US20210201410A1 - Systems and methods for updating a distributed ledger based on partial validations of transactions - Google Patents
Systems and methods for updating a distributed ledger based on partial validations of transactions Download PDFInfo
- Publication number
- US20210201410A1 US20210201410A1 US17/184,472 US202117184472A US2021201410A1 US 20210201410 A1 US20210201410 A1 US 20210201410A1 US 202117184472 A US202117184472 A US 202117184472A US 2021201410 A1 US2021201410 A1 US 2021201410A1
- Authority
- US
- United States
- Prior art keywords
- asset
- ledger
- request
- distributed ledger
- transaction
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Abandoned
Links
- 238000010200 validation analysis Methods 0.000 title claims abstract description 230
- 238000000034 method Methods 0.000 title claims abstract description 128
- 238000012545 processing Methods 0.000 claims abstract description 39
- 230000008569 process Effects 0.000 claims description 79
- 230000004044 response Effects 0.000 claims description 6
- 238000012986 modification Methods 0.000 claims description 4
- 230000004048 modification Effects 0.000 claims description 4
- 238000012550 audit Methods 0.000 abstract 1
- 238000003860 storage Methods 0.000 description 18
- 238000010586 diagram Methods 0.000 description 16
- 230000006870 function Effects 0.000 description 7
- 238000013475 authorization Methods 0.000 description 5
- 230000007246 mechanism Effects 0.000 description 5
- 230000000694 effects Effects 0.000 description 4
- 239000012634 fragment Substances 0.000 description 4
- 230000001105 regulatory effect Effects 0.000 description 4
- 238000012795 verification Methods 0.000 description 4
- 238000004900 laundering Methods 0.000 description 3
- 230000003287 optical effect Effects 0.000 description 3
- 238000004891 communication Methods 0.000 description 2
- 238000013500 data storage Methods 0.000 description 2
- 239000002245 particle Substances 0.000 description 2
- 238000012546 transfer Methods 0.000 description 2
- OKTJSMMVPCPJKN-UHFFFAOYSA-N Carbon Chemical compound [C] OKTJSMMVPCPJKN-UHFFFAOYSA-N 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 230000006399 behavior Effects 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000005540 biological transmission Effects 0.000 description 1
- 230000000903 blocking effect Effects 0.000 description 1
- 229910052799 carbon Inorganic materials 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 239000003795 chemical substances by application Substances 0.000 description 1
- 230000001010 compromised effect Effects 0.000 description 1
- 238000004590 computer program Methods 0.000 description 1
- 230000001276 controlling effect Effects 0.000 description 1
- 230000008878 coupling Effects 0.000 description 1
- 238000010168 coupling process Methods 0.000 description 1
- 238000005859 coupling reaction Methods 0.000 description 1
- 238000002790 cross-validation Methods 0.000 description 1
- 230000001186 cumulative effect Effects 0.000 description 1
- 230000003111 delayed effect Effects 0.000 description 1
- 230000001419 dependent effect Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000001514 detection method Methods 0.000 description 1
- 238000009826 distribution Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 208000015181 infectious disease Diseases 0.000 description 1
- 230000001788 irregular Effects 0.000 description 1
- 230000007257 malfunction Effects 0.000 description 1
- 238000013507 mapping Methods 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 230000000737 periodic effect Effects 0.000 description 1
- 238000002360 preparation method Methods 0.000 description 1
- 230000001360 synchronised effect Effects 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/04—Trading; Exchange, e.g. stocks, commodities, derivatives or currency exchange
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/22—Indexing; Data structures therefor; Storage structures
- G06F16/2282—Tablespace storage structures; Management thereof
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/23—Updating
- G06F16/2358—Change logging, detection, and notification
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/02—Payment architectures, schemes or protocols involving a neutral party, e.g. certification authority, notary or trusted third party [TTP]
- G06Q20/023—Payment architectures, schemes or protocols involving a neutral party, e.g. certification authority, notary or trusted third party [TTP] the neutral party being a clearing house
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/381—Currency conversion
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4016—Transaction verification involving fraud or risk level assessment in transaction processing
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/12—Accounting
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/12—Accounting
- G06Q40/128—Check-book balancing, updating or printing arrangements
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q2220/00—Business processing using cryptography
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/50—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
Definitions
- the processing of financial transactions can involve substantial settlement risk because such transactions generally comprise two parts.
- a transaction in which a first party buys a certain amount of U.S. dollars from a second party in exchange for Euros may be processed in two parts, namely (i) the transfer of Euros from the first to the second party, and (ii) the transfer of U.S. dollars from the second to the first party.
- the two parts of such foreign exchange transactions are processed at different times due to varying processing times, time zone differences, or other factors.
- a party that has completed its part of the transaction but not yet received funds from the other party is subject to risk, because the other party may default on its obligation. This risk is known as “Herstatt” risk.
- Intraday liquidity requirements can be reduced by processing transactions in near-real-time, such that transactions settle before new transactions are initiated. In conventional banking systems this is difficult, if not impossible, to realize, because payments need to move through multiple private ledgers and thus incur delay.
- Cryptographic currencies such as Bitcoin or Ripple
- Ripple maintain transaction records in a single ledger for all participants and thus are able to process transactions in order and fast compared to conventional banking systems.
- Ripple typically processes transactions in a matter of a few seconds and Bitcoin in a matter of a few hours.
- these systems suffer from significant disadvantages in terms of privacy, because they maintain balances and transaction records in publicly accessible ledgers that are stored on distributed servers. This transparency helps maintain the accuracy of records by allowing many parties to observe and approve changes applied to the ledger.
- crypto-ledger systems such as Bitcoin and Ripple may obfuscate the identity of a specific party by using arbitrary account numbers that are not easy to attribute to a specific real-world party
- large financial institutions e.g., central banks
- AML policing anti-money laundering
- the disclosed systems and methods are generally directed to a distributed computer network that includes a plurality of servers for maintaining and updating copies of a distributed ledger based on cryptographic authentication techniques. More particularly, the systems and methods track exchanges, such as currency exchanges, or other types of exchanges, that take place in substantially real time. To that end, the system authorizes an individual and associates with the individual an account that represents some amount of an asset (for example a regulated currency). The system performs a payment in a single asset or exchanges two or more assets in substantially real time between two or more authorized individuals by adjusting account balances maintained within redundant copies of a distributed ledger. Further, the system arranges for the exchange in a private and secure form to prevent third parties from observing the exchange (or adjusting the ledger balance) before or during the exchange process.
- exchanges such as currency exchanges, or other types of exchanges
- the system stores redundant copies of the data tables, which include account information and account balances, at the ledger administration server and at asset validation servers associated with the asset issuing authorities.
- the distributed storage of the data tables provides additional protection from attempts to falsify information stored in the data tables of the ledger because more than one server would need to be compromised.
- the system uses authentication techniques to verify identifying information and perform know-your-customer (KYC) or anti-money laundering (AML) checks.
- KYC know-your-customer
- AML anti-money laundering
- the system uses cryptographic codes to authenticate electronic signatures appended to data messages by comparing the electronic signatures to hashes obtained from processing the data messages with a public key of the signing party.
- Accountholders may submit transactions to the system through client devices, such as personal computers, laptops, smartphones, or other suitable types of devices. Responsive to user input, the client devices may generate data messages that include transaction amounts to be transferred, e.g., from a first to a second party. The transaction may involve a single asset or multiple assets, as is the case in foreign exchange transactions. Client devices may send data messages directly to the ledger administration server that controls the processing of the transaction. Client devices may also send the data messages to other servers, such as servers maintained by a commercial bank, and these servers may in turn relay the messages to the ledger administration server. The data messages may include electronic signatures appended by the client devices.
- ledger administration server may employ a processor to identify the assets associated with the transaction, check available balances, and perform KYC validation. For example, the data message of a foreign exchange transaction, in which a first party buys U.S. dollars from a second party in exchange for Euros, may include transaction amounts in “U.S. dollars” and “Euros,” respectively.
- the ledger administration server may further employ the processor to identify a set of asset validation servers that validate the transaction.
- each of the asset validation servers may be associated with the issuing authority of a specific asset involved in the transaction. Responsive to identifying the set of asset validation servers, the ledger administration server creates data messages based on the transaction data and sends it to each of the asset validation servers. As part of creating the data messages, the ledger administration server may append electronic signatures that can be used by each of the asset validation servers to verify that the data message has been sent by the ledger administration server.
- An asset validation server associated with a given asset creates and stores redundant records of account balances included in the ledger for that given asset.
- the redundant records may be employed by the asset validation server to verify the balances of an accountholder independently from the ledger administration server. Responsive to receiving a data message corresponding to a transaction from the ledger administration server, the asset validation server may employ a processor to compare an account balance stored in its records with the transaction amount provided in the data message. If the account balance is greater than the transaction amount (i.e., if sufficient funds are available), the asset validation server may continue the processing of the transaction. Otherwise, the asset validation server may transmit a data message to the ledger administration server to indicate that the transaction should be rejected.
- the asset validation server may append an electronic signature to the data message that can be used by the ledger administration server to verify the authenticity of the data message.
- the ledger administration server may also perform KYC checks in accordance with regulatory requirements.
- the ledger administration server may compile and store indications of such KYC authorizations in a look-up table, e.g., upon receiving such indication in a signed message from a KYC validator such as a commercial bank.
- KYC authorizations may be based on a chain of trust. For example, the ledger administration server may determine to accept a KYC authorization if the corresponding KYC validator indicates that it trusts the client and the ledger administration server (or asset validator associated with the asset involved in the transaction) in turn trusts the KYC validator. If the ledger administration server determines that any of the parties of a transaction is not associated with a valid KYC authorization, the ledger administration server may reject the transaction and provide a corresponding signed message to parties involved in the transaction.
- the ledger administration server receives a separate data message from the asset validation server of each asset involved in the transaction. Responsive to the receipt of the messages, the ledger administration server determines if one or more of the data messages includes an indication that the transaction should be rejected (e.g., due to insufficient funds). If at least one of the data messages includes such a rejection, ledger administration server rejects the transaction in its entirety and does not update the ledger account balances of any parties involved in the transaction. Conversely, if all of the data messages received from the asset validation servers include indications that the transaction should be approved, the ledger administration server updates the account balances maintained in its copy of the encrypted ledger.
- the ledger administration server sends portions of the updated ledger to the asset validation servers in form of data messages.
- the data message sent to a specific asset validation server may only include balances for accounts held in the asset maintained by the specific asset validation server. For example, a validation server for U.S. dollars may only be sent the portion of the updated ledger that corresponds to accounts in U.S. dollars.
- the data messages may also include a list of completed transactions that have been incorporated into the updated ledger together with their respective unique identifiers and transaction amounts. Responsive to receiving the data message, the asset validation server may update its records based on the list of completed transactions, by modifying the account balances and records of reserved and pending payments.
- an asset validation server may remove the transaction amount of a completed transaction from the shadow balance because that completed transaction is now reflected in the account balances included in the updated ledger.
- the asset validation server may further update status indications corresponding to transactions included in the list of transactions to denote that they have been completed and are no longer pending.
- the periodic transmission of account balances from the ledger administration server to the asset validation servers helps ensure that the distributed and redundant copies of the encrypted ledger, which are maintained separately at the ledger administration server and the asset validation server, remain consistent.
- the systems and methods described herein address the problem of the significant time delay that arises in current exchange processes by providing a system architecture that can operate in substantially real-time.
- the systems and methods further address the problem of lack of identity verification of parties participating in current exchange processes by making identity checks that can satisfy KYC standards a component of the exchange process.
- the systems and methods further address the problem of disclosing information about account balances or transactions to third parties that do not need to know or otherwise access that information and thereby can reduce the cost of making transactions compared to current exchange processes.
- systems and methods are provided for modifying a data table having a plurality of accounts in substantially real-time.
- the systems and methods may receive a request to modify an account selected from the plurality of accounts, wherein the selected account comprises at least one asset, and determine an identity of a validator based on the received request and the at least one asset, wherein the validator is configured to validate the request in substantially real-time.
- the systems and methods may further modify the data table in substantially real-time if the validator validates the request.
- the validator may be a first validator and the at least one asset may comprise a first and a second asset.
- the systems and methods may further include determining an identity of a second validator based on the received request, wherein the second validator validates the request in substantially real-time for the second asset.
- the data table is modified to process a payment transaction or a deposit transaction, the at least one asset corresponds to a currency or a bond, and the validator is an issuing-authority of the currency or the bond.
- the issuing authority of the currency or the bond is a proxy for a central bank that issues the currency or a bond holder that issues the bond.
- the data table is modified to process a foreign exchange transaction, and the first asset corresponds to a first currency and the second asset corresponds to a second currency. Further, the first validator corresponds to a first issuing authority of the first currency, and the second validator correspond to a second issuing authority of the second currency.
- the systems and methods may encrypt the plurality of accounts in the data table differently, so that a decryption process used by the first validator to access data of the first asset cannot be used to access data of the second asset.
- the validator may determine whether to validate the request based on retrieving a published balance from the data table for the account and the at least one asset, and computing an available balance by reducing the published balance by shadow balances associated with pending and reserved payments.
- the systems and methods may further approve the request when the available balance is greater than or equal to a transaction amount of the request and reject the request when the available balance is less than the transaction amount of the request.
- the validator stores the shadow balances associated with pending and reserved payments and a redundant copy of the data table.
- the validator determines whether to validate the request based on verifying whether a party associated with the account is authorized to perform the request.
- the validator stores a redundant copy of the data table and the systems and methods further comprise sending modified portions of the data table to the validator, in response to modifying the data table.
- the redundant copy of the data table is encrypted to prevent the validator from accessing data that is of an asset different from the at least one asset.
- FIG. 1 is a block diagram of a distributed computer system that maintains and updates a distributed ledger
- FIG. 2 is a diagram of the distributed ledger to illustrate visibility restrictions
- FIG. 3 is a block diagram of a ledger administration network
- FIG. 4 depicts an exemplary data structure for storing ledger balances and account information in the distributed ledger
- FIG. 5 is a flowchart of a process for updating a distributed ledger based on data messages received from validation servers that each store partial, redundant copies of the ledger:
- FIG. 6 is a schematic of an authentication method using public and private keys.
- FIG. 1 is an illustrative block diagram of a distributed computer system 100 that maintains and updates a distributed ledger.
- Computer system 100 includes ledger administration server 102 , account operator server 120 , asset validation servers 130 , 132 and 142 , proxy validation server 140 , as well as KYC validation server 150 .
- Ledger administration server 102 may be connected directly to clients 112 - 116 and may be connected to clients 122 - 126 through account operator server 120 .
- the servers of computer system 100 may be standalone servers that are connected to one another through suitable network interfaces.
- computer system 100 may be implemented in a cloud-based computing environment. In that case, the servers of computer system 100 may each be implemented as a virtual machine that runs on one or more physical servers.
- Clients 112 - 116 (generally client 112 ) and clients 122 - 126 (generally, client 122 ) may be employed by accountholders to access balances stored in the distributed ledger.
- Client 112 may be a personal computer, a laptop, a smartphone, or any other suitable computing device.
- Client 112 may include a processor and storage circuitry that stores software or other instructions that enable client 112 to exchange information (e.g., in the form of data messages) with account operator server 120 or ledger administration server 102 .
- coupling client 122 to ledger administration server 102 through account operator server 120 may improve the scalability of system 100 , because there may be many more clients than account operators.
- Client 122 may store account balances for an accountholder associated with client 122 . Alternatively or additionally, client 122 may also cause account operator server 120 to store the account balances. In one example, client 122 may store account information exclusively on account operator server 120 because client 122 may be vulnerable to theft (e.g., if client 122 is a mobile device) or may have a higher chance of being accessed illegally (e.g., through hacking) or tampered with (e.g., by infection with a software virus).
- Account operator server 120 may include processors and storage circuitry to store the account information per accountholder and associate the account balance held in the distributed ledger with a conventional bank account (e.g., checking or savings accounts) maintained by the accountholder.
- account operator server 120 may be a commercial bank server.
- Ledger administration server 102 stores a master copy of the distributed ledger, which includes account balances for all accountholders in system 100 .
- the account of each accountholder may include balances in multiple assets.
- Ledger administration server 102 may employ a processor to process transactions received in form of data messages from client 122 (possibly through account operator server 120 ).
- a transaction may involve a single asset or multiple assets (for example: in case of a foreign exchange transaction there will be two assets which are both currencies).
- Ledger administration server 102 may be coupled to asset validation servers 130 and 132 (generally, asset validation server 130 ), and the processing of a transaction by ledger administration server 102 may include the exchange of data messages between ledger administration server 102 and asset validation server 130 .
- Asset validation server 130 may include a processor and storage circuitry configured to store redundant copies of the distributed ledger.
- the storage of the redundant copies may improve the robustness, reliability, and security of the ledger, because in order to falsify or otherwise alter account balances stored by the encrypted distributed ledger, several of the redundant copies would need to be modified.
- ledger administration server 102 and asset validation server 130 operate independently of one another, the task of compromising both servers is made more difficult.
- ledger administration server 102 and asset validation server 130 may further control visibility into the stored ledger by requiring a username and password, two-factor authentication, or other suitable forms of access control to obtain read or write access to the stored ledger. Further, while ledger administration server 102 may have full access to the distributed ledger, asset validation server 130 may only be granted access to those portions of the ledger that include account balances of the specific asset that is validated by asset validation server 130 . For example, each of validation servers 130 and 132 may be associated with a asset (e.g., a fiat currency such as U.S.
- asset e.g., a fiat currency such as U.S.
- asset validation server 130 may ensure that each unit of asset stored in the ledger of system 100 is backed by a “real-life” unit of asset held or controlled by a corresponding asset validator.
- the ledger may maintain customer confidence by being transparent to regulators that oversee the supply of a given asset without revealing confidential transactional information to the general marketplace.
- proxy validation server 140 may validate transactions by means of a proxy validation server 140 .
- Proxy validation server 140 may be similar to asset validation servers 130 and 132 ; however, because proxy validation server 140 is not controlled by an asset issuing authority, proxy validation server 140 may not be able to ensure directly that each unit of asset stored in the ledger of system 100 is backed by a “real-life” unit of asset.
- proxy validation server 140 may further be connected to asset validation server 142 , which is controlled by the respective asset-issuing authority.
- asset validation server 142 may not store or control the distributed ledger
- asset validation server 142 may be configured to verify that the combined ledger balances maintained by proxy validation server 140 are backed by corresponding “real-life” funds in an escrow account.
- Asset validation server 142 may control the amount of funds held in the escrow account in real-time and may continuously update the balance in the escrow account based on supply and demand for the asset.
- Proxy validation server 140 may be configured to associate the funds in the escrow account with account balances in the ledger in real-time, such that the combined operation of proxy validation server 140 and asset validation server 142 provides a similar one-to-one correspondence of balances in the ledger with “real-life” units of the respective asset.
- Ledger administration server 102 and asset validation server 130 may be coupled to account operator server 120 .
- Account operator server 120 may employ a processor and storage circuitry to link ledger account information with customer information on behalf of clients (e.g., clients 122 - 126 ).
- Ledger administration server 102 may further be coupled to KYC validation server 150 .
- KYC validation server 150 may create and store electronic records that contain KYC information, such as tax identification numbers, checking or savings account numbers, passport or driver license numbers, or any other suitable form of personal identification.
- Ledger administration server 102 may access the KYC information stored by KYC validation server 150 by exchanging data messages.
- ledger administration server 102 may send a message that includes indications of the parties of a transaction to KYC validation server 150 along with information that verifies the authenticity of the data messages (e.g., an electronic signature of ledger administration server 102 ). Responsive to receipt of the message, KYC validation server 150 may access customer records based on the account information included in the data message and may retrieve a KYC status. KYC validation server 150 may employ a processor to prepare a data message in response to the request received from ledger administration server 102 and may send it along with its electronic signature to ledger administration server 102 . It is important to note that ledger administration server 102 and asset validation server 130 need not access KYC information in real-time or for each transaction.
- ledger administration server 102 may store KYC information obtained for client 112 and use that information to perform KYC checks. Accordingly, the aforementioned data messages that are exchanged between KYC validation server 150 and ledger administration server 102 are not necessary for every transaction, which helps reduce the time needed to process a transaction.
- FIG. 2 shows a diagram of a distributed ledger 200 to illustrate visibility restrictions.
- ledger 200 is shown as a table including rows 210 that contain ledger account balances per client, and columns 212 that correspond to different assets.
- ledger 200 contains at least one ledger account balance per asset.
- an accountholder associated with client A has an account balance of A USD U.S. dollars, A EUR Euros, A GBP pounds, and A JPY Japanese Yen.
- Some clients may only maintain an account balance for a subset of the available assets. Records stored in ledger 200 may include an indication that specific assets are not used.
- client B has a ledger account balance for U.S. dollars but no account balance for Euros.
- a reserved value may be stored in ledger 200 instead of associating a zero balance to indicate that client B generally does not perform transactions that involve the given asset.
- another reserved value may be used to indicate that a client is not permitted to perform transactions for a certain asset (e.g., due to regulatory or AML regulations).
- client C may not be permitted to perform ledger transactions that involve Japanese Yen, which is denoted by an “X” in the corresponding entry of the ledger.
- system 100 provides swift processing of transactions that may be validated by regulators but opaque to the marketplace.
- ledger 200 illustrates the visibility restrictions that are enforced by system 100 .
- asset validators may have restricted access to ledger account balances that pertain to the specific asset validated by them.
