Mining node for appending block record to blockchain, computer program product and method of operation thereof

By introducing a commitment database into the blockchain system, the mining node publishes the metadata commitment value and verification data to the database, solving the problem that proof of work in the existing technology cannot provide independent verifiable evidence, and achieving decentralization and security improvement of the blockchain system.

CN120226303APending Publication Date: 2025-06-27VIOVIA GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380078660.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-09-20
Filing Date
2023-09-18
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the existing blockchain implementation mode, the data output provided by the mining node is sensitive and should be kept private, resulting in the proof of work that cannot provide preliminary evidence and independently verifiable evidence, which in turn makes the blockchain system rely on authoritative servers, damaging the decentralized characteristics.

Method used

By mining nodes publish metadata commitment values ​​and verification data to the commitment database, providing external verifiable proof of work, ensuring immutability and independence of computing work, and avoiding dependence on authoritative servers.

Benefits of technology

It realizes external verifiability between mining nodes, prevents collusion, and does not need to reveal private data output, enhancing the decentralized characteristics and security of the blockchain system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120226303A_ABST
    Figure CN120226303A_ABST
Patent Text Reader

Abstract

The present application discloses a mining node in a mining network, a committed database server, a data proxy server, methods of operation thereof, and a computer program product for establishing an externally verifiable proof of work as immutable evidence of computing work completed by the mining node to generate a private data output, the proof of work is used to attach the block record to the blockchain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to mining nodes and their computer program products and operating methods for establishing externally verifiable proof-of-work to append block records to a blockchain. Background Art

[0002] A blockchain, sometimes referred to as a distributed ledger or a distributed consensus ledger, is a distributed database. The blockchain enables tamper-proof and decentralized storage of data. Copies of the ledger / blockchain can be stored on each of multiple nodes in a blockchain network.

[0003] The blockchain includes multiple block records, also referred to as blocks or data structure blocks. The block records of the blockchain typically include payload data (i.e., data recorded in the block record for storage in the blockchain), a unique identifier of the previous block record of the blockchain, and a proof-of-work (POW). When a block record is added to the blockchain, a copy of the new block / blockchain is distributed to other nodes in the blockchain network, which can verify the work done to append the new block and accept the update to the blockchain, or can ignore the new block if the associated work cannot be verified.

[0004] The block records typically include payload data in the form of data and / or computer-executable instructions. In this way, for example, if a blockchain is used to record instructions such as transactions, a complete history of the transactions can be established on the ledger. Each transaction is a data structure that encodes the transfer of control of a digital asset from one party to another in the blockchain system. For example, if a blockchain is used to record computer-executable instructions (commonly referred to as "smart contracts" - i.e., computerized protocols that execute the terms of a machine-readable contract or agreement), function calls to the computer-executable instructions can be used to initiate computer-executable processes. Smart contracts can process inputs in order to produce results, which can then cause actions to be executed based on those results.

[0005] Each block record typically contains a link to the previous block record, for example, a hash value of the information in the previous block record or a hash value of the header of the previous block record. The hash value is typically determined by using the information of the previous block as part of the input to the hash function that outputs the hash value. Each block record links back to the previous block record. In this way, once verified, the block record will be linked to the previous block record, and through the previous block record, linked to each earlier block record, and then back to the origin block record-the only block record that does not contain a link to the previous block record. Although hash values ​​are typically easy to calculate, there may be one or more validity requirements imposed on the hash value. In addition, hash values ​​are usually based on a special type of mathematical function that is irreversible, and therefore it is not easy to know which input will give the desired output without trying a large number of inputs.

[0006] Each block record typically also includes a proof of work (POW). A POW is a piece of data that is difficult to generate, but easy for others (i.e., other users or other computing devices) to verify, and that satisfies certain validity requirements. Thus, each block record provides trustworthy and reliable evidence that work was done to generate it. The work may be, for example, the expenditure of a large amount of processing resources, such as the time it takes to compute some output.

[0007] The integrity of the payload data stored in the blockchain is guaranteed because each block record is linked to the previous block record, and because in order to tamper with the payload data in a block record of the blockchain, the tampering party would have to do additional work to store the tampered block and each subsequent block on the blockchain, which is not feasible when the majority of the nodes of the blockchain network are each checking the validity of the blockchain and adding their own block records.

[0008] In some blockchain implementations, such as the popular "Bitcoin", each block includes a header with a hash value for the previous block. In order to create a new block, a miner must find a random value that, when included as part of the input to the hash function, results in a hash value that meets certain validity requirements, particularly a hash value that is below a predetermined threshold. The miner typically guesses a random value and then checks that when the guessed random value is combined with other fixed data including the hash value of the previous block and input into the hash function, the hash function outputs a hash value below the predetermined threshold. In this way, the miner does work while consuming computing resources to find a suitable random value that meets the validity requirements. Once found, a second miner can check that a particular block is valid by inputting the same information including the declared random value into the hash function and checking that the output is valid. Therefore, in such blockchain implementations, the declared random number is used as proof of work for the relevant block.

[0009] Recently, an alternative blockchain implementation has been proposed, such as in International Patent Application Publication No. WO2020 / 120933A1, where the proof-of-work is provided by mining nodes performing "useful" computational work rather than solving mathematical puzzles that have no practical use or value beyond creating the proof-of-work. In WO2020 / 120933A1, an authority server provides data packets for processing to mining nodes in a mining network. Each of the data packets includes a plurality of data sets. Each of the data sets includes signal information. Upon receiving a data packet, a mining node can analyze the data packet to convert the signal information of each data set into a corresponding data output by performing computational work. The mining node then transmits the plurality of data outputs to the authority server, and the plurality of data outputs are used to establish a proof-of-work for attaching a block record to the blockchain. In particular, upon receiving the data output from the mining node, the authority server can generate a signed encrypted datum (such as a "cryptotoken"), which is provided to the mining node. The signed cryptotoken can then be used by the mining node as a proof-of-work, by which the mining node can create a block record that can be successfully attached to the blockchain and transmitted throughout the mining network for replication. The signed token can be intrinsically linked to the specific work performed by the mining node, for example, by including a signed hash of the analyzed data packet. The authority server can send the same data packet to multiple different mining nodes for independent processing, where the data outputs generated by each mining node are differently encoded using different alternative ciphers, and the keys are determined by the content of the data packet and the miner's ID. Thus, the mining nodes will generate different ciphers, preventing them from directly colluding to submit false results.

[0010] The authority server can decode the results received from the mining nodes and can check that the data outputs provided by (at least a threshold number of) other mining nodes corroborate each other before signing the encrypted token for the mining node.

[0011] It is in this context that the present invention has been designed. Summary of the Invention

[0012] The proof-of-work for attaching a block record to the blockchain should ideally be testable by any observer to verify that the work has actually been performed and the requirements for attaching the block record to the blockchain have been met. For example, in the "Bitcoin" implementation, any mining node can test a declared random number value that provides the proof-of-work by using a hash function to determine whether it produces an output value below a necessary level. Thus, the proof-of-work is prima facie evidence and independently verifiable evidence that the required work has been successfully completed.

[0013] However, in the blockchain implementation described in WO2020 / 120933A1, especially where the data output provided by mining nodes is sensitive and should be kept private (at least when creating block records), such as gene sequencing data, the proof of work itself does not provide prima facie evidence and independently verifiable evidence that the participating mining nodes have successfully completed the computational work in such a way that their data outputs corroborate each other. Instead, in this implementation, the mining nodes have to trust the verification of the data output from the mining nodes by the authoritative server when creating the proof of work. That is to say, if the mining nodes cannot verify for themselves that their data outputs corroborate each other, they have no choice but to trust the verification by the authoritative server when generating the proof of work. In this sense, without any external verification of the proof of work, the blockchain implementation is closer to an authoritative proof system, where the consensus mechanism relies on one or more trusted nodes (i.e., the authoritative server) in the blockchain network. However, this may be regarded as undermining the premise of the blockchain system, in which successfully completing the computational work performed by the mining nodes requires it to directly and indisputably result in the effective addition of block records to the blockchain without having to trust any specific node in the blockchain network to provide the verification required to add block records to the blockchain.

[0014] The systems and methods described herein can be applied to a wide range of practical applications. Among many practical applications, blockchain facilitates information sharing and asset management in the overall decentralization. The cost burden associated with decentralization may be reduced. The systems and methods disclosed herein can improve the current blockchain technology protocol by establishing an externally verifiable proof of work completed by mining nodes to generate private data outputs. This serves as immutable evidence of the computational work, where the proof of work is used when appending block records to the blockchain. To provide an externally verifiable proof of work for each block record, the mining nodes can be configured to publish metadata commitment values and verification data to a commitment database. Through cross-verification, the entries in the commitment database can be used to check that other mining nodes have processed the same data packet and obtained the same private data output. This evidence allows the mining nodes to demonstrate that they have successfully completed the analysis work on the data packet without colluding with other mining nodes, and without having to reveal the private data output or having to trust a data proxy server to verify the work.

[0015] Accordingly, in one aspect, the present disclosure provides a method performed in a mining node in a mining network for establishing an externally verifiable proof-of-work as immutable evidence of computational work done by the mining node to generate a private data output, the proof-of-work being for appending a block record to a blockchain, the method comprising: receiving, from a data proxy server, a data packet comprising signal information to be kept private by the mining node; analyzing the data packet through computational work to convert the signal information into a corresponding private data output that is also to be kept private by the mining node; as a result of the analysis, generating metadata characteristics of the analysis of the corresponding signal information, the metadata being independent of the private data output generated through the analysis; using a cryptographic commitment scheme to generate a metadata commitment value for the data packet analyzed by the mining node from a combination of the metadata and verification data; and transmitting the metadata commitment value and the verification data to a commitment database server that allows external access to the metadata commitment value to provide an externally verifiable proof-of-work.

[0016] In another aspect, the present disclosure provides a mining node for establishing an externally verifiable proof-of-work as immutable evidence of computational work done by the mining node to generate a private data output, the proof-of-work being for appending a block record to a blockchain, the mining node comprising: a processor; and a memory storing instructions that, when executed by the processor, configure the mining node to: receive, from a data proxy server, a data packet comprising signal information to be kept private by the mining node; analyze the data packet through computational work to convert the signal information into a corresponding private data output that is also to be kept private by the mining node; as a result of the analysis, generate metadata characteristics of the analysis of the corresponding signal information, the metadata being independent of the private data output generated through the analysis; use a cryptographic commitment scheme to generate a metadata commitment value for the data packet analyzed by the mining node from a combination of the metadata and verification data; and transmit the metadata commitment value and the verification data to a commitment database server that allows external access to the metadata commitment value to provide an externally verifiable proof-of-work.

