Top

Bank of Japan Publishes Results of CBDC PoC

Policy & Regulation·May 31, 2023, 12:38 AM

The Bank of Japan (BoJ) recently concluded the second phase of its central bank digital currency (CBDC) proof of concept (PoC) project, which began in April. The results of this phase were published on Monday, and they shed light on key aspects such as the comparison between account-based and token-based CBDCs and the management of holding limits for users with multiple accounts.

Photo by Manuel Cosentino on Unsplash

 

Token-based CBDCs

The experiments conducted by the central bank covered a wide range of topics. Among the most intriguing findings were the advantages and disadvantages of token-based CBDCs and how to effectively impose holding limits for users with multiple CBDC balances.

Token-based CBDCs have garnered interest from various central banks, with some adopting the UTXO token model used by Bitcoin without the use of a distributed ledger. A UTXO or unspent transaction output, defines where a blockchain transaction starts and finishes. The Bank of Japan explored this model and analyzed its pros and cons.

In the initial proof of concept, both account-based and token-based CBDCs were examined, considering scenarios where the central bank managed the ledger or shared it with intermediaries like banks. In the token-based model, fixed token denominations were used, similar to physical cash in countries like India, and a centralized ledger was employed. However, in the recent phase, the central bank utilized flexible value tokens similar to UTXO and shared ledger functions with intermediaries.

The Bank of Japan favored the flexible value token model due to its ability to handle multiple requests simultaneously. However, it acknowledged that this model may require more technical resources compared to the account-based approach. Challenges may arise when implementing additional functions, such as holding limits, while maintaining optimal performance. The European Central Bank (ECB) also noted in a recent report that most payment providers are accustomed to account-based payments and would incur costs to adapt to token-based systems.

Another significant aspect explored by the BoJ was how to impose holding limits when users have multiple CBDC balances through different intermediaries. The challenge lies in determining if the overall holding limit has been breached without compromising user privacy.

 

Homomorphic encryption

One possible solution discussed in the report is the use of homomorphic encryption, which enables computations to be performed on encrypted data without it first needing to be decrypted. That allows for the necessary checks without intermediaries accessing the specific data being checked. Although this solution may slightly increase processing time, it could introduce a higher risk of data inconsistencies.

Alternatively, a simpler approach proposed by the central bank is to establish a per-account holding limit and a limit on the number of accounts a single user can hold, rather than imposing global limits. Ideally, users with multiple accounts would have a higher per-account holding limit compared to those with fewer accounts.

 

Phase 3 underway

With the next pilot phase already underway, the BoJ aims to test the end-to-end process flow and identify challenges related to integrating with external systems. Additionally, they are creating a CBDC Forum to gather input from the private sector, ensuring a collaborative approach to CBDC development.

While investigation and research into CBDCs continues, the BoJ has said that it will make a final decision on CBDC implementation by 2026.

More to Read
View All
Web3 & Enterprise·

Nov 30, 2023

BU Technology to provide digital asset issuance platform to Ret Games

BU Technology to provide digital asset issuance platform to Ret GamesSouth Korean blockchain firm BU Technology has partnered with digital asset management service provider Byffin to supply a digital asset issuance platform built on its distributed ledger core optimization solution, All-in-one DLT Core (ADC), to Seoul-based Web3 gaming studio Ret Games, according to local news platform Financial Review on Thursday.Photo by GuerrillaBuzz on UnsplashElevating gaming dynamicsAccording to the article, the digital asset issuance platform will be on-boarded to Ret Games’ Play-to-Earn (P2E) gaming platform Pomerium, which houses flagship games like Pome Run and Pome Rumble.“This contract can be seen as proof that ADC is the most competitive blockchain solution in the gaming field,” BU Technology said. “The number of companies submitting inquiries about adopting ADC has increased drastically compared to the previous quarter, especially considering the advantages of ADC like blockchain data processing speeds of over 10,000 transactions per second (TPS).”With ADC and the digital asset issuance platform, Ret Games will be equipped with a high-speed blockchain system that can be utilized in games. The gaming company will also be able to receive a portion of the fees that are paid when issuing digital assets such as game items, thereby yielding increased sales and profits.Safeguarding gaming integrityNotably, Ret Games has generated some KRW 18 billion (approximately $14 million) in revenue through the game data verification system developed by Pomerium called “Guardians”, which validates forged and irregular data in the Pomerium ecosystem and distributes token rewards in return.“Ret Games will be able to detect and verify abnormal transactions of off-chain and on-chain game data for users with the Guardians system installed on their PC,” BU Technology explained. “Web3-based business can also be facilitated since users who participate in the validation of game data are rewarded with PMG tokens.” PMG is the governance token for Pomerium.

