Write-Domain Separation and Non-Custodial Enforcement: A Structural Impossibility in Account-Based Ledgers, with a Commitment-Based Construction

📅 2026-05-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work investigates the enforcement of future asset disposition in account-based ledgers without asset custody or owner cooperation. It formally introduces, for the first time, a four-property specification for Non-Custodial Enforceable Execution (NCEE) and proves that any system satisfying the Key Sovereignty (KS) axiom cannot achieve NCEE, revealing an inherent structural incompatibility between the two. To resolve this tension, the paper proposes a commitment-based “envelope” primitive that leverages conditional trees and token sets to separate write domains for ordinary spending and restricted operations within private-state ledgers. Theoretical analysis demonstrates that this primitive satisfies NCEE under standard cryptographic assumptions. Practical viability is confirmed through three deployment templates implemented in the Noir language with the UltraHonk proving system, which validate its gas efficiency, recursive aggregation performance, and economic feasibility.
📝 Abstract
Account-based ledgers -- standard externally-owned accounts (EOAs), ERC-4337 smart accounts, post-Pectra EIP-7702 delegated EOAs -- place the holder of the controlling key at the apex of asset authorization. We ask a structural question about ledger access control: under this authorization model, can a protocol enforce the future disposition of an asset without taking custody and without requiring the owner's cooperation at enforcement time? We formalize the target as Non-Custodial Enforced Encumbrance (NCEE), a four-property specification covering self-custody, transition restriction, irrevocability, and permissionless enforcement. We define the Key Sovereignty Axiom (KS) and prove that any ledger satisfying KS cannot realize NCEE; standard EOAs, ERC-4337 smart accounts, and EIP-7702 delegated EOAs satisfy KS for their standard asset paths. We define Asset-Authorization Coupling (AAC) and prove it necessary for NCEE in the transfer-dichotomous asset setting. To witness the positive side, we introduce the envelope, a primitive for commitment-based private-state ledgers that binds a note, a condition tree, and a redistribution intent to protocol-maintained marker sets, separating ordinary spend nullifiers from a new encumbrance-namespace nullifier derived from note randomness rather than the owner key. We prove the envelope realizes NCEE under stated cryptographic assumptions and a deployment assumption that the marker-set registry is immutable; three concrete deployment templates are given. We define games for encumbrance integrity, settlement security, key-compromise resilience, and encumbrance indistinguishability. A reference implementation in Noir and UltraHonk supports the empirical claims, with gas measurements, recursive aggregation benchmarks, and a practical-economics analysis.
Problem

Research questions and friction points this paper is trying to address.

Non-Custodial Enforcement
Account-Based Ledgers
Asset Authorization
Encumbrance
Key Sovereignty
Innovation

Methods, ideas, or system contributions that make the work stand out.

Non-Custodial Enforced Encumbrance
Key Sovereignty Axiom
Asset-Authorization Coupling
Envelope Primitive
Commitment-Based Ledger