- an asset validator for U.S. dollars e.g., asset validator 130
- an asset validator for Japanese Yen e.g., asset validator 132
- ledger portion 204 may only have access to ledger portion 204 .
- a client corresponding to a specific accountholder may have access to all ledger account balances associated with said client, such as ledger portion 206 , which includes ledger account balances in U.S. dollars, pounds, and Japanese Yen.
- client A may initiate a transaction with client D, such as a foreign exchange transaction.
- client D may buy A′ USD from client D in exchange for D′ JPY Japanese Yen.
- This transaction involves two currencies, namely U.S. dollars and Japanese Yen.
- Ledger administration server 102 may receive separate data messages from clients A and D that request the transaction and may control the processing of the transaction. As such, ledger administration server 102 may have complete access to the ledger account balances of clients A and D.
- asset validation servers 130 and 132 may only have access to portions of the ledger.
- asset validation server 130 may validate the U.S. dollar portion of the transaction and may therefore access ledger portion 202 which includes the ledger account balances A USD and D USD .
- asset validation server 132 may validate the Japanese Yen portion of the transaction and may therefore access ledger portion 204 which include the ledger account balances A JPY and D JPY .
- FIG. 3 is a block diagram of a ledger administration network 300 .
- Ledger administration network 300 includes ledger administration server 310 , asset validation server 330 , account operator server 340 , and KYC validation server 360 .
- Ledger administration server 310 and asset validation server 330 exchange data messages in order to maintain redundant copies of distributed ledger 200 subject to visibility constraints that allow the transparency required by regulators while making ledger account balances otherwise inaccessible to the general marketplace.
- Ledger administration server 310 controls the processing of a transaction and exchanges data messages with asset validation server 330 to verify the authenticity and accuracy of a transaction. Unless ledger administration server 310 receives a data message from asset validation server 330 that approves the transaction, ledger administration server 310 may not approve the transaction.
- this validation by asset validation server 330 provides that ledger account balances have a one-to-one correspondence with units of an asset controlled by the issuing authority of the asset associated with asset validation server 330 .
- ledger administration server 310 may send a data message to KYC validation server 360 to request validation of the KYC status of parties involved in the transaction.
- ledger administration network 300 may not require that KYC information be verified for each transaction.
- KYC information may be stored at ledger administration 310 or asset validation server 330 and updated only at predetermined times (e.g., by exchanging data with KYC validation server 360 ). An update of KYC information may be requested by ledger administration server 310 or it may be pushed to ledger administration server 310 by KYC validation server 360 .
- Ledger administration server 310 includes processing server 324 and network interface 316 , both of which are connected to bus 326 .
- Network interface 316 may enable the exchange of data messages between ledger administration server 310 , asset validation server 330 , account operator server 340 , and KYC validation server 360 .
- Network interface 316 may also be used to exchange data messages directly with client 112 .
- Processing server 324 may control the processing and data exchange performed by ledger administration server 310 .
- Processing server 324 may also include authentication and encryption circuitry to validate signatures associated with data messages, and enforce the access constraints that ledger 200 is subject to.
- Bus 326 is further coupled to asset validator database 320 , KYC status database 322 , and access control circuitry 318 . Access control circuitry 318 restricts access to wallet database 312 and balance database 314 .
- asset validator database 320 is coupled to bus 326 directly because ledger administration sever 310 makes accessible information stored in asset validator database 320 without access restrictions.
- access control circuitry 318 may control access to information stored in wallet database 312 and balance database 314 .
- asset validator database 320 stores a list of pointers, network addresses, or other suitable identification of asset validation servers (e.g., asset validation server 330 ) per asset.
- ledger administration server 310 requests validation from at least one validation server for each asset involved in the transaction.
- multiple asset validation servers may be provided per asset.
- asset validation server 330 may distribute the processing of transactions among the multiple asset validation servers.
- the multiple asset validation servers may also store a larger number of redundant copies of the distributed ledger. A larger number of ledger copies may further strengthen the resilience of ledger administration network 300 against malicious actors or fraudulent transactions.
- Ledger administration server 310 further includes wallet database 312 and balance database 314 , which are configured to store a copy of the ledger account balances maintained by ledger administration server 310 .
- wallet database 312 may store all assets held by a given client, together with other identifying information such as conventional bank account numbers as well as cryptographic codes (e.g., the client's public key).
- the ledger balances held by the client per asset may be stored in balance database 314 , as will be discussed in relation to FIG. 4 .
- wallet database 312 and balance database 314 may be combined and store, per client, both the assets and the corresponding account balances in a common data structure.
- Ledger administration server 310 may restrict access to information stored in wallet database 312 and balance database 314 by using access control circuitry 318 .
- Access control circuitry 318 may limit the access of a specific client to accounts held by the accountholder associated with the specific client. Access control circuitry 318 may provide these access restrictions by requiring a username and password or two-factor authentication prior to providing access to the database.
- Ledger administration server 310 may also have full access to wallet database 312 and balance database 314 . However, access control circuitry 318 may ensure that ledger balances stored by wallet database 312 and balance database 314 are inaccessible to the general marketplace.
- Ledger administration server 310 includes KYC status database 322 .
- Ledger administration server may employ processing server 324 to store KYC status information (e.g., information identifying whether a client's account is valid or invalid) per client or per account.
- Ledger administration server 310 may utilize KYC status database 322 to obviate the need for exchanging KYC data with KYC validation server 360 every time a transaction is processed. Rather, ledger administration server 310 may update KYC status database 322 at predetermined times, by exchanging data messages with KYC validation server 360 , but otherwise retrieve KYC status information from KYC status database 322 in substantially real-time as part of processing a transaction.
- asset validation server 330 may store KYC status information in a similar way as ledger administration server 310 .
- asset validation server 330 may employ processing server 334 to store KYC status information per client or per account and may perform KYC status verification prior to approving transactions received from ledger administration server 330 .
- asset validation server 330 may employ the stored KYC status information (rather than exchange data messages with KYC validation server 360 for each transaction) in order to reduce the time it takes to process transactions.
- asset validation server 330 includes network interface 332 and processing server 334 , both of which are connected to bus 339 .
- Bus 339 is further coupled to asset balance database 336 , pending balance database 337 , and reserved balance database 338 .
- network interface 332 may be used to exchange data messages with ledger administration server 310 and account operator server 340 .
- network interface 332 may be connected to additional asset validation servers.
- Ledger administration server 310 or asset validation server 330 may control the additional asset validation servers and distribute the load associated with transactions among the additional asset validation servers.
- the additional asset validation servers may further provide additional protection from unauthorized transactions because each of the additional asset validation servers may store redundant copies of the distributed ledger.
- Processing server 334 may be employed to authenticate data messages received from other servers in ledger administration network 300 .
- Asset balance database 336 , pending balance database 337 , and reserved balance database 338 may store a partial copy of ledger 200 , which includes ledger account balances for the asset validated by asset validation server 330 .
- ledger account balances for the asset validated by asset validation server 330 .
- asset validation server 330 validated all transactions in U.S. dollars
- asset balance database 336 , pending balance database 337 , and reserved balance database 338 would store all ledger account balances in U.S. dollars.
- asset validation server 330 would not have access to ledger account balances in other assets, such as Euros or Japanese Yen.
- asset balance database 336 may store a copy of the ledger account balances for transactions that have previously been approved by asset validation server 330 and for which completion of the transaction was reported by ledger administration server 310 as part of a ledger update.
- reserved balance database 338 may store payment balances that have been approved by asset validation server 330 but not yet reported as complete by ledger administration server 310 . For each account balance, only outgoing payments but not incoming payments may be recorded, and thus balances in pending balance database 338 may be non-negative.
- pending balance database 337 may store balances for payments that have been validated by asset validation server 330 and signed by ledger administration server 310 but not yet included in the updated asset balance database.
- asset validation server 330 may reduce a published ledger balance maintained in asset balance database 336 by the amounts stored in pending balance database 337 (e.g., the total sum of pending payments) and by the amount stored in reserved balance database 338 (e.g., the total sum of reserved payments).
- the resulting balance is known as “shadow balance” and accounts for transactions that have been processed by asset validation server 330 but not yet reported as “complete” by ledger administration server 310 in an updated ledger copy.
- attempts to “double spend” e.g., by submitting multiple transactions in quick succession
- asset validation server 330 updates the “shadow balance” in response to validating each transaction.
- KYC validation server 360 may include network interface 362 and processing server 364 , both of which are connected to bus 369 .
- KYC validation server 360 may use network interface 362 to exchange data messages with ledger administration server 310 and asset validation server 330 .
- Processing server 344 may authenticate data messages received from or sent to other servers in ledger administration network 300 .
- KYC validation server 360 further includes KYC database 366 , which may store customer identifications. Information stored in KYC database 366 may be used to ensure compliance with KYC requirements. For example, at predetermined times, ledger administration server 310 may send a data message to KYC validation server 360 to verify a party's KYC status. KYC validation server 360 may store the relevant KYC status in KYC database 366 .
- KYC validation server 360 may search KYC database 366 based on a client identifier (e.g., a client's public key) and retrieve the client's current KYC status. KYC validation server 360 may then transmit a data message back to ledger administration server 310 . It should be noted that KYC status need not be checked in real-time for every transaction. Rather, ledger administration server 310 and asset validation server 330 may access KYC information at predetermined times and use a locally stored status for processing transactions.
- a client identifier e.g., a client's public key
- account operator server 340 may include network interface 342 and processing server 344 , both of which are connected to bus 349 .
- Account operator server 340 may serve as an account processor for parties that prefer that information about ledger account balances be maintained on account operator server 340 rather than on their associated client (e.g., client 112 ). In this scenario, account operator server 340 essentially supplies the aforementioned processes in place of the client.
- Account operator server 340 may store information about the ledger account balances in account database 346 .
- account operator server 340 and KYC validation server 360 may be combined an implemented in a single server architecture.
- the redundant copies of the distributed ledger stored by ledger administration server 310 and asset validation server 330 may be stored in encrypted form.
- Ledger administration server 310 may control the visibility into the distributed encrypted ledger by employing an encryption process that encodes portions of the ledger differently, such that a decryption process that allows access to a first portion of the ledger cannot be used to access a second portion of the ledger.
- ledger administration server 310 may encrypt balances corresponding to a first asset (e.g., U.S. dollars) such that only a decryption process used by a first asset validation server (e.g., a server at the Federal Reserve) can decrypt the balances.
- a first asset e.g., U.S. dollars
- ledger administration server 310 may encrypt balances corresponding to a second asset (e.g., Euros) such that the decryption process used by the first asset validation server (e.g., a server at the Federal Reserve) cannot decrypt the balances of the second asset, but only balances corresponding to the first asset.
- ledger administration server 310 and asset validation server 330 may exchange copies of the distributed encrypted ledger to ensure that the ledger is consistent across servers in ledger administration network 300 .
- the asset validation servers may only be able to access portions of the distributed encrypted ledger, it can be desirable to exchange copies of the ledger in their entirety, e.g., for record keeping or improved robustness against failure of ledger administration server 310 .
- FIG. 4 depicts an exemplary data structure 400 for storing ledger balances and account information in the distributed ledger.
- Data structure 400 includes wallet table 410 , KYC validator table 440 , and asset table 450 .
- Wallet table 410 includes a list of data blocks, each of which stores ledger balances associated with a specific client, such as clients 410 a - 410 c .
- a data block of wallet table 410 may contain a public key 412 , asset 414 , account information 416 , per-account balance 418 , KYC approval status 420 and a copy of the cryptographically signed KYC approval message, and an extra signatures field 422 , for a list of any additional signatures that may be required to process a transaction for account 416 .
- Public key 412 may be used by servers across ledger administration network 300 to verify the authenticity of messages received from a client or server.
- Asset 414 may indicate one or more currencies or other assets for which the client maintains a ledger balance.
- Account information 416 may include conventional bank account information (e.g., corresponding to a checking or savings account, or a custody account for securities), and several accounts per asset may be possible.
- the currencies may include fiat currencies such as U.S. dollars or Euros, but also other types of currencies, such as cryptographic currencies (e.g., bitcoins or ripples), or any other suitable form of currency or asset.
- Data block 410 c may store ledger balances 418 associated with each account 416 . In some aspects, a separate balance table may be maintained in the ledger and may not be incorporated into data block 410 c .
- Data block 410 c may further include per-account KYC status 420 , which includes an indication of whether account 416 has been verified as KYC compliant by one of the approved KYC validators 444 listed in and also the ID of the validator for reference KYC validator table 440 .
- per-account KYC status 420 includes an indication of whether account 416 has been verified as KYC compliant by one of the approved KYC validators 444 listed in and also the ID of the validator for reference KYC validator table 440 .
- “Citibank” may be the KYC validator for one of the accounts in U.S. dollars
- “Deutsche Bank” may be the KYC validator for one of the accounts in Euros, etc.
- data block 410 c may include C.C. transaction list 424 , a field that stores the identity of extra parties that need to be informed (e.g., carbon copied) about a transaction.
- C.C. transaction list 424 may be stored per client, as shown in FIG. 4 , in which case the parties that are notified about a transaction do not depend on which of the client's accounts is involved in a transaction.
- C.C. transaction list 424 may also be stored per account (e.g., as part of account information 416 ). In that case, different parties may be notified of transactions, dependent on which of the client's accounts is involved in a transaction.
- the entries in C.C. transaction list 424 may specifically identify the parties that are to be notified, and may include additional identifiers associated with a transaction.
- Per-account KYC status 416 may be established by a KYC validator 444 listed in KYC validator table 440 .
- KYC validator table 440 may include a pointer 442 which may identify each KYC validator listed in KYC validator list 444 .
- Each KYC validator 444 may be approved by an asset validator 454 in asset table 450 (e.g., a central bank) for a corresponding asset 452 .
- Asset table 450 may store, for each asset validator 454 , a public key 455 that may be employed by other parties to verify the authenticity of data messages received from asset validator 454 .
- asset table 450 includes a list of pointers 456 which are linked with pointers 442 such that every validator 454 may be linked with a group of approved KYC validators in KYC validator 444 for a asset 452 .
- the Federal Reserve may serve as the asset validator, and Bank of America and Citibank may be among approved KYC agents.
- asset table 450 may be a global data structure that is not linked to a specific client or data block 410 c .
- KYC validator table 440 may store a public key 445 for each KYC validator 444 that may be employed by other parties to verify the authenticity of data messages received from KYC validator 444 .
- FIG. 5 shows a flowchart of a process 500 for updating a distributed ledger based on data messages received from validation servers that each store partial, redundant copies of the ledger.
- Process 500 may, at step 502 , receive input from the parties involved in a transaction (e.g., clients 112 or 122 ), while the remaining steps of process 500 may be performed by ledger administration network 300 .
- the successful processing of a transaction may have ledger administration server 102 receive validations from asset validation servers (e.g., asset validation servers 330 ) as well as KYC verifications (e.g., from KYC validation server 360 ).
- Process 500 may start at step 502 by receiving authentication requests from clients that are parties in a transaction.
- the access of the clients to ledger administration network 300 may be protected by a two-factor authentication mechanism or by providing a username and password.
- a username may specifically identify a client (e.g., client 112 ) and may be linked to the account of the client in the distributed ledger.
- the authentication procedure as well as the interface that clients use for submitting data messages with their transaction requests may be part of a specially designed Application Program Interface (API).
- API Application Program Interface
- the API used by the clients to access ledger administration network 300 may collect from the clients and may store information about the requested transaction, such as the assets involved in the transactions, the ledger balances to be transferred or exchanged, as well as any other pertinent information needed for processing the transaction.
- the clients may also input information about other parties (e.g., their respective public key or account information) that have previously agreed to be part of the transaction by other means (e.g., by voice, by email or through a conventional foreign exchange trading or processing platform).
- Each of the clients involved in a transaction may individually append their respective signatures to the data messages. The signatures identify the parties associated with a transaction request as well as transaction details.
- Clients may generate their respective signatures by hashing the data corresponding to the details of the transaction requested by said client, and then by encrypting the resulting hash using the client's private key to obtain an encrypted signature, as will be described in more detail in connection with FIG. 6 .
- process 500 may receive a plurality of transaction requests by clients that have been authenticated by ledger administration server 310 .
- the connection between ledger administration server 310 and the client device that accesses ledger administration server 310 through the API may be authenticated using conventional authentication protocols (e.g., the “Oauth” protocol).
- Process 500 may, at step 506 , validate each party's signature that is associated with a transaction request.
- Process 500 may determine the validity of each client's signature by decrypting the signature to obtain a hash. The hash may then be compared with another hash obtained independently from the data message, as will be described in connection with FIG. 6 .
- process 500 may determine at step 508 whether the processing of the transaction requires any additional signatures. For example, KYC policies for a given client may require that other parties confirm transactions requested by a specific individual by adding extra signatures in extra signatures field 422 of data block 410 c as described in connection with FIG. 4 . If additional signatures are required, ledger administration server 310 may collect and validate the additional signatures at step 510 , prior to continuing with process 500 . Ledger administration server 310 may also check if any of the parties of a transaction have not yet provided their signatures. For example, a transaction may involve multiple clients, not all of which may have provided signed data messages at step 504 .
- ledger administration server 310 may identify the type of transaction requested and send a request for any missing signatures. For instance, in a foreign exchange transaction, where the transaction involves multiple clients, the transaction information sent by a client using the API also contains information about the other parties that may take part in the transaction. In some embodiments, these parties have previously agreed to be part of the transaction by other means (e.g., by voice, by email or through a conventional foreign exchange trading or processing platform) and are known to the other participants in the transaction. At step 510 , ledger administration server 310 , may add the identities of the participants in C.C. transaction list 424 and their signature in extra signatures 422 .
- These data tables may start to be filled when the data from the first client requesting the multiple party transaction is received and authenticated in step 504 by ledger administration server 310 . Then, extra signatures table 422 is marked as incomplete, the identity of the parties listed in C.C. transaction list 424 is checked and matched to extra signatures table 422 one by one, as said parties log into the system and submit a request for the same transaction. When all parties have agreed to the transaction, extra signatures table 422 is marked as complete, and process 500 continues to the next step.
- Ledger administration 310 may implement a time-out mechanism using hardware or software control that sets a window of time for step 510 , in which all the parties in a transaction agree to be part of it. In this way, process 500 may verify that all of the parties involved in a transaction have given authorization to be part of it, and have mutually acknowledged the other parties taking part in the same transaction.
- process 500 may, at step 511 , match transaction between parties.
- ledger administration server 310 may process a foreign exchange transaction by identifying a party that has submitted a transaction to sell a first asset in exchange for a second asset.
- Ledger administration server 310 may process the transaction of that party and match it with another transaction that has been received by another party seeking to sell the second asset in exchange for the first asset.
- Process 500 may, at step 512 , check the KYC status for each client.
- a KYC check may be mandated by law, and ledger administration server 310 may be configured to perform such a KYC check prior to approving any modification to the distributed ledger.
- ledger administration server 310 may check that bank account details linked to each client account in the ledger have been verified and signed by a KYC validator.
- a list of approved KYC validators may be stored in KYC status database 322 (maintained by ledger administration server 310 ).
- a data structure similar to asset table 450 and KYC validator table 440 may be used, as discussed in connection with FIG. 4 .
- Process 500 may determine whether the KYC status of all parties is valid. If any of the parties is associated with an invalid KYC status, process 500 may reject the transaction as a whole and may prevent any of the parties' ledger account balances from being updated. Otherwise, process 500 may determine at step 517 whether the ledger balance stored at ledger administration server 310 is greater than or equal to a payment amount of the transaction. If ledger administration server 310 determines that the ledger balance is sufficient, process 500 causes ledger administration server 310 to sign the transaction at step 518 and forward a data message with the transaction details to asset validators (e.g., asset validation server 330 ).
- asset validators e.g., asset validation server 330
- ledger administration server 310 may determine to which asset validation servers the transaction needs to be forwarded.
- ledger administration server 310 may include a database that stores a list of asset validators (e.g., asset validator table 450 ).
- Ledger administration server 310 may determine the assets involved in the transaction, and forward data messages with transaction details to the asset validators obtained from asset table 450 .
- process 500 may receive either an approval or a rejection from the asset validators associated with the transaction.
- the approval mechanism of a transaction by an asset validator may include the validation of the signatures of both the clients involved in the transaction as well as the validation of the signature associated with ledger administration server 310 .
- the asset validation servers may compare the proposed transaction amount against the currently available balance, or “shadow balance” of each client.
- the shadow balance of a client for a given asset may correspond to the amount of the last published asset ledger balance for that client, minus a cumulative balance of all payments marked as “pending” or “reserved.”
- Pending payments may correspond to fully signed, approved outgoing payments that have not been included in the latest ledger balance update received from ledger administration server 310 .
- Reserved payments may correspond to outgoing payments that have been partially signed and not yet approved by ledger administration server 310 . If this shadow balance is sufficient to cover the requested transaction, the amount required for such a transaction is added to the “reserved” amount, to prevent double-spending or “replay.”
- Asset validation servers may further perform any additional non-public checks as required by regulation or law. Furthermore, asset validation servers may perform an additional layer of KYC validation. At this point, if all checks pass, the asset validation servers sign the transaction, and forward it to ledger administration server 310 .
- process 500 may determine whether any of the asset validation servers has rejected the transaction or if any of the KYC checks has failed. If so, process 500 may determine, at step 524 , that the transaction should be rejected. Conversely, process 500 may determine that the transaction is eligible for approval. Process 500 may then, at step 526 , determine whether the transaction should be approved and marked for publication in the ledger.
