Address identity affirmation method and system based on two layers of transaction networks
By building the tag attribute graph and network maximum flow algorithm of the two-layer transaction network, the problem of incompatibility of USDT addresses on the blockchain network is solved, and the address identity and correlation are efficiently identified, reducing the computational complexity.
Patent Information
- Application Number
- CN202510766199.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-06-10
AI Technical Summary
The USDT version addresses on existing different blockchain networks are incompatible with each other, making it difficult to effectively identify the owner identity and correlation behind it.
By collecting transaction data, a mark attribute diagram based on a two-layer trading network is constructed, and the transaction time sequence constraints and network maximum flow algorithm are used to calculate the maximum flow of funds and the frequency of mutual conversion of funds, analyze the transaction relationship between suspicious addresses, and determine whether the address belongs to the same user or organization.
It realizes efficient and reliable identification of the identity and correlation of different blockchain network addresses, reduces the computational complexity, and is suitable for large-scale transaction data processing.
Smart Images

Figure CN120297984A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of blockchain data analysis, and particularly relates to a method and system for identifying address identity based on a two-layer transaction network. Background Art
[0002] The characteristics of blockchain technology, such as high transparency, decentralization, immutability, anonymity, etc., have created an online information exchange method that does not rely on a third-party trust institution in the Internet era. Up to now, many public blockchains have been issued, and Tron is one of the mainstream public blockchains.
[0003] Tether, abbreviated as USDT in English, is a token launched by Tether based on the stable-value currency US dollar (USD). The feature that USDT is equivalent to the same amount of US dollars makes it a good hedging token in the highly volatile cryptocurrency market. Among several major public blockchains, the stablecoin Tether has the highest liquidity. Currently, there are three versions based on different blockchain networks in the market: Omni-USDT, ERC20-USDT based on the Ethereum main chain, and USDT-TRC20 based on the Tron main chain. Although the above three USDT versions have the same price and are used without difference in the exchange, they remain independent and incompatible at the chain level, specifically manifested as different address formats. The Omni-USDT address starts with 1, the ERC20-USDT address starts with 0x, and the USDT-TRC20 address is prefixed with T. Among them, USDT-TRC20 is a stablecoin anchored to the US dollar issued by Tether based on the Tron network and can be issued, transferred, traded, etc. on Tron. The Tron public chain uses the cryptocurrency Tronix (TRX).
[0004] Currently, tracking transaction behaviors and user identities by deploying detection nodes or designing new blockchain-based proof methods often fails to be effectively implemented due to timeliness issues and it is difficult to comprehensively collect key information transmitted at the cryptocurrency network layer. Therefore, it is necessary to develop a new method and system for identifying address identity based on a two-layer transaction network to solve the problem that it is difficult to identify the identity and correlation of the owners behind existing different addresses. Summary of the Invention
[0005] The purpose of the present invention is to provide a method and system for identifying address identity based on a two-layer transaction network to solve the above problems.
[0006] To achieve the above purpose, the present invention provides the following technical solution: A method for identifying address identity based on a two-layer transaction network, comprising:
[0007] Collect transaction data and process the transaction data to obtain a transaction record set;
[0008] Identify suspicious addresses in the transaction record set and trace the transaction flow paths between the suspicious addresses;
[0009] Analyze the transaction flow paths to determine the possibility that two suspicious addresses belong to the same user or organization.
[0010] Preferably, the identifying suspicious addresses in the transaction record set and tracing the transaction flow paths between the suspicious addresses includes:
[0011] Using the transaction time sequence constraint to screen valid transaction paths;
[0012] Calculate the maximum capital flow on all valid transaction paths;
[0013] Calculate the effective transfer amount from the source node, i.e., the sender address at the starting point of the transaction path, to the sink node, i.e., the receiver address at the end point of the transaction path, on the valid transaction path.
[0014] Preferably, the using the transaction time sequence constraint to screen valid transaction paths includes: for each path from the source node to the sink node check the time sequence constraint of this path, and the expression is as follows:
[0015] ;
[0016] Wherein, represents the occurrence time of the transfer transaction corresponding to the edge connecting two nodes, represents the source node to the sink node an intermediate node on a certain transaction path, represents the source node to the sink node the number of nodes passed through in the middle, represents the transaction timestamp of a direct transaction from node to node ;
[0017] If the transaction path satisfies the time sequence constraint, it means that this path is a valid transaction path, retain this path, and continue to screen valid transaction paths in the transaction flow; for example, there are 3 paths from the source node to the sink node Except for , there are other paths , , and the valid paths are screened out from small to large through the time constraint. Because transfer to must be carried out before transfer to , otherwise this path is invalid.
