Block chain auditable private transaction method suitable for cross-border trade settlement
By using a double hidden commitment and zero-knowledge proof mechanism on the blockchain, the contradiction between privacy transactions and regulatory audits in cross-border trade is resolved, achieving privacy protection and compliant supervision of transaction information, and ensuring the security and legality of transactions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS
- Filing Date
- 2025-12-01
- Publication Date
- 2026-05-12
AI Technical Summary
Existing blockchain privacy transaction solutions cannot simultaneously meet the requirements of privacy protection and regulatory audit compliance in cross-border trade scenarios, especially in terms of enabling regulatory agencies to flexibly trace the identity of transactions and accurately decrypt transaction amounts.
By constructing an auditable privacy transaction method based on blockchain, and utilizing a double hidden commitment and zero-knowledge proof mechanism, asset certificates containing the identities and amounts of both parties to the transaction are generated. Cryptographic commitments and zero-knowledge proofs are then written onto the blockchain to achieve transaction privacy and auditability. Regulatory agencies can proactively trace identities and decrypt amounts after authorization.
It achieves strong privacy protection for transaction information in cross-border trade, prevents the leakage of sensitive business information, meets compliance and regulatory requirements, provides auditing capabilities for regulatory agencies, and enhances the system's practicality and security in complex business environments.
Smart Images

Figure CN122022798A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of information security cryptography and blockchain technology, specifically to a blockchain-based auditable privacy transaction method applicable to cross-border trade settlement. Background Technology
[0002] Blockchain-based privacy transaction schemes allow multiple parties to execute asset transfer agreements on a public distributed ledger while using cryptographic methods to hide sensitive transaction information, ultimately achieving the covert flow of value. Related technologies can be further used to protect the identity and financial privacy of all parties involved in a transaction, thereby enabling commercially sensitive blockchain applications. Based on this, it can be seen that privacy transactions are fundamental to the application of blockchain in high-value commercial scenarios. Since the introduction of privacy-preserving cryptocurrencies (such as Monero and Zcash), numerous privacy protection schemes have been proposed, some relying on hybrid pools, while others employ zero-knowledge proofs. However, current mainstream research schemes, in order to ensure transaction privacy, generally deprive regulatory agencies of auditing capabilities, and therefore are not suitable for commercial application scenarios subject to strict legal and compliance requirements.
[0003] Imagine a cross-border trade alliance blockchain with multiple companies located in various countries. To achieve efficient settlement, a blockchain-based payment mechanism is needed. Furthermore, authorized regulatory bodies such as customs and tax authorities are required to proactively trace the identities of parties involved in suspicious transactions and decrypt and audit the specific transaction amounts. To address this, trading companies need to adopt a blockchain privacy transaction solution to conceal their business information. Clearly, this requires regulatory bodies not to participate in the construction of each transaction, but to be able to proactively initiate identity disclosure and amount decryption audit algorithms when necessary. Therefore, trading companies should be able to proactively implement privacy transaction processes, while regulatory bodies retain the legally mandated authority to proactively intervene and conduct audits.
[0004] A better solution to the above problems is to build a blockchain-based privacy transaction mechanism that supports regulatory intervention. This involves writing all cryptographic commitments and audit trails generated from transactions into the blockchain. Leveraging the blockchain's inherent properties of data immutability and public verifiability, the validity of transactions can be verified by all nodes. While some researchers have proposed privacy protection schemes that support regulation, most do not support the collaborative auditing needs of regulatory agencies for flexible traceability of transaction identities and precise decryption of transaction amounts in the aforementioned scenarios, or they sacrifice too much efficiency and privacy in implementing these functions.
[0005] This invention proposes a blockchain-based auditable privacy transaction method that categorizes all entities into four types based on their roles in the transaction and regulatory processes: transaction sender companies, transaction receiver companies, regulatory agencies, and consensus nodes. The transaction sender company initiates the privacy transaction protocol and can select the transaction receiver company and set the transfer amount. The transaction receiver company needs to scan and identify the on-chain transaction and use its private key to parse the transaction content. The regulatory agency, throughout the transaction process, does not need to participate in the construction and broadcasting of the transaction, but can, upon authorization, proactively trace the identities of both parties in the on-chain transaction, decrypt the encrypted transaction amount, and verify the statistical transaction amount of a specific entity within a time period. The consensus node is primarily responsible for maintaining the blockchain network and verifying the validity of proofs in the privacy transaction. This invention's method can operate in a blockchain environment without relying on a trusted centralized settlement institution. Cryptographic commitments and zero-knowledge proofs are written into the blockchain at each stage of the transaction, fully utilizing the blockchain's immutable and publicly verifiable data attributes to achieve comprehensive verification of transaction privacy, correctness, and auditability. Summary of the Invention
[0006] The purpose of this invention is to propose a blockchain-based auditable privacy transaction method suitable for cross-border trade settlement, aiming to address the key issue that existing blockchain privacy solutions cannot simultaneously meet the requirements of privacy protection and regulatory audit compliance in cross-border trade scenarios. Privacy protection is achieved by preventing unauthorized parties from obtaining the identities and transaction amounts of transaction participants (importers and exporters) during the settlement process. Precise regulatory design is achieved by allowing regulatory agencies, under authorization, to proactively trace the true identities of both parties, decrypt specific transaction amounts, and statistically verify the total trade volume of specific enterprises within a given time period.
