Method for verifying a first private key, terminal device, system, computer program and computer-readable storage medium

WO2026166676A1PCT designated stage Publication Date: 2026-08-13DEUTE BUNDESBANK +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-01-07
Publication Date
2026-08-13

Smart Images

  • Figure EP2026050187_13082026_PF_FP_ABST
    Figure EP2026050187_13082026_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for verifying a first private key generated by means of quantum key distribution, comprising the following steps: providing the first private key to an end user application (2) from a user application (4) of a first device (5) via a local connection (8); sending a first identification information item from the end user application (2) or the user application (4) to an intermediate entity (6), wherein the first identification information item is characteristic of the first private key; the end user application (2) or the user application (4) receiving a verification response from the intermediate entity (6), wherein the verification response is characteristic of a comparison of the first identification information item and a second identification information item, wherein the second identification information item is characteristic of the second private key, which is stored on a second device (7); and verifying the first private key by means of the end user application (2) or the user application (4) in accordance with the verification response. The invention also relates to a terminal device, a system, a computer program and a computer-readable storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] P2024, 1178 WO N 7. January 2026

[0002] 1

[0003] Description

[0004] METHOD FOR VERIFIING A FIRST PRIVATE KEY, END DEVICE, SYSTEM, COMPUTER PROGRAM AND COMPUTER-READABLE STORAGE MEDIUM

[0005] A procedure for verifying a first private key is specified. Furthermore, an end device, a system, a computer program, and a computer-readable storage medium are described.

[0006] Typically, copying and / or transferring a generated private key creates a security risk because this generated private key must leave a secure storage environment. For example, the generated private key being copied and / or transferred could be intercepted by third parties.

[0007] The task to be solved is to specify a method for verifying the integrity of a private key. Furthermore, an end device, a system, and a computer program capable of executing such a method should be specified. Additionally, a computer-readable storage medium containing such a computer program should be provided.

[0008] These tasks are solved by the method and subject matter of the independent patent claims. Advantageous embodiments, implementations, and further developments are the subject of the respective dependent patent claims.

[0009] First, the procedure for verifying a first private key, which together with a second private key, is described in P2024, 1178 WO N 7 January 2026.

[0010] The key is generated in a quantum-safe manner using quantum key distribution, as explained.

[0011] In particular, the first and second private keys each constitute a secret part of a key pair. For example, the first private key is designed to be used in asymmetric encryption methods. Additionally, the second private key can also be designed to be used in asymmetric encryption methods. The first private key can be used, in particular, to decrypt data and / or to generate a digital signature.

[0012] The first and second private keys are generated together, for example, by quantum key distribution and are, in particular, identical to each other. The first and second private keys are identical to each other, for example, if no interception, especially no eavesdropping attempt, occurs during their generation. Quantum key distribution (QKD) involves the quantum-safe generation and distribution of cryptographic keys, especially the first and second private keys, using photons.

[0013] "Quantum-safe" means that cryptographic methods are resistant, in particular, to attacks from quantum computers. The term "quantum-safe" is also referred to as "quantum-resistant" here and in the following. "Quantum-safe" in the context of quantum key distribution means that the generation and distribution of the first private key P2024, 1178 WO N 7 January 2026

[0014] 3

[0015] and the second private key itself cannot be intercepted by quantum computers, since in particular any attempted interception would be physically detectable.

[0016] For example, the first private key and the second private key are not the same in the case of an attempted interception.

[0017] According to at least one implementation of the method, the first private key is provided to an end-user application by a user application on a first device via a local connection. The end-user application is, for example, a software application running on an end device. The user application is, for example, another software application running on the first device.

[0018] In particular, the first private key is provided to the end-user application by the user application via the local connection. The end-user application and the user application are, for example, signal-wise connected via the local connection when the procedure is carried out, especially when the first private key is provided to the end-user application. For example, the end-user application and the user application are part of a local network when the procedure is carried out, especially when the first private key is provided to the end-user application. After the first private key has been provided, especially after the first private key has been received from the end-user application, the local connection can be closed. P2024, 1178 WO N 7 January 2026

[0019] For example, the local connection between the end-user application and the user application is a point-to-point connection. This local connection can be a wireless connection, such as near-field communication (NEC).

[0020] Alternatively or additionally, the local connection between the end-user application and the user application can be a wired connection, such as a USB connection (Universal Serial Bus). For example, an NFC protocol or a USB protocol, or in the case of other point-to-point connections, a DTLS protocol (Datagram Transport Layer Security), is used for communication over the local connection between the end-user application and the user application.

