Digital currency transaction method and system integrating distributed identity recognition and privacy enhancement functions
By integrating distributed identity recognition and privacy enhancement technologies, the balance issue of security, compliance and privacy in digital currency trading systems is solved, secure, private and compliant financial transactions are achieved, and user experience and system efficiency are improved.
Patent Information
- Application Number
- CN202411999123.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-09-12
AI Technical Summary
Existing digital currency trading systems face challenges in balancing transaction security, compliance, and user privacy. In particular, centralized identity authentication is vulnerable to data leaks and unauthorized access, and it is difficult to meet regulatory compliance requirements while providing privacy protection.
Integrating distributed identity (DID) and privacy-enhancing technology (PET) to achieve secure, private and compliant financial transactions through decentralized identity management and smart contracts. Utilizing DID and public-private key pair encryption methods, combined with zero-knowledge proof and anonymous accounts, it ensures transaction privacy and compliance with regulatory rules.
It enables secure transactions without disclosing personal information, reduces the risk of data leakage, improves user experience and system efficiency, ensures compliance and privacy protection, and supports blockchain networks with high transaction volumes.
Smart Images

Figure CN120634720A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of digital currency transactions and blockchain, and in particular, to a digital currency transaction method and system integrating distributed identity recognition and privacy enhancement functions. Background Art
[0002] With the rapid development of blockchain technology and the digitization of the financial system, digital currencies have become a vital component of the financial sector. Central bank digital currencies (CBDCs) are digital representations of national sovereign currencies issued and regulated by central banks. These currencies aim to improve transaction efficiency, reduce costs, and promote financial inclusion. Summary of the Invention
[0003] The present disclosure relates to a digital currency trading system that integrates distributed identity (“DID”) and privacy-enhanced technologies (“PET”) to enable secure, private, and compliant financial transactions on a blockchain network. The system can be configured to provide decentralized identity authentication and management, transaction privacy protection using cryptographic methods, transaction management and execution through smart contracts according to predefined rules, connections to financial institutions, or a combination of the above. The system can also handle the issuance, circulation, and exchange of central bank digital currencies and legal tender. In various aspects, the technology can operate one or more digital currencies or other homogeneous token assets, including central bank digital currencies, stablecoins, tokenized deposits, or other forms of tokenized digital assets.
[0004] By leveraging DIDs, users can securely verify their identities without disclosing personal information to multiple institutions. The integration of privacy-enhancing technologies ensures the confidentiality of transaction details, preventing external observers from identifying the parties involved or the specific transaction amounts. This system aims to balance the needs of transaction security and compliance with user privacy to address challenges in existing digital currency implementations.
[0005] In a first aspect of the present invention, a method includes: receiving user information associated with a user by a first computing device; determining, by the first computing device, a decentralized identifier (DID) associated with the user based on the user information; providing, by the first computing device, the DID to a user device associated with the user; verifying, by a second computing device, the identity of the user by verifying the DID and an associated verifiable credential; and executing, by a third computing device, a transaction involving the user based on the verified DID.
[0006] In a second aspect of the present invention, according to the first aspect, determining the DID includes generating a public-private key pair for the user; associating the DID with a public key of the public-private key pair; and creating a DID document containing the DID and the public key.
[0007] In a third aspect of the present invention, according to any one of the first aspect or the second aspect, determining the DID further includes processing user information to generate a verifiable credential containing user identity attributes; associating the verifiable credential with the DID; and digitally signing the verifiable credential using the private key of the issuing entity.
[0008] In a fourth aspect of the present invention, according to any one of the second aspect or the third aspect, the method further comprises storing the DID document in a distributed ledger accessible to an authorized entity.
[0009] In a fifth aspect of the present invention, according to any one of aspects 1 to 4, verifying the identity of the user includes receiving a verifiable credential associated with the DID by a second computing device; verifying the verifiable credential using a cryptographic signature associated with the issuing entity; and determining whether the user meets predefined compliance requirements based on identity attributes in the verifiable credential.
[0010] In a sixth aspect of the present invention, according to any one of the first to fifth aspects, executing a transaction includes initiating a transaction request including a DID through a user device; and processing the transaction request through a smart contract deployed on a blockchain network.
[0011] In a seventh aspect of the present invention, according to any one of the first to sixth aspects, performing the transaction includes converting the digital currency into legal tender while protecting user privacy.
[0012] In an eighth aspect of the present invention, according to any one of the first to seventh aspects, executing the transaction includes determining whether the transaction exceeds a preset transaction limit associated with the user's verified identity attributes; and rejecting the transaction when it is determined that the transaction exceeds the transaction limit.
[0013] In a ninth aspect of the present invention, according to any one of the first to eighth aspects, the method further comprises providing zero-knowledge proofs to auditors to verify compliance without access to underlying transaction details.
[0014] In a tenth aspect of the present invention, according to any one of the first to ninth aspects, the user information includes an identity document provided in accordance with "Know Your Customer (KYC)" requirements.
[0015] In an eleventh aspect of the present invention, according to any one of the first to tenth aspects, the method further includes updating the DID or related verifiable credentials in response to changes in user identity information or compliance status.
[0016] In a twelfth aspect of the present invention, a method includes deploying a smart contract on a blockchain network through a computing device, wherein the smart contract is configured to verify the DID and related verifiable credentials of users participating in a transaction; execute transaction compliance rules based on the verified identity attributes; process transactions involving digital currency transfers between users based on the relevant DID; interact with the smart contract to initiate transactions based on requests received from user devices; and execute transactions through the smart contract after successful verification and compliance checks.
[0017] In a thirteenth aspect of the present invention, according to the twelfth aspect, executing the transaction includes receiving a transaction through a smart contract deployed on a blockchain network, which transfers a first amount of a first digital asset from a user device associated with a user; and crediting a second amount of a second digital asset to an internal ledger associated with the user's DID through the smart contract, wherein the second amount is determined based on the first amount.
[0018] In a fourteenth aspect of the present invention, according to the thirteenth aspect, the method further includes updating the balance in the internal ledger through the smart contract to reflect the transaction involving the second digital asset without transferring actual tokens to the user device.
[0019] In a fifteenth aspect of the present invention, in accordance with any one of the thirteenth or fourteenth aspects, executing the transaction further includes, when initiating a subsequent transaction, deducting the user's balance of the second digital asset in the internal ledger through the smart contract; and crediting the payee's second digital asset balance in the internal ledger through the smart contract.
[0020] In a sixteenth aspect of the present invention, according to the twelfth aspect, the DID is issued by an authorized and regulated entity selected from a group consisting of financial institutions, government agencies or other regulatory agencies.
[0021] In a seventeenth aspect of the present invention, according to the twelfth aspect, the smart contract includes an authentication module that interacts with the distributed identity recognition module to access the DID document and verify the verifiable credentials.
[0022] In an eighteenth aspect of the present invention, according to the twelfth aspect, executing compliance rules includes determining transaction limits based on the user's verified identity attributes; rejecting transactions that exceed the established transaction limits; or both.
[0023] In a nineteenth aspect of the present invention, according to aspect 12, the smart contract is configured to check the transaction against a regularly updated sanctions list obtained from an authorized source; determine whether any party involved in the transaction is identified as a sanctioned entity; and reject the transaction if the transaction involves a sanctioned entity.
[0024] In a twentieth aspect of the present invention, according to the nineteenth aspect, the sanctions list is dynamically updated by obtaining an updated sanctions list from a regulatory agency or a trusted data source.
[0025] In a twenty-first aspect of the present invention, according to the nineteenth aspect, determining whether a transaction is prohibited includes analyzing the DIDs of the parties to the transaction; comparing the DIDs with the sanctions list; and marking the transaction if a match is found.
[0026] In a twenty-second aspect of the present invention, according to the twelfth aspect, the smart contract processes privacy-enhanced transactions by verifying zero-knowledge proofs provided by users without accessing sensitive transaction data.
[0027] In a twenty-third aspect of the present invention, according to the twenty-second aspect, the method further includes maintaining anonymous state updates on the blockchain network to protect transaction privacy.
[0028] In a twenty-fourth aspect of the present invention, according to the twelfth aspect, the method further includes updating compliance parameters in the smart contract through the authorization management function to respond to changes in regulatory requirements.
[0029] In a twenty-fifth aspect of the present invention, according to the twelfth aspect, the transaction is performed, subject to successful verification, involving the transfer of one or more currency tokens between user accounts on the blockchain network.
[0030] In a twenty-sixth aspect of the present invention, a method includes: generating a digital wallet associated with a user through a user device, the digital wallet configured to manage a DID, privacy-enhanced transactions, and encryption keys for blockchain transactions; associating the digital wallet with the DID through the user device; and performing transactions on a blockchain network using the digital wallet through the user device while maintaining security and privacy.
[0031] In a twenty-seventh aspect of the present invention, according to the twenty-sixth aspect, generating the digital wallet includes generating a hierarchical deterministic wallet that generates multiple cryptographic keys from a seed.
[0032] In a twenty-eighth aspect of the present invention, according to any one of the twenty-sixth or twenty-seventh aspects, the digital wallet supports multiple currencies.
[0033] In a twenty-ninth aspect of the present invention, according to any one of aspects twenty-six to twenty-eight, the method further comprises providing notifications and real-time updates on transaction status and compliance checks via the user device.
[0034] In the thirtieth aspect of the present invention, a system includes a processor and a memory storing instructions. When the processor executes the instructions, the processor will perform operations, including receiving user information associated with a user by a first computing device; determining a DID associated with the user based on the user information by the first computing device; providing the DID to a user device associated with the user by the first computing device; verifying the user identity by verifying the DID and related verifiable credentials by a second computing device; and executing transactions involving the user based on the verified DID by a third computing device.
[0035] In a thirty-first aspect of the present invention, according to the thirtieth aspect, determining the DID includes generating a public-private key pair for the user; associating the DID with the public key of the public-private key pair; and creating a DID document containing the DID and the public key.
[0036] In the thirty-second aspect of the present invention, according to the thirtieth aspect, determining the DID further includes processing user information to generate a verifiable credential containing user identity attributes; associating the verifiable credential with the DID; and digitally signing the verifiable credential using the private key of the issuing entity.
[0037] In a thirty-third aspect of the present invention, according to any one of the thirty-first or thirty-second aspects, the system further includes storing the DID document in a distributed ledger accessible to authorized entities.
[0038] In the thirty-fourth aspect of the present invention, according to any one of aspects 30 to 33, verifying the identity of the user includes receiving a verifiable credential associated with the DID by a second computing device; verifying the verifiable credential using a cryptographic signature associated with the issuing entity; and determining whether the user meets predefined compliance requirements based on identity attributes in the verifiable credential.
[0039] In a thirty-fifth aspect of the present invention, according to any one of aspects 30 to 34, executing a transaction includes initiating a transaction request containing a DID through a user device; and processing the transaction request through a smart contract deployed on a blockchain network.
[0040] In a thirty-sixth aspect of the present invention, according to any one of aspects 30 to 35, wherein executing the transaction includes converting the digital currency into legal tender while protecting user privacy.
[0041] In a thirty-seventh aspect of the present invention, according to any one of aspects 30 to 36, executing the transaction includes determining whether the transaction exceeds a preset transaction limit associated with the user's verified identity attributes; and rejecting the transaction when it is determined that the transaction exceeds the transaction limit.
[0042] In a thirty-eighth aspect of the present invention, according to any one of aspects 30 to 37, the system further includes providing zero-knowledge proofs to auditors to verify compliance without access to underlying transaction details.
[0043] In a thirty-ninth aspect of the present invention, according to any one of aspects 30 to 38, the user information includes identity documents provided in accordance with "Know Your Customer (KYC)" requirements.
[0044] In a 40th aspect of the present invention, according to any one of aspects 30 to 39, the system further includes updating the DID or related verifiable credentials in response to changes in user identity information or compliance status.
