the anonymous banknote account to oneself. Furthermore, the revocation of the anonymous banknote account can be recorded in a ledger, such as a blockchain, by entering the corresponding transaction into that ledger.
[0078] For example, in the case of a blockchain, a smart contract is used for reversals, which specifies that a corresponding payment initiates a reversal.
[0079] For example, the payment from the anonymous banknote account itself involves a payment amount of zero. For example, the payment from the anonymous banknote account itself involves a payment amount greater than zero.
[0080] Alternatively, the fifth cryptogram can authorize a payment from the banknote account to be revoked to a predetermined account at the central bank. This payment revokes the banknote account, and the payment, which may comprise the entire balance of the banknote account, can then be forwarded by the central bank to another account. For example, the balance could be transferred to a registered IBAN or SEPA address.
[0081] In some embodiments, revoking the anonymous banknote account individually assigned to a banknote automatically includes revoking all dependent accounts created using that banknote. These embodiments offer the advantage that revoking the anonymous banknote account simultaneously revokes all dependent accounts. Which banknotes are dependent on the banknote of the corresponding banknote account can be determined, for example, using the central transaction register, which could be a blockchain. For instance, it can be determined to which accounts initial payments were made from the corresponding anonymous banknote account. In the case of a blockchain, the genesis blocks or genesis entries of the registered dependent accounts can be evaluated for this purpose.
[0082] For example, when a dependent account is reversed, the balance of that account is transferred to the banknote account of the banknote on which the dependent account is based. For example, when a dependent account and / or a banknote account is reversed, the balance of the corresponding account is transferred to a stored IBAN or SEPA address.
[0083] According to embodiments, the method further comprises restoring the derived first private cryptographic key. For restoration, the derivation of the dependent account's first private cryptographic key is repeated, and the resulting private cryptographic key is made available for use as the restored first private cryptographic key.
[0084] Some implementations offer the advantage of providing a means to recover the derived private cryptographic key, i.e., key recovery. For example, the first private cryptographic key can be recovered if the previously used first private cryptographic key can no longer be used due to a defect, such as a computer system malfunction.
[0085] Embodiments further include a banknote comprising a security element with a processor and memory containing program instructions. The memory of the security element stores a banknote identification number, which identifies an anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote. A banknote-specific second cryptographic key is stored in a protected memory area of the security element. The banknote also includes a communication interface. Upon execution of the program instructions, the processor is configured to derive a first private cryptographic key for an anonymous account, which is dependent on the anonymous banknote account of the banknote, for a computer system using the banknote.
[0086] The procedure includes: Receiving a derivation request to derive the first private cryptographic key for the dependent anonymous account from the computer system via the communication interface, initiating a derivation of a derived first private cryptographic key for the dependent anonymous account using a one-way function and the banknote-specific second cryptographic key, wherein the derived first private cryptographic key is used to generate cryptograms for releasing payment from the dependent account.
[0087] According to embodiments, the banknote is configured to execute each of the previously described embodiments of the method for deriving the private cryptographic key for the dependent anonymous account.
[0088] Further embodiments include a system comprising a banknote and a computer system, which includes a processor, memory containing program instructions, and a communication interface. The processor is configured, upon execution of the program instructions, to execute a procedure for the computer system with the banknote to derive a first private cryptographic key for an anonymous account, which depends on an anonymous banknote account individually assigned to a banknote.
[0089] The procedure includes: Sending a derivation request to derive the first private cryptographic key for the dependent anonymous account from the banknote via the communication interface, receiving a response to the derivation request, providing the first private cryptographic key for the dependent anonymous account, derived using a one-way function and the banknote-specific second cryptographic key, to the computer system using the received response for provisioning, and storing the provided first private cryptographic key in a protected memory area of the computer system to generate cryptograms for releasing payment from the dependent account.
[0090] According to embodiments, the banknote is configured to execute each of the previously described embodiments of the method for deriving the private cryptographic key for the dependent anonymous account.
[0091] According to embodiments, the banknote's response includes the first private cryptographic key derived from the banknote using the banknote-specific second cryptographic key, which is provided on the computer system.
[0092] In some embodiments, the computer system uses the derived first private cryptographic key received from the banknote to calculate a corresponding first public cryptographic key.
[0093] In some embodiments, the banknote's response additionally includes a first public cryptographic key associated with the derived first private cryptographic key, which the banknote has derived in addition to the derived first private cryptographic key. In this case, the derived first private cryptographic key is received, for example, as part of a first derived asymmetric key pair.
[0094] In some embodiments, the banknote's response includes an input value, or seed, calculated by the banknote from its banknote-specific second cryptographic key, for the one-way function used to derive the first private cryptographic key. Providing the derived first private cryptographic key, for example, involves the computer system using the received input value to derive the first private cryptographic key via the one-way function.
[0095] In some embodiments, the processor is further configured to execute a procedure for calculating with the computer system when the program instructions are run. This calculation with the computer system includes: Receiving a payment request for a payment with the computer system, generating a payment-specific second cryptogram to release the payment with the computer system, wherein the second cryptogram is generated from the identification number of the dependent account and a second payment-specific code as input values using the derived first cryptographic key of the dependent anonymous account, sending a second payment release comprising the payment-specific second cryptogram.
[0096] In some embodiments, the computer system is a mobile portable device, such as a smartphone, smartwatch, smartglasses, tablet or laptop.
[0097] Further embodiments include a system for deriving a first private cryptographic key of an anonymous banknote account, which is uniquely assigned to a banknote according to one of the embodiments described herein. The first private cryptographic key is derived using the banknote and is intended for a computer system according to one of the previously described embodiments. The system comprises the computer system and the banknote.
[0098] According to embodiments, the system is configured to execute each of the previously described embodiments of the method for deriving the private cryptographic key for the dependent anonymous account.
[0099] In some embodiments, the banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. In other embodiments, the banknote includes, for example, a visual indication of the identification number. In other embodiments, the banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.
[0100] For example, the money supply in circulation, which can be transferred both via cash and electronically, is defined by the money supply, or the sum of the nominal values, assigned to banknote accounts. For instance, the money supply in circulation remains constant if the number of banknotes in circulation remains the same. This means, for example, that the number of banknotes in circulation can remain constant, but the nominal values assigned to individual banknotes can change as a result of transactions. It would also be possible, for example, to change the money supply assigned to banknotes without changing the number of banknotes in circulation if the central bank allows payment transfers from banknote accounts to other accounts, such as in other systems like the SEPA GIRO system, and vice versa.
[0101] Since neither the banknote nor its associated banknote account is linked to a legal or natural person, the banknote enables, for example, both cash-based and cashless anonymous payments, as is currently only possible with cash. To prevent misuse, additional restrictions could be implemented, such as limiting the amount of money that can be transferred and / or requiring additional verification mechanisms for certain amounts. Such verification mechanisms could, for example, require the central bank to approve the transaction based on a review of additional information beyond what is strictly necessary.
[0102] The banknote, and thus its nominal value according to the banknote account, can be transferred, for example, through physical handover; that is, a digital currency can be transferred. For this, no personal account belonging to the user of the banknote—that is, an account assigned to a legal or natural person—is necessary. For example, material and effort can be saved by reducing the amount of purely analog currency. In particular, the effort involved in the physical transfer and transport of banknotes can be reduced. Such a banknote can, for example, be upgraded and used for direct contactless payment with little or no control or tracking, since an individual banknote, like traditional cash, can be transferred at any time.
[0103] For example, the current face value of the banknote is also stored in the security element's memory. The banknote's actual face value is determined by its face value according to the banknote account. For example, the face value stored in the banknote can be used for an offline determination of the current face value. For example, the face value stored in the banknote is updated when a transaction confirmation signed by the central bank is forwarded to the banknote to complete a transaction. For example, the security element has a signature verification key for verifying central bank digital signatures.
[0104] The actual face value of a banknote is determined solely by the face value or balance of the banknote account to which that banknote is assigned. To access the balance of the banknote account and thus the face value of the banknote, possession of a banknote genuine to the corresponding banknote account, bearing a banknote-specific cryptographic key, is necessary.
[0105] For example, based on the determined current face value, a decision can be made as to whether a cash payment or a cashless payment should be made with the banknote. If the current face value is identical to the amount to be paid, a cash payment is made, in which case the banknote is handed over to the payee and ownership of it transfers to them. If the current face value is greater than the amount to be paid, a cashless payment is made. In the case of a cashless payment, a corresponding payment request is sent to the banknote for a payment in the form of a transaction of the amount to be paid from the banknote's account to an account, such as a banknote account, of the payee. The banknote can authorize this transaction with a payment-specific cryptogram.
[0106] If the current nominal value is greater than the amount to be paid, it would also be possible for a cash payment to be made and the excess amount to be returned as change, for example in the form of cash, such as banknotes with a matching nominal value, by the payee.
[0107] For example, the current nominal value can take any positive value including zero. Therefore, the banknote account cannot be overdrawn. For example, the current nominal value can take any value between zero and a predetermined maximum nominal value. For example, the current nominal value can take any value greater than or equal to a predetermined minimum nominal value. For example, the current nominal value can take any value from and including a predetermined minimum nominal value up to and including a predetermined maximum nominal value.
[0108] For example, the face value of a banknote can comprise a guaranteed minimum face value and a variable additional face value component. The minimum face value can, for instance, only be paid in cash by handing over the banknote, while the variable additional face value component can be used in cash-based or cashless payment transactions. In other words, the banknote can only be used for cashless payments where the remaining face value of the banknote is greater than or equal to the minimum face value. If an amount is to be paid with the banknote that would result in a remaining face value less than the minimum face value, a cashless payment using the banknote account will be blocked, for example. Thus, a minimum balance in the banknote account is set, in the form of the guaranteed minimum face value.In this case, for example, a cash payment must be made, in which the banknote is handed over. If the current face value of the banknote is greater than the amount to be paid, the difference can be refunded by the recipient, for example, in the form of change.
[0109] For example, the initial face value of the banknote, or the starting balance of the banknote account, is recorded in a register of the central bank and booked by the central bank in a payment system it manages. For example, during the initialization of the banknote, the central bank transfers the starting balance from a central bank account to the banknote account of the banknote being initialized.
[0110] For example, the visual design, security features, and / or format of a banknote depend on its initial face value. Thus, banknotes with different initial face values differ from one another in their visual design, security features, and / or format. Banknotes with the same initial face value, however, have identical visual design, security features, and / or formats, except for one or more banknote-specific details such as a serial number, year of issue, etc.
[0111] For example, a banknote includes a visual indication of its minimum face value. The minimum face value for the banknote, or the minimum balance set for the banknote account, is recorded in a central bank register. The visual design, security features, and / or format of the banknote depend on its minimum face value. Therefore, banknotes with different minimum face values differ from one another in terms of their visual design, security features, and / or format. Banknotes with identical minimum face values, for example, have identical visual design, security features, and / or formats, except for one or more banknote-specific details such as a serial number, year of issue, etc.
[0112] For example, the initial face value assigned to a banknote, which the banknote visually represents, is the total face value transferred from the central bank to the banknote account associated with the banknote during its initialization. This total face value initially assigned to a banknote includes the guaranteed minimum face value and an initial additional face value component. This additional face value component varies depending on the transactions made to and from the banknote account. For example, the visually indicated initial face value is a portion of the total face value that is allocated to the banknote as initial credit in the banknote account during its initialization.For example, the corresponding portion is the minimum face value, whereby the actual total face value may initially be larger, i.e., it may include an initial additional face value portion. For example, the total face value transferred to the banknote account during its initialization is a minimum face value of the banknote, which is, for example, visually indicated on the banknote. In this case, the visual indication of the initial face value is, for example, also a visual indication of the minimum face value of the banknote. Alternatively, the minimum face value may differ from the initial face value. In this case, the banknote may include a visual indication of the minimum face value in addition to the visual indication of the initial face value.
[0113] Adding or increasing a variable additional nominal value is achieved, for example, by transferring a corresponding amount to the banknote's account. This transfer can originate from another account, such as another banknote's account or a central bank account. For example, the variable additional nominal value can be increased without limit. Alternatively, the variable additional nominal value can be increased depending on the minimum nominal value and / or the initial nominal value. For example, a maximum permissible variable additional nominal value for the banknote's account is recorded in a register maintained by the central bank. For example, the maximum permissible variable additional nominal value for the banknote might be 100%, 200%, 300%, 400%, 500%, 600%, 700%, 800%, 900%, or 1000% of the banknote's minimum nominal value.For example, a maximum permissible variable additional nominal value is uniformly limited for all banknotes issued by the central bank. For instance, when a transaction is made to a banknote account, a check is performed to determine whether the transaction would exceed the maximum permissible variable additional nominal value. If the maximum permissible variable additional nominal value is not exceeded, the transaction is executed. If the maximum permissible variable additional nominal value is exceeded, the transaction is not executed.
[0114] The banknote can be paper-based and / or plastic-based. For example, the banknote may comprise one or more layers of material. Materials used for these layers can include paper, plastics, and / or metal foils. A layer can also consist of combinations of several of these materials. For example, the layers may be laminated together. The layers may include, or combine, electronic components, such as a security feature with a processor and memory, an antenna, a display, an input device, and / or sensors. The banknote may also be flexible.
[0115] Banknotes incorporate a number of security features that allow for verification of their authenticity and validity. These features can include one or more Level 1, Level 2, and / or Level 3 security features. Level 1 security features are those that can be directly recognized and verified by humans without any additional tools. Level 2 security features are machine-readable and are used, for example, for commercial purposes to verify the authenticity of banknotes. Level 3 security features are known only to the issuing central bank. Central banks use these secret, machine-readable security features to ensure the integrity of the cash cycle and to guarantee that only genuine banknotes are put back into circulation.Furthermore, central banks use such Level 3 security features to remove genuine banknotes from circulation and destroy them in a controlled manner if the circulation capability of the banknotes is no longer sufficient, for example due to soiling and / or wear and tear.
[0116] Security features can include tactile, acoustic, or visual features. For example, banknotes may be made from materials such as security papers with a characteristic tactile feel and / or sound when rubbed or crumpled. Tactile embossing may be incorporated into the banknote. Visually detectable security features may include watermarks, see-through windows, see-through registers, registration marks, foil elements, guilloches, iris printing elements, anti-copying screens, melange fibers, micro-perforations, microprinting, optically variable inks, pearlescent stripes, security threads, and / or special colors. Security elements such as metameric color combinations, fluorescent colors, diffractive optical elements, and / or scrambled indicia microprinting patterns may also be used.
[0117] For example, machine-readable security elements are used, such as infrared properties of the printing ink, phosphorescent inks, magnetic elements, elements with characteristic electrical conductivity and / or copy protection elements, such as a digital watermark and / or standardized patterns, for example an EURion constellation or Omron rings.
[0118] For example, the banknote includes one or more security features that are only known to and / or verifiable by the issuing central bank, i.e., Level 3 security features, such as the ECB's M-feature.
[0119] Security features, especially Level 1 and Level 2 security features, offer the advantage of allowing parties involved to easily verify the authenticity and validity of a banknote. This enables the use of banknotes for cash payments, which involve the transfer of the banknote from a payer to a payee.
[0120] In this context, a "communication interface" is understood to be, for example, an interface through which data can be received and sent, whereby the communication interface can be configured as contact-based or contactless.
[0121] Communication can take place, for example, via a network. Here, "network" refers to any transmission medium with a connection for communication, in particular a local connection or local network, especially a Local Area Network (LAN), a private network, especially an intranet, and a digital private network (Virtual Private Network - VPN). For example, a computer system can have a standard wireless interface for connecting to a WLAN. Furthermore, it can be a public network, such as the internet. Depending on the specific implementation, this connection can also be established via a mobile network.
