Rayls Private Networks
A Rayls Private Network is multiple Rayls Sovereign chains connected together via a central Hyperledger Besu chain, the Private Network Hub.
Each participating institution runs its own Rayls Sovereign chain (Privacy Node in the code): a private EVM (Ethereum Virtual Machine) chain that holds its tokens, its clients' balances and its own smart contracts. Activity inside that chain stays there. When the institution needs to pay, message or trade with another member of the network, the transaction goes through the Private Network Hub, under rules set by the Private Network operator.
In the code, a Private Network is called a VEN (Value Exchange Network).
Private Networks on rayls.comRayls Private Networks come in more than one flavour. The Private Network page on rayls.com describes the product, including capabilities that Rayls can develop for a client's own deployment. These docs describe Private Networks as they run in production today, as published in the open-source code.
The Private Network Hub
The Private Network Hub is a Hyperledger Besu chain at the centre of every Rayls Private Network, run by the Private Network operator. Every message between Rayls Sovereign chains passes through it. It holds the network's registries for participants, tokens and approved contract templates, the cross-chain messaging contracts, and the Enygma and delivery-versus-payment (DvP) contracts.
The Hub doesn't hold client accounts. It holds what the chains need to share: encrypted message batches, the registries, a record of each chain's latest block headers, and, for Enygma tokens, each participant's balance as a commitment that hides the amount. It copies the registries out to every Rayls Sovereign chain, so each chain can check the network's rules locally.
Who runs what
| Component | Run by | What it does |
|---|---|---|
| Rayls Sovereign chain (Privacy Node) | Each participating institution | The institution's own EVM chain, running the Axyl node. Holds its tokens, client balances and contracts. |
| Private relayer | Each institution, one per chain | Carries messages between its chain and the Hub. Encrypts what it sends and decrypts what it receives. |
| Key service (CTS, the Cryptography Trust Suite) | Each institution | Holds the institution's keys, encrypted with a key management service (KMS), and signs its relayer's transactions. |
| Private Network Hub | The Private Network operator | The Besu chain described above. |
| Governance services (API, listener, flagger) | The Private Network operator | Index and decrypt Hub activity, track balances per chain and token, and flag anomalies. |
| Auditor Explorer | The Private Network operator | A web interface for searching decrypted cross-chain transactions. |
| Proofs API | Shared by the network | Generates the zero-knowledge proofs that Enygma and DvP need. |
Private Network Technical Architecture describes each component and how a message moves through them.
What moves between chains
| Feature | What it does | Status |
|---|---|---|
| Arbitrary messages | A contract on one chain calls a contract on another chain. | Available |
| Enygma private transfers | Moves an Enygma token between chains. Amounts and receivers are hidden from the other members. See Rayls Enygma. | Available |
| Enygma DvP | Swaps Enygma tokens for ERC-721 or ERC-1155 tokens in one settlement on the Hub. See DvP on Rayls Private Networks. | Available |
What a Private Network gives you
- Privacy between institutions. An institution's internal payments never leave its own chain. Messages between chains cross the Hub encrypted, and Enygma also hides amounts and receivers from the other members. See Privacy in a Private Network.
- Governance by one accountable operator. The Private Network operator admits participants, approves tokens and contract templates, and can freeze a participant or a token. See Governance.
- Oversight. The operator can decrypt every cross-chain message and every Enygma transfer in the network, and its governance services flag anomalies as they happen. See Auditing.
- Scale. Each institution's workload runs on its own chain, and the relayers batch cross-chain traffic before it reaches the Hub. See Scalability.
The operator sees all cross-chain trafficWhen an institution joins, its key service encrypts the institution's view private key to the Private Network operator. The operator can then read every message and Enygma transfer between chains, though not the activity inside each chain. Choose the operator with that in mind. See Who sees what.
Where the design comes from
The Private Network follows the shape described in the Rayls research: each bank keeps its own private ledger, and a shared commit chain settles and records what passes between them. In this implementation the private ledgers are Rayls Sovereign chains and the commit chain is the Private Network Hub. See Published academic material and CBDCs on Rayls Private Networks.
In this section
Concepts:
- Why a Rayls Private Network?
- Private Network Technical Architecture
- Privacy in a Private Network
- Scalability
- Interoperability
- Governance
- Auditing
- CBDCs on Rayls Private Networks
- DvP on Rayls Private Networks
Running a network:
Operating a network:
Private payments and DvP:
Updated about 2 hours ago