[0017] From another aspect, the present disclosure provides a computer program product, optionally embodied in a non-transitory computer-readable storage medium, the computer program product including instructions that, when executed by a computer, cause the computer to: receive, from a data proxy server, a data packet including signal information to be kept private by a mining node; analyze the data packet through computational work to convert the signal information into a corresponding private data output also to be kept private by the mining node; as a result of the analysis, generate metadata features of the analysis of the corresponding signal information, the metadata being independent of the private data output generated through the analysis; use a cryptographic commitment scheme to generate a metadata commitment value of the data packet analyzed by the mining node from a combination of the metadata and verification data; and transmit the metadata commitment value and the verification data to a commitment database server that allows external access to the metadata commitment value to provide an externally verifiable proof of work.

[0018] In an embodiment, the method may further include: using a second metadata commitment value received from the commitment database server (the second metadata commitment value being generated by a second mining node through analyzing the same data packet) to verify that: the second mining node has generated matching metadata as a result of the analysis performed by the second mining node; and based on the verification, transmit the metadata for the data packet to the commitment database server that allows external access to the metadata for persistent storage therein.

[0019] In an embodiment, the verification may further include: after the second mining node has completed the analysis of the same data packet, receiving from the commitment database server the second metadata commitment value for the data packet generated by the second mining node and transmitted to the commitment database server and second verification data; using a cryptographic commitment scheme to generate a recreated second metadata commitment value for the data packet from a combination of the metadata for the data packet generated by the mining node and the received second verification data; comparing the recreated second metadata commitment value and the received second metadata commitment value generated by the second mining node; and if the comparison indicates that the recreated second metadata commitment value matches the received second metadata commitment value, verifying that the second mining node has successfully performed the same analysis of the data packet to generate the same metadata and the same private data output.

[0020] In an embodiment, the method may further include: if the second metadata commitment value is verified, transmitting only the metadata for the data packet to the commitment database server.

[0021] In this way, by reference to other metadata commitment values in an externally accessible commitment database, a mining node can check and verify whether other mining nodes in the mining network have analyzed the same data packet and produced the same metadata through their analysis. This is achieved by the mining node in the following manner: it accesses the metadata commitment values published to the commitment database by other mining nodes, and uses a cryptographic commitment scheme to attempt to recreate the metadata commitment value using the metadata generated by the mining node in its own analysis and the verification data published to the commitment database together with the metadata commitment value. If the recreated metadata commitment value is the same as the metadata commitment value published to the commitment server by another mining node, the mining node will be able to prove that it has successfully completed the analysis and that this is consistent with another mining node (with which it cannot collude). When the minimum verification requirements are met, the mining node can then request the issuance of an encryption token, for example from a data proxy server, and the metadata commitment value entry is published in the commitment database as an externally verifiable proof of work without revealing the private data output. In particular, if after the mining node has verified the second metadata commitment value from a second mining node, the mining node publishes the metadata it has generated to the commitment database, then any node with access to the commitment database can use the cryptographic commitment scheme to verify the work done by the mining node based on the combination of the published metadata and verification data and by comparing the recreated metadata commitment value with the published metadata commitment value. In this way, the commitment database entry of the mining node serves as an externally verifiable proof of work for the analysis of the data packet performed at the mining node without revealing the private data output. Thus, the commitment database can support the proof of work for this type of blockchain implementation without having to rely solely on the authority of the data proxy server. Additionally, through the commitment database, mining nodes can be induced to perform computational work to produce private data output in a way that prevents collusion between mining nodes while also allowing non-colluding mining nodes to cross-check their analysis and publish externally verifiable proof of work.

[0022] In an embodiment, at least one additional mining node may be sent the data packet for analysis, and the method may further include: using one or more additional metadata commitment values received from a commitment database server (the or each additional metadata commitment value having been generated by the corresponding at least one additional mining node) to verify that all of the at least one additional mining nodes have produced matching metadata as a result of their analysis; and based on that verification, if a minimum number of the received metadata commitment values are verified, only transmitting the metadata for the data packet to the commitment database server. In this way, the same data packet can be analyzed by two or more, or at least three, mining nodes, and the analysis result of each mining node is externally verifiable.

[0023] In an embodiment, external access to the or each metadata commitment value and the or each corresponding verification data for each metadata commitment value, and subsequently revealed metadata, from the commitment database server may allow proof-of-work to be performed by verifying that each metadata commitment value generated by each mining node is generated using a cryptographic commitment scheme from a combination of their corresponding verification data and matching metadata generated by analysis performed at each mining node.

[0024] In an embodiment, proof-of-work may be verified without reference to private data outputs.

[0025] In an embodiment, the method may further include transmitting a private data output for a data packet to a data proxy server.

[0026] In an embodiment, the method may further include: using a reference to at least the metadata commitment value stored at the commitment database server as proof-of-work to create a block record for a blockchain; and transmitting the created block record to at least another mining node of the mining network. In this way, the metadata commitment value may serve as proof-of-work.

[0027] In an embodiment, creating a block record for a blockchain may include: querying a version of the blockchain stored in one or more machine-readable storage media to extract a unique identifier of the previous block of the blockchain; and retrieving payload data from a data pool of unprocessed payload data.

[0028] In an embodiment, the verification data may include one or more of the following: a mining node identifier of a mining node for performing analysis of a data packet; a data packet identifier for the data packet assigned by the data proxy server; a cryptographic nonce. In this way, the metadata commitment value for the same metadata output for the same data packet may be different for each mining node. The data packet identifier assigned by the data proxy server for the same data packet may be different for each mining node assigned to analyze the data packet. This may prevent collusion between mining nodes as they cannot identify other mining nodes processing the same data packet. A mining node may view the commitment database and attempt to verify the metadata commitment value posted thereon by cross-checking the metadata generated by the mining node in a data packet that has not yet been verified, in an attempt to find the same metadata generated by other mining nodes that may have analyzed the same data packet and generated the same metadata.

[0029] In an embodiment, using a cryptographic commitment scheme may include: generating a hash of a combination of metadata and verification data generated by a mining node using a cryptographic hash function. A suitable cryptographic hash function has the properties required to provide a suitable cryptographic commitment scheme.

[0030] In an embodiment, a data packet may include at least one data entity, wherein the data entity or each data entity includes signal information, and the signal information of the data entity or each data entity is analyzed to convert it into a corresponding private data output, and the metadata commitment value is a hash of the combination of metadata and verification data for all data entities in the data packet.

[0031] In an embodiment, the signal information may represent a polynucleotide or polypeptide sequence; and converting the signal information into a corresponding private data output may include converting the signal information into corresponding readings, and each reading in the plurality of readings describes the corresponding polynucleotide or polypeptide sequence.

[0032] In an embodiment, the polynucleotide sequence may include a deoxyribonucleic acid (DNA) sequence or a ribonucleic acid (RNA) sequence. In an embodiment, the signal information may include raw data generated by a nanopore sequencer. In an embodiment, the signal information may include current information corresponding to the current flowing through the nanopore and a polynucleotide or polypeptide translocating through the nanopore. In this way, the method can provide a mechanism for a mining node to analyze the signal information output from a genetic sequencer to generate readings of polynucleotide or polypeptide sequences, and the computational work required to generate the polynucleotide or polypeptide sequences, so that it can be externally verifiable, and thus a proof of work can be generated and used to append a block record to a blockchain.

[0033] In an embodiment, the data packet received from the data proxy server and assigned to the mining node for analysis may be randomly selected from a plurality of data packets stored at the data proxy server for analysis.

[0034] In an embodiment, the data packet received from the data proxy server may specify one or more computer program products or algorithms to be used by the mining node in analyzing the data packet.

[0035] In an embodiment, the analysis of the data packet by the mining node or each mining node outputs the same metadata for the same private data output generated by the analysis, and the metadata and the private data output do not contain mutual information. In an embodiment, the metadata is deterministically generated as a byproduct of the analysis of the data packet to convert the signal information into a private data output. In an embodiment, the metadata and the metadata commitment value can be used as evidence indicating the private data output of the analysis of the data packet by the mining node.

[0036] In an embodiment, the analysis of the data packet by the mining node may include: using a pre-trained neural network to convert signal information into a private data output. In an embodiment, the metadata is based on a score generated by the neural network, where the score represents the probability of correctness of the private data output and / or the quality of the input signal information.

[0037] In an embodiment, the blockchain is permissionless, allowing any computing device to operate as a mining node.

[0038] In an embodiment, the metadata, verification data, and metadata commitment value for any data packet can be accessed by any mining node in the commitment database server. The commitment database in the commitment database server may be publicly accessible. In this way, any computing node capable of processing signal data can act as a mining node in the mining network.

[0039] In an embodiment, the method may further include: receiving, from another mining node of the blockchain network, a block record for addition to the blockchain; extracting, from the received block record, a reference to a second metadata commitment value stored at the commitment database server; using the second metadata commitment value stored at the commitment database server to verify the proof of work for the second mining node; and based on the verification, updating the blockchain to include the received block record. In this way, at each mining node, an entry in the commitment database can be referenced to verify the proof of work in the received block record for attachment to the blockchain, without relying on the trust of a data proxy server to act as an authoritative server. In an embodiment, verifying the proof of work for the second mining node may include: receiving, from the commitment database server, the second metadata commitment value, the second verification data, and the subsequently revealed second metadata; hashing the received second metadata and the second mining node identifier to generate a recreated second metadata commitment value; comparing the recreated second metadata commitment value and the received second metadata commitment value; and if the comparison indicates that the recreated second metadata commitment value matches the received second metadata commitment value, verifying the proof of work for the received block record.