[0122] Contactless communication with banknotes is possible, for example, via Near Field Communication (NFC). This is a communication method based on RFID technology for the contactless exchange of data via electromagnetic induction using loosely coupled coils over short distances, such as a few centimeters. NFC can be implemented according to standards such as ISO 14443, 18092, 21481, ECMA 340, 352, 356, 362, or ETSI TS 102 190.
[0123] The banknote's communication interface includes, for example, an antenna for contactless communication. The antenna may contain an induction coil. The induction coil can also be configured to supply external power to the banknote, for example, via energy harvesting. For instance, the induction coil could be configured to allow a terminal to couple energy into the banknote.
[0124] In this and the following text, a "processor" is understood to be a logic circuit used to execute program instructions. The logic circuit can be implemented on one or more discrete components, particularly on a chip. A processor includes, for example, an arithmetic logic unit (ALU), a control unit, registers, and data lines for communication with other components. Specifically, a "processor" is understood to be a microprocessor or a microprocessor system consisting of multiple processor cores and / or multiple microprocessors.
[0125] In this context, "memory" refers specifically to non-volatile memory. For example, "non-volatile memory" refers to electronic storage for the permanent storage of data. Non-volatile memory can be configured as non-removable memory, also known as Read-Only Memory (ROM), or as removable memory, also known as Non-Volatile Memory (NVM). In particular, this can be an EEPROM, such as a Flash EEPROM, or simply Flash. A key characteristic of non-volatile memory is that the data stored on it is retained even after the power supply is switched off.
[0126] A "protected memory area" is understood here to be an area of electronic storage that can only be accessed—that is, read or write—via a processor of the security element. For example, no external access is possible to the protected memory area; data can neither be added to it from the outside nor output to it. For example, data can be read from the protected memory area via the processor. For example, data can be added to the protected memory area from the outside via the processor. According to certain embodiments, access from or via the processor connected to the memory is only possible if a required condition is met. This condition could be, for example, a cryptographic condition, in particular successful authentication and / or successful authorization verification.Such a verification can, for example, be based on an electronic signature with a signature key.
[0127] Asymmetric key pairs are used in a variety of cryptosystems and also play a crucial role in the signing of electronic documents. An asymmetric key pair consists of a public key, which is used to encrypt and / or decrypt data and may be shared with third parties, and a private key, which is also used to encrypt and / or decrypt data and must generally be kept secret. The public key allows anyone to encrypt data for the owner of the private key and to verify digital signatures created with the private key. A private key allows its owner to decrypt data encrypted with the public key or to create digital signatures. A signature created with a private key can be verified with the corresponding public key.
[0128] Creating a digital signature, hereinafter also referred to simply as a "signature," is a cryptographic process in which an additional data value, called a "signature," is calculated for any given data. A signature could, for example, be a hash value of the source data encrypted with a private cryptographic key.
[0129] A security element, in this context, is understood to be an electronic component comprising a processor and memory, to which only certain predefined access rights are granted. For example, only specific data values, stored in certain memory areas, can be read. Data values stored in a protected memory area cannot be read. For example, writing a data value to the security element's memory requires a digital signature, the verification key for which is stored within the security element. For example, only the processor has write access to write data to a protected memory area.
[0130] The security element also provides, for example, cryptographic core routines in the form of cryptographic program instructions with cryptographic algorithms for signature creation and / or verification, key generation, and / or random number generation, and can also serve as a secure storage for cryptographic keys.
[0131] For example, at least parts of the security element are signed. Before the security element can be used, the system checks whether the signature(s) are valid. If one of the signatures is not valid, the use of the security element is blocked, for example.
[0132] For example, the security element has physically restricted access. Furthermore, the security element may incorporate additional measures against misuse, particularly against unauthorized access to data stored in the security element's memory. For instance, a security element includes sensors for monitoring the security element's condition and its environment to detect deviations from normal operation that could indicate tampering attempts. Corresponding sensor types include, for example, a clock frequency sensor, a voltage sensor, and / or a light sensor. Clock frequency sensors and voltage sensors, for example, detect deviations in clock frequency, temperature, and / or voltage above or below a predefined normal range. In particular, a security element may include non-volatile memory with a protected memory area.
[0133] For example, the means of protecting the security element against unauthorized manipulation include mechanical means designed to prevent, for instance, the opening of the security element or its parts, or which render the security element unusable upon attempted tampering, for example, by causing data loss. For example, at least parts of the security element may be encased, cast, and / or laminated in a material whose attempted removal would inevitably destroy the corresponding parts of the security element.
[0134] Visual information refers, for example, to information that is incorporated into the banknote in an optically readable form. This information may be printed, embossed, engraved, punched, cut out, or otherwise optically detectable on the banknote and / or a layer of its material. These visual features can be detected, for example, with an optical sensor such as a camera.
[0135] The cryptogram results from the application of a cryptographic algorithm. For example, the banknote's identification number and a payment-specific code are used as input values and encrypted with the banknote's unique cryptographic key.
[0136] In some embodiments, the identification number is also stored in the protected memory area of the security element. These embodiments offer the advantage that the identification number can also be effectively protected against unauthorized access.
[0137] According to some embodiments, the banknote comprises multiple security features. These embodiments can have the advantage that, using these security features, which may be, for example, Level 1, Level 2, and / or Level 3 security features, it is possible to verify the authenticity and validity of the banknote. According to some embodiments, one or more of these security features include the banknote's serial number and / or identification number. These embodiments can have the advantage that when one or more of the corresponding security features are detected, the banknote's serial number and / or identification number can also be detected.As part of the corresponding security features, these features can be used to verify not only the authenticity and validity of the banknote itself, but also the authenticity and validity of the banknote's serial number and / or identification number. Thus, for example, a secure connection or assignment between the physical banknote and the banknote account can be established, which can be identified using the banknote's serial number and / or identification number. Depending on the specific implementation, the one or more security features that include the banknote's serial number and / or identification number are, for example, Level 1, Level 2, and / or Level 3 security features.
[0138] In some embodiments, the banknote includes the serial number displayed multiple times across its surface. These embodiments offer the advantage that the serial number can be read even if the banknote is partially damaged. For example, the serial number may be incorporated into the banknote in combination with and / or as part of several security features. This could have the advantage that, as long as sufficient security features are present to confirm the banknote's authenticity and validity, the banknote's serial number can be read.
[0139] In some embodiments, the majority of the serial number information is distributed across the banknote in such a way that it can be determined as long as more than 50% of the banknote is present. These embodiments offer the advantage that, even if part of the banknote is lost, it can be ensured that as long as more than 50% of the banknote remains—a prerequisite, for example, for replacing the banknote—the remaining portion includes the banknote's serial number. Thus, even in the case of partial loss, it can be ensured that, as long as the remaining portion(s) of the banknote are valid, the serial number can be recorded and the current face value of the banknote can be determined according to the banknote account.
[0140] In some embodiments, the identification number is a banknote account number of the anonymous banknote account individually assigned to the banknote. In other embodiments, the identification number is a number generated independently of the banknote's serial number. In other embodiments, the independently generated identification number is assigned to the banknote's serial number. For example, the identification number is assigned to the serial number using an entry in a register maintained by the central bank, which assigns the identification number to the serial number.
[0141] In some embodiments, the identification number is the banknote's serial number. In other embodiments, the identification number is a banknote account number generated using the serial number, belonging to the anonymous banknote account individually assigned to the banknote. These embodiments can have the advantage that, based on information from the banknote, such as its serial number, the associated banknote account can be identified and thus the current nominal value of the banknote can be determined.
[0142] In some embodiments, the identification number is an identification number assigned to the banknote account number of the anonymous banknote account individually assigned to the banknote, for example, in a register entry of a register maintained by the issuing central bank. In other embodiments, the identification number is generated independently of the banknote's serial number and assigned to it, for example, in a register entry of a register maintained by the issuing central bank. In other embodiments, the identification number is generated independently of the banknote account number of the anonymous banknote account individually assigned to the banknote and assigned to it, for example, in a register entry of a register maintained by the issuing central bank.
[0143] Some implementations offer the advantage that, in a register-based allocation, access to the register may be necessary to determine the corresponding banknote account for a banknote. For example, in a register managed by the issuing central bank, only that central bank can determine the banknote account associated with a banknote.
[0144] In some embodiments, the payment-specific code includes a timestamp and / or a random number. These embodiments offer the advantage of efficiently individualizing the cryptogram for each payment. They also ensure that the cryptogram can be efficiently individualized. In other words, this prevents, for example, the generation of the same cryptogram for two different payments with the same banknote, even if identical amounts are paid to identical payees. For instance, if a cryptogram is submitted to the central bank for payment authorization that has already been processed by the central bank, it follows that the submitted cryptogram is no longer valid.
[0145] According to some embodiments, the banknote-specific cryptographic key is a symmetric cryptographic key. According to other embodiments, the banknote-specific cryptographic key is a private cryptographic key of a banknote-specific asymmetric key pair.
[0146] According to various embodiments, the serial number and / or identification number of the banknote is one of the banknote's individual public cryptographic keys, a number derived from the banknote's public cryptographic key, and / or a number assigned to the banknote's public cryptographic key. Such an assignment can be made, for example, using a corresponding entry in a register maintained by the issuing central bank.
[0147] According to various embodiments, the banknote includes a visual indication of the banknote's public cryptographic key, a value derived from the banknote's public cryptographic key, and / or a value assigned to the banknote's public cryptographic key. Such an assignment can be made, for example, by using a corresponding assignment entry in a register maintained by the issuing central bank.
[0148] According to embodiments, one or more security features of the plurality of security features include an indication of the banknote's public cryptographic key, a value derived from the banknote's public cryptographic key, and / or a value assigned to the banknote's public cryptographic key. Such an assignment can be made, for example, using a corresponding assignment entry in a register maintained by the issuing central bank. Embodiments can have the advantage that, when the corresponding one or more security features are scanned, the banknote's public cryptographic key, a value derived from the banknote's public cryptographic key, and / or a value assigned to the banknote's public cryptographic key can also be captured.As part of the corresponding security features, these features can be used to verify not only the authenticity and validity of the banknote itself, but also the authenticity and validity of the banknote's public cryptographic key, a value derived from the banknote's public cryptographic key, and / or a value assigned to the banknote's public cryptographic key. Thus, for example, a secure connection or assignment between the physical banknote and the banknote account can be established using the corresponding security features, which can be identified, for example, using the banknote's public cryptographic key, a value derived from the banknote's public cryptographic key, and / or a value assigned to the banknote's public cryptographic key.According to various embodiments, the one or more security features, which include an indication of the serial number and / or the identification number of the banknote, are, for example, Level 1, Level 2 and / or Level 3 security features.
[0149] In some embodiments, the payment request specifies an amount to be paid, and this amount is used as an additional input value to generate the payment-specific cryptogram. Some embodiments have the advantage that the amount to be paid is also taken into account when individualizing the cryptogram.
[0150] In some embodiments, the payment authorization further includes the identification number and / or the payment-specific code in plaintext. These embodiments can have the advantage that the identification number and / or the payment-specific code provided in plaintext can be used to verify the validity of the cryptogram. Furthermore, the identification number can be used to identify the banknote account from which the payment is to be made.
[0151] In some embodiments, the payment authorization also includes the amount to be paid in plaintext. These embodiments can have the advantage that the amount provided in plaintext can be used to verify the validity of the cryptogram. Furthermore, the amount to be paid is thus visible without additional cryptographic processing steps.
[0152] In some embodiments, the banknote includes a communication interface for communicating with a terminal. The banknote receives the payment request from the terminal via the communication interface and / or sends the payment authorization to the terminal via the communication interface.
[0153] In some embodiments, the banknote includes a user interface for communication with a user of the banknote, wherein the banknote receives the payment request from a user via an input device of the user interface and / or sends the payment authorization to the user interface for output via a display device of the user interface. The terminal may, for example, be a seller's terminal at a point of sale (POS), i.e., at the location where a sale is completed. The terminal may also be a terminal connected to a user's computer system through which a payment with the banknote is to be processed. For example, this could involve payment processing via a network, such as the internet, with a service provider, be it a seller or a payment service provider.Alternatively, the terminal could be provided to a user in the form of a mobile portable communication device, such as a smartphone. The user could then use this mobile portable communication device, for example, to process a payment via a network, such as the internet, with a service provider, be it a seller or a payment service provider.
[0154] According to embodiments, the banknote includes a user interface for communication with a user of the banknote, wherein the banknote receives the payment request from a user via an input device of the user interface and / or sends the payment authorization to the user interface for output via a display device of the user interface. Embodiments can have the advantage that the user can see and / or control which data is entered into the banknote and which data the banknote outputs.
[0155] The input device can, for example, include a touchpad. The display device can, for example, include a screen. The input device can be combined with the display device, for example, in the form of a touchscreen. The user enters the payment request data, for example, into Banknote using the input device.
[0156] For example, the payment request and / or payment authorization is displayed to the user on the banknote's display device. Confirmation of the displayed payment request and / or payment authorization by the user using the banknote's input device is, for instance, a prerequisite for generating the payment authorization.
[0157] For example, the payment authorization is sent to the banknote's display device for display, such as an alphanumeric string, barcode, or QR code. The payment authorization displayed on the device can then be scanned or read using an optical sensor, such as one on a terminal.
[0158] In some embodiments, the current face value of the banknote is also stored in the memory of the security element. These embodiments can have the advantage that the current face value can be read from the banknote. However, the actual legally binding face value of the banknote is determined by the balance of the associated banknote account.
[0159] For example, the current face value is stored in the protected memory area of the security element's memory. For example, the current face value is not stored in the protected memory area of the security element's memory. For example, the current face value of the banknote stored in the security element's memory can be read externally. For example, the current face value of the banknote stored in the security element's memory cannot be read externally. For example, the current face value of the banknote stored in the security element's memory is used solely for internal verification, such as checking whether a payment amount is less than or equal to the current face value of the banknote.
[0160] According to some embodiments, the serial number of the banknote is also stored in the memory of the security element.
[0161] In some embodiments, the initial face value of the banknote is stored in the security element's memory as the current face value. These embodiments can have the advantage that, starting from this initial face value, the stored face value is adjusted with each successfully processed payment, thus allowing the current face value to be tracked on the banknote side.
[0162] In some embodiments, the processor is further configured to compare the amount to be paid with the stored current face value of the banknote when the program instructions are executed, and to generate the payment-specific cryptogram for releasing or authorizing the payment only if the stored current face value is greater than or equal to the amount to be paid. These embodiments can have the advantage of ensuring that the current face value is sufficient for the payment to be executed.
[0163] In some embodiments, the processor is further configured to execute an update procedure to update the stored current face value of the banknote when the program instructions are executed. The update procedure includes: Receiving an update request to update the current face value of the banknote stored in the security element's memory, wherein the update request includes an updated face value of the banknote together with a cryptographically secured confirmation from the issuing central bank for the updated face value; verifying the cryptographically secured confirmation using a cryptographic check key stored in the security element's memory; if the verification is successful, replacing the current face value of the banknote stored in the security element's memory with the received updated face value.
[0164] Some embodiments offer the advantage of ensuring that the stored nominal value is up-to-date. In some embodiments, the cryptographic verification key is the banknote-specific cryptographic key, for example, a symmetric cryptographic key. In other embodiments, the cryptographic verification key is an additional cryptographic verification key stored in the security element's memory, in addition to the banknote-specific cryptographic key. This additional key could be a public cryptographic key of an asymmetric key pair assigned to the central bank. The signature verification key is stored in the security element, for example, during the banknote production process.