[0021] For example, the first private key is generated or provided by the first device, and in particular, the first private key of the first device is subsequently provided. Specifically, the first private key is transferred from the first device to the end-user application. That the first key is provided to the end-user application means that the end-user application receives the first private key from the first device.

[0022] According to at least one implementation of the method, an initial identification information is sent from the end-user application or the user application to an intermediate instance, wherein the initial identification information is characteristic of the first P2024, 1178 WO N 7 January 2026

[0023] The private key is . For example, the end-user application is configured to generate the initial identification information and send it to the intermediate instance. Alternatively or additionally, the user application is configured to generate the initial identification information and send it to the intermediate instance. It is possible that both the end-user application and the user application each send the initial identification information to the intermediate instance.

[0024] The first identification information is generated based on the first private key. For example, a first public key is generated based on the first private key.

[0025] The first identification information is then generated based on the first public key.

[0026] The end-user application is connected to the intermediate instance via a network, with the initial identification information being transmitted over the network. Alternatively or additionally, the user application is connected to the intermediate instance via a network, with the initial identification information being transmitted over the network.

[0027] For example, the network is part of a Wide Area Network (WAN), specifically, the network is part of the Internet. For example, a TLS / SSL protocol, short for Transport Layer Security and Secure Sockets Layer, is used for communication over the network, for example, between the end-user application and the intermediary instance (P2024, 1178 WO N 7 January 2026).

[0028] 6

[0029] and / or for communication over the network between the user application and the intermediate instance.

[0030] In particular, the local connection between the end-user application and the user application, and a network connection through the network between the end-user application and the intermediate instance, are different from each other. Specifically, the local connection and the network connection involve different protocols used for the respective communication.

[0031] According to at least one implementation of the method, a verification response is received by the end-user application or the user application by the intermediate instance, wherein the verification response is characteristic of a comparison of the first identification information and a second identification information, wherein the second identification information is characteristic of the second private key stored on a second device.

[0032] If only the end-user application sends the initial identification information to the intermediary, the end-user application receives the verification response from the intermediary. If only the user application sends the initial identification information to the intermediary, the user application receives the verification response from the intermediary. If both the end-user application and the user application each send the initial identification information to the intermediary, it is possible that both the end-user application and the user application send the initial identification information. P2024, 1178 WO N 7 January 2026

[0033] 7

[0034] Each verification response was received from the intermediate instance.

[0035] For example, the second private key is generated by the second device, or the second private key is provided to the second device. Specifically, the second private key is stored by the second device. The fact that the second private key is stored on the second device means that the second private key is permanently stored locally on an entity of the second device.

[0036] For example, the second device is configured to generate the second identification information and send it to the intermediate instance. The second identification information is generated, for example, based on the second private key. Similarly, a second public key is generated based on the second private key.

[0037] The second identification information is then generated depending on the second public key.

[0038] The second device is, for example, connected to the intermediate instance via the network, with the second identification information being sent in particular via the network, especially the WAN.

[0039] For example, the intermediate instance is designed to compare the first identification information with the second identification information and generate the verification response based on the comparison. The generated verification response is, for example, from P2024, 1178 WO N 7 January 2026.

[0040] 8

[0041] The verification response is sent from an intermediate instance to the end-user application and / or to the user application over the network. The verification response includes, for example, information on whether the first identification information is equal to the second identification information. Due to the dependency of each identification information on the respective private key, the verification response includes, for example, information on whether the first private key is equal to the second private key.

[0042] According to at least one implementation of the procedure, the first private key is verified by either the end-user application or the user application, depending on the verification response. If only the end-user application receives the verification response, the first private key is verified by the end-user application. If only the user application receives the verification response, the first private key is verified by the user application. If both the end-user application and the user application each receive the verification response, it is possible that both the end-user application and the user application each verify the first private key.

[0043] For example, if the verification response includes information that the first identification information is equal to the second identification information, the first private key is verified. If, for example, the verification response includes information that the first identification information is not equal to the second, see P2024, 1178 WO N 7 January 2026.

[0044] 9

[0045] The identification information is not verified if the first private key is not verified.

[0046] The method described here is, in particular, a computer-implemented method.

[0047] The method described here uses quantum key distribution to generate the same private key simultaneously in a way that is both eavesdropping-proof and quantum-safe – specifically at the first and second devices. The first private key is advantageously provided via the local connection of the end-user application. This eliminates the need to transmit a generated private key over an insecure channel for safekeeping.

