A blockchain-based bond business processing method, device, equipment and medium

By leveraging blockchain technology, homomorphic commitments, and zero-knowledge scope proofs, combined with consortium blockchain smart contracts, privacy verification for cross-institutional bond transactions has been achieved. This solves the problems of opaque processes and data privacy in traditional bond transactions, and improves collaboration efficiency and data security.

CN122134465APending Publication Date: 2026-06-02成方金融科技有限公司

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
成方金融科技有限公司
Filing Date
2026-02-13
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Traditional bond issuance and trading businesses rely on centralized financial infrastructure, which suffers from opaque business processes, information silos, data tampering risks, and low efficiency in cross-institutional collaboration. Furthermore, they lack the ability to verify the privacy of investors' diversified assets globally.

Method used

By adopting a blockchain-based approach to bond business processing, and combining homomorphic commitments and zero-knowledge scope proofs with consortium blockchain smart contracts, cross-institutional privacy-preserving asset verification is achieved, ensuring that investors can meet business requirements without disclosing the specific amount of bonds.

Benefits of technology

It has improved the efficiency of cross-institutional business collaboration, while resolving the conflict between mutual trust of sensitive data and privacy protection among financial institutions, ensuring that data is usable but not visible.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122134465A_ABST
    Figure CN122134465A_ABST
Patent Text Reader

Abstract

This invention discloses a blockchain-based method, apparatus, device, and medium for processing bond transactions. Relating to the field of blockchain technology, the method includes: responding to a bond asset verification request, obtaining homomorphic commitments and corresponding first zero-knowledge scope proofs generated by at least two first underwriters regarding the amount of bonds held by the investor; the first underwriters are those holding and managing the investor's bond assets; based on the at least two homomorphic commitments, calculating an aggregate commitment of the total amount of bonds held by the investor at at least two first underwriters, and generating a second zero-knowledge scope proof to prove that the total amount satisfies a preset threshold; verifying the validity of each first zero-knowledge scope proof, the correctness of the aggregate commitment, and the validity of the second zero-knowledge scope proof through a joint verification smart contract; if all verifications pass, confirming that the total amount of bonds held by the investor satisfies the preset threshold. This achieves a trusted on-chain closed loop and cross-institutional privacy verification for bond transactions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of blockchain technology and can be used in the field of financial technology. In particular, it relates to a method, apparatus, equipment and medium for processing bond business based on blockchain. Background Technology

[0002] Traditional bond issuance and trading businesses rely heavily on centralized financial infrastructure and manual processes, involving multiple parties such as issuers, underwriters, and investors. This results in problems such as opaque business processes, information silos, data tampering risks, and low efficiency in cross-institutional collaboration.

[0003] While some existing technologies attempt to leverage the immutability of blockchain for bond data notarization (e.g., only recording transaction summaries on the chain), they are essentially post-event auditing tools, failing to provide on-chain trusted anchoring and automated management of the entire bond issuance, allocation, and transaction execution process. Furthermore, existing solutions lack the ability to perform global, privacy-preserving verification of bond assets held by investors across multiple underwriters. When investors need to conduct cross-institutional transactions (such as collateralized financing), they often have to expose their entire portfolio details, making it impossible to prove their assets meet requirements while protecting their business privacy and the specific amounts involved.

[0004] Therefore, how to build a bond business processing system that supports trusted on-chain operations throughout the entire process and enables cross-institutional privacy asset verification has become a pressing technical challenge in the fintech field. Summary of the Invention

[0005] This invention provides a blockchain-based method, apparatus, device, and medium for processing bond business, in order to solve the problems of fragmented bond issuance business processes, low data credibility, low efficiency of cross-institutional asset verification, and inability to protect business privacy in the prior art.

[0006] According to one aspect of the present invention, a blockchain-based bond transaction processing method is provided, applied to a consortium blockchain consisting of an issuer node, at least two underwriter nodes, and an investor node, comprising: In response to the bond asset verification request of the investor node, obtain the homomorphic commitment of the bond amount held by the investor node and the corresponding first zero-knowledge scope proof generated by at least two first underwriter nodes; wherein, the first underwriter node is the underwriter node that holds and manages the bond assets of the investor node; Based on at least two homomorphic commitments, calculate the aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, and generate a second zero-knowledge range proof to prove that the total satisfies a preset threshold. The validity of each first zero-knowledge scope proof is verified by jointly verifying the smart contract, the correctness of the aggregate commitment is verified based on each homomorphic commitment, and the validity of the second zero-knowledge scope proof is verified. If all checks pass, it is confirmed that the total bond amount of the investor node meets the preset threshold.

[0007] According to another aspect of the present invention, a blockchain-based bond transaction processing device is provided, deployed on a consortium blockchain consisting of an issuer node, at least two underwriter nodes, and investor nodes, comprising: The first proof acquisition module is used to respond to the bond asset verification request of the investor node and acquire the homomorphic commitment of the bond amount held by the investor node and the corresponding first zero-knowledge scope proof generated by at least two first underwriter nodes; wherein, the first underwriter node is the underwriter node that holds and manages the bond assets of the investor node. The second proof acquisition module is used to calculate, based on at least two homomorphic commitments, an aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, and generate a second zero-knowledge range proof to prove that the total amount satisfies a preset threshold. The verification module is used to verify the validity of each first zero-knowledge scope proof by jointly verifying the smart contract, verify the correctness of the aggregate commitment based on each homomorphic commitment, and verify the validity of the second zero-knowledge scope proof; if all verifications pass, it is confirmed that the total bond amount of the investor node meets the preset threshold.

