IP Library › Granted Patent US 12,701,005
Granted Patent B2
US 12,701,005 · App. 17/564,326 · Granted Aug 4, 2026

Selective audit process for privacy-preserving blockchain

Inventors: Kaoutar El Khiyaoui (Rueschlikon, CH); Angelo De Caro (Zürich, CH)
Assignee: International Business Machines Corporation
H04L9/321H04L9/085H04L9/3218H04L9/3247H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,701,005
App. No.
17/564,326
Granted
Aug 4, 2026
Kind
B2
Abstract

An example operation may include one or more of identifying a first blockchain transaction stored on a blockchain ledger based on a first identifier of a user that submitted the first blockchain transaction, retrieving a secret key shared between an auditor node and the user, decrypting, via the auditor node, ciphertexts included in the first blockchain transaction based on the secret key to recover a second user identifier of the user, and identifying, via the auditor node, a second blockchain transaction of the user stored on the blockchain ledger which includes the second user identifier.

Claims (49)

1 . An apparatus, comprising:

a hardware-implemented processor configured to:

identify, based on a first user identifier of a user that submitted a first blockchain transaction, the first blockchain transaction stored on a blockchain ledger;

retrieve a secret key shared between an auditor node and the user;

decrypt, via the auditor node, based on the secret key, ciphertexts and transaction details included in the first blockchain transaction;

validate, via the auditor node, the transaction details against a determined audit criteria, wherein the validation includes validation of a zero-knowledge proof (ZKP), submitted by the user, included in the first blockchain transaction;

recover a second user identifier of the user based on the decryption of the ciphertexts, and the validation;

identify, via the auditor node, a second blockchain transaction of the user based on the recovery of the second user identifier, wherein

the second blockchain transaction is stored on the blockchain ledger, and

the second blockchain transaction includes the second user identifier;

decrypt, based on the secret key, ciphertexts included in the second blockchain transaction; and

recover a third user identifier based on the decryption of the ciphertexts included in the second blockchain transaction.

2 . The apparatus of claim 1 , wherein the hardware-implemented processor is further configured to verify that there are no blockchain transactions, other than the first blockchain transaction, stored on the blockchain ledger with the first user identifier.

3 . The apparatus of claim 1 , wherein the first user identifier and the second user identifier are each verifiably generated based on a unique user identifier of the user and a key of the user.

4 . The apparatus of claim 1 , wherein the hardware-implemented processor is further configured to:

determine, via the auditor node, that there are no blockchain transactions stored on the blockchain ledger with the third user identifier; and

terminate, based on the determination, an audit process.

5 . The apparatus of claim 1 , wherein the first blockchain transaction and the second blockchain transaction are signed with anonymous signatures.

6 . A computer-implemented method, comprising:

identifying, based on a first user identifier of a user that submitted a first blockchain transaction, the first blockchain transaction stored on a blockchain ledger;

retrieving a secret key shared between an auditor node and the user;

decrypting, via the auditor node, based on the secret key, ciphertexts and transaction details included in the first blockchain transaction;

validating, via the auditor node, the transaction details against a determined audit criteria, wherein the validating comprises validating a zero-knowledge proof (ZKP), submitted by the user, included in the first blockchain transaction;

recovering a second user identifier of the user based on the decrypting of the ciphertexts, and the validating;

identifying, via the auditor node, a second blockchain transaction of the user based on the recovery of the second user identifier, wherein

the second blockchain transaction is stored on the blockchain ledger, and

the second blockchain transaction includes the second user identifier;

decrypting, based on the secret key, ciphertexts included in the second blockchain transaction; and

recovering a third user identifier based on the decrypting of the ciphertexts included in the second blockchain transaction.

7 . The computer-implemented method of claim 6 , wherein the validating further comprises verifying that there are no blockchain transactions, other than the first blockchain transaction, stored on the blockchain ledger with the first user identifier.

8 . The computer-implemented method of claim 6 , wherein the first user identifier and the second user identifier are each verifiably generated based on a unique user identifier of the user and a key of the user.

9 . The computer-implemented method of claim 6 , wherein the computer-implemented method further comprises:

determining, via the auditor node, that there are no blockchain transactions stored on the blockchain ledger with the third user identifier; and

terminating, based on the determining, an audit process.

