arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向央行数字货币(CBDC)银行间结算的松弛发送方匿名性:许可型EVM上的零知识方法

Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM

Pietro Tiberi, Gabriele Marcelli, Vitangelo Lasorella

arXiv 2608.28529首次发表:更新:

发表机构

Banca d’Italia(意大利银行)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对CBDC银行间结算的隐私与监管需求,提出许可型EVM上的松弛发送方匿名零知识协议,在Hyperledger Besu实现并经五节点网络验证,兼顾交易保密与合规问责。

AI 中文摘要

运行在分布式账本技术(DLT)上的央行数字货币(CBDC)银行间结算系统面临根本权衡:区块链透明度支持无需信任的验证,但会将商业敏感的双边交易流暴露给所有网络参与者。我们提出一种适用于许可型以太坊兼容网络的保密银行间结算协议,通过针对反洗钱/反恐怖主义融资(AML/CFT)监管要求定制的松弛发送方匿名模型解决该矛盾。在该模型中,发起机构在链上保持公开可识别以实现问责和合规,而接收机构、转账金额和业务载荷则被密码学混淆。我们在Hyperledger Besu上使用QBFT共识实现该协议,结合基于BN254的Groth16零知识证明、增量默克尔树中的Poseidon哈希承诺、多接收方ECIES载荷加密,以及将加密票据存储为仅追加账本日志的链上NoteRegistry合约,消除了可信的链外托管服务器。该协议支持遮蔽、保密转账和去遮蔽状态转换。在五节点网络(三家商业银行、一家央行运营方和一家证券存管机构)上的实验评估显示,端到端结算耗时8-16秒,通过EVM预编译实现的证明验证开销约1毫秒(约22万gas),在普通ARM硬件上的客户端证明生成为4-12秒。尽管在协议层面实现了接收方保密性,但当前概念验证的NoteRegistry使用所有者索引事件,这一权衡可在生产环境中通过统一事件广播解决。

英文摘要

Central Bank Digital Currency (CBDC) interbank settlement systems operating on Distributed Ledger Technology (DLT) face a fundamental trade-off: blockchain transparency enables trustless verification but exposes commercially sensitive bilateral transaction flows to all network participants. We propose a confidential interbank settlement protocol for permissioned Ethereum-compatible networks that resolves this tension through a relaxed sender anonymity model tailored to regulatory AML/CFT requirements. In this model, the initiating institution remains publicly identifiable on-chain for accountability and compliance, while the receiving institution, transfer amount, and business payload are cryptographically obfuscated. We realize the protocol on Hyperledger Besu using QBFT consensus, combining Groth16 zero-knowledge proofs over BN254, Poseidon hash commitments in an incremental Merkle tree, multi-recipient ECIES payload encryption, and an on-chain NoteRegistry contract that stores encrypted notes as an append-only ledger log, eliminating trusted off-chain custody servers. The protocol supports shield, confidential transfer, and unshield state transitions. Experimental evaluation across a five-node network (three commercial banks, a central bank operator, and a securities depository) demonstrates end-to-end settlement in 8-16 s, proof verification overhead of about 1 ms (around 220k gas) via EVM precompiles, and client proof generation in 4-12 s on commodity ARM hardware. While receiver confidentiality is established at the protocol level, the current proof-of-concept NoteRegistry uses owner-indexed events, a trade-off addressable in production via uniform event broadcasting.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