- Ledger administration server 310 may employ a consensus process that processes the fully approved messages received from the asset validation servers in order to include them in a new version of the ledger. Ledger administration server 310 may execute the consensus process periodically. In one example, the consensus process executed by ledger administration server 310 may determine to include those transactions if all of the messages received from the asset validation servers approve including those transactions. Otherwise, if the consensus process determines that at least one of the messages rejects those transactions, the proposed new ledger may be rejected in its entirety and the process repeated with an updated set of transactions. In another example, the consensus process executed by ledger administration server 310 may only require that at least a certain fraction of the data messages received from the asset validation servers approves the new ledger.
- the consensus process may determine that the new ledger for each asset should be approved if more than 80% of the messages received from the asset validation servers for that asset approve the transaction.
- every transaction may have an associated “transaction ID” and may be listed alongside a hash of the signed transaction message. This hash may be used by the asset validation servers to quickly compare with transactions which it has approved in order to identify all the participants (e.g. clients and validators) in the transaction and the amounts and assets of the transaction.
- the process of agreeing a new ledger may be used to consolidate updates to the distributed ledger at each of the asset validators, e.g., in order to remove the “pending” or “reserved” status for completed transactions and to update asset balance database 336 .
- process 500 may further perform anti-money laundering (AML) checks.
- the asset validation servers e.g., asset validation server 330
- Asset validation server 330 may further use a detection process to analyze the collected data and flag activity that matches suspicious patterns or other types of irregular account activities. Responsive to flagging an activity as suspicious, asset validation server 330 may generate a warning message. The warning message may cause the KYC status of the affected account to be changed to “not approved,” thus blocking transactions relating to this account from being approved.
- Process 500 may publish the ledger on a need-to-know basis.
- An important aspect of the present disclosure is the ability of ledger administration network 300 to maintain a distributed ledger without revealing sensitive information to the general marketplace, while providing regulators with the necessary transparency to validate transactions.
- the full ledger is stored by ledger administration server 310 and redundant partial copies are kept by the asset and KYC validators.
- the data contained in the redundant copies of the distributed ledger stored at ledger administration server 310 , and at the asset validation servers, is kept synchronized, and the circuitry required for communication between asset validation servers and the ledger administration server may be designed such as to avoid latency between transaction publication in the ledger, and the process of cross-validation of the full ledger with the partial fragments kept by the validators.
- even fully-redundant copies of the ledger may be stored by asset validation servers and the ledger administration server, thus reducing the risk of external interference or system wide malfunctions.
- Authentication techniques may provide that full access to the ledger balances is only available at the ledger administration server, while asset validation servers are only able to access their respective portions of the distributed ledger.
- FIG. 6 illustrates two interrelated high level block diagrams 600 and 650 which jointly describe the process of authenticating a transaction.
- Diagram 600 details the procedure used to generate signed data by a party seeking the authentication, from a second authenticating party.
- Diagram 600 includes the original data 602 to be authenticated, a hash function 604 , which processes the original data to produce a hash 606 , an encrypted signature 610 generated with a private encryption key 608 , and a new data structure 612 that results from appending the encrypted signature 610 to the original data 602 .
- the generation of the signed data may start with the hashing of the original data 602 .
- the hashing is performed based on a hash function 604 that takes transaction details as input data, and outputs a unique string of data (hash) 606 .
- the hash is then encrypted by conventional encryption methods (e.g., using RSA encryption) using a private key 608 which is only known to the party that authenticates the transaction.
- private key 608 a string of data is generated, corresponding to an encrypted signature 610 .
- Signature 610 may then be appended at the end of the original data 602 , or it may be included as a header.
- the resulting signed data 612 is sent to the party seeking to authenticate the origin of the data 612 .
- Diagram 650 describes the authentication procedure followed by an authenticating party of the signed data 612 generated by the process described in diagram 600 . It includes the received signed data 652 , which is composed of the original data 654 of the transaction, and the encrypted signature 656 generated in accordance with diagram 600 . Diagram 650 also includes a public key 660 , used for decryption of the signature 656 , a hash function, 658 , and two hashes 658 and 664 , generated by the two alternate mechanisms described below.
- Signed data 652 received by the authenticating party is separated into two fragments.
- the first data fragment 654 corresponds to the original data describing the transaction solicited by the party seeking authentication.
- the second fragment is an encrypted signature 656 .
- the transaction data 654 is hashed by the hash function 658 , which is identical to hash function 604 , used in diagram 600 to generate the encrypted signature 610 .
- the encrypted signature 656 is decrypted with a public key 660 that is in the possession of the authenticating party, which according to conventional encryption techniques is linked with private key 608 .
- the decryption of the signature using the public key produces a second hash, 664 , which is compared with hash 662 .
- the authentication is successful if 662 and 664 are identical. If this is not the case, the authentication process is marked as invalid and the requested transaction is rejected.
- FIG. 7 is a flowchart 700 for processing transactions by ledger administration server 702 and two asset validation servers, asset validation servers 704 and 706 .
- These validation servers may validate transactions for two different assets.
- asset validation server 704 may validate transactions in U.S. dollars
- asset validation server 706 may validate transactions in Euros.
- Asset validation servers 704 and 706 may validate transactions by verifying that the transactions have been properly authenticated and by determining that the transaction amount is below an available balance in the account, reduced by pending or reserved payments.
- Flowchart 700 illustrates the process for a foreign exchange trade, for instance, of U.S. dollars and Euros. Time has been incorporated in FIG.
- flowchart 700 (represented by the arrow) along the vertical axis such as to illustrate the timing of data exchanges between servers in the ledger administration network.
- the steps depicted in flowchart 700 are executed in response to validating the signatures of the parties involved in a transaction, as discussed in relation to steps 508 and 510 in FIG. 5 .
- the servers of ledger administration network are represented by ledger administration server 702 , asset validation server 704 , and asset validation server 706 , each of which may provide validating input to determine the processing and approval of the transaction.
- the exchange of messages between the different servers of process 700 may be implemented based on the network architecture illustrated in FIG. 3 .
- the circuitry of the network interfaces 316 , 332 and 342 may be used in combination with the two-stage authentication process 600 for the exchange of messages between ledger administration server 702 and asset validation servers 704 and 706 .
- the circuitry of the network interfaces may work in conjunction with a machine-to-machine authentication protocol such as “Oauth” to prevent external interference with the communication between servers. This may be important given the possible large geographic spread of ledger administration server 702 , asset validation server 704 and asset validation server 706 .
- ledger administration server 702 determines the assets associated with the transaction at step 708 . Once this list of assets has been identified, the list may be compared with asset table 450 in order to determine the identity of the asset validation server for each asset to be exchanged in the transaction. Similar to step 517 discussed in relation to FIG. 5 , ledger administration server 702 may further determine whether the ledger balance stored at ledger administration server 702 is greater than or equal to a payment amount required by the transaction. If ledger administration server 702 determines that the balance is not sufficient, ledger administration server 702 may reject the transaction. Otherwise, ledger administration server 702 may sign the transaction and mark it as “pending validation” at step 710 . The signature process 600 as described in FIG.
- the data block 602 in this case, may contain as a header the signed data block 652 which may be sent by the API running in the device that the client used to request the transaction. This data block may be signed at step 710 by ledger administration server 702 as described by process 600 in FIG. 6 and the transaction may be marked as “pending validation.”
- Ledger administration server 702 may send the transaction information to the asset validators that may be determined internally at step 708 by ledger administration server 702 according to the mapping specified in currency table 450 , and using the network architecture described in FIG. 3 .
- asset validation server 704 e.g., the server validating U.S. dollar transactions
- the signatures of the clients and the signature of ledger administration server 702 are decrypted and verified.
- the decryption and validation of the signatures and the verification of the integrity of the data describing the transaction may follow process 650 as described in FIG. 6 .
- Asset validation server 704 calculates the shadow balance for a given asset of the client.
- the shadow balance per client per asset is the balance of the last published asset balances in the ledger for a given client, denoted as the “latest published ledger balance”, minus the amount for “pending transactions”, which are payments that have been approved, validated and fully signed, but that have not been included in the last published distributed ledger, minus the amount for “reserved” transactions, which are transactions that have not been marked as completed but have been partially signed.
- Pending and reserved transactions may be moved to the local ledger balance once an updated ledger including the last transaction ID is published by ledger administration server 702 .
- asset validation server 704 determines if the shadow balance calculated at step 716 , is greater than the amount of the requested transaction. In that case, asset validation server 704 allows the transaction to continue.
- step 720 if the shadow balance is greater than or equal to the amount of the current transaction, asset validation server 704 updates the local asset ledger to reserve the transaction amount and update the shadow balance.
- the swift or immediate update of the shadow balance may be an important safeguard against “double spending” or “replay” attempts.
- asset validation server 704 signs and sends a validation approval message to ledger administration server 702 .
- the approval message may include an acknowledgment flag that marks the asset validation process as successful.
- a second message is sent by ledger administration server 702 to asset validation server 706 , which in this example, may be the server validating the Euro portion of the transaction.
- the steps 724 - 730 , performed by asset validation server 706 may be similar to steps 712 - 718 performed by asset validation server 704 .
- step 730 performed by asset validation server 706 may determine that the shadow balance of the client in Euros is less than the amount of the requested transaction. Responsive to this determination, asset validation server 706 may sign and send a rejection message to ledger administration server 702 .
- ledger administration server 702 After receiving an approval message from asset validation server 704 and a rejection message from asset validation server 706 , ledger administration server 702 determines that no consensus has been reached and rejects the transaction. In another scenario, in which all the asset validation servers have validated the transaction, the transaction is marked as “pending publication” as described at step 526 in connection with the discussion of FIG. 5 .
- Some embodiments of the present disclosure may be conveniently implemented using a conventional general purpose or a specialized digital computer or microprocessor programmed according to the teachings herein, as will be apparent to those skilled in the computer art.
- Appropriate software coding may be prepared by programmers based on the teachings herein, as will be apparent to those skilled in the software art.
- Some embodiments may also be implemented by the preparation of application-specific integrated circuits or by interconnecting an appropriate network of conventional component circuits, as will be readily apparent to those skilled in the art.
- Those of skill in the art would understand that information and signals may be represented using any of a variety of different technologies and techniques.
- data, instructions, requests, information, signals, bits, symbols, and chips may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
- Some embodiments may be implemented using existing parallel, distributed computer processing and distributed data storage frameworks (e.g., Hadoop).
- Some embodiments include a computer program product comprising a computer readable medium (media) having instructions stored thereon/in and, when executed (e.g., by a processor), perform methods, techniques, or embodiments described herein, the computer readable medium comprising sets of instructions for performing various steps of the methods, techniques, or embodiments described herein.
- the computer readable medium may comprise a storage medium having instructions stored thereon/in which may be used to control, or cause, a computer to perform any of the processes of an embodiment.
- the storage medium may include, without limitation, any type of disk including floppy disks, mini disks (MDs), optical disks, DVDs, CD-ROMs, micro-drives, and magneto-optical disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices (including flash cards), magnetic or optical cards, nanosystems (including molecular memory ICs), RAID devices, remote data storage/archive/warehousing, or any other type of media or device suitable for storing instructions and/or data thereon/in. Additionally, the storage medium may be a hybrid system that stored data across different types of media, such as flash media and disc media. Optionally, the different media may be organized into a hybrid storage aggregate.
- different media types may be prioritized over other media types, such as the flash media may be prioritized to store data or supply data ahead of hard disk storage media or different workloads may be supported by different media types, optionally based on characteristics of the respective workloads.
- the system may be organized into modules and supported on blades configured to carry out the storage operations described herein.
- some embodiments include software instructions for controlling both the hardware of the general purpose or specialized computer or microprocessor, and for enabling the computer or microprocessor to interact with a human user and/or other mechanism using the results of an embodiment.
- software may include without limitation device drivers, operating systems, and user applications.
- computer readable media further includes software instructions for performing embodiments described herein. Included in the programming (software) of the general-purpose/specialized computer or microprocessor are software modules for implementing some embodiments.
- DSP digital signal processor
- ASIC application-specific integrated circuit
- FPGA field programmable gate array
- a general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine.
- a processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
- any software module, software layer, or thread described herein may comprise an engine comprising firmware or software and hardware configured to perform embodiments described herein.
- functions of a software module or software layer described herein may be embodied directly in hardware, or embodied as software executed by a processor, or embodied as a combination of the two.
- a software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
- An exemplary storage medium is coupled to the processor such that the processor can read data from, and write data to, the storage medium.
- the storage medium may be integral to the processor.
- the processor and the storage medium may reside in an ASIC.
- the ASIC may reside in a user device.
- the processor and the storage medium may reside as discrete components in a user device.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- Finance (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Computer Security & Cryptography (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Marketing (AREA)
- Technology Law (AREA)
- Data Mining & Analysis (AREA)
- Databases & Information Systems (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
The systems and methods described herein relate to processing financial transactions using a computer network that stores a distributed ledger, and particularly, to updating the distributed ledger based on data messages received from validation servers that each store a portion of the ledger corresponding to a respective asset. The systems and methods described herein employ the distributed ledger to control visibility of transactions to the general marketplace, but still provide swift and assured completion of transactions and visibility and audit capability for regulators.
Description
- The processing of financial transactions, in particular on the foreign exchange market, can involve substantial settlement risk because such transactions generally comprise two parts. For example, a transaction in which a first party buys a certain amount of U.S. dollars from a second party in exchange for Euros may be processed in two parts, namely (i) the transfer of Euros from the first to the second party, and (ii) the transfer of U.S. dollars from the second to the first party. In the absence of a trusted third party, the two parts of such foreign exchange transactions are processed at different times due to varying processing times, time zone differences, or other factors. Until both parts of the transaction are completed, a party that has completed its part of the transaction but not yet received funds from the other party is subject to risk, because the other party may default on its obligation. This risk is known as “Herstatt” risk.
- To mitigate the Herstatt risk associated with foreign exchange transactions, transactions may be settled by a trusted third party (e.g., CLS). The trusted third party accepts transactions from its member institutions (e.g., commercial banks), temporarily holds the funds of one party until the other party has also provided its funds, and then processes all parts of the transaction together. The trusted third party thus ensures that a transaction is either processed in its entirety or not at all. Further, the trusted third party can guarantee that funds are reserved for a specific transaction and cannot be used in unrelated transactions. This “all-or-nothing” approach of processing a transaction is known as “atomic settlement” or “payment-vs-payment.” However, the use of a trusted third party does not necessarily establish a predetermined order in which transactions settle over the course of a given business day. In the FX market, current practice is that transactions scheduled for a specific day may settle at any time during the course of that day, which requires parties to maintain sufficient funds to ensure that, regardless of the order in which transactions are processed, funds will be available. The need to budget for a worse-case scenario can require that large amounts of funds be set aside to meet this so-called intraday liquidity requirement.
- Intraday liquidity requirements can be reduced by processing transactions in near-real-time, such that transactions settle before new transactions are initiated. In conventional banking systems this is difficult, if not impossible, to realize, because payments need to move through multiple private ledgers and thus incur delay. Cryptographic currencies, such as Bitcoin or Ripple, maintain transaction records in a single ledger for all participants and thus are able to process transactions in order and fast compared to conventional banking systems. For example, Ripple typically processes transactions in a matter of a few seconds and Bitcoin in a matter of a few hours. However, these systems suffer from significant disadvantages in terms of privacy, because they maintain balances and transaction records in publicly accessible ledgers that are stored on distributed servers. This transparency helps maintain the accuracy of records by allowing many parties to observe and approve changes applied to the ledger. For example, while a single malicious actor may be able to falsify records on a few servers, wide dissemination of the publicly available ledger may prevent such a malicious actor from altering sufficient copies of the ledger. Although wide distribution of the ledger may be desirable for record accuracy, this public availability is contrary to the desire of wholesale market participants to support controlled visibility as it can reduce the willingness of parties to supply liquidity. For example, the cost associated with providing liquidity may increase for market makers, because transactions are fully visible and this allows other parties to change their behavior before the market makers have hedged the risk associated with the transaction. In practice this means the market will move against the market maker as soon as the transaction is published. Because both the customer and the market maker know this, then expected additional cost is passed from the market-maker to the customer. For this reason neither buyer nor seller in a large transaction has an interest in immediate publication. Most regulated securities exchanges have rules which allow for delayed publication of at least some trades. The practice of moving against the market maker is known as predatory trading and is discussed in detail in the journal article “Predatory Trading,” authored by Markus K. Brunnermeier and Lasse H. Pedersen, published in “The Journal of Finance,” vol. LX, No. 4 in August 2005, which is hereby incorporated by reference herein in its entirety.
- While crypto-ledger systems such as Bitcoin and Ripple may obfuscate the identity of a specific party by using arbitrary account numbers that are not easy to attribute to a specific real-world party, large financial institutions (e.g., central banks) cannot rely on such obfuscation alone because the sheer size and volume of their transactions may reveal their identity to the general marketplace. Moreover, existing cryptographic transaction systems, such as Bitcoin or Ripple, lack designed-in identity checks that aid regulators with policing anti-money laundering (AML).
- As such, there is a need for new systems and methods that can process transactions as swiftly as Bitcoin or Ripple without sacrificing the privacy of the parties involved.
- The disclosed systems and methods are generally directed to a distributed computer network that includes a plurality of servers for maintaining and updating copies of a distributed ledger based on cryptographic authentication techniques. More particularly, the systems and methods track exchanges, such as currency exchanges, or other types of exchanges, that take place in substantially real time. To that end, the system authorizes an individual and associates with the individual an account that represents some amount of an asset (for example a regulated currency). The system performs a payment in a single asset or exchanges two or more assets in substantially real time between two or more authorized individuals by adjusting account balances maintained within redundant copies of a distributed ledger. Further, the system arranges for the exchange in a private and secure form to prevent third parties from observing the exchange (or adjusting the ledger balance) before or during the exchange process.
- The systems and methods described herein include a ledger administration server that controls a ledger to allow a payment or foreign currency exchange transaction to occur in real-time or substantially real-time. The system creates a data table that records verified accountholders and the balance of each asset held by that respective accountholder. The system further records asset issuing authorities. Each asset issuing authority is an authority (or a proxy for that authority) that controls the supply of a particular asset held by one or more of the accountholders. The system includes a validation process that provides each asset issuing authority with view/approval access to the account of each accountholder, but restricts that access to a portion of that account that records balances in the asset issued by that issuing authority.
- The system stores redundant copies of the data tables, which include account information and account balances, at the ledger administration server and at asset validation servers associated with the asset issuing authorities. The distributed storage of the data tables provides additional protection from attempts to falsify information stored in the data tables of the ledger because more than one server would need to be compromised. The system uses authentication techniques to verify identifying information and perform know-your-customer (KYC) or anti-money laundering (AML) checks. The system uses cryptographic codes to authenticate electronic signatures appended to data messages by comparing the electronic signatures to hashes obtained from processing the data messages with a public key of the signing party.
- Accountholders may submit transactions to the system through client devices, such as personal computers, laptops, smartphones, or other suitable types of devices. Responsive to user input, the client devices may generate data messages that include transaction amounts to be transferred, e.g., from a first to a second party. The transaction may involve a single asset or multiple assets, as is the case in foreign exchange transactions. Client devices may send data messages directly to the ledger administration server that controls the processing of the transaction. Client devices may also send the data messages to other servers, such as servers maintained by a commercial bank, and these servers may in turn relay the messages to the ledger administration server. The data messages may include electronic signatures appended by the client devices. These electronic signatures may be processed by the ledger administration server to verify that the data messages were sent from the client device and authorized by the respective accountholder. Responsive to verifying the electronic signatures, ledger administration server may employ a processor to identify the assets associated with the transaction, check available balances, and perform KYC validation. For example, the data message of a foreign exchange transaction, in which a first party buys U.S. dollars from a second party in exchange for Euros, may include transaction amounts in “U.S. dollars” and “Euros,” respectively. In addition to determining the assets associated with the transaction, the ledger administration server may further employ the processor to identify a set of asset validation servers that validate the transaction. For example, each of the asset validation servers may be associated with the issuing authority of a specific asset involved in the transaction. Responsive to identifying the set of asset validation servers, the ledger administration server creates data messages based on the transaction data and sends it to each of the asset validation servers. As part of creating the data messages, the ledger administration server may append electronic signatures that can be used by each of the asset validation servers to verify that the data message has been sent by the ledger administration server.
- An asset validation server associated with a given asset creates and stores redundant records of account balances included in the ledger for that given asset. The redundant records may be employed by the asset validation server to verify the balances of an accountholder independently from the ledger administration server. Responsive to receiving a data message corresponding to a transaction from the ledger administration server, the asset validation server may employ a processor to compare an account balance stored in its records with the transaction amount provided in the data message. If the account balance is greater than the transaction amount (i.e., if sufficient funds are available), the asset validation server may continue the processing of the transaction. Otherwise, the asset validation server may transmit a data message to the ledger administration server to indicate that the transaction should be rejected. The asset validation server may append an electronic signature to the data message that can be used by the ledger administration server to verify the authenticity of the data message.
- If the asset validation server determines that the account balance is greater than or equal to the transaction amount for all accountholders included in the data message and for all assets it is responsible for, the asset validation server modifies the account balance stored at the asset validation server to reserve a balance equal to the transaction amount while the transaction continues to be processed. For example, the asset validation server may employ a separate data structure to update payment amounts associated with current or pending transactions. By reserving a portion of the available balance to obtain a “shadow balance,” the asset validation server may reduce the likelihood of “double spending” or “replay.” Such double spending or replay may occur in systems that process transactions faster than updating the available balance. In such systems, fraudulent transactions that individually meet but cumulatively exceed the available balance may be approved, because the system may not update the available balance between transactions. Asset validation servers help eliminate such double spending by maintaining a shadow balance while transactions continue to be processed.
