A programmable value code and a trusted settlement management method and system across heterogeneous domains

By combining programmable value codes and a unified settlement layer with privacy computing technology, the problems of centralized dependence, value silos, and privacy protection in inter-enterprise settlement systems are solved, enabling efficient, secure, and compliant settlement across heterogeneous domains.

CN122134348APending Publication Date: 2026-06-02SHUYIYUAN (HANGZHOU) DIGITAL TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHUYIYUAN (HANGZHOU) DIGITAL TECHNOLOGY CO LTD
Filing Date
2026-03-20
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing inter-enterprise settlement systems rely heavily on centralized intermediaries, resulting in lengthy processes, high costs, and low efficiency. Traditional blockchain settlement solutions suffer from single value representation and rigid settlement logic in complex business scenarios. Consortium blockchains exhibit 'value silos' when crossing heterogeneous chains or traditional systems. Privacy computing technology has low coupling with blockchain settlement processes and complex state maintenance, making it difficult to simultaneously meet business privacy and regulatory audit requirements.

Method used

Using programmable value codes as the core carrier, a unified settlement layer is constructed, integrating privacy computing technologies such as zero-knowledge proofs and homomorphic encryption. Cross-domain settlement is achieved through a layered modular architecture, and oracles and improved hash time locking mechanisms are introduced. The Nash algorithm is designed to ensure compliance and security.

Benefits of technology

It enables the interoperability and mutual recognition of value carriers and settlement status across heterogeneous domains, improves the flexibility and automation of settlement logic expression, ensures the privacy protection and regulatory compliance of commercially sensitive data, reduces settlement costs, and improves efficiency and transparency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122134348A_ABST
    Figure CN122134348A_ABST
Patent Text Reader

Abstract

This invention belongs to the interdisciplinary field of information technology and fintech, specifically relating to a programmable value code and a trusted settlement management method and system across heterogeneous domains. More specifically, this invention relates to a trusted settlement management scheme that utilizes a value code as a value representation and circulation carrier. It aims to construct a decentralized, highly transparent, auditable, and privacy-protected settlement management platform by integrating distributed ledger technology, smart contracts, privacy computing, and digital identity. This platform is applicable to various business scenarios requiring high trust and automation, such as digital asset clearing, supply chain finance, multi-party transaction reconciliation, and cross-border payment settlement. This invention utilizes the value code as a measure of human value and constructs a nonlinear value normalization axiomatic system across heterogeneous domains. System Integration: 1. A cross-domain value measurement operator based on log-normal distribution, which eliminates dimensional bias between heterogeneous domains through logarithmic space mapping; 2. A settlement and pricing model based on Milgrom's information value equation, which realizes the marginal contribution accounting of data and asset elements; 3. A cross-domain game consensus engine based on Nash algorithm, which ensures the logical consistency and economic security of cross-heterogeneous domain settlement by solving the optimal Nash equilibrium solution of multi-party strategies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the interdisciplinary field of information technology and financial technology, specifically relating to a programmable value code and a trusted settlement management method and system across heterogeneous domains. Background Technology

[0002] With the deepening development of the digital economy, the settlement process in commercial activities is facing multiple challenges in terms of efficiency, cost, transparency, and trust. Traditional centralized settlement systems, such as bank payment clearing networks, third-party payment platforms, and enterprise ERP financial modules, while relatively mature after years of development, have inherent defects that are becoming increasingly prominent under new business models: First, the systems heavily rely on trusted intermediaries, resulting in long and slow settlement processes (especially in cross-border settlements) and high intermediary fees; second, each participating party maintains independent ledgers, information is not shared, the reconciliation process is cumbersome and error-prone, and the cost of resolving settlement disputes is high; third, centralized systems are susceptible to single points of failure and data tampering risks, posing challenges to security and reliability; finally, with increasingly stringent data privacy regulations, protecting sensitive commercial information while ensuring settlement compliance has become a difficult problem.

[0003] In recent years, blockchain technology, with its distributed, immutable, and traceable characteristics, has provided innovative ideas for building new settlement systems. Blockchain-based settlement systems can achieve shared ledgers among participants, simplify reconciliation processes, and automatically execute settlement logic through smart contracts, improving efficiency and transparency. However, existing blockchain settlement solutions still have many limitations: Public blockchain settlement solutions: Public blockchains, represented by Bitcoin and Ethereum, offer completely transparent and permissionless settlements (such as asset transfers). However, directly applying them to enterprise-level settlement scenarios presents significant problems: a) Limited transaction performance (TPS), making it difficult to support high-frequency commercial settlements; b) Completely public transaction information, failing to meet enterprise privacy protection needs; c) Volatile gas fees, leading to uncontrollable settlement costs; d) Lack of effective identity management and regulatory compliance interfaces.

[0004] Consortium blockchain settlement solutions: For inter-enterprise collaboration scenarios, consortium blockchains (such as Hyperledger Fabric and FISCOBCOS) achieve a balance between performance, privacy, and controllability through admission mechanisms, node permission control, and channel isolation. Many projects have already built settlement platforms for supply chain finance and trade finance based on consortium blockchains. Existing technologies typically use on-chain issuance of digital certificates (such as accounts receivable certificates and warehouse receipts) to represent assets, and control their circulation and final settlement through smart contracts. However, These solutions still face challenges: a) Difficulty in interoperability between heterogeneous systems: Different enterprises may use different underlying consortium blockchains or traditional systems, making it difficult for asset certificates to flow across chains / systems, forming "value silos." b) Insufficient support for complex settlement logic: Simple asset transfer contracts are easy to implement, but settlement scenarios involving multiple triggering conditions (such as cash on delivery, installment settlement, performance-based earnouts), multi-party collaborative computation (such as profit sharing, complex tax calculations), and off-chain events (such as logistics receipts, quality inspection reports) require high levels of expressive power and security verification complexity from existing smart contracts. c) Balancing privacy protection and compliance auditing: Although channels can isolate transaction visibility, sensitive commercial data involved in settlement (such as specific transaction prices and amounts) are still completely exposed to nodes within the channel. Simply relying on channel isolation cannot meet the fine-grained privacy computing requirements of "data usable but not visible," while simultaneously meeting the regulatory requirements for auditability of the entire settlement process. d) Insufficient flexibility in value representation: Fixed-format digital asset certificates are difficult to adapt flexibly to various non-standard, complex value contracts (e.g., a trade contract that combines ownership of goods, rights to future revenue, and specific obligations).

