Computer-implemented systems and methods for enabling access to data stored on a blockchain
By storing the attributes and content of data in blockchain transactions, and generating tokens in combination with cryptographic systems and one-way functions, the problem of data storage and access control on the blockchain is solved, and secure and efficient data storage and access control are achieved.
Patent Information
- Application Number
- CN201980078214.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-11-27
- Filing Date
- 2019-11-14
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2039-11-14
AI Technical Summary
The prior art is difficult to effectively utilize the distributed, immutable and permanent characteristics of blockchain to store, process, retrieve and share data, and lacks a secure access control mechanism.
By using the attributes and contents of the data that cannot be spent to output and generate tokens in blockchain transactions, combining the private key encryption of the cryptographic system and one-way functions to achieve secure storage and access control of data, and using an atomic exchange mechanism for payment and license management.
It realizes secure and efficient storage and access of data on the blockchain, reduces storage space requirements, enhances the security of data processing, and improves the flexibility and efficiency of access control.
Smart Images

Figure CN113169874B_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to cryptographic techniques for improved data communication and exchange across electronic networks, particularly peer-to-peer networks such as blockchain networks. It relates to data storage, access, retrieval, and processing, and particularly to such data-related activities on a blockchain. The present invention is particularly suitable for, but not limited to, use when processing data in a manner similar to that provided by websites and web pages, but using a blockchain as the underlying mechanism or platform instead of a web server. Thus, the present invention provides a secure, efficient, cryptographically implemented alternative infrastructure for data processing and transmission. Background Art
[0002] In this document, we use the term "blockchain" to include all forms of electronic computer-based distributed ledgers. These include consensus-based blockchain and transaction chain technologies, permissioned and unpermissioned ledgers, shared ledgers, and their variant terms. The term "user" in this document can refer to a person or a processor-based resource.
[0003] A blockchain is a peer-to-peer electronic ledger that is implemented as a computer-based decentralized distributed system consisting of blocks, which in turn consist of transactions. Each transaction is a data structure that encodes the transfer of digital asset control rights between participants in the blockchain system and includes at least one input and at least one output. Each block contains the hash value of the previous block, such that the blocks are linked together to create a permanent, immutable record of all transactions that have been written to the blockchain since its inception. Transactions contain small programs called scripts embedded in their inputs and outputs that specify how and by whom the output of the transaction can be accessed.
[0004] In order to write a transaction to the blockchain, it must be "verified". Network nodes (miners) perform work to ensure that each transaction is valid, and invalid transactions are rejected by the network. The software client installed on the node performs this verification work on unspent transactions (UTXOs) by executing their locking scripts and unlocking scripts. If the execution of the locking script and the unlocking script evaluates to TRUE, the transaction is valid and the transaction is written to the blockchain. Thus, in order to write a transaction to the blockchain, it is necessary to: i) verify the transaction by the first node that receives the transaction - if the transaction is verified, the node relays it to other nodes in the network; ii) add the transaction to a new block built by the miners; and iii) the transaction is mined, i.e., added to the public ledger of past transactions.
[0005] It would be highly advantageous if blockchain could be used for tasks and processes that can take advantage of the benefits of blockchain (e.g., permanence of events, tamper-proof records, distributed processing, etc.) and have more uses in their applications.
[0006] One such area of concern is using blockchain to store, share, access, and control data among users. Currently, this is achieved via the Internet, where servers host websites and pages that users typically access through search engines to access the required data.
[0007] However, some observers have begun to envision using blockchain to address certain drawbacks of the Internet, such as the control of large amounts of data and content by centralized parties. See, for example, "Life After Google: The Fall of Big Data and the Rise of the Blockchain Economy", George Gilder, Gateway Editions, July 2018, ISBN-10: 9781621575764 and ISBN-13: 978-1621575764. Summary of the Invention
[0008] Accordingly, it is desirable to provide an arrangement that enables the storage, processing, retrieval, search, and / or sharing of such data on a blockchain, taking advantage of the distributed, immutable, and permanent nature of the blockchain. Such an improved solution has now been devised.
[0009] Embodiments of the present disclosure provide at least alternative efficient and secure techniques for implementing blockchain solutions and for storing, processing, searching, and / or retrieving data thereon or therefrom. Embodiments also provide at least an alternative technical infrastructure for a blockchain implementation for storing, processing, retrieving, transmitting, searching, and / or sharing data among computing nodes. Since the present invention enables the use of a blockchain network in a new way and for providing improved technical results, the present invention provides an improved network for blockchain implementation.
[0010] Embodiments also provide a solution for securely controlling access to digital resources on technically different and improved computing platforms that include a blockchain and a blockchain protocol.
[0011] The present invention is defined in the appended claims.
[0012] According to the present invention, a computer-implemented method can be provided. The method can be a method for enabling access to data stored on a blockchain, the method comprising:
[0013] Generate at least one first blockchain transaction of a blockchain, wherein the first data is stored in at least one of the first blockchain transactions and is inaccessible to a first participant without first access data; and
[0014] Generate a second blockchain transaction of the blockchain, wherein the second blockchain transaction includes means for making the first access data available to the first participant.