[0165] In some implementations, the update request is received in response to the sending of the payment authorization. For example, the central bank's confirmation of the updated face value is a payment confirmation from the central bank. For example, the updated face value is the previous face value of the banknote less the amount paid.
[0166] In some embodiments, the update request is sent in response to a payment transfer of an additional amount to the anonymous banknote account individually assigned to the banknote. For example, the updated face value is the banknote's previous face value plus the additional amount. These embodiments can have the advantage of also taking into account changes to the face value resulting from a payment transfer of an additional amount to the banknote's account.
[0167] According to some embodiments, no authorization by the banknote itself is necessary for a payment transfer of an additional amount to the banknote account.
[0168] According to some implementations, a payment transfer of an additional amount to the banknote's account requires authorization by the corresponding banknote. This authorization is carried out, for example, analogously to the authorization of payments made with the banknote. The authorization includes, for example: Receiving a payment request for a payment to the banknote account, generating a payment-specific cryptogram to authorize the payment to the banknote account, wherein the cryptogram is generated from the banknote identification number and a payment-specific code as input values using the banknote-specific cryptographic key, and sending a payment authorization comprising the payment-specific cryptogram.
[0169] The payment-specific cryptogram for authorizing the transfer of the additional amount to the banknote's account can, for example, be generated analogously to the payment-specific cryptogram for authorizing payments made with the banknote. Such embodiments can have the advantage of ensuring that the banknote receives information about payments to the account and the associated changes in the banknote's face value.
[0170] In some embodiments, the cryptographically secured confirmation from the issuing central bank includes the encrypted updated face value of the banknote. In other embodiments, the cryptographically secured confirmation from the issuing central bank includes the updated face value together with the banknote's identification number and / or serial number in encrypted form. In other embodiments, the cryptographically secured confirmation from the issuing central bank includes the updated face value together with a timestamp in encrypted form. In other embodiments, a hash function is first applied to the data to be encrypted, for example, the updated face value, identification number, serial number, and / or timestamp, and the resulting hash value is then encrypted.
[0171] In some embodiments, the cryptographically secured confirmation is received along with the banknote account number, the banknote serial number, and / or the timestamp. In other embodiments, the update request includes, in addition to the updated face value, the banknote identification number, the banknote serial number, and / or the timestamp in plaintext. In other embodiments, the cryptographically secured confirmation is decrypted for verification using the verification key, and the resulting hash value is compared with a reference hash value calculated, for example, using the accompanying plaintext data. If there is a match, the verification is successful.
[0172] According to embodiments, the updated nominal value is encrypted using the banknote-specific cryptographic key in the form of a symmetric cryptographic key. According to embodiments, the verification key is the banknote-specific cryptographic key in the form of a symmetric cryptographic key, which can be used to decrypt the cryptographically secured confirmation for verification purposes.
[0173] In some embodiments, the updated nominal value is encrypted using a private cryptographic key from an asymmetric key pair assigned to the central bank, which serves as the signature key. In other embodiments, the verification key is a public cryptographic key of the central bank's asymmetric key pair, stored in the security element's memory, which can be used to decrypt the cryptographically secured confirmation for verification purposes.
[0174] In some embodiments, the banknote receives the update request from a terminal via the communication interface and / or sends the current face value of the banknote, stored in the security element's memory, to the terminal via the communication interface. Some embodiments offer the advantage that the terminal can provide a communication link for the banknote to the central bank or a central bank server.
[0175] In some embodiments, the processor is further configured to execute an output procedure to print the stored current face value of the banknote when the program instructions are executed. The output procedure includes: Receiving an output request to output the current face value of the banknote stored in the memory of the security element, in response to the output request, sending the current face value of the banknote stored in the memory of the security element.
[0176] Some implementations offer the advantage that the current face value stored in the banknote can be directly queried, thus providing access to this information. The query can be performed, for example, using a terminal or, if available, via a user interface on the banknote. The response is then sent to the terminal or to a display device of the user interface for presentation.
[0177] According to embodiments, the transmitted current face value of the banknote is signed with the banknote-specific cryptographic key in the form of a private cryptographic key from an asymmetric key pair associated with the banknote. According to embodiments, the recipient of the signed current face value, for example, a terminal such as a POS terminal, a user computer system, and / or a mobile portable telecommunications device, can verify the signature using a public cryptographic key from the asymmetric key pair associated with the banknote as a signature verification key.
[0178] In some implementations, the transmitted current face value is unsigned. For example, a confirmation request is sent to the central bank to confirm the received current face value of the banknote.
[0179] According to some embodiments, the serial number and / or identification number of the banknote is sent together with the stored current nominal value of the banknote and serves as an identifier of the banknote for the recipient of the current nominal value to send a confirmation request to the central bank to confirm the received current nominal value of the banknote.
[0180] According to some embodiments, the banknote includes a communication interface for contactless communication with a mobile portable telecommunications device. The banknote receives the dispensing request from the mobile portable telecommunications device via the communication interface and / or transmits the current face value of the banknote, stored in the memory of the security element, to the mobile portable telecommunications device via the communication interface.
[0181] According to various embodiments, the banknote includes a user interface for communication with a user of the banknote. The banknote receives the output request from a user via an input device of the user interface and / or sends the current face value of the banknote, stored in the memory of the security element, to the user interface for output via a display device of the user interface.
[0182] According to embodiments, the processor is further configured to execute an output procedure for printing the identification number and / or serial number of the banknote stored in the memory of the security element when the program instructions are executed, wherein the output procedure comprises: Receiving an output request to output the identification number and / or serial number of the banknote stored in the memory of the security element, in response to the request, sending the identification number and / or serial number of the banknote stored in the memory of the security element.
[0183] In some embodiments, the serial number and / or identification number of the banknote serves as an identifier for the recipient to query the current face value of the banknote from the issuing central bank. These embodiments can have the advantage that, with such an identifier, the current face value of the banknote can be queried from the issuing central bank, thus providing reliable information about it.
[0184] According to embodiments, a method for issuing a banknote comprises: Production of the banknote, wherein the banknote further comprises a security element with a processor and a memory containing program instructions, reception of a banknote identification number via a first cryptographically secured channel, wherein the identification number identifies an anonymous banknote account managed by a central bank issuing the banknote and individually assigned to the corresponding banknote, storage of the received identification number in the memory of the security element, reception of a banknote-specific cryptographic key via a second cryptographically secured channel independent of the first channel, storage of the received banknote-specific cryptographic key in a protected memory area of the memory of the security element.
[0185] According to embodiments, the produced banknote includes, for example, a visual indication of a banknote serial number that uniquely identifies the banknote from a predefined range of serial numbers. According to embodiments, the produced banknote includes, for example, a visual indication of the identification number. According to embodiments, the produced banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.
[0186] Design options may have the advantage that the banknote can be initialized securely, i.e., an identification number and banknote-specific cryptographic key can be inserted.
[0187] According to embodiments, the issuing procedure is configured to issue each of the previously described embodiments of the banknote. According to embodiments, the banknote issued using the issuing procedure is a banknote according to one of the previously described embodiments.
[0188] In some embodiments, the identification number is also stored in the protected memory area of the security element. These embodiments offer the advantage of secure storage of the identification number.
[0189] According to embodiments, the method further comprises storing the initial nominal value of the banknote as the current nominal value in the memory of the security element.
[0190] According to embodiments, the method further comprises storing the banknote's serial number in the security element's memory. Embodiments may have the advantage that the current face value and / or the banknote's serial number are stored electronically.
[0191] According to embodiments, the method further comprises storing a public cryptographic key of an asymmetric key pair of the issuing central bank. According to embodiments, the public cryptographic key is used as a verification key for verifying signatures of the issuing central bank.
[0192] According to embodiments, the method further comprises sending a production confirmation to the issuing central bank to confirm the banknote's production. The production confirmation includes the serial number and the initial face value of the produced banknote for storage in a first register of the issuing central bank. The initial face value indicates the current face value of the banknote at the time of issuance. The banknote's identification number and the banknote-specific cryptographic key are received in response to the transmission of the production confirmation for storage in the security element.
[0193] These methods can offer the advantage of ensuring that the production of the banknote is accompanied by the central bank's initialization of a banknote account, which is then assigned to the banknote. This assignment is made centrally by the bank using the serial number and the initial face value. Furthermore, the corresponding identification number and the banknote-specific cryptographic key are provided to the produced banknote, and this assignment is also reflected on the banknote itself.
[0194] In some embodiments, the first register is a publicly accessible register of the central bank. In others, the serial number serves as a database access key for reading the current face value of the banknote from the first register. These embodiments can have the advantage that the current face value of a banknote is generally accessible.
[0195] According to some embodiments, the identification number and the banknote-specific cryptographic key are received in response to the transmission of the production confirmation, after the issuing central bank has stored the identification number and / or the banknote-specific cryptographic key in a second register, which assigns the identification number and / or the banknote-specific cryptographic key to the banknote's serial number. These embodiments can have the advantage that the link or assignment between the physical banknote on the one hand and the digital banknote account on the other can be effected by a corresponding entry in the second register.
[0196] In some embodiments, the identification number serves as a database access key for reading the banknote's serial number and / or the banknote-specific cryptographic key from the second register.
[0197] In some implementations, the registers managed by the central bank, e.g., the first and / or second register, are implemented as a blockchain. In other implementations, the banknote's identification number is a blockchain address of the banknote. For example, the banknote account is implemented using a blockchain or as a blockchain address. For example, the banknote-specific cryptographic key is a private cryptographic key of a banknote-specific asymmetric key pair, which further comprises a public cryptographic key of the banknote, from which, for example, the banknote's blockchain address is derived.
[0198] In this and the following, a "blockchain" is understood to be an ordered data structure comprising multiple interconnected data blocks. Specifically, a blockchain is understood to be an ordered data structure in which each block (except the first block) contains a verification value, such as a hash value, of its predecessor block, thus allowing the validity of all its predecessor blocks to be verified and, if necessary, confirmed. For examples of a blockchain, see https: / / en.wikipedia.org / wiki / Block_chain_(database) and "Mastering Bitcoin," Chapter 7, The Blockchain, page 161 ff. The concept of the blockchain was described, for example, in a 2008 white paper on Bitcoin under the pseudonym Satoshi Nakamoto ("Bitcoin: Peer-to-Peer Electronic Cash System" (https: / / bitcoin.org / bitcoin.pdf)).The blockchain described therein consists of a series of data blocks, each containing one or more entries or transactions and accompanied by a checksum in the form of a hash value. Additional blocks of the blockchain are generated, for example, in a computationally intensive process also known as mining. These newly generated blocks are then added to the blockchain and distributed via a network to all participants, or nodes, of the network.
[0199] Implementations of blockchain technology offer the advantage that the storage of cryptographic checksums (hashes) of the preceding block in each subsequent block provides a high degree of security against subsequent manipulation. The chaining of blocks can then be verified using these root hashes. Each block in the blockchain contains in its header the hash of the entire previous block header. This uniquely establishes the order of the blocks and creates a chain structure. This implemented chaining of individual blocks effectively prevents subsequent modification of previous blocks or individual entries, as this would require recalculating the hash values of all subsequent blocks within a short timeframe.
[0200] A blockchain can also be implemented in the form of a blockchain where only a select group of participants has the authorization to add valid blocks. Such authorization can be verified, for example, by means of a signature using a private cryptographic key. The private cryptographic key can belong to an asymmetric key pair, which also includes a public cryptographic key used to verify the signature. The asymmetric key pair can also be associated with a certificate that confirms the authorization to create a valid block in the blockchain. This certificate can further be associated with a Public Key Infrastructure (PKI), which verifies the certificate's authenticity.In another implementation, for example, a public key for each additional participant to be added to the selected group can be stored in an initialization entry on the blockchain. These public keys can then be used to verify the validity of block signatures and, consequently, the validity of the blocks themselves. The public keys of the original participants in the selected group can, for instance, be stored in a genesis block of the blockchain.
[0201] The blockchain in question, managed by a central bank, is a public blockchain hosted on the central bank's blockchain servers. For example, new blocks are added exclusively by these central bank-managed blockchain servers. In this case, computationally intensive processes for adding additional blocks are eliminated. For instance, adding additional blocks requires only a signature with a signature key assigned to the central bank.
[0202] Consensus can also be implemented in a blockchain in other ways. For example, consensus can be reached by voting on the inclusion of proposed entries in the blockchain. Each participant or blockchain server maintains a unique list of other participants they trust as a group. Each participant can propose additional entries to be included in an additional block of the blockchain. A vote is then held on the inclusion, and thus the validity, of the proposed entries. For example, each participant only votes on those proposals that originate from participants on their list. In other words, the decision as to whether a proposal for an additional entry is recognized as valid, i.e.,Whether there is consensus among the participants regarding the validity of an entry is determined by considering only the votes of those participants included on the list of the participant making the proposal. For a proposal to be accepted as valid, a certain minimum percentage of eligible participants must vote in favor, for example, 80%, 90%, 95%, or 100%. All proposed entries that meet this criterion are added to the blockchain. Such a vote can involve multiple rounds. All other proposals that do not meet the aforementioned criterion are either rejected or put to a vote again when voting on the next block of the blockchain.The aforementioned lists represent subgroups of the blockchain network, which the participant maintaining the respective list trusts as a whole, without requiring them to trust each individual participant on the list. An example of such a consensus mechanism is the Ripple Protocol Consensus Algorithm (David Schwartz et al.: "The Ripple Protocol Consensus Algorithm", Ripple Labs Inc., 2014, https: / / ripple.com / files / ripple_consensus_whitepaper.pdf).
[0203] In some embodiments, the banknote is produced upon receipt of an order from the issuing central bank. In other embodiments, information about the predefined range of serial numbers is received. In other embodiments, information about the initial nominal value intended for the banknote is received.
[0204] Embodiments include a method for using a banknote. The banknote comprises a security element with a processor and a memory. The memory of the security element stores a banknote identification number, which identifies an anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote. A banknote-specific cryptographic key is stored in a protected memory area of the security element's memory.
[0205] The procedure for paying with banknotes includes: Receiving a payment request for a payment with the banknote, generating a payment-specific cryptogram to authorize the payment with the banknote, wherein the cryptogram is generated from the banknote's identification number and a payment-specific code as input values using the banknote-specific cryptographic key, sending a payment authorization comprising the payment-specific cryptogram.
[0206] In some embodiments, the banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. In other embodiments, the banknote includes, for example, a visual indication of the identification number. In other embodiments, the banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.
[0207] Design options can have the advantage that the banknote, as previously described, can be used not only for cash payments but also for cashless payments.
[0208] According to the embodiments, the banknote used for payment is a banknote according to one of the embodiments described above.
[0209] In some embodiments, the payment request specifies an amount to be paid. The payment procedure further includes comparing the amount to be paid with the current face value of the banknote stored in the security element's memory. The payment-specific cryptogram for authorizing the payment is generated only if the stored current face value of the banknote is greater than or equal to the amount to be paid. Some embodiments offer the advantage of ensuring that the banknote has a sufficient face value to execute the payment.
[0210] According to embodiments, the method further includes updating the stored current nominal value of the banknote: Receiving an update request to update the current face value of the banknote stored in the security element's memory, wherein the update request includes an updated face value of the banknote together with a cryptographically secured confirmation from the central bank for the updated face value; verifying the cryptographically secured confirmation using a cryptographic check key stored in the security element's memory; if the verification is successful, replacing the current face value of the banknote stored in the security element's memory with the received updated face value.