[0005] Exploring the Application of Privacy Computation Technology in Settlement: To address data privacy issues, privacy computing technologies such as Secure Multi-Party Computation (MPC), Homomorphic Encryption (HE), and Zero-Knowledge Proofs (ZKP) have been introduced. Existing technical solutions attempt to combine privacy computing with blockchain: a) Off-chain computation with on-chain evidence storage: Data is computed off-chain using MPC or homomorphic encryption, and only the result hash or zero-knowledge proof is submitted to the blockchain for verification. This model protects the original data, but it is usually computationally inefficient, and complex multi-party computation coordination is difficult, with poor tolerance for node downtime. b) Solutions based on specific privacy blockchains: For example, blockchains focused on financial privacy (such as Monero and Zcash) use technologies such as ring signatures and zero-knowledge proofs to hide the parties and amounts in a transaction. However, these public chains are mainly designed for anonymous cryptocurrency payments and are difficult to directly adapt to enterprise settlement scenarios that require identity authentication, complex rules, and support for regulation. c) Privacy computing middleware: Some platforms attempt to build independent privacy computing layers, loosely coupled with the upper blockchain settlement layer. However, this layered architecture often leads to complex consistency maintenance between the settlement state (on-chain) and the privacy computation state (off-chain), increasing the complexity of system design and security risks.

[0006] Preliminary Practices of "Value Codes" or Similar Concepts: "Value codes" can be understood as a digital carrier of value or a certificate of rights. In existing technologies, related concepts include: a) Digital payment QR codes: such as Alipay / WeChat Pay QR codes, which are essentially encoding payment instructions. Their value derives from the credit of the centralized account behind them and does not possess independent value carrying capacity or smart contract execution capabilities.

[0007] b) One item, one code / traceability code: Widely used for product traceability, it links physical product information through a unique code. However, its focus is on information recording and traceability, rather than value transfer and settlement. c) Token: On the blockchain, tokens are the main digital form of value. However, existing token standards (such as ERC-20, ERC-721) focus more on the expression of fungible / non-fungible assets and basic transfers. Support for embedding complex settlement logic, dynamic states, and binding with off-chain conditions still requires a lot of customized development, resulting in insufficient universality and manageability.

[0008] There is an urgent need for an innovative settlement management solution that should be able to: ① design a flexible, programmable value representation unit (“value code”) that not only represents assets but also embeds settlement rules and states; ② build a unified and trusted settlement underlying layer that supports access from heterogeneous environments, enabling interoperability between different on-chain and off-chain values; ③ deeply integrate privacy computing capabilities to ensure the confidentiality of sensitive data during settlement without sacrificing verifiability and auditability; and ④ balance performance, security, privacy, and compliance requirements through systematic architectural design. However, no mature solution has yet emerged that can systematically and comprehensively address all of these challenges. Existing solutions often address single issues, lacking an end-to-end architectural design encompassing value representation, cross-chain interoperability, privacy-preserving computation, and final settlement verification. In particular, there is a significant technological gap in how to securely, efficiently, and privately encode dynamic, conditional settlement logic into a circulating value carrier and ensure its reliable execution and verification in complex multi-party, cross-domain environments.

[0009] This invention is proposed against this backdrop, aiming to overcome the shortcomings of existing technologies and provide a more complete, efficient, and secure trusted settlement management method and system based on value codes. Existing technologies lack a unified measurement benchmark. This invention proposes a value code as a measure of human value. Its technical essence lies in constructing a high-dimensional value topology space. By utilizing probability measure and information entropy theory, nonlinear economic activities in heterogeneous domains are mapped to scalar scales with global consistency, thereby providing a physically accurate 'metric' for cross-domain settlement. Summary of the Invention

[0010] The technical problems that need to be solved in this invention are: This addresses the problems of lengthy processes, high costs, low efficiency, and difficulties in reconciliation caused by the heavy reliance of existing inter-enterprise settlement systems on centralized intermediaries. This addresses the problems of traditional blockchain settlement solutions in complex business scenarios, such as limited value representation, rigid settlement logic, and difficulty in supporting multi-condition triggering and off-chain event coordination. To solve the "value silo" problem that exists in settlement platforms based on consortium blockchains when crossing heterogeneous blockchains or traditional systems, and to achieve mutual recognition of value carriers and settlement status under different trust domains; To address the privacy risks of commercially sensitive data (such as transaction amount, fee rate, and revenue sharing details) being visible to unrelated parties during the settlement process, and to achieve "usable but not visible" settlement data during the calculation and transfer process; This addresses the issues of low coupling between existing privacy computing technologies and blockchain settlement processes, complex state maintenance, poor tolerance for node dynamism, and difficulty in simultaneously meeting business privacy and regulatory audit requirements.

[0011] To address the aforementioned issues, this invention provides a programmable value code and a trusted settlement management method and system for cross-heterogeneous domains. First, a programmable, state-traceable value code is defined as the core value carrier and settlement contract container. Second, a unified settlement layer supporting heterogeneous environment access is constructed to realize the cross-domain issuance, verification, and transfer of the value code. Next, privacy-preserving computation technologies such as zero-knowledge proofs and homomorphic encryption are deeply integrated into the settlement process to ensure data privacy. Finally, through a layered and modular system architecture, fully auditable, efficient, secure, and reliable automated settlement is achieved.