[0007] To achieve the above objectives, this invention provides a blockchain-based auditable privacy transaction method suitable for cross-border trade settlement, comprising the following steps: Step 1: The regulatory agency selects security parameters and collision-resistant hash functions, generates system public parameters, its own master key pair, and audit trapdoors, and writes the public parameters into the initial block of the blockchain; Step 2: Each participating company registers with the regulatory agency, which then generates a public-private key pair that satisfies a specific mathematical relationship for them; Step 3: Based on the recipient company's public key, the transfer amount, and the set of public keys of participating companies in the system, the sending company constructs an asset certificate that hides the identities and amounts of both parties in the transaction, generates a one-time transaction address and audit ciphertext, and generates multiple zero-knowledge proofs to prove the rationality of the transaction; Step 4: Consensus nodes verify the validity of various zero-knowledge proofs in privacy transactions to ensure that transactions are not created or destroyed out of thin air, are not invalid, and that the sender and receiver are identifiable and consistent, and then package valid transactions onto the blockchain; Step 5: The receiving company scans the transactions on the blockchain, identifies and confirms the transactions belonging to itself by calculating the shared secret and using a one-time address matching mechanism; Step 6: After obtaining authorization, the regulatory agency performs statistical auditing operations such as identity tracing and amount decryption on on-chain transactions to achieve compliance supervision of transaction behavior.
[0008] Optionally, the execution process of step 1 includes the following steps: Step 1.1: Regulatory agency Au selects safety parameters The system according to Choose the size of the large prime number Calculate separately and ; Step 1.2: The regulatory agency Au, based on the multiplication group Construct a cyclic subgroup of a large order And randomly select the generator of the group. ; Step 1.3: The regulatory body Au selects a collision-resistant hash function. It satisfies all the properties of a collision-resistant hash function, its input is a string of arbitrary length, and its output is... Element; Step 1.4: The regulatory agency Au runs a random number generation algorithm to select random numbers. As its private key, and calculate As its public key; Step 1.5: Regulatory agency Au constructs system trapdoor ; Finally, the system common parameters are expressed as follows: The regulatory body Au and the consensus node CN will and It was secretly stored as an audit trap.
[0009] Optionally, the execution process of step 2 includes the following steps: Step 2.1: Enterprise Submit registration information to regulatory authorities; Step 2.2: The regulatory agency Au generates a public-private key pair for the enterprise. ,satisfy .
[0010] Optionally, the execution process of step 3 includes the following steps: Step 3.1: Sending Company For each receiving enterprise Calculate asset certificates ,in As a blinding factor, Representative transaction middle The transaction amount. Among them, for the sending company... asset changes And blinding factor For the receiving company asset changes And randomly select blinding factors As for other participating companies asset changes 0 Simultaneously, a blinding factor is randomly selected. The above blinding factor satisfies ; Step 3.2: Sending Company Random selection Calculate one-time address At the same time, the commitment value was made public. ; Step 3.3: Sending Company Random selection ,calculate And generate ciphertext ,in ; Step 3.4: Sending Company To ensure the legitimacy of the transaction, four additional proofs are required. Specifically, step 3.4 includes the following sub-steps: Step 3.4.1: Prove that the transaction did not create or destroy assets out of thin air; this proof is denoted as... First, calculate the product of all asset certificates. ,because and ,so modN, calculated during verification A product of 1 proves that no assets were created or destroyed out of thin air in the transaction. Step 3.4.2: Prove that invalid on-chain transactions with all amounts of 0 are prevented; the proof is denoted as... If the total amount of all companies in a transaction So for any enterprise Its asset certificates Because the regulatory agency Au knew... Then it can be calculated and stored. Therefore, regulatory agencies can compare them sequentially. and Are they equal? If they are equal, then the transaction is invalid. Step 3.4.3: Prove that the consensus node CN can be correctly identified. This means that the transaction cannot be faked as a transfer from another company to itself, and its proof is recorded as follows: First, the consensus node CN sequentially checks each enterprise's... calculate Because the consensus node CN knows... Calculate one by one during verification When a certain At that time, determine As the initiator of the transaction and The corresponding asset certificate is negative; Step 3.4.4: Prove that the same recipient public key is used to generate the one-time address and for ElGamal encryption. Its proof is denoted as First, select a random number. ,calculate Then calculate the challenge value separately. and response value Finally, output the proof. During verification, calculate separately. and challenge value .like This proves that the same recipient public key was used to generate the one-time address and for ElGamal encryption. ; Finally, output the transaction. And write it into the blockchain.
