Skip to content
ENBANKDesk

Enbank docs

Architecture

How the browser desk, an Arcium MXE, and Solana settlement fit together.

On this page

Three layers

A production Enbank instruction crosses three layers. Each layer has a different job, and only the last one is a public ledger write.

  1. Client. Holds the account key, builds the private inputs, and encrypts them for the MXE before they are submitted.
  2. MXE. The confidential application: a Solana program, Arcis circuits, MXE metadata, and one Arx cluster that executes those circuits.
  3. Solana. Queues the computation, stores accounts, and runs the callback after the cluster returns a result the Arcium program can verify.

Arcium's own map of this split is the architecture overview. Enbank uses that split for vault, transfer, allocation, and card withdrawal. This website implements only the client-side preview of the desk.

Preview path

On this site the path never leaves the tab.

form → validate address and amount
     → BankProvider updates React state
     → localStorage["enbank.preview.v1"]
     → activity row, status "Queued"

BankProvider is the only writer. send, allocate, settle, toggleReveal, and setAddress all mutate one Desk object and persist it. There is no RPC client, no wallet adapter broadcast, and no fetch to an MXE.

Production path

The production path follows Arcium's computation lifecycle.

  1. The client encrypts arguments for the MXE. Arcium documents that step as an X25519 exchange and the Rescue cipher.
  2. The MXE Solana program receives the ciphertext and cross-program invokes the Arcium program.
  3. The Arcium program places the computation in that cluster's mempool.
  4. Arx nodes, running arxOS, fetch the job and execute the Arcis circuit with MPC. Clusters currently run Cerberus, a dishonest-majority, detect-and-abort protocol.
  5. The cluster callbacks with the result. The Arcium program verifies it, then the MXE program's callback applies the published fields.

Waiting for that callback is not the same as waiting for one Solana transaction. The cluster has to finish offchain and then submit the callback. Arcium's TypeScript client exposes awaitComputationFinalization for that wait.

Instruction set

These are the confidential instructions the product is specified around. They are not compiled circuits in this repository.

InstructionPrivate inputsDesk equivalent
ShieldAsset balances for the accountVault seed and the reveal flag
TransferAmount, asset, recipientsend on Sealed transfers
AllocateAmount, asset, marketallocate on Markets
WithdrawAmount, asset, card destinationSpecified on Withdraw to a debit card

On Solana, each encrypted instruction typically has three program instructions: one to initialize the computation definition, one to queue a run, and one callback. That pattern is Arcium's, documented in their hello world.

Published fields

Privacy is a property of the circuit outputs, the cluster, and the accounts the app writes. A transfer can publish "this address settled a transfer" and keep the amount inside the MPC state. If the callback writes the amount into a public account, the seal is gone, regardless of the MXE.

Enbank's rule for published fields: the account address and the fact of settlement may be public. The amount, the asset mix inside the vault, and the card destination stay encrypted unless the user reveals them on their own device. The privacy model lists the split field by field.