Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM

arXiv:2608.28529 · cs.CR, cs.DC · Submitted 2026-08-28 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: Next we'll be talking about the paper "Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM".

Jane: The paper was written by Pietro Tiberì, Vitangelo Lasorella and Gabriele Marcelli from Banca d’Italia.

Tom: Stay tuned as we take you through the paper and discuss its implications.

Paper discussion segment 1: Tom: We're looking at "Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM," a title that immediately suggests we're solving one of the biggest headaches in digital banking. The core conflict is obvious—how to keep transactions private while making sure everyone knows who is responsible for them.

Jane: That’s exactly what this paper addresses, Tom. The summary section really fleshes out how this relaxed anonymity model works. It details a protocol where transaction proofs are generated and verified using these zero-knowledge techniques, making the transfer verifiable without revealing sensitive details like specific account balances or exact counterparties to unauthorized eyes.

Lu: What I found particularly compelling in the summary was how it addresses the state of ownership. It doesn't just track that money moved; it tracks the proof that ownership was valid at a specific point in time, which is critical for auditing purposes later on, providing a verifiable history even when confidentiality is maintained.

Meng: And this relates directly to how they define sender accountability versus receiver confidentiality. The summary suggests a gradient of disclosure—the system knows enough to reconcile accounts between banks without knowing enough to profile individual users or reveal the entire transaction graph.

Lalam: It seems like the paper is defining a new standard of trustworthy data exchange. Instead of trusting an intermediary to keep secrets, you trust mathematics and cryptography to enforce confidentiality rules automatically across a decentralized network.

Tom: That level of structured oversight is what makes it appealing to central banks and regulators, who are tasked with ensuring stability without wanting to become invasive surveillance entities by knowing every single person’s spending habits.

Jane: Precisely. The summary shows that this isn't just about making transactions private; it’s about making the entire settlement process auditable by regulators under controlled conditions, which is a massive practical win for compliance.

Lu: This architectural elegance—where the system enforces rules cryptographically rather than through legal mandates alone—is a massive leap for systemic resilience in finance, creating automated trust.

Meng: It forces us to think about data governance not as a policy layer bolted onto technology, but as an inherent function of the cryptographic protocol itself.

Lalam: This framework suggests that future financial plumbing will be defined by these mathematical proofs, moving away from complex bespoke agreements between different banking consortiums toward a unified cryptographic standard.

Tom: Knowing the general mechanism helps us prepare for the next challenge: scaling this system and identifying its weak points, which leads us into the specific improvements they suggest in the later sections.

Paper discussion segment 2: Jane: The paper is quite advanced, but in its thoroughness, it also acts as a critique of its own preliminary model. When discussing improvements, the primary focus shifts toward strengthening confidentiality and addressing potential gaps in receiver privacy.

Tom: So, even with the initial architecture being strong on anonymity through ZK proofs, they identified areas where a bad actor or an advanced regulator might still gain too much insight into the transaction flow or the identities involved.

Lu: I was very interested in their discussion around viewing keys and batch scanning. The concept that auditors can use specific keys to scan for patterns or validate compliance without ever decrypt the actual, sensitive values is incredibly powerful for regulatory oversight.

Meng: Furthermore, they point out the need to address the value binding at what they term a 'transparent boundary.' This suggests that where the private cryptographic domain meets a public ledger element, we need extra mathematical rigor to ensure values can't be manipulated or misrepresented across that interface.

Lalam: It sounds like they are building in multiple layers of failsafes. They aren't just presenting a solution; they are providing an entire engineering roadmap for hardening the system against real-world exploitation vectors.

Jane: That’s right, Lalam. The suggestions move beyond theoretical perfection and into practical implementation fixes, such as adopting a multi-party trusted setup to distribute key management risks.

Tom: It really highlights that even the most advanced research requires acknowledging its limitations and proactively designing countermeasures for those weaknesses from the outset.

Lu: This design philosophy ensures that the system is not brittle; it anticipates failure modes and builds in resilience, which is a huge factor in long-term stability.

Meng: From an engineering standpoint, this means we are moving away from fragile assumptions about perfect software and toward robust cryptographic guarantees that hold up under stress.

Lalam: This provides a model for how complex systems can be designed to handle not just success, but also failure and scrutiny, allowing the financial system to evolve safely.

Tom: That brings us perfectly to the next point: the structural improvements—specifically the "NoteRegistry" pattern—that make this whole thing function.

Paper discussion segment 3: Tom: We’ve seen how this system manages the core conflict between needing visibility for regulation and keeping transaction details secret, but what are the specific structural improvements that the authors propose to make this even better?

Jane: The most significant addition in their design is this "NoteRegistry" pattern. It moves away from needing a trusted third party to hold note secrets; instead, they use the ledger itself as a secure place for the notes.