[0211] Design options can have the advantage of ensuring that the banknote has knowledge of its assigned current nominal value according to the banknote account.
[0212] According to embodiments, the method further includes outputting the stored current nominal value of the banknote: Receiving an output request to output the current face value of the banknote stored in the memory of the security element, in response to the request, sending the current face value of the banknote stored in the memory of the security element.
[0213] Some implementations offer the advantage that the current face value stored in the banknote can be directly queried, thus providing access to this information. The query can be performed, for example, using a terminal or, if available, via a user interface on the banknote. The response is then sent to the terminal or to a display device of the user interface for presentation.
[0214] According to embodiments, the serial number of the banknote is also stored in the memory of the security element, which is sent together with the stored current nominal value of the banknote and serves the recipient of the current nominal value as an identifier of the banknote for a confirmation request to the central bank to confirm the received current nominal value of the banknote.
[0215] Design options can have the advantage that the issued current nominal value of the banknote can be confirmed by the central bank.
[0216] Implementations include a method for payment processing using a terminal. Payment is made with a banknote, which comprises a communication interface for communication with the terminal and a security element with a processor and memory. The security element's memory stores a banknote identification number, which identifies an anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote. A banknote-specific cryptographic key is stored in a protected memory area of the security element's memory. The terminal comprises a processor, memory, and a communication interface for communication with the banknote.
[0217] The procedure for processing a payment transfer through the terminal includes: Sending a payment request to the banknote, receiving a payment-specific cryptogram to authorize payment with the banknote, wherein the cryptogram is generated from the banknote's identification number and a payment-specific code as input values using the banknote-specific cryptographic key, forwarding the payment-specific cryptogram with an indication of the amount to be paid to the issuing central bank for validation of the payment-specific cryptogram, a register check to see if the current face value of the banknote is greater than or equal to the amount to be paid, and executing the payment transfer if the payment transfer is successfully executed following successful validation and register check by the central bank, receiving confirmation of the successful payment transfer.
[0218] In some embodiments, the banknote includes, for example, a visual indication of a serial number that uniquely identifies the banknote. In other embodiments, the banknote includes, for example, a visual indication of the identification number. In other embodiments, the banknote includes, for example, a visual indication of an initial nominal value assigned to the banknote.
[0219] Design options can have the advantage that the banknote, as previously described, can be used not only for cash payments but also for cashless payments.
[0220] According to the embodiments, the banknote used for payment processing is a banknote according to one of the embodiments described above.
[0221] Design options can have the advantage that the central bank, in addition to its role as the issuing institution of the banknote, also provides services in the area of payment transactions or payment processing to the banknote and / or the terminal or a payment recipient using it, and thus acts as a classic bank or a commercial bank.
[0222] A central bank, as used here, is understood to be a national or supranational institution that has the monopoly right to issue coins and banknotes as legal tender. Furthermore, a central bank can perform monetary and currency policy functions. For example, a central bank holds the currency reserves of a currency area, regulates the money supply, influences money creation through lending by commercial banks, and / or refinances these commercial banks and the government. For example, the central bank issues banknotes and puts them into circulation.
[0223] The terminal could be, for example, a seller's terminal at a point of sale (POS), i.e., the location where a sale is completed. The terminal could also be a terminal connected to a user's computer system, used to process a banknote payment. This could involve, for example, processing a payment over a network, such as the internet, with a service provider, be it a seller or a payment service provider. Alternatively, the terminal could be a mobile, portable communication device, such as a smartphone, belonging to a user. The user could then use this mobile, portable communication device, for example, to process a payment over a network, such as the internet, with a service provider, be it a seller or a payment service provider.
[0224] In some embodiments, the payment-specific cryptogram also transmits the serial number and / or identification number of the banknote to the issuing central bank. These embodiments offer the advantage that the central bank can assign the cryptogram to a specific banknote or banknote account. The serial number and / or identification number of the banknote are, for example, sent to the issuing central bank in plain text.
[0225] According to some embodiments, the serial number and / or identification number of the banknote is received together with the payment-specific cryptogram.
[0226] In some embodiments, the payment-specific cryptogram is received along with the payment-specific code, which is then sent to the issuing central bank. These embodiments offer the advantage that the payment-specific code can be used to validate the cryptogram. For example, the payment-specific code is sent to the issuing central bank in plaintext.
[0227] In some embodiments, the issuing central bank has a verification key to check the validity of the payment-specific cryptogram. For example, the banknote-specific cryptographic key is a symmetric cryptographic key, and the verification key is the same symmetric cryptographic key. Alternatively, the banknote-specific cryptographic key may be a private cryptographic key, and the verification key may be a public cryptographic key of the same asymmetric key pair that is associated with the banknote's private cryptographic key.
[0228] According to some embodiments, the issuing central bank uses the banknote's identification number to determine the banknote's serial number, for example by means of a register query, such as of the second register.
[0229] In some implementations, the issuing central bank uses the identification number and / or the serial number to determine the current nominal value of the banknote. This determination may involve, for example, register queries, such as those of the first and / or second register.
[0230] In some embodiments, an identification number of a recipient account is sent to the issuing central bank to receive the payment. These embodiments can have the advantage that the central bank can execute the payment from the banknote or the banknote account associated with the banknote to the recipient account.
[0231] In some embodiments, the issuing central bank uses the recipient account's identification number to transfer the payment amount from the anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote to the recipient account, provided the payment-specific cryptogram has been successfully validated and the register has been successfully checked. For example, payments could thus be made from one banknote account to another.
[0232] According to embodiments, the confirmation of the payment transfer is cryptographically secured, and the method further includes verifying the confirmation using a cryptographic check key. According to embodiments, the cryptographic check key for verifying the confirmation of the payment transfer is, for example, a public cryptographic key of an asymmetric key pair assigned to the central bank.
[0233] In some embodiments, the confirmation of the payment transfer includes a statement of the updated face value of the banknote along with a cryptographically secured confirmation from the central bank for the updated face value. These embodiments can have the advantage that the confirmation of the payment transfer simultaneously provides confirmation of the updated face value, which can then be forwarded, for example, to the banknote to update the stored face value.
[0234] In some embodiments, the issuing central bank updates the face value of the banknote in a register. According to these embodiments, the updated face value is the previous face value of the banknote minus the amount paid. For example, the face value of a banknote can be viewed in a register, such as the first register.
[0235] According to embodiments, the method further comprises sending an update request to update the current face value of the banknote stored in the security element's memory. The update request includes the updated face value of the banknote together with the central bank's cryptographically secured confirmation of the updated face value. Embodiments can have the advantage that the banknote can thus be prompted to update its stored face value.
[0236] In some embodiments, the banknote replaces the current face value stored in the security element's memory with the received updated face value, provided that the verification of the cryptographically secured confirmation using a cryptographic check key stored in the security element's memory is successful. In some embodiments, the cryptographic check key is the banknote-specific cryptographic key, for example, a symmetric cryptographic key. In other embodiments, the cryptographic check key is an additional cryptographic check key stored alongside the banknote-specific cryptographic key, for example, a public cryptographic key of an asymmetric key pair assigned to the central bank.
[0237] In some embodiments, the cryptographically secured confirmation includes the encrypted updated face value. In other embodiments, the updated face value is encrypted together with the banknote's identification number or serial number. In other embodiments, the updated face value is encrypted together with a timestamp. In other embodiments, a hash function is first applied to the data to be encrypted, and the resulting hash value is then encrypted. These embodiments can have the advantage that the transmission of the updated face value can be carried out in a cryptographically secure manner and can be uniquely assigned to the banknote. Furthermore, the timestamp can ensure that it is indeed a current face value or a face value that is more recent than a stored face value.For example, the banknote stores the current face value along with a timestamp associated with that face value. For instance, when the face value is replaced with an updated face value during an update, the banknote also replaces the previously stored timestamp with an updated timestamp that corresponds to the updated face value. For example, before updating the stored face value, the banknote checks whether the timestamp of a face value being offered for update is indeed more recent than the stored timestamp of the previous face value. This ensures that the timestamp used for the update is actually more recent.
[0238] In some embodiments, the cryptographically secured confirmation is received together with the banknote's identification number, serial number, and / or timestamp. These embodiments may have the advantage that the cryptographically secured confirmation can be uniquely assigned to the banknote.
[0239] In some embodiments, the banknote comprises multiple security features. The process requires, as a prerequisite for sending the payment request, the successful detection and validation of one or more predefined security features of the banknote. These embodiments offer the advantage that the banknote's authenticity and validity can be verified based on its security features.
[0240] In one embodiment, a plurality of banknotes is received. For each banknote, a current face value is determined. From this plurality of banknotes, a set of banknotes is selected and retained whose sum of current face values results in an amount less than the amount due. Any remaining difference between the amount due and the sum of the amounts of the selected banknotes is less than the current face value of another banknote from the plurality of banknotes not included in the selected set. The payment request for the difference is sent to this other banknote.
[0241] Implementations can offer the advantage of enabling a combination of cash-based and cashless payment. For the retained set of banknotes, there is no need for payment authorization and / or payments using the banknote accounts of the corresponding banknotes. Instead, payment with these banknotes is made by handing them over, as is customary with cash payments. If the amount to be paid does not balance, i.e., if the sum of the face values of the banknotes in the retained set is less than the amount to be paid and no further banknote is available whose face value corresponds to the difference, the difference is paid cashlessly using another banknote whose face value is greater than the corresponding difference.Alternatively, the difference can be paid by retaining the remaining banknote and refunding the overpaid amount. This can be done, for example, through a transaction from the payee's banknote account to the banknote account of the unretained banknote, which remains the property of the payer. In some versions, all unretained banknotes are returned.
[0242] According to embodiments, the banknotes of the plurality of banknotes each comprise a plurality of security features. The method includes, for example, a validity check for each banknote. The validity check of the banknotes comprises, for example, the successful detection and validation of one or more predefined security features of the plurality of security features of the respective banknote. Embodiments can have the advantage that the authenticity and validity of all banknotes can be ensured, in particular the retained banknotes.
[0243] According to embodiments, a method for replacing a damaged banknote is provided. The banknote includes the serial number displayed multiple times across its surface. If the banknote is damaged, the replacement process by the issuing central bank includes: Checking the degree of damage to the banknote, provided that the degree of damage does not exceed a predefined maximum permissible degree of damage, recording the serial number and / or identification number of the banknote, initiating a block on the register entries assigned to the recorded serial number and / or identification number, determining a current nominal value of the banknote using the recorded serial number and / or identification number, paying out the current nominal value of the damaged banknote.
[0244] Some embodiments offer the advantage that, in the event of damage, the actual face value of the banknote can be replaced. This actual face value can differ significantly from the initial face value of the banknote and / or a minimum face value. According to some embodiments, to ensure that the degree of damage to the banknote does not exceed a predefined maximum permissible degree of damage, more than 50% of the banknote must be present and / or the banknote must include one or more valid security features necessary for replacement.
[0245] According to some embodiments, the replaced banknote is a banknote conforming to one of the previously described embodiments. According to some embodiments, the damaged banknote is retained.
[0246] In some embodiments, serial number acquisition includes reading the visual representation of the serial number using a sensor on the terminal. In other embodiments, serial number acquisition includes receiving the serial number transmitted via the banknote's communication interface using the terminal's communication interface.
[0247] According to embodiments, capturing the identification number includes receiving the serial number transmitted via the banknote's communication interface using the terminal's communication interface.
[0248] According to some embodiments, paying out the current face value of the damaged banknote includes providing one or more replacement banknotes whose current face values, in sum, correspond to the current face value of the damaged banknote. According to some embodiments, the one or more replacement banknotes are banknotes of one of the embodiments described above. According to other embodiments, paying out the current face value of the damaged banknote includes transferring an amount equal to the current face value from the bank account of the damaged banknote or a bank account of the central bank that issued the damaged banknote to a bank account specified by an owner of the damaged banknote.For example, the specified banknote account is assigned to another banknote belonging to the owner of the damaged banknotes, to the owner of the damaged banknotes personally, or to another institution chosen by the owner of the damaged banknotes.
[0249] In some embodiments, the damage includes damage to the security element such that the security element can no longer provide payment-specific cryptograms. For example, the processor, memory, and / or a communication interface of the security element may be damaged. Alternatively, the security element may be missing altogether.
[0250] In some embodiments, the majority of the visual serial number information is distributed across the banknote in such a way that the serial number, and thus the banknote account, can be determined as long as more than 50% of the banknote is present. In other embodiments, the majority of security features are distributed across the banknote in such a way that the necessary valid security features for replacement are present as long as more than 50% of the banknote is undamaged.
[0251] According to some embodiments, the replacement of the banknote by the issuing central bank further includes a block entry in a block register maintained by the issuing central bank. This block entry freezes the banknote account. In the event of a block entry for the banknote account by the central bank, it can be ensured, for example, that no money can be transferred from the frozen bank account to another account, such as a banknote account (i.e., that no payments can be sent), and / or that no money can be transferred from another account, such as a banknote account, to the frozen bank account (i.e., that no payments can be received).
[0252] For example, blocking the banknote account of a damaged banknote involves transferring any remaining balance from that account to an account held by the central bank, such as another banknote account held by the central bank. This can have the advantage that no balance remains in the blocked account when a damaged banknote is replaced.
[0253] These embodiments could have the advantage that, when replacing a banknote, the processor and / or security element of the damaged banknote are not retained, and payments—i.e., the issuance of cryptograms—cannot continue to be made with it after the (last) current face value of the damaged banknote has been paid out. Furthermore, they can prevent, for example, accidental payments being made to the banknote account of the damaged banknote after the (last) current face value has already been paid out and the damaged banknote has been retained.
[0254] For example, when a banknote account is used for a transaction, the central bank checks whether the corresponding banknote account is blocked, i.e., whether a block entry exists, as a prerequisite for executing the transaction. If the banknote account is not blocked, the transaction is executed. If the banknote account is blocked, the transaction is not executed.
[0255] For example, when a transaction is made to a banknote account, the central bank checks whether the corresponding banknote account is blocked, i.e., whether a block entry exists, as a prerequisite for executing the transaction. If the banknote account is not blocked, the transaction is executed. If the banknote account is blocked, the transaction is not executed.
[0256] Embodiments of the invention will now be explained in more detail with reference to the drawings. These show: Figure 1: Schematic block diagrams of exemplary banknotes; Figure 2: A schematic block diagram of an exemplary system with an exemplary banknote; Figure 3: A schematic flowchart of an exemplary procedure for issuing banknotes; Figure 4: A schematic flowchart of an exemplary procedure for payment processing with a terminal; Figure 5: A schematic flowchart of an exemplary procedure for confirming a current face value of a banknote; Figure 6: A schematic block diagram of an exemplary procedure for using banknotes; Figure 7: A schematic flowchart of exemplary procedures for using a banknote; Figure 8: A schematic flowchart of an exemplary procedure for updating a face value of a banknote; Figure 9: A schematic flowchart of an exemplary procedure for dispensing a face value of a banknote.Figure 10: A schematic flowchart of an exemplary procedure for issuing a banknote; Figure 11: A schematic flowchart of an exemplary procedure for payment processing with a terminal; Figure 12: A schematic flowchart of an exemplary procedure for payment processing with multiple banknotes; Figure 13: Schematic block diagrams of exemplary banknotes; Figure 14: A schematic block diagram of an exemplary system with an exemplary banknote; Figure 15: A schematic flowchart of an exemplary procedure for deriving a private cryptographic key; Figure 16: A schematic flowchart of an exemplary procedure for deriving a private cryptographic key; Figure 17: A schematic flowchart of an exemplary procedure for deriving a private cryptographic key.Figure 18 shows a schematic flowchart of an exemplary procedure for deriving a private cryptographic key; Figure 19 shows a schematic flowchart of an exemplary procedure for payment processing using a derived private cryptographic key.