[0015] This provides the following advantages: by ensuring that the first data becomes accessible if the terms of the unlocking script of the second transaction are met, the security of the process is enhanced, thus enabling an arrangement in which either two transactions can be executed or neither of the two transactions can be executed.
[0016] At least one of the first blockchain transactions may have at least one corresponding input that is a corresponding output of a previous blockchain transaction, wherein the output is redeemable by means of a corresponding private key of a cryptosystem, and the first data may be encrypted by means of the cryptosystem.
[0017] This provides the following advantages: reducing the codebase of the transaction, thus reducing the size of the storage space required.
[0018] Access by the first participant to the first data may enable the first participant to store additional data in at least one third blockchain transaction related to at least one of the first blockchain transactions.
[0019] This provides the following advantages: enabling the effective use of storage space for data on the blockchain.
[0020] The second blockchain transaction may include second data representing at least one token.
[0021] This provides the following advantages: enabling conditions (such as timed access or expiration) to be applied to the token, thus increasing the flexibility of the method.
[0022] At least one of the tokens may be at least one of a plurality of tokens generated by repeated application of a one-way function.
[0023] For example, a token may be generated from an initial token and repeated application of a generation algorithm in the form of a one-way function (such as a hash function), enabling subsequent tokens to be generated from the initial token. This provides the following advantages: requiring less data storage space.
[0024] The method may further include: generating at least one fourth blockchain transaction for refunding at least part of the second data without redeeming at least one output of the second blockchain transaction.
[0025] This provides the following advantage: preventing the second data from becoming irrecoverable without redeeming the first blockchain transaction.
[0026] At least one of the at least one fourth blockchain transaction may have at least one output that is redeemable only after a predetermined time period.
[0027] At least one of the at least one fourth blockchain transaction may have at least one output that is redeemable only after a predetermined number of blocks.
[0028] At least one of the at least one first blockchain transaction may have at least one output that is redeemable by means of a script that includes data that makes the first access data available to the first participant.
[0029] The script may include data that enables the determination of an input of a one-way function.
[0030] At least one of the at least one one-way function may be a hash function.
[0031] The script may include data that enables the first participant to determine the private key in a public-private key pair.
[0032] The method may further include: securely sharing a first secret between the first participant and the second participant to enable the determination of data that makes the first access data available to the first participant.
[0033] For example, the shared secret can be used to mask a temporary key or a hash preimage.
[0034] The present invention also provides a system, which includes:
[0035] A processor; and
[0036] A memory including executable instructions that, when executed by the processor, cause the system to perform any embodiment of the computer-implemented method described herein.
[0037] The present invention also provides a non-transitory computer-readable storage medium having stored thereon executable instructions that, when executed by a processor of a computer system, cause the computer system to perform at least an embodiment of the computer-implemented method described herein. Description of the Drawings
[0038] These and other aspects of the invention will become apparent from and will be elucidated with reference to the embodiments described herein. Embodiments of the invention will now be described, by way of example only and with reference to the accompanying drawings, in which:
[0039] Figure 1 A blockchain transaction embodying the invention is shown, in which data is stored in multiple outputs;
[0040] Figure 2 A blockchain transaction embodying the invention is shown, in which data is stored in inputs.
[0041] Figure 3 A series of blockchain transactions embodying the invention are shown, in which data is stored on the outputs of multiple blockchain transactions;
[0042] Figure 4 A blockchain transaction embodying the invention is shown, which transfers a payment to allow access to data by means of an atomic swap;
[0043] Figure 5 A blockchain transaction embodying the invention is shown, for redeeming Figure 4 the payment of a transaction;
[0044] Figure 6 A secret value held by a participant in a blockchain transaction embodying the invention is shown, which issues a token to allow access to data by means of an atomic swap;
[0045] Figure 7 and Figure 8 A blockchain transaction embodying the invention is shown, for issuing a token to allow access to data by means of an atomic swap;
[0046] Figure 9 and Figure 10 A blockchain transaction embodying the invention is shown, for redeeming a token issued by a transaction by means of Figure 7 and Figure 8 the transaction;
[0047] Figure 11 and Figure 12 A blockchain transaction for accessing a secret swapped by a transaction by means of Figure 9 and Figure 10 the transaction is shown;
[0048] Figure 13 A diagram of a meta-network graph structure according to an embodiment of the invention is provided.
[0049] Figure 14Shows an illustration of a meta-network graph tree for the domain "bobsblog" including MURL search paths according to an embodiment of the present invention.
[0050] Figure 15 Provides a diagram showing how to perform a search for content within the infrastructure of an embodiment of the present invention.
[0051] Figure 16 Shows an illustrative interaction between a local full-copy peer and a global full-copy peer according to an embodiment of the present invention.
[0052] Figure 17 Shows a meta-network tree (or graph) for use in reference to the illustrative use cases described below.
[0053] Figure 18 Shows a flowchart that illustrates the process embodied in the illustrative use cases provided below.