Tom: And it’s structured so that no owner index is stored, which is a huge leap toward decentralization—anyone can potentially find their own encrypted notes just by trial decryption on the ledger.

Lu: The fact that this registry allows for self-recovery—a bank finding its entire portfolio by scanning the ledger—is a massive paradigm shift in how we view asset ownership, removing external dependency.

Meng: That design is incredibly elegant, but it also raises questions about the efficiency of "trial decryption" when we scale up to millions of notes; we must be able to handle that load without slowing down the network.

Lalam: It’s fundamentally moving away from centralized trust entirely, suggesting that distributed systems are capable of maintaining high levels of privacy without relying on a single custodian for financial records.

Tom: The paper points out several areas needing further work, like how to achieve full sender accountability and better receiver confidentiality in the current implementation.

Jane: Exactly, but it also shows how "selective disclosure" allows the central bank to audit specific transactions without revealing them to other banks in this system.

Lu: I think this capability for selective disclosure is truly revolutionary; it means regulators can see exactly what they need to see when they need it, without everyone else seeing everything.

Meng: We must be able to efficiently scale that "selective disclosure" mechanism so that the cryptographic operations don't become a bottleneck as the number of participating banks grows.

Lalam: It shows that technology can solve systemic issues of transparency and security simultaneously, building a more trustworthy financial ecosystem for cultural adoption.

Tom: This paper lays out not just a solution, but an entire blueprint for solving complex financial problems. What does this mean for our discussion on the performance and real-world speed of the system?

Conclusion: Tom: So, to summarize our discussion today, it’s clear that "Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM" moves the concept of digital currency far beyond simple transactions; it addresses systemic trust itself.

Jane: Exactly. The implications are profound because they show how advanced cryptography can solve deep-seated structural problems within global finance—problems that have historically required costly oversight or centralized trust.

Lu: From a policy standpoint, what I take away is the necessity of designing these systems from the ground up with privacy as a primary feature, not an afterthought in terms architectural integrity.

Meng: And I think it highlights that the convergence of ZK proofs with permissioned ledger technology is what finally makes this level of rigorous control practical for real-world adoption by a large set of financial institutions.

Lalam: Ultimately, this isn't just about moving money faster; it’s about establishing a new baseline standard where verifiable privacy is the expectation, not the exception in cultural norms.

Tom: It really paints a picture of financial infrastructure maturing into something incredibly sophisticated and resilient. Jane, do you have one final thought on the overall significance?

Jane: I think the most exciting part is seeing how all these disparate concepts—the registry, selective disclosure, and ZK proofs—coalesce into a single, coherent framework that actually works together to create a usable system.

Tom: It certainly gives us a very robust blueprint for what the next generation of financial services might look like. We’ve covered an enormous amount of ground today discussing this paper.

Lu: I’m really looking forward to diving into the next paper and exploring how these principles might apply to entirely different economic models, building on this foundation.

Meng: We appreciate the deep technical insights today; it gives us a lot of material to consider as we think about future standards for secure finance.

Lalam: It has been a truly insightful conversation, and I’m already eager to transition our focus to the next topic of discussion, having seen how this technology can redefine trust itself.

Banca d’Italia

cs.CR, cs.DC

Submitted: 2026-08-28

Updated: 2026-09-04

Code: https://github.com/iden3/snarkjs

Project page: https://berkeley-defi.github.io/assets/material/Tornado%20Cash%20Whitepaper.pdf

License: http://creativecommons.org/licenses/by-nc-nd/4.0/

Importance score: 95/100

The gist: The paper introduces a confidential interbank settlement protocol designed for permissioned Ethereum Virtual Machine (EVM) networks.

Key concepts

Zero-Knowledge Proofs (ZK proofs)
These cryptographic techniques allow transaction proofs to be generated and verified without revealing sensitive details, such as specific account balances or exact counterparties. This enables verifiable transfers while maintaining confidentiality for unauthorized eyes.
CBDC Interbank Settlement
This refers to the process of moving digital central bank currency between banks. The system is designed to make this complex settlement process auditable by regulators while keeping individual transaction details private.
NoteRegistry Pattern
A structural design improvement where the ledger itself acts as a secure place for financial notes. This pattern allows for self-recovery of an entire portfolio by scanning the ledger, removing reliance on a single custodian or trusted third party.

Terminology

Summary

The paper introduces a confidential interbank settlement protocol designed for permissioned Ethereum Virtual Machine (EVM) networks. This work is critical because it establishes a framework that preserves the sender accountability required by financial regulation while providing strong cryptographic guarantees for receiver identity and transfer amount confidentiality. The protocol achieves this balance using advanced zero-knowledge techniques to verify mathematical settlements without disclosing the underlying values.