[0018] Preferably, calculating the maximum fund flow on all valid transaction paths includes: for each valid transaction path, calculating the maximum fund flow on this path:
[0019] ;
[0020] wherein, represents a valid transaction path of the valid transaction amount; represents the direct transaction amount from node to node ; represents the number of nodes passed through from the source node to the sink node .
[0021] Preferably, calculating the effective transfer amount from the source node to the sink node includes:
[0022] ;
[0023] wherein, represents the effective transfer amount from the source node to the sink node ; represents the set of all possible valid transaction paths from the source node to the sink node ; represents the valid transaction amount of a certain valid transaction path; represents a found valid transaction path.
[0024] Preferably, analyzing the transaction flow to determine the possibility that two suspicious addresses belong to the same user or organization includes:
[0025] measuring the mutual transfer frequency between the two suspicious addresses;
[0026] judging whether the two suspicious addresses belong to the same user or group through the identity index.
[0027] Preferably, measuring the mutual transfer frequency between the two suspicious addresses includes:
[0028] calculating the harmonic mean The formula is as follows:
[0029] ;
[0030] wherein, represents the number of transactions from the source node to the sink node in the Represents The number of transactions from the sink node To the source node In the layer network
[0031] Preferably, calculate the trading fund flow intensity To measure the total transfer amount between the source node And the sink node The formula is as follows:
[0032]
[0033] Represents The valid transaction amount from the source node To the sink node In the layer network Represents The number of transactions from the sink node To the source node In the layer network Represents the maximum transaction amount between a pair of addresses in the network, used for normalization;
[0034] Use the weight parameter to adjust the influence of two factors on the mutual transfer index The mutual transfer index The formula is as follows:
[0035] ;
[0036] Wherein, Respectively represent the weight parameters, Represents the harmonic mean, Represents the trading fund flow intensity;
[0037] Preferably, determining whether two suspicious addresses belong to the same user or group through the identity index includes:
[0038] The address And the address The identity index of The formula is as follows:
[0039] ;
[0040] Wherein, Represents The number of transactions from the source node To the sink node In the layer network Represents The number of transactions from the sink node To the source node In the layer network Indicate Addresses in the layer network And The mutual transfer indicator for transactions between them, The value of is That is Layer network.
[0041] The present invention further provides an address identity determination system based on a two - layer transaction network, including:
[0042] A transaction data collection module for collecting transaction data;
[0043] A processing module for processing the transaction data to obtain a transaction record set;
[0044] A transaction flow path identification module for identifying suspicious addresses in the transaction record set and tracing the transaction flow path between the suspicious addresses;
[0045] A hidden funds determination module for analyzing the transaction flow path in the transaction record set to determine hidden funds;
[0046] A possibility analysis module for analyzing the transaction flow path to determine the possibility that two suspicious addresses belong to the same user or organization.
[0047] The technical effects and advantages of the present invention: The address identity determination method and system based on a two - layer transaction network extract transaction characteristics and rules by analyzing public transaction records, and then judge the correlation between addresses on different chains, and excavate hidden address clusters under the same user or organizational structure; it can directly use the public transaction records on the blockchain website to conveniently obtain the transaction data set of on - chain addresses. The transparency of the data source and easy access make the transaction data set easy to obtain; and starting from the actual supervision requirements, by analyzing historical case data, feasible address identity determination rules are summarized and induced, and at the same time, a mathematical formula is used to model the identity between addresses, thus providing an efficient and reliable hidden address identification method to solve the problem that the prior art has not fully utilized the transaction relationship between addresses to determine the identity of addresses; compared with the prior art that relies on complex algorithms for identification, it reduces the computational complexity and is applicable to the processing of large - scale transaction data. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 Is a schematic flowchart of the method of the present invention; Figure 2This is the transaction relationship marking attribute diagram of the method of the present invention. Among them, layer A represents the USDT-TRC20 transaction network (the currency of transaction transfer between addresses is USDT-TRC20), and layer B represents the TRX transaction network (the currency of transaction transfer between addresses is TRX). Nodes in each layer network represent addresses. The addresses in layer A and layer B are the same, and the upper and lower layers correspond one by one. The connecting edges with arrows represent the transfer relationship between two addresses. The connecting edges contain attribute information of transfer time and transaction amount respectively. For example, address 1 transfers 50 USDT to address 5 at 16:35:55 on February 20, 2025. In addition, address 1 transfers 100 TRX to address 5 at 11:45:32 on February 23, 2025. Represented in the two-layer transaction network topology diagram, there is a connecting edge from node 1 to node 5 in the A-layer transaction network, and there is also a connecting edge from node 1 to node 5 in the B-layer network. However, the attributes (transaction time and amount) of these two connecting edges are different, and the currencies representing transactions in different layers (USDT-TRC20 in layer A, TRX in layer B) are also different; Figure 3 This is an example diagram of the valid transaction path of the method of the present invention, which refers to the transaction path that satisfies the transaction time sequence constraint. Among them, TCY3zyEa..., THt34jtu..., TGzgwdHw..., TYxMrB8q..., TMprkhAw..., TAWja7Kq... represent the transaction addresses represented by each node. USDT (TRC-20 standard) on the Tron chain adopts the TRON address format, with a length of 34 characters. The first 8 characters are shown in the figure. Address (TCY3zyEa...) to address (THt34jtu...) has a transaction time of March 22, 2025, 11:45:32. Address (THt34jtu...) to address (TGzgwdHw...) has a transaction time of March 22, 2025, 13:23:55. It can be seen that address receives the transfer from address , and then address transfers to address ( ). After address receives the transfer, it continues to transfer to the downstream receiving address until the final address (TAWja7Kq...). By judging that the transfers between addresses on the transaction path all satisfy the time sequence constraint ( ), it shows that this path is a valid transaction path. Specific implementation manner
[0049] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0050] The present invention provides Figure 1 A method for identifying address identity based on a two-layer transaction network is shown in the text, which mines hidden on-chain addresses and different addresses belonging to the same user or group to solve the problem that it is difficult to identify the owner identity and association behind different existing addresses.