[0048] In particular, the method described here ensures that sensitive information, including the first private key, is not distributed by mail or via the internet—advantageously including the secure storage of the second private key corresponding to the first. The method described here specifically verifies the integrity of the first private key. The first private key can subsequently be used advantageously for transactions, and the verification simultaneously ensures that the first private key transmitted to the end-user application is integer. At the same time, it is ensured that the first private key used is secured on the second device in the form of the same second private key. P2024, 1178 WO N 7 January 2026

[0049] 10

[0050] The use of such a method can advantageously lead to greater acceptance and future-proofing of purely digital currencies, as a quantum-safe infrastructure is provided.

[0051] According to at least one implementation of the procedure, a request message is sent from the end-user application to the user application. For example, after the local connection is established, the request message is sent from the end-user application to the user application. The request message is characteristic of information such as the end-user application needing the first private key.

[0052] For example, the request message can be actively sent by a user of the end-user application.

[0053] Alternatively, the request message can be characteristic of a successfully established local connection. Alternatively or additionally, the request message can be provided directly by the user application.

[0054] According to at least one implementation of the procedure, the first private key of the end-user application is provided depending on the request message.

[0055] For example, the local connection is terminated after the end-user application receives the private key.

[0056] For example, the first private key is generated by the first device after receiving the request message, and in particular the second private key is generated by the second device. That is to say, the first private key, and in particular the second private key, are generated by the second device. P2024, 1178 WO N 7 January 2026

[0057] 11

[0058] Keys are generated on request via the request message, instead of being generated in advance or stored in advance. The first generated private key is subsequently provided to the end-user application.

[0059] It is advantageous to generate the first and second private keys only when they are actually needed. This reduces the risk of the first and second private keys being stolen or compromised before they are used. Furthermore, this approach can conserve storage resources.

[0060] Alternatively, the first private key is provided from a first memory of the first device upon receipt of the request message, and, in particular, the second private key is provided from a second memory of the second device. For example, a plurality of first private keys and a plurality of second private keys, each corresponding to the plurality of first private keys, are quantum-safely generated in advance using quantum key distribution and stored in the first memory and the second memory. That is, the first private key, and in particular the second private key, are provided from the first memory, and in particular the second memory, upon request via the request message, rather than being generated directly upon request. The provided first private key is then made available to the end-user application.The second private key corresponding to the provided first private key is stored on the second device. P2024, 1178 WO N 7 January 2026.

[0061] 12

[0062] Advantageously, the first and second private keys are already stored on the first and second devices, allowing immediate access to them. Such pre-generated first and second private keys can be advantageously used for automated processes and / or for rapid deployment in a large system.

[0063] According to at least one embodiment of the method, the end-user application is executed on an end device. For example, the end device is assigned to a user, in particular exactly one user or several users. In particular, each end-user application is uniquely assigned to a single user. It is possible for an end device to comprise several end-user applications, with each individual end-user application being uniquely assigned exclusively to one of the several users.

[0064] For example, the first private key is permanently stored on the end device, in particular the end-user application, after deployment.

[0065] The end device is, for example, at least one of the following user devices: a mobile device, such as a mobile phone or tablet; a mobile storage device, such as a USB device; or a smart card. In particular, the end-user application is stored on the end device.

[0066] If the end device is, for example, the mobile device, the end-user application includes P2024, 1178 WO N 7 January 2026

[0067] 13

[0068] For example, a graphical user interface. The user can be shown the verification of the first private key graphically via the graphical user interface. For example, once the local connection is established, the user can send the request message via the graphical user interface depending on a user action.

[0069] If the end device is, for example, a mobile storage device or a smart card, it can be connected to a user's electronic device, such as a computer, card reader, or mobile terminal, after the initial private key has been provided, particularly via a connection that is characteristic of a further point-to-point connection. In this case, the end-user application includes, for example, instructions that cause the electronic device to execute the end-user application. The user can be graphically informed of the verification of the initial private key via a graphical user interface of the electronic device.

[0070] For example, once the further point-to-point connection is established, the user can send the request message via the graphical user interface of the electronic device, or the request message will be sent automatically once the further point-to-point connection is established.

[0071] According to at least one embodiment of the method, the user application is executed on the first device. The user application includes, for example, the graphical user interface. In the event that the end device P2024, 1178 WO N 7 January 2026

[0072] 14

[0073] For example, if the device is a mobile storage device or a smart card, the procedure can be started via a graphical user interface of the user application.

[0074] For example, once the local connection is established, the user can send the request message via the graphical user interface of the first device.

[0075] For example, the user is graphically informed of the verification of the first private key via the graphical user interface.