[0040] In another aspect, the present disclosure provides a commitment database server, a method, and a computer program product for implementing the method in the commitment database server and for use in combination with a plurality of mining nodes as described herein. The method in the commitment database server includes: receiving a first metadata commitment value and first verification data from a first mining node; receiving a second metadata commitment value and second verification data from a second mining node; the first metadata commitment value and the second metadata commitment value are generated by the first mining node and the second mining node using a cryptographic commitment scheme from: the metadata characteristics of the analysis of the data packet provided by the data proxy server by the corresponding mining node through computational work and the combination of the corresponding verification data, where the data packet includes signal information to be kept private by the mining node, and the analysis converts the signal information into a corresponding private data output and generates the metadata characteristics of the analysis of the corresponding signal information; the method further includes: storing the first metadata commitment value and the second metadata commitment value, and the first verification data and the second verification data together with a timestamp for their reception time at the commitment database server in an externally accessible, tamper-proof, and immutable commitment database; providing the second metadata commitment value and the second verification data to the first mining node for the first mining node to verify; and if the first mining node verifies that the second mining node has analyzed the same data packet as the first mining node, receiving from the first mining node the metadata characteristics of the analysis of the data packet by the first mining node; storing the metadata together with a timestamp for the reception time at the commitment database server in the commitment database.

[0041] In this way, the commitment database retains a tamper-proof and timestamped record of the metadata commitment values and verification data, allowing external verification of the computational work done by the mining nodes to generate private data outputs without revealing the private data outputs. Successfully verified entries include metadata that provides an externally verifiable proof of work for appending block records to the blockchain.

[0042] From another aspect, the present disclosure provides a data proxy server, a method, and a computer program product for implementing the method in the data proxy server and for use in combination with a commitment database server and a plurality of mining nodes as described herein. The method in the data proxy server includes: receiving signal information to be kept private; storing the signal information as one or more data packets in a data packet storage device; receiving requests for data packets from a first mining node and requests for data packets from a second mining node; randomly selecting a data packet to be processed from the data packet storage device; sending the selected data packet to the first mining node using a first data packet identifier and sending the selected data packet to the second first mining node using a second data packet identifier different from the first data packet identifier; receiving a first private data output from the first mining node that has analyzed the data packet and receiving a second private data output from the second mining node that has analyzed the data packet; accessing a commitment database in the commitment database server and cross-checking whether the database entries for the first data packet identifier and the second data packet identifier are valid. Once the miners have all verified the values in the commitment database, then each miner can release a metadata string into the database so that the process can be externally verified.

[0043] In this way, the data proxy server can provide randomly selected data packets to the mining nodes in the mining network for processing, and if the metadata commitment values posted to the commitment database cross-verify the computational work performed by the mining nodes, it can provide a signed encryption token for adding a block record to the blockchain, thereby enabling the entries in the commitment database to provide externally verifiable proof of work.

[0044] From the foregoing disclosure and the following detailed description of the examples, it will be understood that certain optional features and embodiments described as related to any given aspect of the above disclosure should be understood by the reader to be disclosed in combination with other aspects of the present disclosure where applicable. Similarly, it will be understood that any accompanying advantages described in relation to any given aspect of the present disclosure set forth above should be understood by the reader to be disclosed as advantages of other aspects of the present disclosure where applicable. That is, the description of optional features and advantages with respect to a particular aspect disclosed above is not restrictive, and it should be understood that the disclosure of these optional features and advantages is intended to be combined with all aspects related to the present disclosure, provided that such combination is applicable. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Certain embodiments of the present invention will now be described by way of example only with reference to the accompanying drawings, in which:

[0046] Figure 1Shows an example system of a networking device according to aspects of the present disclosure for providing data packets derived from a genetic sequencer to mining nodes of a mining network for analysis and providing an externally verifiable proof-of-work that can be used to append a block record to a blockchain without releasing private data outputs of the analysis;

[0047] Figure 2 Shows a graph that plots over time Figure 1 signal information in the form of current data output by the genetic sequencer shown in, where the signal information is provided to a mining node for analysis by a data proxy server; and an example sequence of values generated by the mining node from the analyzed signal information, where the sequence of values represents a private data output;

[0048] Figure 3 Shows for use as Figure 1 a block diagram of an embodiment of a computing device for the mining node shown in;

[0049] Figure 4 Shows by Figure 3 an embodiment of a method implemented by the example mining node shown in, the method for establishing an externally verifiable proof-of-work as immutable evidence of computational work done by the mining node to generate a private data output, where the proof-of-work is used to append a block record to a blockchain;

[0050] Figure 5 Shows for use as Figure 1 a block diagram of an embodiment of a computing device for the commitment database server shown in;

[0051] Figure 6 Shows for use by Figure 5 the example commitment database server shown in in combination with Figure 3 multiple example mining nodes shown in an embodiment of a method implemented;

[0052] Figure 7 Shows for use as Figure 1 a block diagram of an embodiment of a computing device for the data proxy server shown in;

[0053] Figure 8 Shows for use by Figure 7 the example data proxy server shown in in combination with Figure 5 the example commitment database server shown in and Figure 3 multiple example mining nodes shown in an embodiment of a method implemented. Detailed Description

[0054] In the following, embodiments of the present disclosure are described with reference to the accompanying drawings. However, it should be understood that the present disclosure is not limited to the embodiments, and all changes and / or equivalents or substitutions thereof also fall within the scope of the present disclosure. The same or similar reference numerals may be used throughout the specification and the drawings to refer to the same or similar elements.

[0055] As used herein, the terms "having", "may have", "including", or "may include" a feature (e.g., a number, a function, an operation, or a component such as a part) indicate the presence of the feature and do not exclude the presence of other features. Throughout the description and claims of this specification, the words "comprise" and "comprising" and their variants mean "including but not limited to", and they are not intended to (nor do they) exclude other components, integers, or steps. Throughout the description and claims of this specification, the singular encompasses the plural unless the context otherwise requires. In particular, in the case of using an indefinite article, this specification should be understood to contemplate both plurality and singularity unless the context otherwise requires.

[0056] As used herein, the terms "A or B", "at least one of A and / or B", or "one or more of A and / or B" may include all possible combinations of A and B. For example, "A or B", "at least one of A and B", "at least one of A or B" may indicate all of the following: (1) including at least one A, (2) including at least one B, or (3) including at least one A and at least one B.

[0057] As used herein, the terms "first" and "second" may modify various components regardless of their importance and do not limit the components. These terms are only used to distinguish one component from another. For example, the reference to a first component and a second component may indicate components different from each other regardless of the order or importance of the components.

[0058] It will be understood that when an element (e.g., a first element) is referred to as being "(physically, operatively, or communicatively) coupled / coupled to another element" or "connected / connected to another element" (e.g., a second element), it may be directly or via a third element coupled / coupled to another element or connected / connected to another element. Conversely, it should be understood that when an element (e.g., a first element) is referred to as "directly coupled / directly coupled to another element" or "directly connected / directly connected to another element" (e.g., a second element), no other element (e.g., a third element) intervenes between the element and the other element.

[0059] The terms used herein are provided merely to describe certain embodiments thereof and are not intended to limit the scope of other embodiments of the present disclosure. It should be understood that the singular forms "a", "an", and "the" include plural references unless the context clearly dictates otherwise. All terms, including technical and scientific terms used herein, have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments of the present disclosure belong. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0060] Figure 1 An example system 100 of a networking device according to aspects of the present disclosure is shown for providing data packets derived from a genetic sequencer to mining nodes of a mining network for analysis and for providing an externally verifiable proof of work that can be used to append a block record to a blockchain without releasing private data outputs of the analysis.

[0061] System 100 includes a genetic sequencer 102 for extracting genetic signal information from a sample tube 106 containing a polynucleotide chain from a biological organism 104 (in this case a human subject). That is, the sample tube 106 can contain a sample of DNA or RNA of the biological organism 104 that is appropriately prepared for sequencing by the genetic sequencer 102.

[0062] The genetic sequencer 102 provides output data including the genetic signal information contained in the sample tube 106 to a computing device that is configured as a genetic sequencer user node 110. The genetic sequencer user node 110 reads the genetic signal information from the genetic sequencer 102 and transmits it via the Internet 112 to a data proxy server 114, which arranges the genetic signal information in one or more data packets that are then randomly distributed to a plurality of mining nodes 116a, 116b, 116c... 116n (only mining nodes 116a - 116c are illustrated) for analysis to extract a polynucleotide sequence from the genetic signal information through computational work.

[0063] For the purposes of the present disclosure, the genetic sequencer 102 and the genetic sequencer user node 110 are provided merely to facilitate understanding of the operation of system 100. The data proxy server 114 can include storage of data packets of genetic signal information obtained from any suitable source processed by the mining network 120. There is no requirement for a direct connection to the genetic sequencer or the genetic sequencer user node 110.

[0064] In an embodiment, the illustrated example genetic sequencer 102 represents a third-generation nanopore sequencer, such as those available from Oxford Nanopore Technologies (https: / / nanoporetech.com / ). However, the genetic signal information used in system 100 can come from any suitable source and is not limited to such sequencing technology, and genetic signal information provided by second-generation sequencers can be used, or any other suitable signal information that needs to be analyzed or processed through computational efforts, which is suitable for processing by mining nodes 116a - 116c in mining network 120, where proof-of-work can be used to append block records to the blockchain.

[0065] In Figure 1 the example of, genetic sequencer 102 includes a transmembrane pore 108 (e.g., nanopore), which is used as an electro-biosensor to sense genetic signal information in the form of a polynucleotide sequence in a DNA or RNA strand from a biological sample contained in sample tube 106. Such a transmembrane pore 108 can be used to identify small molecules or folded proteins and to monitor chemical or enzymatic reactions at an approximately single-molecule level by, for example, sending an ion current through transmembrane pore 108 as a DNA / RNA strand passes through the pore. When an analyte translocates through the nanopore, the interaction of the analyte with transmembrane pore 108 can cause characteristic changes in the ion current (e.g., characteristic current distribution). That is, the ion current (e.g., electron current / current) through transmembrane pore 108 can be measured under a potential difference applied across transmembrane pore 108.

[0066] Figure 2 A graph showing an example of genetic signal information 200 varying over time by genetic sequencer 102 is shown. It can be seen that the graph shows genetic information 200 in the form of an ion current / current signal information, which is characteristic of the analyte passing through transmembrane pore 108.