[0008] According to another aspect of the present invention, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the blockchain-based bond business processing method according to any embodiment of the present invention.

[0009] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the blockchain-based bond business processing method according to any embodiment of the present invention.

[0010] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the blockchain-based bond business processing method according to any embodiment of the present invention.

[0011] According to another aspect of the present invention, a computer program product is provided, comprising a computer program / instructions that, when executed by a processor, implement the blockchain-based bond business processing method as described in any embodiment of the present invention.

[0012] This invention provides a novel privacy protection verification solution for bond transactions by combining homomorphic commitments, zero-knowledge scope proofs, and consortium blockchain smart contracts. When investors conduct bond pledging and other transactions across institutions, the receiving institution (such as other underwriters or exchanges) can reliably verify on-chain whether the investor's total bond assets meet business requirements (such as reaching a certain threshold). The entire process requires no institution to disclose the specific amount of bonds held by them, achieving data usability without visibility. While ensuring the efficiency of cross-institutional business collaboration, this fundamentally resolves the contradiction between mutual trust of sensitive data and privacy protection among financial institutions.

[0013] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 This is a first flowchart of a blockchain-based bond business processing method provided in an embodiment of the present invention; Figure 2 This is a second flowchart of a blockchain-based bond business processing method provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a blockchain-based bond business processing device provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device that implements an embodiment of the present invention. Detailed Implementation

[0016] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0017] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0018] Figure 1 This is a first flowchart of a blockchain-based bond business processing method provided by an embodiment of the present invention. This embodiment is applicable to cross-institutional collaboration scenarios where investors need to prove to other financial institutions that their total bond assets dispersed across multiple underwriters meet a business threshold, but require confidentiality of specific individual account holding information. This method can be executed by a blockchain-based bond business processing device, which can be implemented in hardware and / or software. This device can be configured in an electronic device with corresponding data processing capabilities, such as a consortium blockchain in a server consisting of an issuer node, at least two underwriter nodes, and an investor node. Figure 1 As shown, the method includes: S110. In response to the bond asset verification request of the investor node, obtain the homomorphic commitment of the bond amount held by the investor node and the corresponding first zero-knowledge scope proof generated by at least two first underwriter nodes.

[0019] In this context, the first underwriter node is the underwriter node that holds and manages the bond assets of the investor node. Homomorphic commitment refers to a cryptographic commitment (such as a Pedersen commitment) that guarantees the immutability of data and possesses homomorphic properties, meaning that operations on the commitment (such as addition) correspond to corresponding operations on its bound secret value (such as bond amount), without revealing the secret value. Zero-knowledge range proof is a special type of zero-knowledge proof that allows the prover to prove to the verifier that a certain secret value lies within a specific range without revealing the specific information of that value. The first zero-knowledge range proof proves, without revealing the specific amount, that the bond amount held by the investor node in the current first underwriter node is within a valid range. This valid range is predefined during the design of the consortium blockchain or the deployment of smart contracts to constrain the reasonableness of a single bond amount. Each first underwriter node executes the first zero-knowledge range proof based on this valid range to ensure that all amount data has met basic business validity checks before entering the aggregation calculation.

[0020] When investors need to prove the quality of their assets to other financial institutions (such as lenders, custodians, or regulators), they must consolidate the same bond assets held by multiple underwriters or custodians for verification, while maintaining strict confidentiality regarding the specific amounts held by each institution. Examples include cross-institutional bond-backed financing, compliant look-through audits, or multi-channel asset verification. Investor nodes may hold the same bond quotas at different financial institutions (i.e., first-tier underwriter nodes). In response to a bond asset verification request from an investor node, each first-tier underwriter node generates a homomorphic commitment and a corresponding first-zero-knowledge scope proof for the investor's bond quota at that first-tier underwriter node, based on its internal records or on-chain data. The asset verification request includes the investor node's account, a list of first-tier underwriter nodes corresponding to the investor node, and preset thresholds.

[0021] S120. Based on at least two homomorphic commitments, calculate the aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, and generate a second zero-knowledge scope proof to prove that the total amount satisfies a preset threshold.

[0022] Among them, the preset threshold refers to a specific numerical threshold required in the business scenario for the total amount of bonds held by investors to reach, such as the minimum collateral amount for pledged financing, the upper limit for compliant holdings, etc. An aggregate commitment refers to a new commitment formed by merging multiple homomorphic commitments through homomorphic operations (such as addition), and its bound secret value is the sum of the secret values ​​bound to each original commitment. Homomorphic addition / homomorphic subtraction operations refer to mathematical operations performed on cryptographic commitments that utilize the homomorphic properties of the commitments. The result of the operation is a new commitment, and its bound secret value is the result of performing corresponding arithmetic operations on the original secret values.