[0012] A programmable value code and a trusted settlement management method across heterogeneous domains, comprising the following steps: Step 1. Definition and Generation of Value Code. A value code is a structured digital object whose data structure includes at least a unique identifier (CodeID), issuer identity, current holder (Holder), intrinsic value description (ValueDescriptor), state machine, associated privacy commitment, and historical operation hash chain (OpHashChain). The state machine defines the state transition rules and triggering conditions within the value code's lifecycle (e.g., creation, locking, splitting, merging, conditional payment, and write-off), and is initialized by the issuer through a verifiable template smart contract. In this invention, the value code is not only a data carrier but also a measure operator of value energy level. (The last sentence appears to be incomplete and possibly refers to a different topic.) The economic activity in the data follows the parameter: The value follows a log-normal distribution. To eliminate cross-domain friction, the system performs the following calibration procedure: First, construct the value probability density: The second step is to calculate the 'energy level fingerprint' of the value code. : The third step is to map the energy levels to a standard range through a normalization transformation. This mechanism ensures that, during cross-domain settlement, the intrinsic value description of the value code possesses cross-platform 'axiomatic' and 'additivity'.

[0013] Step 2. Construction and Heterogeneous Access of the Unified Settlement Layer. A logically unified settlement layer is constructed, which connects to different underlying blockchains (such as Fabric, FISCOBCOS) or traditional trusted databases via adapters. The adapter is responsible for mapping transactions, events, and states of the underlying system to unified "Settlement Primitives" for the settlement layer, including asset anchoring, value code transfer, state verification, and event notification. The settlement layer maintains a lightweight cross-chain state relay network for synchronizing key state change proofs of value codes across different access domains.

[0014] Step 3. Privacy-enhanced settlement logic execution. When a value code state transition is triggered (e.g., payment settlement), the settlement instruction is sent to the privacy-enhancing computation engine. For calculations involving sensitive data (e.g., profit sharing calculation P=Revenue)... The Ratio-Cost algorithm employs homomorphic encryption or secure multi-party computation on ciphertext or fragmented data. After computation, a zero-knowledge proof (such as a zk-SNARK) is generated, proving that the computation process conforms to predefined rules in the value code state machine and that the original input data is not leaked. This proof, along with the ciphertext or hash of the computation result, is submitted to the settlement layer for verification and recording.

[0015] Step 4. Conditional Settlement and Cross-Domain Atomicity Guarantee. For settlements relying on off-chain events (such as logistics receipts), an oracle service is introduced. The oracle submits digitally signed off-chain event data to the settlement layer. After the settlement layer smart contract verifies that the oracle signature and event satisfy the value code state machine conditions, it automatically triggers subsequent settlement steps. Value code operations across multiple heterogeneous domains (such as value code locking on chain A and asset release on chain B) use a combination of an improved Hash Time Locked Contract (HTLC) and relay verification to ensure the atomicity of the operation, i.e., all steps are either successful or all are rolled back. The settlement price is determined using the Milgrom information value equation. In a cross-domain environment, settlement requests... This reduces system uncertainty. Assume the settlement participants are in the information set... The expected posterior benefit is : Settlement fees and marginal incentive coefficients The functional relationship is defined as follows: in This reduces the overhead of cross-chain communication. The equation establishes a mathematical relationship between settlement revenue and value code contribution, solving the problem of value-based pricing in complex heterogeneous networks.

[0016] Step 5. Audit and Regulatory Interface. All settlement operations (regardless of privacy protection) generate an immutable audit trail at the settlement layer. The audit trail includes the operation identifier, the anonymized identity of the participants (e.g., zero-knowledge proof), the value code ID, the state change digest, the verification result (pass / fail) of the privacy computation proof, and a timestamp. Regulatory nodes are authorized to access a more detailed audit view and, if necessary, can request data disclosure of specific transactions from specific participants for compliance review via security protocols. To ensure that settlement fraud does not occur between heterogeneous domains, the system introduces the Nash algorithm. The settlement game is defined as... The system searches for a steady-state solution (Nash equilibrium point) that satisfies the following conditions through multiple iterations: in In order to settle the revenue, The cost of default. Solved using the gradient descent method. : Only when the system state converges to the equilibrium solution Only then will the cross-domain settlement layer release the locked assets. The algorithm mathematically proves that honest settlement is not only a compliance requirement, but also the only solution for maximizing the interests of all participating parties.

[0017] Preferably, in step 1, the state machine of the value code is formally described using a state chart, and its state set is as follows: S = {Issued, Locked, Split_Pending, Merged, Settlement_Triggered, Settled, Canceled}, where the set of transition conditions C includes time conditions, event conditions (such as on-chain / off-chain event hashes), multi-party signature threshold conditions, and logical conditions consisting of verification results from privacy computation proofs. The value code's data structure is serialized and stored in the underlying blockchain or trusted storage; its addressing identifier, CodeID, is globally unique within the unified settlement layer.

[0018] Preferably, in step 2, the unified settlement layer adopts a microservices architecture, and its core modules include: Adapter Management Module (AdapterManager), Primitive Routing Module (PrimitiveRouter), Cross-Domain State Synchronizer (Cross-DomainStateSynchronizer), and Global Naming Service (GlobalNamingService). The adapter implements a standardized set of interfaces I = {SubmitTransaction(tx), QueryState(codeID), ListenEvent(contractAddr), GenerateProof(state)}. The cross-domain state synchronizer lightly synchronizes and verifies the state snapshots of value codes within each domain through Merkle Proof or Vector Commitment.

[0019] Preferably, in step 3, the privacy computing engine has a pluggable architecture and supports multiple backends: Homomorphic encryption libraries (such as SEAL, Paillier), secure multi-party computing frameworks (such as ABY, SPDZ), and Zero-knowledge proof circuit compilers (such as circom, ZoKrates). When the settlement layer verifies the privacy computing proof, it calls the corresponding verification contract or verification key for on-chain verification. For complex computations, a "off-chain - on-chain" hybrid mode of generating proofs off-chain and verifying results on-chain is adopted to balance privacy, efficiency, and settlement finality.