[0257] Elements of the following embodiments that correspond to each other are marked with the same reference numerals.
[0258] Figure 1 , i.e. Figures 1A and 1B , show exemplary 100 banknotes. The in Figure 1AThe banknote shown comprises a number of security features 110, which verify the authenticity and validity of the banknote 100. These security features 110 are distributed across the banknote 100. For example, the security features 110 are distributed across the banknote 100 in such a way that, as long as more than 50% of the banknote is in an undamaged condition, the authenticity and validity of the banknote 100 can be verified. The banknote 100 also includes a visual indication of the banknote's serial number 106, which is printed on the banknote 100. For example, the banknote 100 includes multiple visual indications of the serial number 106, which are distributed across the banknote 100, such as in microprinting.For example, the serial number 106 is distributed across the banknote 100 in such a way that, as long as more than 50% of the banknote is undamaged, the serial number 106 of the banknote 100 can be determined. The serial number 106 serves, for example, to identify the banknote 100 and can be assigned to a current face value of the banknote, such as the balance of a banknote account and / or an identification number of the banknote account for the banknote 100. Thus, using the serial number 106 of the banknote 100, the current face value of the banknote 100 can be determined.
[0259] Furthermore, the banknote includes one or more visual indications of an initial face value 108 of the banknote 100. The initial face value 108 is, for example, a minimum face value of the banknote 100. For example, the banknote 100 includes one or more visual indications of a minimum face value different from the initial face value 108, in addition to the indication of the initial face value 108. For example, the banknote 100 includes one or more visual indications of the minimum face value instead of visual indications of an initial face value 108 that differs from the minimum face value. Additionally, the banknote includes a security element 102 with a processor and memory. An identification number of the banknote 100 is stored in the memory of the security element 102.The identification number identifies an anonymous banknote account managed by the central bank that issued the banknote 100 and individually assigned to the corresponding banknote 100. A banknote-specific cryptographic key, for example, in the form of a symmetric or private cryptographic key, is stored in a protected memory area. The banknote 100 uses this banknote-specific cryptographic key to generate payment-specific cryptograms for releasing or authorizing cashless payments with the banknote 100. Such cashless payments are transactions from the banknote 100's banknote account to a recipient's account, for example, another banknote account for a different banknote.The cryptograms are generated from the banknote's identification number and a payment-specific code as input values, using the banknote's unique cryptographic key. The payment-specific code includes information characterizing the individual payment, such as a time stamp, the amount to be paid, and / or the recipient's account details. Furthermore, the banknote uses its unique cryptographic key to derive a private cryptographic key for an anonymous account in a computer system. For example, the banknote uses a one-way function, such as a KDF function, for this purpose. Alternatively, the banknote derives an input value from its unique cryptographic key to calculate the private cryptographic key.Furthermore, the banknote 100 can be configured to calculate a public cryptographic key associated with the private cryptographic key. Alternatively, the associated public cryptographic key can also be calculated by a computer system receiving the private cryptographic key.
[0260] Furthermore, the banknote includes a communication interface 104 for communicating with a terminal, particularly for contactless communication. Via the communication interface 104, the banknote 100 receives, for example, payment requests and sends, for example, payment authorizations with payment-specific cryptograms. The banknote 100 could also include visual information such as its identification number.
[0261] Figure 1B shows an exemplary banknote 100, which is the exemplary banknote 100 made of Figure 1AThis corresponds to the banknote's value. Additionally, the banknote contains 100 in Figure 1B A user interface 112. The user interface 112 includes, for example, an input and / or output device for the banknote 100. For example, the user interface 112 includes a touchpad for entering data, such as transaction data, into the banknote 100 and / or a display for showing data, such as transaction data, which the banknote 100 is intended to process or has processed. For example, the user interface 112 includes a touch display with which data can be both entered by the user and displayed to the user.
[0262] Figure 2Figure 157 shows an exemplary system with an exemplary banknote 100. The banknote 100 comprises a security element 102 with a processor 124 and a memory 120. The processor 124 outputs program instructions 128. These program instructions 128 include, for example, cryptographic program instructions for generating payment-specific cryptograms. Furthermore, the cryptographic program instructions can be configured, for example, to generate cryptographic keys. The memory 120 stores an identification number 116 of a banknote account for the banknote 100 (banknote account number / BAN). The memory 120 also stores, for example, the serial number 106 of the banknote 100 and / or a current face value 109 of the banknote 100. In a protected storage area 122 of the memory 120, a banknote-specific cryptographic key 118 of the banknote is stored for generating payment-specific cryptograms.Furthermore, the banknote 100 includes, for example, a communication interface 104 for communication with external devices, such as a terminal 130. The communication interface 104 is configured, for example, for contactless near-field communication. Additionally, the banknote 100 includes visual information 107, such as the serial number 106 and / or identification number 116. Furthermore, the banknote 100 may also include, for example, a user interface with an input and / or output device for entering and / or displaying data, such as transaction data.
[0263] The banknote 100 communicates, for example, with a computer system, such as a mobile device 180 or a user computer system 190, using the communication interface 104. The banknote 100 is configured to provide the corresponding computer system 180, 190 with a private cryptographic key 250 of an anonymous account, derived from the banknote 100's banknote-specific cryptographic key 118. For this purpose, the banknote 100 derives, for example, a one-way function from the banknote-specific cryptographic key 250, such as a KDF function. Alternatively, the banknote 100 derives, for example, an input value for calculating the private cryptographic key 250 from the banknote-specific cryptographic key 118.Furthermore, the banknote 100 can be configured to calculate a public cryptographic key 252 associated with the private cryptographic key 250. Alternatively, the associated public cryptographic key 252 can also be calculated by the computer system 180, 190 receiving the private cryptographic key 250.
[0264] The banknote 100 communicates, for example, with a terminal 130 using the communication interface 104. The terminal 130 is, for example, a payment terminal of a point of sale (POS). The terminal 130 includes a processor 134 for executing program instructions 136 and a memory 132. Furthermore, the terminal 130 includes a communication interface 137 for communicating with the banknote 100. Additionally, the terminal 130 includes a communication interface 139 for communication via a network 160, such as the internet. The terminal 130 is, for example, configured for payment processing with the banknote 100.For this purpose, terminal 130 sends, for example, a payment request to banknote 100 and receives a payment authorization with a payment-specific cryptogram from banknote 100. Terminal 130 then transmits this authorization via network 160 to a central bank server 220 of a central bank system 156 for execution as a transaction from the banknote account assigned to banknote 100 to a recipient account of the payment recipient. Furthermore, the terminal may, for example, include sensor 139. Sensor 139 is configured, for example, to capture visual information 107 from banknote 100, such as the serial number 106. Sensor 139 may also be configured, for example, to capture security features of banknote 100 to verify its authenticity and validity. Memory 132 stores, for example, an identifier or identification number of an account, which terminal 130 uses as the recipient account for receiving payments.
[0265] For example, Terminal 130 communicates with the central bank server 220 via a remote server 170. Server 170 includes, for example, memory 172, a processor 174 for executing program instructions 176, and a communication interface 178 for communication over the network 160. For example, Server 170 provides Terminal 130 with the identifier of an account or banknote account used as a receiving account. For example, Server 170 forwards payment authorizations received by Terminal 130 to the central bank server 220. For example, Server 170 forwards payment confirmations received from the central bank server 220 to Terminal 130.
[0266] System 157 further comprises a central bank server 220 with a memory 222 and a processor 224 for executing program instructions 226. The central bank server 220 also includes, for example, a communication interface 228 for communication via the network 160. The central bank server 220 is configured, for example, to check authorization requests with payment-specific cryptograms for authorizing payments using banknote accounts of banknotes 100 and, in the case of successful checks, to execute the authorized payments. Once the payments have been executed, the central bank server 220 sends, for example, payment confirmations. The payment confirmations include, for example, information on the current nominal values of the banknotes resulting from the payments.Furthermore, the central bank server 220 is configured, for example, to create a banknote-specific account for each banknote 100 during its production and / or to block an existing banknote account, such as if a damaged banknote is withdrawn from circulation by the central bank. Additionally, the central bank server 220, or another computer system of the central bank system communicating with the central bank server, may include a sensor for checking the security features of damaged banknotes. If the check of the security features and the degree of damage to the banknote reveals that it is a valid banknote, the central bank replaces the damaged banknote.For this purpose, the central bank server 220, for example, determines the current face value of the damaged banknote using a corresponding query to the central bank's managed registers 148 and 150, pays out the current face value, and blocks the banknote account of the damaged banknote. For example, a block entry is made in one of the several registers 148 and 150.
[0267] The central banking system 156 also includes registers 148 and 150. Register 148, for example, contains mappings of the serial numbers of individual banknotes 100 to the respective identification numbers of the banknote account for the corresponding banknote. Furthermore, the register can assign a cryptographic check key to each banknote account identification number for the respective banknote account, enabling verification of cryptograms for the corresponding banknote 100. Register 150 is configured, for example, as a lookup table and contains mappings of current face values of banknotes 100 to the serial numbers of individual banknotes 100. For example, using register 150, a current face value of a banknote 100 can be queried with the serial number of the corresponding banknote 100 as a database access key.Furthermore, the central bank system 156 may include an accounting system for carrying out transactions using the banknote account of the banknotes 100 issued by the central bank.
[0268] Instead of terminal 130, a mobile portable device or communication device 180 or a user computer system 190 can also be used for payment processing, for example, for payment processing via the internet. The mobile communication device 180 or the user computer system 190 can, for example, serve as a local point of sale (POS). Payment processing can also be carried out using a remote server 170. Alternatively, payment processing can be carried out using a server 200 of a payment service provider or financial services provider, which acts as a PSP.
[0269] The mobile communication device 180, such as a smartphone, includes, for example, a memory 182 and a processor 184 for executing program instructions 186. Furthermore, the mobile communication device 180 includes, for example, a communication interface 187 for communicating with the banknote 100 and a communication interface 188 for communicating via the network 160. For example, the mobile communication device 180 includes a camera for capturing visual information 107 from the banknote 100, such as the serial number 106 of the banknote 100. The mobile communication device 180 is configured, for example, to forward a payment request, for example from the server 170 or the payment service server 200, to the banknote 100 and a payment authorization of the banknote 100 with a payment-specific cryptogram to the server 170 or the payment service server 200.For example, the mobile communication device 180 can be configured to determine the current face value of the banknote 100, either directly or via a server such as the server 170 or the payment service server 200, and to display it to a user using a user interface 181. The user interface 181 includes, for example, an input and an output device for communication between the user and the mobile communication device 180. The input device includes, for example, a keyboard. The output device includes, for example, a display. For example, the input and output devices are combined in the form of a touch display.
[0270] Furthermore, the mobile communication device 180 can include a private cryptographic key 250 of an anonymous account derived from the banknote-specific cryptographic key 118. The private cryptographic key 250 is stored, for example, in a protected memory area 183 of the memory 182. The memory 182 can also include, for example, a public cryptographic key 252 associated with the private cryptographic key 250. Additionally, an identification number 254 of the anonymous account (“account number” / AN) can be stored in the memory 182. For example, the mobile communication device 180 calculates the public cryptographic key 252 using the private cryptographic key 250 provided by the banknote.
[0271] The user computer system 190 includes, for example, a memory 192 and a processor 194 for executing program instructions 196. Furthermore, the user computer system 190 includes, for example, a communication interface 197 for communication with the banknote 100 and a communication interface 198 for communication via the network 160. For example, the user computer system 190 includes a sensor, such as a camera, for capturing visual information 107 from the banknote 100, such as the serial number 106 of the banknote 100. The user computer system 190 is configured, for example, to forward a payment request, for example from the server 170 or the payment service server 200, to the banknote 100 and a payment authorization of the banknote 100 with a payment-specific cryptogram to the server 170 or the payment service server 200.For example, the user computer system 190 can be configured to determine, directly or via a server such as server 170 or payment service server 200, the current face value of banknote 100 according to the banknote account assigned to banknote 100 and to display it to a user using a user interface 191. The user interface 191 includes, for example, an input and an output device for communication between the user and the mobile communication device 190. The input device includes, for example, a keyboard and / or mouse. The output device includes, for example, a display. For example, the input and output devices are combined in the form of a touch display.
[0272] Furthermore, the user computer system 190 can include a private cryptographic key 250 of an anonymous account derived from the banknote-specific cryptographic key 118. The private cryptographic key 250 is stored, for example, in a protected memory area 193 of memory 192. Memory 192 can also include, for example, a public cryptographic key 252 associated with the private cryptographic key 250. Additionally, memory 192 can store an identification number 254 of the anonymous account (“account number” / AN). For example, the user computer system 190 calculates the public cryptographic key 252 using the private cryptographic key 250 provided by the banknote.
[0273] The payment service provider's server 200 is configured, for example, to enable payment processing using the banknote 100 and a local device for communicating with the banknote 100, such as the terminal 130, mobile communication device 180, or user computer system 190. The payment service server 200 includes, for example, memory 202, a processor 204 for executing program instructions 206, and a communication interface 208 for communication over the network 160. For example, the payment service server 200 provides the local device with transaction data for a transaction to be executed, such as an identifier of a recipient account and / or details of the amount to be paid. For example, the payment service server 200 forwards payment authorizations received via the local device to the central bank server 220.For example, the payment service server 200 forwards payment confirmations received from the central bank server 220 to the local device.
[0274] System 157 also includes, for example, a manufacturing computer system 210, which is used in the production of banknote 100. Manufacturing computer system 210 includes, for example, a memory 212 and a processor 214 for executing program instructions 216. Furthermore, manufacturing computer system 210 includes, for example, a communication interface 221 for communicating with the banknote 100. For example, during the initialization of the banknote, manufacturing computer system 210 sends banknote-specific data received from the central bank server 220 to the banknote 100 for storage using communication interface 217. This data could include the identification number 116 or the cryptographic key 118. Furthermore, manufacturing computer system 210 includes, for example, a sensor 219 for checking the banknote 100. Using sensor 219, for example, quality control of the banknote 100 is carried out.If the banknote 100 passes quality control, a production confirmation is sent from the manufacturer's computer system 210 to the central bank using a communication interface 218 for communication with a central bank computer system, such as the central bank server 220. The production confirmation includes, for example, the serial number 106 and / or information for initializing the banknote 100 to the central bank system 156 and setting up a banknote account for the produced banknote 100.