[0045] In the forty-first aspect of the present invention, a non-volatile, computer-readable medium stores instructions, and when a processor executes these instructions, the processor will perform operations, including: receiving user information related to a user by a first computing device; determining a DID associated with the user based on the user information by the first computing device; providing the DID to a user device associated with the user by the first computing device; verifying the user identity by verifying the DID and the associated verifiable credentials by a second computing device; and executing a transaction involving the user based on the verified DID by a third computing device.
[0046] In a forty-second aspect of the present invention, according to the forty-first aspect, determining the DID includes generating a public-private key pair for the user; associating the DID with the public key of the public-private key pair; and creating a DID document containing the DID and the public key.
[0047] In the forty-third aspect of the present invention, according to the forty-first aspect, determining the DID further includes processing user information to generate a verifiable credential containing user identity attributes; associating the verifiable credential with the DID; and digitally signing the verifiable credential using the private key of the issuing entity.
[0048] In a 44th aspect of the present invention, according to any one of the 42nd or 43rd aspects, the method further includes storing the DID document in a distributed ledger accessible to an authorized entity.
[0049] In a forty-fifth aspect of the present invention, according to any one of aspects forty-first to forty-fourth, verifying the identity of the user includes receiving a verifiable credential associated with the DID by a second computing device; verifying the verifiable credential using a cryptographic signature associated with the issuing entity; and determining whether the user meets predefined compliance requirements based on identity attributes in the verifiable credential.
[0050] In the forty-sixth aspect of the present invention, according to any one of aspects forty-first to forty-fifth, executing a transaction includes initiating a transaction request containing a DID through a user device; and processing the transaction request through a smart contract deployed on a blockchain network.
[0051] In a forty-seventh aspect of the present invention, according to any one of aspects forty-first to forty-sixth, wherein executing the transaction includes converting the digital currency into legal tender while protecting user privacy.
[0052] In a 48th aspect of the present invention, according to any one of aspects 41 to 47, executing the transaction includes determining whether the transaction exceeds a preset transaction limit associated with the user's verified identity attributes; and rejecting the transaction when it is determined that the transaction exceeds the transaction limit.
[0053] In a forty-ninth aspect of the present invention, according to any one of aspects forty-first to forty-eight, the method further comprises providing zero-knowledge proofs to auditors to verify compliance without access to the underlying transaction details.
[0054] In a fiftieth aspect of the present invention, according to any one of aspects 41 to 49, the user information includes identity documents provided in accordance with "Know Your Customer (KYC)" requirements.
[0055] In a fifty-first aspect of the present invention, according to any one of aspects forty-first to fiftieth, a DID or related verifiable credentials is updated in response to changes in user identification information or compliance status.
[0056] In the fifty-second aspect of the present invention, a system includes a processor and a memory storing instructions, and when the processor executes the instructions, the processor will perform operations, including deploying a smart contract on a blockchain network through a computing device, and the smart contract is configured to verify the DID and related verifiable credentials of users participating in the transaction; based on the verified identity attributes, execute transaction compliance rules; based on the relevant DID, process transactions involving digital currency transfers between users; interact with the smart contract to initiate transactions based on requests received from user devices; and execute transactions through the smart contract after successful verification and compliance checks.
[0057] In the fifty-third aspect of the present invention, according to the fifty-second aspect, executing the transaction includes receiving a transaction through a smart contract deployed on a blockchain network, which transfers a first amount of a first digital asset from a user device associated with a user; and crediting a second amount of a second digital asset to an internal ledger associated with the user's DID through the smart contract, wherein the second amount is determined based on the first amount.
[0058] In a fifty-fourth aspect of the present invention, according to the fifty-third aspect, the system further includes updating the balance in the internal ledger through a smart contract to reflect the transaction involving the second digital asset without transferring actual tokens to the user device.
[0059] In a fifty-fifth aspect of the present invention, according to any one of aspects fifty-third or fifty-four, executing the transaction further includes deducting the user balance of the second digital asset in the internal ledger through the smart contract when initiating a subsequent transaction; and crediting the payee's second digital asset balance in the internal ledger through the smart contract.
[0060] In a fifty-sixth aspect of the present invention, according to the fifty-second aspect, the DID is issued by an authorized and regulated entity selected from a group consisting of financial institutions, government agencies or other regulatory agencies.
[0061] In the fifty-seventh aspect of the present invention, according to the fifty-second aspect, the smart contract includes an authentication module that interacts with the distributed identity recognition module to access the DID document and verify the verifiable credentials.
[0062] In a fifty-eighth aspect of the present invention, according to the fifty-second aspect, executing compliance rules includes determining transaction limits based on the user's verified identity attributes; rejecting transactions that exceed the established transaction limits; or both.
[0063] In a fifty-ninth aspect of the present invention, according to the fifty-second aspect, the smart contract is configured to check the transaction against a regularly updated sanctions list obtained from an authorized source; determine whether any party involved in the transaction is identified as a sanctioned entity; and reject the transaction if the transaction involves a sanctioned entity.
[0064] In the sixtieth aspect of the present invention, according to the fifty-ninth aspect, the sanctions list is dynamically updated by obtaining an updated sanctions list from a regulatory agency or a trusted data source.
[0065] In a sixty-first aspect of the present invention, according to the fifty-ninth aspect, determining whether a transaction is prohibited includes analyzing the DIDs of the parties to the transaction; comparing the DIDs with the sanctions list; and marking the transaction if a match is found.
[0066] In a sixty-second aspect of the present invention, according to the fifty-second aspect, the smart contract processes privacy-enhanced transactions by verifying zero-knowledge proofs provided by users without accessing sensitive transaction data.
[0067] In a sixty-third aspect of the present invention, according to the sixty-second aspect, the system further includes maintaining anonymous status updates on the blockchain network to protect transaction privacy.
[0068] In the sixty-fourth aspect of the present invention, according to the fifty-second aspect, the system further includes updating compliance parameters in the smart contract through the authorization management function to respond to changes in regulatory requirements.
[0069] In a sixty-fifth aspect of the present invention, according to the fifty-second aspect, the execution of a transaction, subject to successful verification, involves transferring one or more currency tokens between user accounts on a blockchain network.
[0070] In the sixty-sixth aspect of the present invention, a non-volatile, computer-readable medium stores instructions, and when a processor executes these instructions, the processor will perform operations, including: deploying a smart contract on a blockchain network through a computing device, and the smart contract is configured to verify the DID and related verifiable credentials of users participating in the transaction; executing transaction compliance rules based on the verified identity attributes; processing transactions involving digital currency transfers between users based on the relevant DID; interacting with the smart contract to initiate transactions based on requests received from user devices; and executing transactions through the smart contract after successful verification and compliance checks.
[0071] In the sixty-seventh aspect of the present invention, according to the sixty-sixth aspect, executing the transaction includes receiving a transaction through a smart contract deployed on a blockchain network, which transfers a first amount of a first digital asset from a user device associated with a user; and crediting a second amount of a second digital asset to an internal ledger associated with the user's DID through the smart contract, wherein the second amount is determined based on the first amount.
[0072] In a sixty-eighth aspect of the present invention, according to the sixty-seventh aspect, the method further includes updating the balance in the internal ledger through the smart contract to reflect the transaction involving the second digital asset without transferring the actual token to the user device.
[0073] In the sixty-ninth aspect of the present invention, according to any one of aspects sixty-seven or sixty-eight, executing the transaction further includes deducting the user balance of the second digital asset on the internal ledger through the smart contract when initiating a subsequent transaction; and crediting the second digital asset balance of the payee on the internal ledger through the smart contract.
[0074] In a seventieth aspect of the present invention, according to the sixty-sixth aspect, the DID is issued by an authorized and regulated entity selected from a group consisting of financial institutions, government agencies or other regulatory agencies.
[0075] In the seventy-first aspect of the present invention, according to the sixty-sixth aspect, the smart contract includes an authentication module that interacts with the distributed identity recognition module to access the DID document and verify the verifiable credentials.
[0076] In the seventy-second aspect of the present invention, according to the sixty-sixth aspect, executing compliance rules includes determining transaction limits based on the user's verified identity attributes; rejecting transactions that exceed the established transaction limits; or both.
[0077] In the seventy-third aspect of the present invention, according to the sixty-sixth aspect, the smart contract is configured to check the transaction against a regularly updated sanctions list obtained from an authorized source; determine whether any party involved in the transaction is identified as a sanctioned entity; and reject the transaction if the transaction involves a sanctioned entity.
[0078] In a seventy-fourth aspect of the present invention, according to the seventy-third aspect, the sanctions list is dynamically updated by obtaining an updated sanctions list from a regulatory agency or a trusted data source.
[0079] In a seventy-fifth aspect of the present invention, according to the seventy-third aspect, determining whether a transaction is prohibited includes analyzing the DIDs of the parties to the transaction; comparing the DIDs with the sanctions list; and marking the transaction if a match is found.
[0080] In a seventy-sixth aspect of the present invention, according to the sixty-sixth aspect, the smart contract processes privacy-enhanced transactions by verifying zero-knowledge proofs provided by users without accessing sensitive transaction data.
[0081] In a seventy-seventh aspect of the present invention, according to the seventy-sixth aspect, the method further includes maintaining anonymous state updates on the blockchain network to protect transaction privacy.
[0082] In the seventy-eighth aspect of the present invention, according to the sixty-sixth aspect, the method further includes updating the compliance parameters in the smart contract through the authorization management function to respond to changes in regulatory requirements.
[0083] In a seventy-ninth aspect of the present invention, according to aspect sixty-six, the execution of a transaction, subject to successful verification, involves transferring one or more currency tokens between user accounts on a blockchain network.
[0084] In an eightieth aspect of the present invention, a system includes a processor and a memory storing instructions, and when the processor executes the instructions, the processor will perform operations including generating a digital wallet associated with a user through a user device, the digital wallet being configured to manage encryption keys for DIDs, privacy-enhancing transactions, and blockchain transactions; associating the digital wallet with the DID through the user device; and performing transactions on a blockchain network using the digital wallet through the user device while maintaining security and privacy.
[0085] In an eighty-first aspect of the present invention, according to the eightieth aspect, generating the digital wallet includes generating a hierarchical deterministic wallet that generates multiple cryptographic keys from a seed.
[0086] In an eighty-second aspect of the present invention, according to any one of the eightieth or eighty-first aspects, the digital wallet supports multiple currencies.
[0087] In an eighty-third aspect of the present invention, according to any one of aspects 80 to 82, the system further comprises providing notifications and real-time updates about transaction status and compliance checks via a user device.
[0088] In an eighty-fourth aspect of the present invention, a non-volatile, computer-readable medium stores instructions that, when executed by a processor, cause the processor to perform operations including: generating a digital wallet associated with a user through a user device, the digital wallet configured to manage encryption keys for DIDs, privacy-enhancing transactions, and blockchain transactions; associating the digital wallet with the DID through the user device; and performing transactions on a blockchain network using the digital wallet through the user device while maintaining security and privacy.
[0089] In an eighty-fourth aspect of the present invention, according to the eighty-fifth aspect, generating the digital wallet includes generating a hierarchical deterministic wallet that generates multiple cryptographic keys from a seed.
[0090] In an eighty-sixth aspect of the present invention, according to any one of the eighty-fourth or eighty-fifth aspects, the digital wallet supports multiple currencies.
[0091] In an eighty-seventh aspect of the present invention, according to any one of aspects eighty-four to eighty-six, the non-volatile, computer-readable medium further stores instructions that, when executed by the processor, cause the processor to perform operations including providing notifications and real-time updates regarding transaction status and compliance checks via a user device.
[0092] The features and technical advantages described in this application are not exhaustive. In particular, many additional features and technical advantages will be apparent to one of ordinary skill in the art from the accompanying drawings and description. Furthermore, it should be understood that the language used in this specification is primarily for ease of reading and instruction and is not intended to limit the scope of the disclosed subject matter. BRIEF DESCRIPTION OF THE DRAWINGS
[0093] Figure 1 According to one aspect of the present disclosure, a privacy-enhanced transaction system is shown.