[0011] Optionally, the execution of step 4 may include the following steps: Step 4.1: Consensus Node CN Calculation ,verify Does mod N hold true? If it does, it proves that the transaction did not create or destroy assets out of thin air; Step 4.2: Consensus node CN calculates the transaction initiator's... asset certificates and Are they equal? If they are equal, the transaction is invalid. Step 4.3: Consensus node CN calculates a certain Is it true? If true, then confirm. As the initiator of the transaction and The corresponding asset certificate is negative; Step 4.4: Consensus node CN calculates the challenge value Is this true? If true, it proves that the same recipient public key was used to generate the one-time address and for ElGamal encryption. .
[0012] Optionally, the execution process of step 5 includes the following steps: Step 5.1: Receiving Company First, scan the transaction Tx on the blockchain and calculate the shared secret. Does this equate to a public commitment D? Step 5.2: Receiving Company calculate .like If the transaction is established, then the transaction belongs to the receiving company. .
[0013] Optionally, the execution process of step 6 includes the following steps: Step 6.1: The regulatory agency Au inspects the sending company. Conduct identity tracing. Find those who meet the criteria. Enterprises Then according to Find the corresponding sending company identity; Step 6.2: The regulatory agency Au assesses the receiving company. Identity tracing is conducted. The regulatory body first calculates... Then decrypt. get .calculate ,like According to Find the corresponding receiving company identity; Step 6.3: The regulatory body Au reviews the designated asset certificates. Using audit traps and known sender companies private key calculate This allows us to decipher the transaction amount. ; Step 6.4: Regulatory agency Au requires companies Provided within a time period Aggregated value of asset certificates within Aggregate value of blinding factor The total amount of claimed asset changes Then the regulatory agency Au calculates the theoretical aggregate value. and verify Is it valid? If valid, then the company... In time period Total changes in internal assets precise.
[0014] This invention proposes a blockchain-based auditable privacy transaction method suitable for cross-border trade settlement. Based on a double-hidden commitment and zero-knowledge proof mechanism, it constructs a transaction model with privacy protection capabilities. Regulatory agencies generate public-private key pairs with specific mathematical associations for each participating enterprise, serving as identity credentials for entities participating in privacy transactions within the system. The sending enterprise constructs asset credentials, one-time addresses, and audit ciphertexts that conceal the identities and amounts of both parties in the transaction, and generates a unified zero-knowledge proof to achieve privacy processing of transaction information. The system combines transaction verification, consensus auditing, and supervision. Consensus nodes complete transaction consensus based on the validity of the zero-knowledge proof. The receiving enterprise identifies and receives the transaction by matching the one-time address. After obtaining legal authorization, regulatory agencies can perform operations such as identity tracing, amount decryption, and statistical auditing. This invention achieves strong privacy protection for transaction identity and amount through the double-hidden commitment structure, effectively preventing sensitive business information from being publicly disclosed on the blockchain and reducing the risk of data leakage. Simultaneously, through the auditing mechanism, it empowers regulatory agencies with the ability to audit in accordance with the law while ensuring transaction privacy, enhancing the system's practicality and security in complex business environments such as cross-border trade while meeting compliance requirements. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 This is a flowchart illustrating the steps of an auditable blockchain privacy settlement method applicable to cross-border trade, according to the present invention.
[0017] Figure 2 This is a schematic diagram of an auditable blockchain privacy settlement method applicable to cross-border trade, based on the present invention.
[0018] Figure 3 This is a flowchart illustrating the system initialization protocol in this invention.
[0019] Figure 4 This is a schematic diagram of the privacy transaction construction protocol in this invention.
[0020] Figure 5 This is a schematic diagram of the transaction verification consensus and reception identification protocol in this invention.
[0021] Figure 6This is a flowchart illustrating the regulatory audit protocol in this invention. Detailed Implementation
[0022] Embodiments of the present invention are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.