[0076] According to at least one embodiment of the method, photons of an entangled photon pair are provided to both the first and second devices. The photons are generated, for example, by an emitter and received by a first receiver device and a second receiver device. The first receiver device is associated with the first device; in particular, the first receiver device is part of the first device or connected to the first device. The second receiver device is associated with the second device; in particular, the second receiver device is part of the second device or connected to the second device. In this embodiment, the emitter is not associated with either the first or second device and is not part of either of them.

[0077] The receiver devices can each be part of a quantum key distribution box, each of which is assigned to one of the devices. The quantum key distribution boxes are each equipped with a P2024, 1178 WO N 7 January 2026

[0078] 15

[0079] Quantum key distribution end nodes are connected, each being part of the respective devices.

[0080] According to at least one embodiment of the method, photons, each with a predetermined state, are provided from the first device to the second device or from the second device to the first device. In this embodiment, the emitter is associated with either the first or the second device. The emitter can be part of the first device or connected to it when the photons are provided from the first device to the second device. Similarly, the emitter can be part of the second device or connected to it when the photons are provided from the second device to the first device.

[0081] The receiver and the emitter can each be part of the quantum key distribution box, each of which is assigned to one of the devices. The quantum key distribution boxes are each connected to the quantum key distribution end nodes, each of which is part of the respective device.

[0082] According to at least one embodiment of the method, photons, each with a predetermined state, are supplied by the first device and the second device to a relay. A first emitter is present in this

[0083] The first device has a design form, and a second emitter is assigned to the second device. The first emitter may be part of the first device or connected to the first device. The second emitter may be part of the second device or connected to the second device. P2024, 1178 WO N 7 January 2026

[0084] 16

[0085] The relay, in this embodiment, is not associated with, nor is part of, either the first or second device. In this embodiment, the relay includes a receiver for receiving the emitted photons.

[0086] The emitters can each be part of the quantum key distribution box, each of which is assigned to one of the devices. The quantum key distribution boxes are each connected to the quantum key distribution end nodes, each of which is part of the respective device.

[0087] According to at least one implementation of the method, the first private key is generated by the first device and the second private key by the second device, each depending on the number of photons. The first and second private keys thus generated are advantageously identical and quantum-safe.

[0088] According to at least one implementation of the method, the first private key is representative of a single first key generated by the quantum key distribution, and the second private key is representative of a single second key generated by the quantum key distribution. The generated first and second keys are, for example, raw keys that are processed into the first and second private keys by means of further processing steps. These processing steps include, for example, an error correction step and / or a hashing step. (P2024, 1178 WO N 7 January 2026)

[0089] 17

[0090] For example, the first private key is generated by quantum key distribution and provided to the first device, and in particular, the second private key is generated by quantum key distribution and provided to the second device.

[0091] According to at least one embodiment of the method, the first private key and the second private key are each representative of a combination of a first subkey and a second subkey, wherein the first subkey is provided by the quantum key distribution of the first device, and the second subkey is provided by the quantum key distribution of the second device. For example, at least one first subkey is provided to the first device, and in particular, at least one second subkey is provided to the second device. The first private key can be generated in terms of the first subkey and the second subkey, and in particular, the second private key can be generated in terms of the first subkey and the second subkey.For example, the first sub-key and the second sub-key are linked together by a mathematical operation, in particular by linking, to generate the first private key for the first device and the second private key for the second device.

[0092] The mathematical operation is characteristic of at least one of the following operations, for example: an XOR operation, a concatenation operation, a modulo operation, a hash operation.

[0093] Advantageously, the linking can ensure the security and integrity of the resulting private keys. P2024, 1178 WO N 7 January 2026

[0094] 18

[0095] This can be improved, especially if the sub-keys are provided via one or more relays, particularly a relay network.

[0096] According to at least one implementation of the method, the first private key of the end-user application is provided by the first device in a secure environment. For example, the local connection is restricted to the secure environment. In particular, the local connection in the secure environment is restricted to a predefined geographical area, such as a single secure room. The secure room is located, for example, in a bank.

[0097] Data traffic between the end-user application and the user application takes place exclusively within the secure environment. By restricting the local connection to the secure environment, the transmission of the initial private key advantageously occurs in a controlled environment, making man-in-the-middle attacks, for example, more difficult to execute. Using the local connection within the secure environment also advantageously provides physical and logical control over access to the initial device.

[0098] According to at least one implementation of the method, the second private key is stored in a hardware security module of the second device. Specifically, the entity of the second device on which the second private key is permanently stored is the hardware security module. P2024, 1178 WO N 7 January 2026

[0099] 19

[0100] If the second private key is generated with the first private key depending on the request, the second private key is stored on the hardware security module.