[0051] This embodiment constructs a method for identifying address identity based on a two-layer transaction network on the TRON chain, including the following steps:
[0052] Transaction data collection: Synchronize transaction information on the blockchain, extract the incoming and outgoing transaction data including USDT-TRC20 and TRX transactions based on the input address, such as suspicious accounts, and use the counterparty address as the new input address to recursively retrieve and download transaction data until the counterparty is a large exchange account or platform address, forming the original transaction data set;
[0053] Transaction data cleaning: Clean the original transaction data set, remove duplicate records and invalid records, such as non-USDT, non-TRX transactions or records with transaction amounts less than 0.01, and obtain two transaction record sets, USDT-TRC20 and TRX;
[0054] Construct a two-layer network: Based on the USDT-TRC20 and TRX transaction record sets, construct a labeled property graph, also known as a Labeled Property Graph (LPG); specifically, use a weighted directed graph to represent the transfer-in and transfer-out relationships between USDT-TRC20 and TRX transaction addresses respectively, thereby constructing a two-layer network (multi-relationship network) based on USDT-TRC20 and TRX transaction records. Among them, the upper-layer network represents the transfer-in and transfer-out relationships of USDT-TRC20 through nodes and weighted directed edges, and the lower-layer network represents the transfer-in and transfer-out relationships of TRX through nodes and weighted directed edges; since the address sets of the upper and lower layer networks are the same, the inter-layer coupling relationship can be constructed by whether the addresses are the same, forming a complete two-layer network structure. It should be noted that there is only a single USDT-TRC20 transaction relationship between some addresses, only a single TRX transaction relationship between some addresses, and there are both USDT-TRC20 and TRX transaction relationships between some other addresses; the two-layer network can intuitively reflect the correlation between different transaction types (USDT-TRC20, TRX) between addresses. In the two-layer transaction network, each layer represents a different transaction currency, the nodes represent addresses, the directed edges between the nodes represent the transfer transaction relationships between addresses, and the edge attributes record the transaction time and amount.
[0055] Analyze the transaction flow: Filter out the valid transaction paths in the USDT-TRC20 transaction layer according to the time sequence constraint, calculate the maximum flow of funds for the transaction path from the source node (suspicious account) to the sink node (target account), so as to identify the main path and key nodes of the fund flow. On this basis, further analyze the total transaction amount, the number of transfer-in and transfer-out transactions, the round-trip transaction frequency between two suspicious addresses, the mutual transfer (round-trip transfer) index, and the identity index of a certain address in the USDT-TRC20 transaction layer and the TRX transaction layer, and identify the address pairs belonging to common social relationships.
[0056] Visualize the transaction data: Visualize the transaction topology of the address pairs belonging to common social relationships.
[0057] Among them, the specific operation of transaction data collection is as follows: Based on the first input address, that is, the suspicious address, extract the transfer-in and transfer-out transaction data of the input address through the synchronized on-chain transaction information, redefine the transaction counterparty as the input address, and continue to retrieve and download the transaction data of the transaction counterparty as the original transaction data until the transaction counterparty is the large account of the exchange or the platform address.
[0058] Invalid records refer to records that are neither USDT nor TRX and the transaction amount is less than 0.01. The finally obtained table contains transaction hash, block height, date and time, sender, receiver, token, and transaction amount data.