[0094] Figure 2 According to one aspect of the present disclosure, a smart contract management system for privacy-enhanced transactions is shown.
[0095] Figure 3 According to one aspect of the present disclosure, a system for user verification and identification for privacy-enhanced transactions is shown.
[0096] Figure 4 According to one aspect of the present disclosure, a method for privacy-enhanced transactions is shown.
[0097] Figure 5 According to one aspect of the present disclosure, a smart contract management method for privacy-enhanced transactions is shown.
[0098] Figure 6 According to one aspect of the present disclosure, a method for user verification and identification for privacy-enhanced transactions is shown.
[0099] Figure 7 According to one aspect of the present disclosure, a computer system is shown. DETAILED DESCRIPTION
[0100] Existing central bank digital currency systems often face challenges balancing transaction security, regulatory compliance, and user privacy. While traditional blockchain technology offers transparency and traceability, all or most transaction details are publicly visible on the ledger. This transparency can lead to privacy breaches, as external parties can access sensitive user information and transaction data. This lack of privacy can be a deterrent for users of financial transactions that require confidentiality.
[0101] Furthermore, current identity verification processes are often centralized, relying on databases controlled by banks or government agencies. These centralized systems are vulnerable to data breaches, unauthorized access, and single points of failure, compromising user privacy and system security. Users are often required to repeatedly provide personal information when using different banks' services, leading to inefficiencies and increased risk of data leaks.
[0102] Furthermore, while privacy is crucial, regulatory compliance requires a certain level of traceability to prevent illicit activities such as money laundering and fraud. Existing systems struggle to provide strong privacy protections without compromising regulatory compliance. Lack of interoperability between banks further complicates this issue, as siloed identity verification processes hinder a seamless user experience across financial institutions.
[0103] One solution to this problem is to integrate distributed identity (DID) and privacy-enhancing technologies (PET) into the digital currency system, thereby enhancing user privacy while maintaining transaction security and compliance. The present invention utilizes decentralized identity management to enable users to securely control their identity information. In particular, the technology of the present invention can couple authentication using distributed identity with privacy-enhancing smart contracts, thereby achieving privacy protection of permissioned chains in digital currency transactions. By associating user identities with cryptographic key pairs and storing identifiers on a distributed ledger, the system can reduce reliance on centralized databases and reduce the risk of data leakage and unauthorized access.
[0104] Various advanced cryptographic methods, such as zero-knowledge proofs, are used to ensure transaction privacy. This integration allows users to conduct transactions while maintaining confidentiality regarding their identities and amounts, preventing external observers from identifying transacting parties or analyzing the transaction process. By utilizing privacy proxies and anonymous accounts, the system enables privacy-enhanced transactions that comply with regulatory requirements through selective disclosure and a secure verification process.
[0105] Compliance is achieved by codifying regulatory rules and validating transactions according to predefined policies. This system interacts with a decentralized identity management and privacy-enhancing framework to ensure that only authenticated and authorized users can execute transactions and that all activities comply with Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations. This interconnected approach addresses the limitations of existing systems by providing a scalable and interoperable solution that strikes a balance between privacy, security, and compliance.
[0106] In certain aspects, this disclosure provides techniques for improving privacy and security in central bank digital currency transactions by integrating distributed identity and privacy-enhancing technologies. These techniques may be particularly useful in financial systems where user privacy and regulatory compliance are paramount. For example, users can conduct confidential transactions without exposing personal information or transaction details, thereby reducing the risk of privacy breaches and unauthorized data access.
[0107] By decentralizing identity management through DIDs, the technology provided by this invention can enhance seamless access to services across different banks without the need for repeated identity verification, thereby improving the user experience. The interoperability facilitated by adherence to standards ensures that users can interact securely and efficiently with multiple financial institutions. Furthermore, the use of smart contracts automates compliance enforcement and transaction processing, thereby improving the overall efficiency and reliability of the financial system.
[0108] The integration of PET protects sensitive transaction data while maintaining the integrity and traceability required for regulatory compliance. Users can flexibly choose between standard and privacy-enhanced transactions based on their privacy needs. Furthermore, the system's scalability and performance optimizations improve the functionality of the underlying blockchain infrastructure, supporting high transaction volumes without compromising security or privacy.
[0109] The proposed method can be used in various practical applications to improve the security, privacy, and compliance of digital currency transactions by integrating specific implementations of this technology. In particular, the proposed method leverages decentralized identifiers (DIDs) and privacy-enhancing technologies (PETs) within blockchain networks to address challenges faced by traditional digital currency systems, such as the leakage of sensitive user information and the balance between privacy and compliance.
[0110] For example, a user might want to transfer digital currency to a friend in another country. Using the system described above, the user's financial institution generates a DID after verifying their identity according to Know Your Customer (KYC) requirements. The transaction is then securely conducted through a smart contract, which verifies the DID and ensures compliance without leaking personal data.
[0111] In one example, the technology leverages DIDs and verifiable credentials to securely authenticate users without revealing personal information to multiple entities. Users register with an authorized issuing entity, such as a financial institution or government agency, providing user information that complies with Know Your Customer (KYC) requirements. The system processes this information and generates a DID associated with the user by creating a public-private key pair and associating the DID with the public key. The DID document, containing the DID and public key, is stored on a distributed ledger and can be accessed by authorized entities.
[0112] For example, when a user registers on a bank's digital platform, they provide identification documents and biometric data. The bank generates a DID for the user and stores it on a secure blockchain ledger. Later, when the user initiates a transaction, the bank uses this DID and verifiable credentials to verify their identity, streamlining the process and improving security.
[0113] The user's device receives the DID and associated verifiable credentials, which include digitally signed identity attributes. When conducting a transaction, the user initiates a transaction request containing the DID. The system verifies the DID and associated credentials through cryptographic signatures, verifying the user's identity. Compliance checks are then performed to determine whether the user meets predefined requirements based on the identity attributes in the verifiable credentials.
[0114] For example, a user wants to make a large purchase using digital currency. The digital wallet sends a request with the user's DID. The system verifies this credential to ensure the user meets the compliance requirements for large-scale transactions, ensuring the transaction goes through smoothly.
[0115] This approach enables secure and private digital currency transactions because user identities can be verified without exposing sensitive personal data. The integration of DIDs reduces reliance on centralized databases, lowering the risk of data breaches and unauthorized access.
[0116] For example, users can transact with new suppliers without having to worry about their personal information being leaked. This DID and verifiable credentials enable secure authentication while protecting privacy and reducing the risk of identity theft or fraud.
[0117] In another example, the above method involves deploying a smart contract on a blockchain network to verify DIDs and enforce compliance rules. This smart contract processes transactions involving digital currency transfers between users based on their associated DIDs. It enforces compliance by determining transaction limits based on verified identity attributes and rejecting transactions that exceed the limits. The smart contract also checks transactions against sanctions lists obtained from authorized sources and is regularly updated, rejecting any transactions involving sanctioned entities.
[0118] For example, a user might attempt to send money to a new business partner overseas. The smart contract would verify the DIDs of both parties and perform a compliance check. By accessing updated sanctions lists, the system ensures that neither party has been flagged, ensuring the transaction proceeds securely.
[0119] Furthermore, the proposed method is used to ensure compliance for high-value transactions. The smart contract determines transaction limits based on the user's verified identity and rejects transactions exceeding the limits. Transactions are checked against sanctions lists and any involving sanctioned entities are rejected. Compliance parameters in the smart contract can be updated through authorized management functions to address changes in regulatory requirements. This dynamic functionality enables the system to maintain operational efficiency while maintaining compliance.
[0120] For example, if a regulatory change lowers the transaction limits for some users, the smart contract will be updated accordingly. If a user's identity attributes place them in a lower limit category, any attempt to initiate a large transaction will be automatically rejected. The user will be prompted to complete additional verification to restore their higher transaction limits and ensure compliance with the new regulations.
[0121] This approach also facilitates updating DIDs and associated verifiable credentials in response to changes in a user's identity or compliance status. Users can securely update their information through their user device, and the system processes the update and securely stores the new DID document on the distributed ledger. This ensures that authorized entities have access to the latest information, maintaining data integrity and compliance across different jurisdictions.
[0122] For example, if a user moves to a new country, they can update their address and residency status through their digital wallet. The system will securely update the DID and credentials to ensure that future transactions comply with local regulations and avoid potential compliance issues.
[0123] In summary, the methods proposed in this paper provide a comprehensive solution for enhancing network security, privacy, and compliance in digital currency transactions. By integrating decentralized authentication and privacy-enhancing technologies into blockchain networks, these methods address key challenges in existing digital currency implementations. These technologies enable users to conduct secure and private transactions, efficiently manage digital assets, and ensure compliance with evolving regulatory standards, thereby promoting practical applications in the digital financial sector.
[0124] Figure 1 According to one aspect of the present disclosure, a system 100 is described that includes a user device 106 associated with a user, a first computing device 102 , a second computing device 104 , a third computing device 120 , and a distributed ledger 126 .
[0125] The user device 106 can be any appropriate computing device, such as a smartphone, tablet, or personal computer, through which the user interacts with the system. The first computing device 102, the second computing device 104, and the third computing device 120 can be server computers, cloud computing resources, or any appropriate computing systems configured to implement specific functions within the system 100. For example, the first computing device 102 can be associated with an issuing institution (such as a bank or government organization) responsible for generating decentralized identifiers (DIDs) and verifiable credentials (VCs). The second computing device 104 can be associated with a service provider or entity that needs to verify the user's identity and compliance status. The third computing device 120 can be part of a transaction processing network that processes transactions involving users based on the verified DID 112. Additional details of these computing devices are described below.
[0126] The first computing device 102 is configured to receive user information 108 related to the user. The user information 108 may include identification documents provided in accordance with Know Your Customer (KYC) requirements. For example, the user may submit personal details such as name, address, date of birth, government-issued identification number, biometric data, etc. The user information 108 can be received through a user interface on the user device 106, such as a mobile application or portal that guides the user through a registration process. For example, the user can use the device's camera to take an image of their identification document, or manually enter the required information. The interface can also allow the user to provide biometric data, such as a fingerprint or facial recognition scan, for additional security. This initial registration lays the foundation for the secure payment and transaction examples described below.
[0127] Confirming decentralized identifiers
[0128] The first computing device 102 determines a decentralized identifier (DID) 112 associated with the user based on the user information 108. In some implementations, the DID 112 may be issued by an authorized entity. Authorized entities that may issue DIDs include financial institutions, government agencies, or other regulatory bodies to ensure trustworthiness and compliance in the system. The verifiable credential and / or DID 112 may be digitally signed by an authorized and regulatory entity (e.g., a bank or government agency).
[0129] The determination process may include generating a public key and a private key pair 110 for the user. The public key-private key pair 110 may be generated using a cryptographic algorithm, such as elliptic curve cryptography (ECC) or RSA. For example, the first computing device 102 may use the ECC algorithm and a curve such as secp256k1 to generate a key after receiving the user information 108.
[0130] The public key in the public key pair 110 is associated with a DID 112. The DID 112 may be a unique identifier that complies with a specific standard, such as the Decentralized Identifier (DID) specification of the World Wide Web Consortium (W3C), which is used to reference a user's decentralized identity without revealing personal information. Decentralized identity may refer to a self-sovereign identity model in which users control their own identity information without relying on a central authority.
[0131] A DID document 114 is then created, containing the DID 112 and the associated public key. The DID document 114 may include metadata related to the user's identity, authentication methods, and service endpoints. For example, the DID document 114 may specify cryptographic methods that can be used to authenticate the user, such as a public key or verification method, and include service endpoints for interacting with the identity, such as a URL for obtaining verifiable credentials.
