Papers
Topics
Authors
Recent
Search
2000 character limit reached

SilentLedger: Private & Auditable Blockchain

Updated 10 July 2026
  • SilentLedger is a privacy-preserving blockchain system that decouples user-to-user transactions from auditor involvement by enabling completely non-interactive, retrospective audits.
  • It employs a renewable anonymous certificate scheme alongside dual-path encryption and zero-knowledge proofs to ensure both confidentiality and traceable, independent auditing solely through on-chain data.
  • The system demonstrates practical efficiency with low computational overhead and competitive benchmark metrics compared to alternative privacy-preserving blockchain solutions.

SilentLedger is a privacy-preserving blockchain transaction system with auditing and complete non-interactivity: users can transact privately without payees being online and without auditor involvement, while auditors can retrospectively recover participant identities and transaction amounts using only on-chain data. The system introduces a renewable anonymous certificate scheme with formal semantics and a rigorous security model, combines traceable transaction mechanisms constructed from established cryptographic primitives, and provides a concrete instantiation evaluated under a standard 2-2 transaction model (Liu et al., 10 Sep 2025).

1. Problem setting and design objective

Privacy-preserving blockchain systems protect transaction data, but they must also provide auditability that enables auditors to recover participant identities and transaction amounts when warranted. SilentLedger targets a failure mode in prior auditable designs: existing approaches often compromise the independence of auditing and transactions by introducing extra interactions, and many require auditors to serve as validators or recording nodes, which introduces risks to both data security and system reliability (Liu et al., 10 Sep 2025).

Within that setting, SilentLedger is specified as the first to decouple both user-to-user and user-to-auditor interactions. Its design goal is not merely confidential transfer, but confidential transfer with independent audit recovery. “Complete non-interactivity” therefore has two dimensions. First, payers do not depend on payees being online. Second, transaction correctness and later audit do not require the auditor to participate at transaction time. This framing is central to SilentLedger’s position in the literature, because several earlier systems provide on-chain privacy while preserving some live dependency on an auditor, a validator role, or user-side disclosure.

A common misconception is that auditable privacy systems must weaken transaction autonomy. SilentLedger is defined precisely to avoid that trade-off: traceability is cryptographically ensured, and the auditor can audit solely from on-chain data (Liu et al., 10 Sep 2025).

2. Cryptographic composition

SilentLedger composes a set of established primitives rather than relying on a single monolithic construction. The architecture couples anonymous credential randomization, dual-path encryption, and zero-knowledge validity proofs so that authorization remains publicly verifiable while identity and amount recovery are reserved for the payee and the auditor.

Primitive Role in SilentLedger
Renewable Anonymous Certificate scheme (RAC) Derives unlinkable anonymous credentials from a long-term certificate, with verifiable linkage for the auditor
Public Key Encryption (Elliptic curve ElGamal) Encrypts short secrets under the auditor’s or payee’s keys
Symmetric Key Encryption (SKE) Encrypts long-term addresses and transaction amounts efficiently
Authenticated Key Exchange (AKE) Generates shared keys between payer and payee, or payer and auditor
One-way Functions (OF) Derives symmetric keys from shared DH keys
Signatures of Knowledge (SoK) Proves correct transaction formation, certificate validity, ownership, balance, and range proofs
Reversible Function (RF) Encodes amounts into scalars or curve points

This composition yields a dual-key structure. Short secrets are protected with PKE, while long plaintexts such as addresses and amounts are protected with SKE under keys derived through AKE and one-way functions. Zero-knowledge proofs bind these ciphertexts to valid transaction semantics: ownership, balance, certificate validity, and range constraints are proved without disclosing the underlying transaction data (Liu et al., 10 Sep 2025).

The resulting design is notable for separating confidentiality from traceability without making them mutually exclusive. A plausible implication is that SilentLedger treats auditability as a decryptable view over already valid private transactions, rather than as an external approval workflow.

3. Renewable Anonymous Certificate scheme

The RAC is the most distinctive credential component in SilentLedger. It is introduced to provide user privacy, understood as anonymity and unlinkability relative to a long-term or real-world address, while preserving verifiable linkage so that the anonymous transaction address can be cryptographically connected to the registered long-term address if tracing is invoked (Liu et al., 10 Sep 2025).