10 . The computer-implemented method of claim 6 , wherein the first blockchain transaction and the second blockchain transaction are signed with anonymous signatures.

11 . A non-transitory computer-readable storage medium comprising instructions, that when read by a hardware-implemented processor, cause the hardware-implemented processor to perform:

identifying, based on a first user identifier of a user that submitted a first blockchain transaction, the first blockchain transaction stored on a blockchain ledger;

retrieving a secret key shared between an auditor node and the user;

decrypting, via the auditor node, based on the secret key, ciphertexts and transaction details included in the first blockchain transaction;

validating, via the auditor node, the transaction details against a determined audit criteria, wherein the validating includes validating a zero-knowledge proof (ZKP), submitted by the user, included in the first blockchain transaction;

recovering a second user identifier of the user based on the decrypting of the ciphertexts, and the validating;

identifying, via the auditor node, a second blockchain transaction of the user based on the recovery of the second user identifier, wherein

the second blockchain transaction is stored on the blockchain ledger, and

the second blockchain transaction includes the second user identifier;

decrypting, based on the secret key, ciphertexts included in the second blockchain transaction; and

recovering a third user identifier based on the decrypting of the ciphertexts included in the second blockchain transaction.

12 . The non-transitory computer-readable storage medium of claim 11 , wherein the validating further comprises:

verifying that there are no blockchain transactions, other than the first blockchain transaction, stored on the blockchain ledger with the first user identifier.

13 . The non-transitory computer-readable storage medium of claim 11 , wherein the first user identifier and the second user identifier are each verifiably generated based on a unique user identifier of the user and a key of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2021
From: EL KHIYAOUI, KAOUTAR; DE CARO, ANGELO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058497/0160 →
Continuity (1)
Related Publication 20230208640A1 · Jun 29, 2023
References Cited (24)
US 10666423B2 · Benini · 2020 [cited by examiner]
US 10951409B2 · Konda et al. · 2021 [cited by applicant]
US 11025433B1 · Griffin et al. · 2021 [cited by applicant]
US 20180189753A1 · Konda et al. · 2018 [cited by applicant]
US 20190012662A1 · Krellenstein et al. · 2019 [cited by applicant]
US 20190013931A1 · Benini · 2019 [cited by applicant]
US 20190034923A1 · Greco · 2019 [cited by examiner]
US 20190356674A1 · Irazabal · 2019 [cited by examiner]
US 20200210946A1 · Goodwin · 2020 [cited by applicant]
US 20200412524A1 · Das et al. · 2020 [cited by applicant]
US 20220393858A1 · Barger · 2022 [cited by examiner]
CN 112002436A · 2020 [cited by applicant]
CN 116361823A · 2023 [cited by applicant]
JP 2018007168A · 2018 [cited by applicant]
JP 2021512569A · 2021 [cited by applicant]
JP 2021118444A · 2021 [cited by applicant]
JP 2023098847A · 2023 [cited by applicant]
TW M608974U · 2021 [cited by applicant]
TW M638100U · 2023 [cited by examiner]
Androulaki et al., Privacy-preserving auditable token payments in a permissioned blockchain system. Cryptology ePrint Archive, Report 2019/1058, 2019. https://eprint.iacr.org/2019/1058. [cited by applicant]
Ben-Sasson et al, Decentralized anonymous payments from bitcoin. In IEEE Symposium on Security and Privacy, pp. 459-474. IEEE, 2014. [cited by applicant]
Narula et al., Privacy-preserving auditing for distributed ledgers. In Symposium on Networked Systems Design and Implementation, pp. 65-80. USENIX, Feb. 2018. [cited by applicant]
Poelstra et al., Confidential assets. In Aviv Zohar, Ittay Eyal, Vanessa Teague, Jeremy Clark, Andrea Bracciali, Federico Pintore, and Massimiliano Sata, editors, Financial Cryptography and Data Security, vol. 10958 of … [cited by applicant]
Japan Patent Office, “Notice of Reasons for Refusal” May 7, 2026, 07 Pages, JP Application No. 2022-205037. [cited by applicant]