[0023] Please see Figure 1 This invention provides an auditable blockchain privacy settlement method suitable for cross-border trade, comprising the following steps: Step 1: The regulatory agency selects security parameters and collision-resistant hash functions, generates system public parameters, its own master key pair, and audit trapdoors, and writes the public parameters into the initial block of the blockchain; Step 2: Each participating company registers with the regulatory agency, which then generates a public-private key pair that satisfies a specific mathematical relationship for them; Step 3: Based on the recipient company's public key, the transfer amount, and the set of public keys of participating companies in the system, the sending company constructs an asset certificate that hides the identities and amounts of both parties in the transaction, generates a one-time transaction address and audit ciphertext, and generates multiple zero-knowledge proofs to prove the rationality of the transaction; Step 4: Consensus nodes verify the validity of various zero-knowledge proofs in privacy transactions to ensure that transactions are not created or destroyed out of thin air, are not invalid, and that the sender and receiver are identifiable and consistent, and then package valid transactions onto the blockchain; Step 5: The receiving company scans the transactions on the blockchain, identifies and confirms the transactions belonging to itself by calculating the shared secret and using a one-time address matching mechanism; Step 6: After obtaining authorization, the regulatory agency performs statistical auditing operations such as identity tracing and amount decryption on on-chain transactions to achieve compliance supervision of transaction behavior.
[0024] The following provides further explanation with reference to specific embodiments and execution processes: like Figure 2 As shown, the entity composition of an auditable blockchain privacy settlement method model applicable to cross-border trade according to the present invention is as follows: (1) Physical role The sender enterprise (SEntity) in cross-border trade refers to the exporter or fund transferor. Utilizing the system's privacy transaction construction algorithm, based on the recipient's public key, the transfer amount, and a ring of system public keys, it generates encrypted asset certificates, one-time addresses, and audit trails that conceal the identity and transaction amount. It also constructs corresponding zero-knowledge proofs to ensure the confidentiality and verifiability of transaction information.
[0025] Receiver Enterprise: This refers to the importer or recipient of funds in cross-border trade. It scans transactions on the blockchain, uses its private key to calculate and match one-time addresses, thereby identifying and confirming transactions belonging to it, and completing the receipt and confirmation of assets.
[0026] The Regulatory Authority (RA) acts as a trusted authoritative entity, responsible for system initialization, generating global public parameters, audit trapdoors, and its own master key pair, and generating public and private keys that satisfy specific mathematical relationships for each participating enterprise. Once authorized, the RA can perform identity verification, transaction decryption, and statistical auditing of on-chain transactions to ensure the system's compliant operation.
[0027] Consensus Node: Responsible for maintaining the blockchain network and verifying the validity of various zero-knowledge proofs in privacy transactions, including asset conservation, non-all-zero transactions, sender identifiability, and receiver consistency, ensuring that only valid transactions are recorded on the chain.
[0028] (2) Protocol-related parameters System common parameters are represented as ,in For the product of large prime numbers, For generators of cyclic subgroups, This is a system trapdoor. For collision-resistant hash functions, Public key for regulatory agencies. Transactions. From asset certificate collection One-time address Confidential Audit Documents and zero-knowledge proof Composition. Audit ciphertext Used to conceal the identity of the recipient, and for regulatory agencies to trace the identity of the transaction entity.
[0029] (3) Privacy transaction layer The privacy transaction layer is built during system initialization, which mainly includes two modules: transaction construction and verification.
[0030] 1) Transaction Construction Module: The transaction sender enterprise constructs an asset certificate with a double hidden commitment structure based on the transaction receiver enterprise's public key, the transfer amount, and the public key set ring of the participating enterprises in the current system. It generates a one-time address and audit ciphertext, and generates a unified zero-knowledge proof to ensure the privacy and verifiability of transaction information.
[0031] 2) Transaction verification module: Consensus nodes perform parallel verification of zero-knowledge proofs in privacy transactions to ensure that transactions meet rules such as asset conservation, non-all-zero, sender identification and consistency with receiver. Valid transactions will be packaged and uploaded to the chain.
[0032] (4) Regulatory auditing level This layer, led by the regulatory body, is responsible for issuing identity keys to participating companies, maintaining system public parameters and audit trapdoors, and performing on-chain audit operations under authorization, specifically including: 1) Identity tracing: By decrypting the audit ciphertext and verifying the promised data, the identities of both parties to the transaction can be restored; 2) Amount Decryption: Decrypt the transaction amount using an audit trap and the sender's private key information; 3) Statistical audit: Verify the accuracy of the total transaction amount of a specific enterprise within a time period and support compliance supervision.
