Issuer-Controlled Co-Signing for Institutional Card Wallets

Granted US Patent: Issuer-Controlled Transaction Co-Signing for Hardware Card Wallets

The Problem: Institutions Need Control Over Card Wallets Without Holding the Keys

Banks, fintechs, crypto exchanges and asset managers that issue hardware wallets to their clients face a dilemma. A classic hardware wallet signs whatever its holder presents to it — the issuing institution has no way to enforce compliance rules, spending limits or a freeze on a lost card, short of taking custody of the private keys itself. Custodial models solve the control problem but reintroduce the single point of failure that hardware wallets were meant to remove, and they turn the institution into a target.

The Innovation: Two Independent Gates Before the Secure Element Signs

US 12,719,697 B2, granted by the United States Patent and Trademark Office on 25 August 2026, protects a digital-signing method in which a secure-element card (the “data processing apparatus” of the claims) signs a cryptocurrency transaction only after two independent authorisations have succeeded: the cardholder’s own authentication to the card, and a signing element issued by the institution’s remote system. The user device — typically a phone app — first authenticates to the card; the card answers with a remote authentication element. The app forwards that element together with the transaction details to the issuer’s server, which returns a signing element. Only when the app presents this signing element to the card together with a second authentication, and the card verifies both, does the card sign the transaction hash with its private signature key. The private key never leaves the secure element, and the issuer never sees or holds it.

What the Granted Claims Cover

The claims cover the complete round trip. The transaction data structure carries the details of a crypto transaction, and the card signs a hash of each transaction (claims 1 and 2); the user device then broadcasts the signed transaction to the blockchain (claim 3). The issuer’s server performs a compliance check on each transaction and verifies the card’s remote authentication element before it generates the signing element (claims 4 and 9). The private signature key is stored in a secure portion of the apparatus, which may be a smart card (claims 5 and 6). The remote authentication element can be the transaction hash signed with a card-specific private remote-access key, and the signing element the same hash signed with the issuer’s private key, which the card verifies with the issuer’s public key (claims 7 to 9). Several transactions can be approved in one round trip by concatenating their hashes into a meta data element that is signed once (claims 10 to 14). Claims 15 and 16 cover the corresponding system of user device, card and issuer server.

What This Enables: Card-Wallet-as-a-Service With Built-In Policy Control

This is the mechanism behind Cryptnox’s Card-Wallet-as-a-Service (C-WAAS) platform. An institution can issue white-label crypto cards to thousands of clients and apply its own rules — whitelisted blockchains and addresses, spending caps, travel-rule and sanctions screening, or an immediate freeze of a lost or stolen card — because every transaction must pass its compliance check before the card will sign. At the same time, the institution never holds the client’s private key: it can approve, but it cannot spend. The client keeps true self-custody inside a CC EAL6+ secure element; the institution keeps the oversight regulators expect.

Why This Matters

Issuer-controlled co-signing closes the gap between self-custody and regulated custody. With this US patent granted, Cryptnox holds protected technology for hardware card wallets that combine the security of a tamper-resistant secure element with institutional policy enforcement — without custodial key risk. The corresponding European application, EP 4 258 596 A1, is under examination at the European Patent Office. The full specification and the granted claims can be downloaded above.