[0275] Figure 3Figure 3 shows a schematic flowchart of an exemplary procedure for issuing banknotes 100. In step 300, the central bank 220 sends an order to a manufacturer 210, e.g., a printing works, to produce banknotes 100. The order specifies, for example, a range of serial numbers. This range of serial numbers specifies the serial numbers to be used for the banknotes 100 to be produced. The order also specifies, for example, initial face values for the banknotes 100 to be produced. For example, the order specifies a minimum face value and / or a variable additional face value component. In step 302, the manufacturer 210 produces the banknotes 100 according to the received order. The produced banknotes 100 each include, for example, a security feature with a processor.Furthermore, the produced banknotes 100 each include, for example, a visual indication of one of the serial numbers from the specified range of serial numbers, which was assigned to the respective banknote during the production process. In step 304, the manufacturer 210 reads the visual indication of the serial numbers of the produced banknotes 100. For example, the serial numbers of the banknotes 100 are also stored in the banknote memory. For example, the manufacturer 210 also reads the serial number from the banknote memory of each banknote 100. Furthermore, the produced banknotes 100 each include, for example, visual indications of an initial face value and / or a minimum face value. For example, the manufacturer 210 reads the visual indications of the initial face value and / or the minimum face value of the produced banknotes 100.For example, the banknote 100's memory stores additionally contain the initial face values, minimum face values, and / or variable additional face value components assigned to the respective banknote 100. For example, the manufacturer 210 additionally reads the initial face value, minimum face value, and / or variable additional face value component from the memory stores of the banknote 100. In step 306, a production confirmation is sent to the central bank 220, which identifies the produced banknote 100. For example, the production confirmation specifies the serial numbers of the produced banknote 100. For example, the production confirmation specifies the initial face values of the produced banknote 100. For example, the production confirmation specifies minimum face values and / or variable additional face value components of the initial face values.
[0276] In step 308, the central bank 220 stores the serial numbers of the produced banknotes in a first register or database 148. For example, the central bank also stores the assigned face value, minimum face value, and / or variable additional face value component of the initial face value for each produced banknote 100. In step 310, the first register 148, or the central banking system 156 managing the first register 148, generates an identification number for each of the produced banknotes 100 whose serial numbers are stored in the first register 148. This identification number identifies an anonymous banknote account managed by the central bank 220 and individually assigned to the corresponding banknote 100. The identification number is therefore a "banknote account number" (BAN).The serial number is used, for example, to identify the banknote, and the identification number is used, for example, to identify the banknote account for payment processing. For example, the serial number is used as a seed to generate the identification number for the corresponding banknote. Furthermore, a seed from the central bank 220 is used to generate the identification number. The central bank seed is, for example, a secret of the central bank 220, such as a random number, a symmetric cryptographic key, or a private cryptographic key. Furthermore, the first register 148, or the central banking system 156 managing the first register 148, generates a banknote-specific cryptographic key for each of the banknotes 100 produced.This banknote-specific cryptographic key is, for example, a banknote-specific symmetric cryptographic key or a private cryptographic key of a banknote-specific asymmetric key pair. The BAN and the banknote-specific key are forwarded internally from the first register 148 to a server of the central bank 220.
[0277] In step 312, a first cryptographically secured channel is established between a server of central bank 220 and a computer system of manufacturer 210. The banknote identification number (BAN) is sent from central bank 220 to manufacturer 210 via this first cryptographically secured channel. This first cryptographically secured channel is, for example, an end-to-end encrypted communication link between central bank 220 and manufacturer 210. The connection is encrypted, for example, with a first symmetric session key. In step 314, a second cryptographically secured channel is established between the server of central bank 220 and the computer system of manufacturer 210. The banknote-specific cryptographic key is sent from central bank 220 to manufacturer 210 via this second cryptographically secured channel.The second cryptographically secured channel is, for example, an end-to-end encrypted communication link between the central bank 220 and the manufacturer 210. The connection is encrypted, for example, with a second symmetric session key.
[0278] In step 316, the manufacturer 210 stores the BAN and the banknote-specific cryptographic key in a memory of the security element of the respective banknote. The banknote-specific cryptographic key is stored, for example, in a protected memory area of the security element's memory. Furthermore, in step 318, the first register 148 records the serial numbers of the produced banknotes in a second register or database 150. For example, the central bank also stores the assigned face value, minimum face value, and / or variable additional face value component of the initial face value for each produced banknote 100 in the second register 150. The serial number serves, for example, as a database access key for accessing the information on the face value of the corresponding banknote stored in the second register 150.The second register, for example, is a publicly accessible register that can be configured as lookup tables (LUTs) or conversion tables. This second register would allow anyone to look up the current face value of a banknote using its serial number, for example, via the internet.
[0279] Figure 4Figure 1 shows a schematic flowchart of an exemplary payment processing procedure using a terminal at a point of sale (POS) 164. In step 320, the user 162 provides a banknote 100 for a cashless payment. In step 322, the POS 164 creates a payment request for a specific amount and sends the payment request to the banknote 100. In step 324, the banknote 100, or rather its security feature, generates a payment-specific cryptogram to authorize the payment. The cryptogram is generated, for example, from the banknote's identification number and a payment-specific code as input values, using the banknote's unique cryptographic key. The payment-specific code includes, for example, a timestamp. Furthermore, the payment-specific code, or rather, the security feature of the banknote 100, can contain other information.The cryptogram takes as further input values the amount to be paid and an identification number of the payee's account to which the amount is to be paid. For example, to generate the cryptogram, a hash function or other one-way function is applied to the input values, and the result is encrypted with the banknote's unique cryptographic key. Alternatively, the input values could also be encrypted with the banknote's unique cryptographic key without applying a one-way function. The 100-mark banknote sends a payment authorization, comprising the payment-specific cryptogram, to POS 164. In addition to the cryptogram, the payment authorization includes, for example, the input values used to create the cryptogram, either in encrypted form or in plaintext (i.e., unencrypted form).In step 326, the PoS 164 sends an authorization request to the central bank system 156 to validate the payment authorization for banknote 100. In step 328, the central bank system 156 extracts the BAN from the payment authorization. If the payment authorization includes the BAN in encrypted form, the central bank system 156 decrypts the BAN. For this purpose, in the case of a symmetric banknote-specific cryptographic key, the central bank system 156 has, for example, a corresponding symmetric banknote-specific cryptographic key. In the case of a private cryptographic key of a banknote-specific asymmetric key pair, the central bank system 156 has, for example, a corresponding public cryptographic key of the banknote-specific asymmetric key pair.
[0280] Central banking system 156 sends the BAN to first register 148 to validate that the BAN is a valid BAN registered in first register 148 for an existing banknote account. Furthermore, the cryptogram is checked for validity, i.e., it is verified whether it was encrypted with the banknote-specific cryptographic key of the banknote 100 belonging to the BAN. For example, first register 148 contains, in addition to the BAN, a check key for verifying the banknote-specific cryptographic key. This check key is, for example, a symmetric or public cryptographic key for decrypting encryptions created with the banknote-specific cryptographic key.In step 330, the first register 148 confirms the BAN (Bank Account Number) if it is valid and provides the corresponding banknote 100 serial number associated with the BAN. This serial number is used to look up the current face value of the banknote in the second register 150. If the current face value of the banknote 100 stored in the second register 150, which represents the balance in the banknote 100's account, is sufficient for payment, the payment is made in step 332. For this, the central bank transfers the amount to be paid from the banknote 100's account to a recipient account, for example, one identified in the payment authorization. Furthermore, the current face value in the second register 150 is updated, i.e., reduced by the paid amount. This updated face value of the banknote is, for example, the updated account balance.The updated balance on the banknote account of banknote 100. In step 334, the central bank system 156 sends a payment confirmation to the point of sale (PoS) 164. The payment confirmation includes, for example, the updated face value of banknote 100. Furthermore, the payment confirmation is signed, for example, with a signature key of the central bank system 156. In step 336, the payment confirmation is forwarded by the PoS, for example, to the banknote 100. The banknote 100 verifies, for example, the signature of the central bank system 156 or the central bank 220 with a signature verification key. The signature verification key for verifying the signature of the central bank system 156 or the central bank 220 is, for example, stored in the banknote 100 during production or in the memory of the security element of the banknote 100.The signature key is, for example, a private cryptographic key of a central banking system asymmetric key pair, while the signature verification key is, for example, a public cryptographic key of the corresponding asymmetric key pair. If the signature verification is successful, the banknote replaces the face value stored in the security element's memory with, for example, the updated face value according to the central banking system payment confirmation.
[0281] Figure 5Figure 340 shows a schematic flowchart of an exemplary procedure for confirming the current face value 109 of a banknote 100. In step 340, the user 162 provides a banknote 100 to a mobile portable communication device 180, e.g., a smartphone, to determine the current face value of the corresponding banknote 100. For example, the user uses an app installed on the mobile communication device 180, in which they request a verification of the face value stored in the banknote. In step 342, the mobile communication device 180 then sends an output request to output the current face value stored in the memory of the security element of banknote 100, as well as, for example, the banknote's serial number as an identifier. In step 344, the banknote 100 responds by sending the stored face value NW(BN) and the banknote's serial number to the mobile communication device 180.The serial number can also be captured visually using an optical sensor of the mobile communication device 180, such as a camera. In step 346, the mobile communication device 180 further sends a request to the central banking system 156 for the current face value stored in the second register 150 for the serial number of the banknote 100. In step 348, the mobile communication device 180 receives in response the current face value NW(R2) stored in the second register 150 for the banknote 100. In step 350, the mobile communication device 180 compares the two face values NW(BN) and NW(R2). If these two values match, the mobile communication device 180 confirms the face value stored in the banknote 100 as current and displays it, for example, on a display device, such as a screen, for the user 162.If the two values do not match, the mobile communication device 180 forwards the current nominal value NW(R2) stored in the second register 150, for example, to the banknote 100 to update the nominal value stored there. To verify the authenticity of the nominal value NW(R2), it is signed by the central banking system 156, for example, with a signature key.
[0282] Figure 6Figure 1 shows a schematic block diagram illustrating exemplary procedures for using banknotes 100. Central Bank 220 issues the banknotes 100. During the initialization of the banknotes 100, Central Bank 220 generates an identification number for each banknote 100, which identifies an anonymous banknote account managed by the central bank and individually assigned to the corresponding banknote 100. Furthermore, the central bank generates, for example, a banknote-specific cryptographic key for the banknotes 100. The identification number and cryptographic key are provided to the banknote 100 by Central Bank 220 and stored in the banknote's security element. Alternatively, the banknote-specific cryptographic key can also be generated by the banknote 100 itself, for example, as the private cryptographic key of an asymmetric key pair belonging to the banknote 100.In this case, for example, the central bank 220 can be provided with a corresponding public cryptographic key of the asymmetric key pair as a verification key for checking the banknote's cryptograms. The banknote account identified by the banknote's identification number is credited with an initial face value of the banknote 100 as a balance. This is done, for example, by the central bank. The initial face values are specified, for example, by the central bank during the production of the banknotes. The crediting of the initial face values to the banknote accounts, or the initialization of the banknotes, occurs, for example, upon the central bank generating the corresponding identification number. The identification numbers are generated, for example, for each specific serial number of a produced banknote.The identification number, serial numbers, and / or banknote-specific verification keys for checking cryptograms of the corresponding banknotes are stored in a first register 148, managed by the central bank 220. A second register 150, also managed by the central bank 220, stores the current nominal values, i.e., the current balances of the banknote accounts. The assignment to the banknotes 100 is made, for example, using the serial numbers of the banknotes 100, which serve as database access keys for the second register 150.
[0283] Once the banknotes 100 are produced, they enter free circulation 165. They can be handed over as cash by a user 162 to a payee 161. Upon handover, not only ownership of the banknote 100 but also of the balance assigned to the banknote 100 in the banknote account, i.e., the current nominal value of the banknote, is transferred to the payee 161. Furthermore, the user 162 can use the banknote 100 for payment using a mobile portable communication device 180, such as a smartphone. For example, payments can be processed via the internet, where the mobile communication device 180 acts as a local terminal. For example, payments can be sent or initiated from the banknote account to other accounts.Furthermore, the mobile communication device 180 can be used, for example, to verify the banknote 100 and / or a current face value stored on the banknote. Finally, the banknote 100 can be used, for example, to make payments at a terminal 130, such as a point-of-sale (POS) terminal. To authorize a payment, the banknote 100 generates a payment-specific cryptogram using the banknote's unique cryptographic key. The terminal can communicate, for example, with a payment service provider 200 (PSP), which then processes the payment using the cryptogram. The payment service provider 200 forwards the cryptogram to the central bank 220 for payment processing, which verifies the cryptogram using the first register 148.If the cryptogram is valid and the face value of banknote 100 is sufficient for payment according to the second register 150, the central bank 220 records the payment and confirms it to the payment service provider 200. The payment confirmation is forwarded, for example, by the payment service provider 200 to the banknote 100 via terminal 130. The payment confirmation includes, for example, the current face value of the banknote 100 resulting from the payment. Using the current face value provided by the payment confirmation, the banknote 100 can update its previous face value stored within it. In this case, the account balance or credit balance of the banknote 100's banknote account is decisive for the actual face value of a banknote 100.
[0284] Figure 7Figure 1 shows a schematic flowchart of an exemplary procedure for using a banknote. The banknote includes a visual indication of a serial number that uniquely identifies the banknote and represents its initial nominal value. The banknote incorporates a security element with a processor and memory. The security element's memory stores a banknote identification number, which identifies an anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote. A banknote-specific cryptographic key is also stored in a protected memory area of the security element's memory.
[0285] Block 600 receives a payment request for a banknote payment. Block 602 generates a payment-specific cryptogram to authorize the banknote payment. The banknote's identification number and a payment-specific code serve as input values, from which the cryptogram is generated using the banknote's unique cryptographic key. Block 604 sends a payment authorization containing the payment-specific cryptogram.
[0286] Figure 8Figure 6 shows a schematic flowchart of an exemplary procedure for updating the face value of a banknote. In block 610, the banknote receives an update request to update its current face value, which is stored in a security element memory. The update request includes the updated face value along with a cryptographically secured confirmation from the central bank for the updated face value. In block 612, the banknote checks the update request. In block 614, as part of this check, the banknote determines whether the cryptographically secured confirmation is valid. For this purpose, the banknote uses a cryptographic check key stored in the security element memory. If a corresponding confirmation is missing or invalid, the procedure is terminated in block 616.If the corresponding confirmation is valid, the current face value of the banknote stored in the memory of the security element in block 618 is replaced with the received updated face value.
[0287] Figure 9 Figure 6 shows a schematic flowchart of an exemplary procedure for outputting the face value of a banknote. In block 620, the banknote receives an output request to output the current face value of the banknote stored in the security element's memory. In response to the request, the banknote sends the current face value of the banknote stored in the security element's memory in block 622.
[0288] Figure 10Figure 6 shows a schematic flowchart of an exemplary procedure for issuing a banknote. In block 630, the banknote is produced. The produced banknote includes a visual indication of a unique serial number from a predefined range of serial numbers, as well as an initial face value assigned to the banknote. Furthermore, the banknote includes a security element with a processor and memory containing program instructions. In block 632, an identification number for the banknote is received via a first cryptographically secured channel. This identification number identifies an anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote. In block 634, the received identification number is stored in the memory of the security element.In block 636, a banknote-specific cryptographic key is received via a second cryptographically secured channel independent of the first. In block 638, the received banknote-specific cryptographic key is stored in a protected memory area of the security element's memory. In block 640, the initial face value of the banknote is stored as the current face value in the security element's memory. In block 642, the banknote's serial number is stored in the security element's memory. In block 644, a public cryptographic key of an asymmetric key pair belonging to the issuing central bank is stored in the banknote's memory.
[0289] Figure 11Figure 1 shows a schematic flowchart of an exemplary payment processing procedure using a terminal. This payment is made with a banknote, which includes a visual indication of a unique serial number and an initial nominal value assigned to the banknote. Furthermore, the banknote includes a communication interface for communication with the terminal and a security element with a processor and memory. The security element's memory stores a banknote identification number. This identification number identifies an anonymous banknote account, which is managed by the issuing central bank and is individually assigned to the corresponding banknote. A banknote-specific cryptographic key is stored in a protected memory area of the security element's memory.The terminal includes a processor, a memory, and a communication interface for communicating with the banknote.