[0132] In addition, the first computing device 102 can process the user information 108 to generate a verifiable credential 118 that includes user identity attributes. The verifiable credential 118 can include statements such as the user's name, date of birth, and citizenship. For example, the verifiable credential may state that the user is over 18 years old, a resident of a certain country, and has a valid driver's license, all of which is cryptographically signed by the issuing authority. These credentials are digitally signed using the private key of a bank or government agency to ensure their authenticity and integrity. The digital signature can use standards such as JSON Web Tokens (JWT) or JSON-LDSignatures.
[0133] The DID document 114 is securely stored in a distributed ledger 126 (which may be a blockchain network accessible to authorized entities). The distributed ledger 126 may be implemented using a blockchain platform (such as Ethereum, Hyperledger Fabric, or other platforms that support smart contracts and data immutability). Authorized entities may include financial institutions, regulatory agencies, or service providers authorized to read or interact with certain data on the ledger. The use of the distributed ledger 126 ensures immutability and transparency while protecting user privacy through encryption technology. In order to securely store the DID file 114 on the distributed ledger 126, the system may use a hash function to record the file's fingerprint without exposing sensitive information. For example, SHA-256 can be used to hash the DID document 114 and store the generated hash value on the ledger, thereby verifying the integrity of the file without revealing the file's contents.
[0134] Provide DID to user devices
[0135] The first computing device 102 provides the DID 112 to a user device 106 associated with the user. The DID 112 and associated credentials are transmitted to the user device 106 using a secure transmission method (e.g., end-to-end encryption or a secure API). The user device 106 uses a secure storage method to store and manage the DID 112 and the private key in the public-private key pair 110. This may involve utilizing a hardware security module (HSM), secure enclaves, or an encrypted storage solution to protect the encryption key.
[0136] The user can interact with a wallet application, which manages identities, keys, and transactions, on the user device 106. Access to the DID 112 and related credentials can be protected using authentication mechanisms such as biometrics (e.g., fingerprint or facial recognition) or multi-factor authentication (MFA), as discussed further below.
[0137] Identity Recognition
[0138] The second computing device 104 can be configured to verify the user's identity by verifying the DID 112 and the associated verifiable credentials 118. The verification process includes receiving the verifiable credentials 118 from the user device 106 via a secure communication protocol (such as HTTPS or a secure messaging framework). In particular, the second computing device 104 can be configured to ensure that the user has a valid DID issued by a regulatory entity to participate in privacy-preserving transactions, ensuring that only authorized users can access privacy functions.
[0139] The second computing device 104 verifies the digital signature on the verifiable credential 118 using an encryption method corresponding to the issuing entity's public key. Typically, this involves retrieving the issuer's public key, which can be obtained from the issuer's DID document on the distributed ledger 126, and using it to verify the signature on the verifiable credential 118. This ensures that the credential is indeed issued by a trusted authority and has not been tampered with. The above verification can ensure that the credential is authentic and has not been tampered with. The verification algorithm may involve signature verification technology provided by a cryptographic library. For example, if the verifiable credential is signed using ECDSA (Elliptic Curve Digital Signature Algorithm), the second computing device 104 uses the ECDSA verification function in the cryptographic library to verify the signature.
[0140] The second computing device 104 then determines whether the user meets one or more predefined compliance requirements 124 based on the identity attributes in the verifiable credential 118. Compliance requirements 124 may involve regulatory conditions that must be met when the user performs a specific transaction or accesses a service. These requirements are defined by laws and regulations relevant to the jurisdiction, such as Know Your Customer (KYC), Anti-Money Laundering (AML), and Combating the Financing of Terrorism (CFT) regulations. Compliance requirements 124 may include age verification, residency status, sanctions screening, and / or other regulatory standards required by laws such as Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) regulations.
[0141] For example, if the user attempts to perform a transaction that requires the user to be at least 18 years old, the second computing device 104 will check the date of birth attribute in the verifiable credential 118 to confirm whether the user meets the requirements. If the user does not meet the compliance requirements 124, appropriate action is taken, such as denying the transaction and notifying the user. This verification process may involve parsing the verifiable credential to extract the date of birth, calculating the user's age, and comparing it to the minimum required age. The system may log the verification attempt and provide feedback to the user through the user device 106, indicating the reason for the denial and any steps required to remedy the situation. As another example, the second computing device 104 may perform sanctions screening by comparing the user's identity attributes to a list of sanctioned individuals provided by a government agency. If a match is found, the system will block the transaction and may report the attempt to the relevant authorities as required by law.
[0142] In some implementations, the first computing device 102 can be configured to perform one or more functions of the second computing device 104. For example, in a system where the issuing institution is also the service provider, the first computing device 102 can handle both DID generation and authentication. In this case, the system 100 may not include a separate second computing device 104. For example, a banking institution may use the first computing device 102 to issue verifiable credentials to its customers and verify these credentials when the customers initiate transactions or access services within the banking ecosystem.
[0143] Transaction Processing
[0144] The third computing device 120 executes a transaction 122 involving the user based on the verified DID 112. The user initiates a transaction request from the user device 106, which includes the DID 112 and necessary transaction details. This transaction request may involve transferring funds, accessing services, or other operations provided by the system 100. For example, the user may use the wallet application on the user device 106 to send a payment to another user by selecting a recipient, entering the amount, and authorizing the transaction using biometric authentication. The transaction details and the user's DID 112 are then sent to the third computing device 120 for processing.
[0145] The transaction request is processed by a smart contract deployed on a blockchain network, which may be part of the distributed ledger 126. The smart contract contains code that executes the transaction rules and logic, ensuring transparency and immutability of the transaction. In some implementations, the system allows the exit mechanism (withdrawing funds from the privacy smart contract) to be configured as permissioned (e.g., requiring DID verification) or permissionless (e.g., not requiring DID verification) based on regulatory requirements.
[0146] In some implementations, when a user initiates a transaction involving a digital currency (e.g., a first digital asset), the user device 106 sends a certain amount of the digital currency to the smart contract. The smart contract is configured to hold the digital currency and credit the user's internal balance with a corresponding amount of a second digital asset (e.g., a privacy token). The privacy token may represent a claim on the held digital currency and is recorded as an unspent transaction output (UTXO) in the smart contract's internal ledger. In some implementations, the actual token (e.g., privacy token) is not transferred to the user's wallet; instead, the balance adjustment may be performed in the smart contract's internal ledger, thereby avoiding identity-related on-chain transfers and thus improving privacy.
[0147] For example, suppose Alice wants to privately send 100 units of a digital currency to Bob. Alice's user device 106 sends a transaction request to the smart contract to transfer 100 units of the digital currency to the smart contract. The smart contract holds the digital currency and credits 100 units of the privacy coin to Alice's internal privacy coin balance. When Alice wants to transfer the privacy coin to Bob, she submits a transaction request to the smart contract, including cryptographic instructions or a zero-knowledge proof. The smart contract verifies the validity of the request without revealing sensitive information, deducts 100 units from Alice's privacy coin balance, and credits 100 units to Bob's internal privacy coin balance. Bob can then redeem the digital currency held by the smart contract, provided any exit permission requirements are met.
[0148] Before executing a transaction 122, the smart contract can verify compliance with one or more regulatory rules. The smart contract enforces these rules by incorporating them into the contract's code logic. It can access the user's verified identity attributes by interacting with the verifiable credential 118 or securely retrieving the necessary information. This may include checking the user's identity attributes and transaction details against predefined standards encoded in the smart contract. For example, the smart contract can enforce transaction limits based on the user's verified identity attributes, such as limiting the transaction amount for users who have not completed enhanced due diligence procedures. The smart contract can obtain the user's compliance status and compare the transaction amount to the allowed limits. If a user has only completed basic KYC procedures, their transaction limits may be lower than those of users who have undergone more rigorous verification.
[0149] If the transaction exceeds a predefined transaction limit associated with the user's compliance status, the smart contract will reject the transaction. The system may then notify the user via the user device 106, providing information on the reason for the rejection and any steps required to resolve the issue.
[0150] In some embodiments, this transaction 122 may involve converting a central bank digital currency (CBDC) or other digital currency into fiat currency through authorized channels while maintaining user privacy. This system securely interfaces with financial institutions and utilizes privacy-preserving techniques such as zero-knowledge proofs to prevent the disclosure of sensitive transaction details, as further described below.
[0151] Regulatory compliance enforcement
[0152] One or more computing devices 102, 104, 120 may be configured to enforce regulatory compliance requirements by applying transaction restrictions based on the user's verified identity attributes and compliance requirements 124. This may include checking the DID 112 against updated sanctions lists obtained from authorized sources, such as government agencies or international organizations.
[0153] Sanctions lists may be regularly reviewed and updated to ensure accuracy. Second computing device 104 compares the user's DID 112 with entries on the sanctions list. If the user is identified as a sanctioned user, the system will block the user from executing transaction 122 and take further action as required by law. For example, when the user attempts to initiate a transaction, second computing device 104 may automatically compare DID 112 with the latest sanctions list. If a match is found, the system will block the transaction and may freeze the user's account. Additionally, a notification may be sent to compliance personnel or relevant authorities with relevant details for further investigation.
[0154] Post-transaction monitoring report
[0155] The computing devices in system 100 can use automated systems to monitor transactions for suspicious activity. This can include detecting patterns of money laundering, fraud, or other illegal activity through analytics or machine learning algorithms. For example, the system might analyze transaction amounts, frequency, and counterparties to identify unusual behavior. The system establishes thresholds and rules to flag transactions requiring further investigation. Flagged transactions may be reported to regulators to fulfill legal obligations while protecting user privacy. The system uses secure reporting channels and may employ techniques such as data anonymization or aggregation to protect user identities during the reporting process.
[0156] Privacy-preserving audits
[0157] System 100 also facilitates privacy-preserving audits by authorized entities without disclosing sensitive user data. By providing auditors with zero-knowledge proofs, they can verify regulatory compliance without accessing the underlying transaction details. Zero-knowledge proofs enable one party to prove the truth of a statement to another without revealing any information beyond the validity of the statement itself. For example, the system can prove that a transaction does not exceed a transaction limit or has passed a sanctions list check without revealing the user's identity or the specific transaction amount.
[0158] The system 100 can maintain immutable audit logs of transactions and compliance checks in a secure ledger, such as the distributed ledger 126. These logs contain records of transaction timestamps, the DIDs involved, compliance check results, and other relevant metadata. Access to the audit logs can be limited to authorized personnel through access control and authentication mechanisms. Using a secure ledger ensures data integrity and compliance with data protection regulations, such as the General Data Protection Regulation (GDPR).
[0159] Update DID and credentials
[0160] The system 100 supports updating the DID 112 or associated verifiable credentials 118 in response to changes in the user's identity information 108 or compliance status. This may occur when a user legally changes their name, updates their address, or completes other verification procedures. The user can initiate the update through the user device 106 and provide the necessary documents or information. The first computing device 102 processes the update, regenerates the verifiable credentials 118 as needed, and updates the DID document 114 on the distributed ledger 126. Protective measures can be taken to prevent unauthorized updates or tampering with identity information. Measures here may include authentication measures, verification steps, and an audit trail to track changes.
[0161] In some implementations, the user device 106 may include a user interface that allows the user to manage their identity, view transaction history, and adjust privacy settings. The system may also support multi-signature transactions, where multiple parties jointly approve transactions, thereby enhancing the security of high-value operations. The computing devices 102, 104, and 120 may communicate over a secure network, utilizing encryption and authentication protocols to protect data in transit. The system may be scalable to handle high transaction volumes by utilizing technologies such as distributed computing and load balancing.
[0162] Figure 2According to one aspect of the present disclosure, a system 200 for smart contract management and transaction processing on a blockchain network 202 is described. The system 200 includes the blockchain network 202, a computing device 204 deploying a smart contract 206, user devices 218 and 226 associated with users A and B, respectively, a transaction 234, and a privacy proxy computing device 236.