The RAC algorithms are: Setup(λ)\mathsf{Setup}(\lambda), CertGen(pp)\mathsf{CertGen}(pp), Rndmz(C,r′)\mathsf{Rndmz}(C,r'), SKeyGen(pp)\mathsf{SKeyGen}(pp), Sign(sk,C)\mathsf{Sign}(sk,C), Adapt(σ,r′)\mathsf{Adapt}(\sigma,r'), and Verify(vk,C,σ)\mathsf{Verify}(vk,C,\sigma). In the paper’s notation, the long-term identity can be generated as

C=rG1,C = rG_1,

and randomized to an anonymous identity

C′=C+r′G1.C' = C + r'G_1.

The renewability property is captured by the distributional identity

Adapt(σ,r)=dSign(sk,C+rG1),\mathsf{Adapt}(\sigma,r) \stackrel{d}{=} \mathsf{Sign}(sk, C + rG_1),

which means that an adapted certificate is distributed identically to a freshly signed certificate on the randomized identity.

The formal correctness property is stated as

CertGen(pp)\mathsf{CertGen}(pp)0

Unforgeability is formalized by the standard EUF-CMA game.

The concrete instantiation is pairing-based over asymmetric pairings CertGen(pp)\mathsf{CertGen}(pp)1. In that instantiation, CertGen(pp)\mathsf{CertGen}(pp)2 outputs public parameters, CertGen(pp)\mathsf{CertGen}(pp)3 samples CertGen(pp)\mathsf{CertGen}(pp)4} \mathbb{Z}_pCertGen(pp)\mathsf{CertGen}(pp)5C=rG_1CertGen(pp)\mathsf{CertGen}(pp)6\mathsf{SKeyGen}(pp)CertGen(pp)\mathsf{CertGen}(pp)7x \xleftarrow{$\mathsf{CertGen}(pp)$8 and sets $\mathsf{CertGen}(pp)$9, and $\mathsf{Rndmz}(C,r')$0 produces $\mathsf{Rndmz}(C,r')$1 with the verification equations

$\mathsf{Rndmz}(C,r')$2

The immediate significance of RAC is that it resolves a tension that often appears in auditable privacy systems: anonymous transaction identities remain unlinkable on-chain, yet they remain auditable because the linkage to registered identities is preserved in a verifiable but non-public form (Liu et al., 10 Sep 2025).

4. Transaction construction and complete non-interactivity

SilentLedger’s transaction model begins with long-term registered addresses certified by an authority or auditor via RAC. When sending money, the payer derives a random ephemeral key and establishes a shared secret both with the payee and with the auditor through AKE or EC-DH. This shared-key structure is what makes the system simultaneously spendable by the payee and traceable by the auditor without any live interaction (Liu et al., 10 Sep 2025).

For each output, the transaction contains an anonymous address for the payee, defined as a randomized version of the long-term address plus a derivable certificate via RAC. It also contains the transaction amount encrypted using a symmetric key derivable by both the payee and the auditor, encrypted symmetric keys under the payee’s and auditor’s PKE keys, and zero-knowledge proofs that the outputs have been formed correctly, the amounts balance, and the certificates match. The on-chain publication therefore includes the anonymous address, the encoded amount ciphertext, encrypted keys for the auditor and payee, the adapted certificate, and the associated proofs.

The tracing procedure is correspondingly explicit. Given only on-chain data and the auditor master tracing key $\mathsf{Rndmz}(C,r')$3, $\mathsf{Rndmz}(C,r')$4 decrypts the relevant ciphertext to obtain the symmetric key $\mathsf{Rndmz}(C,r')$5, uses $\mathsf{Rndmz}(C,r')$6 to decrypt the payee’s long-term address and amount, and reconstructs the link to the payee’s real-world identity from the registry (Liu et al., 10 Sep 2025).