- The ledger administration server may also perform KYC checks in accordance with regulatory requirements. The ledger administration server may compile and store indications of such KYC authorizations in a look-up table, e.g., upon receiving such indication in a signed message from a KYC validator such as a commercial bank. In some aspects, KYC authorizations may be based on a chain of trust. For example, the ledger administration server may determine to accept a KYC authorization if the corresponding KYC validator indicates that it trusts the client and the ledger administration server (or asset validator associated with the asset involved in the transaction) in turn trusts the KYC validator. If the ledger administration server determines that any of the parties of a transaction is not associated with a valid KYC authorization, the ledger administration server may reject the transaction and provide a corresponding signed message to parties involved in the transaction.
- For transactions that involve more than one asset, the ledger administration server receives a separate data message from the asset validation server of each asset involved in the transaction. Responsive to the receipt of the messages, the ledger administration server determines if one or more of the data messages includes an indication that the transaction should be rejected (e.g., due to insufficient funds). If at least one of the data messages includes such a rejection, ledger administration server rejects the transaction in its entirety and does not update the ledger account balances of any parties involved in the transaction. Conversely, if all of the data messages received from the asset validation servers include indications that the transaction should be approved, the ledger administration server updates the account balances maintained in its copy of the encrypted ledger.
- The ledger administration server sends portions of the updated ledger to the asset validation servers in form of data messages. The data message sent to a specific asset validation server may only include balances for accounts held in the asset maintained by the specific asset validation server. For example, a validation server for U.S. dollars may only be sent the portion of the updated ledger that corresponds to accounts in U.S. dollars. The data messages may also include a list of completed transactions that have been incorporated into the updated ledger together with their respective unique identifiers and transaction amounts. Responsive to receiving the data message, the asset validation server may update its records based on the list of completed transactions, by modifying the account balances and records of reserved and pending payments. For example, an asset validation server may remove the transaction amount of a completed transaction from the shadow balance because that completed transaction is now reflected in the account balances included in the updated ledger. The asset validation server may further update status indications corresponding to transactions included in the list of transactions to denote that they have been completed and are no longer pending. The periodic transmission of account balances from the ledger administration server to the asset validation servers helps ensure that the distributed and redundant copies of the encrypted ledger, which are maintained separately at the ledger administration server and the asset validation server, remain consistent.
- In summary, the systems and methods described herein address the problem of the significant time delay that arises in current exchange processes by providing a system architecture that can operate in substantially real-time. The systems and methods further address the problem of lack of identity verification of parties participating in current exchange processes by making identity checks that can satisfy KYC standards a component of the exchange process. The systems and methods further address the problem of disclosing information about account balances or transactions to third parties that do not need to know or otherwise access that information and thereby can reduce the cost of making transactions compared to current exchange processes.
- In accordance with embodiments of the present disclosure, systems and methods are provided for modifying a data table having a plurality of accounts in substantially real-time. The systems and methods may receive a request to modify an account selected from the plurality of accounts, wherein the selected account comprises at least one asset, and determine an identity of a validator based on the received request and the at least one asset, wherein the validator is configured to validate the request in substantially real-time. The systems and methods may further modify the data table in substantially real-time if the validator validates the request.
- In some implementations, the validator may be a first validator and the at least one asset may comprise a first and a second asset. The systems and methods may further include determining an identity of a second validator based on the received request, wherein the second validator validates the request in substantially real-time for the second asset.
- In some implementations, the data table is modified to process a payment transaction or a deposit transaction, the at least one asset corresponds to a currency or a bond, and the validator is an issuing-authority of the currency or the bond. In some aspects, the issuing authority of the currency or the bond is a proxy for a central bank that issues the currency or a bond holder that issues the bond. In some implementations, the data table is modified to process a foreign exchange transaction, and the first asset corresponds to a first currency and the second asset corresponds to a second currency. Further, the first validator corresponds to a first issuing authority of the first currency, and the second validator correspond to a second issuing authority of the second currency. In other implementations, the received request comprises modifications to several accounts in the plurality of accounts, the validator is a first validator of a plurality of validators, and each of the plurality of validators is associated with a different asset. Further, the systems and methods include determining a plurality of identities for the plurality of validators based on the received request, wherein each of the plurality of validators validates the request in substantially real time.
- In some implementations, the systems and methods may encrypt the plurality of accounts in the data table differently, so that a decryption process used by the first validator to access data of the first asset cannot be used to access data of the second asset.
- In some implementations, the validator may determine whether to validate the request based on retrieving a published balance from the data table for the account and the at least one asset, and computing an available balance by reducing the published balance by shadow balances associated with pending and reserved payments. The systems and methods may further approve the request when the available balance is greater than or equal to a transaction amount of the request and reject the request when the available balance is less than the transaction amount of the request. In some implementations, the validator stores the shadow balances associated with pending and reserved payments and a redundant copy of the data table.
- In some implementations, the validator determines whether to validate the request based on verifying whether a party associated with the account is authorized to perform the request.
- In some implementations, the validator stores a redundant copy of the data table and the systems and methods further comprise sending modified portions of the data table to the validator, in response to modifying the data table. In some implementations, the redundant copy of the data table is encrypted to prevent the validator from accessing data that is of an asset different from the at least one asset.
- For purpose of explanation, several embodiments are set forth in the following figures.
-
FIG. 1 is a block diagram of a distributed computer system that maintains and updates a distributed ledger; -
FIG. 2 is a diagram of the distributed ledger to illustrate visibility restrictions; -
FIG. 3 is a block diagram of a ledger administration network; -
FIG. 4 depicts an exemplary data structure for storing ledger balances and account information in the distributed ledger; -
FIG. 5 is a flowchart of a process for updating a distributed ledger based on data messages received from validation servers that each store partial, redundant copies of the ledger: -
FIG. 6 is a schematic of an authentication method using public and private keys; and -
FIG. 7 is a flowchart for processing transactions by aledger administration server 702 and two asset validation servers. - In the following description, numerous details are set forth for purpose of explanation. However, one of ordinary skill in the art will realize that the embodiments described herein may be practiced without the use of these specific details. In other instances, well-known structures and devices are shown in block diagram form to not obscure the description with unnecessary detail.
-
FIG. 1 is an illustrative block diagram of a distributedcomputer system 100 that maintains and updates a distributed ledger.Computer system 100 includesledger administration server 102,account operator server 120,asset validation servers proxy validation server 140, as well asKYC validation server 150.Ledger administration server 102 may be connected directly to clients 112-116 and may be connected to clients 122-126 throughaccount operator server 120. In one example, the servers ofcomputer system 100 may be standalone servers that are connected to one another through suitable network interfaces. In another example,computer system 100 may be implemented in a cloud-based computing environment. In that case, the servers ofcomputer system 100 may each be implemented as a virtual machine that runs on one or more physical servers. - Clients 112-116 (generally client 112) and clients 122-126 (generally, client 122) may be employed by accountholders to access balances stored in the distributed ledger.
Client 112 may be a personal computer, a laptop, a smartphone, or any other suitable computing device.Client 112 may include a processor and storage circuitry that stores software or other instructions that enableclient 112 to exchange information (e.g., in the form of data messages) withaccount operator server 120 orledger administration server 102. In one example,coupling client 122 toledger administration server 102 throughaccount operator server 120 may improve the scalability ofsystem 100, because there may be many more clients than account operators. -
Client 122 may store account balances for an accountholder associated withclient 122. Alternatively or additionally,client 122 may also causeaccount operator server 120 to store the account balances. In one example,client 122 may store account information exclusively onaccount operator server 120 becauseclient 122 may be vulnerable to theft (e.g., ifclient 122 is a mobile device) or may have a higher chance of being accessed illegally (e.g., through hacking) or tampered with (e.g., by infection with a software virus).Account operator server 120 may include processors and storage circuitry to store the account information per accountholder and associate the account balance held in the distributed ledger with a conventional bank account (e.g., checking or savings accounts) maintained by the accountholder. For example,account operator server 120 may be a commercial bank server. -
Ledger administration server 102 stores a master copy of the distributed ledger, which includes account balances for all accountholders insystem 100. The account of each accountholder may include balances in multiple assets.Ledger administration server 102 may employ a processor to process transactions received in form of data messages from client 122 (possibly through account operator server 120). A transaction may involve a single asset or multiple assets (for example: in case of a foreign exchange transaction there will be two assets which are both currencies).Ledger administration server 102 may be coupled toasset validation servers 130 and 132 (generally, asset validation server 130), and the processing of a transaction byledger administration server 102 may include the exchange of data messages betweenledger administration server 102 andasset validation server 130. -
Asset validation server 130 may include a processor and storage circuitry configured to store redundant copies of the distributed ledger. The storage of the redundant copies may improve the robustness, reliability, and security of the ledger, because in order to falsify or otherwise alter account balances stored by the encrypted distributed ledger, several of the redundant copies would need to be modified. Asledger administration server 102 andasset validation server 130 operate independently of one another, the task of compromising both servers is made more difficult. - To avoid that the distributed copies of the ledger cause account balances to be visible to the general marketplace,
ledger administration server 102 andasset validation server 130 may further control visibility into the stored ledger by requiring a username and password, two-factor authentication, or other suitable forms of access control to obtain read or write access to the stored ledger. Further, whileledger administration server 102 may have full access to the distributed ledger,asset validation server 130 may only be granted access to those portions of the ledger that include account balances of the specific asset that is validated byasset validation server 130. For example, each ofvalidation servers 130 and 132 may be associated with a asset (e.g., a fiat currency such as U.S. dollars or Euros, a crypto-currency such as bitcoins or ripples, or any other suitable type of asset such as bonds) and operated by the issuing authority of that asset (e.g., the central bank for that currency or the bond issuer of a bond). In such a scenario,asset validation server 130 may ensure that each unit of asset stored in the ledger ofsystem 100 is backed by a “real-life” unit of asset held or controlled by a corresponding asset validator. Thus, the ledger may maintain customer confidence by being transparent to regulators that oversee the supply of a given asset without revealing confidential transactional information to the general marketplace. - It is possible that not all asset issuing authorities choose to provide asset validation servers that exchange data messages with
ledger administration server 102 in substantially real-time. For such assets, a proxy may validate transactions by means of aproxy validation server 140.Proxy validation server 140 may be similar toasset validation servers 130 and 132; however, becauseproxy validation server 140 is not controlled by an asset issuing authority,proxy validation server 140 may not be able to ensure directly that each unit of asset stored in the ledger ofsystem 100 is backed by a “real-life” unit of asset. To increase client confidence,proxy validation server 140 may further be connected toasset validation server 142, which is controlled by the respective asset-issuing authority. Whileasset validation server 142 may not store or control the distributed ledger,asset validation server 142 may be configured to verify that the combined ledger balances maintained byproxy validation server 140 are backed by corresponding “real-life” funds in an escrow account.Asset validation server 142 may control the amount of funds held in the escrow account in real-time and may continuously update the balance in the escrow account based on supply and demand for the asset.Proxy validation server 140 may be configured to associate the funds in the escrow account with account balances in the ledger in real-time, such that the combined operation ofproxy validation server 140 andasset validation server 142 provides a similar one-to-one correspondence of balances in the ledger with “real-life” units of the respective asset. -
Ledger administration server 102 andasset validation server 130 may be coupled to accountoperator server 120.Account operator server 120 may employ a processor and storage circuitry to link ledger account information with customer information on behalf of clients (e.g., clients 122-126).Ledger administration server 102 may further be coupled toKYC validation server 150.KYC validation server 150 may create and store electronic records that contain KYC information, such as tax identification numbers, checking or savings account numbers, passport or driver license numbers, or any other suitable form of personal identification.Ledger administration server 102 may access the KYC information stored byKYC validation server 150 by exchanging data messages. For example,ledger administration server 102 may send a message that includes indications of the parties of a transaction toKYC validation server 150 along with information that verifies the authenticity of the data messages (e.g., an electronic signature of ledger administration server 102). Responsive to receipt of the message,KYC validation server 150 may access customer records based on the account information included in the data message and may retrieve a KYC status.KYC validation server 150 may employ a processor to prepare a data message in response to the request received fromledger administration server 102 and may send it along with its electronic signature toledger administration server 102. It is important to note thatledger administration server 102 andasset validation server 130 need not access KYC information in real-time or for each transaction. For example,ledger administration server 102 may store KYC information obtained forclient 112 and use that information to perform KYC checks. Accordingly, the aforementioned data messages that are exchanged betweenKYC validation server 150 andledger administration server 102 are not necessary for every transaction, which helps reduce the time needed to process a transaction. -
FIG. 2 shows a diagram of a distributedledger 200 to illustrate visibility restrictions. For illustration,ledger 200 is shown as atable including rows 210 that contain ledger account balances per client, andcolumns 212 that correspond to different assets. For each client,ledger 200 contains at least one ledger account balance per asset. For example, an accountholder associated with client A has an account balance of AUSD U.S. dollars, AEUR Euros, AGBP pounds, and AJPY Japanese Yen. Some clients may only maintain an account balance for a subset of the available assets. Records stored inledger 200 may include an indication that specific assets are not used. For example, client B has a ledger account balance for U.S. dollars but no account balance for Euros. A reserved value may be stored inledger 200 instead of associating a zero balance to indicate that client B generally does not perform transactions that involve the given asset. In some aspects, another reserved value may be used to indicate that a client is not permitted to perform transactions for a certain asset (e.g., due to regulatory or AML regulations). For example, client C may not be permitted to perform ledger transactions that involve Japanese Yen, which is denoted by an “X” in the corresponding entry of the ledger. - As discussed in relation to
FIG. 1 ,system 100 provides swift processing of transactions that may be validated by regulators but opaque to the marketplace. The organization ofledger 200 illustrates the visibility restrictions that are enforced bysystem 100. For example, whileledger administration server 102 may have access toledger 200 in its entirety, asset validators may have restricted access to ledger account balances that pertain to the specific asset validated by them. For example, an asset validator for U.S. dollars (e.g., asset validator 130) may only have access toledger portion 202. Similarly, an asset validator for Japanese Yen (e.g., asset validator 132) may only have access toledger portion 204. On the other hand, a client corresponding to a specific accountholder may have access to all ledger account balances associated with said client, such asledger portion 206, which includes ledger account balances in U.S. dollars, pounds, and Japanese Yen. - In some aspects, client A may initiate a transaction with client D, such as a foreign exchange transaction. For example, client A may buy A′USD from client D in exchange for D′JPY Japanese Yen. This transaction involves two currencies, namely U.S. dollars and Japanese Yen.
Ledger administration server 102 may receive separate data messages from clients A and D that request the transaction and may control the processing of the transaction. As such,ledger administration server 102 may have complete access to the ledger account balances of clients A and D. However,asset validation servers 130 and 132 may only have access to portions of the ledger. For example,asset validation server 130 may validate the U.S. dollar portion of the transaction and may therefore accessledger portion 202 which includes the ledger account balances AUSD and DUSD. Similarly, asset validation server 132 may validate the Japanese Yen portion of the transaction and may therefore accessledger portion 204 which include the ledger account balances AJPY and DJPY. -
FIG. 3 is a block diagram of aledger administration network 300.Ledger administration network 300 includesledger administration server 310,asset validation server 330,account operator server 340, andKYC validation server 360.Ledger administration server 310 andasset validation server 330 exchange data messages in order to maintain redundant copies of distributedledger 200 subject to visibility constraints that allow the transparency required by regulators while making ledger account balances otherwise inaccessible to the general marketplace.Ledger administration server 310 controls the processing of a transaction and exchanges data messages withasset validation server 330 to verify the authenticity and accuracy of a transaction. Unlessledger administration server 310 receives a data message fromasset validation server 330 that approves the transaction,ledger administration server 310 may not approve the transaction. In some aspects, this validation byasset validation server 330 provides that ledger account balances have a one-to-one correspondence with units of an asset controlled by the issuing authority of the asset associated withasset validation server 330. Similarly,ledger administration server 310 may send a data message toKYC validation server 360 to request validation of the KYC status of parties involved in the transaction. However,ledger administration network 300 may not require that KYC information be verified for each transaction. For example, KYC information may be stored atledger administration 310 orasset validation server 330 and updated only at predetermined times (e.g., by exchanging data with KYC validation server 360). An update of KYC information may be requested byledger administration server 310 or it may be pushed toledger administration server 310 byKYC validation server 360. -
Ledger administration server 310 includesprocessing server 324 andnetwork interface 316, both of which are connected tobus 326.Network interface 316 may enable the exchange of data messages betweenledger administration server 310,asset validation server 330,account operator server 340, andKYC validation server 360.Network interface 316 may also be used to exchange data messages directly withclient 112.Processing server 324 may control the processing and data exchange performed byledger administration server 310.Processing server 324 may also include authentication and encryption circuitry to validate signatures associated with data messages, and enforce the access constraints thatledger 200 is subject to.Bus 326 is further coupled toasset validator database 320,KYC status database 322, andaccess control circuitry 318.Access control circuitry 318 restricts access towallet database 312 andbalance database 314. - In some aspects,
asset validator database 320 is coupled tobus 326 directly because ledger administration sever 310 makes accessible information stored inasset validator database 320 without access restrictions. In contrast,access control circuitry 318 may control access to information stored inwallet database 312 andbalance database 314. In some aspects,asset validator database 320 stores a list of pointers, network addresses, or other suitable identification of asset validation servers (e.g., asset validation server 330) per asset. - As part of processing a transaction,
ledger administration server 310 requests validation from at least one validation server for each asset involved in the transaction. However, multiple asset validation servers may be provided per asset. When multiple asset validation servers are available,asset validation server 330 may distribute the processing of transactions among the multiple asset validation servers. The multiple asset validation servers may also store a larger number of redundant copies of the distributed ledger. A larger number of ledger copies may further strengthen the resilience ofledger administration network 300 against malicious actors or fraudulent transactions. -
Ledger administration server 310 further includeswallet database 312 andbalance database 314, which are configured to store a copy of the ledger account balances maintained byledger administration server 310. In some embodiments,wallet database 312 may store all assets held by a given client, together with other identifying information such as conventional bank account numbers as well as cryptographic codes (e.g., the client's public key). The ledger balances held by the client per asset may be stored inbalance database 314, as will be discussed in relation toFIG. 4 . In other embodiments,wallet database 312 andbalance database 314 may be combined and store, per client, both the assets and the corresponding account balances in a common data structure.Ledger administration server 310 may restrict access to information stored inwallet database 312 andbalance database 314 by usingaccess control circuitry 318.Access control circuitry 318 may limit the access of a specific client to accounts held by the accountholder associated with the specific client.Access control circuitry 318 may provide these access restrictions by requiring a username and password or two-factor authentication prior to providing access to the database.Ledger administration server 310 may also have full access towallet database 312 andbalance database 314. However,access control circuitry 318 may ensure that ledger balances stored bywallet database 312 andbalance database 314 are inaccessible to the general marketplace. -
Ledger administration server 310 includesKYC status database 322. Ledger administration server may employprocessing server 324 to store KYC status information (e.g., information identifying whether a client's account is valid or invalid) per client or per account.Ledger administration server 310 may utilizeKYC status database 322 to obviate the need for exchanging KYC data withKYC validation server 360 every time a transaction is processed. Rather,ledger administration server 310 may updateKYC status database 322 at predetermined times, by exchanging data messages withKYC validation server 360, but otherwise retrieve KYC status information fromKYC status database 322 in substantially real-time as part of processing a transaction. In some embodiments,asset validation server 330 may store KYC status information in a similar way asledger administration server 310. For example,asset validation server 330 may employprocessing server 334 to store KYC status information per client or per account and may perform KYC status verification prior to approving transactions received fromledger administration server 330. Similar toledger administration server 310,asset validation server 330 may employ the stored KYC status information (rather than exchange data messages withKYC validation server 360 for each transaction) in order to reduce the time it takes to process transactions. - Similar to
ledger administration server 310,asset validation server 330 includesnetwork interface 332 andprocessing server 334, both of which are connected tobus 339.Bus 339 is further coupled toasset balance database 336, pendingbalance database 337, and reservedbalance database 338. Similar toledger administration server 310,network interface 332 may be used to exchange data messages withledger administration server 310 andaccount operator server 340. In some aspects,network interface 332 may be connected to additional asset validation servers.Ledger administration server 310 orasset validation server 330 may control the additional asset validation servers and distribute the load associated with transactions among the additional asset validation servers. The additional asset validation servers may further provide additional protection from unauthorized transactions because each of the additional asset validation servers may store redundant copies of the distributed ledger.Processing server 334 may be employed to authenticate data messages received from other servers inledger administration network 300. -
Asset balance database 336, pendingbalance database 337, and reservedbalance database 338 may store a partial copy ofledger 200, which includes ledger account balances for the asset validated byasset validation server 330. For example, ifasset validation server 330 validated all transactions in U.S. dollars,asset balance database 336, pendingbalance database 337, and reservedbalance database 338 would store all ledger account balances in U.S. dollars. However, in this case,asset validation server 330 would not have access to ledger account balances in other assets, such as Euros or Japanese Yen. In some aspects,asset balance database 336 may store a copy of the ledger account balances for transactions that have previously been approved byasset validation server 330 and for which completion of the transaction was reported byledger administration server 310 as part of a ledger update. In addition,reserved balance database 338 may store payment balances that have been approved byasset validation server 330 but not yet reported as complete byledger administration server 310. For each account balance, only outgoing payments but not incoming payments may be recorded, and thus balances in pendingbalance database 338 may be non-negative. Similarly, pendingbalance database 337 may store balances for payments that have been validated byasset validation server 330 and signed byledger administration server 310 but not yet included in the updated asset balance database. - Together, pending
balance database 337 and reservedbalance database 338 help prevent “double spending” or “replay.” Using the information stored in pendingbalance database 337 and reservedbalance database 338,asset validation server 330 may reduce a published ledger balance maintained inasset balance database 336 by the amounts stored in pending balance database 337 (e.g., the total sum of pending payments) and by the amount stored in reserved balance database 338 (e.g., the total sum of reserved payments). The resulting balance is known as “shadow balance” and accounts for transactions that have been processed byasset validation server 330 but not yet reported as “complete” byledger administration server 310 in an updated ledger copy. As a result, attempts to “double spend” (e.g., by submitting multiple transactions in quick succession) are prevented, becauseasset validation server 330 updates the “shadow balance” in response to validating each transaction. - Similar to
ledger administration server 310,KYC validation server 360 may includenetwork interface 362 andprocessing server 364, both of which are connected tobus 369.KYC validation server 360 may usenetwork interface 362 to exchange data messages withledger administration server 310 andasset validation server 330.Processing server 344 may authenticate data messages received from or sent to other servers inledger administration network 300.KYC validation server 360 further includesKYC database 366, which may store customer identifications. Information stored inKYC database 366 may be used to ensure compliance with KYC requirements. For example, at predetermined times,ledger administration server 310 may send a data message toKYC validation server 360 to verify a party's KYC status.KYC validation server 360 may store the relevant KYC status inKYC database 366. Responsive to a request fromledger administration server 310,KYC validation server 360 may searchKYC database 366 based on a client identifier (e.g., a client's public key) and retrieve the client's current KYC status.KYC validation server 360 may then transmit a data message back toledger administration server 310. It should be noted that KYC status need not be checked in real-time for every transaction. Rather,ledger administration server 310 andasset validation server 330 may access KYC information at predetermined times and use a locally stored status for processing transactions. - Similar to