[0067] For example, when a polynucleotide strand such as DNA passes through transmembrane pore 108, the nucleobases of the DNA passing through transmembrane pore 108 (i.e., adenine (A), cytosine (C), guanine (G), and thymine (T)) produce a resulting characteristic current distribution depending on which combination of 4 - 5 nucleobases, as part of the DNA strand, passes through the sequencer at any given moment. As can be seen in Figure 2as seen in the genetic signal information 200, which generates an electrical current signal that drops to different levels that vary as each base exits the pore and a new base enters at the top. The interpretation of the current variations can be decoded to infer the sequence of the nucleobases on the DNA strand through a process of "base calling". The result of the base calling gives a prediction of the called bases 204 for different segments of the raw data, as shown overlaid above the detail 202 of a portion of the genetic signal information 200 shown in the bottom pane of Figure 2 as shown in the bottom pane of

[0068] It can be seen that the genetic signal information 200 generated by a genetic sequencer (nanopore sequencer or other) is typically very noisy due to, for example, electrical and environmental interference. In addition, the signal as measured by the current passing through the pore reflects the presence of 4 - 5 nucleotides in the pore, which are part of the DNA strand. Thus, the task of base calling for determining the polynucleotide sequence (i.e., determining the "read") from the genetic signal information 200 is a computationally intensive task that typically requires the processing of the genetic signal information 200 through an artificial neural network. Thus, to determine the nucleobases in the original genetic signal information 200, it is necessary to process it through base calling using a process that is typically computationally intensive, such as a deep neural network, to provide a prediction of the nucleobases that generated the original genetic signal information 200.

[0069] To facilitate accurate sequencing of this genetic signal information 200, a mining network 120 of multiple mining nodes 116a - 116n is used to provide distributed computing power to perform base calling analysis on the genetic signal information 200.

[0070] That is, this or each genetic sequencer user node 110 can send its unprocessed genetic signal information 200 via the Internet 112 to a data proxy server 114, which is configured to assemble the genetic signal information 200 into multiple data packets and distribute them among the multiple mining nodes 116a - 116n of the mining network 120 via the Internet 112 for processing. Each mining node can, upon receiving a data packet, use an appropriate base calling software (such as a pre - trained artificial neural network) to analyze the genetic signal information 200 contained in the data packet and generate the sequence of nucleobases in the read as a private data output, which is genetic information that is not to be publicly shared and is to be kept confidential due to reasons of confidentiality. The private data output is then sent by the mining node back to the data proxy server 114, which can then assemble and store or relay this genetic sequence information, for the benefit of the genetic sequencer user node 110, for example.

[0071] As a record of the successful completion of base determination work by the mining nodes, the blockchain can be maintained by the mining network 120, and block records are added when the mining nodes complete the analysis of the data packets received from the data proxy server 114 to meet the verification requirements.

[0072] To provide an externally verifiable proof of work for each block record, the mining nodes 116a - 116n are configured to publish metadata commitment values and verification data to the commitment database in the commitment database server 118. Through cross - verification, the entries in the commitment database can be used to check whether other mining nodes have processed the same data packets and obtained the same private data output. This evidence allows the mining nodes to prove that they have successfully completed the analysis work on the data packets without colluding with other mining nodes and without the need to reveal the private data output or trust the data proxy server to verify the work.

[0073] Now will refer to Figures 3 to 8 The configurations and operations of the mining nodes 116a - 116c, the commitment database server 118, and the data proxy server 114 for implementing the example system 100 will be described in more detail.

[0074] Now will refer to Figure 3 and Figure 4 to describe how, in response to the receipt of data packets, the mining nodes 116a - 116n generate private data outputs, metadata, and publish metadata commitment values to the commitment database for use as an externally verifiable proof of work when adding block records to the blockchain.

[0075] Figure 3 Shows a block diagram of an embodiment of a computing device for use as the Figure 1 mining node shown. Although Figure 3 refers to the mining node 116a, this is for illustration and by way of example only, and should be understood to explain the configuration and operation of any mining node 116a - 116n of the mining network 120.

[0076] The mining node 116a includes a memory 302, one or more processors 304, and an input / output module 308. A bus system (not shown) can be provided that supports communication between at least one of the processor 304, the memory 302, and the input / output module 308.

[0077] The processor 304 executes instructions that can be loaded into the memory 302. The processor 304 can include any suitable number and type of processors or any other device in a suitable arrangement. Example types of processors include microprocessors, microcontrollers, digital signal processors, field - programmable gate arrays, and application - specific integrated circuits.

[0078] Memory 302 can be provided by any structure capable of storing and facilitating the retrieval of information such as data, program code, and / or other suitable information on a temporary or permanent basis. Memory 302 can represent random access memory or any other suitable volatile or non-volatile storage device. Memory 302 can also include one or more components or devices that support longer-term storage of data, such as read-only memory, hard disk drives, flash memory, or optical discs, which can store software code for loading into Memory 302 at runtime. In use, Processor 304 and Memory 302 provide a runtime environment 306 in which instructions or code loaded into Memory 302 can be executed by Processor 304 to generate instances of software modules in the runtime environment 306.

[0079] Mining Node 116a also includes an Input / Output Module 308 that provides a communication interface for receiving data from one or more Data Broker Servers 114 and a Commitment Database Server 118 via a network such as the Internet 112.

[0080] Although shown as a stand-alone computing device in Figure 1 Mining Node 116a can be configured as a networked server or a virtual machine implemented in a cloud computing service, either of which can be suitable for performing the genetic signal information analysis, proof-of-work, and block record appending methods described herein.

[0081] In an example, Memory 302 includes instructions for instantiating software module instances corresponding to a Sequence Data Processor 310, a Sequence Metadata Handler 312, a Sequence Data Handler 314, a Blockchain Management Module 316, and a Commitment Database Management Module 318. The functions and operations of these modules will now be described with reference to Figure 4 to describe the functions and operations of these modules.

[0082] Figure 4 Shown is an embodiment of a method 400 implemented by the example mining node shown in Figure 3 The method 400 is for establishing an externally verifiable proof-of-work as immutable evidence of the computational work done by the mining node to generate a private data output, where the proof-of-work is used to append a block record to a blockchain.

[0083] In method 400, at step 402, Mining Node 116a receives, via Input / Output Module 308, a data packet from Data Broker Server 114 that includes signal information to be kept private by Mining Node 116a. In an example embodiment, the data packet represents Figure 2Genetic signal information 200 of the type shown. The data packet can be passed to the sequence data processor 310, which can store the data packet in the memory 302 for analysis using appropriate analysis tools.

[0084] The data packet can include at least one data entity, where this or each data entity includes genetic signal information representing a polynucleotide sequence, in that it includes current information corresponding to the current flowing through the nanopore and the polynucleotide translocating through the nanopore. In other embodiments, the data packet can include any other form of signal information for processing by one or more mining nodes. For example, the signal information can represent a batch of images for analysis by an object recognition algorithm, images that need to be kept private, or batch documents that need to be processed by optical character recognition to convert them into a machine-readable format.

[0085] Returning to method 400, at step 404, the sequence data processor 310 analyzes the data packet by computational work to convert the signal information into a corresponding private data output that is also kept private by the mining nodes.

[0086] In this step, in the Figure 1 example shown, the genetic signal information 200 output by the genetic sequencer 102 can be analyzed by the sequence data processor 310 by performing an appropriate algorithm for base calling to determine the sequence of the nucleobases of the DNA / RNA molecules in the sample tube 108. Converting the genetic signal information 200 into a corresponding private data output can include converting the genetic signal information 200 into corresponding reads, where each read of the multiple reads for each data entity describes the corresponding polynucleotide sequence. The polynucleotide sequence can include a deoxyribonucleic acid (DNA) sequence or a ribonucleic acid (RNA) sequence. In an embodiment, the signal information can include raw data generated by a nanopore sequencer. Specifically, the sequence data processor 310 can use a pre-trained neural network to analyze the data packet to convert the signal information into a private data output. This base calling process generates the called bases that predict the nucleobases that have passed through the nanopore to generate the analyzed current signal in the genetic information. To illustrate this, in Figure 2Among them, the determined base 204 is output as private data output by the sequence data processor 310 and is displayed as overlaid on the details 202 of the genetic signal information 200. When applying the sequence data processor 310 to the data packet, a large amount of computational work is spent by the mining node 116a, especially because the data packet may contain many data entities, each corresponding to a current trace derived from a single DNA fragment passing through the transmembrane pore 108 according to the genetic sequencer 102. The data packet received from the data proxy server 114 can specify one or more computer program products or algorithms to be used by the mining node 116a when analyzing the data packet. If this is the case, the sequence data processor 310 uses the computer program product specifying the algorithm.

[0087] The operation of the sequence data processor 310 on each data entity can generate a reading of the DNA fragment being analyzed, which is a representation of the DNA sequence of the base-determined nucleobases (A, C, G, T) in a suitable data structure, such as the FASTQ format. An example of the private data for the data entity in the data packet output by the sequence data processor 310 is as follows:

[0088] @5d08ebdf-4b02-45bf-ac72-8e5716ca468d

[0089] runid=3b55a2b916b3c56c641a45f4898b156692a08534

[0090] sampleid=Strawb_leaf

[0091] read=1440

[0092] ch=2028

[0093] start_time=2018-08-30T15:49:09Z

[0094]

[0095] The base calling data for a single read shown above includes the packet identifier assigned randomly by the data proxy server to the data packet (in the example, this is "@5d08ebdf-4b02-45bf-ac72-8e5716ca468d") and the run identifier (in this example, "runid=3b55a2b916b3c56c641a45f4898b156692a08534") and further information about the sample, read size, start time, etc., to provide tracking data for the original read. The base-called read is then passed to the sequence data processor 314 and stored in the payload, which shows the nucleobase sequence, to be shared with the data proxy server 114. This data needs to be kept private as long as the genetic sequencer user node 110 does not consent to the data proxy server 114 sharing the genetic sequence information for the reads from the biological organism 104 with anyone other than the user. This nominally prevents any blockchain network entity other than the data proxy server 114 from being able to verify the private data output generated by the mining nodes for the data packet, for example by cross-checking the private data outputs generated by multiple mining nodes for the same data packet.

[0096] To allow external verification by entities other than the data proxy server 114, metadata for the reads of the data packet generated by the sequence data processor 310 is used, which does not need to be kept private.