This mechanism clarifies what “non-interactive auditing” means in SilentLedger. The auditor does not co-sign transactions, does not need to be online during transaction creation, and does not need to operate as a validator or recording node. All information required for traceability is embedded in the transaction itself. A common misunderstanding is that such auditability would necessarily expose transaction semantics on-chain; SilentLedger instead places the traceability material inside ciphertexts and proves correct formation with SoKs.

5. Security model and formally proved properties

SilentLedger proves four named security properties: authenticity, anonymity, confidentiality, and soundness. The proofs are given through formal definitions and reductions to the security of the underlying primitives, including IND-CPA security of PKE and SKE, the zero-knowledge and soundness properties of the SoKs, and the structure of the RAC (Liu et al., 10 Sep 2025).

Authenticity states that no adversary can produce a valid, unregistered account or transaction that is accepted by the system unless they control the underlying secret. The formal statement is

$\mathsf{Rndmz}(C,r')$7

Anonymity states that an adversary, even with adaptive corruptions and oracle access, cannot link an anonymous transaction to its originating registered account:

$\mathsf{Rndmz}(C,r')$8

Confidentiality states that transferred amounts are hidden from all parties except the payee and the auditor:

$\mathsf{Rndmz}(C,r')$9

Soundness states that no adversary can produce a convincing but false transaction that violates value conservation or the proof rules:

$\mathsf{SKeyGen}(pp)$0

The proof layer also includes Bulletproofs++ for range proofs and custom SoKs for ownership, balance, and certificate validity. This formalization is important because SilentLedger’s claim is not merely that privacy and audit can coexist, but that their coexistence can be stated and proved under a rigorous adversarial model. This suggests that the design treats auditability as an additional authorized decryption capability rather than as an exception to anonymity or confidentiality.

6. Implementation, comparative profile, and relation to adjacent privacy-ledger work

The concrete implementation uses elliptic-curve groups on BLS12-381, bilinear pairings for RAC, ElGamal for PKE, custom SKE, and Bulletproofs++ for range proofs. The reported software and hardware setting is the mcl library in C++ on Windows 11 with an Intel i7-10500 and 16GB RAM (Liu et al., 10 Sep 2025).

Under the standard 2-2 transaction model, the following benchmark figures are reported:

Step Time
Setup 5.49 ms
MKGen 1.83 ms
UKGen 1.04 ms
AAGen 1.88 ms
Trans 9.75 ms
VerfTX 22.43 ms
Trace 2,030 ms

The transaction size for 2-2 transactions is reported as approximately 4.9KB. The paper further states that all user and payee-side costs are below 50ms per payee even under high load, verification remains under tens of milliseconds, and auditor-side tracing is done in up to 3 seconds using baby-step giant-step for discrete log within expected ranges (Liu et al., 10 Sep 2025).

In comparison with state-of-the-art solutions, SilentLedger is reported to have the lowest computational overhead for transaction generation, with 11.63ms versus Platypus at 730ms, PGC at 40ms, and PEReDi at 877ms. Its validation overhead is slightly higher than Platypus and PGC but still practical at 22.43ms versus 14ms or 1.5ms. Its transaction size is slightly larger than Platypus and PGC at 4,896B, but much smaller than PEReDi at 8,632B. The comparison table in the paper also states that Traceable Monero and Platypus do not support completely non-interactive auditing because they require the auditor as a node, while PEReDi supports non-interactive audit but imposes interaction at transaction time because users need auditor sign-off for correctness (Liu et al., 10 Sep 2025).

A related but distinct research direction appears in the zero-knowledge payment-ledger literature on private and atomic exchange. The Oblivious Multi-Asset Protocol (OMAP) extends zero-knowledge-based crypto notes to support private, atomic swaps of multiple asset types, with indistinguishable transactions and workflow guarantees stated as suitable for platforms like SilentLedger (Gao et al., 2019). OMAP focuses on oblivious and privacy-protected fair exchange of crypto notes or privacy enhanced crypto assets, whereas SilentLedger focuses on privacy-preserving auditing with complete non-interactivity. This suggests complementary rather than identical objectives within privacy-ledger research: OMAP addresses private atomic exchange, while SilentLedger addresses private transfer with retrospective, on-chain-only audit recovery.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to SilentLedger.