ledger administration server 310,account operator server 340 may includenetwork interface 342 andprocessing server 344, both of which are connected tobus 349.Account operator server 340 may serve as an account processor for parties that prefer that information about ledger account balances be maintained onaccount operator server 340 rather than on their associated client (e.g., client 112). In this scenario,account operator server 340 essentially supplies the aforementioned processes in place of the client.Account operator server 340 may store information about the ledger account balances inaccount database 346. In some embodiments,account operator server 340 andKYC validation server 360 may be combined an implemented in a single server architecture. - In some embodiments, the redundant copies of the distributed ledger stored by
ledger administration server 310 andasset validation server 330 may be stored in encrypted form.Ledger administration server 310 may control the visibility into the distributed encrypted ledger by employing an encryption process that encodes portions of the ledger differently, such that a decryption process that allows access to a first portion of the ledger cannot be used to access a second portion of the ledger. For example,ledger administration server 310 may encrypt balances corresponding to a first asset (e.g., U.S. dollars) such that only a decryption process used by a first asset validation server (e.g., a server at the Federal Reserve) can decrypt the balances. At the same time,ledger administration server 310 may encrypt balances corresponding to a second asset (e.g., Euros) such that the decryption process used by the first asset validation server (e.g., a server at the Federal Reserve) cannot decrypt the balances of the second asset, but only balances corresponding to the first asset. In some aspects,ledger administration server 310 andasset validation server 330 may exchange copies of the distributed encrypted ledger to ensure that the ledger is consistent across servers inledger administration network 300. Although the asset validation servers may only be able to access portions of the distributed encrypted ledger, it can be desirable to exchange copies of the ledger in their entirety, e.g., for record keeping or improved robustness against failure ofledger administration server 310. -
FIG. 4 depicts anexemplary data structure 400 for storing ledger balances and account information in the distributed ledger.Data structure 400 includes wallet table 410, KYC validator table 440, and asset table 450. Wallet table 410 includes a list of data blocks, each of which stores ledger balances associated with a specific client, such asclients 410 a-410 c. For each client with an entry in wallet table 410, a data block of wallet table 410 (e.g., the data block ofclient 410 c) may contain apublic key 412,asset 414,account information 416, per-account balance 418,KYC approval status 420 and a copy of the cryptographically signed KYC approval message, and anextra signatures field 422, for a list of any additional signatures that may be required to process a transaction foraccount 416.Public key 412 may be used by servers acrossledger administration network 300 to verify the authenticity of messages received from a client or server.Asset 414 may indicate one or more currencies or other assets for which the client maintains a ledger balance.Account information 416 may include conventional bank account information (e.g., corresponding to a checking or savings account, or a custody account for securities), and several accounts per asset may be possible. The currencies may include fiat currencies such as U.S. dollars or Euros, but also other types of currencies, such as cryptographic currencies (e.g., bitcoins or ripples), or any other suitable form of currency or asset. Data block 410 c may store ledger balances 418 associated with eachaccount 416. In some aspects, a separate balance table may be maintained in the ledger and may not be incorporated into data block 410 c. In some embodiments, maintaining balance table separately from data block 410 c may be beneficial because it provides more granular access restrictions, such as a higher level of privacy for the balance table compared to data block 410 c. Data block 410 c may further include per-account KYC status 420, which includes an indication of whetheraccount 416 has been verified as KYC compliant by one of the approvedKYC validators 444 listed in and also the ID of the validator for reference KYC validator table 440. For example, for a specific client associated with data block 410 c, “Citibank” may be the KYC validator for one of the accounts in U.S. dollars, “Deutsche Bank” may be the KYC validator for one of the accounts in Euros, etc. Additionally, data block 410 c may include C.C.transaction list 424, a field that stores the identity of extra parties that need to be informed (e.g., carbon copied) about a transaction. C.C.transaction list 424 may be stored per client, as shown inFIG. 4 , in which case the parties that are notified about a transaction do not depend on which of the client's accounts is involved in a transaction. C.C.transaction list 424 may also be stored per account (e.g., as part of account information 416). In that case, different parties may be notified of transactions, dependent on which of the client's accounts is involved in a transaction. The entries in C.C.transaction list 424 may specifically identify the parties that are to be notified, and may include additional identifiers associated with a transaction. - Per-
account KYC status 416 may be established by aKYC validator 444 listed in KYC validator table 440. Further, KYC validator table 440 may include apointer 442 which may identify each KYC validator listed inKYC validator list 444. Each KYC validator 444 may be approved by anasset validator 454 in asset table 450 (e.g., a central bank) for acorresponding asset 452. Asset table 450 may store, for eachasset validator 454, apublic key 455 that may be employed by other parties to verify the authenticity of data messages received fromasset validator 454. Further, asset table 450 includes a list ofpointers 456 which are linked withpointers 442 such that everyvalidator 454 may be linked with a group of approved KYC validators inKYC validator 444 for aasset 452. For example, for U.S. dollars, the Federal Reserve may serve as the asset validator, and Bank of America and Citibank may be among approved KYC agents. In some aspects, asset table 450 may be a global data structure that is not linked to a specific client or data block 410 c. KYC validator table 440 may store apublic key 445 for each KYC validator 444 that may be employed by other parties to verify the authenticity of data messages received fromKYC validator 444. -
FIG. 5 shows a flowchart of aprocess 500 for updating a distributed ledger based on data messages received from validation servers that each store partial, redundant copies of the ledger.Process 500 may, atstep 502, receive input from the parties involved in a transaction (e.g.,clients 112 or 122), while the remaining steps ofprocess 500 may be performed byledger administration network 300. As is discussed in relation toFIG. 3 , the successful processing of a transaction may haveledger administration server 102 receive validations from asset validation servers (e.g., asset validation servers 330) as well as KYC verifications (e.g., from KYC validation server 360). -
Process 500 may start atstep 502 by receiving authentication requests from clients that are parties in a transaction. The access of the clients toledger administration network 300 may be protected by a two-factor authentication mechanism or by providing a username and password. In some aspects, a username may specifically identify a client (e.g., client 112) and may be linked to the account of the client in the distributed ledger. The authentication procedure as well as the interface that clients use for submitting data messages with their transaction requests may be part of a specially designed Application Program Interface (API). Once clients gain access toledger administration network 300, the API used by the clients to accessledger administration network 300 may collect from the clients and may store information about the requested transaction, such as the assets involved in the transactions, the ledger balances to be transferred or exchanged, as well as any other pertinent information needed for processing the transaction. In some aspects, such as in a foreign exchange transaction, where the transaction involves multiple clients, the clients may also input information about other parties (e.g., their respective public key or account information) that have previously agreed to be part of the transaction by other means (e.g., by voice, by email or through a conventional foreign exchange trading or processing platform). Each of the clients involved in a transaction may individually append their respective signatures to the data messages. The signatures identify the parties associated with a transaction request as well as transaction details. Clients may generate their respective signatures by hashing the data corresponding to the details of the transaction requested by said client, and then by encrypting the resulting hash using the client's private key to obtain an encrypted signature, as will be described in more detail in connection withFIG. 6 . - At
step 504,process 500 may receive a plurality of transaction requests by clients that have been authenticated byledger administration server 310. The connection betweenledger administration server 310 and the client device that accessesledger administration server 310 through the API may be authenticated using conventional authentication protocols (e.g., the “Oauth” protocol).Process 500 may, atstep 506, validate each party's signature that is associated with a transaction request.Process 500 may determine the validity of each client's signature by decrypting the signature to obtain a hash. The hash may then be compared with another hash obtained independently from the data message, as will be described in connection withFIG. 6 . - If
process 500 determines that the signatures are valid,process 500 may determine atstep 508 whether the processing of the transaction requires any additional signatures. For example, KYC policies for a given client may require that other parties confirm transactions requested by a specific individual by adding extra signatures in extra signatures field 422 of data block 410 c as described in connection withFIG. 4 . If additional signatures are required,ledger administration server 310 may collect and validate the additional signatures atstep 510, prior to continuing withprocess 500.Ledger administration server 310 may also check if any of the parties of a transaction have not yet provided their signatures. For example, a transaction may involve multiple clients, not all of which may have provided signed data messages atstep 504. Accordingly,ledger administration server 310 may identify the type of transaction requested and send a request for any missing signatures. For instance, in a foreign exchange transaction, where the transaction involves multiple clients, the transaction information sent by a client using the API also contains information about the other parties that may take part in the transaction. In some embodiments, these parties have previously agreed to be part of the transaction by other means (e.g., by voice, by email or through a conventional foreign exchange trading or processing platform) and are known to the other participants in the transaction. Atstep 510,ledger administration server 310, may add the identities of the participants in C.C.transaction list 424 and their signature inextra signatures 422. These data tables may start to be filled when the data from the first client requesting the multiple party transaction is received and authenticated instep 504 byledger administration server 310. Then, extra signatures table 422 is marked as incomplete, the identity of the parties listed in C.C.transaction list 424 is checked and matched to extra signatures table 422 one by one, as said parties log into the system and submit a request for the same transaction. When all parties have agreed to the transaction, extra signatures table 422 is marked as complete, andprocess 500 continues to the next step.Ledger administration 310 may implement a time-out mechanism using hardware or software control that sets a window of time forstep 510, in which all the parties in a transaction agree to be part of it. In this way,process 500 may verify that all of the parties involved in a transaction have given authorization to be part of it, and have mutually acknowledged the other parties taking part in the same transaction. - After requesting all the needed signatures for the transaction,
process 500 may, atstep 511, match transaction between parties. For example,ledger administration server 310 may process a foreign exchange transaction by identifying a party that has submitted a transaction to sell a first asset in exchange for a second asset.Ledger administration server 310 may process the transaction of that party and match it with another transaction that has been received by another party seeking to sell the second asset in exchange for the first asset. In some cases, it may not be necessary to match transactions between parties, such as for payment transactions, or for transactions in which two or more parties have agreed beforehand to carry out a transaction. -
Process 500 may, atstep 512, check the KYC status for each client. In some aspects, such a KYC check may be mandated by law, andledger administration server 310 may be configured to perform such a KYC check prior to approving any modification to the distributed ledger. In order to complete the KYC check,ledger administration server 310 may check that bank account details linked to each client account in the ledger have been verified and signed by a KYC validator. A list of approved KYC validators may be stored in KYC status database 322 (maintained by ledger administration server 310). A data structure similar to asset table 450 and KYC validator table 440 may be used, as discussed in connection withFIG. 4 . -
Process 500, at step 514, may determine whether the KYC status of all parties is valid. If any of the parties is associated with an invalid KYC status,process 500 may reject the transaction as a whole and may prevent any of the parties' ledger account balances from being updated. Otherwise,process 500 may determine atstep 517 whether the ledger balance stored atledger administration server 310 is greater than or equal to a payment amount of the transaction. Ifledger administration server 310 determines that the ledger balance is sufficient,process 500 causesledger administration server 310 to sign the transaction atstep 518 and forward a data message with the transaction details to asset validators (e.g., asset validation server 330). Conversely, ifledger administration server 310 determines that the ledger balance is less than the payment amount, the transaction may be rejected. In some aspects,ledger administration server 310 may determine to which asset validation servers the transaction needs to be forwarded. For example,ledger administration server 310 may include a database that stores a list of asset validators (e.g., asset validator table 450).Ledger administration server 310 may determine the assets involved in the transaction, and forward data messages with transaction details to the asset validators obtained from asset table 450. - At
step 520,process 500 may receive either an approval or a rejection from the asset validators associated with the transaction. The approval mechanism of a transaction by an asset validator may include the validation of the signatures of both the clients involved in the transaction as well as the validation of the signature associated withledger administration server 310. After the signatures have been validated, the asset validation servers may compare the proposed transaction amount against the currently available balance, or “shadow balance” of each client. The shadow balance of a client for a given asset may correspond to the amount of the last published asset ledger balance for that client, minus a cumulative balance of all payments marked as “pending” or “reserved.” Pending payments may correspond to fully signed, approved outgoing payments that have not been included in the latest ledger balance update received fromledger administration server 310. Reserved payments may correspond to outgoing payments that have been partially signed and not yet approved byledger administration server 310. If this shadow balance is sufficient to cover the requested transaction, the amount required for such a transaction is added to the “reserved” amount, to prevent double-spending or “replay.” Asset validation servers may further perform any additional non-public checks as required by regulation or law. Furthermore, asset validation servers may perform an additional layer of KYC validation. At this point, if all checks pass, the asset validation servers sign the transaction, and forward it toledger administration server 310. - At step 522,
process 500 may determine whether any of the asset validation servers has rejected the transaction or if any of the KYC checks has failed. If so,process 500 may determine, atstep 524, that the transaction should be rejected. Conversely,process 500 may determine that the transaction is eligible for approval.Process 500 may then, atstep 526, determine whether the transaction should be approved and marked for publication in the ledger. -
Ledger administration server 310 may employ a consensus process that processes the fully approved messages received from the asset validation servers in order to include them in a new version of the ledger.Ledger administration server 310 may execute the consensus process periodically. In one example, the consensus process executed byledger administration server 310 may determine to include those transactions if all of the messages received from the asset validation servers approve including those transactions. Otherwise, if the consensus process determines that at least one of the messages rejects those transactions, the proposed new ledger may be rejected in its entirety and the process repeated with an updated set of transactions. In another example, the consensus process executed byledger administration server 310 may only require that at least a certain fraction of the data messages received from the asset validation servers approves the new ledger. For instance, the consensus process may determine that the new ledger for each asset should be approved if more than 80% of the messages received from the asset validation servers for that asset approve the transaction. In the candidate list of transactions to be included in the new ledger every transaction may have an associated “transaction ID” and may be listed alongside a hash of the signed transaction message. This hash may be used by the asset validation servers to quickly compare with transactions which it has approved in order to identify all the participants (e.g. clients and validators) in the transaction and the amounts and assets of the transaction. In one example, the process of agreeing a new ledger may be used to consolidate updates to the distributed ledger at each of the asset validators, e.g., in order to remove the “pending” or “reserved” status for completed transactions and to updateasset balance database 336. - Between
steps process 500 may further perform anti-money laundering (AML) checks. For example, the asset validation servers (e.g., asset validation server 330) may employprocessing server 334 to collect transaction histories and generate statistical data about account activity.Asset validation server 330 may further use a detection process to analyze the collected data and flag activity that matches suspicious patterns or other types of irregular account activities. Responsive to flagging an activity as suspicious,asset validation server 330 may generate a warning message. The warning message may cause the KYC status of the affected account to be changed to “not approved,” thus blocking transactions relating to this account from being approved. -
Process 500 may publish the ledger on a need-to-know basis. An important aspect of the present disclosure is the ability ofledger administration network 300 to maintain a distributed ledger without revealing sensitive information to the general marketplace, while providing regulators with the necessary transparency to validate transactions. In some aspects, the full ledger is stored byledger administration server 310 and redundant partial copies are kept by the asset and KYC validators. The data contained in the redundant copies of the distributed ledger stored atledger administration server 310, and at the asset validation servers, is kept synchronized, and the circuitry required for communication between asset validation servers and the ledger administration server may be designed such as to avoid latency between transaction publication in the ledger, and the process of cross-validation of the full ledger with the partial fragments kept by the validators. In some embodiments, even fully-redundant copies of the ledger may be stored by asset validation servers and the ledger administration server, thus reducing the risk of external interference or system wide malfunctions. Authentication techniques may provide that full access to the ledger balances is only available at the ledger administration server, while asset validation servers are only able to access their respective portions of the distributed ledger. -
FIG. 6 illustrates two interrelated high level block diagrams 600 and 650 which jointly describe the process of authenticating a transaction. Diagram 600 details the procedure used to generate signed data by a party seeking the authentication, from a second authenticating party. Diagram 600 includes theoriginal data 602 to be authenticated, ahash function 604, which processes the original data to produce ahash 606, anencrypted signature 610 generated with aprivate encryption key 608, and anew data structure 612 that results from appending theencrypted signature 610 to theoriginal data 602. - The generation of the signed data, as described in diagram 600, may start with the hashing of the
original data 602. The hashing is performed based on ahash function 604 that takes transaction details as input data, and outputs a unique string of data (hash) 606. The hash is then encrypted by conventional encryption methods (e.g., using RSA encryption) using aprivate key 608 which is only known to the party that authenticates the transaction. Usingprivate key 608, a string of data is generated, corresponding to anencrypted signature 610.Signature 610 may then be appended at the end of theoriginal data 602, or it may be included as a header. The resulting signeddata 612 is sent to the party seeking to authenticate the origin of thedata 612. - Diagram 650 describes the authentication procedure followed by an authenticating party of the signed
data 612 generated by the process described in diagram 600. It includes the received signeddata 652, which is composed of theoriginal data 654 of the transaction, and theencrypted signature 656 generated in accordance with diagram 600. Diagram 650 also includes apublic key 660, used for decryption of thesignature 656, a hash function, 658, and twohashes - Signed
data 652 received by the authenticating party is separated into two fragments. Thefirst data fragment 654 corresponds to the original data describing the transaction solicited by the party seeking authentication. The second fragment is anencrypted signature 656. Once isolated, thetransaction data 654 is hashed by thehash function 658, which is identical to hashfunction 604, used in diagram 600 to generate theencrypted signature 610. This produces ahash 662. Theencrypted signature 656 is decrypted with apublic key 660 that is in the possession of the authenticating party, which according to conventional encryption techniques is linked withprivate key 608. The decryption of the signature using the public key produces a second hash, 664, which is compared withhash 662. The authentication is successful if 662 and 664 are identical. If this is not the case, the authentication process is marked as invalid and the requested transaction is rejected. -
FIG. 7 is aflowchart 700 for processing transactions byledger administration server 702 and two asset validation servers,asset validation servers 704 and 706. These validation servers may validate transactions for two different assets. For example, asset validation server 704 may validate transactions in U.S. dollars, andasset validation server 706 may validate transactions in Euros.Asset validation servers 704 and 706 may validate transactions by verifying that the transactions have been properly authenticated and by determining that the transaction amount is below an available balance in the account, reduced by pending or reserved payments.Flowchart 700 illustrates the process for a foreign exchange trade, for instance, of U.S. dollars and Euros. Time has been incorporated inFIG. 7 (represented by the arrow) along the vertical axis such as to illustrate the timing of data exchanges between servers in the ledger administration network. The steps depicted inflowchart 700 are executed in response to validating the signatures of the parties involved in a transaction, as discussed in relation tosteps FIG. 5 . - In
flowchart 700, the servers of ledger administration network are represented byledger administration server 702, asset validation server 704, andasset validation server 706, each of which may provide validating input to determine the processing and approval of the transaction. The exchange of messages between the different servers ofprocess 700 may be implemented based on the network architecture illustrated inFIG. 3 . In particular, the circuitry of the network interfaces 316, 332 and 342 may be used in combination with the two-stage authentication process 600 for the exchange of messages betweenledger administration server 702 andasset validation servers 704 and 706. The circuitry of the network interfaces may work in conjunction with a machine-to-machine authentication protocol such as “Oauth” to prevent external interference with the communication between servers. This may be important given the possible large geographic spread ofledger administration server 702, asset validation server 704 andasset validation server 706. - After
steps process 500 have been carried out,ledger administration server 702 determines the assets associated with the transaction at step 708. Once this list of assets has been identified, the list may be compared with asset table 450 in order to determine the identity of the asset validation server for each asset to be exchanged in the transaction. Similar to step 517 discussed in relation toFIG. 5 ,ledger administration server 702 may further determine whether the ledger balance stored atledger administration server 702 is greater than or equal to a payment amount required by the transaction. Ifledger administration server 702 determines that the balance is not sufficient,ledger administration server 702 may reject the transaction. Otherwise,ledger administration server 702 may sign the transaction and mark it as “pending validation” at step 710. Thesignature process 600 as described inFIG. 6 may be performed byledger administration server 702. The data block 602 in this case, may contain as a header the signeddata block 652 which may be sent by the API running in the device that the client used to request the transaction. This data block may be signed at step 710 byledger administration server 702 as described byprocess 600 inFIG. 6 and the transaction may be marked as “pending validation.” -
Ledger administration server 702 may send the transaction information to the asset validators that may be determined internally at step 708 byledger administration server 702 according to the mapping specified in currency table 450, and using the network architecture described inFIG. 3 . Once the information is received by asset validation server 704 (e.g., the server validating U.S. dollar transactions) atstep 712, the signatures of the clients and the signature ofledger administration server 702 are decrypted and verified. The decryption and validation of the signatures and the verification of the integrity of the data describing the transaction may followprocess 650 as described inFIG. 6 . - Asset validation server 704 then, at
step 716, calculates the shadow balance for a given asset of the client. The shadow balance per client per asset is the balance of the last published asset balances in the ledger for a given client, denoted as the “latest published ledger balance”, minus the amount for “pending transactions”, which are payments that have been approved, validated and fully signed, but that have not been included in the last published distributed ledger, minus the amount for “reserved” transactions, which are transactions that have not been marked as completed but have been partially signed. Pending and reserved transactions may be moved to the local ledger balance once an updated ledger including the last transaction ID is published byledger administration server 702. - At
step 718, asset validation server 704 determines if the shadow balance calculated atstep 716, is greater than the amount of the requested transaction. In that case, asset validation server 704 allows the transaction to continue. - At
step 720, if the shadow balance is greater than or equal to the amount of the current transaction, asset validation server 704 updates the local asset ledger to reserve the transaction amount and update the shadow balance. The swift or immediate update of the shadow balance may be an important safeguard against “double spending” or “replay” attempts. - At
step 722, after updating the local ledger of asset validation server 707 (which for this example is in USD), asset validation server 704 signs and sends a validation approval message toledger administration server 702. The approval message may include an acknowledgment flag that marks the asset validation process as successful. - At 710 a second message is sent by
ledger administration server 702 toasset validation server 706, which in this example, may be the server validating the Euro portion of the transaction. The steps 724-730, performed byasset validation server 706, may be similar to steps 712-718 performed by asset validation server 704. In this example, step 730 performed byasset validation server 706 may determine that the shadow balance of the client in Euros is less than the amount of the requested transaction. Responsive to this determination,asset validation server 706 may sign and send a rejection message toledger administration server 702. - After receiving an approval message from asset validation server 704 and a rejection message from
asset validation server 706,ledger administration server 702 determines that no consensus has been reached and rejects the transaction. In another scenario, in which all the asset validation servers have validated the transaction, the transaction is marked as “pending publication” as described atstep 526 in connection with the discussion ofFIG. 5 . - Some embodiments of the present disclosure may be conveniently implemented using a conventional general purpose or a specialized digital computer or microprocessor programmed according to the teachings herein, as will be apparent to those skilled in the computer art. Appropriate software coding may be prepared by programmers based on the teachings herein, as will be apparent to those skilled in the software art. Some embodiments may also be implemented by the preparation of application-specific integrated circuits or by interconnecting an appropriate network of conventional component circuits, as will be readily apparent to those skilled in the art. Those of skill in the art would understand that information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, requests, information, signals, bits, symbols, and chips that may be referenced throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof. Some embodiments may be implemented using existing parallel, distributed computer processing and distributed data storage frameworks (e.g., Hadoop).