[0059] An effective transaction path refers to a transaction path that satisfies the transaction time sequence constraint. The maximum fund flow of a transaction path refers to the maximum possible fund flow between nodes under the conditions of satisfying the capacity limit of all edges and flow conservation. The total transaction amount refers to the total amount of incoming and outgoing transactions of a certain transaction address. The total amount of incoming and outgoing transactions refers to the sum of the total amounts of incoming and outgoing transactions between all addresses in a certain layer of the transaction network, that is, the above-mentioned total transaction amount. The round-trip transaction frequency refers to the total number of transactions between a pair of addresses in a certain layer of the transaction network.
[0060] The mutual transfer indicator is used to measure the likelihood of an association between two suspicious addresses.
[0061] The identity indicator is used to measure the likelihood that two suspicious addresses belong to the same user or group.
[0062] Common social relationships that can be analyzed include, but are not limited to: one address is specifically used to receive withdrawals from the exchange and transfer them to another address for external transfer.
[0063] The method for identifying address identity based on a two-layer transaction network refers to constructing two-layer transaction networks of USDT-TRC20 and TRX based on on-chain address transaction data. By analyzing the transaction relationships between addresses in the same layer and between layers, the correlation between addresses is mined to identify whether multiple different addresses are owned by the same person or organization, providing algorithm support for finding other addresses hidden by the owner or team of a specified suspicious account.
[0064] If there are frequent mutual transfer behaviors between two virtual addresses on the two-layer network, then these two suspicious addresses are very likely to belong to the same user or there is a high degree of correlation between the actual controllers behind them.
[0065] Through the above method, the problem of difficult identification of the identity and correlation of the owners behind different addresses is solved, and a method for calculating the maximum fund flow transferred from the initial node to the sink node on the transaction path is proposed based on an improved network maximum flow algorithm. Specifically:
[0066] Improve the identification accuracy: By analyzing the number of mutual transfers, it is possible to relatively accurately judge whether two addresses belong to the same user or group. Analyzing the number of transactions on the two-layer network and referring to multiple groups of data simultaneously can improve the accuracy of address identity determination.
[0067] Low computational complexity: This application does not need to collect and analyze a large amount of transaction data. Instead, it starts from a single address and mines transaction information related to it along the transaction link until the exchange address or platform address is identified. Since it only focuses on the counterparty information directly or indirectly related to the initial input address and gradually expands the retrieval scope recursively, the number of computational addresses involved is limited, the scale of data processing is controllable, and the computational complexity is significantly reduced.
[0068] Efficiently mine hidden funds: Based on the improved network maximum flow algorithm, a funds maximum flow algorithm is proposed to trace the hidden transaction flow paths among multiple addresses and mine the maximum flow of hidden funds at the sink nodes on the transaction link.
[0069] This application solves the problems existing in the determination of the transfer transaction amount between virtual addresses and the identity of the owners of different addresses in the prior art through simple and effective methods, improves the accuracy of identification, reduces the computational complexity, and provides a more effective technical means for the supervision of virtual addresses.
[0070] The method for determining the identity of USDT transaction addresses based on the TRC20 protocol includes four major steps: transaction data collection and cleaning, construction of a two-layer network, analysis of transaction flows, and visualization of transaction data. The steps are as follows:
[0071] Step 1. Transaction data collection and cleaning:
[0072] Step 11. Obtaining transaction records of the initial address: Starting from the specified suspicious address, download all transaction records of this address through a blockchain browser;
[0073] Step 12. Retrieving the counterparty addresses: For each counterparty address of the suspicious address, retrieve and download its transaction records one by one;
[0074] Step 13. Recursively expanding the retrieval scope: Repeat the above steps, starting from the newly discovered counterparty address, continue to retrieve and download its transaction records until the counterparty is a known exchange address or platform address;
[0075] Step 14. Data aggregation and cleaning: Aggregate all downloaded transaction records, and remove duplicate records and invalid records through data cleaning to form a complete and effective USDT-TRC20 transaction record set and a TRX transaction record set.
[0076] Among them, the blockchain browser refers to the blockchain browser represented by OKLink.
[0077] The complete and effective transaction data set contains the addresses of both parties to the transaction, namely the transferor and the transferee, transaction hash, block height, date and time, tokens, and transaction amount.
[0078] Invalid records include non-USDT, non-TRX, and records with a transaction amount less than 0.01.