[0020] Preferably, in step 4, the improved hash time-locked cross-domain settlement process is as follows: 1) The payer locks the value code V1 in the source domain, generates a random secret s and its hash H = Hash(s), and sets a timeout T1; 2) H and the locking proof are propagated to the target domain through the relay network; 3) After the receiver verifies the locking proof in the target domain, it locks the corresponding asset V2 within the time limit T2 (T2 < T1) and associates the same hash H; 4) The payer presents the secret s in the target domain to claim V2, resulting in the exposure of s; 5) The relay network captures the exposed s, and after verification in the source domain, automatically releases V1 to the receiver. The entire process is monitored by the relay network to ensure that if any link times out, all locked assets are returned to the original owner.

[0021] Preferably, in step 5, the generation of the audit trail follows the W3C Verifiable Credentials standard format, with key fields described using JSON-LD. The regulatory interface provides an attribute-based access control (ABAC) policy engine, allowing regulators to define complex policies such as "querying details of all transactions where the single settlement amount exceeds a threshold X and occurred within a time period Y." A query request that satisfies the policy triggers a "secure data disclosure protocol" that is executed only after authorization from the participating parties. This protocol may involve multi-party collaborative decryption or the generation of a specific zero-knowledge proof for that query.

[0022] Beneficial effects This invention innovatively proposes and defines "value code," a programmable and stateful composite value carrier, which internalizes settlement rules into the carrier itself, significantly improving the flexibility and automation level of settlement logic expression. It can directly support various complex and non-standardized commercial contract settlement scenarios, overcoming the limitations of traditional tokens or simple digital certificates with their single function.

[0023] This invention effectively shields the technical differences between underlying heterogeneous blockchains or traditional systems by constructing a logically unified settlement layer and designing standardized adapter interfaces. It enables the smooth flow and mutual recognition of value codes and settlement states between different trust domains, fundamentally breaking down "value silos" and laying the foundation for building a unified settlement network across organizations and ecosystems.

[0024] This invention deeply embeds privacy computing technologies (zero-knowledge proofs and homomorphic encryption) into the core of the settlement process, enabling confidential computation and verifiability of sensitive data during settlement. It achieves the goal of "data remains stationary while value moves, data is usable but not visible," fully protecting commercial privacy while ensuring the correctness and auditability of the settlement process through cryptographic primitives such as zero-knowledge proofs, thus meeting the dual requirements of privacy and compliance for financial-grade applications.

[0025] This invention employs a layered, modular, and pluggable architecture, separating concerns such as settlement logic, cross-chain interoperability, privacy computation, and auditing oversight. This results in a system with excellent scalability, maintainability, and configurability. The introduction of oracles and an improved hash time locking mechanism ensures the reliability and atomicity of on-chain and off-chain collaborative settlement. Ultimately, this invention provides a complete technical solution from value representation, cross-domain circulation, and privacy protection to final settlement verification. It can significantly reduce settlement costs, improve settlement efficiency and automation, and enhance the transparency and credibility of the settlement process, providing crucial infrastructure support for the deep integration of the digital economy and the real economy. Detailed Implementation

[0026] This invention primarily addresses the technical problems of existing inter-enterprise settlement systems, including severe reliance on centralization, low efficiency, difficulties in reconciliation, poor interoperability across heterogeneous systems, difficulty in protecting commercial privacy, and insufficient support for complex settlement logic. To achieve an efficient, reliable, and privacy-secure settlement management method and system based on value codes, this invention designs a comprehensive technical solution that uses programmable value codes as the core carrier, a unified settlement layer as the interoperability hub, and deeply integrates privacy computing and cross-domain atomicity guarantee mechanisms. To more clearly describe the technical solution of this invention, the specific implementation methods are detailed below. The specific implementation process of the value code-based reliable settlement management system proposed in this invention is as follows: First, define and implement the value code as the core data object and its full lifecycle management framework; second, construct a logically unified settlement layer that supports multiple adapter access to shield the differences in the underlying heterogeneous environment; next, integrate a pluggable privacy computing engine into this architecture to handle settlement logic involving sensitive data; then, design and implement a settlement execution protocol that supports on-chain and off-chain condition triggering and atomic operations across multiple heterogeneous domains; finally, establish a complete audit tracking and disclosure mechanism that balances privacy protection and regulatory compliance requirements. The platform's basic logical architecture is divided into a value code definition and generation layer, a unified settlement service layer, a heterogeneous environment adaptation layer, a privacy computing service layer, and an audit and supervision interface layer.

[0027] In the specific implementation of the value code definition and generation layer, the value code is designed as a structured, serializable digital object, which is the most basic value-carrying and settlement contract execution unit in the system. Each value code instance is assigned a globally unique identifier upon creation. This identifier uses a cryptographic hash value generated based on the issuer's digital identity, timestamp, and random number to ensure its uniqueness and collision resistance. The data structure of the value code is defined and stored using extensible formats such as JSON or Protocol Buffers. Its core fields include, but are not limited to: an encoding identifier field, used to store the globally unique ID of the value code; an issuer field, storing the issuer's verifiable digital identity, typically generated based on public key infrastructure or distributed identifiers; a holder field, dynamically recording the digital identity of the entity currently legally holding the value code, with an initial value equal to the issuer; a value description field, a structured metadata field used to describe the value represented by the value code in a machine-readable and human-readable manner, such as including asset type, unit of measurement, referenced regulatory standards, and associated physical asset identification codes. This field supports flexible schema definitions to adapt to different business scenarios; and a state machine definition field, the "intelligent" core of the value code, which defines the entire lifecycle of the value code from creation to termination using a formalized language or domain-specific language. The value code includes a set of possible states, the conditions that trigger state transitions, and the actions to be performed after the transition. States can include issued, locked, payment in progress, partially settled, fully settled, revoked, etc. Triggering conditions can be time conditions, specific event proofs from oracles, digital signature sets from multiple participants, specific account balance thresholds, or verification proofs from the computation results of the privacy computing engine, etc. The privacy computing commitment field stores the cryptographic commitment of the computation logic when the settlement logic associated with the value code involves computation of sensitive data. For example, it may be the hash value of a zero-knowledge proof circuit or the public key fingerprint of a homomorphic encryption scheme, used for subsequent verification of the correctness and consistency of the computation. The operation history hash chain field maintains a cryptographic hash chain that records every key state change operation of the value code. Each change updates this field by hashing the previous hash, the content of the current operation, and the timestamp, ensuring the integrity and immutability of the operation history and facilitating traceability and auditing.