[0097] That is, in step 406, as a result of the analysis, the sequence data processor 310 also generates metadata features of the analysis of the corresponding signal information, which is independent of the private data output generated by the analysis. The metadata can be based on a score generated by a neural network, which represents the probability of the correctness of the private data output and / or the quality of the input signal information. That is, when the base calling software determines which base is at each position in the DNA sequence, it assigns a quality score based on probability to that base, which can be used by downstream software. The quality score is calculated as q=-10log 10 (p), where p is the probability that the base call is incorrect. An example quality string generated by the sequence data processor 310 and stored together with the base calling data in the FASTQ data structure for the reads shown above is as follows:

[0098] )$$$%%$%'+*) / 3 / *+,5424-4.+,..-0+'0::1190.1 / 6)*-88- / / 0,1:;.37977944.781(-"&(#

[0099] ,$)(+-+().5-,('0,&.16:1'1;7.344..09<89734;<3 / 34:+)57+. / / -82$$(+%$&$&*.()(.9-8

[0100] ;:--111 / 0%&%$&&)*'((*'""$%$()'&)####%'*)16-+,5)'++48321"#$$%%$*)*$)&

[0101] &$&&+. / &17557020*-&%%$%*( / -$&'&9::*04 / ##"#"#*')*742-)* / ,&* / ”-1+-.-.0 / -

[0102] ***,)67:9:.,567:787*2.%$&&'+ / (+*,-36<+6499++',$$2:4613539,+*)(+*20-2)&*

[0103] *))6-0112:91.50 / %'(1:41 / 11054<8248596)7*+71+-.43222+:;)'*#+ / 1 / 1-; / 107:882;8

[0104] .0:58:64583*-*19:6,05804.4'(&(%(&'5-++*(+)-& / 3 / 0-%-2('+0.01-+,,,11.#$$$(-(,.

[0105] 50470.-*,(#%&$,.8187766<<8988<95692:9 / ),611272846('*,, / :4 / / 1694.:3*-4:001,.

[0106] )052.-%)&-, / 75343)-)'+$$"%( / ,:1, / 53*,)--:*++- / ,-.433('$#$&&,+243791,*8+460*)

[0107] + / 3-'*%((7167 / 8. / ,;<2, / 912222$*++040.110.'4842;3.092250: / 2.;6'.,(.)&*,*+%4(+'

[0108] (.-2 / ,-,1100297-799:323.000. / 1211()*.-02-.8 / <98. / ..9: / / ..- / 6 / %(-+'$+*+-2 / 0 / #%-' / .)

[0109] / -),-0+.)'%%$&**',-.+5+06-.(2('*+0("#$"%'),+ / 073)'$&(+,9866()-.00308 / 0715--.

[0110] &"&((”&'"&,)$#,-,2&&&%)0( / 7 / )”')%& / 1&+-"$#&,2 / 022703613-,+++ / 1$11&%

[0111] #%&-,24715*))+596896788864(++10310))1-56689772;0-,&%&#-*6 / 27'#

[0112] The quality metadata contains one character for each base in the DNA in the read, and the quality score can be calculated as the ordinal value of the character minus 33. This integer value is calculated by the base calling software as -10log 10 (p), where p is an estimate of the incorrect calling of the base. The quality score is a measure of the quality of the raw signal data and is not related in any way to the base called from the signal. Given this, for any version of the base calling software (and any version of the neural network model), these scores are deterministically calculated and any two mining nodes will produce the same sequence and the same quality data for a given input. This should be true regardless of the architecture on which the software runs (e.g.).

[0113] This quality data can be used for the analysis of sequence data, for example to provide a measure of reliability for each base of the sequence, especially when constructing a consensus sequence at the data proxy server during alignment. However, the quality string can also be used as metadata that allows for external verification by using a cryptographic commitment scheme and the commitment database server 118.

[0114] That is, for the same genetic sequence information, the analysis of the data packet by the mining node 116a outputs metadata of the same quality as the private data output generated by the analysis. The metadata and the private data output do not contain mutual information. The metadata is deterministically produced as a by-product of the analysis of the data packet to convert the signal information into the private data output. The metadata and the metadata commitment value can be used as evidence to indicate the private data output of the analysis of the data packet by the mining node. Since this quality data is independent of the DNA sequence but still requires the computational work of base calling to produce it, for example any other mining node can use it to publicly verify that two miners have run the base calling software on the data entity and have produced the same private data output without having to reveal the private data output, or verify that the miners must also decode the sequence in the data packet to confirm this.

[0115] To allow the mining nodes to verify that each mining node has received the same sequence of quality scores without sharing the quality scores (which would enable collusion), a cryptographic commitment scheme and a commitment database are used.

[0116] That is, in step 408, the sequence data processor 310 passes the metadata to the sequence metadata handler 312, which uses a cryptographic commitment scheme to generate a metadata commitment value for the data packet analyzed by the mining node from the combination of the metadata and the verification data. The verification data can include one or more of the following: the mining node identifier of the mining node used to perform the analysis of the data packet; the data packet identifier assigned by the data proxy server for the data packet; a cryptographic nonce. In this way, the metadata commitment value for the same metadata output for the same data packet can be different for each mining node. The data packet identifier assigned by the data proxy server for the same data packet can be different for each mining node assigned to analyze the data packet. This can prevent collusion between mining nodes because they cannot identify other mining nodes processing the same data packet.

[0117] Any suitable cryptographic commitment scheme can be used, which enables the mining node 116a to generate and first reveal only the 'commitment' (i.e., the metadata commitment value, different from the metadata itself) to some hidden value (i.e., the metadata itself), and then 'open' the commitment (by revealing the hidden value, i.e., the metadata). The cryptographic commitment scheme must enable the public (or at least any other mining node) to reuse the cryptographic commitment scheme to verify that the commitment value (i.e., the metadata commitment value) corresponds to the open ('correctness' property - i.e., the cryptographic commitment scheme generates the metadata commitment value from the metadata itself and any verification data used to generate the metadata commitment value). The cryptographic commitment scheme must also ensure that only given the commitment (i.e., the metadata commitment value), the open (i.e., the metadata used to generate it) remains hidden ('hiding' property, i.e., the metadata cannot be calculated from the metadata commitment value). Finally, the cryptographic commitment scheme must be a scheme that cannot open the commitment in multiple different ways (i.e., the 'binding' property that the metadata commitment value actually binds the committer to a hidden metadata value). The cryptographic commitment scheme can be a cryptographic hash function, such as SHA256 or SHAKE256, as these are particularly effective as cryptographic commitment schemes. However, any suitable cryptographic commitment scheme can be used.

[0118] In the case of using a cryptographic hash function, in step 408, the generated metadata commitment value can be a hash of the combination of the metadata for all data entities in the data packet and the verification data. This combination can be the concatenation of quality strings. The verification data used is such that for each mining node that analyzes the data packet and produces the same metadata output and the same private data output, the metadata commitment value is different. This is beneficial for external verification and prevents collusion.

[0119] To allow cross-checking between mining nodes and subsequent external verification that the mining nodes have successfully completed the computational work of generating valid private data outputs, in step 410, the sequence metadata handler 312 of mining node 116a transmits (via the input / output module 308) the metadata commitment value and the verification data to the commitment database server 118 via the Internet 112. The commitment database server 118 allows external access to the metadata commitment value for use in providing an externally verifiable proof of work.

[0120] The method may further include mining node 116a transmitting the private data output for the data packet to the data proxy server 114, which may verify, align, and assemble all the readings of the data set for all the genetic signal information of the biological organism 104 received from the genetic sequencer 102 (as generated by the mining network 120), and share them with the genetic sequencer user node 110.

[0121] Now will be combined Figure 5 and Figure 6 describe the operations of the commitment database server 118 and the mining nodes to allow external verification of the work done by mining on the data packet and subsequent use as a proof of work in the blockchain network.

[0122] Figure 5 A block diagram showing an embodiment of a computing device serving as the commitment database server 118 is shown. The commitment database server 118 includes a memory 502, one or more processors 504, and an input / output module 508. A bus system (not shown) may be provided that supports communication between at least one of the processor 504, the memory 502, and the input / output module 508.

[0123] The processor 504 executes instructions that can be loaded into the memory 502. The processor 504 may include any suitable number and type of processors or any other device in a suitable arrangement. Example types of processors include microprocessors, microcontrollers, digital signal processors, field programmable gate arrays, and application specific integrated circuits.

[0124] The memory 502 can be provided by any structure capable of storing and facilitating the retrieval of information such as data, program code, and / or other suitable information on a temporary or permanent basis. The memory 502 can represent random access memory or any other suitable volatile or non-volatile storage device. The memory 502 can also include one or more components or devices that support longer-term storage of data, such as read-only memory, hard disk drives, flash memory, or optical discs, which can store software code for loading into the memory 502 at runtime. In use, the processor 504 and the memory 502 provide a runtime environment 506 in which instructions or code loaded into the memory 502 can be executed by the processor 504 to generate instances of software modules in the runtime environment 506.

[0125] The commitment database server 118 also includes an input / output module 508 that provides a communication interface for receiving data from one or more data proxy servers 114 and mining nodes 116a - 116n via a network such as the Internet 112.

[0126] Although shown as a stand-alone computing device in Figure 5 , the commitment database server 118 can be configured as a networked server or a virtual machine implemented in a cloud computing service, either of which can be suitable for executing the methods described below in connection with Figure 6 description.

[0127] In an example, the memory 502 includes instructions for instantiating software modules corresponding to the commitment database request handler 510 and the commitment database 512. The functions and operations of these modules will now be described with reference to Figure 6 to describe.

[0128] Figure 6 Shows an example of a method implemented for use in conjunction with a plurality of example mining nodes as shown in Figure 5 and Figure 3 in an example commitment database server as shown in.

[0129] In step 602, the commitment database server 118 receives a first metadata commitment value and first verification data from a first mining node (e.g., mining node 116a) at the input / output module 508 via the Internet 112. This can be the output of step 410 performed by the mining node 116a, and the commitment database request handler 510 receives the first metadata commitment value and stores it in the commitment database 512 along with a timestamp.

[0130] In step 604, the commitment database server 118 receives a second metadata commitment value and second verification data from a second mining node (e.g., mining node 116b) at the input / output module 508 via the Internet 112. This can be the output of step 410 performed by the mining node 116b. The commitment database request handler 510 receives the second metadata commitment value and stores it in the commitment database 512 together with a timestamp.