[0079] Step 2: Construct a two-layer network:
[0080] Step 21: Use the transaction data in the USDT-TRC20 and TRX transaction record sets to construct a two-layer transaction network topology diagram;
[0081] Abstract the transaction network composed of USDT-TRC20 and TRX transactions into a two-layer network, where the addresses of traders are regarded as nodes, and the USDT-TRC20 or TRX transactions between two suspicious addresses are regarded as directed edges;
[0082] It should be noted that since there may be multiple transactions between any two suspicious addresses in the established two-layer network, there may be multiple unidirectional or bidirectional edges between two nodes. These edges can be characterized by creating a labeled property graph using Cypher statements. The labeled property graph has the following characteristics:
[0083] (1) The labeled property graph consists of nodes and directed edges, where the nodes correspond to on-chain addresses, and the directed edges correspond to the transaction relationships between addresses, as Figure 2 shown.
[0084] (2) Nodes have properties described by key-value pairs.
[0085] For example, create (n1:address {addr:'TCAJfgnAJLbYjFkqDbonkCVyJz8skg61ND'}) represents creating a node with the label "address" and the property "addr". In the node properties, the key-value pair is "addr: TCAJfgnAJLbYjFkqDbonkCVyJz8skg61ND", where "TCAJfgnAJLbYj FkqDbonkCVyJz8skg61ND" is the actual on-chain address.
[0086] (3) Connections can have one or more properties and always have a start node and an end node.
[0087] For example, create (n1:address{addr:'TCAJfgnAJLbYjFkqDbonkCVyJz8skg61ND4'}) - [r:usdt_trans_to{time:['2023-09-22 13:32:48'],amount:['5USDT']}] -> (n2:address{addr: 'TVjXoTnE7HFbZ23GHJjYhZpcqJLSHdMp8XL'}) represents creating a relationship labeled "usdt_trans_to" with attributes "time" and "amount" between two nodes.
[0088] Step 22: Abstract the two - layer network into a directed graph ;
[0089] The top layer (represented by ) represents the USDT - TRC20 transaction network diagram, and the bottom layer (represented by ) represents the TRX transaction network diagram. The thick solid lines in the top layer represent the USDT - TRC20 transaction relationships between addresses, the dotted lines in the bottom layer represent the TRX transaction relationships between addresses, and the dashed lines between the two layers represent the same addresses in the upper and lower layers, which is used to reflect the coupling relationship between the USDT - TRC20 network and the TRX network.
[0090] It should be noted that in the directed graph , is the set of addresses, that is, the set of nodes in the network topology diagram.
[0091] is the edge set in the layer. For example, represents the edge set of USDT - TRC20 transactions in the layer, and represents the edge set of TRX transactions in the
[0092] The node set in the layer is represented as , where is the number of on - chain addresses involved in USDT - TRC20 transactions in the
[0093] The node set in the layer is represented as , where represents the number of on - chain addresses involved in TRX transactions in the
[0094] is the The union of the layer node sets, is the number of nodes in this union.
[0095] and respectively represent the adjacency matrices of the layer graph and the layer graph in the double-layer network graph, indicating the number of directed edges from node to node in the layer graph.
[0096] Step 3. Analyze the transaction flow;
[0097] Step 31. To identify suspicious addresses and trace the main transaction flow paths between suspicious addresses, analyze the USDT-TRC20 transaction flow and find hidden funds: For example - ( transfer 200 yuan)- ( transfer 50 yuan)- ( transfer 150 yuan), To What is the actual transfer amount? It should be the minimum amount of 50 yuan after screening the valid transaction paths according to the transaction time sequence constraint;
[0098] Utilize the transaction time sequence constraint to screen the valid transaction paths; Since there is a sequential order for each transaction in the transaction flow, for each path from the source node to the sink node , as shown in Figure 3 , check the time sequence constraint of this path;
[0099] ;
[0100] Among them, represents the timestamp of the transfer transaction corresponding to the edge connecting the two nodes, is an intermediate node on a certain transaction path from the source node to the sink node , represents the transaction time of a direct transaction from node to node ; represents the number of intermediate nodes passed from the source node to the sink node ;
[0101] If the transaction path satisfies the chronological constraint, it indicates that the path is a valid transaction path. Retain this path and continue to screen for valid transaction paths in the transaction flow.
[0102] Step 32: For each valid transaction path, calculate the maximum flow of funds on this path:
[0103] ;
[0104] Among them, represents the effective transaction amount of a certain valid transaction path ; represents the direct transaction amount from node to node ; represents the source node to the sink node the number of intermediate nodes passed.
[0105] Step 33: Calculate the effective transfer amount from the source node to the sink node :
[0106] ;
[0107] Among them, represents the effective transfer amount from the source node to the sink node ; represents the set of all possible valid transaction paths from the source node to the sink node ; represents the effective transaction amount of a certain valid transaction path, represents a found valid transaction path.