[0028] The generation and management of value codes are achieved through a dedicated value code management service module. This module provides a graphical interface and application programming interface (API) for authorized users to design value code templates, create instances, query them, and manage them. When designing a value code template, users can define the value code's state machine through graphical drag-and-drop or by writing domain-specific language scripts. The state machine engine typically uses a finite state machine or state diagram theoretical model, defining states as nodes, transition conditions as edges, and transition actions as associated with predefined smart contract functions or external service calls. After the template definition is complete, it is compiled into an intermediate representation or directly deployed to the underlying blockchain's smart contract, generating a template identifier. When a specific value code instance needs to be issued, the user specifies the template identifier, fills in the specific parameters of the value description fields, and calls the value code management service's issuance interface. The service then generates a unique identifier, initializes the fields, serializes the initial state of the value code, and stores it in the designated underlying trusted storage, typically a blockchain network, through the corresponding adapter. The value code management service also monitors events in the underlying storage, updates the value code's state in real time, and provides a state query service.

[0029] In the implementation of the unified settlement service layer, this layer serves as the central hub of the entire system, responsible for coordinating all settlement-related operations and providing a consistent interaction interface, regardless of the heterogeneous systems connected to the backend. The unified settlement service layer is built using a microservice architecture, with a set of loosely coupled, single-responsibility service components working collaboratively. These core service components include an adapter management service, a settlement primitive routing service, a cross-domain state synchronization service, and a global naming resolution service. The adapter management service is responsible for the registration, discovery, health monitoring, and lifecycle management of all underlying environment adapters. Each adapter is essentially a proxy service that implements a standardized set of interfaces. These standard interfaces include, but are not limited to: a transaction submission interface for submitting signed transaction instructions to the underlying network; a state query interface for querying specific state data on the underlying network based on resource identifiers, such as the current holder of a value code; an event listening interface for subscribing to specific events emitted by the underlying smart contracts or system and converting the event format to the unified event format of the settlement layer; and a state proof generation interface for generating cryptographic existence proofs for a specific state at a specific time, such as Merkle path proofs, upon request. Upon startup, the adapter registers with the adapter management service, declaring the underlying network types, network identifiers, capability lists, and access endpoints it supports. The settlement primitive routing service acts as the traffic hub for settlement instructions. It defines a set of high-level "settlement primitive" operations independent of the underlying layer, such as the "asset anchoring" primitive, which registers and maps external assets at the settlement layer; the "value code transfer" primitive, which requests a change to the holder field of a value code; the "state verification" primitive, which requests verification of whether a value code is in a specific state or meets specific conditions; and the "event notification" primitive, used to notify the relevant settlement logic of cross-domain or off-chain events. When a business application or upper-layer contract initiates a settlement operation, it calls the application programming interface of the settlement primitive routing service, specifying the target resource identifier, primitive type, and parameters. Based on the domain information in the resource identifier, the routing service locates the specific adapter responsible for that domain by querying the global naming resolution service, then translates the primitive into instructions that the adapter can understand, and sends them to the adapter for execution via remote procedure call or message queue. Finally, it encapsulates the adapter's execution result and returns it to the caller.

[0030] Cross-domain state synchronization services are key to solving the "value silo" problem. Since value codes may be created and circulated across different underlying domains, a lightweight way is needed to allow one domain to know and trust the critical state of value codes in another domain to support cross-domain operations. Cross-domain state synchronization services achieve this by maintaining a lightweight relay network focused on state proof delivery. This network consists of light clients or dedicated relay nodes deployed in various domains. When a value code within a domain undergoes a preset critical state change, such as from "issued" to "locked," the domain's adapter, in addition to performing the operation on its local chain, captures this change through an event listening mechanism and calls its state proof generation interface to generate a short cryptographic proof of the value code's state at the new block height. This proof is sent to the cross-domain state synchronization service. The synchronization service, based on pre-configured rules or subscription relationships, broadcasts the state proof and its associated block header information to relay nodes in other relevant domains. After receiving the proof, the relay node in the receiving domain verifies the validity of the block header and the correctness of the state proof using the known light client verification rules of the sending domain's blockchain. Once verification is successful, the receiving domain locally records a snapshot of the latest verifiable state of the value code in the source domain without synchronizing the entire blockchain data. The global naming resolution service provides a distributed directory service similar to the Internet Domain Name System, used to resolve user-friendly, globally unique resource identifiers into specific network locations and access paths. A value code's global identifier might be resolved into specific location information such as "domain A / blockchain X / contract address Y / token IDZ". This allows the settlement layer to transparently locate and access value code resources distributed across any connected domain.

[0031] In the specific implementation of the heterogeneous environment adaptation layer, the adapter is a key component for achieving "unified interface, diverse backends." Different adapters need to be implemented for different types of underlying systems. For consortium blockchains that support smart contracts, such as Hyperledger Fabric, the adapter implementation needs to encapsulate the Fabric SDK. This adapter needs to maintain gRPC connections with multiple nodes in the Fabric network and manage user certificates and private keys for transaction signing. It needs to translate the "value code transfer" primitives issued by the settlement layer into transaction proposals that call corresponding functions on specific chaincodes and submit them to the Fabric network for endorsement, sorting, and submission. At the same time, it needs to continuously monitor events on the Fabric blockchain, especially events from the value code management chaincode, convert them into a unified event format, and send them to the event bus of the settlement layer. For the FISCOBCOS consortium blockchain, the implementation principle of the adapter is similar, but it needs to be based on the BCOS Java or Python SDK and call its Web3j-style interface to interact with nodes. For public or consortium blockchains compatible with the Ethereum Virtual Machine (EVM), the adapter can utilize standard Web3.js or ethers.js libraries to communicate with nodes via JSON-RPC, resulting in a more standardized interaction with smart contracts. For purely traditional databases or centralized systems, the adapter acts more like a trusted gateway. It needs to maintain a special "mirror table" or log in the traditional system to record all state changes initiated through the settlement layer. When it receives instructions from the settlement layer, it executes the corresponding operation in its local business database and simultaneously records a log entry with a digital signature and timestamp in the "mirror table," which itself serves as trusted proof of the state change. It also needs to provide a query interface that allows the settlement layer to verify the state recorded in the "mirror table." All adapters must implement a unified security protocol, including two-way TLS authentication for communication with the settlement layer, encrypted storage of sensitive configuration information, and retry and timeout mechanisms for downstream system calls, ensuring the reliability and security of the connection.