Core Cryptographic Components

The protocol integrates several sophisticated cryptographic tools to manage transactions and ensure privacy. For settlement verification, it utilizes Groth16 zeroknowledge proofs for mathematical settlement verification without value disclosure. Note management is handled by Poseidon-hashed commitments in an incremental Merkle tree, which provides a mechanism for trustless note custody. Furthermore, the system incorporates multi-recipient ECIES encryption for selective disclosure. The architecture relies on a novel onchain NoteRegistry, which is designed to eliminate the need for any trusted intermediary in note distribution.

Operational Model and Anonymity Guarantees

The central design choice is the adoption of a relaxed sender anonymity model. This model represents a principled compromise, ensuring that while the transfer amount and recipient identity remain confidential, necessary regulatory requirements regarding sender accountability are maintained. The on-chain NoteRegistry is key to this trustless custody, as it ensures that note secrets are recoverable from the chain alone, requiring no cross-service communication.

Production Readiness and Scalability Concerns

The proof-of-concept deployment highlights several critical areas that must be addressed before production deployment. Key among these is ensuring robust security through key generation; a production system requires a multi-party computation (MPC) ceremony involving multiple independent parties... to ensure that no single party can produce false proofs. Furthermore, for efficient auditing, the system must adopt improvements such as implementing Zcash-style viewing key scheme, which would derive a single scan key from the master audit key, enabling efficient batch scanning.

The deployment also faces architectural limitations regarding service isolation. Currently, a single shared ZK service handles proof generation for all banks and holds all participant key material. This must be rectified in production by having each bank operate its own service with isolated key material. Additionally, mitigating potential privacy risks from traffic analysis is necessary; countermeasures such as mandatory delays, dummy transactions, and ciphertext padding are required to counter metadata leakage.

Future Development Pathways

The authors outline several avenues for future work to enhance the protocol's utility and robustness. These include:

  • Implementing a two-output circuit to enable partial transfers with change.

  • Conducting a multi-party trusted setup ceremony.

  • Adopting Zcash-style viewing keys for efficient audit.

  • Developing cross-network interoperability to support multi-CBDC settlement.

The proof of concept has demonstrated practical feasibility on commodity hardware, though the primary bottleneck—software proof generation, measured at 4–12 s—is deemed addressable by specialized hardware accelerators.

Improvements for AI systems

The paper describes a highly specialized financial protocol layer. My improvements will focus on integrating advanced AI/ML models into the system's operational lifecycle—specifically in auditing, risk management, and efficiency optimization—to create a more robust and intelligent financial infrastructure.

Here are the specific improvements and the resulting capabilities of the enhanced AI system:

Improvement: Implement a sophisticated Graph Neural Network (GNN) or advanced Time-Series Anomaly Detection model trained on historical transaction flows and authorized audit patterns. This system would operate atop the Zcash-style viewing key scheme described in Section F.

What the Improved AI System Can Do:

  • Real-Time Behavioral Audit: Instead of merely allowing an auditor to decrypt a single transaction (the current manual process), the GNN models the relationships between addresses, transaction values, and timing across the entire ledger state. It can detect subtle deviations from established interbank behavioral baselines (e.g., unusual recipient clusters, sudden spikes in small-value transfers to previously dormant accounts) that signal potential money laundering or sanctions evasion, even if the transactions themselves are cryptographically shielded.

  • Risk Scoring: Assign a dynamic Suspicion Score to every counterparty and transaction stream based on deviation from peer group norms, significantly preempting manual regulatory review cycles.

Abstract

Central Bank Digital Currency (CBDC) interbank settlement systems operating on Distributed Ledger Technology (DLT) face a fundamental trade-off: blockchain transparency enables trustless verification but exposes commercially sensitive bilateral transaction flows to all network participants. We propose a confidential interbank settlement protocol for permissioned Ethereum-compatible networks that resolves this tension through a relaxed sender anonymity model tailored to regulatory AML/CFT requirements. In this model, the initiating institution remains publicly identifiable on-chain for accountability and compliance, while the receiving institution, transfer amount, and business payload are cryptographically obfuscated. We realize the protocol on Hyperledger Besu using QBFT consensus, combining Groth16 zero-knowledge proofs over BN254, Poseidon hash commitments in an incremental Merkle tree, multi-recipient ECIES payload encryption, and an on-chain NoteRegistry contract that stores encrypted notes as an append-only ledger log, eliminating trusted off-chain custody servers. The protocol supports shield, confidential transfer, and unshield state transitions. Experimental evaluation across a five-node network (three commercial banks, a central bank operator, and a securities depository) demonstrates end-to-end settlement in 8-16 s, proof verification overhead of about 1 ms (around 220k gas) via EVM precompiles, and client proof generation in 4-12 s on commodity ARM hardware. While receiver confidentiality is established at the protocol level, the current proof-of-concept NoteRegistry uses owner-indexed events, a trade-off addressable in production via uniform event broadcasting.

Related papers