[0290] In block 650, the terminal sends a payment request to the banknote. In block 652, the terminal receives a payment-specific cryptogram to authorize the payment with the banknote. The cryptogram is generated from the banknote's identification number and a payment-specific code as input values, using the banknote's unique cryptographic key. In block 654, the terminal forwards the payment-specific cryptogram, along with the amount to be paid, to the issuing central bank for validation. The central bank also checks a register to ensure that the current face value of the banknote is greater than or equal to the amount to be paid. If all checks by the central bank are successful, the payment transfer is executed.If the payment transfer is successfully validated and checked by the central bank, terminal block 656 receives confirmation of the successful payment transfer.
[0291] Figure 12Figure 660 shows a schematic flowchart of an exemplary payment processing procedure with multiple banknotes. In block 660, multiple banknotes are received. In block 662, the current face value is determined for each banknote. In block 664, a set of banknotes is selected and retained from the multiple received banknotes. The sum of these current face values results in an amount less than the amount to be paid. In block 666, a payment request is sent to another banknote from the multiple received banknotes that is not included in the set of selected banknotes. The remaining difference between the amount to be paid and the sum of the amounts in the set of selected banknotes is less than the current face value of the other banknote.
[0292] Figure 13 , i.e. Figures 13A and 13B, show exemplary banknotes of 100. Figure 13A shows an exemplary banknote 100, which is the exemplary banknote 100 made of Figure 1A This corresponds to the banknote's value. Additionally, the banknote contains 100 in Figure 13AIn addition to the visual indication of the serial number 106, there is a visual indication that identifies the blockchain address of banknote 100. This additional indication is, for example, a public cryptographic key 105, from which the blockchain address of banknote 100 can be derived, and / or the blockchain address of banknote 100 itself. Figure 1D shows an exemplary banknote 100, which corresponds to the exemplary banknote 100 in Figure 1C. In the case of the banknote in Figure 1D, the banknote 100 includes multiple additional visual indications that identify a blockchain address of the banknote 100, such as the public cryptographic key 105. These additional visual indications are, for example, distributed across the banknote 100, such as in microprinting.For example, the additional visual information is distributed across the banknote 100 in such a way that as long as more than 50% of the banknote is in undamaged condition, the blockchain address of the banknote 100 can be identified.
[0293] Figure 14Figure 157 shows an exemplary system with an exemplary banknote 100. The banknote 100 includes a security element 102 with a processor 124 and a memory 120. The processor 124 executes program instructions 128. These program instructions 128 include, for example, cryptographic program instructions for generating an asymmetric key pair 105, 118 for the banknote 100 and for signing transaction releases with a private cryptographic key 118 of the asymmetric key pair. Furthermore, the cryptographic program instructions can, for example, be configured to derive a blockchain address of the banknote 110 from the public cryptographic key 105. The public cryptographic key 105 of the asymmetric key pair is stored in the memory 120. Furthermore, the serial number of banknote 100, for example, is stored in memory 120.The private cryptographic key 118 of the asymmetric key pair is stored in a protected memory area 122 of the memory 120. Furthermore, the banknote 100 includes, for example, a communication interface 104 for communication with external devices, such as a terminal 130. The communication interface 104 is configured, for example, for contactless communication. Additionally, the banknote 100 includes visual information 107, such as the serial number 106 and / or the public cryptographic key 105. Furthermore, the banknote 100 may also include, for example, a user interface with an input and / or output device for entering and / or displaying data, such as transaction data.
[0294] The banknote 100 communicates, for example, with a computer system, such as a mobile device 180 or a user computer system 190, using the communication interface 104. The banknote 100 is configured to provide the corresponding computer system 180, 190 with a private cryptographic key 250 of an anonymous account, derived from the banknote 100's banknote-specific cryptographic key 118. For this purpose, the banknote 100 derives, for example, a one-way function from the banknote-specific cryptographic key 250, such as a KDF function. Alternatively, the banknote 100 derives, for example, an input value for calculating the private cryptographic key 250 from the banknote-specific cryptographic key 118.Furthermore, the banknote 100 can be configured to calculate a public cryptographic key 252 associated with the private cryptographic key 250. Alternatively, the associated public cryptographic key 252 can also be calculated by the computer system 180, 190 receiving the private cryptographic key 250.
[0295] The banknote 100 communicates with a terminal 130, for example, using the communication interface 104. The terminal 130 is, for example, a payment terminal of a point of sale (POS). The terminal 130 includes a processor 134 for executing program instructions 136 and a memory 132. Furthermore, the terminal 130 includes a communication interface 137 for communicating with the banknote 100. Additionally, the terminal 130 includes a communication interface 139 for communication via a network 160, such as the internet. The terminal 130 is configured, for example, to process a payment with the banknote 100. For this purpose, the terminal 130 sends, for example, a payment request to the banknote 100 and receives a signed transaction release from the banknote 100, which the terminal 130 then sends via the network 160 to a blockchain server 140, 141 to record the transaction authorized by the signed transaction release in the blockchain 148.Blockchain servers 140 and 141, for example, belong to a blockchain network 154. Furthermore, the terminal can include sensor 139. Sensor 139 is configured, for example, to capture visual information 107 from banknote 100, such as the serial number 106 and / or the public cryptographic key 105. Sensor 139 can also be configured, for example, to capture security features of banknote 100 to verify its authenticity and validity. Memory 132, for example, stores a blockchain address which terminal 130 uses as a receiving address for receiving payments.
[0296] For example, terminal 130 communicates with blockchain servers 140 and 141 via a remote server 170. Server 170 includes, for example, memory 172, a processor 174 for executing program instructions 176, and a communication interface 178 for communication over the network 160. For example, server 170 provides terminal 130 with the blockchain address to be used as the receiver address. For example, server 170 forwards signed transaction approvals received by terminal 130 to blockchain servers 140 and 141. For example, server 170 forwards transaction confirmations and / or entry confirmations received from blockchain servers 140 and 141 to terminal 130.
[0297] System 157 further comprises one or more blockchain servers 140, 141. Blockchain servers 140, 141 are, for example, part of a blockchain network 154 or form blockchain nodes of a blockchain network 154. Blockchain servers 140, 141 and / or the blockchain network 154 are, for example, managed by a central bank that issues banknotes. If the central bank is a central bank to which several countries belong, blockchain network 154 comprises, for example, one or more blockchain servers 140, 141 per country. For example, blockchain servers 140, 141 and / or the blockchain network 154 are comprised of a central bank system 156. Blockchain server 140 comprises, for example, memory, a processor 142 for executing program instructions 144, and a communication interface 152 for communication via the network 160.Memory 146, for example, stores a copy of blockchain 148 and / or a register 150. Register 150 is a regularly updated register containing the current nominal value for each blockchain address in blockchain 148. These current nominal values are calculated from the balances of transactions stored in blockchain 148 for the corresponding blockchain addresses. Register 150 provides, for example, a "fast blockchain" in which the pre-calculated balance results for the blockchain addresses are displayed as the current nominal values for those addresses. Using such a register can have the advantage of allowing current nominal values to be determined more quickly, as they are already available and do not need to be calculated.Register 150, for example, can be managed by a virtual machine (VM) of the blockchain server 140.
[0298] Blockchain server 140 can be configured to register and / or block banknotes or blockchain addresses of banknotes in blockchain 148 upon request from the central bank. Blockchain server 140 can also be configured to provide information on the current nominal values of banknotes, based on transactions stored in blockchain 148, using the blockchain addresses of the corresponding banknotes. For example, blockchain server 140 uses register 150 to provide such information. The blockchain network 154 can, for example, include one or more additional blockchain servers 141. Each of these additional blockchain servers 141 includes, for example, a memory 147, a processor 143 for executing program instructions 145, and a communication interface 153 for communication across the network 160. Each memory 147, for example, stores a copy of blockchain 148.For example, the blockchain servers 141 are configured to register and / or block banknotes or blockchain addresses of banknotes in the blockchain 148 upon request from the central bank.
[0299] Instead of terminal 130, a mobile portable communication device 180 or a user computer system 190 can also be used for payment processing, for example, for payment processing via the internet. The mobile communication device 180 or the user computer system 190 can, for example, serve as a local point of sale (POS). Payment processing can also be carried out using a remote server 170 or a server 200 of a payment service provider or financial services provider.
[0300] The mobile communication device 180, such as a smartphone, includes, for example, a memory 182 and a processor 184 for executing program instructions 186. Furthermore, the mobile communication device 180 includes, for example, a communication interface 187 for communicating with the banknote 100 and a communication interface 188 for communicating via the network 160. For example, the mobile communication device 180 includes a camera for capturing visual information 107 from the banknote 100, such as the serial number 106 or the public cryptographic key 105 of the banknote 100. The mobile communication device 180 is configured, for example, to forward a payment request, for example from the server 170 or the payment service server 200, to the banknote 100 and a transaction release signed by the banknote 100 to the server 170 or the payment service server 200.For example, the mobile communication device 180 is further configured to determine the blockchain address of the banknote 100, for instance using the camera 189, and to add the blockchain address as the originating address of the payment to the payment request for the banknote 100. Furthermore, the mobile communication device 180 can be configured to determine the current face value of the banknote 100 according to the blockchain 148, either directly or via a server such as the server 170 or the payment service server 200, and to display it to a user using a user interface 181. The user interface 181 includes, for example, an input and an output device for communication between the user and the mobile communication device 180. The input device includes, for example, a keyboard. The output device includes, for example, a display. For example, the input and output devices are combined in the form of a touch display.
[0301] Furthermore, the mobile communication device 180 can include a private cryptographic key 250 of an anonymous account derived from the banknote-specific cryptographic key 118. The private cryptographic key 250 is stored, for example, in a protected memory area 183 of the memory 182. The memory 182 can also include, for example, a public cryptographic key 252 associated with the private cryptographic key 250. Additionally, an identification number 254 of the anonymous account (“account number” / AN) can be stored in the memory 182. For example, the mobile communication device 180 calculates the public cryptographic key 252 using the private cryptographic key 250 provided by the banknote.
[0302] The user computer system 190 includes, for example, a memory 192 and a processor 194 for executing program instructions 196. Furthermore, the user computer system 190 includes, for example, a communication interface 197 for communicating with the banknote 100 and a communication interface 198 for communicating via the network 160. For example, the user computer system 190 includes a sensor, such as a camera, for capturing visual information 107 from the banknote 100, such as the serial number 106 or the public cryptographic key 105 of the banknote 100. The user computer system 190 is configured, for example, to forward a payment request, for example from the server 170 or the payment service server 200, to the banknote 100 and a transaction release signed by the banknote to the server 170 or the payment service server 200.For example, the user computer system 190 is further configured to determine the blockchain address of banknote 100, for instance using sensor 199, and to add the blockchain address as the originating address of the payment to the payment request for banknote 100. Furthermore, the user computer system 190 can be configured to determine the current face value of banknote 100 according to blockchain 148, either directly or via a server such as server 170 or payment service server 200, and to display it to a user using a user interface 191. The user interface 191 includes, for example, an input and an output device for communication between the user and the mobile communication device 190. The input device includes, for example, a keyboard and / or mouse. The output device includes, for example, a display.For example, the input and output devices are combined in the form of a touch display.
[0303] Furthermore, the user computer system 190 can include a private cryptographic key 250 of an anonymous account derived from the banknote-specific cryptographic key 118. The private cryptographic key 250 is stored, for example, in a protected memory area 193 of memory 192. Memory 192 can also include, for example, a public cryptographic key 252 associated with the private cryptographic key 250. Additionally, memory 192 can store an identification number 254 of the anonymous account (“account number” / AN). For example, the user computer system 190 calculates the public cryptographic key 252 using the private cryptographic key 250 provided by the banknote.
[0304] The payment service provider's server 200 is configured, for example, to enable payment processing using the banknote 100 and a local device for communication with the banknote 100, such as the mobile communication device 180 or the user computer system 190. The payment service server 200 includes, for example, a memory 202, a processor 204 for executing program instructions 206, and a communication interface 208 for communication over the network 160. For example, the payment service server 200 provides the local device with transaction data for a transaction to be executed, such as a blockchain address to be used as the receiver address and / or information about the amount to be paid. For example, the payment service server 200 forwards signed transaction approvals received via the local device to the blockchain servers 140 and 141.For example, the payment service server 200 forwards transaction confirmations and / or registration confirmations received from the blockchain servers 140, 141 to the local device.
[0305] System 157 includes, for example, a manufacturing computer system 210, which is used in the production of banknote 100. The manufacturing computer system 210 includes, for example, a memory 212 and a processor 214 for executing program instructions 216. Furthermore, the manufacturing computer system 210 includes, for example, a communication interface 221 for communicating with the banknote 100. For example, the manufacturing computer system 210 reads the public cryptographic key 105 of the banknote 100 using the communication interface 217. For example, the manufacturing computer system 210 sends data to the banknote 100 for storage using the communication interface 217, such as the serial number 106 of the banknote 100. Furthermore, the manufacturing computer system 210 includes, for example, a sensor 219 for checking the banknote 100.Using sensor 219, for example, a quality control check of banknote 100 is performed. If banknote 100 passes the quality control check, a production confirmation is sent from the manufacturer's computer system 210 to the central bank using a communication interface 218 for communication with a central bank computer system, such as the central bank computer system 220. The production confirmation includes, for example, the serial number 106 and / or the public cryptographic key 105 of banknote 100 for initializing banknote 100 in the blockchain 148.
[0306] System 157 further comprises, for example, a central bank computer system 220 with a memory 222 and a processor 224 for executing program instructions 226. Furthermore, the central bank computer system 220 includes, for example, a communication interface 228 for communication with the manufacturer's computer system 210 and / or with the blockchain servers 140, 141, for example via the network 160. The central bank computer system 220 is configured, for example, to register and / or block banknotes or blockchain addresses of banknotes in the blockchain 148. In other words, the central bank computer system 220 is configured, for example, to send an initialization request and / or a blocking request to initialize or block the banknote 100 to one of the blockchain servers 140, 141.To generate the initialization request, the central bank computer system 220 uses, for example, data provided by the manufacturer's computer system in the form of the manufacturing confirmation. Furthermore, the central bank computer system 220 may include, for example, a sensor for checking the security features of a damaged banknote. If the check of the security features and the degree of damage to the banknote reveals that it is a valid banknote, the central bank replaces the damaged banknote. To do this, the central bank computer system 220 determines, for example, the current face value of the damaged banknote by sending a corresponding request to one of the blockchain servers 140 or 141, pays out the current face value, and sends a blocking request to block the blockchain address of the damaged banknote to one of the blockchain servers 140 or 141.
[0307] Figure 15This document demonstrates an exemplary procedure for deriving a first private cryptographic key for an anonymous account in a computer system using a banknote. The anonymous account of the computer system depends on an anonymous banknote account individually assigned to a banknote. The banknote comprises a security element with a processor and memory containing program instructions. The memory of the security element stores a banknote identification number, which identifies the anonymous banknote account managed by the issuing central bank and individually assigned to the corresponding banknote. A banknote-specific second cryptographic key is stored in a protected memory area of the security element.