[0023] Obtain the homomorphic commitments and corresponding first zero-knowledge scope proofs for the bond amounts held by the investor node generated by each first underwriter node. Utilizing the homomorphic property of homomorphic commitments, combine at least two obtained homomorphic commitments into a single aggregate commitment through mathematical operations (such as homomorphic addition). This aggregate commitment corresponds to the total bond amounts held by the investor at all first underwriter nodes. Based on the aggregate commitment and a commitment representing a preset threshold (e.g., RMB 1 million for pledged financing), further operations (e.g., homomorphic subtraction) are performed to generate a difference commitment. A second zero-knowledge scope proof is generated for this difference commitment. This second zero-knowledge scope proof is used to prove to the verifier, without revealing the specific sum or difference, that "the result of subtracting the threshold from the total amount is non-negative," i.e., proving that the total amount meets or exceeds the preset threshold.

[0024] S130. Verify the validity of each first zero-knowledge scope proof by jointly verifying the smart contract, verify the correctness of the aggregate commitment based on each homomorphic commitment, and verify the validity of the second zero-knowledge scope proof.

[0025] The joint verification smart contract, deployed on the consortium blockchain, executes multiple verification logics, including verifying the validity of each first zero-knowledge scope proof, the correctness of the aggregate commitment, and the validity of the second zero-knowledge scope proof. The joint verification smart contract verifies the validity of each first zero-knowledge scope proof, ensuring the authenticity of the quota data for each first underwriter node and that it falls within the valid range; it verifies whether the aggregate commitment is indeed generated from the provided homomorphic commitments using the correct homomorphic operation rules, preventing tampering or calculation errors during the aggregation process; and it verifies the validity of the second zero-knowledge scope proof, confirming that the statement that the total amount meets the preset threshold is cryptographically valid. All verification calculations are publicly and automatically executed on the blockchain, and their results possess consensus credibility.

[0026] Specifically, any first underwriter node i uses the secret value v_i of the investor bond quota it holds, selects a random blinding factor r_i, and combines it with the publicly available cyclic group generators g and h to generate the corresponding Pedersen homomorphic commitment. Where g and h are pre-selected public generators in a specific cryptographic cyclic group (such as an elliptic curve group); v_i is the amount of secret bond to be committed; r_i is a random number generated by the first underwriter node i, used to "blind" the commitment and ensure its concealment; C_i is the computed homomorphic commitment. A first zero-knowledge range proof A_i is generated based on the Bulletproofs algorithm to prove that v_i is within the valid interval (e.g., 0 ≤ v_i < ... ). Without revealing its specific value, the homomorphic commitments and first zero-knowledge scope proofs A_i generated by each first underwriter node are submitted to the consortium blockchain.

[0027] Using the homomorphic addition property of Pedersen commitments, multiplying all homomorphic commitments together yields the aggregate commitment. The aggregate commitment is bound to the total bond amount of the investors, V_total = ∑v_i. Homomorphic subtraction is performed to verify whether the total bond amount meets a preset threshold: a public commitment representing the preset threshold T is generated. And calculate the difference commitment The difference promises that C_diff corresponds to the secret difference d = V_total - T between the total amount of bonds and a preset threshold. For the secret difference d and its aggregation blinding factor ∑r_i, the Bulletproofs algorithm is run again to generate a second zero-knowledge scope proof A_total to prove that d ≥ 0 (i.e., V_total ≥ T), while not revealing the specific size of d.

[0028] The on-chain joint verification smart contract is invoked to complete automated verification. The joint verification smart contract executes three cryptographic verifications sequentially: First, for each (C_i, A_i) submitted by the first underwriter node, the Bulletproofs verification algorithm is run to confirm the validity of each A_i, thus ensuring the authenticity and compliance of each v_i; Second, the correctness of the aggregation process is verified by recalculating and comparing C_total with the provided aggregation commitment, preventing data tampering during the aggregation stage; Third, the Bulletproofs verification algorithm is run on (C_diff, A_total) to confirm the validity of A_total, thus cryptographically proving that the difference d is non-negative, i.e., the total amount meets the threshold requirement. Only when all three verifications pass does the joint verification smart contract finally output a "verification successful" confirmation signal, thereby completing cross-institutional asset status verification without requiring any party to disclose the specific bond holding amount v_i or the total amount V_total.

[0029] S140. If all verifications pass, it is confirmed that the total bond amount of the investor node meets the preset threshold.

[0030] The verification results returned after the successful execution of the joint verification smart contract are obtained and publicly recorded on the consortium blockchain. If the validity of each first zero-knowledge scope proof, the correctness of the aggregated commitment, and the validity of the second zero-knowledge scope proof all pass verification, the total bond amount of the investor nodes is confirmed to meet a preset threshold. Investor nodes can obtain on-chain credentials (such as transaction receipts) of the verification results and submit them to the verifier (such as a staking agency). The verifier confirms the validity of the verification result corresponding to the on-chain credentials by querying the consortium blockchain. This provides cryptographic-level assurance to the verification requester (such as the staking agency). The entire process protects the privacy of each node's specific amount while completing cross-institutional trusted verification of asset status.