[0033] (5) Settlement Execution Layer This layer is responsible for writing verified privacy transactions to the blockchain and ensuring that the receiving company can reliably identify and confirm the transaction. After the transaction is completed, the system updates the asset status of all parties, completing the settlement loop and providing an end-to-end auditable privacy payment channel for cross-border trade.
[0034] (6) User interaction layer Participating companies can initiate or receive privacy transactions, and query transaction status and audit results through this layer. All interaction processes are implemented based on cryptographic protocols to ensure the security and privacy of user operations.
[0035] Furthermore, the execution process of this invention includes four core protocols: system initialization, privacy transaction construction, transaction verification consensus and reception identification protocol, and regulatory audit.
[0036] The system initialization protocol ensures the establishment of a secure foundation and trusted starting point for the entire system. This protocol, executed by the regulatory agency, is responsible for generating global system parameters and audit trapdoors, and for generating verifiable identity key pairs for all participating companies. The privacy transaction construction protocol ensures that the sending company can correctly construct privacy transaction data that simultaneously hides the identities and amounts of both parties, and broadcasts it to consensus nodes in the blockchain network. The transaction verification consensus and reception identification protocol ensures the legitimate on-chain recording of valid transactions through efficient verification and consensus of zero-knowledge proofs by consensus nodes, enabling the receiving company to accurately identify and confirm its on-chain transactions. The regulatory audit protocol provides regulatory agencies with the ability to legally intervene in audits, supporting traceability of transaction identities, decryptability of amounts, and verifiability of statistical information, meeting the compliance and regulatory requirements of cross-border trade while protecting privacy. This system ensures the privacy, validity, and immutability of transaction data through cryptographic commitments, zero-knowledge proofs, and digital signature mechanisms. All critical operations are based on trusted key pairs issued by the regulatory agency.
[0037] The main functions of the system initialization protocol are as follows: The regulatory body is responsible for generating system public parameters and managing keys. First, the regulatory body selects security parameters and generates system public parameters including large prime number products, cyclic group generators, system trapdoors, and collision-resistant hash functions, while also generating its own regulatory key pair. Subsequently, the regulatory body writes the public parameters into the blockchain consensus nodes and secretly stores the audit trapdoor. Each participating company completes identity registration with the regulatory body, which then generates public-private key pairs that satisfy a specific mathematical relationship, ensuring that all participants possess verifiable identity credentials and establishing a trusted foundation for subsequent privacy transactions and audits. Figure 3 The main flow of the system initialization protocol is described.
[0038] The main steps in establishing a privacy transaction protocol are as follows: 1) The sending company of the transaction uses the receiving company's public key and the transfer amount... and the current system participating in the enterprise public key set ring Generate a corresponding set of asset certificates for each enterprise in the ring. The amount sent by the transaction company itself is The transaction amount for the receiving company is The amount for other companies is 2) Simultaneously select a random number, calculate a one-time address, and generate the audit ciphertext calculated using the recipient's public key. 3) The company sending the transaction constructs four zero-knowledge proofs, including a proof of asset conservation. Proof that the transaction amount is not all zero Identifiable proof of the sender's corporate identity And one-time address and ciphertext consistency proof 4) Finally, a complete transaction will be generated. And broadcast it to the consensus nodes in the blockchain. Figure 4 The main process of establishing a privacy transaction agreement is described.
[0039] The main functions of the transaction verification consensus and reception identification protocol are as follows: 1) Consensus nodes receive transactions. Next, we first verify the proof of asset conservation. To confirm that no assets were created or destroyed out of thin air, and then verify that the transaction amount was not all zero. To exclude invalid transactions, the identifiable identity of the transaction sender is then verified. To verify the sender's identity and confirm that the transaction amount is negative, the system finally verifies the consistency between the one-time address of the transaction recipient and the encrypted message. 1) To confirm whether the one-time address and audit ciphertext use the same recipient's public key, ensuring consistency among the transaction recipient enterprises. 2) After all proofs are verified, the consensus node packages the transaction into a block, completes consensus, and writes it to the blockchain. 3) The transaction recipient enterprise scans the blocks on the blockchain, calculates the one-time address using its own private key for each transaction, identifies the transaction belonging to itself, and completes transaction reception and confirmation. Figure 5 The main processes of transaction verification consensus and reception identification protocol are described.
[0040] The main functions of the regulatory audit agreement are as follows: 1) After obtaining authorization, the regulatory agency conducts an audit process on designated transactions, obtaining the public key of the transaction recipient company by decrypting the audit ciphertext to trace the recipient's identity. 2) The regulatory agency uses the audit trapdoor and the sender's private key to verify the asset certificates. Perform a trapdoor operation to decrypt the transaction amount. 3) Regulatory authorities may, upon authorization, require companies to provide aggregated asset certificates for a specified period. Aggregate value of blinding factor and the total amount of claimed asset changes Statistical audits are conducted, and all identity and monetary information can be restored and recorded during the audit process, serving as evidence for cross-border trade compliance verification. Figure 6 The main process of the regulatory audit agreement is described.
