SOVEX
CBDC Data Centers Sovereign AI Tokenization Deep Tech Architecture About Team Request access
Sovereign CBDC / Offline & resilience / Offline payments

Offline payments.

A national currency cannot depend on the network being up. Sovex settles value directly between devices when connectivity is gone, then proves every transfer against the ledger the moment it returns.

Offline value moves as signed, self-contained obligations

When the ledger is unreachable, value is carried by the transfer itself rather than looked up from a server.

01

Self-contained value tokens

Each offline unit carries its provenance, denomination, and issuing signatures, so a receiving device can validate it locally without contacting the ledger.

02

Device-held keys

Keys never leave the secure element; the holder authorizes each transfer on-device, preserving the non-custodial guarantee even with no connection.

03

Post-quantum authorization

Every offline transfer is signed with ML-DSA-65 (FIPS 204), so an intercepted or replayed message cannot be forged today or against future quantum capability.

Preventing double-spend without a live ledger to ask

The hardest offline problem is stopping the same value from being spent twice while no authority is reachable to say no.

01

Monotonic device counters

The secure element enforces a strictly increasing transfer sequence; a reused or out-of-order counter is detectable and rejected at reconciliation.

02

Attested hardware

Devices present hardware attestation before transacting, binding value to tamper-resistant elements and excluding cloned or emulated wallets.

03

Bounded exposure

Per-device value ceilings and velocity limits cap the total offline liability a single holder can accumulate before it must reconcile.

The handshake that moves value across a dead network

Two devices establish trust and exchange value entirely between themselves, with no intermediary in the path.

01

Direct device-to-device

Transfers complete over NFC, Bluetooth, or scannable codes without either party reaching a network service.

02

Mutual attestation

Payer and payee verify each other's certificates and revocation status from locally cached trust material before value changes hands.

03

Countersigned receipts

Both sides retain a signed record of the transfer, giving each party independent evidence for later submission and dispute resolution.

Every offline transfer is proven the moment connectivity returns

Reconnection is not a sync of balances but a cryptographic proof that folds offline activity into the authoritative record.

01

Deterministic replay

The device submits its ordered chain of offline transfers; the ledger revalidates signatures and counters and folds accepted transfers into the hash-chain.

02

Conflict detection

If two devices claim the same value, the ledger identifies the collision through counters and quarantines the conflicting branch for adjudication.

03

Tamper-evident anchoring

Reconciled offline transfers occupy the same append-only, hash-linked ledger as online settlement — never a separate, weaker record.

Central banks keep monetary control over offline money

Offline capability is governed by issuer policy, not fixed by the protocol, so systemic bearer risk stays bounded.

01

Configurable ceilings

Offline value limits, transfer counts, and time-to-reconcile windows are policy parameters the issuer sets and can change.

02

Expiry and forced sync

Offline balances can be made to expire or require reconnection after a defined interval, bounding how long value circulates unreconciled.

03

Revocation propagation

Compromised device certificates enter revocation lists that spread through subsequent device contacts, containing fraud without a live connection.

Build it sovereign.

Talk to us about offline payments in a sovereign deployment.