news
Web3 & Enterprise·

Aug 23, 2024

DBS Bank pilots government grants on blockchain

Singapore’s DBS Bank, the largest bank in Southeast Asia with assets totaling $739 billion, has launched a pilot project that utilizes blockchain technology for the purpose of distributing government grants. According to a report from Fintech News Singapore, the bank has partnered with Enterprise Singapore (EnterpriseSG) and the Singapore Fintech Association (SFA) to establish the pilot program. The objective is to realize greater efficiency, governance and user experience where programmable grant disbursements are concerned, as a direct consequence of bringing blockchain technology into the equation. Purpose-bound money The pilot program relies on the use of a protocol known as purpose-bound money (PBM). A whitepaper relative to PBM was first published in 2023 by the Monetary Authority of Singapore (MAS). In developing the protocol, MAS had collaborated with DBS, alongside Amazon, the International Monetary Fund (IMF), the Bank of Korea, Banca d’Italia and JPMorgan-owned blockchain platform Onyx. PBM enables the sender of funds to specify certain conditions relative to funds released. This may include such items as validity periods or a set of controls on how funds can be spent by the recipient. Such conditions can be programmed in through the use of smart contracts. Baking specific parameters in from the outset in turn empowers the distributor to automate disbursements to beneficiaries. With disbursements automated, the process realizes efficiency gains. Manual oversight can be cut out of the process entirely.  DBS noted a previous program established during the Singapore Fintech Festival in 2023. It involved 27 local fintech firms. Prominent among them were Advance Intelligence, Experian Singapore, Intersystems, Dobin and Aspire. DBS Bank effected such payments over its permissioned blockchain, ensuring that specified recipients received the grants only when specific parameters had been met. SFA President Shadab Taiyabi commented on the pilot project, stating:“The solution is designed to streamline business grant disbursements that enables local companies to receive payouts more quickly and efficiently, providing them with additional capital to expand their key business areas.” Taiyabi added that the SFA will continue to support collaborations between the public and private sectors relative to programmable grant disbursements as Singapore works towards its Smart Nation objectives.Photo by Mike Enerio on UnsplashEfficiency gains Han Kwee Juan, DBS Bank’s country head, emphasized the efficiency gains, stating: “Smart contract technology automates and streamlines grant disbursements for government agencies to enable faster, more secure disbursements and payments.” While DBS has progressed this project as a consequence of its collaboration with MAS on PBM, the bank has also been working with the Singaporean regulator on Project Orchid, a project which aims to progress technology and competencies relative to the development of a digital Singaporean dollar. Similarly, it has participated in Project Guardian, an asset tokenization initiative between policymakers and the financial industry. Earlier this month, DBS entered into a collaboration with Ant International, the international division of the Ant Group which in turn is an affiliate of Chinese e-commerce behemoth, Alibaba, with the aim of providing treasury tokens to improve treasury and liquidity management. 

news
Policy & Regulation·

Oct 28, 2023

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability FixSmart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.Photo by Nenad Novaković on UnsplashAccount abstraction vulnerabilityThis vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.Improving user experienceAccount abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.Company mergerEarlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

news
Loading