[0041] The specific implementation steps of the auditable blockchain privacy settlement method applicable to cross-border trade are as follows: Optionally, the execution process of step 1 includes the following steps: Step 1.1: Regulatory agency Au selects safety parameters The system according to Choose the size of the large prime number Calculate separately and ; Step 1.2: The regulatory agency Au, based on the multiplication group Construct a cyclic subgroup of a large order And randomly select the generator of the group. ; Step 1.3: The regulatory body Au selects a collision-resistant hash function. It satisfies all the properties of a collision-resistant hash function, its input is a string of arbitrary length, and its output is... Element; Step 1.4: The regulatory agency Au runs a random number generation algorithm to select random numbers. As its private key, and calculate As its public key; Step 1.5: Regulatory agency Au constructs system trapdoor ; Finally, the system common parameters are expressed as follows: The regulatory body Au and the consensus node CN will and It was secretly stored as an audit trap.
[0042] Optionally, the execution process of step 2 includes the following steps: Step 2.1: Enterprise Submit registration information to regulatory authorities; Step 2.2: The regulatory agency Au generates a public-private key pair for the enterprise. ,satisfy .
[0043] Optionally, the execution process of step 3 includes the following steps: Step 3.1: Sending Company For each receiving enterprise Calculate asset certificates ,in As a blinding factor, Representative transaction middle The transaction amount. Among them, for the sending company... asset changes And blinding factor For the receiving company asset changes And randomly select blinding factors As for other participating companies asset changes 0 Simultaneously, a blinding factor is randomly selected. The above blinding factor satisfies ; Step 3.2: Sending Company Random selection Calculate one-time address At the same time, the commitment value was made public. ; Step 3.3: Sending Company Random selection ,calculate And generate ciphertext ,in ; Step 3.4: Sending Company To ensure the legitimacy of the transaction, four additional proofs are required. Specifically, step 3.4 includes the following sub-steps: Step 3.4.1: Prove that the transaction did not create or destroy assets out of thin air; this proof is denoted as... First, calculate the product of all asset certificates. ,because and ,so modN, calculated during verification A product of 1 proves that no assets were created or destroyed out of thin air in the transaction. Step 3.4.2: Prove that invalid on-chain transactions with all amounts of 0 are prevented; the proof is denoted as... If the total amount of all companies in a transaction So for any enterprise Its asset certificates Because the regulatory agency Au knew... Then it can be calculated and stored. Therefore, regulatory agencies can compare them sequentially. and Are they equal? If they are equal, then the transaction is invalid. Step 3.4.3: Prove that the consensus node CN can be correctly identified. This means that the transaction cannot be faked as a transfer from another company to itself, and its proof is recorded as follows: First, the consensus node CN sequentially checks each enterprise's... calculate Because the consensus node CN knows... Calculate one by one during verification When a certain At that time, determine As the initiator of the transaction and The corresponding asset certificate is negative; Step 3.4.4: Prove that the same recipient public key is used to generate the one-time address and for ElGamal encryption. Its proof is denoted as First, select a random number. ,calculate Then calculate the challenge value separately. and response value Finally, output the proof. During verification, calculate separately. and challenge value .like This proves that the same recipient public key was used to generate the one-time address and for ElGamal encryption. ; Finally, output the transaction. And write it into the blockchain.
[0044] Optionally, the execution of step 4 may include the following steps: Step 4.1: Consensus Node CN Calculation ,verify Does mod N hold true? If it does, it proves that the transaction did not create or destroy assets out of thin air; Step 4.2: Consensus node CN calculates the transaction initiator's... asset certificates and Are they equal? If they are equal, the transaction is invalid. Step 4.3: Consensus node CN calculates a certain Is it true? If true, then confirm. As the initiator of the transaction and The corresponding asset certificate is negative; Step 4.4: Consensus node CN calculates the challenge value Is this true? If true, it proves that the same recipient public key was used to generate the one-time address and for ElGamal encryption. .
[0045] Optionally, the execution process of step 5 includes the following steps: Step 5.1: Receiving Company First, scan the transaction Tx on the blockchain and calculate the shared secret. Does this equate to a public commitment D? Step 5.2: Receiving Company calculate .like If the transaction is established, then the transaction belongs to the receiving company. .