[0054] Figure 19 Is a schematic diagram showing a computing environment in which various embodiments may be implemented. Detailed Description
[0055] In the remainder of this document, the protocol that determines the operation of an embodiment of the present invention will be referred to as the "meta-network protocol".
[0056] According to an embodiment of the present invention, the terms "content" and "data" may be used interchangeably herein to refer to data stored in a blockchain transaction. Herein, "sharing" may include providing, sending, communicating, transmitting a portion of the data to a node or user or providing access to a portion of the data. The term "processing" may be interpreted to mean any activity related to a transaction or its associated data, including generating, transmitting, verifying, accessing, searching, sharing, submitting to a blockchain network, and / or identifying.
[0057] Overview
[0058] As described above, there has been a recognized need for an improved and / or alternative infrastructure for storing, writing, accessing, and viewing data between and by computing nodes. It would be advantageous to use the inherent advantages of blockchain technology (e.g., immutable records, cryptographically enforced control and access, built-in payment mechanisms, the ability to publicly inspect the ledger, distributed architecture, etc.). However, building an "internet implemented with blockchain" is challenging from many technical perspectives.
[0059] These challenges may include, but are not limited to: how to locate specific portions of data in a network; how to protect and control access to data so that only authorized parties can gain access; how to transfer data from one party to another in a peer-to-peer manner; how to arrange data such that it can be logically associated but still stored at different locations within the network, and subsequently how to combine it from different locations to provide an overall and enhanced result; how to provide and / or store data in a hierarchical manner; how to allow users and parties with different computing platforms to access the required data; how to store, provide, and share data across (potentially global) computing networks without relying on or requiring large storage servers and centralized data controllers, and how to improve the efficiency of such data-related activities on the network.
[0060] The present invention provides such an improved solution in such a way that the way is in some aspects similar to the Internet, but uses a platform of hardware components and software components that are completely different from those known in the prior art to achieve its results in a completely different way. According to an embodiment of the present invention, the server that stores Internet / network data and provides it to end users is replaced by a blockchain exchange residing on a blockchain network. To achieve this, several innovations must be designed. These will be described in the following sections.
[0061] Inserting data into the blockchain "meta-network" Refer to Figure 1 , shows a blockchain transaction embodying the present invention, in which first data to be stored on the blockchain is stored in one or more first outputs of the transaction, and second data representing the attributes of the first data is stored in one or more second outputs of the transaction. One or more first parts <content1> of the first data are stored in the spendable outputs of the transaction. Data <attribute1> and <attribute2> representing the corresponding attributes of the first data and a flag indicating that data is being stored according to the meta-network protocol are stored in the second non-spendable output of the transaction. The term "non-spendable" is used to indicate that at least one of the first and / or second outputs of the transaction may include a script opcode (OPRETURN) that is used to mark the output as invalid for subsequent use as an input to a subsequent transaction.
[0062] It is advantageous to store the content and attribute portions of data separately in separate outputs of the transaction.
[0063] Figure 2 shows a blockchain transaction embodying the present invention, in which first data <content1> to be stored on the blockchain is stored in the input of the transaction. The meta-network flag and the attribute data <attribute1> and <attribute2> are stored in the non-spendable output of the transaction in a manner similar to the arrangement shown in Figure 1 shown.
[0064] Data Insertion
[0065] Data Insertion Method
[0066] It is hoped that the following data can be inserted into the blockchain
[0067] a) Metanet flag
[0068] b) Attributes
[0069] c) Content
[0070] The content is the data to be stored on the blockchain. The Metanet flag is a 4-byte prefix that serves as an identifier for any data related to the Metanet protocol, and the attributes contain indexing, permission, and encoding information about the content. This can include, but is not limited to, data types, encryption, and / or compression schemes. Such attributes are often also referred to as metadata. To avoid confusion with transaction metadata, this term will be avoided in this document.
[0071] The following techniques can be used to embed this data into the blockchain script:
[0072] 1. OP_RETURN - In this method, all data (attributes and content) is placed after OP_RETURN in the locking script of a provably unspendable transaction output.
[0073] An example of an output script using this operator is as follows:
[0074] UTXO0: OP_RETURN <Metanet Flag> <attributes> <content>
[0075] 2. OP_RETURN with OP_DROP - In this case, OP_RETURN contains attributes, and the content is stored in the spendable transaction script (lock or unlock) before OP_DROP. The content can be split into multiple data packets in the transaction inputs and outputs. If data is inserted into the transaction input, OP_MOD can be used as a checksum for the data instead of miner verification to ensure its validity. For example, a 32-bit OP_MOD operation can be performed and checked if it equals a pre-computed value.
[0076] In this case, the attributes can contain information on how to reconstruct the content data packets. Additionally, providing the hash of the reconstructed data packet H(content1 + content2) as an attribute enables verification that the recommended reconstruction scheme has been used.
[0077] Figure 1 A transaction implementing the second data insertion method is shown. For simplicity, the transaction only includes inserting the content in its output, which is signed by its single input. Using Figure 2 the method shown to use the OP_DROP statement can also insert the content into additional inputs.