[0131] Thus, in step 606, the commitment database server 118 stores the first metadata commitment value and the second metadata commitment value, as well as the first verification data and the second verification data, together with timestamps for the times at which they were received at the commitment database server, in an externally accessible, tamper-proof, and immutable commitment database 512. The commitment database 512 is maintained as an immutable and tamper-proof record of the data input into it and thus provides permanence and proof of the work completed and metadata commitment values generated and published by the mining nodes of the mining network 120. To achieve this, the commitment database 512 can maintain itself as a blockchain across multiple nodes of the blockchain network.

[0132] When generating the first metadata commitment value and the second metadata commitment value, the first mining node 116a and the second mining node 116b may (or may not) have successfully performed the same analysis on the same data packet. The metadata commitment values stored in the commitment database 512 allow cross-checking by the mining nodes to determine whether any other mining node has analyzed the same data packet and obtained the same result, thus allowing them to provide an externally verifiable proof of work for appending block records to the blockchain.

[0133] To this end, in step 608, the commitment database request handler 510 provides the second metadata commitment value and the second verification data to the first mining node 116a for verification by the first mining node 116a. This can be sent as a result of a request from the first mining node.

[0134] Now, the verification of the second metadata commitment value by the first mining node 116a during the process performed in the first mining node 116a will be described.

[0135] Once the second metadata commitment value and the second verification data are received from the commitment database server via the input / output module 308, the mining node 116a passes the second metadata commitment value and the second verification data to the sequence database handler 312 for verification: whether the second mining node has produced matching metadata as a result of the analysis performed on the (same or different) data packets. Verifying the second metadata commitment value by the first mining node 116a includes: using a cryptographic commitment scheme (each mining node is designated to use the same cryptographic commitment scheme) to generate a recreated second metadata commitment value for the data packet from the combination of the first metadata for the data packet generated by the mining node 116a and the received second verification data.

[0136] That is, the mining node 116a is testing whether it is possible to recreate the second metadata commitment value by hashing the metadata generated by itself through analyzing the data packet together with the second verification data received from the commitment database 512. Therefore, verification is performed by comparing the recreated second metadata commitment value by the mining node 116a with the second metadata commitment value generated by the second mining node received from the commitment database 512 together with the second verification data. If the comparison indicates that the recreated second metadata commitment value matches the received second metadata commitment value, the mining node 116a can verify that the second mining node has successfully performed the same analysis on the data packet to generate the same metadata and the same private data output. Based on this verification, the mining node 116a can transmit the metadata for the data packet to the commitment database server that allows external access to the metadata for persistent storage therein. This is to 'open' the hiding and further enable external verification of the work done by the mining node 116a (especially since the metadata is published with a later timestamp than the metadata commitment value and the verification data).

[0137] Therefore, in step 610, if the first mining node 116a verifies that the second mining node 116b has analyzed the same data packet as the first mining node 116a (and achieved the same result), the commitment database receives the metadata characteristics of the analysis of the data packet by the first mining node 116a from the first mining node 116a.

[0138] In step 612, the commitment database request handler 510 stores the metadata together with a timestamp for the reception time at the commitment database server 118 in the commitment database 512. Thus, the timestamped metadata received from the first mining node 116a can be stored together with the earlier received timestamped first metadata commitment value and the first verification data.

[0139] Because the first metadata commitment value and the second metadata commitment value are included in the externally accessible, timestamped, immutable, and tamper-proof commitment database 512, the mining node 116a can use the entry of the first metadata commitment value and the first verification data in the commitment database 512 as an externally verifiable proof of work. Thus, external access to this or each metadata commitment value and this or each corresponding verification data for each metadata commitment value, and the subsequently revealed metadata, from the commitment database server can allow proof of work to be verified by checking that each metadata commitment value generated by each mining node is generated using a cryptographic commitment scheme from the combination of their corresponding verification data and the matching metadata generated by the analysis performed at each mining node. The metadata stored in the commitment database 512 further enables such external verification.

[0140] The mining node can monitor the commitment database and attempt to verify the metadata commitment values posted thereon by cross-checking the metadata generated by the mining node in the unvalidated data packets to attempt to find the same metadata generated by other mining nodes that may have analyzed the same data packets and generated the same metadata.

[0141] Now will be described in conjunction with Figure 7 and Figure 8 the operation of the data proxy server for distributing data packets.

[0142] Figure 7 shows a block diagram of an embodiment of a computing device serving as Figure 1 the data proxy server 114 shown;

[0143] The data proxy server 114 includes a memory 702, one or more processors 704, and an input / output module 708. A bus system (not shown) may be provided that supports communication between at least one of the processor 704, the memory 702, and the input / output module 708.

[0144] The processor 704 executes instructions that may be loaded into the memory 702. The processor 704 may include any suitable number and type of processors or any other device in a suitable arrangement. Example types of processors include microprocessors, microcontrollers, digital signal processors, field programmable gate arrays, and application specific integrated circuits.

[0145] Memory 702 can be provided by any structure capable of storing and facilitating the retrieval of information such as data, program code, and / or other suitable information on a temporary or permanent basis. Memory 702 can represent random access memory or any other suitable volatile or non-volatile storage device. Memory 702 can also include one or more components or devices that support longer-term storage of data, such as read-only memory, hard disk drives, flash memory, or optical discs, which can store software code for loading into Memory 702 at runtime. In use, Processor 704 and Memory 702 provide a runtime environment 706 in which instructions or code loaded into Memory 702 can be executed by Processor 704 to generate instances of software modules in the runtime environment 706.

[0146] Mining Node 116a also includes an input / output module 708 that provides a communication interface for receiving data from one or more Mining Nodes 116a - 116n and a Commitment Database Server 118 via a network such as the Internet 112.

[0147] Although shown as a stand-alone computing device in Figure 1 , the Data Broker Server 114 can be configured as a networked server or a virtual machine implemented in a cloud computing service, either of which can be suitable for performing the methods described herein.

[0148] In an example, Memory 702 includes instructions for instantiating software modules corresponding to a Packet Creator 710, a Packet Storage Device 712, and a Packet Request Handler 714. The functions and operations of these modules will now be described with reference to Figure 8 .

[0149] Figure 8 Shows an embodiment of a method 800 implemented in conjunction with an example Data Broker Server shown in Figure 7 , an example Commitment Database Server shown in Figure 5 , and a plurality of example Mining Nodes shown in Figure 3 .

[0150] Generally, the Data Broker Server 114 receives a dataset from a sequencing user (e.g., a genetic sequencing user node 110) and then creates work packages of data entities for processing by the Mining Nodes. Once all data entities from the dataset have been base-called by the Mining Nodes, the Data Broker Server 114 returns the assembled base-called data to the sequencing user.

[0151] Thus, in method 800, at step 802, data proxy server 114 receives, via input / output module 708, signal information to be kept private, such as genetic signal information 200 in the form of a data set generated by processing a sample from biological organism 104 by genetic sequencer 102.

[0152] The received signal information is passed to packet creator 710, which configures the signal information and stores it as one or more packets in packet storage device 712. For example, data proxy server 114 may split the received signal information (e.g., by separating the readings of genetic sequencer 102) and randomly group them together into packets of signal information to be processed. This helps to obscure the signal information and prevent the mining nodes from reassembling the genetic sequence information of biological organism 104, which is to be kept private.

[0153] Once the packets have been assembled and stored ready for processing, data proxy server 114 may publish the packets to be processed to the mining nodes, to allow the mining nodes to request packets to work on. Thus, at step 806, data proxy server 114 receives, via input / output module 708, a packet request from first mining node 116a and a packet request from second mining node 116b. These requests are passed to packet request handler 714 for processing.

[0154] At step 808, packet request handler 714 randomly selects a packet waiting for processing from the packet storage device.

[0155] At step 810, packet request handler 714 sends the selected packet from packet storage device 712 to the first mining node via input / output module 708 using a first packet identifier, and sends it to the second mining node using a second packet identifier different from the first packet identifier. In this way, the first mining node and the second mining node do not know that they are receiving the same packet, and collusion is avoided. Since the packets are randomly assigned, it is impractical for the mining nodes to try to find other mining nodes in mining network 120 that are receiving the same packet, and thus collusion is avoided.

[0156] In an embodiment, at least one of mining nodes 116c - 116n may further be sent a packet for analysis, and each mining node may cross-check against other entries in commitment database server 118. In this way, the same packet may be analyzed by two or more, or at least three, mining nodes, where the analysis results of each mining node are externally verifiable.

[0157] Once the first mining node and the second mining node have processed the data packet and have themselves used the commitment database 512 to cross-check that another mining node has successfully verified the same data packet, they send the private data output back to the data proxy server 114.

[0158] Accordingly, in step 812, the data proxy server 114 receives, via the input / output module 708, a first private data output from the first mining node that has analyzed the data packet and a second private data output from the second mining node that has analyzed the data packet. Before assembling the genetic sequence information from all the private data outputs and sending it back to the genetic sequencer user node 110, the data proxy server 114 can directly cross-check and verify the private data outputs for the same data packet. Alternative ciphers can be used by the mining nodes for the genetic sequence information, so that two miners cannot directly see that they have produced the same sequence, but these can all be decoded by the data proxy server 114.

[0159] If the data proxy server 114 issues an encrypted token to the mining node for attaching a block record to the blockchain, the data proxy server 114 can also check the commitment database for an externally verifiable proof of work by accessing the commitment database 512 in the commitment database server 118 in step 814 and cross-checking whether the database entries for the first data packet identifier and the second data packet identifier are valid. The data proxy server 114 can have other verification requirements, such as a minimum number of matching private data outputs, before the signed encrypted token can be issued.

[0160] In this way, the data proxy server 114 can provide randomly selected data packets to the mining nodes in the mining network for processing, and if the metadata commitment value pairs posted to the commitment database are cross-verified against the work calculations performed by the mining nodes, the data proxy server 114 can provide a signed encrypted token for adding a block record to the blockchain such that the entries in the commitment database provide an externally verifiable proof of work.

[0161] In other embodiments, it is not necessary for the mining nodes to have a signed encrypted token from the data proxy server 114 to attach a block record to the blockchain, and the mining nodes can directly rely on the entries in the commitment database 512.