[0046] Optionally, the execution process of step 6 includes the following steps: Step 6.1: The regulatory agency Au inspects the sending company. Conduct identity tracing. Find those who meet the criteria. Enterprises Then according to Find the corresponding sending company identity; Step 6.2: The regulatory agency Au assesses the receiving company. Identity tracing is conducted. The regulatory body first calculates... Then decrypt. get .calculate ,like According to Find the corresponding receiving company identity; Step 6.3: The regulatory body Au reviews the designated asset certificates. Using audit traps and known sender companies private key calculate This allows us to decipher the transaction amount. ; Step 6.4: Regulatory agency Au requires companies Provided within a time period Aggregated value of asset certificates within Aggregate value of blinding factor The total amount of claimed asset changes Then the regulatory agency Au calculates the theoretical aggregate value. and verify Is it valid? If valid, then the company... In time period Total changes in internal assets precise.
[0047] In summary, the present invention has the following beneficial effects: (1) Through the “double hidden commitment” structure, the identity of the transacting parties and the transaction amount are concealed at the transaction level, which effectively protects the trade secrets in cross-border trade. At the same time, through the regulatory audit system, the regulatory agencies are given the ability to trace the identity of the transaction, decrypt the specific amount, and verify the statistical information under legal authorization, which perfectly solves the regulatory problem of applying privacy blockchain in compliance scenarios. (2) By using a unified zero-knowledge proof protocol, the validity of transaction amount, legality of scope, and consistency of identity can be verified in one go. Consensus nodes can quickly verify the legality of transactions without performing complex decryption operations, which greatly reduces consensus latency and improves system throughput. (3) Through the inherent characteristics of cryptographic commitments and zero-knowledge proofs, double-spending attacks and transaction forgery are fundamentally prevented, ensuring the consistency of the system ledger; at the same time, the exercise of regulatory power depends on its private key and system trapdoor, avoiding the abuse of power by a single centralized institution, and realizing the legitimacy and controllability of regulation. (4) It supports precise auditing of individual transactions (identity, amount) and statistical auditing of total transactions within a time period, meeting the multi-dimensional and multi-granular regulatory needs of relevant departments involved in cross-border trade and enhancing the practicality of the system in complex business environments.
[0048] The above description discloses only one preferred embodiment of the present invention, and should not be construed as limiting the scope of the present invention. Those skilled in the art will understand that all or part of the processes of the above embodiments can be implemented, and equivalent changes made in accordance with the claims of the present invention are still within the scope of the invention.
Claims
1. A blockchain-based auditable privacy transaction method suitable for cross-border trade settlement, characterized in that: Includes the following steps: Step 1: The regulatory agency selects security parameters and collision-resistant hash functions, generates system public parameters, its own master key pair, and audit trapdoors, and writes the public parameters into the initial block of the blockchain; Step 2: Each participating company registers with the regulatory agency, which then generates a public-private key pair that satisfies a specific mathematical relationship for them; Step 3: Based on the recipient company's public key, the transfer amount, and the set of public keys of participating companies in the system, the sending company constructs an asset certificate that hides the identities and amounts of both parties in the transaction, generates a one-time transaction address and audit ciphertext, and generates multiple zero-knowledge proofs to prove the rationality of the transaction; Step 4: Consensus nodes verify the validity of various zero-knowledge proofs in privacy transactions to ensure that transactions are not created or destroyed out of thin air, are not invalid, and that the sender and receiver are identifiable and consistent, and then package valid transactions onto the blockchain; Step 5: The receiving company scans the transactions on the blockchain, identifies and confirms the transactions belonging to itself by calculating the shared secret and using a one-time address matching mechanism; Step 6: After obtaining authorization, the regulatory agency performs statistical auditing operations such as identity tracing and amount decryption on on-chain transactions to achieve compliance supervision of transaction behavior.
2. The blockchain-based auditable privacy transaction method for cross-border trade settlement as described in claim 1, characterized in that, The execution process of step 1 includes the following steps: Step 1.1: Regulatory agency Au selects safety parameters The system according to Choose the size of the large prime number Calculate separately and ; Step 1.2: The regulatory agency Au, based on the multiplication group Construct a cyclic subgroup of a large order And randomly select the generator of the group. ; Step 1.3: The regulatory body Au selects a collision-resistant hash function. It satisfies all the properties of a collision-resistant hash function, its input is a string of arbitrary length, and its output is... Element; Step 1.4: The regulatory agency Au runs a random number generation algorithm to select random numbers. As its private key, and calculate As its public key; Step 1.5: Regulatory agency Au constructs system trapdoor ; Finally, the system common parameters are expressed as follows: The regulatory body Au and the consensus node CN will and It was secretly stored as an audit trap.