[0308] In block 400, the banknote receives a derivation request from the computer system to derive the first private cryptographic key for the dependent anonymous account. In block 402, the banknote derives the first private cryptographic key for the dependent anonymous account using a one-way function and the banknote-specific second cryptographic key. In block 404, the banknote sends the derived first private cryptographic key to the computer system in response to the derivation request. The derived first private cryptographic key is used by the computer system to generate cryptograms to authorize payment from the dependent account. For example, in addition to the first private cryptographic key, the banknote computes a first public cryptographic key and sends the resulting first asymmetric key pair to the computer system.For example, the first public cryptographic key for the first private cryptographic key is calculated by the computer system.
[0309] Figure 16This demonstrates another exemplary procedure for deriving the first private cryptographic key of the anonymous account for the computer system using the banknote. In block 410, the banknote receives a derivation request from the computer system to derive the first private cryptographic key for the dependent anonymous account. In block 412, the banknote computes an input value for the one-way function from its banknote-specific second cryptographic key. This input is used to derive the first private cryptographic key for the dependent anonymous account. In block 414, the banknote sends the computed input value to the computer system in response to the derivation request. The computer system can then use the sent input value to derive the first private cryptographic key for the dependent anonymous account using the one-way function.Furthermore, the computer system can calculate a first public cryptographic key for the first private cryptographic key.
[0310] Figure 17 This shows an exemplary procedure for deriving the first private cryptographic key of the anonymous account. For example, the procedure corresponds to... Figure 17 the procedure Figure 15From the perspective of the computer system, in block 420, the computer system sends a derivation request to derive the first private cryptographic key for the dependent anonymous account on the banknote. In block 422, the computer program receives the first private cryptographic key for the dependent anonymous account in response to the derivation request. This first private cryptographic key is derived, for example, using a one-way function and the banknote's unique second cryptographic key. In block 424, the computer system stores the derived first private cryptographic key for further use. For example, the first private cryptographic key is stored in a protected memory area of the computer system. The derived first private cryptographic key is used by the computer system to generate cryptograms to authorize payment from the dependent account.For example, in block 422, the computer system receives a first public cryptographic key along with the first private cryptographic key. For example, the first public cryptographic key is calculated by the computer system for the first private cryptographic key.
[0311] Figure 18 This shows an exemplary procedure for deriving the first private cryptographic key of the anonymous account. For example, the procedure corresponds to... Figure 18 the procedure Figure 16From the perspective of the computer system: In block 430, the computer system sends a derivation request to the banknote to derive the first private cryptographic key for the dependent anonymous account. In block 432, in response to the derivation request, the computer system receives from the banknote an input value for the one-way function for deriving the first private cryptographic key. This input value is calculated from the banknote's unique second cryptographic key. In block 434, the computer system derives the first private cryptographic key for the dependent anonymous account using the one-way function and the received input value. The computer system can also calculate a first public cryptographic key for the first private cryptographic key. In block 436, the computer system stores the derived first private cryptographic key for later use.For example, the first private cryptographic key is stored in a protected memory area of the computer system. The derived first private cryptographic key is used by the computer system to generate cryptograms for authorizing payments from the dependent account.
[0312] Figure 19This demonstrates an exemplary procedure for paying an amount using the computer system with the derived private cryptographic key. In block 440, the computer system receives a payment request for the corresponding amount. In block 442, the computer system generates a payment-specific cryptogram to authorize the payment to the dependent account. The identification number of the dependent account and a payment-specific code serve as input values from which the cryptogram is generated using the derived private cryptographic key. In block 444, a payment authorization containing the payment-specific cryptogram is sent. Reference symbol list
[0313] 100 Banknote 102 Security element 104 Communication interface 105 Public cryptographic key 106 Serial number 107 Visual indication 108 Initial face value 109 Current face value 110 Security feature 112 User interface 116 Identification number 118 Cryptographic key 120 Memory 122 Protected memory area 124 Processor 128 Program instructions 130 Terminal 132 Memory 134 Processor 136 Program instructions 137 Communication interface 138 Communication interface 139 Sensor 148 Register 1 150 Register 2 156 Central bank system 157 System 160 Network 162 User 161 Payee 164 Point of Sale 165 Payment transaction 170 Server 172 Memory 174 Processor 176 Program instructions 178 Communication interface 180 Mobile portable communication device 181 User interface 182 Memory 183 Protected memory area 184 Processor 186 Program instructions 187 Communication interface 188 Communication interface 189 Camera 190 User computer system 191 User interface192 Memory 193 Protected memory area 194 Processor 196 Program instructions 197 Communication interface 198 Communication interface 199 Sensor 200 Payment service server 202 Memory 204 Processor 206 Program instructions 208 Communication interface 210 Manufacturer computer system 212 Memory 214 Processor 216 Program instructions 217 Communication interface 218 Communication interface 219 Sensor 220 Central computer system 222 Memory 224 Processor 226 Program instructions 228 Communication interface 229 Sensor 250 Private cryptographic key 252 Public cryptographic key 254 Identification number
Claims
1. A method for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on an anonymous banknote account individually assigned to a banknote (100), for a computer system (180, 190) using the banknote (100), wherein the banknote (100) comprises a security element (102) with a processor (124) and a memory (120) with program instructions (128), wherein an identification number (116) of the banknote (100) is stored in the memory (120) of the security element (102) and identifies the anonymous banknote account managed by a central bank (220) issuing the banknote (100) and individually assigned to the corresponding banknote (100), wherein a second cryptographic key (118) specific to the banknote is stored in a protected memory area (122) of the memory (120) of the security element (102), wherein the method comprises, by the banknote (100): • receiving a derivation request for deriving the first private cryptographic key (250) for the dependent anonymous account from the computer system (180, 190), • initiating derivation of the first private cryptographic key (250) for the dependent anonymous account using a one-way function and the banknote-specific second cryptographic key (118), wherein the derived first private cryptographic key (250) serves to generate cryptograms for releasing payment from the dependent account, wherein the banknote (100) derives the first private cryptographic key (250) for the dependent anonymous account using the banknote-specific second cryptographic key (118) and sends the derived first private cryptographic key (250) to the computer system (180, 190) in response to the derivation request.
2. The method according to claim 1, wherein the banknote (100) additionally derives a first public cryptographic key (252) associated with the derived first private cryptographic key (250) and sends the derived first private cryptographic key (250) to the computer system (180, 190) as part of a resulting first asymmetric key pair, or the computer system (180, 190) uses the derived first private cryptographic key (250) to calculate the associated first public cryptographic key (252).
3. A method for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on an anonymous banknote account individually assigned to a banknote (100), for a computer system (180, 190) using the banknote (100), wherein the banknote (100) comprises a security element (102) with a processor (124) and a memory (120) with program instructions (128), wherein an identification number (116) of the banknote (100) is stored in the memory (120) of the security element (102) and identifies the anonymous banknote account managed by a central bank (220) issuing the banknote (100) and individually assigned to the corresponding banknote (100), wherein a second cryptographic key (118) specific to the banknote is stored in a protected memory area (122) of the memory (120) of the security element (102), wherein the method comprises, by the banknote (100): • receiving a derivation request for deriving the first private cryptographic key (250) for the dependent anonymous account from the computer system (180, 190), • initiating derivation of the first private cryptographic key (250) for the dependent anonymous account using a one-way function and the banknote-specific second cryptographic key (118), wherein the derived first private cryptographic key (250) serves to generate cryptograms for releasing payment from the dependent account, wherein the banknote (100) calculates an input value for the one-way function for deriving the first private cryptographic key (250) for the dependent anonymous account from the banknote-specific second cryptographic key (118) and sends the resulting input value for deriving the first private cryptographic key (250) by the computer system (180, 190) in response to the derivation request to the computer system (180, 190).
4. The method according to claim 3, wherein the method further comprises deriving the first private cryptographic key (250) for the dependent anonymous account by the computer system (180, 190) using the one-way function and the received input value, wherein, for example, the computer system (180, 190) derives the first private cryptographic key (250) together with an associated first public cryptographic key (252) as a first asymmetric key pair.
5. The method according to any one of the preceding claims, wherein the banknote-specific second cryptographic key (118) is a second private cryptographic key of a second asymmetric key pair of the banknote (100) and / or wherein a maximum number of derivations of cryptographic keys for dependent anonymous bank accounts is specified for the banknote (100), wherein the banknote (100) comprises, for example, a counter, wherein the counter starts at zero and increases by one with each derivation until the counter reaches the maximum number of derivations, or wherein the counter starts at the maximum number and is decremented by one with each derivation until the counter reaches zero.
6. A method according to any one of the preceding claims, wherein the method further comprises: • generating a payment-specific first cryptogram for releasing an initial payment from the banknote account to the dependent account, wherein the first cryptogram is generated from the identification number (116) of the banknote (100) and a first payment-specific code as input values using the banknote-specific second cryptographic key (118), • sending a first payment release comprising the payment-specific first cryptogram to the computer system (180, 190).
7. The method according to claim 6, wherein the first cryptogram further comprises an indication specifying where, in the event of a reversal of the dependent account, a credit balance of the dependent account is to be transferred, wherein the indication comprises, for example, an identification number of a banknote account, an identification number of another dependent account, or a bank account number independent of banknotes.
8. The method according to any one of claims 6 to 7, wherein the initial payment from the banknote account to the dependent account comprises an amount to be paid of zero or wherein the initial payment from the banknote account to the dependent account comprises an amount to be paid greater than zero.
9. The method according to any one of the preceding claims, wherein the method further comprises revoking the dependent account, wherein revoking the dependent account comprises, for example, repeating the derivation of the derived first private cryptographic key (250) of the account to be revoked and using the derived first private cryptographic key (250) to revoke the account to be revoked, or wherein revoking the dependent account further comprises, with use of the banknote (100), for example: • generating a payment-specific fifth cryptogram for releasing a payment from the anonymous banknote account to the account to be revoked, wherein the payment from the banknote account to the account to be revoked comprises an amount to be paid of zero, • sending a fourth payment release comprising the payment-specific fifth cryptogram.
10. A banknote (100) comprising a security element (102) with a processor (124) and a memory (120) with program instructions (128), wherein an identification number (116) of the banknote (100) is stored in the memory (120) of the security element (102) and identifies an anonymous banknote account managed by a central bank (220) issuing the banknote (100) and individually assigned to the corresponding banknote (100), wherein a second cryptographic key (118) specific to the banknote is stored in a protected memory area (122) of the memory (120) of the security element (102), wherein the banknote (100) further comprises a communication interface (104), wherein the processor (124) is configured to execute the program instructions (128), to execute a method for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on the anonymous banknote account of the banknote (100), for a computer system (180, 190) with the banknote (100), wherein the method comprises: • receiving a derivation request for deriving the first private cryptographic key (250) for the dependent anonymous account from the computer system (180, 190) via the communication interface (104), • initiating derivation of a derived first cryptographic private key for the dependent anonymous account using a one-way function and the banknote-specific second cryptographic key (118), wherein the derived first cryptographic private key (250) is used to generate cryptograms for releasing payment from the dependent account, wherein the banknote (100) derives the first private cryptographic key (250) for the dependent anonymous account using the banknote-specific second cryptographic key (118) and sends the derived first private cryptographic key (250) to the computer system (180, 190) in response to the derivation request.
11. A banknote (100) comprising a security element (102) with a processor (124) and a memory (120) with program instructions (128), wherein an identification number (116) of the banknote (100) is stored in the memory (120) of the security element (102) and identifies an anonymous banknote account managed by a central bank (220) issuing the banknote (100) and individually assigned to the corresponding banknote (100), wherein a second cryptographic key (118) specific to the banknote is stored in a protected memory area (122) of the memory (120) of the security element (102), wherein the banknote (100) further comprises a communication interface (104), wherein the processor (124) is configured to execute the program instructions (128), to execute a method for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on the anonymous banknote account of the banknote (100), for a computer system (180, 190) with the banknote (100), wherein the method comprises: • receiving a derivation request for deriving the first private cryptographic key (250) for the dependent anonymous account from the computer system (180, 190) via the communication interface (104), • initiating derivation of a derived first cryptographic private key for the dependent anonymous account using a one-way function and the banknote-specific second cryptographic key (118), wherein the derived first cryptographic private key (250) is used to generate cryptograms for releasing payment from the dependent account, wherein the banknote (100) calculates an input value for the one-way function for deriving the first private cryptographic key (250) for the dependent anonymous account from the banknote-specific second cryptographic key (118) and sends the resulting input value for deriving the first private cryptographic key (250) by the computer system (180, 190) in response to the derivation request to the computer system (180, 190).
12. A system with a computer system (180, 190) comprising a processor (184, 194), a memory (182, 192) with program instructions (186, 196) and a communication interface (187, 197), wherein the processor (184, 194) is configured, when the program instructions (186, 196) are executed, to execute a method for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on an anonymous banknote account individually assigned to a banknote (100), for the computer system (180, 190) with the banknote (100), wherein the method comprises: • sending a derivation request for deriving the first private cryptographic key (250) for the dependent anonymous account to the banknote (100) via the communication interface (186, 196), • receiving a response to the derivation request, • providing the first private cryptographic key (250) derived for the dependent anonymous account on the computer system (180, 190) using a one-way function and the banknote-specific second cryptographic key (118) of the banknote (100), wherein the received response is used for the provision, wherein the computer system (180, 190) receives, from the banknote (100), the derived first private cryptographic key (250) in response to the derivation request, • storing the provided first private cryptographic key (250) in a protected memory area (183, 193) of the computer system (180, 190) for generating cryptograms for releasing payment from the dependent account, and the banknote (100) according to claim 10 for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on an anonymous banknote account individually assigned to a banknote (100), for the computer system (180, 190) using the banknote (100).
13. A computer system (180, 190) comprising a processor (184, 194), a memory (182, 192) with program instructions (186, 196) and a communication interface (187, 197), wherein the processor (184, 194) is configured, when the program instructions (186, 196) are executed, to execute a method for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on an anonymous banknote account individually assigned to a banknote (100), for the computer system (180, 190) with the banknote (100), wherein the method comprises: • sending a derivation request for deriving the first private cryptographic key (250) for the dependent anonymous account to the banknote (100) via the communication interface (186, 196), • receiving a response to the derivation request, • providing the first private cryptographic key (250) derived for the dependent anonymous account on the computer system (180, 190) using a one-way function and the banknote-specific second cryptographic key (118) of the banknote (100), wherein the received response is used for the provision, wherein the computer system (180, 190) receives, from the banknote (100), an input value, calculated from the banknote-specific second cryptographic key (118), for the one-way function for deriving the first private cryptographic key (250) and derives the first private cryptographic key (250) using the received input value and the one-way function, • storing the provided first private cryptographic key (250) in a protected memory area (183, 193) of the computer system (180, 190) for generating cryptograms for releasing payment from the dependent account.
14. The system according to claim 12 or computer system (180, 190) according to claim 13, wherein the processor (184, 194) is further configured, upon execution of the program instructions (186, 196), to perform a method for paying with the computer system (180, 190), wherein paying with the computer system (180, 190) comprises: • receiving a payment request for a payment using the computer system (180, 190), • generating a payment-specific second cryptogram for authorising the payment using the computer system (180, 190), wherein the second cryptogram is generated from the identification number (254) of the dependent account and a second payment-specific code as input values using the derived first cryptographic key (250) of the dependent anonymous account, • sending a second payment release comprising the payment-specific second cryptogram, wherein the computer system (180) is, for example, a mobile portable terminal device.
15. A system (157) comprising a computer system (180, 190) according to claim 13 and a banknote (100) according to claim 11 for deriving a first private cryptographic key (250) of an anonymous account, which is dependent on an anonymous banknote account individually assigned to a banknote (100), for the computer system (180, 190) using the banknote (100).