[0162] Once the mining node has checked the commitment database server 118 and can use its entries as an externally verifiable proof of work related to the data packet, and once other requirements are met, it can attach the block record to the blockchain. Now, in conjunction with the mining node 116a and Figure 3The method steps for achieving this are described. The blockchain management module 316 can use a reference to at least a metadata commitment value stored at the commitment database server 118 as a proof of work to create a block record for the blockchain.

[0163] Thus, creating a block record for the blockchain can include the blockchain management module 316 querying the mining node 116a for the version of the blockchain locally stored in one or more machine-readable storage media to extract the unique identifier of the previous block of the blockchain, and retrieving payload data from the data pool of unprocessed payload data. A new block can be created, including a reference to the previous block and a reference to an entry in the commitment database 512 at the commitment database server 118 as a proof of work, and / or any cryptographic tokens received from the data proxy server 114.

[0164] The mining node 116a can then transmit the created block record to at least another mining node (e.g., mining node 116b and mining node 116b) of the mining network via the input / output module 308. These mining nodes can query their locally stored versions of the blockchain and check whether the newly received block from the mining node 116a is valid by verifying the proof of work (referencing the commitment database server 118) - this is done before appending the block record to their locally stored blockchain and before sending the new block record to other mining nodes in the mining network so that they can update their blockchains to append the block record.

[0165] Appending a block record to the blockchain at another mining node (e.g., mining node 116b) can include the mining node 116b receiving a block record for addition to the blockchain from another mining node of the blockchain network (in this case, the mining node 116a). The mining node 116b can extract a reference to a first metadata commitment value stored at the commitment database server from the received block record and use the first metadata commitment value stored at the commitment database server to verify the proof of work for the first mining node. Based on this verification, the mining node 116b can update the version of the blockchain stored thereon to include the received block record.

[0166] Verifying the proof of work for the first mining node 116a can include the second mining node 116b receiving a first metadata commitment value, first verification data, and subsequently revealed first metadata from a committed database server. The second mining node 116b can then use a cryptographic commitment scheme to generate a recreated first metadata commitment value, such as by hashing the received first metadata and the first mining node identifier. The second mining node 116b can then compare the recreated first metadata commitment value and the received first metadata commitment value, and if the comparison indicates that the recreated first metadata commitment value and the received first metadata commitment value match, the second mining node 116b can verify the proof of work for the received block record.

[0167] In this way, the proof of work in received block records for attachment to the blockchain can be verified at each mining node with reference to entries in the committed database, rather than having to rely on a data proxy server to act as an authoritative server.

[0168] The blockchain can be permissionless, which should allow any computing device to operate as a mining node (provided they are able to run mining software to process signal information).

[0169] According to the present disclosure, the commitment database retains tamper-proof and timestamped records of metadata commitments and verification data, which allows external verification of the computational work done by mining nodes to generate private data outputs without revealing the private data outputs. Successfully verified entries include metadata providing an externally verifiable proof of work for appending block records to the blockchain. By referencing other metadata commitment values in the externally accessible commitment database, mining nodes can check and verify whether other mining nodes in the mining network have analyzed the same data packets and produced the same metadata through their analysis. This is achieved by the mining node accessing the metadata commitment values published to the commitment database by other mining nodes and using a cryptographic commitment scheme to attempt to recreate the metadata commitment values using the metadata generated by the mining node in its own analysis and the verification data published to the commitment database along with the metadata commitment values. If the recreated metadata commitment value is the same as the metadata commitment value published to the commitment server by another mining node, the mining node will be able to prove that it has successfully completed the analysis and that this is consistent with another mining node (with which it cannot collude). Upon meeting the minimum verification requirements, the mining node can then request the issuance of a cryptographic token, e.g., from a data proxy server, and the metadata commitment value entry is published in the commitment database, serving as an externally verifiable proof of work without revealing the private data output. In particular, if after a mining node has verified a second metadata commitment value from a second mining node, the mining node publishes the metadata it has generated to the commitment database, then any node with access to the commitment database can use a cryptographic commitment scheme to verify the work done by the mining node based on the combination of the published metadata and verification data and by comparing the recreated metadata commitment value with the published metadata commitment value. In this way, the commitment database entry of the mining node serves as an externally verifiable proof of work for the analysis of the data packets performed at the mining node without revealing the private data output. Thus, the commitment database can support the proof of work for such blockchain implementations without having to rely solely on the authority of the data proxy server. Additionally, through the commitment database, mining nodes can be made to perform computational work to generate private data outputs in a way that prevents collusion between mining nodes while also allowing non-colluding mining nodes to cross-check their analyses and publish externally verifiable proofs of work.

[0170] Furthermore, according to the present disclosure, the method can provide a mechanism for mining nodes to analyze signal information output from a genetic sequencer to generate reads of a polynucleotide sequence, and the computational work required to generate the polynucleotide sequence is externally verifiable such that a proof of work can be generated and used to append block records to the blockchain while being able to keep the polynucleotide sequence private.

[0171] Features, integers, characteristics or groups described in connection with specific aspects, embodiments or examples of the present invention should be understood to be applicable to any other aspect, embodiment or example described herein, unless incompatible therewith. All features disclosed in this specification (including any accompanying claims, abstract and drawings), and / or all steps of any method or process so disclosed, may be combined in any combination, except combinations where at least some of such features and / or steps are mutually exclusive. The present invention is not restricted to the details of any foregoing embodiment. The present invention extends to any novel one or any novel combination of the features disclosed in this specification (including any accompanying claims, abstract and drawings), or to any novel one or any novel combination of the steps of any method or process so disclosed. In particular, any dependent claim may be combined with any independent claim and any other dependent claim.

[0172] In the foregoing detailed description, many of the processing tasks have related to the conversion of signal information representing a polynucleotide sequence to a base sequence. However, those skilled in the art will understand that the methods and apparatuses described herein can be applied to other types of signal information. For example, the signal information can relate to other natural molecules, such as proteins or secondary modifications. As another example, the signal information can relate to modified or synthetic molecules, such as oligonucleotide tags, nucleic acid analogs or expanders including expandable nucleoside triphosphates.

[0173] Unless otherwise expressly stated, each feature disclosed in this specification (including any accompanying claims, abstract and drawings) may be replaced by alternative features serving the same, equivalent or similar purpose. Thus, unless otherwise expressly stated, each feature disclosed is only one example of a general series of equivalent or similar features. The present invention is not restricted to the details of any foregoing embodiment. The present invention extends to any novel one or any novel combination of the features disclosed in this specification (including any accompanying claims, abstract and drawings), or to any novel one or any novel combination of the steps of any method or process so disclosed. The claims should not be construed as limited to only the foregoing embodiments, but also cover any embodiment falling within the scope of the claims.

Claims

1. A method performed in a mining node in a mining network for establishing an externally verifiable proof of work as immutable evidence of computational work done by the mining node to generate a private data output, the proof of work being for appending a block record to a blockchain, the method comprising: Receiving a data packet from a data proxy server, the data packet including signal information to be kept private by the mining node; Analyzing the data packet by computational work to convert the signal information into a corresponding private data output also to be kept private by the mining node; As a result of the analysis, generating metadata characteristics of the analysis of the corresponding signal information, the metadata being independent of the private data output generated by the analysis; Using a cryptographic commitment scheme to generate a metadata commitment value for the data packet analyzed by the mining node from a combination of the metadata and verification data; Transmitting the metadata commitment value and the verification data to a commitment database server, the commitment database server allowing external access to the metadata commitment value to provide an externally verifiable proof of work.

2. The method according to claim 1, further comprising: Using a second metadata commitment value received from the commitment database server, under the condition that the second metadata commitment value is generated by a second mining node by analyzing the same data packet, to verify that the second mining node has generated matching metadata as a result of the analysis performed by the second mining node; And Based on the verification, transmitting the metadata for the data packet to the commitment database server that allows external access to the metadata for persistent storage therein.

3. The method according to claim 2, wherein the verification further comprises: After the second mining node completes the analysis of the same data packet, receiving from the commitment database server a second metadata commitment value for the data packet generated by the second mining node and transmitted to the commitment database server, and second verification data; Using a cryptographic commitment scheme to generate a recreated second metadata commitment value for the data packet from a combination of the metadata for the data packet generated by the mining node and the received second verification data; Comparing the recreated second metadata commitment value with the received second metadata commitment value generated by the second mining node; and If the comparison indicates that the recreated second metadata commitment value matches the received second metadata commitment value, verifying that the second mining node has successfully performed the same analysis of the data packet to generate the same metadata and the same private data output.

4. The method according to claim 2 or 3, further comprising: If the second metadata commitment value is verified, only transmitting the metadata for the data packet to the commitment database server.

5. The method according to claim 4, wherein, At least one additional mining node has been sent the data packet for analysis, the method further comprising: Using one or more additional metadata commitment values received from the commitment database server, under the condition that each of the one or more additional metadata commitment values has been generated by a corresponding at least one additional mining node, to verify that: all of the at least one additional mining node has generated matching metadata as a result of their analysis; and Based on the verification, if a minimum number of the received metadata commitment values are verified, then only the metadata for the data packet is transmitted to the commitment database server.

6. The method according to any one of claims 2 to 5, wherein, External access to the or each metadata commitment value, the or each corresponding verification data for each metadata commitment value, and the subsequently revealed metadata from the commitment database server is allowed by verifying the proof of work by checking that each metadata commitment value generated by each mining node is generated using the cryptographic commitment scheme from the combination of their corresponding verification data and the matching metadata generated by the analysis performed at each mining node.

7. The method according to any one of claims 1 to 6, wherein, The proof of work can be verified without referring to the private data output.

8. The method according to any one of claims 1 to 7, further comprising transmitting the private data output for the data packet to the data proxy server.

9. The method according to any one of claims 1 to 8, further comprising: Using a reference to at least the metadata commitment value stored at the commitment database server as the proof of work to create a block record for the blockchain; And Transmitting the created block record to at least one other mining node of the mining network.

10. The method according to claim 9, wherein, Creating a block record for the blockchain includes: Querying the version of the blockchain stored in one or more machine-readable storage media to extract the unique identifier of the previous block of the blockchain; and Retrieving payload data from a data pool of unprocessed payload data.