[0031] Optionally, the step of calculating an aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes based on at least two homomorphic commitments, and generating a second zero-knowledge range proof to prove that the total amount satisfies a preset threshold, includes: combining the homomorphic commitments into an aggregate commitment through homomorphic addition; generating a difference commitment through homomorphic subtraction between the aggregate commitment and the commitment representing the preset threshold, the difference commitment corresponding to the difference between the total amount of bonds held by the investor node and the threshold; generating the second zero-knowledge range proof based on the difference commitment; the second zero-knowledge range proof is configured to verify, through a zero-knowledge verification protocol, that the difference is non-negative without disclosing the specific difference.

[0032] Among them, the difference commitment refers to the new commitment obtained by performing homomorphic subtraction operation between the aggregate commitment and the commitment representing the preset threshold. The secret value bound to the difference commitment is the difference between the total amount of bonds and the threshold.

[0033] Optionally, leveraging the additivity of homomorphic commitments, homomorphic addition is performed on the obtained homomorphic commitments to combine them into a single aggregate commitment. This aggregate commitment is secretly bound to the sum of the current bond amounts held by the investor nodes in each of the first underwriter nodes. By performing homomorphic subtraction between this aggregate commitment and a standard commitment representing a preset threshold, a difference commitment is derived. This difference commitment cryptographically corresponds to the actual difference between the total bond amounts held by the investor nodes and the preset threshold. Based on this difference commitment, a zero-knowledge scope proof algorithm (such as Bulletproofs) is invoked to generate a second zero-knowledge scope proof. Through a zero-knowledge verification protocol, it is confirmed that the difference bound to the difference commitment is a non-negative value without revealing the specific difference, thus implicitly proving the proposition that "total amount ≥ threshold," while the verifier cannot know the specific value of the total amount or the difference throughout the process.

[0034] This invention provides a novel privacy protection verification solution for bond transactions by combining homomorphic commitments, zero-knowledge scope proofs, and consortium blockchain smart contracts. When investors conduct bond pledging and other transactions across institutions, the receiving institution (such as other underwriters or exchanges) can reliably verify on-chain whether the investor's total bond assets meet business requirements (such as reaching a certain threshold). The entire process requires no institution to disclose the specific amount of bonds held by them, achieving data usability without visibility. While ensuring the efficiency of cross-institutional business collaboration, this fundamentally resolves the contradiction between mutual trust of sensitive data and privacy protection among financial institutions.

[0035] Figure 2 This is a second flowchart of a blockchain-based bond business processing method provided by an embodiment of the present invention. This embodiment is an optimization and improvement based on the above embodiment. Figure 2 As shown, the method includes: S210. Obtain offline bond issuance information through an oracle, and generate a fungible token for the bond based on the bond issuance information.

[0036] Through the collaborative mechanism of blockchain oracles and smart contracts, real-world bond issuance information is reliably mapped onto the consortium blockchain, generating programmable and transferable digital equity certificates (i.e., fungible tokens).

[0037] Optionally, generating the fungible token of the bond based on the bond issuance information includes: generating the fungible token on the consortium blockchain through an asset minting smart contract, based on the planned total issuance amount, bond identifier, and bond terms in the bond issuance information; wherein the total issuance amount of the fungible token is determined according to the planned total issuance amount, the asset identifier of the fungible token is associated with the bond identifier, and the bond terms are recorded in the metadata of the fungible token.

[0038] Through an oracle service certified by consensus among consortium blockchain members, bond issuance information signed by the issuer is automatically retrieved or received from trusted off-chain data sources (such as central clearing institutions' systems or issuers' official announcement systems). This bond issuance information forms the original data foundation for minting digital certificates, including at least: the planned total issuance amount (used to anchor the total token supply), a unique bond identifier, and standardized bond terms (such as coupon rate, issuance start date, issuance end date, interest payment method, and other legal and financial elements). Through a pre-deployed and verified asset-minting smart contract on the consortium blockchain, the planned total issuance amount is converted into the smallest unit of on-chain fungible tokens (such as "cents"), thereby determining and locking the total supply of fungible tokens. This ensures a strict correspondence between the total on-chain fungible token supply and the planned off-chain bond issuance size, technically preventing over-issuance. The asset-minting smart contract immutably and permanently associates the bond identifier with the fungible token through contract address mapping, token symbols, or custom attributes, thus establishing the bond's unique digital identity on the blockchain. By using asset-minting smart contracts, the complete terms of the bond (usually in a structured format such as JSON) are written into the metadata of the fungible token and stored on-chain or in a verifiable distributed storage system, making the holders of the fungible token on the chain and all nodes able to check and trust it at any time.

[0039] For example, the minting function in the asset minting smart contract is: Mint(tokenId, to, amount, data), where tokenId is the symbol of the fungible token of the bond, which is bound to the bond identifier; to is the account address of the issuer, and the fungible token is stored in the account at this address after minting; amount is the total amount of fungible tokens issued; and data is the bond terms.

[0040] Through the above process, an off-chain bond issuance can generate a "digital twin" token on the alliance chain that fully corresponds to it and carries all the key terms, building a standardized, programmable, and trusted underlying asset data foundation for subsequent on-chain implementation of bond asset registration, custody splitting (managed by underwriter nodes), privacy quota verification based on homomorphic commitments and zero-knowledge proofs, and possible secondary market circulation.