[0032] In the specific implementation of the privacy-preserving computation service layer, this layer provides cryptographic safeguards for settlement computations that require data privacy protection. The privacy-preserving computation service layer is designed with a pluggable architecture, invoked as an independent service module within the settlement process. It typically does not directly hold large amounts of raw business data, but rather acts as the executor of computational logic and the generator of proofs. When a transition condition or action defined in the value code's state machine involves computation on sensitive data, such as calculating the net profit sharing of multi-party transactions, the settlement engine initiates a computation task to the privacy-preserving computation service layer. The privacy-preserving computation service layer invokes different backend engines based on the privacy-preserving computation paradigm selected in the task description. If the task selects a homomorphic encryption paradigm, the privacy-preserving computation service layer invokes homomorphic encryption libraries such as Microsoft SEAL or IBM HELib. Under this paradigm, the data owner encrypts their sensitive data beforehand using a homomorphic encryption public key and uploads it to the designated storage service. When computation is required, the settlement engine sends the ciphertext data and computation instructions to the privacy-preserving computation service layer. The privacy-preserving computation service layer performs the specified computational operation in the ciphertext state, such as ciphertext addition or multiplication, generating the ciphertext result. Then, the ciphertext result can be directly returned to the settlement engine, which distributes it to the result recipient for decryption using their private key; alternatively, to verify the correctness of the computation, the privacy computation service layer can generate an additional zero-knowledge proof proving that the ciphertext result was indeed correctly computed from the input ciphertext according to specified rules, without revealing any plaintext information. This proof will be submitted to the settlement layer for on-chain verification.

[0033] If the task chooses the secure multi-party computation paradigm, the privacy-preserving computation service layer acts as a coordinator or participant. It may invoke frameworks such as ABY or MP-SPDZ. In this mode, each participant's original data remains local and does not leave their respective control domain. The privacy-preserving computation service layer assists the parties in establishing secure communication channels and coordinates their execution of the secure multi-party computation protocol. During protocol execution, the parties interact with secretly shared or obfuscated data fragments, ultimately jointly computing the result, without any party being able to peek at the other party's original input. Similarly, to prove to the settlement layer, the "referee," that the computation was conducted honestly, the parties can collaborate to generate a joint zero-knowledge proof demonstrating that the final output is the correct protocol execution result. If the task chooses the zero-knowledge proof paradigm, this is typically used to prove a statement is true without revealing the details of the statement. For example, proving that an encrypted transaction amount falls within a certain range without disclosing the specific amount. The privacy-preserving computation service layer integrates zero-knowledge proof libraries such as libsnark, bellman, or ZoKrates. The data owner, as the prover, needs to provide their private data (witness). The privacy-preserving computation service layer helps compile settlement logic requiring proof (e.g., "the amount is greater than zero and less than my balance") into arithmetic circuits or R1CS constraint systems. Then, using a proof key pre-generated through trusted settings, a short zero-knowledge proof is generated for the currently provided "witness." This proof verification process is highly efficient; the settlement layer can quickly verify the validity of the proof on-chain using a publicly available verification key, thus confirming that the corresponding settlement conditions are met without needing to know any sensitive data. The privacy-preserving computation service layer manages the lifecycle of these proof and verification keys and provides high-level services such as proof generation, verification, and circuit compilation.

[0034] In the specific implementation of the cross-domain conditional settlement and atomicity guarantee mechanism, this invention handles two complex situations: first, settlement depends on off-chain real-world events; second, the settlement operation itself needs to be completed atomically across multiple heterogeneous domains. For off-chain event dependencies, the system introduces a decentralized oracle network as a trusted information bridge. The oracle network consists of multiple independent oracle nodes that obtain information from pre-defined, verifiable data sources. When the state transition condition of the value code includes an off-chain event such as "goods have been received," the settlement engine initiates a data request to the oracle network. Each oracle node independently obtains a "proof of receipt" from the designated logistics company's application programming interface or IoT device signature data, and submits the proof with its own digital signature to an oracle aggregation contract at the settlement layer. This contract uses mechanisms such as threshold signatures or multi-signatures. When a sufficient number (exceeding a pre-defined threshold) of consistent and valid oracle node signatures are collected, a final, authoritative "event has occurred" proof is generated, triggering subsequent value code state transitions. This ensures the reliability and resistance to manipulation of off-chain event triggering on-chain.

[0035] For atomic settlement across multiple heterogeneous domains, a typical scenario is asset exchange: a user wants to exchange value code V1 in domain A for asset V2 in domain B. The system employs an enhanced protocol combining hash-time locking contracts and relay monitoring. First, in domain A, the payer creates a hash-time locking contract, locking value code V1 within it. The locking condition is: within a time window T1, if someone can provide a preimage of a secret value s such that its hash value equals the preset hash value H in the contract, then that person can take V1; if no one claims it within time T1, V1 is automatically returned to the payer. The payer generates a random secret s and calculates its hash H. Then, the payer sends the locked transaction proof and H to domain B via the relay network of the cross-domain state synchronization service. In domain B, after verifying that V1 in domain A has indeed been locked and that its corresponding hash is H, the receiver creates a corresponding locking contract within a time window T2 to lock its asset V2. The locking condition is also to reveal the secret s, and T2 must be less than T1. Subsequently, to obtain V2 in domain B, the payer must reveal secret 's' in the domain B contract to claim V2. This reveal causes secret 's' to be exposed in the public transactions of domain B. The monitoring service in the relay network constantly listens for contract events in domain B. Once it detects that secret 's' has been revealed, it immediately acquires 's' and, before the locking contract in domain A expires, uses 's' to claim V1 in the contract in domain A and transfers it to the recipient. This process ensures that either both parties successfully exchange assets, or the assets are returned to their original owners after the timeout, preventing either party from unjustly profiting and thus achieving atomic swaps across heterogeneous domains. The relay network acts as an automated and trusted intermediary executor in this process; its behavior logic is defined by open-source code, and its operations are monitored and audited by the settlement layer.

