Digital asset reference architectures on AWS

Explore financial messaging integration, settlement, tokenization, price feeds, proof of reserves, key management, and digital asset payments.

Reference patterns

Reusable architectures that explain the core building blocks of a digital asset workflow on AWS. Start here when designing a new solution.

Key management & custody

Use case

Secure private key custody and transaction signing, from single-key KMS accounts to MPC wallets in Nitro Enclaves.

How it works

  1. Generate or import private keys in a hardened environment (KMS, Nitro Enclaves, or MPC co-signer).
  2. Sign blockchain transactions without exposing key material.
  3. Restrict signing authority through KMS key policies or enclave attestation.

Bridging financial messaging systems to digital asset settlement

Use case

Connect off-chain financial instructions to blockchain-based settlement.

How it works

  1. Receive a financial message or settlement instruction.
  2. Normalize, sign, store, and orchestrate the instruction.
  3. Execute validated on-chain token movement or another settlement action.

AWS Chainlink Runtime Environment (CRE) Price Feeds & Proof of Reserves

Use case

Deliver price, reserve, or collateral data to smart contracts.

How it works

  1. Expose price, reserve, or collateral data through AWS services.
  2. Use Chainlink CRE to fetch the data and coordinate execution.
  3. Update smart contracts with feed, reserve, or collateral state.

Serverless Digital Asset Payments

Use case

Generate invoices, detect blockchain payments, and sweep confirmed funds to treasury.

How it works

  1. Create an invoice, payment request, or checkout event.
  2. Monitor blockchain activity and update the payment status.
  3. Confirm the payment and sweep the funds to treasury.

Example implementations

Concrete solutions that apply the reference patterns to specific digital asset use cases.

Builds on: Bridging financial messaging systems

Tokenized deposits

Use case

Issue and redeem tokenized commercial-bank deposits from off-chain instructions.

How it works

  1. Receive a deposit or redemption instruction from a bank system.
  2. Normalize, sign, store, and orchestrate the instruction.
  3. Mint or burn deposit tokens on a private Hyperledger Besu network to match the ledger.
Builds on: CRE Price Feeds & Proof of Reserves

Synthetic tokenized equity

Use case

Mint a token that tracks an S&P 500 ETF price as USDC-collateralized debt, without holding the underlying shares.

How it works

  1. Serve real-time ETF prices through a Lambda, DynamoDB, and API Gateway backend.
  2. Chainlink CRE reads that price plus on-chain collateral, computes the collateralization ratio, and writes price and health back on-chain through DON consensus.
  3. Deposit USDC to mint the token, burn to unlock, and liquidate undercollateralized positions.

Delivery versus Payment (DvP)

Use case

Settle tokenized securities atomically, so the asset and payment transfer together or not at all.

How it works

  1. Escrow both legs of a trade—tokens and stablecoin—using a smart contract.
  2. Validate the KYC allowlist, manage timeouts, and log audit events.
  3. Execute an atomic swap or refund in a single transaction.

Agentic payments

Use case

Enable conversational AI agents to purchase goods, settle USDC micropayments, and process refunds autonomously.

How it works

  1. Authenticate the user and provision an embedded wallet with spending limits.
  2. Let the agent browse products, handle HTTP 402 responses, and initiate payment through the x402 protocol.
  3. Sign and settle USDC on-chain through the x402 facilitator.

Need blockchain node infrastructure? AWS Node Runners