- Some embodiments include a computer program product comprising a computer readable medium (media) having instructions stored thereon/in and, when executed (e.g., by a processor), perform methods, techniques, or embodiments described herein, the computer readable medium comprising sets of instructions for performing various steps of the methods, techniques, or embodiments described herein. The computer readable medium may comprise a storage medium having instructions stored thereon/in which may be used to control, or cause, a computer to perform any of the processes of an embodiment. The storage medium may include, without limitation, any type of disk including floppy disks, mini disks (MDs), optical disks, DVDs, CD-ROMs, micro-drives, and magneto-optical disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices (including flash cards), magnetic or optical cards, nanosystems (including molecular memory ICs), RAID devices, remote data storage/archive/warehousing, or any other type of media or device suitable for storing instructions and/or data thereon/in. Additionally, the storage medium may be a hybrid system that stored data across different types of media, such as flash media and disc media. Optionally, the different media may be organized into a hybrid storage aggregate. In some embodiments different media types may be prioritized over other media types, such as the flash media may be prioritized to store data or supply data ahead of hard disk storage media or different workloads may be supported by different media types, optionally based on characteristics of the respective workloads. Additionally, the system may be organized into modules and supported on blades configured to carry out the storage operations described herein.
- Stored on any one of the computer readable medium (media), some embodiments include software instructions for controlling both the hardware of the general purpose or specialized computer or microprocessor, and for enabling the computer or microprocessor to interact with a human user and/or other mechanism using the results of an embodiment. Such software may include without limitation device drivers, operating systems, and user applications. Ultimately, such computer readable media further includes software instructions for performing embodiments described herein. Included in the programming (software) of the general-purpose/specialized computer or microprocessor are software modules for implementing some embodiments.
- Those of skill would further appreciate that the various illustrative logical blocks, modules, circuits, techniques, or method steps of embodiments described herein may be implemented as electronic hardware, computer software, or combinations of both. To illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described herein generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the embodiments described herein.
- The various illustrative logical blocks, modules, and circuits described in connection with the embodiments disclosed herein may be implemented or performed with a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
- The techniques or steps of a method described in connection with the embodiments disclosed herein may be embodied directly in hardware, in software executed by a processor, or in a combination of the two. In some embodiments, any software module, software layer, or thread described herein may comprise an engine comprising firmware or software and hardware configured to perform embodiments described herein. In general, functions of a software module or software layer described herein may be embodied directly in hardware, or embodied as software executed by a processor, or embodied as a combination of the two. A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read data from, and write data to, the storage medium. In the alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user device. In the alternative, the processor and the storage medium may reside as discrete components in a user device.
Claims (23)
1.-24. (canceled)
25. A method comprising:
receiving, using control circuitry, a request to modify a data account selected from a plurality of data accounts stored in a distributed ledger, wherein the selected data account stores at least one value associated with at least one asset;
identifying multiple validation servers based on the received request and the at least one asset, wherein the multiple validation servers will validate whether the request can be performed;
modifying the distributed ledger in response to the multiple validation servers validating the request, wherein each of the multiple validation servers is configured to store a redundant copy of the distributed ledger;
sending at least one modified portion of the distributed ledger to each of the multiple validation servers, wherein each of the multiple validation servers is configured to update its respective redundant copy of the distributed ledger with the at least one modified portion of the distributed ledger; and
controlling the multiple validation servers in order to distribute a processing load associated with validating transactions that include the request between the multiple validation servers;
wherein the redundant copy of the distributed ledger at each of the multiple validation servers is a partial redundant copy of the distributed ledger.
26. The method of claim 25 , further comprising:
encrypting the plurality of data accounts in the distributed ledger differently so that a decryption process used by the multiple validation servers to access data of a first type of asset cannot be used to access data of a second type of asset.
27. The method of claim 25 , wherein:
the distributed ledger is modified to process a payment transaction or a deposit transaction;
the at least one asset corresponds to a security; and
the multiple validation servers belong to an issuing authority of the security.
28. The method of claim 27 , wherein the issuing authority of the security is a proxy for a central bank that issues a currency or a bond issuer that issues a bond.
29. The method of claim 25 , wherein:
the multiple validation servers collectively form a first validator;
the at least one asset comprises a first asset and a second asset; and
the method further comprises determining an identity of a second validator based on the received request, the second validator configured to validate the request for the second asset.
30. The method of claim 29 , wherein:
the distributed ledger is modified to process a foreign exchange transaction;
the first asset corresponds to a first currency;
the second asset corresponds to a second currency;
the first validator comprises multiple first computing devices that correspond to a first issuing authority of the first currency; and
the second validator comprises at least one second computing device that corresponds to a second issuing authority of the second currency.
31. The method of claim 25 , wherein:
the received request comprises modifications to several data accounts in the plurality of data accounts;
the multiple validation servers collectively form a first validator of a plurality of validators;
each of the plurality of validators is associated with a different asset; and
the method further comprises determining a plurality of identities for the plurality of validators based on the received request, each of the plurality of validators configured to validate the request.
32. The method of claim 25 , wherein the multiple validation servers are configured to determine whether to validate the request based on:
retrieving a published balance from the distributed ledger for the selected account and the at least one asset;
computing an available balance by reducing the published balance by shadow balances associated with pending and reserved payments;
approving the request when the available balance is greater than or equal to a transaction amount of the request; and
rejecting the request when the available balance is less than the transaction amount of the request.
33. The method of claim 32 , wherein the multiple validation servers are configured to store the shadow balances associated with the pending and reserved payments and the redundant copy of the distributed ledger.
34. The method of claim 25 , wherein the multiple validation servers are configured to determine whether to validate the request based on:
verifying whether a party associated with the selected account is authorized to perform the request.
35. The method of claim 25 , wherein the redundant copy of the distributed ledger is encrypted to prevent the multiple validation servers from accessing data for an asset different from the at least one asset.
36. A system comprising:
a memory configured to store a distributed ledger having a plurality of accounts; and
control circuitry configured to:
receive a request to modify an account selected from the plurality of accounts, wherein the selected account is associated with at least one asset;
determine an identity of multiple validation servers associated with the at least one asset based on the received request, wherein the multiple validation servers are configured to validate the request;
modify the distributed ledger in response to the multiple validation servers validating the request, wherein each of the multiple validation servers is configured to store a redundant copy of the distributed ledger;
send at least one modified portion of the distributed ledger to each of the multiple validation servers, wherein each of the multiple validation servers is configured to update its respective redundant copy of the distributed ledger with the at least one modified portion of the distributed ledger; and
control the multiple validation servers in order to distribute a processing load associated with validating transactions that include the request between the multiple validation servers;
wherein the redundant copy of the distributed ledger at each of the multiple validation servers is a partial redundant copy of the distributed ledger.
37. The system of claim 36 , wherein the control circuitry is further configured to encrypt the plurality of accounts in the distributed ledger differently so that a decryption process used by the multiple validation servers to access data of a first type of asset cannot be used to access data of a second type of asset.
38. The system of claim 36 , wherein:
the distributed ledger is modified to process a payment transaction or a deposit transaction;
the at least one asset corresponds to a security; and
the multiple validation servers belong to an issuing authority of the security.
39. The system of claim 38 , wherein the issuing authority of the security is a proxy for a central bank that issues a currency or a bond issuer that issues a bond.
40. The system of claim 36 , wherein:
the multiple validation servers collectively form a first validator;
the at least one asset comprises a first asset and a second asset; and
the control circuitry is further configured to determine an identity of a second validator based on the received request, the second validator configured to validate the request for the second asset.
41. The system of claim 40 , wherein:
the distributed ledger is modified to process a foreign exchange transaction;
the first asset corresponds to a first currency;
the second asset corresponds to a second currency;
the first validator comprises multiple first computing devices that correspond to a first issuing authority of the first currency; and
the second validator comprises at least one second computing device that corresponds to a second issuing authority of the second currency.
42. The system of claim 36 , wherein:
the received request comprises modifications to several accounts in the plurality of accounts;
the multiple validation servers collectively form a first validator of a plurality of validators;
each of the plurality of validators is associated with a different asset; and
the control circuitry is further configured to determine a plurality of identities for the plurality of validators based on the received request, each of the plurality of validators configured to validate the request.
43. The system of claim 36 , wherein the multiple validation servers are configured to determine whether to validate the request by being configured to:
retrieve a published balance from the distributed ledger for the selected account and the at least one asset;
compute an available balance by reducing the published balance by shadow balances associated with pending and reserved payments;
approve the request when the available balance is greater than or equal to a transaction amount of the request; and
reject the request when the available balance is less than the transaction amount of the request.
44. The system of claim 43 , wherein the multiple validation servers are configured to store the shadow balances associated with the pending and reserved payments and the redundant copy of the distributed ledger.
45. The system of claim 36 , wherein the multiple validation servers are configured to determine whether to validate the request by being configured to verify whether a party associated with the selected account is authorized to perform the request.
46. The system of claim 36 , wherein the redundant copy of the distributed ledger is encrypted to prevent the multiple validation servers from accessing data for an asset different from the at least one asset.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US17/184,472 US20210201410A1 (en) | 2015-03-05 | 2021-02-24 | Systems and methods for updating a distributed ledger based on partial validations of transactions |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US14/639,895 US11023968B2 (en) | 2015-03-05 | 2015-03-05 | Systems and methods for updating a distributed ledger based on partial validations of transactions |
US17/184,472 US20210201410A1 (en) | 2015-03-05 | 2021-02-24 | Systems and methods for updating a distributed ledger based on partial validations of transactions |
Related Parent Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US14/639,895 Continuation US11023968B2 (en) | 2015-03-05 | 2015-03-05 | Systems and methods for updating a distributed ledger based on partial validations of transactions |
Publications (1)
Publication Number | Publication Date |
---|---|
US20210201410A1 true US20210201410A1 (en) | 2021-07-01 |
Family
ID=55586433
Family Applications (2)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US14/639,895 Active 2036-05-20 US11023968B2 (en) | 2015-03-05 | 2015-03-05 | Systems and methods for updating a distributed ledger based on partial validations of transactions |
US17/184,472 Abandoned US20210201410A1 (en) | 2015-03-05 | 2021-02-24 | Systems and methods for updating a distributed ledger based on partial validations of transactions |
Family Applications Before (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US14/639,895 Active 2036-05-20 US11023968B2 (en) | 2015-03-05 | 2015-03-05 | Systems and methods for updating a distributed ledger based on partial validations of transactions |
Country Status (9)
Country | Link |
---|---|
US (2) | US11023968B2 (en) |
EP (2) | EP3265985B1 (en) |
JP (1) | JP6697008B2 (en) |
CN (2) | CN107683493B (en) |
AU (2) | AU2016226026B2 (en) |
CA (1) | CA2985763C (en) |
ES (2) | ES2832709T3 (en) |
HK (1) | HK1248883A1 (en) |
WO (1) | WO2016141361A1 (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20220058638A1 (en) * | 2020-08-24 | 2022-02-24 | Capital One Services, Llc | Systems and methods for obfuscating transactions |
Families Citing this family (192)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20160307197A1 (en) * | 2014-01-15 | 2016-10-20 | Solutio LLC | System and method of generating and validating a unique transaction identifier |
CN107409123B (en) * | 2015-02-09 | 2020-10-30 | 缇零集团股份有限公司 | Encryption integration platform |
US9967333B2 (en) * | 2015-03-02 | 2018-05-08 | Dell Products Lp | Deferred configuration or instruction execution using a secure distributed transaction ledger |
US10592985B2 (en) | 2015-03-02 | 2020-03-17 | Dell Products L.P. | Systems and methods for a commodity contracts market using a secure distributed transaction ledger |
US9967334B2 (en) * | 2015-03-02 | 2018-05-08 | Dell Products Lp | Computing device configuration and management using a secure decentralized transaction ledger |
US9965628B2 (en) | 2015-03-02 | 2018-05-08 | Dell Products Lp | Device reporting and protection systems and methods using a secure distributed transactional ledger |
US10484168B2 (en) | 2015-03-02 | 2019-11-19 | Dell Products L.P. | Methods and systems for obfuscating data and computations defined in a secure distributed transaction ledger |
US11023968B2 (en) * | 2015-03-05 | 2021-06-01 | Goldman Sachs & Co. LLC | Systems and methods for updating a distributed ledger based on partial validations of transactions |
US9397985B1 (en) | 2015-04-14 | 2016-07-19 | Manifold Technology, Inc. | System and method for providing a cryptographic platform for exchanging information |
US20160321751A1 (en) * | 2015-04-28 | 2016-11-03 | Domus Tower, Inc. | Real-time settlement of securities trades over append-only ledgers |
US10515409B2 (en) * | 2016-03-23 | 2019-12-24 | Domus Tower, Inc. | Distributing work load of high-volume per second transactions recorded to append-only ledgers |
US11704733B2 (en) * | 2015-05-01 | 2023-07-18 | Tzero Ip, Llc | Crypto multiple security asset creation and redemption platform |
US11392944B2 (en) | 2015-05-20 | 2022-07-19 | Ripple Luxembourg S.A. | Transfer costs in a resource transfer system |
US11481771B2 (en) * | 2015-05-20 | 2022-10-25 | Ripple Luxembourg S.A. | One way functions in a resource transfer system |
US11386415B2 (en) | 2015-05-20 | 2022-07-12 | Ripple Luxembourg S.A. | Hold condition in a resource transfer system |
US11392955B2 (en) | 2015-05-20 | 2022-07-19 | Ripple Luxembourg S.A. | Temporary consensus networks in a resource transfer system |
US10740732B2 (en) | 2015-05-20 | 2020-08-11 | Ripple Luxembourg S.A. | Resource transfer system |
AU2016307202A1 (en) | 2015-05-26 | 2017-12-07 | Tzero Ip, Llc | Obfuscation of intent in transactions using cryptographic techniques |
CN108352016B (en) * | 2015-07-08 | 2022-11-11 | 巴克莱执行服务有限公司 | Data validation and storage |
US20170011460A1 (en) * | 2015-07-09 | 2017-01-12 | Ouisa, LLC | Systems and methods for trading, clearing and settling securities transactions using blockchain technology |
US10402792B2 (en) * | 2015-08-13 | 2019-09-03 | The Toronto-Dominion Bank | Systems and method for tracking enterprise events using hybrid public-private blockchain ledgers |
US11195177B1 (en) | 2015-08-21 | 2021-12-07 | United Services Automobile Association (Usaa) | Distributed ledger systems for tracking recurring transaction authorizations |
US11188907B1 (en) | 2015-08-21 | 2021-11-30 | United Services Automobile Association (Usaa) | ACH authorization validation using public blockchains |
SG11201803010UA (en) * | 2015-10-14 | 2018-05-30 | Cambridge Blockchain Llc | Systems and methods for managing digital identities |
EP3362970B1 (en) * | 2015-10-17 | 2024-08-14 | Banqu, Inc. | Blockchain-based identity and transaction platform |
WO2017069874A1 (en) * | 2015-10-21 | 2017-04-27 | Manifold Technology, Inc. | Event synchronization systems and methods |
US10432758B2 (en) | 2015-11-04 | 2019-10-01 | Altiostar Networks, Inc. | Dynamic robust downlink packet delivery |
US10949856B1 (en) | 2015-11-17 | 2021-03-16 | United Services Automobile Association (Usaa) | Systems and methods for adaptive learning to replicate peak performance of human decision making |
US11361286B1 (en) | 2015-11-20 | 2022-06-14 | United Services Automobile Association (Usaa) | Identifying negotiable instrument fraud using distributed ledger systems |
US10423938B1 (en) | 2015-11-20 | 2019-09-24 | United Services Automobile Association | Identifying negotiable instrument fraud using distributed ledger systems |
US10833843B1 (en) | 2015-12-03 | 2020-11-10 | United Services Automobile Association (USAA0 | Managing blockchain access |
US11270299B2 (en) * | 2015-12-07 | 2022-03-08 | Visa International Service Association | Methods and systems of using a cryptocurrency system to manage payments and payment alternatives |
JP6923946B2 (en) * | 2015-12-21 | 2021-08-25 | コチャバ インコーポレイテッドKochava Inc. | Self-regulating trading systems, their methods, programs, data processing device systems, computer readable storage media systems, computer program products and computer program products |