[0078] If the content is large, it may be advantageous to split it across multiple transactions. Such an arrangement is shown in Figure 3 In. Figure 3 A pair of blockchain transactions embodying the present invention is shown, in which the first data <content> to be stored on the blockchain is split into two chunks <content chunk1> and <content chunk2>, which can then be recombined as <content> = <content chunk1> || <content chunk2>, where the operator "||" concatenates the content data of the two chunks. This concatenation operator can be replaced by any desired bitwise or similar segmented binary operator. Then the two chunks <content chunk1> and <content chunk2> are stored in the respective spendable outputs of separate blockchain transactions, while the data related to the attributes of the content data is stored in the respective unspendable outputs of the blockchain transactions. Again, the attributes can contain information on the recombination scheme. For example, the content can be raw data, an executable program, or an HTML web page. Additionally, content1 can include a pointer to the location of content2 on the blockchain, which functions in the same way as an embedded HTML link within a web page.
[0079] It should be noted that the two transactions will use the same public key P (and ECDSA signature) as an input, such that although <content chunk1> and <content chunk2> are stored in different transactions with TxID1 and TxID2 respectively, they can be related by the same public key P.
[0080] Function of Miner Verification
[0081] Here, the transaction verification process performed by miners is used to gain an advantage when storing this data. This is because all the data in the transaction output will be signed by the owner of the public key P in at least one transaction input (if the SIGHASH|ALL flag exists), and this signature will be checked during the transaction verification process performed by all miners.
[0082] This ensures
[0083] · Data integrity - If the data is damaged, the CHECKSIG operation will fail.
[0084] · Data authenticity - The owner of P has provably witnessed and signed the data.
[0085] This is especially beneficial for content split across multiple transactions because the input signature of P provides a provable link between the split components of the data, as described by the arrangement shown in the reference Figure 3 above.
[0086] Rabin Signature
[0087] Another way to ensure data authenticity is to use Rabin signatures, which can be used to sign the data itself rather than the entire message. This can be beneficial because the signer does not need to sign each individual transaction in which the data appears, and the signature can be reused across multiple transactions.
[0088] Rabin signatures can be easily verified in a script. By inserting Rabin signature verification before the OP DROP command, these can be incorporated into case (2) above, i.e.,
[0089] <content1><Rabin Sig(content 1)>FUNC_CHECKRABSIG OP_DROP<H(P1)>[CheckSig P1]
[0090] It should be noted that this cannot be done in case (1) above because, in any case, the script containing OP_RETURN fails and thus verification cannot be achieved.
[0091] Specific Example of Using Rabin Signature
[0092] Introduction
[0093] Digital signatures are a fundamental part of blockchain protocols. They ensure that any transaction recorded on the blockchain has been authorized by the legitimate holder of the tokens being sent. In blockchain transactions, the Elliptic Curve Digital Signature Algorithm (ECDSA) is used to sign transaction messages. However, ECDSA signatures are typically applied to the entire transaction.
[0094] There are some use cases for blockchains where participants from outside the network may want to provide signatures for arbitrary data types, which can then be used by network participants. By using Rabin digital signatures, any data segment can be signed - even if it originates outside the blockchain - and then placed in one or more transactions.
[0095] Now it will be shown how data can be directly signed and verified in a script by leveraging the algebraic structure of the Rabin cryptosystem.
[0096] Rabin Digital Signature
[0097] Rabin Digital Signature Algorithm
[0098] Background Mathematics
[0099] Definition - Integer mod p
[0100] The integers modulo p are defined as the following set
[0101]
[0102] Fermat's Little Theorem
[0103] Let p be a prime number. Then for any integer a, the following condition holds
[0104] a p-1 ≡ 1 mod p
[0105] Euler's Criterion
[0106] Let p be a prime number. Then r is a quadratic residue modulo p if and only if the following holds
[0107]
[0108] Modular square root (p = 3 mod 4)
[0109] Let p be a prime number such that p ≡ 3 mod 4. Then for any integer r that satisfies Euler's criterion, if a is an integer, then such that
[0110] a 2 ≡ r mod p
[0111] Then, a has a solution in the form of the following formula
[0112]
[0113] Chinese Remainder Theorem
[0114] Given pairs of relatively prime positive integers n1, n2,..., n k and arbitrary integers a1, a2,..., a k , the system of simultaneous congruences
[0115]
[0116] has a unique solution modulo N = n1n2...n k . As a special case of the Chinese Remainder Theorem, it can be shown that:
[0117] if and only if
[0118] x = r mod n1·n2, then
[0119] x ≡ r mod n1 and x ≡ r mod n2
[0120] Rabin Digital Signature Algorithm
[0121] The Rabin digital signature algorithm can be described as follows:
[0122] For any message m, let H be a collision-resistant hash algorithm with k output bits.
[0123] To generate the key, choose prime numbers p and q, each with a bit length approximately k / 2, such that p ≡ 3 mod 4, q ≡ 3 mod 4 and calculate the product n = p·q. The private key is (p, q), and the public key is n = p·q.
[0124] To sign the message m, the signer chooses padding U such that H(m||U) satisfies
[0125]
[0126]
[0127] The signature S is calculated using the following formula
[0128]
[0129] The signature of the message m is (S, U). Verification can be simply performed by checking the following equation for the given m, U, and S
[0130] H(m||U) ≡ S 2 mod n (Equation 1).