[0101] If the second private key is generated in advance with the first private key and is stored in the second memory, the second private key is stored in the hardware security module depending on the request.

[0102] According to at least one implementation of the procedure, a first digital wallet is generated based on the first private key. For example, to generate the first digital wallet, the first public key is generated based on the first private key.

[0103] The following steps generate an initial wallet address based on the first public key.

[0104] For example, the first digital wallet and the first private key are permanently stored on the end device.

[0105] The first digital wallet can be used by the end-user application user to manage, store and / or use cryptocurrencies and / or digital assets.

[0106] For example, the first digital wallet is created by the end-user application using the first private key. Alternatively or additionally, the first digital wallet can be created by the user application using the first private key. P2024, 1178 WO N 7 January 2026

[0107] 20

[0108] According to at least one implementation of the procedure, the first identification information is characteristic of at least one parameter of the first digital wallet. This at least one parameter of the first digital wallet is, for example, the first wallet address. The first wallet address is, for example, a first Ethereum wallet address.

[0109] According to at least one implementation of the procedure, a second digital wallet is generated based on the second private key. For example, to generate the second digital wallet, the second public key is generated based on the second private key.

[0110] A second wallet address is then generated based on the second public key. For example, the second digital wallet is generated using the second private key by an application on the second device.

[0111] It is advantageous that the second digital wallet can be securely stored on the second device.

[0112] According to at least one implementation of the procedure, the second piece of identification information is characteristic of at least one parameter of the second digital wallet. This at least one parameter of the second digital wallet is, for example, the second wallet address. The second wallet address is, for example, a second Ethereum wallet address.

[0113] According to at least one implementation of the procedure, the intermediate instance is part of a blockchain that receives the second identification information from the second device (P2024, 1178 WO N 7 January 2026).

[0114] 21

[0115] is provided. In particular, the first identification information is provided by the end-user application or the user application to the intermediate instance, and the second identification information is provided by the application of the second device to the intermediate instance.

[0116] For example, if the first private key is provided to the end-user application, the second identification information is generated by the second device and provided to the intermediate instance. Sending the first identification information to the intermediate instance can occur at a later time, which might be specified by the user.

[0117] By using blockchain technology, a central authority is advantageously unnecessary. In particular, a transaction that generates the verification response is advantageously secure, as this transaction is validated jointly by a large number of blockchain participants. This advantageously reduces the possibility of data manipulation.

[0118] According to at least one implementation form of the procedure, the intermediate instance performs the query automatically.

[0119] In particular, the comparison of the first identification information and the second identification information is carried out automatically, and subsequently the verification response is generated and sent.

[0120] The intermediate instance includes, for example, a self-executing element, to which the first P2024, 1178 WO N 7 . January 2026

[0121] 22

[0122] First identification information and second identification information are provided. The self-executing element is, for example, a smart contract.

[0123] By using the smart contract on the blockchain, verification can be advantageously automated and carried out efficiently.

[0124] According to at least one embodiment of the method, a further first private key is provided to a further end-user application by a further user application of a further first device via a further local connection. This provision is analogous to the provision of the first private key to the end-user application. The features are thus also disclosed for the provision of the further first private key to the further end-user application.

[0125] According to this implementation, the additional end-user application can be executed on the end device or on a further end device. According to this implementation, another user with the additional end-user application can obtain the additional first key from the further first device, in particular to generate another first digital wallet, which can be advantageously verified. In particular, the further device can be located in a different geographical location than the first device.

[0126] Alternatively or additionally, the further first private key can be provided to a further end-user application by the user application of the first device. P2024, 1178 WO N 7 January 2026

[0127] 23

[0128] In this case, another user with the other end-user application can obtain the first key.

[0129] The deployment can be scaled accordingly to a large number of additional users and / or additional initial devices.

[0130] If the additional first private key is provided to the additional end-user application by the additional user application of the additional first device via the additional local connection, the first private key and the additional first private key are, in particular, different from each other. The provided first key and second private key are, in particular, different from the provided additional first key and additional second key.

[0131] The first private key is distinct from the second first private key because the first private key is generated on request using the request message, while the second first private key is generated on request using a further request message. Since the corresponding keys are generated using quantum key distribution, they are inherently different from each other.

[0132] Alternatively, a multitude of further first private keys and a multitude of further second private keys are generated together in advance using quantum-safe quantum key distribution and stored in a further first memory of the further first device and the second memory of the second device. The multitude of first private keys in the first memory P2024, 1178 WO N 7 January 2026

[0133] 24

[0134] and the multitude of further first private keys in the further first storage are, in particular, all different from each other.