ES2703861T3 (en) * | 2016-01-08 | 2019-03-12 | Retarus Gmbh | Technique to detect malicious electronic messages |
US11651341B2 (en) * | 2016-01-08 | 2023-05-16 | Worldpay, Llc | Multi-platform electronic payment transaction risk profiling |
US10262164B2 (en) | 2016-01-15 | 2019-04-16 | Blockchain Asics Llc | Cryptographic ASIC including circuitry-encoded transformation function |
US10129238B2 (en) * | 2016-02-10 | 2018-11-13 | Bank Of America Corporation | System for control of secure access and communication with different process data networks with separate security features |
US10142347B2 (en) * | 2016-02-10 | 2018-11-27 | Bank Of America Corporation | System for centralized control of secure access to process data network |
US11374935B2 (en) | 2016-02-11 | 2022-06-28 | Bank Of America Corporation | Block chain alias person-to-person resource allocation |
US10762504B2 (en) | 2016-02-22 | 2020-09-01 | Bank Of America Corporation | System for external secure access to process data network |
EP4209983A1 (en) * | 2016-02-23 | 2023-07-12 | nChain Licensing AG | Methods and systems for the efficient transfer of entities on a blockchain |
CA3019275A1 (en) | 2016-04-11 | 2017-10-19 | nChain Holdings Limited | Computer-implemented methods and systems for validating tokens for blockchain-based cryptocurrencies |
US11521185B1 (en) * | 2016-05-19 | 2022-12-06 | Citibank, N.A. | Distributed private ledger systems and methods |
US11829998B2 (en) | 2016-06-07 | 2023-11-28 | Cornell University | Authenticated data feed for blockchains |
US10063379B2 (en) * | 2016-06-16 | 2018-08-28 | The Bank Of New York Mellon | Distributed, centrally authored block chain network |
US10402796B2 (en) | 2016-08-29 | 2019-09-03 | Bank Of America Corporation | Application life-cycle transition record recreation system |
US10282558B2 (en) * | 2016-09-02 | 2019-05-07 | The Toronto-Dominion Bank | System and method for maintaining a segregated database in a multiple distributed ledger system |
WO2018049203A1 (en) * | 2016-09-09 | 2018-03-15 | MonetaGo Inc. | Asset exchange system and method |
WO2018049358A1 (en) * | 2016-09-12 | 2018-03-15 | Baton Systems, Inc. | Financial management systems and methods |
US11601498B2 (en) | 2016-09-12 | 2023-03-07 | Baton Systems, Inc. | Reconciliation of data stored on permissioned database storage across independent computing nodes |
US10185550B2 (en) * | 2016-09-28 | 2019-01-22 | Mcafee, Inc. | Device-driven auto-recovery using multiple recovery sources |
US10339014B2 (en) * | 2016-09-28 | 2019-07-02 | Mcafee, Llc | Query optimized distributed ledger system |
US10733602B2 (en) | 2016-09-29 | 2020-08-04 | Microsoft Technology Licensing, Llc. | Heartbeats and consensus in verifiable outsourced ledgers |
CA3039111A1 (en) * | 2016-10-28 | 2018-05-03 | Jpmorgan Chase Bank, N.A. | Application of distributed ledgers for network payments as financial exchange settlement and reconciliation |
US10171509B2 (en) * | 2016-11-10 | 2019-01-01 | International Business Machines Corporation | Filtering and redacting blockchain transactions |
CN110383757B (en) | 2016-12-16 | 2022-08-30 | 维萨国际服务协会 | System and method for secure processing of electronic identities |
DE112017006701T5 (en) | 2016-12-30 | 2019-09-19 | Intel Corporation | Internet of Things |
US10243731B2 (en) * | 2017-01-27 | 2019-03-26 | Accenture Global Solutions Limited | Hardware blockchain acceleration |
US11341488B2 (en) * | 2017-02-06 | 2022-05-24 | Northern Trust Corporation | Systems and methods for issuing and tracking digital tokens within distributed network nodes |
US11321681B2 (en) | 2017-02-06 | 2022-05-03 | Northern Trust Corporation | Systems and methods for issuing and tracking digital tokens within distributed network nodes |
US10764259B2 (en) | 2017-02-07 | 2020-09-01 | Microsoft Technology Licensing, Llc | Transaction processing for consortium blockchain network |
US10356102B2 (en) * | 2017-02-24 | 2019-07-16 | Verizon Patent And Licensing Inc. | Permissions using blockchain |
SG11201907468UA (en) | 2017-03-07 | 2019-09-27 | Mastercard International Inc | Method and system for recording point to point transaction processing |
US20180285882A1 (en) * | 2017-03-30 | 2018-10-04 | Baton Systems, Inc. | Activity management systems and methods |
US20180285971A1 (en) * | 2017-03-31 | 2018-10-04 | International Business Machines Corporation | Management of consumer debt collection using a blockchain and machine learning |
EP3610440A4 (en) * | 2017-04-11 | 2020-12-02 | Hewlett-Packard Development Company, L.P. | Blockchain partial ledgers |
US20200111091A1 (en) * | 2017-04-21 | 2020-04-09 | InfoSci, LLC | Systems and Methods for Certifying Authenticated Transaction Information |
US11463439B2 (en) | 2017-04-21 | 2022-10-04 | Qwerx Inc. | Systems and methods for device authentication and protection of communication on a system on chip |
EP3396612A1 (en) | 2017-04-24 | 2018-10-31 | BlockSettle AB | Method and system for creating a user identity |
EP3396608A1 (en) | 2017-04-24 | 2018-10-31 | BlockSettle AB | Method and system for settling a blockchain transaction |
US10176308B2 (en) * | 2017-04-28 | 2019-01-08 | Accenture Global Solutions Limited | Entitlement management system |
US12026780B1 (en) | 2017-05-02 | 2024-07-02 | State Farm Mutual Automobile Insurance Company | Distributed ledger system for managing loss histories for properties |
WO2018209148A1 (en) * | 2017-05-10 | 2018-11-15 | Responsible Gold Operations Ltd. | Method of tokenization of asset-backed digital assets |
US10664591B2 (en) | 2017-05-11 | 2020-05-26 | Microsoft Technology Licensing, Llc | Enclave pools |
US10528722B2 (en) | 2017-05-11 | 2020-01-07 | Microsoft Technology Licensing, Llc | Enclave pool shared key |
US10637645B2 (en) | 2017-05-11 | 2020-04-28 | Microsoft Technology Licensing, Llc | Cryptlet identity |
US10747905B2 (en) | 2017-05-11 | 2020-08-18 | Microsoft Technology Licensing, Llc | Enclave ring and pair topologies |
US11488121B2 (en) | 2017-05-11 | 2022-11-01 | Microsoft Technology Licensing, Llc | Cryptlet smart contract |
US10833858B2 (en) | 2017-05-11 | 2020-11-10 | Microsoft Technology Licensing, Llc | Secure cryptlet tunnel |
US10740455B2 (en) | 2017-05-11 | 2020-08-11 | Microsoft Technology Licensing, Llc | Encave pool management |
TWI644556B (en) * | 2017-05-18 | 2018-12-11 | 富邦金融控股股份有限公司 | Know your customer (kyc) data sharing system with privacy and method thereof |
US10581621B2 (en) * | 2017-05-18 | 2020-03-03 | International Business Machines Corporation | Enhanced chaincode analytics provenance in a blockchain |
US10382965B2 (en) * | 2017-05-30 | 2019-08-13 | Sap Se | Identity verification using computer-implemented decentralized ledger |
US10238288B2 (en) | 2017-06-15 | 2019-03-26 | Microsoft Technology Licensing, Llc | Direct frequency modulating radio-frequency sensors |
US10581909B2 (en) * | 2017-06-26 | 2020-03-03 | Oath Inc. | Systems and methods for electronic signing of electronic content requests |
US10984134B2 (en) | 2017-07-14 | 2021-04-20 | Microsoft Technology Licensing, Llc | Blockchain system for leveraging member nodes to achieve consensus |
CN112865982A (en) | 2017-07-26 | 2021-05-28 | 创新先进技术有限公司 | Digital certificate management method and device and electronic equipment |
CA3014385A1 (en) * | 2017-08-16 | 2019-02-16 | Royal Bank Of Canada | Platform for generating authenticated data objects |
US20200175501A1 (en) * | 2017-08-25 | 2020-06-04 | Token Iq, Inc. | Methods and apparatus for value transfer |
EP3676676A4 (en) * | 2017-08-31 | 2021-01-20 | General Electric Company | Intellectual property exchange ecosystem for additive manufacturing |
US10810581B2 (en) * | 2017-09-26 | 2020-10-20 | Paypal, Inc. | Secure offline transaction system using digital tokens and a secure ledger database |
CN107862215B (en) | 2017-09-29 | 2020-10-16 | 创新先进技术有限公司 | Data storage method, data query method and device |
US10549202B2 (en) * | 2017-10-25 | 2020-02-04 | Sony Interactive Entertainment LLC | Blockchain gaming system |
EP3702950B1 (en) * | 2017-10-27 | 2021-12-01 | Digital Asset (Switzerland) GmbH | Computer system and method for distributed privacy-preserving shared execution of one or more processes |
WO2019089778A1 (en) | 2017-10-31 | 2019-05-09 | Jordan Simons | Management of virtual goods in distributed multi-ledger gambling architecture |
EP3496027A1 (en) | 2017-12-06 | 2019-06-12 | BlockSettle AB | Method for settling a blockchain asset |
US10699493B2 (en) | 2017-12-09 | 2020-06-30 | Hausman Properties, Llc | System and method for toll transactions utilizing a distributed ledger |
US11386405B2 (en) * | 2017-12-19 | 2022-07-12 | International Business Machines Corporation | Dynamic blockchain transactional policy management |
US20190188698A1 (en) * | 2017-12-19 | 2019-06-20 | Tbcasoft, Inc. | Computer apparatus for cross-ledger transfers between distributed ledgers |
US10958436B2 (en) | 2017-12-28 | 2021-03-23 | Industrial Technology Research Institute | Methods contract generator and validation server for access control of contract data in a distributed system with distributed consensus |
CN111640021B (en) * | 2018-01-19 | 2023-06-30 | 创新先进技术有限公司 | Funds circulation method and device and electronic equipment |
US10887254B2 (en) | 2018-02-01 | 2021-01-05 | Red Hat, Inc. | Enterprise messaging using blockchain system |
US11449842B2 (en) * | 2018-02-23 | 2022-09-20 | Jpmorgan Chase Bank, N.A. | Systems and methods for private settlement of distributed ledger transactions |
US10372943B1 (en) | 2018-03-20 | 2019-08-06 | Blockchain Asics Llc | Cryptographic ASIC with combined transformation and one-way functions |
US11068978B1 (en) | 2018-04-02 | 2021-07-20 | Liquid Mortgage Inc. | Decentralized systems and methods for managing loans and securities |
US10256974B1 (en) * | 2018-04-25 | 2019-04-09 | Blockchain Asics Llc | Cryptographic ASIC for key hierarchy enforcement |
US11194837B2 (en) * | 2018-05-01 | 2021-12-07 | International Business Machines Corporation | Blockchain implementing cross-chain transactions |
US11030217B2 (en) | 2018-05-01 | 2021-06-08 | International Business Machines Corporation | Blockchain implementing cross-chain transactions |
GB201807389D0 (en) * | 2018-05-04 | 2018-06-20 | Hubii As | Controlling transactions on a network |
CN108734582A (en) * | 2018-05-21 | 2018-11-02 | 深圳市富途网络科技有限公司 | A kind of securities account management method based on social relations and system |
US11038676B2 (en) * | 2018-05-25 | 2021-06-15 | Incertrust Technologies Corporation | Cryptographic systems and methods using distributed ledgers |
CN108876572A (en) | 2018-05-29 | 2018-11-23 | 阿里巴巴集团控股有限公司 | The account checking method and device, electronic equipment of block chain transaction |
US11694788B2 (en) * | 2018-05-29 | 2023-07-04 | Medtronic, Inc. | Healthcare protocols for use with a distributed ledger |
CN108805712B (en) | 2018-05-29 | 2021-03-23 | 创新先进技术有限公司 | Asset transfer rollback processing method and device and electronic equipment |
CN113283988A (en) * | 2018-05-29 | 2021-08-20 | 创新先进技术有限公司 | Asset transfer method and device and electronic equipment |
CN108876606B (en) | 2018-05-29 | 2021-02-09 | 创新先进技术有限公司 | Asset transfer method and device and electronic equipment |
AU2019282536A1 (en) * | 2018-06-04 | 2021-01-14 | Noah RAFALKO | Telecommunication system and method for settling session transactions |
WO2019236638A1 (en) * | 2018-06-06 | 2019-12-12 | Argosoperem Llc | Method and system for data storage and retrieval |
US11568402B2 (en) * | 2018-06-06 | 2023-01-31 | International Business Machines Corporation | Decentralized out-of-band accelerated blockchain transaction processing |
US10771240B2 (en) * | 2018-06-13 | 2020-09-08 | Dynamic Blockchains Inc | Dynamic blockchain system and method for providing efficient and secure distributed data access, data storage and data transport |
CN112823367A (en) * | 2018-06-21 | 2021-05-18 | 第九齿轮科技公司 | Method, device and system for accelerating transaction processing based on block chain |
US10887081B2 (en) | 2018-06-28 | 2021-01-05 | International Business Machines Corporation | Audit trail configuration in a blockchain |
WO2020018523A1 (en) * | 2018-07-17 | 2020-01-23 | Jpmorgan Chase Bank, N.A. | System and method for distributed ledger-based software supply chain management |
US10839395B2 (en) * | 2018-07-31 | 2020-11-17 | Americorp Investments Llc | Techniques for expediting processing of blockchain transactions |
US10776781B2 (en) | 2018-08-01 | 2020-09-15 | Mff Llc | Systems and methods for facilitating transactions using a digital currency |
CN112567408A (en) * | 2018-08-07 | 2021-03-26 | 科氏工业公司 | Distributed ledger platform for access control |
US10721069B2 (en) * | 2018-08-18 | 2020-07-21 | Eygs Llp | Methods and systems for enhancing privacy and efficiency on distributed ledger-based networks |
GB201813685D0 (en) * | 2018-08-22 | 2018-10-03 | Choice International Ltd | Transaction system and method |
US10250395B1 (en) * | 2018-08-29 | 2019-04-02 | Accenture Global Solutions Limited | Cryptologic blockchain interoperation |
CN109325747B (en) * | 2018-08-30 | 2020-06-09 | 阿里巴巴集团控股有限公司 | Remittance method and device based on block chain |
CN109308658A (en) * | 2018-09-11 | 2019-02-05 | 北京永恒纪元科技有限公司 | A kind of decentralization assets trustship clearance plateform system of highly effective and safe |
US10250394B1 (en) | 2018-09-20 | 2019-04-02 | Accenture Global Solutions Limited | Cryptologic self-executing blockchain export commitment |
CN109325772B (en) * | 2018-09-30 | 2021-06-25 | 泰康保险集团股份有限公司 | Service settlement processing method and device |
RU2679532C1 (en) * | 2018-10-03 | 2019-02-11 | Банк ВТБ (публичное акционерное общество) | System of decentralized digital settlement service |
CN109447784A (en) * | 2018-10-11 | 2019-03-08 | 依睿迪亚(南京)智能科技有限公司 | A method of above-mentioned market reward is obtained by the automatic purchase strategy of loan point-to-point on secondary market |
US10951615B1 (en) | 2018-10-16 | 2021-03-16 | Sprint Communications Company L.P. | Wireless network access for data appliances |
US11146399B2 (en) | 2018-10-19 | 2021-10-12 | Eygs Llp | Methods and systems for retrieving zero-knowledge proof-cloaked data on distributed ledger-based networks |
US20200134606A1 (en) * | 2018-10-31 | 2020-04-30 | EMC IP Holding Company LLC | Asset management in asset-based blockchain system |
WO2020096996A2 (en) * | 2018-11-05 | 2020-05-14 | Tunnel International Inc. | Methods, systems, and devices for concealing account balances in ledgers |
US10986500B1 (en) | 2018-11-06 | 2021-04-20 | Sprint Communications Company L.P. | Hardware-trusted ledger client for distributed ledgers that serve wireless network slices |
US11436675B2 (en) | 2018-11-08 | 2022-09-06 | Jpmorgan Chase Bank, N.A. | Systems and methods for distributed-ledger based intraday trading |
US11023490B2 (en) * | 2018-11-20 | 2021-06-01 | Chicago Mercantile Exchange Inc. | Selectively replicated trustless persistent store |
US20220114193A1 (en) * | 2018-12-10 | 2022-04-14 | Cambridge Blockchain, Inc. | Systems and methods for data management |
EP3895049B1 (en) * | 2018-12-12 | 2024-05-29 | Thermo Electron Scientific Instruments LLC | Utilizing independently stored validation keys to enable auditing of instrument measurement data maintained in a blockchain |
CN109658248B (en) * | 2018-12-20 | 2023-01-24 | 姚前 | System and method for updating registration information after return of managed assets |
CN109670833B (en) * | 2018-12-20 | 2023-06-16 | 姚前 | Escrow registration system and method for under-chain assets to be uplinked |
US10861008B2 (en) | 2018-12-21 | 2020-12-08 | Capital One Services, Llc | System and method for optimizing cryptocurrency transactions |
US10637644B1 (en) * | 2018-12-21 | 2020-04-28 | Capital One Services, Llc | System and method for authorizing transactions in an authorized member network |
CN109685648A (en) * | 2018-12-28 | 2019-04-26 | 中国工商银行股份有限公司 | Processing method, processing system and the supply chain financial platform of digital certificate |
US11593799B2 (en) * | 2019-02-01 | 2023-02-28 | EMC IP Holding Company LLC | Message-less B2B transaction processing |
US11038857B1 (en) | 2019-02-14 | 2021-06-15 | Sprint Communications Company L.P. | Data messaging service with distributed ledger control |
US20220138748A1 (en) | 2019-02-15 | 2022-05-05 | Blocksettle Ab | Method and system for settling a blockchain transaction |
US11616652B2 (en) * | 2019-03-15 | 2023-03-28 | Hcl Technologies Limited | Data security using a blockchain ledger |
US11159308B2 (en) | 2019-03-20 | 2021-10-26 | PolySign, Inc. | Preventing an erroneous transmission of a copy of a record of data to a distributed ledger system |
US11349636B2 (en) | 2019-03-25 | 2022-05-31 | Micron Technology, Inc. | Local ledger block chain for secure updates |
US11316691B2 (en) | 2019-04-15 | 2022-04-26 | Eygs Llp | Methods and systems for enhancing network privacy of multiple party documents on distributed ledger-based networks |
US11502838B2 (en) | 2019-04-15 | 2022-11-15 | Eygs Llp | Methods and systems for tracking and recovering assets stolen on distributed ledger-based networks |
US11677563B2 (en) | 2019-04-15 | 2023-06-13 | Eygs Llp | Systems, apparatus and methods for local state storage of distributed ledger data without cloning |
US11943358B2 (en) | 2019-04-15 | 2024-03-26 | Eygs Llp | Methods and systems for identifying anonymized participants of distributed ledger-based networks using zero-knowledge proofs |
US11551216B2 (en) * | 2019-05-01 | 2023-01-10 | Sony Corporation | Transaction security on distributed-ledger based MaaS platform |
US11206138B2 (en) | 2019-05-02 | 2021-12-21 | Ernst & Young U.S. Llp | Biosignature-based tokenization of assets in a blockchain |
WO2020240771A1 (en) * | 2019-05-30 | 2020-12-03 | 日本電気株式会社 | Virtual currency system, terminal, server, transaction method for virtual currency, and program |
CN110264173B (en) * | 2019-05-30 | 2022-07-05 | 银清科技有限公司 | Block chain based bilateral service settlement method and node device |
US11249985B2 (en) * | 2019-06-15 | 2022-02-15 | Facebook, Inc. | Scalable, secure, efficient, and adaptable distributed digital ledger transaction network |
US11843703B2 (en) | 2019-07-17 | 2023-12-12 | Hewlett-Packard Development Company, L.P. | Blockchain-based distributed ledgers for image forming apparatuses |
US11232439B2 (en) | 2019-08-09 | 2022-01-25 | Eygs Llp | Methods and systems for preventing transaction tracing on distributed ledger-based networks |
JP6840319B1 (en) * | 2019-09-24 | 2021-03-10 | スタンダードキャピタル株式会社 | Transaction information processing system |
US11636470B2 (en) * | 2019-09-25 | 2023-04-25 | Visa International Service Association | Key-value map commitments system and method |
US11196570B2 (en) | 2019-10-07 | 2021-12-07 | Accenture Global Solutions Limited | Cryptologic blockchain interoperability membership system |
EP4055791B1 (en) * | 2019-11-06 | 2023-12-27 | Visa International Service Association | Blockchain enabled fault tolerance |
CN110807187B (en) * | 2019-11-06 | 2021-09-14 | 福建福链科技有限公司 | Block chain-based network market illegal information evidence storing method and platform terminal |
EP4062585A1 (en) | 2019-11-20 | 2022-09-28 | Eygs LLP | Systems, apparatus and methods for identifying and securely storing distinguishing characteristics in a distributed ledger within a distributed ledger-based network based on fungible and non-fungible tokens |
US11531980B2 (en) * | 2019-12-06 | 2022-12-20 | Mastercard International Incorporated | Method and system for optimizing blockchain parsing using a wallet's static characteristics |
US11574308B2 (en) | 2020-04-15 | 2023-02-07 | Eygs Llp | Intelligent assertion tokens for authenticating and controlling network communications using a distributed ledger |
US11676117B2 (en) * | 2020-05-07 | 2023-06-13 | International Business Machines Corporation | Blockchain compliance verification network |
US11599858B2 (en) | 2020-05-07 | 2023-03-07 | International Business Machines Corporation | Blockchain settlement network |
US11645632B2 (en) * | 2020-05-26 | 2023-05-09 | Derek Norman La Salle | System and method for a decentralized portable information container supporting privacy protected digital information credentialing, remote administration, local validation, access control and remote instruction signaling utilizing blockchain distributed ledger and container wallet technologies |
US11410180B2 (en) * | 2020-06-25 | 2022-08-09 | Stripe, Inc. | Database with dimensional balances updating |
