Rayls Private Networks

A Rayls Private Network is multiple Rayls Sovereign chains connected together via a central Hyperledger Besu chain, the Private Network Hub.

Each participating institution runs its own Rayls Sovereign chain (Privacy Node in the code): a private EVM (Ethereum Virtual Machine) chain that holds its tokens, its clients' balances and its own smart contracts. Activity inside that chain stays there. When the institution needs to pay, message or trade with another member of the network, the transaction goes through the Private Network Hub, under rules set by the Private Network operator.

In the code, a Private Network is called a VEN (Value Exchange Network).

📘

Private Networks on rayls.com

Rayls Private Networks come in more than one flavour. The Private Network page on rayls.com describes the product, including capabilities that Rayls can develop for a client's own deployment. These docs describe Private Networks as they run in production today, as published in the open-source code.

The Private Network Hub

The Private Network Hub is a Hyperledger Besu chain at the centre of every Rayls Private Network, run by the Private Network operator. Every message between Rayls Sovereign chains passes through it. It holds the network's registries for participants, tokens and approved contract templates, the cross-chain messaging contracts, and the Enygma and delivery-versus-payment (DvP) contracts.

The Hub doesn't hold client accounts. It holds what the chains need to share: encrypted message batches, the registries, a record of each chain's latest block headers, and, for Enygma tokens, each participant's balance as a commitment that hides the amount. It copies the registries out to every Rayls Sovereign chain, so each chain can check the network's rules locally.

Who runs what

ComponentRun byWhat it does
Rayls Sovereign chain (Privacy Node)Each participating institutionThe institution's own EVM chain, running the Axyl node. Holds its tokens, client balances and contracts.
Private relayerEach institution, one per chainCarries messages between its chain and the Hub. Encrypts what it sends and decrypts what it receives.
Key service (CTS, the Cryptography Trust Suite)Each institutionHolds the institution's keys, encrypted with a key management service (KMS), and signs its relayer's transactions.
Private Network HubThe Private Network operatorThe Besu chain described above.
Governance services (API, listener, flagger)The Private Network operatorIndex and decrypt Hub activity, track balances per chain and token, and flag anomalies.
Auditor ExplorerThe Private Network operatorA web interface for searching decrypted cross-chain transactions.
Proofs APIShared by the networkGenerates the zero-knowledge proofs that Enygma and DvP need.

Private Network Technical Architecture describes each component and how a message moves through them.

What moves between chains

FeatureWhat it doesStatus
Arbitrary messagesA contract on one chain calls a contract on another chain.Available
Enygma private transfersMoves an Enygma token between chains. Amounts and receivers are hidden from the other members. See Rayls Enygma.Available
Enygma DvPSwaps Enygma tokens for ERC-721 or ERC-1155 tokens in one settlement on the Hub. See DvP on Rayls Private Networks.Available

What a Private Network gives you

  • Privacy between institutions. An institution's internal payments never leave its own chain. Messages between chains cross the Hub encrypted, and Enygma also hides amounts and receivers from the other members. See Privacy in a Private Network.
  • Governance by one accountable operator. The Private Network operator admits participants, approves tokens and contract templates, and can freeze a participant or a token. See Governance.
  • Oversight. The operator can decrypt every cross-chain message and every Enygma transfer in the network, and its governance services flag anomalies as they happen. See Auditing.
  • Scale. Each institution's workload runs on its own chain, and the relayers batch cross-chain traffic before it reaches the Hub. See Scalability.
🚧

The operator sees all cross-chain traffic

When an institution joins, its key service encrypts the institution's view private key to the Private Network operator. The operator can then read every message and Enygma transfer between chains, though not the activity inside each chain. Choose the operator with that in mind. See Who sees what.

Where the design comes from

The Private Network follows the shape described in the Rayls research: each bank keeps its own private ledger, and a shared commit chain settles and records what passes between them. In this implementation the private ledgers are Rayls Sovereign chains and the commit chain is the Private Network Hub. See Published academic material and CBDCs on Rayls Private Networks.

In this section

Concepts:

Running a network:

Operating a network:

Private payments and DvP:


Did this page help you?