[0108] Step 4: To quantitatively measure the likelihood that two suspicious addresses belong to the same user or organization, mutual transfer index and identity index are proposed:
[0109] Step 41: Measure the mutual transfer frequency between address and address and address through the improved harmonic mean. The harmonic mean is sensitive to extreme values and is more affected by the minimum value than by the maximum value. This makes when the number of transactions from address to address and the number of transactions from address to address are very different, the calculated harmonic mean is close to the smaller value between the two. For example, is equal to 90, is equal to 10, and at this time the harmonic mean equals 9, close to the smaller 10. Improved harmonic mean The calculation formula is:
[0110] ;
[0111] wherein, represents the number of transactions from the source node to the sink node in the -layer network, represents the number of transactions from the sink node to the source node in the -layer network;
[0112] Meanwhile, to further consider the impact of transaction amounts, by improving the network maximum flow algorithm, the transaction fund flow intensity index is introduced, which is used to measure the total transfer amount between address and address . The calculation formula of the transaction fund flow intensity is as follows:
[0113]
[0114] represents the effective transaction amount from the source node to the sink node in the -layer network, represents the effective transaction amount from the sink node to the source node in the -layer network, represents the maximum transaction amount between a pair of addresses in the network, used for normalization.
[0115] On the basis of considering that the contributions of the mutual transfer frequency and the transaction fund flow intensity to measuring the correlation degree between two suspicious addresses are in a linear relationship, the harmonic mean and the transaction fund flow intensity are linearly combined to evaluate the correlation degree between two suspicious addresses; in view of the differences in the impacts of the mutual transfer frequency and the transaction fund flow intensity on the mutual transfer index , a weight parameter is introduced to adjust the impacts of the two factors on the mutual transfer index, so as to achieve a more scientific and accurate quantitative evaluation. In practical applications, considering the differences in transaction scales, the weight parameter needs to be adjusted specifically according to the specific transaction scale, and the initial values are set to 1 and 10 respectively; there is a better quantitative analysis effect, and the parameters of different data sets are different;
[0116] Thus, Nodes in the layer network And the node Mutual transfer index Is:
[0117] ;
[0118] Among them, : The number of transactions from the source node To the sink node In the layer network;
[0119] : The number of transactions from the sink node To the source node In the layer network; Represents the harmonic mean, Represents the intensity of the transaction capital flow;
[0120] : Weight parameter;
[0121] : The effective transaction amount from the source node To the sink node In the layer network;
[0122] : The effective transaction amount from the sink node To the source node In the layer network;
[0123] : The maximum transaction amount between a pair of addresses in the network, used for normalization;
[0124] Mutual transfer index Through the improved harmonic mean term , Measure the balance of the transaction between the two parties; through the dynamic weight term ( ), Adjust the impact of the improved harmonic mean And the intensity of the transaction capital flow On the mutual transfer index; through the threshold condition , Avoid interference from occasional (1 or 2 mutual transfers) transactions.
[0125] Mutual transfer index The larger the value, the greater the possibility of connection between the two addresses.
[0126] Step 42, Mutual transfer index It can only preliminarily indicate the potential association between two addresses. To further determine whether the two addresses belong to the same user or group, an identity index is introduced as the core judgment basis. This index comprehensively considers two types of transaction behaviors, USDT-TRC20 and TRX. When there are not only USDT-TRC20 transfer records between two suspicious addresses, but also the characteristics of mutual payment of TRX (as transaction fees or independent transfers), it indicates that the address pair forms a coupling relationship at two levels: the token trading network and the underlying public chain trading network. The superimposed effect of the cross-layer transaction mode will significantly increase the value of the identity index, and ultimately greatly increase the probability of determining that the address pair belongs to a single user or group. The logarithmic function is used to transform the number of TRX transactions. The technical principle and parameter selection basis are as follows:
[0127] The logarithmic function has non-linear mapping characteristics: the representation of TRX transaction behavior on address correlation has the law of diminishing marginal utility. Specifically, when the first TRX transaction occurs between two addresses, its weight contribution to proving address correlation is the largest. As the number of transactions increases, the corroborative effect of a single new transaction shows a decreasing trend. Using the logarithmic function (a convex function) can effectively describe this decreasing law, and its mathematical characteristics conform to the non-linear relationship between the number of transactions and the correlation strength in the actual business scenario.
[0128] Technical adaptation of the base parameter: Select the logarithmic function with base 2 ( ), aiming to strengthen the feature discrimination in low-frequency trading scenarios. When the number of TRX transactions is in a low range (such as 1 - 5 times), the function has a steeper initial growth slope compared to the natural logarithm or logarithmic functions with larger bases, which can significantly amplify the judgment weight of the initial transaction behavior, thus improving the detection sensitivity to sporadic correlation behaviors.