[0135] According to at least one implementation of the method, a further first identification piece of information is sent from the further end-user application or the further user application to the intermediate instance, wherein the further first identification piece of information is characteristic of the further first private key. Sending the further first identification piece of information is analogous to sending the first identification piece of information to the intermediate instance, so that the relevant characteristics are accordingly disclosed.

[0136] The sending can be scaled accordingly to a large number of additional users and / or additional initial devices.

[0137] According to at least one implementation of the method, a further verification response is received by the further end-user application or by the further user application from the intermediate instance, wherein the further verification response is characteristic of a comparison of the further first identification information and a further second identification information, wherein the further second identification information is characteristic of a further second private key stored on the second device.

[0138] Receiving the further verification response is analogous to receiving the verification response from the further end-user application or the further P2024, 1178 WO N 7 January 2026

[0139] 25

[0140] User application, so that the relevant features are disclosed accordingly.

[0141] The receiving capacity can be scaled accordingly to a large number of additional users and / or additional initial devices.

[0142] According to at least one implementation of the procedure, the additional first private key is verified by the additional end-user application or the additional user application depending on the additional verification response. The verification of the additional first private key is analogous to the verification of the first private key, so that the relevant characteristics are accordingly disclosed.

[0143] The verification process can be scaled accordingly to a large number of additional users and / or additional initial devices.

[0144] The method is advantageously scalable. This allows a large number of users to each be provided with an initial private key, which is also securely stored on the second device. Furthermore, each of these users can verify the provided initial private key.

[0145] Furthermore, an end device is specified. The end device is configured to carry out the method described herein. All features of the embodiment disclosed in connection with the method are therefore also disclosed in connection with the device and vice versa. P2024, 1178 WO N 7 January 2026

[0146] 26

[0147] Furthermore, a system is specified. The system includes, in particular, the end device and is thus configured to carry out the method described herein. All features of the embodiment disclosed in connection with the method or the end device are therefore also disclosed in connection with the system, and vice versa.

[0148] According to at least one embodiment, the system comprises a first device. The first device is, for example, a user terminal.

[0149] According to at least one embodiment, the system comprises a second device connected to the first device. The second device is, for example, part of a central data center.

[0150] If the system comprises the first device and the further first device, in particular a plurality of further first devices, the first device and the further first device, in particular a plurality of further first devices, are connected to the central data center.

[0151] According to at least one implementation of the system, the end device is temporarily connected to the first device when the first private key is provided.

[0152] According to at least one embodiment of the system, the first and second devices are connected via a quantum link and a network link. The quantum link includes, for example, a satellite link and / or a fiber optic link through which the photons are transmitted. P2024, 1178 WO N 7 January 2026

[0153] 27

[0154] can be transmitted. The network link is part of the network, especially the WAN.

[0155] The listed implementation forms of the method, the end device, and the system described here can be combined with each other, even if the explicit combination is not explicitly described.

[0156] Furthermore, a computer program is specified, comprising commands which, when executed by a computer, cause it to perform the procedure described herein.

[0157] Furthermore, a computer-readable storage medium is specified on which the computer program described here is stored.

[0158] The following section provides a more detailed explanation of the method, end device, and system described here for verifying a first private key, which is generated quantum-safely together with a second private key using quantum key distribution, with reference to exemplary embodiments and the associated figures.

[0159] They show:

[0160] Figure 1 shows a flow diagram of the process according to an exemplary embodiment, and

[0161] Figure 2 is a schematic representation of the system for the method according to an embodiment .P2024, 1178 WO N 7 . January 2026

[0162] Identical, similar, or similarly effective elements in the figures are marked with the same reference symbols. The figures and the relative sizes of the elements depicted within them are not to be considered to scale. Rather, individual elements may be exaggerated for clarity and / or better understanding.

[0163] In the flow diagram of the method according to the embodiment of Figure 1, in step S1 a first private key is provided to an end-user application 2 by a user application 4 of a first device 5 via a local connection 8. End-user application 2 is executed, for example, on an end device 3, wherein the end device 3 and the first device 5 are described in more detail in conjunction with Figure 2.

[0164] In step S2, an initial identification information is sent from the end-user application 2 or the user application 4 to an intermediate instance, where the initial identification information is characteristic of the first private key.

[0165] In step S3, following step S2, a verification response is received from the end-user application 2 or the user application 4, wherein the verification response is sent by the intermediate instance, wherein the verification response is characteristic of a comparison of the first identification information and a second identification information, wherein the second identification information is characteristic of the second private key, which is stored on a second device 7. P2024, 1178 WO N 7 January 2026

[0166] 29

[0167] Subsequently, in step S4, the first private key is verified by the end-user application 2 or the user application 4, depending on the verification response.