[0163] The blockchain network 202 can be any suitable distributed ledger technology platform that supports smart contracts and decentralized applications. For example, Ethereum, Hyperledger Fabric, or other blockchain platforms that allow for programmable transaction logic and consensus mechanisms. The blockchain network 202 includes the distributed ledger 126, which maintains an immutable record of all transactions and smart contract executions within the system 200. The computing device 204 deploys smart contracts 206 on the blockchain network 202. This computing device can be a server computer, a server cluster, or a cloud-based computing resource operated by the entity responsible for managing the smart contract 206.
[0164] The smart contract 206 can be implemented as a self-executing code that is configured to manage transactions involving users based on a decentralized identifier (DID) and related verifiable credentials. The smart contract may include one or more modules that can be implemented as instructions or code. The modules may include an authentication module 208, a compliance enforcement module 210, and a transaction processing module 212. The authentication module 208 interacts with the distributed identity mechanism to verify the DID 222, 230 and related verifiable credentials 224, 232 of the user in the transaction. It accesses the DID document and verifies the verifiable credentials within the smart contract logic to ensure that the user is authenticated and authorized to participate in the transaction. In some implementations, the authentication module 208 can be configured to only allow users holding a valid DID issued by an authorized issuing authority to access the system's privacy-enhancing features, thereby achieving permissioned privacy.
[0165] The compliance enforcement module 210 enforces transaction compliance rules based on verified identity attributes. This module 210 utilizes compliance parameters 214 and compares them against sanctions lists 216 to determine whether the transaction complies with regulatory requirements. This module applies rules that may limit transaction amounts, frequency, or prohibit transactions with sanctioned entities to comply with legal and regulatory standards, as discussed further below.
[0166] The transaction processing module 212 processes a transaction 234 involving a transfer of digital currency between users based on their DIDs. After successful verification and compliance checks, the transaction processing module executes the transaction and updates the account balance associated with the user's DID. The smart contract 206 can store compliance parameters 214 and sanctions list 216 as part of its state or access them through mechanisms provided by the blockchain network 202.
[0167] User devices 218 and 226 are associated with users A and B, respectively. These devices can be smartphones, tablets, laptops, or other computing devices, through which users interact with the system 200. Each user device manages a user's decentralized identifier and verifiable credentials. User device 218 is associated with user A and manages DID 222 and verifiable credentials 224. User device 226 is associated with user B and manages DID 230 and verifiable credentials 232. Users interact with the smart contract 206 through their respective user devices to initiate transactions. User devices 218 and 226 can run one or more wallet applications or decentralized applications (dApps) to handle identity management, credential storage, transaction creation, and communication with the blockchain network 202.
[0168] The privacy proxy computing device 236 can be used to conduct privacy-enhancing transactions on behalf of users. Its functions include submitting transactions to the blockchain network 202, verifying privacy proofs, and processing transaction fees. Acting as an intermediary, the privacy proxy computing device 236 enhances user privacy when interacting with the smart contract 206, ensuring that sensitive information is protected throughout the transaction process.
[0169] The method includes several steps to achieve secure and compliant transaction processing. First, the computing device 204 deploys the smart contract 206 on the blockchain network 202. The smart contract is configured to verify the decentralized identifier and associated verifiable credentials by accessing the DID document and verifying the credentials of the user participating in the transaction. This involves retrieving the DID document from the distributed ledger 126, parsing the identity attributes, and verifying the digital signature using the public key associated with the DID.
[0170] Furthermore, the smart contract enforces compliance rules based on the verified identity attributes. The compliance enforcement module 210 uses compliance parameters 214 (e.g., transaction limits and verification status) and compares them against sanctions lists 216 to ensure that transactions comply with regulatory requirements. It applies rules that may limit transaction amounts, frequency, or prohibit transactions with sanctioned entities.
[0171] The smart contract also handles DID-based transactions. The transaction processing module 212 performs digital currency transfers between users by updating the account balances associated with their DIDs after successful verification and compliance checks. This ensures the accuracy of transaction records and maintains the integrity of the ledger.
[0172] Users interact with smart contracts through their devices. User devices 218 and 226 initiate transactions by generating transaction requests through their wallet applications. These requests include details such as the recipient's DID, the transaction amount, and any required privacy proofs. Transactions can be standard or privacy-enhanced. For privacy-enhanced transactions, user devices 218 and 226 can generate zero-knowledge proofs or other cryptographic proofs to hide sensitive information, thereby enhancing privacy and security.
[0173] User devices submitting transactions to the blockchain network 202 may pass through a privacy proxy computing device 236, which helps manage transaction fees and enhance privacy. The privacy proxy plays a key role in ensuring that the origin of transactions is not revealed, contributing to user anonymity on the network.
[0174] The smart contract 206 executes the transaction after successful authentication and compliance checks. The identity verification module 208 verifies the provided DID and verifiable credentials, confirming the authenticity of the credentials through digital signature verification and validity period checking. The compliance enforcement module 210 enforces compliance rules by determining transaction limits based on the verified identity attributes and checking the sanctions list 216 to ensure that neither party is a sanctioned entity.
[0175] If verification and compliance checks pass, the transaction processing module 212 will update the ledger to reflect the digital currency transfer between users. For privacy-enhanced transactions, this module processes transactions without disclosing sensitive information, maintaining anonymous state updates and protecting user privacy.
[0176] Further details of the system components further illustrate the comprehensiveness of the present solution. The authentication module 208 interfaces with the distributed identity module to access DID documents and verify verifiable credentials. This includes accessing the DID document stored on the distributed ledger 126 to retrieve the public key and service endpoint, verifying the verifiable credential by checking the digital signature against the issuer's public key, and ensuring that the credential has not expired or been revoked and meets the required assurance level. In this way, for privacy-enhanced transactions, the module processes transactions without disclosing sensitive information, maintains anonymous state updates, and protects user privacy by requiring identity verification via DID.
[0177] The compliance enforcement module 210 enforces compliance rules by determining permitted transaction amounts based on the user's verification level. For example, users with basic verification may have lower limits than those with enhanced verification, reflecting the varying trust and risk levels associated with different user profiles. This module performs sanctions list checks by comparing a user's DID against a sanctions list 216 obtained from regulatory authorities. Sanctions lists are dynamically updated by retrieving data from trusted sources and integrating it into smart contract checks, ensuring the system complies with current regulations. Specifically, in some implementations, sanctions checks are performed on public blockchain transactions by referencing an on-chain oracle or sanctions list to verify that neither the payer nor the recipient's address is sanctioned. Additionally or alternatively, the DID issuing entity may perform sanctions checks against known lists before issuing, updating, or allowing a DID to create transactions. In some implementations, if a user is added to a sanctions list after obtaining a DID, the DID issuer may revoke the DID. This revocation can be recorded on-chain, immediately preventing the DID from being used for future transactions.
[0178] Trading bans are enforced by rejecting transactions that exceed limits or involve sanctioned entities. Users are notified of rejected transactions via their device, providing transparency and guidance on taking necessary corrective action.
[0179] The transaction processing module 212 handles transaction execution by transferring tokens between user accounts, which are associated with their DIDs. These tokens may conform to blockchain-specific standards, such as ERC-20 for fungible tokens, to promote compatibility and interoperability within the blockchain ecosystem. This module performs privacy-enhanced transactions, using zero-knowledge proofs or other privacy methods to conceal amounts and participant identities from the public ledger. This module ensures atomicity and security by processing transactions atomically to prevent partial execution and leveraging blockchain security features to mitigate attacks, maintaining system integrity and reliability.
[0180] The privacy proxy computing device 236 enhances user privacy by submitting transactions to the blockchain network 202 on behalf of the user, thereby masking the source of the transaction. It can verify the validity of privacy proofs before submission to prevent fraudulent activity and handle transaction fees (gas fees), which may be subsidized or managed to optimize costs. Strategies such as batching transactions or using second-layer solutions can be adopted (e.g., to improve efficiency and reduce expenses). In some implementations, the computing device 236 can be associated with a financial institution. In some implementations, the computing device 236 can be an exemplary implementation of the computing devices 104, 120, or a combination thereof.
[0181] Figure 3A system 300 is shown for managing user wallets and key integration on a user device 302 associated with a user 304. The system enables the user device 302 to generate a digital wallet 306 for managing decentralized identities (DIDs), privacy-enhancing transactions, and cryptographic keys for blockchain transactions. The digital wallet 306 is associated with the user's DID and allows the user 304 to perform transactions on the blockchain network 202 while maintaining security and privacy.
[0182] Generate a digital wallet
[0183] The user device 302 generates a digital wallet 306 associated with the user 304. The digital wallet 306 is configured to manage cryptographic keys 308 required for various functions, including DID management, privacy-enhanced transactions, and standard blockchain transactions. After launching the wallet application on the user device 302, the user 304 is guided through a setup process, which may include creating a wallet, such as a hierarchical deterministic (HD) wallet.
[0184] The wallet can generate, receive, or otherwise determine multiple cryptographic keys from a single seed phrase 316, such as in accordance with standards such as BIP32 and BIP44. The seed phrase 316, such as a mnemonic seed phrase (e.g., a multi-word phrase generated in accordance with the BIP39 standard), can serve as the foundation of the wallet's security and as the source of all cryptographic keys. For example, the seed phrase 316 can be "Right Horse Red Lodge."
[0185] The digital wallet 306 manages various cryptographic keys 308, each tailored for a specific function within the system. The DID management key 310 is used to create, update, and control a user's decentralized identifier (DID), ensuring that identity operations comply with the W3C Decentralized Identifier (DID) standard. The private transaction key 312 is a dedicated key used to generate cryptographic proofs, such as zero-knowledge proofs, in privacy-enhanced transactions, enabling users to conduct confidential transactions on the blockchain network 22. In addition, the blockchain transaction key 314 is used to sign standard transactions on the blockchain network 202, such as the transfer of digital assets or tokens. Separating these keys from identity keys can improve security and reduce the risk of linking identity to transaction activities.
[0186] To protect access to the digital wallet 306 and encryption key 308, the user device 302 employs multi-factor authentication (MFA) via a multi-factor authentication module 318. The MFA may include some combination of something the user knows (e.g., a password or PIN), something the user has (e.g., the device itself), and something the user is (biometric data). Biometric security may be further enhanced by a biometric security module 320 that authenticates the user 304 using device features such as a fingerprint scanner or facial recognition hardware. The private key associated with the encryption key 308 is encrypted and securely stored on the user device 302. Secure key storage may utilize hardware-enabled security features such as a Trusted Execution Environment (TEE) or a secure enclave, employing strong encryption algorithms such as AES-256 to protect data at rest.
[0187] Linking the e-wallet to the user's DID
[0188] The user device 302 associates the digital wallet 306 with the user's DID, thereby establishing a connection between the user's identity and their wallet functionality. This process involves creating or importing a unique identifier (DID) that complies with the W3C DID specification. The digital wallet 306 assists the user 304 in generating a new DID or importing an existing DID, and associates a DID management key 310 with the DID for identity management operations, such as updating or revoking the DID document. The DID document contains the DID and the associated public key, and may include metadata, authentication methods, and user identity information related to the service endpoint.
[0189] By using cryptographic keys in the digital wallet 306 for different functions—identity management, transaction signing, and generating privacy proofs—the system improves security and user control. Key separation reduces risk by isolating keys, ensuring that even if one key is compromised, the others remain secure. The wallet utilizes different derivation paths for different key types, adhering to hierarchical deterministic practices. The digital wallet 306 can automatically execute the key rotation process and update the DID document accordingly. Regular key rotation improves security, and users can revoke compromised keys through the wallet, which interacts with a revocation registry on the distributed ledger 126.