11. The method according to any one of claims 1 to 10, wherein, The verification data includes one or more of the following: The mining node identifier of the mining node that performs the analysis of the data packet; The data packet identifier assigned by the data proxy server for the data packet; A cryptographic nonce.

12. The method according to any one of claims 1 to 11, wherein, Using the cryptographic commitment scheme includes: generating a hash of the combination of the metadata generated by the mining node and the verification data using a cryptographic hash function.

13. The method according to any one of claims 1 to 12, wherein The data packet includes at least one data entity, wherein the data entity or each data entity includes signal information, the signal information of the data entity or each data entity is analyzed to convert it into a corresponding private data output, and the metadata commitment value is a hash of the combination of the metadata and the verification data for all data entities in the data packet.

14. The method according to any one of claims 1 to 13, wherein, The signal information represents a polynucleotide sequence; And Wherein, converting the signal information into the corresponding private data output includes: converting the signal information into corresponding readings, and each of the multiple readings describes a corresponding polynucleotide sequence.

15. The method according to claim 14, wherein, The polynucleotide sequence includes a deoxyribonucleic acid (DNA) sequence or a ribonucleic acid (RNA) sequence.

16. The method according to any one of claims 1 to 15, wherein The signal information includes raw data generated by a nanopore sequencer.

17. The method according to claim 16, wherein, The signal information includes current information corresponding to the current flowing through the nanopore and polynucleotides translocating through the nanopore.

18. The method according to any one of claims 1 to 17, wherein The data packet received from the data proxy server and assigned to the mining node for analysis is randomly selected from a plurality of data packets stored at the data proxy server for analysis.

19. The method according to any one of claims 1 to 18, wherein, The data packet received from the data proxy server specifies one or more computer program products or algorithms to be used by the mining node in analyzing the data packet.

20. The method according to any one of claims 1 to 19, wherein The analysis of the data packet by the or each mining node outputs the same metadata for the same private data output generated by the analysis, and the metadata and private data output do not contain mutual information.

21. The method according to any one of claims 1 to 20, wherein The metadata is deterministically generated as a byproduct of the analysis of the data packet to convert the signal information into the private data output.

22. The method according to any one of claims 1 to 21, wherein, The metadata and the metadata commitment value can be used as evidence indicating the private data output of the analysis of the data packet by the mining node.

23. The method according to any one of claims 1 to 22, wherein, The analysis of the data packet by the mining node includes: using a pre-trained neural network to convert the signal information into the private data output.

24. The method according to claim 23, wherein The metadata is based on a score generated by the neural network, where the score represents the probability of the correctness of the private data output and / or the quality of the input signal information.

25. The method according to any one of claims 1 to 24, wherein, The blockchain is permissionless, allowing any computing device to operate as a mining node.

26. The method according to any one of claims 1 to 25, wherein, The metadata, verification data, and metadata commitment value for any data packet can be accessed by any mining node in the commitment database server, and optionally can be publicly accessed.

27. The method according to any one of claims 1 to 26, further comprising: Receiving a block record for addition to the blockchain from another mining node of the blockchain network; Extracting a reference to a second metadata commitment value stored at the commitment database server from the received block record; Using the second metadata commitment value stored at the commitment database server to verify the proof of work for the second mining node; And Based on the verification, updating the blockchain to include the received block record.

28. The method according to claim 27, wherein, Verifying the proof of work for the second mining node includes: Receiving the second metadata commitment value, second verification data, and subsequently revealed second metadata from the commitment database server; Hashing the received second metadata and the second mining node identifier to generate a recreated second metadata commitment value; Comparing the recreated second metadata commitment value and the received second metadata commitment value; and If the comparison indicates that the recreated second metadata commitment value matches the received second metadata commitment value, verifying the proof of work for the received block record.

29. A mining node for establishing an externally verifiable proof of work as an immutable evidence of the computational work done by the mining node to generate a private data output, the proof of work being for appending a block record to a blockchain, the mining node comprising: A processor; And A memory storing instructions which, when executed by the processor, configure the mining node to: Receive, from a data proxy server, a data packet including signal information to be kept private by the mining node; Analyze the data packet through computational work to convert the signal information into a corresponding private data output also to be kept private by the mining node; As a result of the analysis, generate metadata features of the analysis of the corresponding signal information, the metadata being independent of the private data output generated through the analysis; Use a cryptographic commitment scheme to generate a metadata commitment value for the data packet analyzed by the mining node from a combination of the metadata and verification data; Transmit the metadata commitment value and the verification data to a commitment database server, which allows external access to the metadata commitment value to provide an externally verifiable proof of work.

30. A computer program product, optionally embodied in a non-transitory computer-readable storage medium, the computer program product including instructions which, when executed by a computer, cause the computer to: Receive, from a data proxy server, a data packet including signal information to be kept private by the mining node; Analyze the data packet through computational work to convert the signal information into a corresponding private data output also to be kept private by the mining node; As a result of the analysis, generate metadata features of the analysis of the corresponding signal information, the metadata being independent of the private data output generated through the analysis; Use a cryptographic commitment scheme to generate a metadata commitment value for the data packet analyzed by the mining node from a combination of the metadata and verification data; Transmit the metadata commitment value and the verification data to a commitment database server, which allows external access to the metadata commitment value to provide an externally verifiable proof of work.

31. A method performed in a commitment database server for use in conjunction with a plurality of mining nodes as claimed in claim 29 to establish an externally verifiable proof of work as immutable evidence of computational work done by the mining nodes to generate a private data output, the proof of work being for appending a block record to a blockchain, the method comprising: Receive a first metadata commitment value and first verification data from a first mining node; Receive a second metadata commitment value and second verification data from a second mining node; The first metadata commitment value and the second metadata commitment value are generated by the first mining node and the second mining node using a cryptographic commitment scheme from: the metadata features of the analysis of a data packet provided by the data proxy server through computational work by the respective mining node and a combination of corresponding verification data, wherein the data packet includes signal information to be kept private by the mining node, the analysis converting the signal information into a corresponding private data output and generating metadata features of the analysis of the corresponding signal information; The method further comprises: Store the first metadata commitment value, the second metadata commitment value, the first verification data, and the second verification data, together with a timestamp for their reception time at the commitment database server, in an externally accessible, tamper-proof, and immutable commitment database; Provide the second metadata commitment value and the second verification data to the first mining node for verification by the first mining node; and If the first mining node verifies that the second mining node has analyzed the same data packets as the first mining node, receive from the first mining node the metadata characteristics of the analysis of the data packets by the first mining node; Store the metadata, together with a timestamp for the reception time at the commitment database server, in the commitment database.

32. A commitment database server for use in combination with a plurality of mining nodes as claimed in claim 29 to establish an externally verifiable proof of work as immutable evidence of computational work done by the mining nodes to generate a private data output, the proof of work being for appending a block record to a blockchain, the commitment database server comprising: A processor; And A memory storing instructions which, when executed by the processor, configure the commitment database server to: Receive a first metadata commitment value and first verification data from a first mining node; Receive a second metadata commitment value and second verification data from a second mining node; The first metadata commitment value and the second metadata commitment value are generated by the first mining node and the second mining node using a cryptographic commitment scheme from: a combination of the metadata characteristics of the analysis of data packets provided by the data proxy server by the respective mining node through computational work and the corresponding verification data, wherein the data packets include signal information to be kept private by the mining nodes, the analysis converts the signal information into a corresponding private data output, and generates the metadata characteristics of the analysis of the corresponding signal information; The commitment database server is further configured to: Store the first metadata commitment value, the second metadata commitment value, the first verification data, and the second verification data, together with a timestamp for their reception time at the commitment database server, in an externally accessible, tamper-proof, and immutable commitment database; Provide the second metadata commitment value and the second verification data to the first mining node for verification by the first mining node; And If the first mining node verifies that the second mining node has analyzed the same data packets as the first mining node, receive from the first mining node the metadata characteristics of the analysis of the data packets by the first mining node; Store the metadata, together with a timestamp for the reception time at the commitment database server, in the commitment database.

33. A computer program product, optionally embodied in a non-transitory computer-readable storage medium, the computer program product comprising instructions which, when executed by a computer, cause the computer to perform the method as claimed in claim 29.

34. A method implemented in a data proxy server for use in conjunction with a commitment database server as claimed in claim 32 and a plurality of mining nodes as claimed in claim 29 to establish an externally verifiable proof-of-work as immutable evidence of computational work performed by the mining nodes to generate a private data output, the proof-of-work being used to append a block record to a blockchain, the method comprising: Receiving signal information to be kept private; Storing the signal information as one or more data packets in a data packet storage device; Receiving requests for data packets from a first mining node and requests for data packets from a second mining node; Randomly selecting a data packet awaiting processing from the data packet storage device; Sending the selected data packet to the first mining node using a first data packet identifier and sending the selected data packet to the second first mining node using a second data packet identifier different from the first data packet identifier; Receiving a first private data output from the first mining node that has analyzed the data packet and receiving a second private data output from the second mining node that has analyzed the data packet; Accessing the commitment database in the commitment database server and cross-checking whether database entries for the first data packet identifier and the second data packet identifier are valid.

35. A data proxy server for use in conjunction with a commitment database server as claimed in claim 32 and a plurality of mining nodes as claimed in claim 29 to establish an externally verifiable proof-of-work as immutable evidence of computational work performed by the mining nodes to generate a private data output, the proof-of-work being used to append a block record to a blockchain, the data proxy server comprising: A processor; And A memory storing instructions which, when executed by the processor, configure the data proxy server to: Receive signal information to be kept private; Store the signal information as one or more data packets in a data packet storage device; Receive requests for data packets from a first mining node and requests for data packets from a second mining node; Randomly select a data packet awaiting processing from the data packet device storage; Send the selected data packet to the first mining node using a first data packet identifier and send the selected data packet to the second first mining node using a second data packet identifier different from the first data packet identifier; Receive a first private data output from the first mining node that has analyzed the data packet and receive a second private data output from the second mining node that has analyzed the data packet; Access the commitment database in the commitment database server and cross-check whether database entries for the first data packet identifier and the second data packet identifier are valid.

36. A computer program product, optionally embodied in a non-transitory computer-readable storage medium, the computer program product comprising instructions which, when executed by a computer, cause the computer to perform the method of claim 34.

Citation Information

Patent Citations

  • Proof-of-work for blockchain applications

    WO2020120933A1