[0131] This is true if and only if there exists an integer λ in the range 0,..., n - 1 such that
[0132] H(m||U) + λ·n = S 2 (Equation 2).
[0133] The factor λ can be safely included in the signature to provide the combination (S, λ, U).
[0134] The advantageous features of the Rabin signature scheme are as follows:
[0135] a) Signature generation is computationally expensive, while signature verification is computationally easy.
[0136] b) The security of the signature depends only on the difficulty of integer factorization. Therefore, the Rabin signature is inherently unforgeable (unlike RSA).
[0137] c) The hash function value H(m||U) must have a size similar to the public key n.
[0138] The verification in the script is straightforward because it only requires squaring the given signature, performing modular reduction, and then checking whether the result is equal to H(m||U).
[0139] Rabin Signature Proof
[0140] Let p and q be relatively prime, and n = p·q. By the Chinese Remainder Theorem, it can be shown that
[0141] if and only if
[0142] S 2 ≡ H(m||U) mod p
[0143] S 2 ≡ H(m||U) mod q, then
[0144] then
[0145] S 2 ≡ H(m||U) mod n
[0146] Use the following equation
[0147]
[0148] It can be shown that
[0149] S 2 ≡ H(m||U) mod q
[0150] Therefore
[0151]
[0152] where it has been assumed that H(m||U) satisfies Euler's criterion. By similar calculations, it can also be shown that
[0153] S 2 ≡ H(m||U) mod p.
[0154] Rabin Signature in Blockchain
[0155] Signature Verification in Script
[0156] A small number of arithmetic and stack manipulation opcodes are required to verify a Rabin signature. Consider a redemption script of the following form
[0157] OP_DUP OP_HASH160 <H 160 (n)> OP_EQUALVERIFY OP_MUL OP_SWAP OP_2 OP_ROLL OP_CAT FUNC_HASH3072 OP_ADD OP_SWAP OP_DUP OP_MUL OP_EQUAL
[0158] where n is the signer's public key. This will evaluate to true if and only if the following inputs are available
[0159] <s> <m><λ> <n>
[0160] Where m is an arbitrary message and (S, λ, U) is a valid Rabin signature. Alternatively, if the Rabin signature is verified using Equation 1 above, the redemption script is given by:
[0161] OP_DUP OP_HASH160<H 160 (n)>OP_DUP OP_TOALTSTACK OP_SWAP<roll index>OP_ROLL OP_CAT FUNC_HASH3072 OP_SWAP OP_MOD OP_SWAP OP_DUP OP_MUL OP_FROMALTSTACK OP_MOD OP_EQUAL
[0162] In this case, this will evaluate to true if and only if the following inputs are present
[0163] S> <m> <n>
[0164] In both of these redemption scripts, the 3072-bit hash projection function "FUNC_HASH3072" is used. For a given message / padding concatenation, the following script is used to generate the FUNC_HASH3072 hash projection:
[0165] OP_SHA256{OP_2 OP_SPLIT OP_SWAP OP_SHA256 OP_SWAP}(x11)
[0166] OP_SHA256 OP_SWAP OP_SHA256{OP_CAT}(x11)
[0167] Data Compression
[0168] Internet data consists of JavaScript and common file types (e.g., text files (SML, HTML, etc.), video files (MPEG, M-JPEG, etc.), image files (GIF, JPEG, etc.), and audio files (AU, WAV, etc.)), as described in more detail, for example, at the following link: https: / / www.doc.ic.ac.uk / ~nd / surprise_97 / journal / vol1 / mmp / #text Using the above data insertion techniques, these different data types can also be embedded on the blockchain.
[0169] Before embedding a larger file size on the blockchain, it can be compressed using one of several existing coding schemes. Lossless data compression algorithms such as run-length and Huffman coding can be used for several applications, including ZIP files, executable programs, text documents, and source code.
[0170] Depending on the specific input data, there are many different algorithms. Apple Lossless and Adaptive Transform Acoustic Coding can be used to compress audio files, PNG and TIFF for graphic files, and movie files can be compressed using one of many lossless video codecs. Flags within the attributes can be used to indicate any compression of the data content. For example, the flag for the LZW lossless coding scheme in the attribute would be <lzw>。
[0171] Decryption of Encryption and Payment
[0172] Data Encryption
[0173] The owner of the content can choose to protect the content before embedding it on the blockchain. This ensures that the content cannot be viewed without obtaining the necessary permissions.
[0174] There are many well - recognized techniques for encrypting data (plaintext or other data types). These techniques can be classified as asymmetric encryption or symmetric encryption.
[0175] Elliptic Curve Cryptography (ECC) is asymmetric because it relies on a public - key / private - key pair. It is one of the most secure cryptographic systems. For ECC cryptography, the Koblitz algorithm can be used to encrypt data.