[0168] In system 1 according to the embodiment shown in Figure 2, the process steps SI, S2, S3, and S4 are characterized as shown in Figure 1. The end-user application 2 of the end device 3 can comprise several application layers, with two application layers shown in Figure 2. The end-user application 2 is configured to send a request message from the end-user application 2 to the user application 4 in a sub-step S1, which is included in step S1. The elements connected by sub-step S1 in Figure 2 can be a sending unit of the end-user application 2 and a receiving unit of the user application 4. The request message is sent, for example, when the user of the end-user application 2 requests the creation of a first digital wallet, particularly via a graphical user interface. The request message is then sent, in particular, when the local connection 8 is established.

[0169] The first private key of the end-user application 2 is provided as a function of the request message. A first quantum key distribution end node 11 of the first device 5, which is connected, for example, to a first quantum key distribution box 13, is specifically configured to generate the first private key. P2024, 1178 WO N 7 January 2026

[0170] 30

[0171] In substep S2.1, which is encompassed by step S2, parameters of a first digital wallet can subsequently be generated based on the first private key. These parameters can then be sent to the end-user application 2 via the local connection 8. In substep S2.2, which is encompassed by step S2, the end-user application 2 can generate the first digital wallet based on the parameter, and thus also based on the first private key. At least one parameter of the first wallet is characteristic of the first identification information, which is sent to the intermediate instance 6. Furthermore, in substep S1.2, which is encompassed by step S1, the first private key is sent to the end-user application 2 via the local connection 8. Specifically, the first private key is permanently stored by the end-user application 2 on the end device 3.

[0172] The first device 5 and the second device 7 are connected to each other via a quantum link 9 and a network link 10. The second private key is generated on the second device 7, in particular using quantum key distribution, in a quantum-safe manner when the first private key is generated on the first device 5. A second quantum key distribution end node 12 of the second device 7, which is connected, for example, to a second quantum key distribution box 14, is configured specifically for generating the second private key. In a further step S5, parameters of a second digital wallet can subsequently be generated depending on the second private key. The parameters of the second digital wallet, in particular the second private key, are defined as follows: P2024, 1178 WO N 7. January 2026

[0173] 31

[0174] Keys are stored on a hardware security module 15 of the second device 7. At least one parameter of the second wallet is characteristic of the second identification information, which is sent to the intermediate instance 6 in the subsequent step S6.

[0175] This advantageously utilizes quantum key distribution to generate the private key – that is, the first private key, which is equal to the second private key if they are generated as integers. The first and second private keys are generated, for example, by entanglement of photons at multiple locations, namely at the location of the first device 5 and at the location of the second device 7, and in particular, not transmitted via a WÄN (Wireless Interconnection Network).

[0176] In the scenario involving digital currencies, the user initiates the generation of the first digital wallet at the first device 5, which corresponds to a user terminal, by requesting the first private key. Upon initiation of the process, identical private keys—the first and second private keys—are generated at both the first device 5 and the second device 7. The second device 7 represents a storage location, specifically part of a data center.

[0177] After successful generation, the user can transfer and store the first private key on the terminal device 3, for example, on a mobile phone or a hardware wallet, using NEC. Additionally, the second private key is stored securely in the hardware security module 15 of the second device 7. P2024, 1178 WO N 7 . January 2026

[0178] 32

[0179] A public key can be derived from the first and second private keys, along with the first and second identification information. The second identification information can be referenced on the intermediate instance 6 in a smart contract. This allows the user to conveniently verify that the first private key has been correctly generated and stored.

[0180] The first device 5 and the second device 7 are connected to each other, in particular by a quantum link 9, for example implemented via fiber optic cable or satellite, to implement the quantum key distribution system for generating the first and second keys. Additionally, the first device 5 and the second device 7 are connected via the network, for example the WAN, to transmit control information. No sensitive information is shared over the network; that is, this channel can also be implemented via the public internet. Furthermore, communication between the end device 3 and the intermediate instance 6, and communication between the second device 7 and the intermediate instance 6, can also take place via the network, for example the WAN.

[0181] The invention is not limited by the description based on the forms of implementation and exemplary embodiments.

