Glowing layered stack rising from a secure chip

Technology

Trust begins in silicon

The SEALCOIN platform combines secure hardware, PKI, post-quantum cryptography and a distributed ledger so machines can transact autonomously, without a central authority or human intervention. Together they form the foundation for Quantum AI Transactions (QAIT).

SEALCOIN ecosystem

Six core technologies working together

Post-quantum cryptography sits at the centre, because every other layer relies on identities that must stay trustworthy for a device’s whole service life.

Quantum-safe

Post-Quantum Cryptography (PQC)

Quantum-resistant algorithms protect device identities, signatures and key exchange, so what SEALCOIN issues today is not exposed when large quantum computers arrive.

Hardware Root of Trust

SEALSQ secure elements generate and store private keys inside the chip. Keys never leave the hardware, which makes device identities impossible to copy in software.

Public Key Infrastructure (PKI)

WISeKey PKI creates and assigns a unique digital identity, a certificate, to every connected device or agent, and manages it through its whole lifecycle.

Elliptic Curve Cryptography (ECC)

Efficient authentication of devices and transactions for resource-constrained IoT hardware, used alongside PQC.

Distributed Ledger (Hedera)

Hedera provides fast, low-cost and tamper-proof records of every transaction, with enterprise-grade security and energy-efficient consensus.

Non-Custodial Wallets

Owners keep full control of their QAIT and private keys. No third party can move a device’s funds.

Why post-quantum, why now

Machine identities outlive today’s cryptography

A smart meter, a vehicle or an industrial controller can stay in service for ten to twenty years. Attackers can record signed traffic and certificates today and wait until a quantum computer can break classical keys. This is called “harvest now, decrypt later”.

SEALCOIN protects identities with post-quantum cryptography from the moment a device is provisioned, so a device shipped this year does not become a liability later in its life.

Timeline: a device is provisioned today and stays in service for up to 20 years; classical keys may become breakable during that period, PQC keys stay safe

Illustrative timeline. When classical keys become breakable is uncertain; the exposure window is shown as a range, not a date.

Security stack

A hardware-rooted stack from silicon to autonomous transactions

Click a layer to see what it does and which part of the WISeKey Group provides it.

Autonomous Transactions

Machines negotiate, execute and settle service-for-payment exchanges on their own, within the rules their owners set, with QAIT as the settlement token on Hedera.

SEALCOIN transaction engine · Hedera · QAIT

Service Discovery

Authenticated machines find trusted services, prices and counterparties through broker nodes, even from behind firewalls and carrier networks.

SEALCOIN broker nodes

Machine Authentication

Before any exchange, machines prove who they are to each other with their certificates. Unknown or revoked devices are refused automatically.

SEALCOIN platform

PQC Identity

Each device and agent receives a certificate-based identity protected with post-quantum cryptography, so identities issued today stay trustworthy through the device’s whole service life.

WISeKey PKI + post-quantum cryptography

Hardware Root of Trust

Keys are generated and stored inside a secure element at manufacturing. They never leave the chip, so a device cannot be cloned or impersonated in software.

SEALSQ secure hardware

Platform architecture & key features

Three layers, one connected infrastructure

Industries bring their own logic. SEALCOIN supplies the platform and the trust infrastructure underneath. Click any module to see what it does.

Industry Applications

Business Logic

The rules of a specific market: who may buy what, at which price, under which conditions. Written by the industry partner.

Sector Rules

Regulatory and sector constraints, such as grid codes, battery passports or data-protection terms, expressed as policy the platform enforces.

Commercial Models

Pay-per-use, subscriptions, revenue sharing or device-as-a-service pricing, settled automatically.

SEALCOIN Platform

Device Registry

The record of every enrolled device and agent, its owner, its certificate and its status.

Certificate Lifecycle

Issuance, renewal and revocation of PKI and PQC certificates for the full life of a device.

Broker Nodes

Route and translate messages between machines behind firewalls and private networks without ever becoming a trusted intermediary.

Messaging

Encrypted peer-to-peer messages between authenticated machines.

Wallet

A non-custodial wallet per device or agent. The owner keeps control of the keys.

Transaction Engine

Negotiation, execution and policy checks for each service-for-payment exchange.

Settlement

Programmable settlement in QAIT, recorded on Hedera.

Trust Infrastructure

Secure Hardware

Secure elements that generate and protect device keys. Provided by SEALSQ.