[0041] S220. Obtain the sales quota allocation information submitted by the issuer node through an oracle, and configure the sellable quota of the fungible token for at least one underwriter node according to the sales quota allocation information.

[0042] The sellable quota follows the following constraint: the sum of the sellable quotas configured for all underwriter nodes does not exceed the total issuance amount of the fungible token.

[0043] Optionally, obtaining the sales quota allocation information submitted by the issuer node through an oracle and configuring the sellable quota of the fungible token for at least one underwriter node according to the sales quota allocation information includes: through an authorization smart contract, based on the quota allocation information, granting the sellable quota of the fungible token to the specified underwriter node account on the chain.

[0044] Optionally, the authorization function of the authorization smart contract is: SetApprovalForAll(tokenId, fromAddr, toAddr[], approvAmount[]), where tokenId is the symbol of the fungible token of the bond, bound to the bond identifier, representing the bond asset on the chain; fromAddr is the account address of the issuer node; toAddr[] is an array composed of the account addresses of all underwriter nodes; approvAmount[] is an array composed of the sellable quotas of the bonds allocated to all underwriter nodes this time. Through the authorization function, the sellable quota allocation for the underwriters is completed on the chain, and when allocating, it is verified that sum(approvAmount[]) < amount (total planned issuance amount) to ensure that the sum of the allocated sellable quotas is less than the total planned issuance amount.

[0045] S230. Obtain the investment transaction data submitted by any underwriter node through an oracle, and transfer the corresponding quantity of the fungible token from the issuer node account to the investor node account according to the sellable quota of the fungible token of the bond in the underwriter node and the investment transaction data.

[0046] Once the underwriter node reaches a bond subscription agreement with its client (investor) offline, the underwriter node submits the key data of this transaction (i.e., investment transaction data) to the consortium blockchain system via an oracle service. This investment transaction data includes at least the accounts of the two parties (the issuer node account and the investor node account), the bond identifier, and the transaction amount. Upon receiving this investment transaction data, before executing the transfer, the consortium blockchain verifies, based on the bond identifier, whether the remaining sales quota for the fungible token in the underwriter node account initiating the transaction is not less than the transaction amount. This ensures that the transfer operation complies with the sales authorization previously configured for the underwriter node by the issuer. This verification ensures that the sales activity is conducted within the authorized limit, technically preventing overselling. If the verification passes, the asset transfer smart contract is invoked to transfer fungible tokens equivalent to the transaction amount from the bond issuer node account to the designated investor node account, completing the formal change of ownership of the bond assets on the blockchain and enabling the investor to obtain the corresponding digital asset rights.

[0047] Optionally, the investment transaction data includes the transaction amount, bond identifier, issuer node account, and investor node account; the step of transferring a corresponding number of fungible tokens from the issuer node account to the investor node account based on the saleable quota of the fungible tokens of the bond in the underwriter node and the investment transaction data includes: verifying whether the saleable quota of the fungible tokens corresponding to the bond identifier in the underwriter node is greater than or equal to the transaction amount; if the verification passes, then transferring fungible tokens equal to the transaction amount from the issuer node account to the investor node account through an asset transfer smart contract.

[0048] In a preferred embodiment, the investment transaction data is structured and defined, including at least: transaction amount, bond identifier, issuer node account, and investor node account. Based on the bond identifier in the investment transaction data, the salable quota status of the underwriter node is obtained and compared with the transaction amount in the investment transaction data, performing a logical check that the salable quota ≥ transaction amount. When the remaining salable quota for the fungible token in the underwriter node account initiating this transaction is not less than the transaction amount, the asset transfer smart contract is invoked, passing the issuer node account, investor node account, transaction amount, and bond identifier as parameters. For example, the transfer function of the asset transfer smart contract is: SafeTransferFrom(from,to,tokenId,amount,data), where from is the issuer node account address; to is the investor node account address; tokenId is the symbol of the fungible token, bound to the bond identifier, representing the on-chain bond asset; amount represents the transaction amount; and data is other auxiliary data. During the asset transfer process, a transaction ID is constructed for each transaction using a hash algorithm. Merkle root and block data are then constructed using these transaction IDs and other transaction-related data, ensuring the integrity and immutability of each bond issuance transaction. Through the asset transfer smart contract, on-chain accounting operations are automatically executed, deducting the corresponding number of fungible tokens from the issuer node account specified by parameters and crediting the corresponding fungible tokens to the investor node account specified by parameters. The entire verification and execution process is atomically completed by the smart contract, ensuring that the transaction either succeeds completely or is completely rolled back, maintaining ledger consistency. Through the asset transfer smart contract, offline bond purchase and sale contracts are securely, accurately, and immutably anchored to the blockchain, completing the confirmation and delivery of asset ownership.

[0049] S240. In response to a successful on-chain transfer transaction event, generate a non-fungible token uniquely corresponding to the transaction based on the investment transaction data, and allocate the non-fungible token to the investor node account.