[0182] Rather, the invention encompasses every new feature as well as every combination of features, which in particular includes every combination of features in the claims, even if that feature or combination itself is not explicitly specified in the claims, embodiments, or exemplary embodiments. P2024, 1178 WO N 7 January 2026

[0183] 33

[0184] Reference symbol list

[0185] 1 system

[0186] 2 End-user application

[0187] 3 End device

[0188] 4 User application

[0189] 5 first device

[0190] 6 Intermediate instance

[0191] 7 second device

[0192] 8 local connection

[0193] 9 Quantum Link

[0194] 10 network link

[0195] 11 First quantum key distribution end node 12 Second quantum key distribution end node 13 First quantum key distribution box

[0196] 14 second quantum key distribution box

[0197] 15 Hardware security module

[0198] S1. . S6 Procedural steps

Claims

1. P2024, 1178 WO N 7 . January 2026 - 34 - Patent claims 1. A method for verifying a first private key, which is generated quantum-safely together with a second private key using quantum key distribution, comprising - Providing the first private key to an end-user application (2) from a user application (4) of a first device (5) via a local connection (8), - Sending a first identification information from the end-user application (2) or the user application (4) to an intermediate instance (6), wherein the first identification information is characteristic of the first private key, - Receiving a verification response from the end-user application (2) or the user application (4) from the intermediate instance (6), wherein the verification response is characteristic of a comparison of the first identification information and a second identification information, wherein the second identification information is characteristic of the second private key stored on a second device (7), and - Verifying the first private key from the end-user application (2) or the user application (4) depending on the verification response.

2. The method according to claim 1, further comprising - Sending a request message from the end-user application (2) to the user application (4), wherein - the first private key of the end-user application (2 ) is provided depending on the request message. P2024, 1178 WO N 7 January 2026 3. Method according to claim 1 or 2, wherein - the end-user application (2) is executed on an end device (3), and - the user application (4 ) is executed on the first device (5).

4. Method according to any one of claims 1 to 3, wherein - photons of an entangled photon pair are provided to the first device (5) and the second device (7) respectively, - Photons with each a predetermined state are provided from the first device (5) to the second device (7) or from the second device (7) to the first device (5), or - Photons with a predefined state are provided from the first device (5) and the second device (7) to a relay, - wherein the first private key is generated by the first device (5) and the second private key by the second device (7) each depending on the photons.

5. Method according to any one of claims 1 to 4, wherein - the first private key is representative of a single first key generated by the quantum key distribution, and the second private key is representative of a single second key generated by the quantum key distribution, or - the first private key and the second private key are each representative of a combination of a first subkey and a second subkey, where the first subkey is represented by the P2024, 1178 WO N 7 January 2026 The quantum key distribution of the first device is provided, and the second sub-key is provided by the quantum key distribution of the second device.

6. Method according to any one of claims 1 to 5, wherein - the first private key of the end-user application (2) is provided in a secure environment by the first device (5), and / or - the second private key is stored in a hardware security module ( 15) of the second device (7 ).

7. Method according to any one of claims 1 to 6, wherein - a first digital wallet is generated depending on the first private key, and - the first identification information is characteristic of at least one parameter of the first digital wallet.

8. Method according to any one of claims 1 to 7, wherein - a second digital wallet is generated depending on the second private key, and - the second identification information is characteristic of at least one parameter of the second digital wallet.

9. Method according to any one of claims 1 to 8, wherein - the intermediate instance ( 6) is part of a blockchain, to which the second identification information is provided by the second device (7 ), and - the intermediate instance ( 6) automatically performs the query .

10. Method according to any one of claims 1 to 9, further comprising P2024, 1178 WO N 7 January 2026 - Providing another first private key to another end-user application (2) from another user application (4) of another first device (5) via another local connection (8) , - Sending another first identification information from the further end-user application (2) or the further user application (4) to the intermediate instance (6), wherein the further first identification information is characteristic of the further first private key, - Receiving a further verification response from the further end-user application (2) or the further user application (4) from the intermediate instance (6), wherein the further verification response is characteristic of a comparison of the further first identification information and a further second identification information, wherein the further second identification information is characteristic of a further second private key stored on the second device (7), and - Verifying the further first private key from the further end-user application (2) or the further user application (4) depending on the further verification response.

11. End device (3) which is configured to carry out the method according to any one of claims 1 to 10.

12. System ( 1 ) , comprising - a first device (5) , - a second device (7) connected to the first device (5), and - an end device (3) according to claim 9, wherein P2024, 1178 WO N 7 January 2026 - the end device (3) is temporarily connected to the first device (5) when the first private key is provided.

13. System ( 1 ) according to claim 12, wherein - the first device (5) and the second device (7) are connected to each other via a quantum link (9) and a network link (10).

14. Computer program comprising instructions which, when executed by a computer, cause the computer to execute the method according to any one of claims 1 to 10.

15. Computer-readable storage medium on which the computer program according to claim 14 is stored.