[0190] Executing transactions on the blockchain network
[0191] The user device 302 uses the digital wallet 306 to execute transactions on the blockchain network 202 while maintaining security and privacy. The blockchain network 202 can be any suitable distributed ledger technology platform that supports smart contracts and decentralized applications, such as Ethereum or Hyperledger Fabric. Users interact with the wallet application on the user device 302 to initiate transactions. The wallet interface is designed to be intuitive and easy to use, guiding users through the process of creating a transaction request. In certain implementations, when initiating a transaction, the user's digital currency is sent to the smart contract, which holds the digital currency and credits the user's balance to a second current or digital asset (e.g., an internal privacy token balance). The private transfer can then adjust the balance in the smart contract's internal ledger without disclosing the transaction details on the public blockchain. In this case, the digital wallet 306 can be configured to construct the transaction so that tokens are not directly or physically transferred. Instead, the smart contract can be configured to update the internal ledger, deducting the payer's privacy token balance and crediting the payee's balance.
[0192] When initiating a transaction, the user 304 enters the necessary details, such as the recipient's address or DID and the transfer amount. The digital wallet 306 constructs the transaction, including any optional data or messages. Before submitting the transaction, the wallet automatically performs transaction limit and compliance checks by verifying the user's compliance status associated with the relevant DID and verifiable credentials. This includes checking whether the transaction amount complies with predefined transaction limits associated with the user's verified identity attributes and blocking transactions that exceed these limits or violate compliance requirements. For example, if the user 304 has a daily transaction limit of $10,000 based on their compliance status, the wallet may block any transactions exceeding this amount. Compliance checks may also include ensuring that the recipient is not on any sanctions list or flagged for regulatory issues.
[0193] The digital wallet 306 signs transactions using appropriate cryptographic keys. For standard transactions, blockchain transaction keys 314 are used; for privacy-enhanced transactions, private transaction keys 312 generate cryptographic proofs, such as zero-knowledge proofs, that enable transactions to be verified without revealing sensitive information. Privacy-enhancing techniques may also include ring signatures or the use of anonymity sets to obscure transaction patterns.
[0194] The user device 302 can be connected to a privacy proxy computing device (similar to Figure 2 The privacy proxy computing device 236 in the [Context unclear] is connected to the [Context unclear] to conduct privacy-enhanced transactions. The privacy proxy submits transactions on behalf of the user, handles transaction fees (gas fees), and adds a layer of anonymity by obscuring the origin of the transaction.
[0195] The digital wallet 306 supports multiple currencies, enabling users 304 to manage different central bank digital currencies or cryptocurrencies within a unified interface. Users can check balances, conduct cross-currency transactions, and access real-time exchange rates for conversions, thereby enhancing the wallet's versatility and user convenience.
[0196] The digital wallet 306 can provide notifications and real-time updates to inform the user 304 of transaction status and compliance. For example, the user may receive updates about pending transactions, confirmations, or any failures, as well as reminders related to compliance.
[0197] Other features
[0198] The digital wallet 306 includes a recovery mechanism that allows the user 304 to restore the wallet, for example, using a seed phrase 316, secure cloud backup, or a combination thereof. Seed phrase recovery requires entering the seed phrase into the wallet application on a new device, which then regenerates all keys and addresses based on the seed phrase. Secure cloud backup is a feature of the wallet that provides encrypted backups to ensure security in the cloud.
[0199] Integration with banking systems and other computing devices can be achieved through APIs, middleware, and similar means. The wallet 306 can be configured to comply with various industry standards and protocols, such as ISO 20022 for financial information transmission, to ensure compatibility with other systems and services.
[0200] Figure 4-6 Methods 400, 500, and 600 are described according to embodiments of the present disclosure. Figure 4 Initially, method 400 may be implemented on a computer system (e.g., system 100). For example, method 400 may be implemented by computing devices 102, 104, 106. Method 400 may also be implemented by a set of instructions stored on a computer-readable medium, which, when executed by a processor, causes the computing device to perform method 400. Although the following examples are based on Figure 4 The flowchart in the figure is described, but the execution is the same as Figure 4 There are many other ways to perform related actions. For example, the order of some steps can be changed, some steps can be combined with other modules, one or more steps can be repeated, and some steps can be optional.
[0201] In block 402, the method 400 includes receiving, by a first computing device, user information associated with a user. For example, the first computing device 102 may receive user information 108 associated with a user. In some implementations, the user information may include identification documents provided in accordance with "Know Your Customer" (KYC) requirements. The user information 108 may include personal details such as the user's name, address, date of birth, government-issued identification number, and biometric data. The first computing device 102 may receive this information from a user device 106 associated with the user via a secure communication channel.
[0202] In box 404, the method 400 includes determining, by the first computing device, a decentralized identifier (DID) associated with the user based on the user information. For example, the first computing device 102 may determine the DID 112 associated with the user based on the user information 108. Determining the DID may include generating a public-private key pair for the user, associating the DID with the public key of the public-private key pair, and creating a DID document containing the DID and the public key. In some implementations, the DID may be issued by an authorized and regulated entity selected from a group consisting of financial institutions, government agencies, or other regulatory agencies. In some implementations, the first computing device 102 may process the user information 108 to generate a verifiable credential containing user identity attributes. The verifiable credential may be associated with the DID 112 and digitally signed using the private key of the issuing entity.
[0203] In block 406, the method 400 includes providing, by the first computing device, the DID to a user device associated with the user. For example, the first computing device 102 can provide the DID 112 to the user device 106 associated with the user. In some implementations, the DID document containing the DID 112 and the public key can be stored on a distributed ledger 126 accessible to an authorized entity. The user device 106 can securely receive the DID 112 and the associated verifiable credentials 118 from the first computing device 102.
[0204] At block 408, the method 400 includes verifying the DID and the associated verifiable credentials by the second computing device to verify the user's identity. For example, the second computing device 104 may verify the user's identity by verifying the DID 112 and the associated verifiable credentials 118. Verifying the user's identity may include receiving, by the second computing device 104, the verifiable credentials associated with the DID 112, validating the verifiable credentials using a cryptographic signature associated with the issuing entity, and determining whether the user meets predefined compliance requirements based on identity attributes in the verifiable credentials.
[0205] At block 410, method 400 includes executing, by a third computing device, a transaction involving the user based on the verified DID. For example, third computing device 120 may execute transaction 122 involving the user based on verified DID 112. Executing the transaction may include a smart contract receiving a transfer transaction of a first amount of a first digital asset (e.g., digital currency) from the user's device 106. The smart contract may hold the digital currency and credit an internal ledger with a second amount of a second digital asset (e.g., a privacy token) associated with the user's DID, where the second amount is determined based on the first amount. The smart contract may update the balance in its internal ledger to reflect the transaction involving the privacy token without actually transferring the token to the user's device. When the user initiates a subsequent transaction, the smart contract may, based on cryptographic instructions or zero-knowledge proofs provided by the user, deduct the user's privacy token balance from its internal ledger and credit the balance to the recipient's internal ledger. Before executing the transaction, the smart contract may verify compliance with regulatory rules. Compliance verification may include determining whether the transaction exceeds a pre-set transaction limit associated with the user's verified identity attributes and rejecting the transaction if the limit is exceeded.
[0206] In some implementations, enforcing regulatory compliance may involve the second computing device 104 applying transaction restrictions based on the user's verified identity attributes and compliance requirements. This may include checking the DID 112 against an updated sanctions list obtained from an authorized source and preventing the user from performing transactions if the user is identified as a sanctioned user.
[0207] Additionally, the computing devices 102, 104, and 120 may use automated systems to monitor transactions for suspicious activity. Monitoring transactions may include detecting signs of money laundering or fraud through analytics or machine learning algorithms. Once suspicious activity is detected, the system may, while protecting user privacy, report the flagged transaction to regulators in accordance with legal obligations.
[0208] Furthermore, computing devices can help authorized entities conduct privacy-preserving audits without disclosing sensitive user data. Facilitating privacy-preserving audits involves providing auditors with zero-knowledge proofs, allowing them to verify compliance without access to underlying transaction details. The system maintains an immutable transaction audit log and compliance checks in a secure ledger accessible to authorized personnel.
[0209] In some implementations, the user device 106 may update the DID 112 or associated verifiable credentials 118 to correspond to changes in the user's identity information 108 or compliance status. This ensures that the user's information remains up-to-date and in compliance with regulatory requirements.
[0210] Furthermore, transactions performed by the third computing device 120 may involve converting digital currency into fiat currency through authorized channels while protecting user privacy. The system can securely interface with financial institutions to facilitate such conversions without compromising the confidentiality of user transaction details.
[0211] exist Figure 5 In the example, the method 500 can be implemented on a computer system (such as system 200). For example, the method 500 can be implemented by computing devices 204, 218, 226 and smart contract 206. The method 500 can also be implemented by a set of instructions stored on a computer readable medium, and when the processor executes the instructions, the computing device will perform the method 500. Although the following examples are based on Figure 5 The flowchart in the figure is described, but the execution is the same as Figure 5 There are many other ways to do this. For example, the order of some step boxes can be changed, some step boxes can be combined with other step boxes, one or more step boxes can be repeated, and some step boxes can be optional.
[0212] In block 502, the method 500 includes deploying a smart contract on a blockchain network by a computing device. The smart contract is configured to verify the decentralized identifiers (DIDs) and related verifiable credentials of users participating in a transaction, enforce transaction compliance rules based on the verified identity attributes, and process transactions involving digital currency transfers between users based on the users' DIDs. For example, the computing device 204 may deploy a smart contract 206 on the blockchain network 202. In some implementations, the smart contract 206 may be configured to include an authentication module 208 coupled to a distributed identity module to access DID documents and verify verifiable credentials. The smart contract 206 may be configured to enforce compliance rules by determining transaction limits based on the users' verified identity attributes and rejecting transactions that exceed the determined transaction limits. In addition, the smart contract 206 may be configured to check transactions against sanctions lists obtained from regularly updated authorized sources to determine whether any party to the transaction is identified as a sanctioned entity and reject transactions if a sanctioned entity is involved.
[0213] In block 504, the method 500 includes interacting with the smart contract to initiate a transaction. For example, user devices 218 and 226 associated with users A and B may interact with the smart contract 206 to initiate a transaction. Interacting with the smart contract may include the user device sending a transaction to transfer a first amount of a first digital asset to the smart contract. The smart contract may hold digital currency and record a corresponding amount of a second digital asset (privacy token) associated with the user's DID (privacy token) in an internal ledger. The user device may submit cryptographic instructions or zero-knowledge proofs to execute the transaction involving the privacy token in the internal ledger without transferring the actual token to the user device.
[0214] In block 506, the method 500 includes executing the transaction via the smart contract after successful verification and compliance checks. For example, the smart contract 206 may execute the transaction after successfully verifying the user's DID and verifiable credentials, and after enforcing compliance rules based on the verified identity attributes. Executing the transaction may involve deducting the payer's privacy token balance from an internal ledger and crediting the payee's internal ledger balance based on provided cryptographic instructions or zero-knowledge proofs. The smart contract may maintain internal ledgers to prevent double payments and use cryptographic proofs to ensure transaction integrity. In some implementations, executing the transaction may involve transferring digital currency tokens between user accounts on the blockchain network 202 after successful verification. The smart contract 206 can process privacy-enhanced transactions without revealing the user's identity or transaction details. The smart contract 206 can verify the user-provided zero-knowledge proof without accessing sensitive transaction data and maintain anonymous state updates on the blockchain network 202 to protect transaction privacy.
[0215] In some implementations, the smart contract 206 can facilitate privacy-preserving audits by authorized entities without disclosing sensitive user data. Enabling privacy-preserving audits can include generating cryptographic proofs, such as zero-knowledge proofs, to demonstrate compliance with regulatory requirements and providing the cryptographic proofs to authorized auditors to verify transaction compliance without disclosing transaction details.
[0216] Additionally, the smart contract 206 can process transaction fees associated with processing transactions on the blockchain network 202, potentially by submitting transactions on behalf of users through the privacy proxy computing device 236. The privacy proxy computing device 236 can verify the validity of privacy proofs before submitting transactions to the blockchain network 202 and process transaction fees associated with submitting transactions.