[0050] The system determines whether the on-chain asset transfer was successful. If it fails, it indicates that the underwriter's sales quota is insufficient or that the underwriter's transaction is non-compliant, resulting in the transaction's failure. If the on-chain asset transfer is successful, in response to the successful on-chain transfer transaction event, the system invokes the certificate minting smart contract, using the investment transaction data as input, to mint and generate a unique non-fungible token (NFT) on the consortium blockchain. This NFT itself represents the legal and technical ownership of the transaction. After minting, the NFT is sent and recorded in the investor node account corresponding to this transaction. The investor not only holds a fungible token (FT) representing a share of the bond assets in their account, but also possesses a unique NFT certificate serving as proof of the source and details of this holding, achieving dual anchoring of assets and transaction records.

[0051] Optionally, the step of generating a non-fungible token uniquely corresponding to the investment transaction data and allocating the non-fungible token to the investor node account includes: generating a digital certificate file based on the investment transaction data and obtaining the storage address of the digital certificate file; generating a non-fungible token on the consortium blockchain through a certificate minting smart contract based on the investment transaction data and the storage address of the digital certificate file; wherein the Uniform Resource Identifier of the non-fungible token points to the storage address, and the metadata of the non-fungible token records the investor node account, issuer node account, transaction amount, and bond identifier from the investment transaction data.

[0052] Optionally, the off-chain certificate generation service generates a structured digital certificate file (e.g., a standard-format JSON file or a PDF electronic confirmation) based on the investment transaction data. This file comprehensively records all elements of the transaction. The digital certificate file is stored in a persistent, publicly accessible storage service (such as IPFS or cloud storage), and its unique access address, i.e., the storage address, is obtained. The certificate minting smart contract is invoked, passing the core investment transaction data and the storage address of this digital certificate file as key parameters. A unique non-fungible token is created on-chain through the certificate minting smart contract. The Uniform Resource Identifier (URI) attribute of this non-fungible token is set to the storage address of the digital certificate file, thus establishing a robust link between the non-fungible token and the complete off-chain certificate file. Simultaneously, core fields from the investment transaction data, including the investor node account, issuer node account, transaction amount, and bond identifier, are written into the on-chain metadata of this non-fungible token. Non-fungible tokens possess both lightweight on-chain verifiability (through metadata) and complete off-chain information accessibility (through digital credential files pointed to by Uniform Resource Identifiers), forming a complete, trustworthy, and easy-to-use digital transaction record, and ultimately allocating ownership of the non-fungible token to the corresponding investor node account.

[0053] S250. In response to the bond asset verification request of the investor node, obtain the homomorphic commitment of the bond amount held by the investor node and the corresponding first zero-knowledge scope proof generated by at least two first underwriter nodes.

[0054] Wherein, the first underwriter node is the underwriter node that holds and manages the bond assets of the investor node.

[0055] S260. Based on at least two homomorphic commitments, calculate the aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, and generate a second zero-knowledge scope proof to prove that the total amount satisfies a preset threshold.

[0056] S270. Verify the validity of each first zero-knowledge scope proof by jointly verifying the smart contract, verify the correctness of the aggregate commitment based on each homomorphic commitment, and verify the validity of the second zero-knowledge scope proof.

[0057] S280. If all verifications pass, it is confirmed that the total bond amount of the investor node meets the preset threshold.

[0058] Optionally, CA certificates are generated for each node in each consortium blockchain, and account and address information is generated based on the certificates. The address information is calculated using the formula: addr = Keccak - 256(keyPair.getPublic()). Each node's account in the consortium blockchain is generated based on a digital certificate issued by a public key infrastructure. The oracle is configured to convert offline data from external business systems into input data conforming to the consortium blockchain transaction format to trigger corresponding smart contracts.

[0059] This invention constructs a complete blockchain business loop integrating digital bond issuance, automated sales and circulation, and multi-party privacy verification. It reliably anchors the entire lifecycle of traditional bond issuance and trading onto a consortium blockchain. It not only utilizes fungible tokens (FTs) to achieve standardized and efficient transfer of bond assets, but also provides unique and tamper-proof digital credentials for each transaction through non-fungible tokens (NFTs). Finally, it innovatively introduces a multi-party joint verification mechanism based on homomorphic commitments and zero-knowledge proofs. This allows investors to cryptographically prove to third parties (such as financial institutions) that their total bond asset amount meets business requirements without disclosing the specific details of their holdings across multiple underwriters. This fundamentally solves the problems of data silos, lack of trust, and privacy leaks in cross-institutional collaboration while improving business transparency, operational efficiency, and automation.

[0060] Figure 3This is a schematic diagram of a blockchain-based bond processing device provided in an embodiment of the present invention. The device can be implemented in hardware and / or software and can be configured in an electronic device with corresponding data processing capabilities, such as a consortium blockchain within a server, consisting of an issuer node, at least two underwriter nodes, and investor nodes. Figure 3 As shown, the device includes: The first proof acquisition module 310 is used to respond to the bond asset verification request of the investor node and acquire the homomorphic commitment of the bond amount held by the investor node and the corresponding first zero-knowledge scope proof generated by at least two first underwriter nodes; wherein, the first underwriter node is the underwriter node that holds and manages the bond assets of the investor node. The second proof acquisition module 320 is used to calculate, based on at least two homomorphic commitments, an aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, and generate a second zero-knowledge scope proof to prove that the total amount satisfies a preset threshold. The verification module 330 is used to verify the validity of each first zero-knowledge scope proof by jointly verifying the smart contract, verify the correctness of the aggregate commitment based on each homomorphic commitment, and verify the validity of the second zero-knowledge scope proof; if all verifications pass, it is confirmed that the total amount of bonds of the investor node meets the preset threshold.