[0129] Compensation mechanism of the constant term: Introduce the constant term +2 in the function. Its technical effects are reflected in two aspects: First, when there is no TRX transaction between two addresses (i.e., N = 0), the function value degenerates into , making the identity index automatically revert to the original mutual transfer index, ensuring the robustness of the algorithm in the case of missing TRX transaction data. Second, the numerical stability of the function in the neighborhood of N = 0 is optimized through parameter translation, avoiding operation anomalies caused by zero input.
[0130] The identity between address pairs is measured by the product of the mutual transfer index of the USDT-TRC20 layer and the logarithm of the number of TRX transactions. The identity index of address and address is formulated as follows:
[0131] ;
[0132] : Layer address and The mutual transfer index of USDT-TRC20 transactions between; The possible values of are or ;
[0133] The higher the value, the more likely it indicates that the address is associated with has a higher probability. The higher the value, the more it indicates that the address is associated with not only has USDT-TRC20 transactions, but also there is a situation of transferring TRX to the other party, which means the higher the probability that a pair of addresses belong to the same user or group.
[0134] Step 5, Transaction data visualization:
[0135] Use the py2neo package in Python to batch import transaction data into the Neo4j graph database, and use this database to store the complex transaction network topology structure between addresses.
[0136] The transaction paths between addresses are output through Cypher statements. Cypher is a declarative graph database query language.
[0137] This application realizes the intuitive visualization of the transaction relationship between addresses. By constructing a labeled property graph and using a directed graph to clearly represent the coupling relationship between the USDT-TRC20 and TRX transaction networks, the transaction flow and association relationship between addresses are clear at a glance, significantly improving the analysis efficiency and interpretability of the transaction network.
[0138] The present invention also provides an address identity determination system for implementing the above method, including:
[0139] Transaction data collection module: Synchronize the transaction information on the blockchain, extract its incoming and outgoing transaction data (including USDT-TRC20 and TRX transactions) based on the input address (such as a suspicious account), and use the counterparty address as a new input address to recursively retrieve and download transaction data until the counterparty is a large account or platform address of the exchange, forming an original transaction data set.
[0140] Transaction data cleaning module: Clean the original transaction data set, remove duplicate records and invalid records such as non-USDT, non-TRX transactions or records with a transaction amount less than 0.01, to obtain two transaction record sets of USDT-TRC20 and TRX.
[0141] Two - layer network construction module: Construct an attribute graph with labels based on the transaction data of addresses on the USDT - TRC20 chain and the transaction data of addresses on the TRX chain. Use a directed graph to represent the transfer - in and transfer - out relationships between addresses, and realize the construction of a multi - relationship network graph, where nodes represent addresses and directed edges represent transfer - in and transfer - out relationships.
[0142] Transaction flow analysis module: Filter out the valid transaction paths in the USDT - TRC20 transaction layer according to the time - order constraint, calculate the maximum fund flow of the transaction path from the source node (suspicious account) to the sink node (target account), so as to identify the main path and key nodes of fund flow. On this basis, further analyze the total transaction amount, the number of transfer - in and transfer - out transactions, the round - trip transaction frequency between two suspicious addresses, the mutual transfer index, and the identity index of a certain address in the USDT - TRC20 transaction layer and the TRX transaction layer, and identify the address pairs belonging to common social relationships.
[0143] Transaction data visualization module: Visualize the transaction topological structure of the address pairs belonging to common social relationships.
[0144] The address identity determination method based on the two - layer transaction network is based on the USDT - TRC20 chain transaction network, including five modules: transaction data collection, transaction information cleaning, two - layer network construction, transaction flow analysis, and transaction data visualization. The entry of the system needs to provide a USDT address, which is defined as the input address. Through the synchronized on - chain transaction information, extract the transfer - in and transfer - out transactions of the input address, and set the address of the transaction counterparty as the new input address. Continuously retrieve and download the transaction data of the transaction counterparty as the original transaction data until the counterparty is the large account of the exchange or the platform address. Integrate and screen the downloaded data, remove duplicate and invalid records, construct a topological graph describing the two - layer transaction networks of USDT - TRC20 and TRX based on the cleaned and summarized transaction dataset, and use conventional indicators and the new indicators proposed in the present invention to analyze the transaction data, sort out and identify possible social relationships, and finally realize the visualization of transaction data.
[0145] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for identifying address identity based on a two - layer transaction network, characterized in that: including: Collecting transaction data and processing the transaction data to obtain a transaction record set; Identifying suspicious addresses in the transaction record set and tracing the transaction flow paths between the suspicious addresses; Analyzing the transaction flow paths to determine the possibility that two suspicious addresses belong to the same user or organization.
