Back to Home
Security & Technical Whitepaper

USA ID APP Security & Technical Architecture

A detailed overview of the blockchain architecture, private key management, supported chains, and privacy features that power USA ID APP's self-custody digital identity and wallet platform.

USA ID APP, LLC·Version 1.0·August 2026
1 · Architecture

Blockchain Architecture

USA ID APP is built on a layered architecture that separates the user-facing application, the on-chain settlement and identity layer, the infrastructure gateway, and the self-custody key layer. This separation keeps sensitive cryptographic operations on the client while leveraging the immutability of public blockchains for verification and auditability.

Application Layer

React-based client rendering the identity registration, verification, and wallet interfaces. Credentials are issued as W3C Verifiable Credentials and anchored on-chain via cryptographic hashes.

Blockchain Layer

EVM-compatible chains (Ethereum, BSC, Polygon) plus Solana and XRP Ledger for asset settlement. Identity commitments and credential hashes are written as immutable on-chain records, providing a tamper-proof audit trail.

Infrastructure Layer

Alchemy serves as the primary RPC gateway for reliable transaction estimation and broadcast, with public fallback nodes for resilience. Backend functions act as a serverless API gateway, masking API keys and enforcing per-request authentication.

Custody Layer

Private keys never leave the user's device. Wallets are encrypted client-side and stored as encrypted JSON in the user's private file storage and local browser cache—never in a centralized database in plaintext.

2 · Private Key Management

Self-Custody Key Management

USA ID APP implements a strict self-custody model. The platform never holds or transmits a user's private key. All key generation, signing, and encryption occur on the user's device, ensuring only the user can authorize transactions or decrypt their wallet.

Client-Side Key Generation

Mnemonic seed phrases and key pairs are generated locally using ethers.js cryptographic primitives. The seed phrase is never transmitted to any server; it is shown once to the user for offline backup.

Password-Based Encryption

The wallet is encrypted into a JSON keystore using the user's chosen password (AES-256, scrypt-based key derivation via ethers encrypt/decrypt). Without the password, the encrypted blob is cryptographically useless.

No Plaintext Storage

Encrypted wallet JSON is stored in the user's private file storage and mirrored in browser localStorage. The platform database stores only the ciphertext—never the private key, seed phrase, or password.

Account Checksumming

All Ethereum addresses are normalized with EIP-55 checksumming (ethers.getAddress) before any contract interaction or transaction generation, preventing address-corruption and mistyped-recipient errors.

3 · Supported Chains

Supported Blockchains

USA ID APP is multi-chain, supporting EVM-compatible networks through ethers.js and non-EVM networks through native SDKs. Each chain is accessed through a resilient RPC layer with cached Alchemy providers and public fallbacks for reliability.

Chain
Type
Role
Capabilities
Ethereum
ETH
EVM
Primary chain for identity anchoring, ENS registration, and ETH payments.
EIP-1559 gasENS supportERC-20 tokensNFT (ERC-721)
BNB Smart Chain
BNB
EVM
Low-fee EVM settlement for transactions and token transfers.
Low feesBEP-20 tokensFast finality
Polygon
MATIC
EVM
Layer-2 scaling for high-throughput, low-cost credential anchoring.
Low feesScalableEVM-compatible
Solana
SOL
Non-EVM
High-performance chain for fast SPL token transfers and payments.
SPL tokensPhantom connectSub-second finality
XRP Ledger
XRP
Non-EVM
Efficient cross-border payment rail with near-instant settlement.
Low costCross-borderAccount-based
4 · Privacy Features

Privacy by Design

Privacy is not a feature bolted on after the fact—it is the foundational design principle of USA ID APP. The platform ensures citizens reveal only what a transaction requires, using cryptographic proofs and selective disclosure so that no central party ever holds the full identity data.

Selective Disclosure & Zero-Knowledge Proofs

Citizens prove a single attribute (e.g., age over 21) without revealing the underlying data. USA ID APP leverages selective disclosure built on W3C Verifiable Credentials and is architected to support zero-knowledge proof (ZKP) schemes, allowing a holder to demonstrate the truth of a claim to a verifier without exposing the raw personal data behind it.

Data Minimization

Only the minimum cryptographic proof required for a transaction is shared. A credential verifier receives a verified assertion—not a copy of the source document—so the user's full identity never leaves their wallet.

W3C Verifiable Credentials

Government and third-party credentials are stored as W3C Verifiable Credentials in the user's wallet. Verification is cryptographic: the verifier checks the issuer's signature and chain of trust, without contacting a central database.

On-Chain Hash Anchoring

For auditability, a one-way hash of a credential is optionally anchored on-chain. The hash proves existence and integrity at a point in time while the full credential remains private to the holder—revealing nothing sensitive on a public ledger.

5 · Security Practices

Security & Operational Practices

Beyond the cryptographic architecture, USA ID APP applies defense-in-depth operational practices to keep keys, transactions, and credentials safe end-to-end.

Serverless Secret Management

API keys (Alchemy, Stripe) live in platform-managed secrets, never in client code. Backend functions proxy all privileged RPC and payment calls, enforcing per-request user authentication.

Transaction Integrity

Nonces are fetched once and incremented manually for sequential broadcasts to prevent collisions. EIP-55 checksumming is applied to every address. Gas, fees, and balances are estimated via Alchemy to avoid provider-related failures.

Identity Verification Pipeline

Document uploads, liveness checks, and sanctions screening produce a layered verdict. Each credential is hashed and anchored on-chain, producing an immutable, independently verifiable record without storing raw PII on-chain.

Standards Compliance

Built to align with ISO/IEC 18013-5 (in-person mDL verification), ISO/IEC 18013-7 (online mDL verification), and W3C Verifiable Credentials for interoperability with government and commercial infrastructure.

Conclusion

USA ID APP's security model rests on three pillars: self-custody key management that keeps private keys on the user's device, a multi-chain architecture anchored on immutable public ledgers, and privacy-by-design credential exchange using selective disclosure and verifiable credentials. Together they deliver a platform where identity is portable, payments are self-sovereign, and trust is cryptographically provable—without a central point of failure.