[0061] The blockchain-based bond business processing device provided in this embodiment of the invention can execute the blockchain-based bond business processing method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0062] Optionally, the second proof acquisition module is specifically used to combine each homomorphic commitment into an aggregate commitment through homomorphic addition; generate a difference commitment through homomorphic subtraction between the aggregate commitment and the commitment representing the preset threshold, the difference commitment corresponding to the difference between the total amount of bonds held by the investor node and the threshold; generate the second zero-knowledge scope proof based on the difference commitment; the second zero-knowledge scope proof is configured to verify that the difference is non-negative without disclosing the specific difference value through a zero-knowledge verification protocol.

[0063] Optionally, it also includes a bond issuance module, used to obtain offline bond issuance information through an oracle before obtaining the homomorphic commitment of the bond amount held by the investor node generated by at least two first underwriter nodes, and to generate a fungible token for the bond based on the bond issuance information; The bond quota allocation module is used to obtain sales quota allocation information submitted by the issuer node through an oracle, and configure the sales quota of the fungible token for at least one underwriter node according to the sales quota allocation information. The bond trading module is used to obtain investment transaction data submitted by any underwriter node through an oracle, and transfer the corresponding number of fungible tokens from the issuer node account to the investor node account based on the saleable quota of the fungible tokens of the bond in the underwriter node and the investment transaction data. The transaction certificate generation module is used to respond to a successful on-chain transfer transaction event, generate a non-fungible token uniquely corresponding to the transaction based on the investment transaction data, and allocate the non-fungible token to the investor node account.

[0064] Optionally, the bond issuance module is specifically used to generate fungible tokens on the consortium blockchain through an asset-minting smart contract, based on the planned total issuance amount, bond identifier, and bond terms in the bond issuance information; wherein, the total issuance amount of the fungible tokens is determined according to the planned total issuance amount, the asset identifier of the fungible tokens is associated with the bond identifier, and the bond terms are recorded in the metadata of the fungible tokens.

[0065] Optionally, the investment transaction data includes transaction amount, bond identifier, issuer node account, and investor node account; the bond trading module includes: The quota verification unit is used to verify whether the sales quota of the fungible token corresponding to the bond identifier in the underwriter node is greater than or equal to the transaction amount. The asset transfer unit is used to transfer, if the verification passes, fungible tokens equal to the transaction amount from the issuer node account to the investor node account via an asset transfer smart contract.

[0066] Optionally, the transaction certificate generation module is specifically used to generate a digital certificate file based on the investment transaction data and obtain the storage address of the digital certificate file; through the certificate minting smart contract, a non-fungible token is generated on the consortium blockchain based on the investment transaction data and the storage address of the digital certificate file; wherein, the Uniform Resource Identifier of the non-fungible token points to the storage address, and the metadata of the non-fungible token records the investor node account, issuer node account, transaction amount, and bond identifier from the investment transaction data.

[0067] The blockchain-based bond processing device described in further detail can also execute the blockchain-based bond processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method.

[0068] According to embodiments of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.

[0069] Figure 4 A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0070] like Figure 4 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory 42 or a random access memory 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the read-only memory 42 or loaded from storage unit 48 into the random access memory 43. The random access memory 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, read-only memory 42, and random access memory 43 are interconnected via a bus 44. An input / output interface 45 is also connected to the bus 44.

[0071] Multiple components in electronic device 40 are connected to input / output interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0072] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, central processing units, graphics processing units, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, digital signal processors, and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as blockchain-based bond business processing methods.

[0073] In some embodiments, the blockchain-based bond transaction processing method can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 40 via read-only memory 42 and / or communication unit 49. When the computer program is loaded into random access memory 43 and executed by processor 41, one or more steps of the blockchain-based bond transaction processing method described above can be performed. Alternatively, in other embodiments, processor 41 can be configured to execute the blockchain-based bond transaction processing method by any other suitable means (e.g., by means of firmware).

[0074] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays, application-specific integrated circuits (ASICs), application-specific standard products (ASICs), systems-on-a-chip (SoCs), payload programmable logic devices, computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0075] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0076] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory, optical fibers, portable compact disk read-only memory, optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0077] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a cathode ray tube, liquid crystal display, or monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0078] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0079] A computing system can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product within the cloud computing service system to address the shortcomings of traditional physical hosts and virtual private servers, such as high management difficulty and weak business scalability.