[0217] In addition, the smart contract 206 can enforce predefined transaction limits on privacy-enhanced transactions based on the user's verified identity attributes. The smart contract 206 can be developed using a programming language compatible with the blockchain network 202. The compliance parameters in the smart contract 206 can be updated by authorized management functions to address changes in regulatory requirements.
[0218] Furthermore, the method 500 includes performing authentication using a secure communication protocol before submitting the transaction, by the smart contract 206 or a related system, the privacy proxy computing device 236, and the user devices 218 and 226. The smart contract 206 can record the transaction details in an immutable ledger while protecting the user's anonymity through cryptographic techniques.
[0219] In some implementations, sanctions lists may be dynamically updated by retrieving updated sanctions lists from regulators or trusted data sources and integrating the updated lists into the smart contract's compliance checks. Determining whether a transaction is prohibited may include analyzing the DIDs of the parties to the transaction, comparing the DIDs to the sanctions list, and flagging the transaction if a match is found.
[0220] exist Figure 6 In the example, the method 600 can be implemented on a computer system (e.g., system 300). For example, the method 600 can be implemented by the user device 302. The method 600 can also be implemented by a set of instructions stored on a computer readable medium, which, when executed by a processor, causes the computing device to perform the method 600. Although the following examples are with reference to Figure 6 The flowchart in the figure is described, but the execution is the same as Figure 6 There are many other ways to do this. For example, the order of some step boxes can be changed, some step boxes can be combined with other step boxes, one or more step boxes can be repeated, and some step boxes can be optional.
[0221] At block 602, the method 600 includes generating, via a user device, a digital wallet associated with a user, the digital wallet configured to manage cryptographic keys for decentralized identities (DIDs), privacy-enhanced transactions, and blockchain transactions. For example, the user device 302 may generate a digital wallet 306 associated with a user 304, wherein the digital wallet 306 is configured to manage cryptographic keys 308 for decentralized identities (DIDs), privacy-enhanced transactions, and blockchain transactions. In some implementations, generating the digital wallet may include generating a hierarchical deterministic (HD) wallet that generates multiple cryptographic keys from a single seed. In this case, the seed may be derived from a mnemonic seed phrase provided by the user 304. Furthermore, the user device 302 may protect the digital wallet 306 through multi-factor authentication and biometric security measures within the user device 302. The user device 302 may use the mnemonic seed phrase to provide a backup mechanism for the digital wallet 306. The user 304 may restore the digital wallet 306 on a new device using the seed phrase or a secure cloud backup.
[0222] At block 604, the method 600 includes associating the digital wallet with the user's DID via the user device. For example, the user device 302 may associate the digital wallet 306 with the user's DID 112. In some implementations, the user device 302 may separate the cryptographic keys in the digital wallet 306 for different functions, including identity management, transaction signing, and generating privacy proofs. This separation improves security by isolating the keys used for different purposes.
[0223] At block 606, method 600 includes executing a transaction on a blockchain network using a digital wallet by a user device. For example, the user device 302 may use the digital wallet 306 to execute a transaction on the blockchain network 202 while maintaining security and privacy. Executing the transaction may include the user device sending a transaction to transfer an amount of a first digital asset to a smart contract deployed on the blockchain network. The smart contract may hold digital currency and credit the corresponding amount of a second digital asset (a privacy token) associated with the user's DID to its internal ledger. The user device may initiate subsequent transactions by submitting cryptographic instructions or zero-knowledge proofs to the smart contract, which may deduct the user's privacy token balance from its internal ledger and increase the recipient's internal ledger balance. In some implementations, before executing a transaction, the user device 302 verifies the user's compliance status based on the associated DID 112 and verifiable credentials 118, checks the transaction amount against predefined transaction limits associated with the user's verified identity attributes, and prevents transactions that exceed the transaction limits or violate compliance requirements, thereby automatically enforcing transaction limits and compliance checks. Additionally, the user device 302 may use analytics or machine learning algorithms to monitor transactions for suspicious activity and alert the user 304 to potential security issues when suspicious activity is detected.
[0224] Furthermore, the digital wallet 306 can support multiple currencies, enabling the user 304 to manage different digital currencies or cryptocurrencies. The user device 302 can provide notifications and real-time updates on transaction status and compliance checks. The user device 302 can automatically update the software components of the digital wallet 306 to maintain compatibility and security with the blockchain network 202 and comply with regulatory requirements.
[0225] Figure 7A computer system 700 is shown, which can be used to implement one or more devices and / or components discussed herein, such as first computing device 102, second computing device 104, third computing device 120, computing device 204, user devices 106, 218, 226, user device 302, privacy proxy computing device 236, digital wallet 306, and any components associated with systems 100, 200, and 300. In certain embodiments, one or more computer systems 700 perform one or more steps of one or more methods described or illustrated herein. In certain embodiments, one or more computer systems 700 provide functionality described or illustrated herein. In certain embodiments, software running on one or more computer systems 700 performs one or more steps of one or more methods described or illustrated herein, or provides functionality described or illustrated herein. Certain embodiments include one or more portions of one or more computer systems 700. References herein to computer systems may include computing devices, and vice versa. Furthermore, references to computer systems may include one or more computer systems, as appropriate.
[0226] The present disclosure relates to any suitable number of computer systems 700. The present disclosure relates to computer systems 700 that can take any suitable physical form. For example, but not limited to, the computer system 700 can be an embedded computer system, a system-on-chip (SOC), a single-board computer system (SBC) (e.g., a computer-on-module ("COM") or a system-on-module ("SOM"), a desktop computer system, a laptop or notebook system, a mobile device such as a smartphone or tablet (e.g., user devices 106, 218, 226, 302), an interactive information service station, a mainframe computer, a network of computer systems, a hardware wallet, a privacy proxy computing device, a server computer (e.g., computing devices 102, 104, 204), a personal digital assistant (PDA), a blockchain node, a distributed ledger technology platform, an augmented / virtual reality device, or two or more of the above. Various combinations. Where appropriate, the computer system 700 may include one or more computer systems 700, which may be single or distributed, across multiple locations, across multiple machines, across multiple data centers, or stored in the cloud. The cloud may include one or more cloud components in one or more networks. Where appropriate, one or more computer systems 700 may perform one or more steps of one or more methods described or illustrated in the present disclosure without substantial spatial or temporal limitations. For example, but not limited to, one or more computer systems 700 may perform one or more steps of one or more methods described or illustrated in the present disclosure in real time or in batches. Where appropriate, one or more computer systems 700 may perform one or more steps of one or more methods described or illustrated in the present disclosure at different times or at different locations.
[0227] In a particular embodiment, computer system 700 includes a processor 706, memory 704, storage 708, input / output (I / O) interface 710, secure key storage module 716, cryptographic hardware module 718, and communication interface 712. In some embodiments, computer system 700 may include a trusted execution environment (TEE) or secure enclave to enhance the security of cryptographic operations. Although this disclosure describes and illustrates a particular computer system having a particular number of particular components in a particular arrangement, this disclosure is directed to any suitable computer system having any suitable number of any suitable components in any suitable arrangement.
[0228] In certain embodiments, the processor 706 includes hardware for executing instructions, such as instructions that constitute a computer program. For example, and without limitation, to execute instructions, the processor 706 may retrieve (or fetch) instructions from an internal register, an internal cache, memory 704, or storage 708; decode and execute those instructions; and then write one or more results to an internal register, an internal cache, memory 704, or storage 708. In certain embodiments, the processor 706 may include one or more internal caches for data, instructions, or addresses. The present disclosure relates to the processor 706 including any appropriate number of any appropriate internal caches, where appropriate. For example, and without limitation, the processor 706 may include one or more instruction caches, one or more data caches, and one or more translation lookaside buffers (TLBs). The instructions in the instruction caches may be copies of instructions in memory 704 or storage 708, and the instruction caches may speed up the speed at which the processor 706 retrieves those instructions. The data in the data cache may be a copy of data in memory 704 or storage 708 to be operated on by computer instructions; the results of previous instructions executed by processor 706 may be accessed by subsequent instructions or written to memory 704 or storage 708; or any other appropriate data. The data cache may speed up read or write operations of the processor 706. The TLBs may speed up virtual address translation of the processor 706. In some embodiments, the processor 706 may include one or more internal registers for data, instructions, or addresses. Where appropriate, the present disclosure relates to the processor 706 including any suitable number of any suitable internal registers. Where appropriate, the processor 706 may include one or more arithmetic logic units (ALUs), may be a multi-core processor, or include one or more processors 706. In some embodiments, the processor 706 may be specifically designed or configured to perform cryptographic operations, such as generating public-private key pairs, performing digital signature verification, and processing zero-knowledge proofs to enhance privacy-preserving transactions. Although the present disclosure describes and illustrates a particular processor, the present disclosure relates to any suitable processor.
[0229] In certain embodiments, the memory 704 includes main memory for storing instructions executed by the processor 706 or data operated on by the processor 706. For example, but not limited to, the computer system 700 may load instructions from the memory 708 or other sources (e.g., another computer system 700) into the memory 704. The processor 706 may load the instructions from the memory 704 into internal registers or internal caches. To execute the instructions, the processor 706 may retrieve the instructions from the internal registers or internal caches and decode them. During or after executing the instructions, the processor 706 may write one or more results (which may be intermediate results or final results) to the internal registers or internal caches. Subsequently, the processor 706 may write one or more results to the memory 704. In certain embodiments, the processor 706 executes instructions only in one or more internal registers or internal caches or memory 704 (relative to the memory 708 or other locations) and processes data only in one or more internal registers or internal caches or memory 704 (relative to the memory 708 or other locations). One or more memory buses (which may each include an address bus and a data bus) may couple the processor 706 to the memory 704. The bus may include one or more memory buses, which will be further described below. In certain embodiments, one or more memory management units (MMUs) are located between the processor 706 and the memory 704 to facilitate the processor 706 to access the memory 704. In certain embodiments, the memory 704 includes a random access memory (RAM). The RAM can be volatile memory, where appropriate. Where appropriate, the RAM can be dynamic RAM (DRAM) or static RAM (SRAM). In addition, where appropriate, the RAM can be single-port or multi-port RAM. The present disclosure relates to any appropriate RAM. Where appropriate, the memory 704 may include one or more memories 704. In certain embodiments, the memory 704 may store encryption keys, DID documents, verifiable credentials, transaction data, compliance parameters, and sanctions lists required for the functions described herein.
[0230] In certain embodiments, the memory 708 includes a mass storage device for storing data or instructions. For example, but not limited to, the memory 708 may include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disk, a solid-state drive (SSD), an optical disk, magnetic tape, a universal serial bus (USB) drive, or a combination of two or more of the foregoing. Where appropriate, the memory 708 may include removable or non-removable (or fixed) media. Where appropriate, the memory 708 may be located internally or externally to the computer system 700. In certain embodiments, the memory 708 is a non-volatile solid-state memory. In certain embodiments, the memory 708 includes a read-only memory (ROM). Where appropriate, the ROM may be a mask-programmable ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of the foregoing. The mass storage device 708 provided herein may take any suitable physical form. The memory 708 may include one or more storage control units to facilitate communication between the processor 706 and the memory 708 where appropriate. Where appropriate, the memory 708 may include one or more memories 708. Although this disclosure describes and illustrates specific memories, this disclosure is directed to any suitable memories. In certain embodiments, the memory 708 may store blockchain data, distributed ledger records, smart contracts, and audit logs to maintain transaction integrity and compliance records.