[0036] In the specific implementation of the audit and regulatory interface layer, this invention provides robust privacy protection capabilities while ensuring the system complies with financial regulatory and compliance requirements. All operations occurring through the unified settlement layer, regardless of whether privacy-preserving computations are involved, generate a structured, tamper-proof audit trail record. This record is formatted according to internationally accepted verifiable credential data model standards, using JSON-LD and related data technologies to ensure its semantic clarity and interoperability. A typical audit trail includes the following key fields: a unique identifier for the audit record; an operation timestamp; the operation type; the anonymized identifier of the entity initiating the operation; a list of globally unique identifiers for the value codes involved in the operation; a state digest hash before and after the operation; metadata related to privacy-preserving computations; and most importantly—the cryptographic anchoring proof of this operation. Metadata related to privacy-preserving computations may include: the privacy-preserving computation paradigm used, the verification result (success / failure) of the zero-knowledge proof, the public key fingerprint used for homomorphic encryption, and a list of anonymized identifiers of the participants in secure multi-party computations, etc. Cryptographic anchored proofs are obtained by hashing the content of the audit record and submitting it to the underlying blockchain for notarization through an adapter. This ensures the time sequence and immutability of the audit record itself.

[0037] These audit trails are indexed and stored in a distributed database or blockchain optimized for auditing, forming a complete query system that can be queried by multiple dimensions such as time, participants, and asset type. Logs. For regular business participants, they can only see audit trail views that are relevant to themselves and do not contain sensitive information about others. The system provides a standard application programming interface (API) for them to query their own transaction history. For regulatory agencies, the system provides a set of regulatory interfaces subject to strict access control. Regulatory agencies need to first register their regulatory status in the system and apply for a regulatory certificate. The system has a built-in attribute-based access control policy engine. Regulatory agencies can write and submit complex audit query policies, which are described using policy languages ​​such as XACML or Rego. For example, a policy might be: "Query the details of all transactions involving the 'Digital Copyright Transactions' value code type within the time period 2023-Q4, with a single settlement amount equivalent to more than US$100,000 RMB." When a regulatory node submits such a policy query, the policy engine first verifies the regulatory agency's permissions, then parses the policy, and matches all transaction records in the audit log that meet the conditions (time period, asset type, amount threshold).

[0038] However, because many transaction details (such as specific amounts and counterparty identities) may be protected by privacy-preserving computation techniques, the system triggers a "secure data disclosure protocol." This protocol is a multi-party interactive process. The strategy engine generates a more granular data request specific to the query and sends it to the relevant transaction participants. Upon receiving the request, the compliance module on the participant's client prompts the user (or authorizes it according to pre-defined automated compliance rules). If the participant agrees to disclose specific information for the purpose of this regulatory review, they can utilize existing cryptographic materials. For example, a homomorphic encryption private key holder can decrypt specific ciphertext fields; a zero-knowledge proof prover can generate a new zero-knowledge proof specific to this query for the fact that "the amount is greater than $100,000," without revealing the specific amount. This authorized disclosure or proof is submitted directly to the regulatory node through a secure channel. After aggregating this information, the regulatory node completes its compliance review. The entire process ensures the effectiveness of regulation while adhering to the principles of data minimization and privacy protection to the greatest extent possible, achieving a technical balance between privacy protection and compliant regulation. All regulatory inquiry requests, policy applications, and data disclosure authorization actions are also recorded in the audit log to ensure the transparency and accountability of regulatory actions.

[0039] The specific embodiments of this invention, through the aforementioned layered, modular, and collaborative system design, fully realize a trusted settlement management scheme based on value codes. Starting from the definition of programmable value carriers, this scheme constructs a unified interoperability layer, deeply integrates advanced privacy computing technologies, designs robust cross-domain atomic operation protocols, and ultimately establishes an audit and oversight framework adapted to modern compliance requirements. Communication between layers is achieved through clearly defined application programming interfaces and event-driven mechanisms, ensuring loose coupling, high cohesion, and good scalability of the system. Developers can customize and extend the system at different layers, such as developing new underlying adapters to support more blockchain types, integrating new privacy computing algorithm libraries, or designing proprietary value code templates and settlement rules for specific industries. This allows the invention to flexibly adapt to a wide range of enterprise-level application scenarios, including supply chain finance, digital asset trading, cross-border trade settlement, sharing economy revenue sharing, and intellectual property revenue distribution, providing a comprehensive technical solution for building next-generation efficient, trusted, and privacy-secure digital business infrastructure.