2. The method for identifying address identity based on a two-layer transaction network according to claim 1, characterized in that: The identifying suspicious addresses in the transaction record set and tracing the transaction flow paths between the suspicious addresses includes: Using the chronological constraint of the transaction time to screen out valid transaction paths; Calculating the maximum fund flow on all valid transaction paths; Calculating the effective transfer amount from the source node to the sink node on the valid transaction path.
3. The method for identifying address identity based on a two - layer transaction network according to claim 2, characterized in that: The screening of valid transaction paths using the transaction time order constraint includes: checking each transaction flow path from the source node to the sink node for the time order constraint, and the expression is as follows: ; Among them, represents the transfer transaction timestamp corresponding to the edge connecting two nodes, represents the source node to the sink node an intermediate node on a certain transaction flow path, represents from the source node to the sink node the number of nodes passed through, represents the transaction time of a direct transaction from node to node ; If the transaction flow path meets the chronological constraint, then the path is a valid transaction path, and continue to screen out the valid transaction paths between the source node and the sink node.
4. The method for identifying address identity based on a two-layer transaction network according to claim 2, wherein: The calculating the maximum fund flow on all valid transaction paths includes: calculating the maximum fund flow on each valid transaction path: ; Among them, represents the effective transaction amount of a certain effective transaction path ; represents the direct transaction amount from node to node ; represents the number of nodes passed through from the source node to the sink node .
5. The method for identifying address identity based on a two-layer transaction network according to claim 2, characterized in that: The calculating the effective transfer amount from the source node to the sink node on the valid transaction path includes: ; Among them, represents the effective transfer amount from the source node to the sink node ; represents the set of all possible effective transaction paths from the source node to the sink node ; represents the effective transaction amount of a certain effective transaction path ; represents a found effective transaction path.
6. The method for identifying address identity based on a two - layer transaction network according to claim 1, wherein: The analyzing the transaction flow paths to determine the possibility that two suspicious addresses belong to the same user or organization includes: Measuring the mutual transfer frequency between two suspicious addresses; Determining whether two suspicious addresses belong to the same user or organization through an identity index.
7. The method for identifying address identity based on a two-layer transaction network according to claim 6, wherein: The measuring the mutual transfer frequency between two suspicious addresses includes: Calculate the harmonic mean , the formula is as follows: ; Among them, represents the number of transactions from the source node to the sink node in the - layer network, represents the number of transactions from the sink node to the source node in the - layer network; Calculate the intensity of trading fund flow , the formula is as follows: ; Among them, represents the effective transaction amount from the source node to the sink node in the - layer network, represents the effective transaction amount from the sink node to the source node in the - layer network, represents the maximum transaction amount between a pair of suspicious addresses in the network; It should be noted that there seems to be some missing information in the tags , , , . I have translated it as best as possible based on the existing context. If there are specific values or details for these tags, the translation can be more accurate. Adjust the influence of two factors on the mutual conversion index using weight parameters The formula for the mutual conversion index is as follows: ; Among them, respectively represent weight parameters, represents the harmonic mean, represents the intensity of trading fund flow.
8. The method for identifying address identity based on a two-layer transaction network according to claim 6, wherein: The determining whether two suspicious addresses belong to the same user or organization through an identity index includes: Source node The identity index with the sink node is as follows: The formula is as follows: ; Among them, represents the number of transactions from the source node to the sink node in the -layer network, represents the number of transactions from the sink node to the source node in the -layer network, represents the mutual transfer index of transactions between addresses and in the -layer network, The value of is , that is, the -layer network.
9. An address identity recognition system based on a two-layer transaction network, characterized in that: including: A transaction data collection module for collecting transaction data; A processing module for processing the transaction data to obtain a transaction record set; A transaction flow path identification module for identifying suspicious addresses in the transaction record set and tracing the fund flow paths between the suspicious addresses; A hidden fund determination module for analyzing the transaction flow paths in the transaction record set to determine hidden funds; A possibility analysis module for analyzing the transaction flow paths to determine the possibility that two suspicious addresses belong to the same user or organization.
10. The address identity recognition system based on a two-layer transaction network according to claim 9, characterized in that: The system further includes: A module for executing any one of the steps in claims 2-8.
Citation Information
Patent Citations
Blockchain-based underlying chain integration management method
CN109905238A
Mixed currency transaction tracing method based on heuristic rule
CN117314444A
Wave field currency (TRX) and Taida currency (USDT-TRC20) exchange (mixed currency) transaction identification method based on wave field chain (TRON)
CN120070057A
Financial transaction analysis using directed graphs
US20050182708A1
Technologies for creating non-fungible tokens for know your customer and Anti-money laundering
US20240412220A1