3. The blockchain-based auditable privacy transaction method for cross-border trade settlement as described in claim 2, characterized in that, The execution process of step 2 includes the following steps: Step 2.1: Enterprise Submit registration information to regulatory authorities; Step 2.2: The regulatory agency Au generates a public-private key pair for the enterprise. ,satisfy .
4. The blockchain-based auditable privacy transaction method for cross-border trade settlement as described in claim 3, characterized in that, The execution process of step 3 includes the following steps: Step 3.1: Sending Company For each receiving enterprise Calculate asset certificates ,in As a blinding factor, Representative transaction middle The transaction amount. Among them, for the sending company... asset changes And blinding factor For the receiving company asset changes And randomly select blinding factors As for other participating companies asset changes 0 Simultaneously, a blinding factor is randomly selected. The above blinding factor satisfies ; Step 3.2: Sending Company Random selection Calculate one-time address At the same time, the commitment value was made public. ; Step 3.3: Sending Company Random selection ,calculate And generate ciphertext ,in ; Step 3.4: Sending Company To ensure the legitimacy of the transaction, four additional proofs are required. Specifically, step 3.4 includes the following sub-steps: Step 3.4.1: Prove that the transaction did not create or destroy assets out of thin air; this proof is denoted as... First, calculate the product of all asset certificates. ,because and ,so mod N, calculated during verification A product of 1 proves that no assets were created or destroyed out of thin air in the transaction. Step 3.4.2: Prove that invalid on-chain transactions with all amounts of 0 are prevented; the proof is denoted as... If the total amount of all companies in a transaction So for any enterprise Its asset certificates Because the regulatory agency Au knew... Then it can be calculated and stored. Therefore, regulatory agencies can compare them sequentially. and Are they equal? If they are equal, then the transaction is invalid. Step 3.4.3: Prove that the consensus node CN can be correctly identified. This means that the transaction cannot be faked as a transfer from another company to itself, and its proof is recorded as follows: First, the consensus node CN sequentially checks each enterprise's... calculate Because the consensus node CN knows... Calculate one by one during verification When a certain At that time, determine As the initiator of the transaction and The corresponding asset certificate is negative; Step 3.4.4: Prove that the same recipient public key is used to generate the one-time address and for ElGamal encryption. Its proof is denoted as First, select a random number. ,calculate Then calculate the challenge value separately. and response value Finally, output the proof. During verification, calculate separately. and challenge value .like This proves that the same recipient public key was used to generate the one-time address and for ElGamal encryption. ; Finally, output the transaction. And write it into the blockchain.
5. The blockchain-based auditable privacy transaction method for cross-border trade settlement as described in claim 4, characterized in that, The execution process of step 4 includes the following steps: Step 4.1: Consensus Node CN Calculation ,verify Does mod N hold true? If it does, it proves that the transaction did not create or destroy assets out of thin air; Step 4.2: Consensus node CN calculates the transaction initiator's... asset certificates and Are they equal? If they are equal, the transaction is invalid. Step 4.3: Consensus node CN calculates a certain Is it true? If true, then confirm. As the initiator of the transaction and The corresponding asset certificate is negative; Step 4.4: Consensus node CN calculates the challenge value Is this true? If true, it proves that the same recipient public key was used to generate the one-time address and for ElGamal encryption. .
6. The blockchain-based auditable privacy transaction method for cross-border trade settlement as described in claim 5, characterized in that, The execution process of step 5 includes the following steps: Step 5.1: Receiving Company First, scan the transaction Tx on the blockchain and calculate the shared secret. Does this equate to a public commitment D? Step 5.2: Receiving Company calculate .like If the transaction is established, then the transaction belongs to the receiving company. .
7. The blockchain-based auditable privacy transaction method for cross-border trade settlement as described in claim 6, characterized in that, The execution process of step 6 includes the following steps: Step 6.1: The regulatory agency Au inspects the sending company. Conduct identity tracing. Find those who meet the criteria. Enterprises Then according to Find the corresponding sending company identity; Step 6.2: The regulatory agency Au assesses the receiving company. Identity tracing is conducted. The regulatory body first calculates... Then decrypt. get .calculate ,like According to Find the corresponding receiving company identity; Step 6.3: The regulatory body Au reviews the designated asset certificates. Using audit traps and known sender companies private key calculate This allows us to decipher the transaction amount. ; Step 6.4: Regulatory agency Au requires companies Provided within a time period Aggregated value of asset certificates within Aggregate value of blinding factor The total amount of asset changes claimed Then the regulatory agency Au calculates the theoretical aggregate value. and verify Is it valid? If valid, then the company... In time period Total changes in internal assets precise.