[0176] In a symmetric scheme, a single key is used to both encrypt and decrypt data. The Advanced Encryption Standard (AES) algorithm is considered one of the most secure symmetric algorithms seeded by such a secret, for example, as described in more detail in the following literature: Chapter 4 in C. Paar and J. Pelzl, "Understanding Cryptography", Springer - Verlag Berlin Heidelberg, 2nd Edition, 2010, pp. 87 - 118.
[0177] When encrypting data stored on the blockchain, there are advantages to using the same cryptographic system as the underlying blockchain. These advantages are:
[0178] - The security level of the encryption is the same as the underlying system on which the data is stored.
[0179] - The software architecture required to store encrypted data will have a smaller codebase.
[0180] - Key management in the wallet can be used for both transactions and encryption / decryption.
[0181] - Since the same key can be used for encryption and payment, it is more efficient and thus fewer keys are required. This also reduces storage space.
[0182] - The ability to exchange / purchase decrypted data may require fewer communication channels.
[0183] - Since the keys used for encryption and transactions are the same data structure, security is enhanced, thus mitigating targeted attacks on specific key types.
[0184] For illustrative purposes, a description of how the Koblitz algorithm can be used to encrypt data using ECC is provided.
[0185] Koblitz Algorithm
[0186] Given an ECC key pair P1 = S1·G, the Koblitz algorithm allows anyone to encrypt a message using the public key P1 such that only the person who knows the corresponding private key S1 can decrypt the message.
[0187] Suppose it is desired to encrypt the plaintext message 'hello world' using the Koblitz method. This is done character by character. The first character 'h' is encrypted and decrypted as follows.
[0188] 1. The character 'h' is mapped to a point on the secp256k1 curve. This can be achieved by mapping the plaintext character to an 8-bit number using the ASCII convention. Then the point on the curve is calculated by multiplying the base point G by that number. In this example, 'h' maps to 104 in ASCII, and the elliptic curve point is given by P m = 104·G.
[0189] 2. Then the public key P1 is used to encrypt the point P m This is done by choosing a random temporary key k0 and calculating the pair of points C m = {k0·G, Q} (where Q := P m + k0·P1), and then this pair of points can be broadcast.
[0190] 3. The owner of the private key S1 can decrypt the original point by calculating P m = Q - S1·k0·G. Then they can recover the original ASCII number by trial and error or with the help of a lookup table to establish which number x corresponds to P m = x·G.
[0191] Using Blockchain to Purchase License
[0192] Storing data on a blockchain has the distinct advantage of having a payment mechanism built into the system. Payments can be used to purchase
[0193] - decrypting data for viewing / use
[0194] - permission to insert data at a specific address
[0195] In both cases, the buyer uses tokens to purchase the secret that grants them permission to do something. The secret can be a hash preimage or a private key.
[0196] An efficient and secure way to make such a purchase is to use an atomic swap. This keeps the secure communication channel minimal and ensures that payment is made to the seller and the secret is revealed to the buyer, or that nothing happens.
[0197] It is also convenient to purchase a license using an access token. This is a secret value (usually a hash preimage) that the buyer owns and can use to make a purchase. The buyer can purchase a large number of such access tokens in advance and then activate them when they actually want to use the license.
[0198] Now we will refer to Figure 4 and Figure 5 to describe how to perform an atomic swap.
[0199] Atomic Swap Using Hash Puzzle or Private Key Puzzle
[0200] Suppose Alice is the owner of the secret. The secret can be a hash preimage of a known hash digest or a private key of a known public key. Suppose Bob wants to use a token to purchase the secret from Alice. Describe a mechanism called an atomic swap that enables this transaction to occur. This is atomic in the sense that either Alice receives the token and reveals the secret to Bob, or nothing happens.
[0201] The method is as follows:
[0202] Alice owns a public key / private key pair P A = S A ·G's private key S A , and Bob owns a public key / private key pair P B = S B ·G's private key S B .
[0203] Alice owns a secret that is either the preimage X of a known hash digest H(X) or the private key S1 of a known public key P1 = S1·G.
[0204] They agree that Alice will sell the secret to Bob at the token price.
[0205] Before this, Bob must set up the transaction to send a temporary key k0 to Alice outside the block so that Alice can calculate the component r0 of the digital signature.
[0206] Now refer to Figure 4 ,
[0207] 1. Bob transfers the token locked by the following redemption script R (written schematically) to Alice:
[0208] For the hash preimage:
[0209] R = [Hash Puzzle H(X)][CheckSig P A
[0210] This forces the preimage X to be exposed in the input of the redemption script.
[0211] For the private key:
[0212] R = [Private Key Puzzle P1, r0][CheckSig P A
[0213] This forces the private key S1 to be computable from the input of the redemption script. In this case, Bob and Alice must agree on a temporary key k0 used to construct r0, where (r0, R y ) = k0·G.
[0214] 2. Since Alice knows her secret (X or S1), she can spend her funds on the blockchain with the help of Figure 5 the transactions shown. This allows Bob to determine her secret.
[0215] As an optional security feature, Alice and Bob can use their public keys P A , P B to establish a shared secret S known only to the two of them. This can be achieved in the manner outlined in International Patent Publication No. WO 2017 / 145016. In this case, S can be added to the preimage X in the hash puzzle so as not to publicly disclose X on the blockchain. Similarly, in the private key puzzle, S can be used as the temporary key k0 to ensure that only Alice or Bob can compute the private key.