US20230298009A1 (en) * | 2020-08-18 | 2023-09-21 | Visa International Service Association | Rapid cryptocurrency transaction processing |
CA3091660A1 (en) * | 2020-08-31 | 2021-11-03 | Polymath Inc. | Method, system, and medium for blockchain-enabled atomic settlement |
CN113129017B (en) * | 2020-08-31 | 2022-06-24 | 支付宝(杭州)信息技术有限公司 | Information sharing method, device and equipment |
US11847637B2 (en) * | 2020-11-11 | 2023-12-19 | Stripe, Inc. | Database with data integrity maintenance |
US12021861B2 (en) * | 2021-01-04 | 2024-06-25 | Bank Of America Corporation | Identity verification through multisystem cooperation |
CN112910965B (en) * | 2021-01-18 | 2022-12-06 | 香港理工大学深圳研究院 | Method and system for submitting fragmented block chain down-across-fragmentation transaction |
US20220358235A1 (en) * | 2021-05-05 | 2022-11-10 | EMC IP Holding Company LLC | Access Control of Protected Data Using Storage System-Based Multi-Factor Authentication |
US20230043731A1 (en) | 2021-08-06 | 2023-02-09 | Salesforce.Com, Inc. | Database system public trust ledger architecture |
US11989726B2 (en) | 2021-09-13 | 2024-05-21 | Salesforce, Inc. | Database system public trust ledger token creation and exchange |
US11770445B2 (en) | 2022-01-25 | 2023-09-26 | Salesforce, Inc. | Decentralized information management database system |
US11880372B2 (en) | 2022-05-10 | 2024-01-23 | Salesforce, Inc. | Distributed metadata definition and storage in a database system for public trust ledger smart contracts |
US12033122B2 (en) | 2022-07-07 | 2024-07-09 | Lithic, Inc. | Systems and methods for configuring serverless authorization stream access (ASA) for virtual bank account transactions |
US11971862B1 (en) * | 2022-09-20 | 2024-04-30 | Lithic, Inc. | Processing transactions with idempotency in real-time ledgers |
EP4390720A4 (en) * | 2022-11-07 | 2024-08-28 | Tencent Tech Shenzhen Co Ltd | Blockchain-based data processing method and apparatus, device, and medium |
Citations (37)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20020156726A1 (en) * | 2001-04-23 | 2002-10-24 | Kleckner James E. | Using digital signatures to streamline the process of amending financial transactions |
US20040138973A1 (en) * | 2003-01-14 | 2004-07-15 | American Express Travel Related Services Company, Inc. | Method and system for exchange of currency related instructions |
US20040143539A1 (en) * | 2002-11-08 | 2004-07-22 | Neill Penney | Method and apparatus for trading assets |
US20050137961A1 (en) * | 2003-11-26 | 2005-06-23 | Brann John E.T. | Latency-aware asset trading system |
US20060213980A1 (en) * | 2005-03-25 | 2006-09-28 | Bluko Information Group | Method and system of detecting cash deposits and attributing value |
US20080082452A1 (en) * | 2006-10-03 | 2008-04-03 | John Wankmueller | Proxy Authentication Methods and Apparatus |
US20080113776A1 (en) * | 2006-11-13 | 2008-05-15 | Bally Gaming, Inc. | Multiple account funds transfer in a wagering environment |
US20080281907A1 (en) * | 2007-05-07 | 2008-11-13 | Hilary Vieira | System and method for globally issuing and validating assets |
US20090121015A1 (en) * | 2007-11-13 | 2009-05-14 | Steve Newmark | Tradesmans card system |
US20090182672A1 (en) * | 2008-01-11 | 2009-07-16 | Doyle Paul F | System and Method for Financial Transaction Validation |
US20120047052A1 (en) * | 2010-08-20 | 2012-02-23 | Samir Kiritkumar Patel | Systems and Methods of Processing and Classifying a Financial Transaction |
US20120095885A1 (en) * | 2010-10-18 | 2012-04-19 | Bank Of America Corporation | Global Treasury Monitoring System |
US20120323654A1 (en) * | 2011-06-17 | 2012-12-20 | Children's Edutainment Network, Inc. | System and method of managing and tracking a plurality of tokens |
US20130030941A1 (en) * | 2007-02-08 | 2013-01-31 | Thomas Meredith | Method of providing cash and cash equivalent for electronic transactions |
US20130036476A1 (en) * | 2011-08-02 | 2013-02-07 | Rights Over Ip, Llc | Rights-based system |
US20130125114A1 (en) * | 2011-11-11 | 2013-05-16 | Vmware, Inc. | Computational asset identification without predetermined identifiers |
US20130179337A1 (en) * | 2012-01-09 | 2013-07-11 | Walter Ochynski | Account free possession and transfer of electronic money |
US20130204785A1 (en) * | 2012-01-31 | 2013-08-08 | Justin T. Monk | Mobile managed service |
US20130226880A1 (en) * | 2010-10-20 | 2013-08-29 | Fujitsu Limited | Information processing system, memory device, information processing apparatus, and method of controlling information processing system |
US20130229452A1 (en) * | 2012-03-02 | 2013-09-05 | Xerox Corporation | Systems and methods for forming raised markings on substrates for braille identification and security and to facilitate automatic handling of the substrates |
US20130268438A1 (en) * | 2011-09-29 | 2013-10-10 | Monetaris, Llc | Virtual Currency Payment Network |
US20130346309A1 (en) * | 2011-03-07 | 2013-12-26 | Roberto Giori | System and method for providing and transferring fungible electronic money |
US20140025521A1 (en) * | 2012-07-19 | 2014-01-23 | Apple Inc. | Securing in-app purchases |
US20140222671A1 (en) * | 2013-02-07 | 2014-08-07 | Aurelio Elias | System and method for the execution of third party services transaction over financial networks through a virtual integrated automated teller machine on an electronic terminal device. |
US20140330721A1 (en) * | 2013-05-02 | 2014-11-06 | Quan Wang | Systems and methods for verifying and processing transactions using virtual currency |
US8886570B1 (en) * | 2013-10-29 | 2014-11-11 | Quisk, Inc. | Hacker-resistant balance monitoring |
US20140337206A1 (en) * | 2013-05-10 | 2014-11-13 | Albert Talker | Electronic Currency System |
US20150067344A1 (en) * | 2013-08-27 | 2015-03-05 | Morphotrust Usa, Llc | Digital Identification Document |
US20150066748A1 (en) * | 2013-09-04 | 2015-03-05 | Anthony Winslow | Systems and methods for transferring value to and managing user selected accounts |
US20150074764A1 (en) * | 2013-09-12 | 2015-03-12 | The Boeing Company | Method of authorizing an operation to be performed on a targeted computing device |
US20150095225A1 (en) * | 2013-10-02 | 2015-04-02 | Mastercard International Incorporated | Enabling synchronization between disparate payment account systems |
US20150220928A1 (en) * | 2014-01-31 | 2015-08-06 | Robert Allen | Platform for the purchase and sale of digital currency |
US20150262173A1 (en) * | 2014-03-17 | 2015-09-17 | Bank Of America Corporation | System and Method for Wire Transfers Using Cryptocurrency |
US20150312233A1 (en) * | 2010-04-30 | 2015-10-29 | T-Central, Inc. | System and Method to Enable PKI- and PMI- Based Distributed Locking of Content and Distributed Unlocking of Protected Content and/or Scoring of Users and/or Scoring of End-Entity Access Means - Added |
US20150339886A1 (en) * | 2014-05-26 | 2015-11-26 | Lazlo 326 LLC | Encrypted electronic gaming ticket |
US20150363876A1 (en) * | 2014-06-16 | 2015-12-17 | Bank Of America Corporation | Cryptocurrency Transformation System |
US11023968B2 (en) * | 2015-03-05 | 2021-06-01 | Goldman Sachs & Co. LLC | Systems and methods for updating a distributed ledger based on partial validations of transactions |
Family Cites Families (33)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5262942A (en) * | 1990-06-05 | 1993-11-16 | Bankers Trust Company | Financial transaction network |
US7028187B1 (en) * | 1991-11-15 | 2006-04-11 | Citibank, N.A. | Electronic transaction apparatus for electronic commerce |
US5970479A (en) * | 1992-05-29 | 1999-10-19 | Swychco Infrastructure Services Pty. Ltd. | Methods and apparatus relating to the formulation and trading of risk management contracts |
US6725202B1 (en) * | 1995-04-10 | 2004-04-20 | Texas Instruments Incorporated | Transaction accounting of toll transactions in transponder systems |
IES990584A2 (en) * | 1999-07-12 | 2000-07-12 | Mainline Corporate Holdings | Dynamic currency conversion for card payment systems |
AU783008B2 (en) * | 2000-05-02 | 2005-09-15 | Charles R.J. Moore | Methods and apparatus for securing, integrating, automating, and manipulating internet based accounting systems |
US20020065919A1 (en) * | 2000-11-30 | 2002-05-30 | Taylor Ian Lance | Peer-to-peer caching network for user data |
US20020073015A1 (en) * | 2000-12-08 | 2002-06-13 | Chan Hiok Khiang | Method and system for trading redeemable assets |
KR101194730B1 (en) * | 2002-02-14 | 2012-10-25 | 자차리 페신 | Apparatus and method of a distributed capital system |
US20030225683A1 (en) * | 2002-05-31 | 2003-12-04 | Mt One, Inc. | Electronic bid/proposal system for the construction industry |
US20130282580A1 (en) * | 2003-02-28 | 2013-10-24 | Payment Pathways, Inc. | SYSTEMS AND METHODS FOR EXTENDING IDENTITY ATTRIBUTES AND AUTHENTICATION FACTORS IN AN ePAYMENT ADDRESS REGISTRY |
US20050131836A1 (en) * | 2003-12-12 | 2005-06-16 | Armstrong Thomas W. | Method, device and software for ordering and paying for a purchase |
US7314168B1 (en) * | 2004-03-12 | 2008-01-01 | Ameriprise Financial, Inc. | Account monitoring system |
NZ595027A (en) * | 2005-04-19 | 2013-03-28 | Microsoft Corp | Network commercial transactions |
CN101523428A (en) | 2006-08-01 | 2009-09-02 | Q佩控股有限公司 | Transaction authorisation system and method |
AU2007281028B2 (en) | 2006-08-01 | 2011-09-08 | SQID Technologies Ltd | Transaction authorisation system and method |
US20100205153A1 (en) * | 2009-02-12 | 2010-08-12 | Accenture Global Services Gmbh | Data System Architecture to Analyze Distributed Data Sets |
CN101499913B (en) * | 2009-03-06 | 2015-04-15 | 腾讯科技(深圳)有限公司 | Method, system and device for service processing |
CA2758464A1 (en) * | 2009-04-30 | 2010-11-04 | Comverse, Inc. | Controlling consumption of a shared service |
US20110153434A1 (en) * | 2009-12-17 | 2011-06-23 | American Express Travel Related Services Company, Inc. | System and method for merchandising intellectual property assets |
GB201005733D0 (en) * | 2010-04-06 | 2010-05-19 | Wallin Lars | Digital asset authentication system and method |
US20120078785A1 (en) * | 2010-09-24 | 2012-03-29 | Bank Of America Corporation | Estimated balance |
US9147188B2 (en) * | 2010-10-26 | 2015-09-29 | Tectonics | Electronic currency and authentication system and method |
US20150026072A1 (en) * | 2011-07-18 | 2015-01-22 | Andrew H B Zhou | Global world universal digital mobile and wearable currency image token and ledger |
JP5742054B2 (en) | 2011-08-02 | 2015-07-01 | 株式会社日本総合研究所 | Received remittance receiving system and receiving method |
US20140279680A1 (en) * | 2013-03-14 | 2014-09-18 | Tiptree Asset Management Company, Llc | Systems and methods for providing asset-backed securities |
US20140279451A1 (en) * | 2013-03-15 | 2014-09-18 | Fedbid, Inc. | Escrow Payment System for Transactions |
US9411982B1 (en) * | 2013-08-07 | 2016-08-09 | Amazon Technologies, Inc. | Enabling transfer of digital assets |
US9497349B2 (en) * | 2013-08-28 | 2016-11-15 | Morphotrust Usa, Llc | Dynamic digital watermark |
US20150170112A1 (en) * | 2013-10-04 | 2015-06-18 | Erly Dalvo DeCastro | Systems and methods for providing multi-currency platforms comprising means for exchanging and interconverting tangible and virtual currencies in various transactions, banking operations, and wealth management scenarios |
US9396338B2 (en) * | 2013-10-15 | 2016-07-19 | Intuit Inc. | Method and system for providing a secure secrets proxy |
US10776761B2 (en) * | 2014-03-18 | 2020-09-15 | nChain Holdings Limited | Virtual currency system |
CN104320262B (en) * | 2014-11-05 | 2017-07-21 | 中国科学院合肥物质科学研究院 | The method and system of client public key address binding, retrieval and the verification of account book technology are disclosed based on encryption digital cash |
-
2015
- 2015-03-05 US US14/639,895 patent/US11023968B2/en active Active
-
2016
- 2016-03-04 EP EP16710594.9A patent/EP3265985B1/en active Active
- 2016-03-04 JP JP2017564775A patent/JP6697008B2/en active Active
- 2016-03-04 CA CA2985763A patent/CA2985763C/en active Active
- 2016-03-04 CN CN201680025792.5A patent/CN107683493B/en active Active
- 2016-03-04 CN CN202111376403.2A patent/CN114049212A/en active Pending
- 2016-03-04 ES ES16710594T patent/ES2832709T3/en active Active
- 2016-03-04 AU AU2016226026A patent/AU2016226026B2/en active Active
- 2016-03-04 WO PCT/US2016/021069 patent/WO2016141361A1/en active Application Filing
- 2016-03-04 EP EP19211923.8A patent/EP3633585B1/en active Active
- 2016-03-04 ES ES19211923T patent/ES2881656T3/en active Active
-
2018
- 2018-06-27 HK HK18108292.8A patent/HK1248883A1/en unknown
-
2020
- 2020-04-14 AU AU2020202492A patent/AU2020202492B2/en active Active
-
2021
- 2021-02-24 US US17/184,472 patent/US20210201410A1/en not_active Abandoned
Patent Citations (37)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20020156726A1 (en) * | 2001-04-23 | 2002-10-24 | Kleckner James E. | Using digital signatures to streamline the process of amending financial transactions |
US20040143539A1 (en) * | 2002-11-08 | 2004-07-22 | Neill Penney | Method and apparatus for trading assets |
US20040138973A1 (en) * | 2003-01-14 | 2004-07-15 | American Express Travel Related Services Company, Inc. | Method and system for exchange of currency related instructions |
US20050137961A1 (en) * | 2003-11-26 | 2005-06-23 | Brann John E.T. | Latency-aware asset trading system |
US20060213980A1 (en) * | 2005-03-25 | 2006-09-28 | Bluko Information Group | Method and system of detecting cash deposits and attributing value |
US20080082452A1 (en) * | 2006-10-03 | 2008-04-03 | John Wankmueller | Proxy Authentication Methods and Apparatus |
US20080113776A1 (en) * | 2006-11-13 | 2008-05-15 | Bally Gaming, Inc. | Multiple account funds transfer in a wagering environment |
US20130030941A1 (en) * | 2007-02-08 | 2013-01-31 | Thomas Meredith | Method of providing cash and cash equivalent for electronic transactions |
US20080281907A1 (en) * | 2007-05-07 | 2008-11-13 | Hilary Vieira | System and method for globally issuing and validating assets |
US20090121015A1 (en) * | 2007-11-13 | 2009-05-14 | Steve Newmark | Tradesmans card system |
US20090182672A1 (en) * | 2008-01-11 | 2009-07-16 | Doyle Paul F | System and Method for Financial Transaction Validation |
US20150312233A1 (en) * | 2010-04-30 | 2015-10-29 | T-Central, Inc. | System and Method to Enable PKI- and PMI- Based Distributed Locking of Content and Distributed Unlocking of Protected Content and/or Scoring of Users and/or Scoring of End-Entity Access Means - Added |
US20120047052A1 (en) * | 2010-08-20 | 2012-02-23 | Samir Kiritkumar Patel | Systems and Methods of Processing and Classifying a Financial Transaction |
US20120095885A1 (en) * | 2010-10-18 | 2012-04-19 | Bank Of America Corporation | Global Treasury Monitoring System |
US20130226880A1 (en) * | 2010-10-20 | 2013-08-29 | Fujitsu Limited | Information processing system, memory device, information processing apparatus, and method of controlling information processing system |
US20130346309A1 (en) * | 2011-03-07 | 2013-12-26 | Roberto Giori | System and method for providing and transferring fungible electronic money |
US20120323654A1 (en) * | 2011-06-17 | 2012-12-20 | Children's Edutainment Network, Inc. | System and method of managing and tracking a plurality of tokens |
US20130036476A1 (en) * | 2011-08-02 | 2013-02-07 | Rights Over Ip, Llc | Rights-based system |
US20130268438A1 (en) * | 2011-09-29 | 2013-10-10 | Monetaris, Llc | Virtual Currency Payment Network |
US20130125114A1 (en) * | 2011-11-11 | 2013-05-16 | Vmware, Inc. | Computational asset identification without predetermined identifiers |
US20130179337A1 (en) * | 2012-01-09 | 2013-07-11 | Walter Ochynski | Account free possession and transfer of electronic money |
US20130204785A1 (en) * | 2012-01-31 | 2013-08-08 | Justin T. Monk | Mobile managed service |
US20130229452A1 (en) * | 2012-03-02 | 2013-09-05 | Xerox Corporation | Systems and methods for forming raised markings on substrates for braille identification and security and to facilitate automatic handling of the substrates |
US20140025521A1 (en) * | 2012-07-19 | 2014-01-23 | Apple Inc. | Securing in-app purchases |
US20140222671A1 (en) * | 2013-02-07 | 2014-08-07 | Aurelio Elias | System and method for the execution of third party services transaction over financial networks through a virtual integrated automated teller machine on an electronic terminal device. |
US20140330721A1 (en) * | 2013-05-02 | 2014-11-06 | Quan Wang | Systems and methods for verifying and processing transactions using virtual currency |
US20140337206A1 (en) * | 2013-05-10 | 2014-11-13 | Albert Talker | Electronic Currency System |
US20150067344A1 (en) * | 2013-08-27 | 2015-03-05 | Morphotrust Usa, Llc | Digital Identification Document |
US20150066748A1 (en) * | 2013-09-04 | 2015-03-05 | Anthony Winslow | Systems and methods for transferring value to and managing user selected accounts |
US20150074764A1 (en) * | 2013-09-12 | 2015-03-12 | The Boeing Company | Method of authorizing an operation to be performed on a targeted computing device |
US20150095225A1 (en) * | 2013-10-02 | 2015-04-02 | Mastercard International Incorporated | Enabling synchronization between disparate payment account systems |
US8886570B1 (en) * | 2013-10-29 | 2014-11-11 | Quisk, Inc. | Hacker-resistant balance monitoring |
US20150220928A1 (en) * | 2014-01-31 | 2015-08-06 | Robert Allen | Platform for the purchase and sale of digital currency |
US20150262173A1 (en) * | 2014-03-17 | 2015-09-17 | Bank Of America Corporation | System and Method for Wire Transfers Using Cryptocurrency |
US20150339886A1 (en) * | 2014-05-26 | 2015-11-26 | Lazlo 326 LLC | Encrypted electronic gaming ticket |
US20150363876A1 (en) * | 2014-06-16 | 2015-12-17 | Bank Of America Corporation | Cryptocurrency Transformation System |
US11023968B2 (en) * | 2015-03-05 | 2021-06-01 | Goldman Sachs & Co. LLC | Systems and methods for updating a distributed ledger based on partial validations of transactions |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20220058638A1 (en) * | 2020-08-24 | 2022-02-24 | Capital One Services, Llc | Systems and methods for obfuscating transactions |
Also Published As
Publication number | Publication date |
---|---|
AU2020202492B2 (en) | 2021-08-05 |
EP3265985A1 (en) | 2018-01-10 |
EP3633585B1 (en) | 2021-06-09 |
CN114049212A (en) | 2022-02-15 |
CA2985763C (en) | 2022-11-15 |
EP3633585A1 (en) | 2020-04-08 |
HK1248883A1 (en) | 2018-10-19 |
AU2016226026B2 (en) | 2020-04-23 |
CN107683493A (en) | 2018-02-09 |
AU2020202492A1 (en) | 2020-05-07 |
EP3265985B1 (en) | 2020-10-21 |
CA2985763A1 (en) | 2016-09-09 |
JP6697008B2 (en) | 2020-05-20 |
CN107683493B (en) | 2021-12-10 |
AU2016226026A1 (en) | 2017-09-21 |
ES2832709T3 (en) | 2021-06-11 |
ES2881656T3 (en) | 2021-11-30 |
US20160260169A1 (en) | 2016-09-08 |
US11023968B2 (en) | 2021-06-01 |
WO2016141361A1 (en) | 2016-09-09 |
JP2018507501A (en) | 2018-03-15 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
AU2020202492B2 (en) | Systems and methods for updating a distributed ledger based on partial validations of transactions | |
AU2022200068B2 (en) | Telecommunication system and method for settling session transactions | |
US20220084013A1 (en) | Identity management, smart contract generator, and blockchain mediating system, and related methods | |
US20180075422A1 (en) | Financial management systems and methods | |
US20180308094A1 (en) | Time stamping systems and methods | |
CN111418184A (en) | Credible insurance letter based on block chain | |
WO2019123001A1 (en) | Atomically swapping ownership certificates | |
CN111417945A (en) | Credible insurance letter based on block chain | |
CN111433799A (en) | Credible insurance letter based on block chain | |
US20210233070A1 (en) | Notary system for a distributed ledger | |
CN113826134A (en) | Credible insurance letter based on block chain | |
CN111433798A (en) | Credible insurance letter based on block chain |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AS | Assignment |
Owner name: GOLDMAN SACHS & CO. LLC, NEW YORK Free format text: ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:ARNOLD, MATTHEW TIMOTHY;NAEEM, ZARTASHA;SIGNING DATES FROM 20120705 TO 20150705;REEL/FRAME:055397/0402 |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: APPLICATION DISPATCHED FROM PREEXAM, NOT YET DOCKETED |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: DOCKETED NEW CASE - READY FOR EXAMINATION |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: NON FINAL ACTION MAILED |
|
STCB | Information on status: application discontinuation |
Free format text: ABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTION |