scieee AI-readable full text Open interactive document viewer

DECENTRALIZED IDENTITY (DID) ARCHITECTURE FOR SECURE KYC IN U.S. BANKING AND FINTECH ECOSYSTEMS

Vikas Reddy Mandadhi

Abstract

The increasing complexity of identity verification in U.S. banking and fintech ecosystems has highlighted thelimitations of traditional centralized Know Your Customer (KYC) processes, which often involve redundantdata collection, slow onboarding, and increased risk of data breaches. This study explores the design andimplementation of a Decentralized Identity (DID) architecture to enable secure, privacy-preserving, and usercentric KYC. By leveraging self-sovereign identity (SSI) principles, verifiable credentials (VCs), andcryptographic proofs, the proposed framework allows individuals to control their identity data while banks,fintechs, and regulatory authorities can authenticate users efficiently and compliantly. The architectureintegrates permissioned networks, identity wallets, credential issuers, and verifier nodes, supportinginteroperability with existing financial systems. Security, privacy, and regulatory compliance—including AML,FinCEN, and OFAC requirements—are embedded through robust cryptography, zero-knowledge proofs, andselective disclosure mechanisms. The study concludes that DID-enabled KYC can streamline onboarding,reduce operational costs, enhance user privacy, and strengthen overall financial ecosystem trust, providing aviable path for next-generation identity verification in U.S. banking and fintech.

Full text

Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [222] DECENTRALIZED IDENTITY (DID) ARCHITECTURE FOR SECURE KYC IN U.S. BANKING AND FINTECH ECOSYSTEMS Vikas Reddy Mandadhi Bellevue university, [email protected] ABSTRACT The increasing complexity of identity verification in U.S. banking and fintech ecosystems has highlighted the limitations of traditional centralized Know Your Customer (KYC) processes, which often involve redundant data collection, slow onboarding, and increased risk of data breaches. This study explores the design and implementation of a Decentralized Identity (DID) architecture to enable secure, privacy-preserving, and usercentric KYC. By leveraging self-sovereign identity (SSI) principles, verifiable credentials (VCs), and cryptographic proofs, the proposed framework allows individuals to control their identity data while banks, fintechs, and regulatory authorities can authenticate users efficiently and compliantly. The architecture integrates permissioned networks, identity wallets, credential issuers, and verifier nodes, supporting interoperability with existing financial systems. Security, privacy, and regulatory compliance—including AML, FinCEN, and OFAC requirements—are embedded through robust cryptography, zero-knowledge proofs, and selective disclosure mechanisms. The study concludes that DID-enabled KYC can streamline onboarding, reduce operational costs, enhance user privacy, and strengthen overall financial ecosystem trust, providing a viable path for next-generation identity verification in U.S. banking and fintech. Keywords: Decentralized Identity, DID, Self-Sovereign Identity, SSI, KYC, Verifiable Credentials, Banking, Fintech, Privacy-Preserving Authentication, AML Compliance 1. INTRODUCTION 1.1 Background on Identity Management Challenges in U.S. Banking and Fintech Identity verification is a foundational component of financial services, ensuring that customers are accurately identified, financial crimes are mitigated, and regulatory compliance is maintained. In the U.S., banks and fintech companies operate under stringent regulatory frameworks, including anti-money laundering (AML), know your customer (KYC), and counter-terrorism financing (CTF) requirements. Despite the critical importance of identity management, current systems face significant challenges. These include fragmented data silos across institutions, repetitive verification processes for users, susceptibility to identity fraud, and inefficiencies caused by manual or semi-automated workflows. Additionally, the growing adoption of digital banking and fintech platforms has amplified the need for scalable and robust identity management solutions capable of supporting millions of users while safeguarding privacy and regulatory compliance. Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [223] The rapid proliferation of digital financial services has also increased the attack surface for cyber threats, including identity theft, account takeovers, and fraudulent onboarding. Banks and fintechs are further burdened by the operational costs of maintaining centralized identity databases and performing redundant KYC checks across multiple platforms. These challenges underscore the need for an innovative approach to identity management that balances efficiency, security, and user control, while ensuring seamless integration with regulatory mandates. 1.2 Limitations of Traditional KYC (Know Your Customer) Processes Traditional KYC processes in the U.S. financial sector rely heavily on centralized identity verification methods. Customers are required to provide sensitive personal data, which financial institutions store and manage within proprietary systems. These approaches have several inherent limitations. First, they often involve redundant verification, as users must undergo identity checks each time they engage with a new bank or fintech platform, leading to inefficiencies and poor user experience. Second, centralized storage of sensitive data increases the risk of data breaches and cyberattacks, exposing personally identifiable information (PII) and financial credentials. Third, conventional KYC processes are resource-intensive, requiring significant staff involvement for document verification, exception handling, and regulatory reporting. Moreover, traditional KYC approaches struggle with cross-institution interoperability. Each institution maintains its own verification protocols, making it difficult to share verified credentials across platforms without compromising privacy or security. Regulatory compliance adds additional complexity, as institutions must continually adapt to evolving AML, FinCEN, and OFAC guidelines. Collectively, these limitations highlight the need for a more secure, efficient, and user-centric identity verification mechanism that can operate across the U.S. banking and fintech ecosystem. 1.3 Emergence of Decentralized Identity (DID) Frameworks and Self-Sovereign Identity (SSI) Decentralized Identity (DID) frameworks have emerged as a promising solution to the challenges of traditional KYC systems. DID leverages distributed ledger technology (DLT) to create verifiable, cryptographically secure identifiers that users can control directly. Unlike centralized identity databases, DIDs are self-sovereign, meaning that individuals retain ownership of their identity information and can selectively disclose attributes to institutions or service providers. This approach significantly reduces the need for repetitive verification while enhancing privacy and data security. Self-Sovereign Identity (SSI) complements DIDs by enabling users to manage verifiable credentials (VCs), which can include proof of identity, financial eligibility, or regulatory compliance. Banks and fintech platforms can verify these credentials through cryptographic proofs without accessing the underlying personal data, thereby reducing exposure to breaches and maintaining regulatory compliance. The combination of DID and SSI enables a privacy-preserving, interoperable, and user-centric identity verification ecosystem, which can streamline KYC workflows, improve customer experience, and support regulatory objectives. In summary, the emergence of decentralized identity frameworks offers a transformative approach to secure KYC in U.S. banking and fintech ecosystems, addressing the inefficiencies, security risks, and interoperability challenges inherent in traditional systems. By empowering users with control over their own identity data and enabling cryptographically verifiable credentials, DID-based KYC frameworks provide a foundation for the next generation of secure, efficient, and compliant financial services. Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [224] 2. OBJECTIVES AND REQUIREMENTS 2.1 Core Objectives: Secure Authentication, Privacy, Interoperability The primary objective of integrating Decentralized Identity (DID) frameworks into the KYC process is to enhance the security, privacy, and interoperability of identity verification in U.S. banking and fintech ecosystems. Secure authentication ensures that users are correctly identified, reducing the risk of fraud, identity theft, and unauthorized account access. Privacy is central to the design, allowing individuals to control which attributes of their identity are disclosed, when, and to whom, thereby minimizing unnecessary exposure of personally identifiable information (PII). Interoperability ensures that verified credentials can be recognized and validated across multiple banks, fintech platforms, and regulatory systems without requiring repetitive verification, supporting seamless cross-institution operations. These objectives collectively aim to provide a trustworthy, user-centric, and regulatory-compliant identity verification framework that balances operational efficiency with stringent security and privacy requirements. 2.2 Functional Requirements for DID-Based KYC Integration For DID-based KYC integration to be effective, several functional requirements must be satisfied: • Credential Issuance and Management: Banks, fintechs, and regulatory authorities must be able to issue verifiable credentials (VCs) that users can securely store in identity wallets. • Authentication and Verification: Systems must support cryptographically verifiable authentication processes, including digital signatures and DID resolution, enabling real-time verification without exposing underlying data. • Interoperability: The architecture must allow credentials to be recognized and validated across multiple platforms, ensuring cross-institution operability and reducing onboarding redundancy. • Revocation and Update Mechanisms: The system must enable timely revocation, update, or expiration of credentials to maintain regulatory compliance and mitigate fraud risks. • Integration with Existing Banking and Fintech Systems: Middleware or adapters should translate between DID standards and legacy KYC databases or processes, enabling smooth operational integration. 2.3 Non-Functional Requirements: Scalability, Resiliency, Privacy, Regulatory Alignment Beyond functional capabilities, the DID-based KYC framework must meet rigorous non-functional requirements: • Scalability: The system must support millions of users and high-frequency transaction verification without performance degradation. Distributed ledger and identity wallet infrastructures should be horizontally scalable to accommodate growth in banking and fintech networks. • Resiliency: Continuous availability is critical for financial operations. The architecture must include fault-tolerant consensus mechanisms, redundant node deployment, and disaster recovery strategies. • Privacy: Privacy-preserving techniques such as zero-knowledge proofs, selective disclosure, and encryption must be embedded to protect sensitive identity information while maintaining verifiability. • Regulatory Alignment: The framework must comply with AML, FinCEN, OFAC, and relevant state or federal regulations. Audit trails and reporting mechanisms must be integrated to satisfy supervisory and compliance requirements. Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [225] These requirements collectively ensure that the DID-based KYC system is not only secure and privacypreserving but also robust, scalable, and regulatory-compliant, making it suitable for deployment across U.S. banking and fintech ecosystems. Table 1: Summary of Objectives and Requirements Category Requirement Description Core Objectives Secure Authentication Ensure users are accurately identified using cryptographically verifiable methods. Privacy Enable user-controlled disclosure of identity attributes to minimize PII exposure. Interoperability Support cross-institution credential recognition and validation for seamless operations. Functional Requirements Credential Issuance & Management Verifiable credentials issued by banks, fintechs, or regulators, stored securely in identity wallets. Authentication & Verification Real-time, cryptographically verifiable authentication without exposing underlying data. Revocation & Updates Timely revocation or updates of credentials for fraud prevention and compliance. System Integration Middleware to connect DID frameworks with legacy KYC systems and databases. Non-Functional Requirements Scalability Support millions of users and high transaction volumes without performance loss. Resiliency Fault-tolerant nodes, disaster recovery, and continuous system availability. Privacy & Security Zero-knowledge proofs, selective disclosure, and encryption to safeguard identity data. Regulatory Alignment Compliance with AML, FinCEN, OFAC, state/federal laws, and audit/reporting capabilities. 3. OVERVIEW OF DECENTRALIZED IDENTITY (DID) 3.1 Definition and Principles of DID Decentralized Identity (DID) is a novel framework for digital identity management that enables individuals and entities to control and manage their identity data independently of centralized authorities. Unlike traditional identity systems, which rely on centralized databases maintained by banks, governments, or service providers, DIDs are cryptographically verifiable identifiers that can be registered on distributed ledger technologies (DLTs). A DID uniquely identifies an entity and is designed to be persistent, globally resolvable, and cryptographically secure. The core principles of DIDs revolve around self-sovereignty, security, privacy, and interoperability. Selfsovereignty ensures that users retain full control over their identity data, deciding when and to whom their Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [226] credentials are disclosed. Security is achieved through public-private key cryptography, enabling authentication and tamper-proof verification of credentials. Privacy is maintained by minimizing the exposure of personally identifiable information (PII) and supporting selective disclosure mechanisms. Interoperability ensures that DIDs can operate across multiple systems, networks, and institutions, fostering a unified digital identity ecosystem. 3.2 DID Methods and Standards (W3C, Sovrin, uPort, etc.) DID frameworks adhere to global standards to ensure interoperability and compliance across financial institutions and fintech platforms. The World Wide Web Consortium (W3C) has published a comprehensive DID specification that defines the structure, resolution, and lifecycle of DIDs. According to this standard, each DID consists of a unique identifier, an associated DID document, and cryptographic public keys that enable verification. Several implementations of DID standards have emerged in practice. Sovrin is a permissioned distributed ledger specifically designed for identity use cases, emphasizing trust frameworks and regulatory compliance. uPort, built on the Ethereum blockchain, enables user-controlled identity wallets, verifiable credentials, and seamless integration with decentralized applications. Other DID methods include Veres One, Hyperledger Indy, and Microsoft ION, each providing unique trade-offs in scalability, governance, and consensus mechanisms. The adoption of standardized methods ensures that verifiable credentials and identity proofs can be validated consistently across banks, fintechs, and regulatory networks. 3.3 Self-Sovereign Identity (SSI) Model and User-Centric Control The Self-Sovereign Identity (SSI) model is the practical realization of DID principles, emphasizing user-centric control and autonomy over digital identities. In SSI, individuals store verifiable credentials in digital identity wallets, which they control entirely. This contrasts sharply with traditional centralized models, where identity data is stored and managed by financial institutions or third-party providers, often creating single points of failure or targets for cyberattacks. SSI enables users to selectively disclose attributes—such as age, citizenship, or financial eligibility—without exposing unrelated personal information. For instance, a user can prove they are over 18 to open a bank account without revealing their full date of birth or address. SSI also supports portable identity, allowing credentials to be used across multiple banks, fintech platforms, or regulatory bodies without repeated verification. By empowering users to manage their own identity, SSI reduces friction, enhances privacy, and strengthens trust between service providers and their clients. 3.4 Verifiable Credentials (VCs) and Cryptographic Proofs Verifiable Credentials (VCs) are a key component of DID and SSI ecosystems, providing cryptographically signed proofs of identity attributes. A VC is issued by a trusted entity—such as a bank, regulatory authority, or fintech provider—and stored securely in the user’s identity wallet. When required, the holder can present the VC to a verifier, who validates the credential’s authenticity and integrity using cryptographic proofs, without necessarily accessing the underlying sensitive data. VCs typically leverage digital signatures, public-key infrastructure (PKI), and zero-knowledge proofs (ZKPs) to ensure that credentials are tamper-proof, non-repudiable, and privacy-preserving. For example, a user can prove compliance with KYC requirements or regulatory eligibility without revealing unnecessary PII, reducing both security risks and compliance overhead for banks and fintechs. By integrating VCs into DID frameworks, Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [227] financial institutions can implement secure, real-time, and interoperable KYC processes that satisfy regulatory requirements while maintaining user privacy and control. In summary, the DID framework—grounded in cryptographically secure identifiers, standardized methods, selfsovereign control, and verifiable credentials—provides a robust foundation for transforming identity verification and KYC processes in U.S. banking and fintech ecosystems. By enabling user-centric, privacy-preserving, and interoperable identity management, DIDs and SSI models address the limitations of traditional identity systems and lay the groundwork for secure, scalable, and regulatory-compliant financial services. 4. DID ARCHITECTURE FOR SECURE KYC 4.1 High-Level Architecture of a DID-Enabled KYC System The architecture of a DID-enabled KYC system is designed to integrate securely with U.S. banking and fintech ecosystems while maintaining privacy, security, and interoperability. At a high level, the system comprises four primary layers: • User Layer: Individuals interact with the system via identity wallets or user agents that store and manage verifiable credentials. • Credential Layer: Trusted institutions such as banks, fintechs, and regulatory authorities act as credential issuers, providing cryptographically signed verifiable credentials (VCs). • Ledger/Resolution Layer: A permissioned distributed ledger stores decentralized identifiers (DIDs) and DID documents, enabling verifiable resolution without exposing sensitive data. • Verifier Layer: Banks, fintech platforms, and regulators act as verifiers, validating presented credentials in real time while preserving user privacy. This layered architecture supports modular integration with existing KYC workflows, allowing institutions to adopt DID-based identity management without disrupting legacy systems. It also ensures scalability, resiliency, and regulatory compliance while providing end-users with full control over their identity data. 4.2 Decentralized Identifiers (DIDs) and Public/Private Key Infrastructure DIDs form the foundation of this architecture. Each DID is a globally unique, cryptographically verifiable identifier linked to a DID document that stores public keys, service endpoints, and authentication methods. The public/private key infrastructure (PKI) enables secure interactions: Private keys are held exclusively by the identity owner and are used to sign transactions or authorize disclosure of attributes. Public keys are registered on the permissioned ledger and used by verifiers to validate credentials and signatures. This approach eliminates reliance on centralized identity databases, reduces the risk of data breaches, and enables secure, real-time verification across institutions. PKI also supports revocation mechanisms, enabling issuers to revoke compromised credentials or update access permissions without exposing sensitive data. 4.3 Identity Wallets and User Agents for End-Users Identity wallets or user agents act as the interface for end-users to manage their DIDs and verifiable credentials. These wallets allow users to: • Store credentials securely on their device or in a secure cloud enclave • Present credentials to verifiers via selective disclosure • Approve or deny requests for identity verification in real time Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [228] • Track credential validity, revocation status, and expiry dates By giving users direct control over their credentials, identity wallets enable self-sovereign identity (SSI), reducing dependency on intermediaries and enhancing privacy. The wallets can be implemented as mobile applications, desktop software, or browser extensions, providing flexibility and accessibility for diverse user populations. 4.4 Credential Issuers (Banks, Fintechs, Regulatory Authorities) Credential issuers are trusted entities responsible for issuing verifiable credentials to users after authenticating their identity. These may include: • Banks: Issue credentials for account opening, financial eligibility, and credit verification. • Fintechs: Issue credentials for lending, payments, or investment onboarding. • Regulatory Authorities: Issue credentials for AML/KYC compliance, certifications, or sanctioned identity verification. Issuers sign the credentials using their private keys, embedding cryptographic proofs that verifiers can validate against the public keys stored on the ledger. The issuance process can include tiered credentialing, allowing different levels of verification based on the type of service, regulatory requirement, or risk assessment. Table 2: Core Components of DID Architecture for Secure KYC Component Description Function Decentralized Identifiers (DIDs) Unique, cryptographically verifiable identifiers Enable secure identity representation and authentication Public/Private Key Infrastructure (PKI) Keys linked to each DID Support credential signing, verification, and revocation Identity Wallets / User Agents Software for end-user credential management Allow storage, selective disclosure, and real-time consent Credential Issuers Banks, fintechs, regulators Authenticate users and issue verifiable credentials Permissioned Ledger / DID Registry Blockchain-based storage of DID documents Enable resolution, verification, and interoperability Verifiers Banks, fintechs, regulatory authorities Validate credentials without accessing unnecessary personal data 5. WORKFLOW OF DID-BASED KYC 5.1 Onboarding Process Using DID and Verifiable Credentials The onboarding process in a DID-based KYC system begins with the user creating a decentralized identifier (DID) through an identity wallet or user agent. Once the DID is generated, the user undergoes initial verification by a trusted credential issuer, such as a bank or fintech platform. The issuer validates the user’s identity using traditional KYC methods (e.g., government-issued IDs, biometric verification) and then issues a verifiable credential (VC). The VC is cryptographically signed by the issuer and stored securely in the user’s identity wallet. This credential contains proof of verified identity attributes, which can later be presented selectively to verifiers. The process eliminates repetitive identity checks across different institutions, reducing onboarding time and operational cost while enhancing security and user control. 5.2 Authentication and Access Control for Banking and Fintech Services Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [229] Once the user holds verifiable credentials, authentication to banking or fintech services is achieved by presenting these credentials to service verifiers. Using cryptographic proofs, the verifier confirms the authenticity and integrity of the credential without exposing unnecessary personal information. Access control policies are enforced dynamically based on the attributes in the credentials. For example, a lending platform can verify a user’s age, residency, or creditworthiness without accessing full identity documents. By integrating DID-based authentication with existing access control frameworks, institutions can provide secure, real-time, and privacy-preserving access to services. 5.3 Real-Time Verification and Revocation of Credentials The architecture supports real-time credential verification by checking the digital signatures against the public keys stored on the permissioned ledger. This ensures immediate confirmation of identity while maintaining tamper-proof records. Credential revocation is handled through the ledger’s update mechanisms. If a credential is compromised, expires, or is invalidated due to compliance changes, the issuer can revoke or update the credential in real time. Verifiers querying the ledger will automatically detect revoked credentials, reducing fraud and maintaining regulatory compliance. 5.4 Cross-Institution Interoperability and Data Portability A major advantage of DID-based KYC is cross-institution interoperability. Users can present the same verifiable credentials to multiple banks, fintechs, or regulatory authorities without undergoing repeated verification. This is enabled by adherence to global DID standards (W3C) and verifiable credential formats, which ensure that credentials are universally recognizable and verifiable. Data portability allows users to maintain control over their identity attributes and selectively disclose them as required. Institutions benefit from reduced duplication of effort, improved compliance, and enhanced customer experience. This interoperability is critical for fintech ecosystems, where multiple platforms and services require identity verification while preserving user privacy. 6. CONCLUSION The adoption of decentralized identity (DID) frameworks represents a transformative approach to identity management and KYC processes in U.S. banking and fintech ecosystems. Traditional centralized KYC methods are increasingly challenged by inefficiencies, repetitive verification, susceptibility to data breaches, and difficulties in cross-institution interoperability. By contrast, a DID-enabled architecture, grounded in selfsovereign identity (SSI) principles, empowers users to control their own identity data, ensures privacy through selective disclosure, and provides cryptographically verifiable credentials for secure authentication. The proposed DID-based KYC system integrates identity wallets, credential issuers, verifiers, and permissioned ledgers to deliver real-time verification, credential revocation, and cross-institution interoperability. Cryptographic proofs and public/private key infrastructure ensure the authenticity, integrity, and nonrepudiation of credentials while maintaining compliance with AML, FinCEN, OFAC, and other regulatory standards. This architecture not only strengthens security and privacy but also improves operational efficiency, reduces onboarding friction, and enables scalable adoption across diverse banking and fintech platforms. By leveraging DID standards and verifiable credential frameworks, financial institutions can implement a usercentric, interoperable, and privacy-preserving KYC process. The combination of cryptographic assurance, decentralized verification, and regulatory alignment positions DID-enabled KYC as a viable and forward- Volume-08 Issue 01, January-2024 ISSN: 2456-9348 Impact Factor: 6.736 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [230] looking solution for the modern financial ecosystem. As digital banking, fintech innovation, and cross-platform financial services continue to expand, the integration of decentralized identity mechanisms is likely to become a core component of secure, efficient, and trusted identity management in the U.S. financial sector. REFERENCES 1) Abadi, M., & Feigenbaum, J. (2019). Secure multiparty computation for financial applications. Journal of Financial Cryptography, 14(2), 45–62. 2) Adrian, T., & Griffoli, T. M. (2019). The rise of digital money. International Monetary Fund. https://www.imf.org 3) Auer, R., & Claessens, S. (2020). Regulating fintech: Observations from market developments. BIS Quarterly Review, Bank for International Settlements. 4) Buterin, V. (2014). A next-generation smart contract and decentralized application platform. Ethereum White Paper. https://ethereum.org 5) Catalini, C., & Gans, J. S. (2020). Some simple economics of the blockchain. Communications of the ACM, 63(7), 105–113. 6) Chen, Y., Li, X., & Zhao, R. (2021). Fraud detection in financial transactions: A machine learning perspective. IEEE Transactions on Neural Networks and Learning Systems, 32(9), 4305–4317. 7) FATF. (2020). Guidance on digital identity. Financial Action Task Force. https://www.fatf-gafi.org 8) Gai, K., Qiu, M., & Sun, X. (2020). Blockchain-enabled financial services: Challenges and opportunities. Journal of Network and Computer Applications, 115, 1–11. 9) Gudgeon, L., Perez, D., Harz, D., Livshits, B., & Gervais, A. (2020). The decentralized insurance landscape. In Proceedings of the IEEE Symposium on Security and Privacy Workshops, 39–44. 10) Hardjono, T., & Smith, N. (2019). Decentralized trusted computing for financial ecosystems. MIT Connection Science Working Paper. 11) Khan, B., Niu, X., & Thapa, S. (2021). Blockchain-based fraud prevention in payment systems: A systematic review. Information Systems Frontiers, 23(5), 1239–1254. 12) Narayanan, A., Bonneau, J., Felten, E., Miller, A., & Goldfeder, S. (2016). Bitcoin and cryptocurrency technologies: A comprehensive introduction. Princeton University Press. 13) Peters, G. W., & Panayi, E. (2016). Understanding modern banking ledgers through blockchain technologies. In Banking Beyond Banks and Money (pp. 239–278). Springer. 14) Schär, F. (2021). Decentralized finance: On blockchainand smart contract-based financial markets. Federal Reserve Bank of St. Louis Review, 103(2), 153–174. 15) Wang, S., Ouyang, L., Yuan, Y., Ni, X., Han, X., & Wang, F. (2019). Blockchain-enabled smart contracts: Architecture, applications, and future trends. IEEE Transactions on Systems, Man, and Cybernetics, 49(11), 2266–2277.