[0080] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0081] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A blockchain-based bond transaction processing method, characterized in that, Applied to a consortium blockchain consisting of an issuer node, at least two underwriter nodes, and investor nodes, the method includes: In response to the bond asset verification request of the investor node, obtain the homomorphic commitment of the bond amount held by the investor node and the corresponding first zero-knowledge scope proof generated by at least two first underwriter nodes; wherein, the first underwriter node is the underwriter node that holds and manages the bond assets of the investor node; Based on at least two homomorphic commitments, calculate the aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, and generate a second zero-knowledge range proof to prove that the total satisfies a preset threshold. The validity of each first zero-knowledge scope proof is verified by jointly verifying the smart contract, the correctness of the aggregate commitment is verified based on each homomorphic commitment, and the validity of the second zero-knowledge scope proof is verified. If all checks pass, it is confirmed that the total bond amount of the investor node meets the preset threshold.

2. The method according to claim 1, characterized in that, The process involves calculating an aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, based on at least two homomorphic commitments, and generating a second zero-knowledge range proof to demonstrate that the total satisfies a preset threshold, including: Homomorphic commitments are combined into aggregate commitments through homomorphic addition. A difference commitment is generated by homomorphic subtraction between the aggregated commitment and the commitment representing the preset threshold. The difference commitment corresponds to the difference between the total amount of bonds held by the investor node and the threshold. Based on the difference commitment, a second zero-knowledge range proof is generated; the second zero-knowledge range proof is configured to verify, through a zero-knowledge verification protocol, that the difference is non-negative without disclosing the specific difference.

3. The method according to claim 1, characterized in that, Before obtaining the homomorphic commitment generated by at least two first underwriter nodes regarding the bond quota held by the investor node, the process also includes: Obtain offline bond issuance information through oracles, and generate fungible tokens for the bonds based on the bond issuance information; Obtain sales quota allocation information submitted by the issuer node through an oracle, and configure the sales quota of the fungible token for at least one underwriter node based on the sales quota allocation information. By obtaining investment transaction data submitted by any underwriter node through an oracle, and based on the saleable quota of the fungible tokens of the bond in the underwriter node and the investment transaction data, the corresponding number of fungible tokens are transferred from the issuer node account to the investor node account. In response to a successful on-chain transfer transaction event, a non-fungible token uniquely corresponding to the transaction is generated based on the investment transaction data, and the non-fungible token is allocated to the investor's node account.

4. The method according to claim 3, characterized in that, The step of generating a fungible token for the bond based on the bond issuance information includes: By using asset-minting smart contracts, fungible tokens are generated on the consortium blockchain based on the planned total issuance amount, bond identifier, and bond terms in the bond issuance information. The total issuance of the fungible token is determined based on the planned total issuance amount. The asset identifier of the fungible token is associated with the bond identifier, and the bond terms are recorded in the metadata of the fungible token.

5. The method according to claim 3, characterized in that, The investment transaction data includes transaction amount, bond identifier, issuer node account, and investor node account; the step of transferring a corresponding number of the fungible tokens from the issuer node account to the investor node account based on the saleable quota of the fungible tokens of the bond in the underwriter node and the investment transaction data includes: Verify whether the saleable amount of the fungible token corresponding to the bond identifier in the underwriter node is greater than or equal to the transaction amount; If the verification passes, the asset transfer smart contract will transfer the number of fungible tokens equal to the transaction amount from the issuer node account to the investor node account.

6. The method according to claim 3, characterized in that, The process of generating a unique non-fungible token (NFT) corresponding to the investment transaction based on the investment transaction data, and allocating the NFT to the investor node account, includes: A digital voucher file is generated based on the investment transaction data, and the storage address of the digital voucher file is obtained; By using a smart contract for credential minting, non-fungible tokens are generated on the consortium blockchain based on the investment transaction data and the storage address of the digital credential file. The nonfungible token's Uniform Resource Identifier points to the storage address, and the nonfungible token's metadata records the investor node account, issuer node account, transaction amount, and bond identifier from the investment transaction data.

7. A blockchain-based bond transaction processing device, characterized in that, Deployed on a consortium blockchain consisting of issuer nodes, at least two underwriter nodes, and investor nodes, the device includes: The first proof acquisition module is used to respond to the bond asset verification request of the investor node and acquire the homomorphic commitment of the bond amount held by the investor node and the corresponding first zero-knowledge scope proof generated by at least two first underwriter nodes; wherein, the first underwriter node is the underwriter node that holds and manages the bond assets of the investor node. The second proof acquisition module is used to calculate, based on at least two homomorphic commitments, an aggregate commitment representing the total amount of bonds held by the investor node at the at least two first underwriter nodes, and generate a second zero-knowledge range proof to prove that the total amount satisfies a preset threshold. The verification module is used to verify the validity of each first zero-knowledge scope proof by jointly verifying the smart contract, verify the correctness of the aggregate commitment based on each homomorphic commitment, and verify the validity of the second zero-knowledge scope proof; if all verifications pass, it is confirmed that the total bond amount of the investor node meets the preset threshold.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores a computer program that can be executed by the at least one processor, which is then executed by the at least one processor to enable the at least one processor to perform the blockchain-based bond business processing method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the blockchain-based bond business processing method according to any one of claims 1-6.

10. A computer program product comprising a computer program that, when executed by a processor, implements the blockchain-based bond business processing method according to any one of claims 1-6.