Institutional Hardware Wallet Card Issuance (White Label)

Issuer-Controlled Co-Signing for Institutional Card Wallets — European Application (Pending)

The Problem: Institutions Need Control Over Card Wallets Without Holding the Keys

Banks, fintechs, crypto exchanges and asset managers that issue hardware wallets to their clients face a dilemma. A classic hardware wallet signs whatever its holder presents to it — the issuing institution has no way to enforce compliance rules, spending limits or a freeze on a lost card, short of taking custody of the private keys itself. Custodial models solve the control problem but reintroduce the single point of failure that hardware wallets were meant to remove, and they turn the institution into a target.

The Innovation: Two Independent Gates Before the Secure Element Signs

European patent application EP 4 258 596 A1 (filed 8 April 2022, under examination) covers the issuer-controlled co-signing protocol that has already been granted in the United States as US 12,719,697 B2. A secure-element card signs a transaction only after two independent authorisations have succeeded: the cardholder’s own authentication to the card, and a signing element issued by the institution’s remote system. The user device — typically a phone app — first authenticates to the card; the card answers with a remote authentication element. The app forwards that element together with the transaction details to the issuer’s server, which checks the transaction against the institution’s rules and returns a signing element. Only when the app presents this signing element to the card together with a second authentication, and the card verifies both, does the card sign the transaction hash with its private signature key. The private key never leaves the secure element, and the issuer never sees or holds it.

How the Protocol Works in Practice

The remote authentication element can be the transaction hash signed with a card-specific private remote-access key, so the issuer’s server can verify that the request really comes from a card it issued. The signing element is the same hash signed with the issuer’s private key, which the card verifies with the issuer’s public key stored inside the secure element. Several transactions can be approved in one round trip by concatenating their hashes into a single meta data element that is signed once. The signed transaction is then broadcast to the blockchain by the user device — the card itself needs no network connection.

What This Enables: Card-Wallet-as-a-Service With Built-In Policy Control

This is the mechanism behind Cryptnox’s Card-Wallet-as-a-Service (C-WAAS) platform. An institution can issue white-label crypto cards to thousands of clients and apply its own rules — whitelisted blockchains and addresses, spending caps, travel-rule and sanctions screening, or an immediate freeze of a lost or stolen card — because every transaction must pass its compliance check before the card will sign. At the same time, the institution never holds the client’s private key: it can approve, but it cannot spend. The client keeps true self-custody inside a CC EAL6+ secure element; the institution keeps the oversight regulators expect.

Status of the European Application

The application is under examination at the European Patent Office (UPC opt-out registered). The same invention is protected in the United States by US 12,719,697 B2, granted on 25 August 2026. See the US patent page for the granted claims and the full specification.