[0216] If Alice decides not to spend her funds, a time-locked refund can be introduced into the program to prevent Bob's funds from being locked by Alice.
[0217] Purchase Using Token
[0218] Suppose the same situation as described above exists, but Bob wishes to redeem an access token purchased in advance in exchange for a secret.
[0219] The procedure that Alice and Bob must follow is similar to the situation described in the previous section, but uses a sequence of similar atomic swaps. The process has two phases; token issuance and token redemption.
[0220] Phase 1: Token Issuance
[0221] The token issuance phase is actually Bob's single purchase of a token. For example, consider the following scenario: Alice has 10 different secrets X1, X2,..., X 10 , and Bob wishes to purchase 10 tokens T1, T2, ..., T that each grant him access to a corresponding secret in a single purchase 10 .
[0222] First, Bob generates a set of 10 tokens from a secret seed value known only to him. These tokens are created by hashing the sequence of the seed to form a hash chain, where each token is computed as:
[0223] T i = H 10-i (Y) for i ∈ {1, 2, ..., 10}.
[0224] Alice and Bob now each have 10 secret values that can be revealed in a hash puzzle for, e.g., redeeming tokens. However, to release these tokens, they must also generate secret initialisation values I Alice and I Bob . These values are given as follows:
[0225] I Alice = k,
[0226] I Bob = H 10 (Y).
[0227] It should be noted that Alice's initialiser is simply a random integer with no specific meaning, but Bob's initialiser should be the hash of his first token T1 = H 9 (Y). Extending the token chain to the initialisation value in this way allows token release to also define the tokens to be used for successive redemptions later. Figure 6 All the secret values held by each participant are shown in
[0228] Now Alice and Bob can agree to purchase 10 tokens at a price of 10 units. The purchase of these tokens can be done in various ways, and here atomic swap is used for illustration. The atomic swap starts with Alice and Bob broadcasting the transactions shown in Figure 7 and Figure 8 respectively, where the outputs in both transactions require the solutions of two hash puzzles and valid signatures.
[0229] Once the two transactions appear in the blockchain, Alice and Bob can share their shared initialisation values I Alice and I Bob , and complete the atomic swap for token release.
[0230] Due to this atomic swap, Alice receives payment for purchasing 10 tokens and the two initialisation value secrets are revealed. It should be noted that here only Bob's secret I Bob = H 10 (Y) is meaningful because it will define the first hash puzzle to be solved [Hash Puzzle (T1)], whose solution is the initialization value H 10 The preimage H of (Y) 9 (Y).
[0231] Phase 2: Token Exchange
[0232] At some future point, Bob wants to exchange his first token T1 = H 9 (Y) and receive his first secret X1, but as mentioned before he has already paid for this secret by purchasing a valid token. The process of exchanging the token will take the form of another atomic swap, where the solution to the locked hash puzzle is the token T i and the corresponding secret X i .
[0233] To exchange his token, Bob should broadcast the transaction shown in Figure 9 , the output of which is locked by two hash puzzles. When Alice sees this transaction, she broadcasts her own similar transaction as shown in Figure 10 , the output of which is locked by the same two hash puzzles. The two participants can now exchange their secrets T1 and X1 and unlock the outputs of these transactions. The two parties can now exchange the nominal fee x by providing the correct unlocking scripts that also expose the two secrets. Figure 11 and Figure 12 show the transactions with these unlocking scripts.
[0234] The completion of this atomic swap for token exchange reveals Alice's first secret X1 to Bob, reveals Bob's first token T1 to Alice, and given that the amount x is large enough to encourage both parties to spend the locked output, there is a net-zero exchange of funds. Crucially, this also establishes that the next token Bob can use must be the solution T2 of a hash puzzle [Hash Puzzle H(T2)], where the target hash H(T2) = T1 has just been revealed to Alice. This process can be recursively repeated until Bob has used his last token T 10 = Y.
[0235] Naming and Addressing
[0236] Node and Edge Structure
[0237] It has been explained above how data can be inserted into the blockchain by providing data within a transaction. Now a protocol for structuring these transactions in a logical way is presented, which allows node addressing, permissioning, and content version control. The structure of this distributed peer-to-peer network is similar to the existing Internet.
[0238] Note that this is a "tier-2" protocol that does not modify the protocol or consensus rules of the underlying blockchain.
[0239] The goals of the structure described herein are:
[0240] (i) To associate relevant content in different transactions to enable searching, identifying, and accessing of data
[0241] (ii) To allow the identification of content using human-readable keyword searches to improve search speed, accuracy, and efficiency
[0242] (iii) To construct and simulate a server-like structure in the blockchain
[0243] Our approach is to structure the data associated with the metanet as a directed graph. The nodes and edges of this graph correspond to:
[0244] Nodes - Transactions associated with the metanet protocol. Nodes store content. (The terms "content" and "data" are used interchangeably within this document).