PKI

Public key infrastructure that issues and manages machine identities. Provided by WISeKey.

PQC

Post-quantum cryptographic algorithms that keep identities and signatures secure against future quantum computers.

Distributed Ledger

Hedera, a public distributed ledger for fast, low-cost, tamper-proof transaction records.

Smart Contracts

Standardised, auditable logic for industry agreements and automated settlement.

SEALCOIN secure device onboarding
Platform walkthrough: devices, certificates, wallet and transactions

See it working

From enrolment to first payment in the SEALCOIN platform

The walkthrough shows how an operator enrols devices, assigns certificates, funds a wallet and follows transaction operations in real time.

Streamlined user onboarding

KYC through the WISeID platform, with role-based access for professional and individual users. Phased activation: B2B first, then B2C.

Device onboarding & management

Secure enrolment with PKI and PQC certificates and a unique identity per device, backed by secure elements and on-chip cryptographic operations.

Advanced security

End-to-end encryption and hardware security modules protect transaction integrity and device authenticity.

Device lifecycle

From device to economic actor in ten steps

Every authenticated device can securely discover, negotiate, purchase and provide services autonomously. Click a step, or use the arrows, to follow one from the factory to its first transaction.

  1. Manufacturing

    The device is built with a SEALSQ secure element on board.

    Hardware root of trust

  2. Secure Element Provisioning

    Keys are generated inside the secure element in a trusted provisioning process. Private keys never leave the chip.

    Hardware root of trust

  3. PKI / PQC Certificates

    WISeKey PKI issues the device’s certificate, protected with post-quantum cryptography. This is the device’s identity for life.

    PQC Secure Identity

  4. Wallet

    A non-custodial wallet is bound to the device identity so it can hold and spend QAIT.

    PQC Secure Identity

  5. SEALCOIN Agent

    The SEALCOIN agent software runs on the device and acts for it within the rules its owner sets.

    Trusted Coordination

  6. Network Registration

    The device joins the SEALCOIN network and appears in the device registry.

    Trusted Coordination

  7. Authentication

    Each session starts with certificate-based mutual authentication between machines.

    Trusted Coordination

  8. Service Discovery

    Through broker nodes, the device finds trusted services and counterparties.

    Trusted Coordination

  9. Negotiation

    Machines agree price and terms automatically, within owner-defined policy.

    Autonomous Transactions

  10. Transaction Execution

    The exchange is executed and settled in QAIT, with a tamper-proof record on Hedera.

    Autonomous Transactions

Connectivity

Why broker nodes matter

Broker nodes facilitate communication. They never become trusted transaction intermediaries. Machines remain in control.

Devices operate behind

  • Firewalls
  • Carrier networks
  • Private networks
  • Enterprise gateways
  • Cloud isolation
Broker node

Broker node

Trustless layer that routes and translates messages, keeps them private and gives devices global reach.

Broker nodes enable

  • Secure discovery
  • Encrypted negotiation
  • Authenticated peer connections
  • Scalable global connectivity
  • Secure communication channel

Security features

Built into the device, enforced by the network

  • Secure Elements (SE). SEALSQ hardware that performs cryptographic operations and protects private keys inside the chip.
  • Role-Based Access Control (RBAC). Only authorised users and devices can access and act in the SEALCOIN ecosystem.
  • Certificate of Authenticity. SEALCOIN issues and manages the certificates that identify a device as part of the trusted ecosystem, for security, interoperability and ease of use.
  • Post-quantum protection. Identities and signatures are protected against future quantum attacks.

Proof of concept

Secure, real-time IoT transactions, demonstrated in July 2024

Each IoT device registered on the SEALCOIN platform with a unique digital ID secured by encrypted authentication. Devices then initiated transactions, shared data and completed service-for-payment exchanges on their own, without intermediaries.

The proof of concept confirmed SEALCOIN’s foundational role in a decentralised IoT ecosystem and shaped the platform now running on Hedera with QAIT settlement.

SEALCOIN PoC demo
Two devices authenticate, agree a price and settle on Hedera

Next

See where the technology is applied

Stay close to the machine economy

Product releases, PQC milestones and ecosystem news from SEALCOIN. Roughly once a month.

You bring the business layer. We provide the trust layer.

Tell us about your devices, agents or marketplace. The SEALCOIN team replies within a few working days.

SEALCOIN Whitepaper

Open the PDF