[0040] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A programmable value code and a cross-heterogeneous domain trusted settlement management method, comprising the following steps: Step 1. Definition and Generation of Value Code: A value code is a structured digital object whose data structure includes at least a unique identifier (CodeID), issuer identity (Issuer), current holder (Holder), intrinsic value description (ValueDescriptor), state machine, associated privacy commitment, and historical operation hash chain (OpHashChain). The state machine defines the state transition rules and triggering conditions throughout the lifecycle of the value code (such as creation, locking, splitting, merging, conditional payment, and reversal), and is initialized by the issuer through a verifiable template smart contract. Its key feature is that the value code serves as a measure of human value, and its internal value description field, ValueDescriptor, is derived from a log-normal distribution function. Definition, used to determine the original settlement strength Mapped to a standard value scale : in, and The heterogeneous domain characteristic parameters are calibrated in real time using the maximum likelihood estimation operator to achieve the equivalent transformation of heterogeneous values. Step 2. Construction and Heterogeneous Access of the Unified Settlement Layer: Construct a logically unified settlement layer. This layer connects to different underlying blockchains (such as Fabric, FISCOBCOS) or traditional trusted databases through adapters. The adapters are responsible for mapping the transactions, events, and states of the underlying system to the unified "Settlement Primitives" of the settlement layer, including asset anchoring, value code transfer, state verification, and event notification. The settlement layer maintains a lightweight cross-chain state relay network to synchronize key state change proofs of value codes in different access domains. Step 3. Execution of privacy-enhanced settlement logic: When a value code state transition is triggered (e.g., payment settlement), the settlement instruction is sent to the privacy computing engine. For calculations involving sensitive data (e.g., profit sharing calculation P=Revenue),... The Ratio-Cost algorithm employs homomorphic encryption or secure multi-party computation on ciphertext or fragmented data. After computation, a zero-knowledge proof (such as a zk-SNARK) is generated, proving that the computation process conforms to predefined rules in the value code state machine and does not reveal the original input data. This proof, along with the ciphertext or hash of the computation result, is submitted to the settlement layer for verification and recording. The settlement process follows Milgrom's information value distribution law, with the settlement value increment... The calculation formula is: in, For the set of value code information exchanged during the settlement process, The utility function of the settlement entity is used; simultaneously, the zeros of the cross-domain settlement game matrix are solved using the Nash algorithm. To determine the optimal strategy combination for each participant under the settlement contract. Step 4. Conditional Settlement and Cross-Domain Atomicity Guarantee: For settlements that rely on off-chain events (such as logistics receipts), an oracle service is introduced. The oracle submits digitally signed off-chain event data to the settlement layer. After the settlement layer smart contract verifies that the oracle signature and the event meet the value code state machine conditions, it automatically triggers subsequent settlement steps. Value code operations across multiple heterogeneous domains (such as value code locking on chain A and asset release on chain B) adopt an improved Hash Time Locked Contract (HTLC) combined with relay verification to ensure the atomicity of the operation, that is, all steps are either successful or all are rolled back. Step 5. Audit and Regulatory Interface: All settlement operations (regardless of privacy protection) generate an immutable audit trail at the settlement layer. The audit trail includes the operation identifier, the anonymized identity of the participant (such as zero-knowledge proof), the value code ID, the state change summary, the verification result (pass / fail) of the privacy computation proof, and the timestamp. Regulatory nodes can access a more detailed audit view when authorized, and can request specific participants to disclose data on designated transactions for compliance review through security protocols when necessary.

2. The programmable value code and cross-heterogeneous domain trusted settlement management method according to claim 1, characterized in that: In step 1, the state machine of the value code is formally described using a state chart, with its state set being S={Issued,Locked,Split_Pending,Merged,Settlement_Triggered,Settled,Canceled}. The transition condition set C includes time conditions, event conditions (such as on-chain / off-chain event hashes), multi-party signature threshold conditions, and logical conditions consisting of verification results from privacy computation proofs. After the data structure of the value code is serialized, it is stored in the underlying blockchain or trusted storage, and its addressing identifier CodeID is globally unique within the unified settlement layer.

3. The programmable value code and cross-heterogeneous domain trusted settlement management method according to claim 1, characterized in that: In step 2, the unified settlement layer adopts a microservices architecture, and its core modules include: Adapter Management Module (AdapterManager), Primitive Routing Module (PrimitiveRouter), Cross-Domain State Synchronizer (Cross-DomainStateSynchronizer), and Global Naming Service (GlobalNamingService). The adapter implements a standardized set of interfaces I = {SubmitTransaction(tx), QueryState(codeID), ListenEvent(contractAddr), GenerateProof(state)}. The cross-domain state synchronizer lightly synchronizes and verifies the state snapshots of value codes within each domain through Merkle Proof or Vector Commitment (MerkleProof).

4. The programmable value code and cross-heterogeneous domain trusted settlement management method according to claim 1, characterized in that: In step 3, the privacy computing engine has a pluggable architecture and supports multiple backends: homomorphic encryption libraries (such as SEAL, Paillier), secure multi-party computing frameworks (such as ABY, SPDZ), and zero-knowledge proof circuit compilers (such as circom, ZoKrates). When the settlement layer verifies the privacy computing proof, it calls the corresponding verification contract or verification key for on-chain verification. For complex computations, a "off-chain - on-chain" hybrid mode of generating proofs off-chain and verifying results on-chain is adopted to balance privacy, efficiency, and settlement finality.

5. The programmable value code and cross-heterogeneous domain trusted settlement management method according to claim 1, characterized in that: In step 4, the improved hash time-locked cross-domain settlement process is as follows: 1) The payer locks the value code V1 in the source domain, generates a random secret s and its hash H = Hash(s), and sets a timeout T1; 2) H and the lock proof are propagated to the target domain through the relay network; 3) After verifying the lock proof in the target domain, the recipient locks the corresponding asset V2 within the time limit T2 (T2 < T1) and associates the same hash H; 4) The payer presents the secret s in the target domain to claim V2, resulting in the exposure of s; 5) The relay network captures the exposed s, and after verifying in the source domain, automatically releases V1 to the recipient. The entire process is monitored by the relay network to ensure that if any link times out, all locked assets are returned to the original owner.

6. The programmable value code and cross-heterogeneous domain trusted settlement management method according to claim 1, characterized in that: In step 5, the generation of the audit trail follows the W3C Verifiable Credentials standard format. Key fields are described using JSON-LD. The regulatory interface provides an attribute-based access control (ABAC) policy engine, allowing regulators to define complex policies such as "querying details of all transactions whose single settlement amount exceeds threshold X and occurs within time period Y". Query requests that satisfy the policy will trigger a "secure data disclosure protocol" that is executed only after authorization from the participating parties. This protocol may involve multi-party collaborative decryption or the generation of a specific zero-knowledge proof for that query.