[0231] In certain embodiments, the I / O interface 710 includes hardware, software, or a combination of both, providing one or more interfaces for communication between the computer system 700 and one or more I / O devices. Where appropriate, the computer system 700 may include one or more I / O devices. The one or more I / O devices enable communication between an individual (i.e., a user) and the computer system 700. For example, and without limitation, an I / O device may include a keyboard, a keypad, a microphone, a touch screen display, a display, a screen, a display panel, a mouse, a printer, a scanner, a speaker, a still camera, a biometric sensor (such as a fingerprint scanner or a facial recognition camera), a stylus, a tablet computer, a touch screen, a trackball, a video camera, other suitable I / O devices, or a combination of two or more of the foregoing. An I / O device may include one or more sensors. Where appropriate, the I / O interface 710 may include one or more device or software drivers that enable the processor 706 to drive one or more I / O devices. Where appropriate, the I / O interface 710 may include one or more I / O interfaces 710. Although this disclosure describes and illustrates a particular I / O interface, this disclosure is contemplated by any suitable I / O interface or combination of I / O interfaces.
[0232] In certain embodiments, the communication interface 712 includes hardware, software, or a combination of both, providing one or more communication interfaces (e.g., packet-based communication) between the computer system 700 and one or more other computer systems 700 or one or more networks 714. For example, but not limited to, the communication interface 712 may include a network interface controller (NIC) or network adapter for communicating with Ethernet or any other wired network, or a wireless NIC (WNIC) or wireless adapter for communicating with a wireless network, such as a Wi-Fi network. In certain embodiments, the communication interface 712 supports secure communication protocols, such as SSL / TLS, HTTPS, or secure messaging frameworks (e.g., DIDComm) to ensure the secure transmission of sensitive data. This disclosure relates to any suitable network 714 and any suitable communication interface 712 for use with the network 714. For example, but not limited to, the network 714 may include one or more ad hoc networks, personal area networks (PANs), local area networks (LANs), wide area networks (WANs), metropolitan area networks (MANs), the Internet, blockchain networks (e.g., blockchain networks 202, 328), or a combination of two or more thereof. One or more portions of these networks may be wired or wireless. For example, the computer system 700 may be connected to a wireless personal area network (WPAN) (e.g., Bluetooth The computer system 700 may communicate with a wireless network (e.g., a WPAN), a Wi-Fi network, a Wi-MAX network, a cellular telephone network (e.g., a Global System for Mobile Communications (GSM) network), a blockchain peer-to-peer network, or any other suitable wireless network, or a combination of two or more thereof. Where appropriate, the computer system 700 may include any suitable communication interface 712 for any of these networks. Where appropriate, the communication interface 712 may include one or more communication interfaces 712. Although the present disclosure describes and illustrates particular communication interface implementations, the present disclosure is directed to any suitable communication interface implementation.
[0233] The computer system 700 may also include a bus 702. The bus 702 may include hardware, software, or a combination of both, and may enable the various components of the computer system 700 to communicate with each other. For example, but not limited to, the bus 702 may include an accelerated graphics port (AGP) or any other graphics bus, an enhanced industry standard architecture (EISA) bus, a front-side bus (FSB), a HyperTransport (HT) interconnect, an industry standard architecture (ISA) bus, an infinite bandwidth (INFINIBAND) interconnect, a low pin count (LPC) bus, a memory bus, a micro channel architecture (MCA) bus, a peripheral component interconnect (PCI) bus, a PCI-Express (PCIe) bus, a serial advanced technology attachment (SATA) bus, a video electronics standard association local bus (VLB), a controller area network (CAN) bus, or other suitable buses, or a combination of two or more of the above buses. Where appropriate, the bus may include one or more buses. Although the present disclosure describes and illustrates a specific bus, the present disclosure relates to any suitable bus or interconnect.
[0234] In certain embodiments, the computer system 700 may include a secure key storage module 716. This module may be a hardware security module (HSM) or a trusted platform module (TPM) to securely store cryptographic keys used for DID management, transaction signing, and privacy-enhancing transactions. The secure key storage module 716 ensures that private keys are protected from unauthorized access and potential security vulnerabilities.
[0235] Additionally, the computer system 700 may include a cryptographic hardware module 718 for accelerating cryptographic operations. This module may include a dedicated cryptographic processor or accelerator for handling encryption, decryption, digital signature generation and verification, and zero-knowledge proof computations. By offloading these computationally intensive tasks, the cryptographic hardware module 718 can improve performance and efficiency, which is critical for user devices executing privacy-enhanced transactions or smart contracts.
[0236] As used herein, a computer-readable non-transitory storage medium may include one or more semiconductor-based or other types of integrated circuits (ICs) (e.g., field programmable gate arrays (FPGAs) or application-specific integrated circuits (ASICs)), hard disk drives (HDDs), hybrid hard disk drives (HHDs), optical disks, optical disk drives (ODDs), magneto-optical disks, magneto-optical drives, solid-state drives (SSDs), floppy disks, floppy disk drives (FDDs), magnetic tape, RAM drives, secure digital cards or drives, flash memory devices, any other suitable computer-readable non-transitory storage medium, or any suitable combination of two or more of the foregoing. Where appropriate, the computer-readable non-transitory storage medium may be volatile, non-volatile, or a combination of volatile and non-volatile.
[0237] As used herein, "or" is inclusive, not exclusive, unless expressly stated otherwise or the context indicates otherwise. Thus, unless expressly stated otherwise or the context indicates otherwise, "A or B" herein refers to "A, B, or a combination of both." Furthermore, "and" is both conjunctive and singular, unless expressly stated otherwise or the context indicates otherwise. Thus, unless expressly stated otherwise or the context indicates otherwise, "A and B" herein refers to "A and B, conjunctive or singular."
[0238] The scope of this disclosure includes all variations, substitutions, changes, modifications, and alterations to the embodiments described or illustrated herein that would be understood by a person of ordinary skill in the art. The scope of this disclosure is not limited to the embodiments described or illustrated herein. In addition, although this disclosure describes and illustrates corresponding embodiments including specific components, elements, features, functions, operations, or steps, it should be understood by a person of ordinary skill in the art that any of the embodiments herein may include any combination or arrangement of any components, elements, features, functions, operations, or steps described or illustrated herein. In addition, in the appended claims, if a device or system, or a component of a device or system, is adjusted, arranged, used, configured, enabled, operated, or functioned to perform a specific function, then the device, system, component, or specific function is included, regardless of whether the device, system, or component is activated, turned on, or unlocked, as long as it is so adjusted, arranged, used, configured, enabled, operated, or functioned. In addition, although this disclosure describes or illustrates specific embodiments having specific technical advantages, the specific embodiments may not provide, provide some, or all of these technical advantages.
[0239] All disclosed methods and steps described in this disclosure may be implemented using one or more computer programs or components. These components may be provided as a series of computer instructions on any conventional computer-readable or machine-readable medium, including volatile and non-volatile memory, such as RAM, ROM, flash memory, magnetic or optical disks, optical storage, or other storage media. These instructions may be provided in the form of software or firmware, or may be implemented in whole or in part in the form of hardware components, such as an ASIC, FPGA, DSP, or any other similar device. These instructions may be configured to be executed by one or more processors, which, when executing the series of computer instructions, perform or facilitate the performance of all or part of the disclosed methods and steps.
[0240] It should be understood that various changes and modifications to the examples described herein will be apparent to those skilled in the art. Changes and modifications may be made without departing from the spirit and scope of the present invention. Therefore, such changes and modifications should be encompassed by the appended claims.
Claims
1. A method, characterized in that include: receiving, by the first computing device, user information associated with the user; determining, by the first computing device, a decentralized identifier (DID) associated with the user based on the user information; providing, by the first computing device, the DID to a user device associated with the user; verifying, by a second computing device, the identity of the user by verifying the DID and the associated verifiable credentials; The transaction involving the user is executed by a third computing device based on the verified DID.
2. The method according to claim 1, wherein Determining the DID includes: generating a public-private key pair for the user; Associating the DID with the public key of the public-private key pair; Create a DID document containing the DID and the public key.
3. The method according to claim 1, wherein Determining the DID further includes: processing the user information to generate a verifiable credential containing identity attributes of the user; Associating the verifiable credential with the DID; The verifiable credential is digitally signed using the issuing entity's private key.
4. The method according to claim 2, wherein Further comprising storing the DID document in a distributed ledger accessible to authorized entities.
5. The method according to claim 1, wherein The verifying the user identity includes: receiving, by the second computing device, the verifiable credential associated with the DID; verifying the verifiable credential using a cryptographic signature associated with the issuing entity; Determining whether the user meets predefined compliance requirements based on identity attributes in the verifiable credential.
6. The method according to claim 1, wherein The execution transaction includes: Initiating a transaction request including the DID through the user device; Transaction requests are processed through smart contracts deployed on the blockchain network.
7. The method according to claim 1, wherein The executing transaction includes converting digital currency into fiat currency while protecting user privacy.
8. The method according to claim 1, wherein The execution transaction includes: determining whether the transaction exceeds a preset transaction limit associated with the verified identity attribute of the user; The transaction is rejected when it is determined that the transaction exceeds the transaction limit.
9. The method according to claim 1, wherein This further includes providing auditors with zero-knowledge proofs to verify compliance without requiring access to the underlying transaction details.
10. The method according to claim 1, wherein The user information includes identity documents provided in accordance with "Know Your Customer (KYC)" requirements.
11. The method according to claim 1, wherein Further includes updating the DID or related verifiable credentials in response to changes in user identity information or compliance status.
12. A system, characterized in that: include: processor, and a memory storing instructions that, when executed by the processor, cause the processor to perform operations comprising: Deploy a smart contract on the blockchain network, where the smart contract is configured to: Verify the decentralized identifier (DID) and related verifiable credentials of users participating in transactions; Enforce transaction compliance rules based on verified identity attributes; and Process transactions involving digital currency transfers between users based on the relevant DID; interacting with the smart contract to initiate transactions based on requests received from user devices; and After successful verification and compliance checks, the transaction is executed through the said smart contract.
13. The system according to claim 12, wherein: The execution transaction includes: Receiving, via the smart contract deployed on the blockchain network, a transaction to transfer a first amount of a first digital asset from a user device associated with the user; Crediting, by the smart contract, a second amount of a second digital asset to an internal ledger associated with the user's DID, wherein the second amount is determined based on the first amount.
14. The system according to claim 13, wherein The operations further include: The balance in the internal ledger is updated by the smart contract to reflect the transaction involving the second digital asset without transferring actual tokens to the user device.
15. The system according to claim 13, wherein: The executing transaction further comprises: When initiating a subsequent transaction, deducting the user's balance of the second digital asset in the internal ledger through the smart contract; The second digital asset balance of the payee is recorded in the internal ledger through the smart contract.
16. The system of claim 12, wherein: The DID is issued by an authorized and regulated entity selected from a group consisting of financial institutions, government agencies or other regulatory bodies.
17. The system of claim 12, wherein: The smart contract includes an authentication module that is coupled with a distributed identity module to access the DID document and verify the verifiable credentials.
18. The system of claim 12, wherein: The enforcement compliance rules include: Determine transaction limits based on the user's verified identity attributes; Reject transactions that exceed the stated established transaction limit.
19. The system of claim 12, wherein: The smart contract configuration is: Checking transactions against regularly updated sanctions lists obtained from authorized sources; Determine whether any party involved in the transaction in question has been identified as a sanctioned entity; and If the transaction involves a sanctioned entity, the transaction will be rejected.
20. A non-volatile, computer-readable medium having instructions stored thereon, which, when executed by a processor, cause the processor to perform operations comprising: Deploy a smart contract on the blockchain network, where the smart contract is configured to: Verify the decentralized identifier (DID) and related verifiable credentials of users participating in transactions; Enforce transaction compliance rules based on verified identity attributes; and Process transactions involving digital currency transfers between users based on the relevant DID; interacting with the smart contract to initiate transactions based on requests received from user devices; as well as After successful verification and compliance checks, the transaction is executed through the said smart contract.
Citation Information
Cited By
Internet big data processing financial system
CN121682865A
Distributed data use control method and system based on DID and verifiable certificate
CN121690700A