[0245] Nodes are created by including an OP_RETURN just before <Metanet Flag>. Each node is assigned a public key P node . The combination of the public key and the transaction ID uniquely specifies the index ID of the node node := H(P node ||TxID node ).
[0246] The hash function used should conform to the underlying blockchain protocol that will be used with, for example, SHA-256 or RIPEMD-160.
[0247] Edges - The association of child nodes with parent nodes.
[0248] Edges are created when the signature Sig P parent appears in the input of a metanet transaction, so only the parent can give permission to create an edge. All nodes can have at most one parent, and a parent node can have any number of children. In the language of graph theory, the in-degree of each node is at most 1, and the out-degree of each node is arbitrary.
[0249] Note that an edge is an aspect of the metanet protocol and is not itself a transaction associated with the underlying blockchain.
[0250] A valid metanet node (with a parent) is given by a transaction having the following form:
[0251]
[0252]
[0253] This transaction contains all the information required to specify the indices of the following nodes and their parents:
[0254] ID node = H(P node || TxID node ),
[0255] ID parent = H(P parent || TxID parent ).
[0256] In addition, since the signature of the parent node is required, only the parent can create an edge to the child. If the <TxID parent > field does not exist or it does not point to a valid meta-network transaction, the node is an orphan. There are no higher-level nodes that can reach it.
[0257] Additional attributes can be added to each node. These attributes can include flags, names, and keywords. These attributes are discussed later in this document.
[0258] As shown, the index of a node (transaction) can be partitioned into
[0259] a) public key P node , which we interpret as the address of the node
[0260] b) transaction ID TxID node , which we interpret as the version of the node
[0261] This structuring gives rise to two advantageous features:
[0262] 1. Version control - If there are two nodes with the same public key, then we interpret the node with the transaction ID having the maximum proof of work as the latest version of that node. If the nodes are in different blocks, this can be checked by the block height. For transactions within the same block, this is determined by the topological transaction ordering rule (TTOR).
[0263] 2. Permission - A child of a node can only be created if the owner of the public key P node signs the transaction input when creating the child node. Thus, P node represents not only the address of the node, but also the permission to create a child node. This is deliberately similar to a standard blockchain transaction - the public key is not only an address, but also the permission associated with that address.
[0264] Note that since the signature of the parent node appears in the UXTO unlocking script, it is verified through the standard miner verification process when the network accepts the transaction. This means that the permission to create child nodes is verified by the blockchain network itself.
[0265] It is worth noting that standard Internet Protocol (IP) addresses are unique within the network only at a given point in time. On the other hand, the indices of nodes in the metanet are unique at all times and there is no concept of separate networks, which allows data to be permanently anchored to a single object ID node 。
[0266] The node and edge structure allows the metanet to be visualized as a graph, as Figure 13 shown.
[0267] Domain, Naming and Localization Content in Meta-Network
[0268] The hierarchical structure of the metanet graph allows for rich domain-like structures to emerge. We interpret orphan nodes as top-level domains (TLDs), the children of orphan nodes as subdomains, the grandchildren as sub-subdomains, etc., and nodes without children as end-points. See Figure 13 。
[0269] Domain names are interpreted as IDs node 。Each top-level domain in the metanet can be considered a tree, where the root is the orphan node and the leaves are the nodes without children. The metanet itself is a global collection of trees that form a graph.
[0270] The metanet protocol does not dictate that any node contain content data, but leaf (childless) nodes represent the ends of directed paths in the data tree and will therefore typically be used to store content data. However, content can be stored at any node in the tree. Protocol-specific flags included as attributes in the nodes can be used to specify the role of the nodes in the data tree (disk space, folder, file, or permission to change).
[0271] It was previously mentioned that the Internet uses the Domain Name System (DNS) to associate human-readable names to Internet Protocol (IP) addresses. DNS is decentralized in a sense, although in practice it is controlled by a small number of key players (e.g., governments and large corporations). Depending on your DNS provider, the same name can take you to different addresses. This problem is inherent when mapping human-readable short names to computer-generated numbers.
[0272] We assume the existence of an equivalent distributed system that maps human-readable top-level domain names to the root node's decentralized index ID root . In other words, there is a one-to-one function κ that maps human-readable names to the metanet root node index, e.g.:
[0273] κ('bobsblog') = ID bobsblog (= H(P bobsblog ||TxID bobsblog ))
[0274] The input on the left is a human-readable word, while the output on the right is a hash digest, which will typically be a 256-bit data structure. It should be noted that P bobsblog and TxID bobsblog are usually not human-readable either. In the standard IP protocol, this would be a mapping of the IP address from www.bobsblog.com to the corresponding domain within the network.
[0275] The mapping κ should be interpreted as a measure to ensure the backward compatibility of the metanet and the Internet when replicating the human readability of DNS-published domain names, but the naming and addressing scheme providing the structure of the metanet does not explicitly depend on this mapping.
[0276] Possible existing forms of the mapping function include the DNSLink system adopted by the InterPlanetary File System (IPFS) or the OpenNIC service (https: / / www.openic.org). This mapping can be stored as part of DNS in an existing TXT record. This is similar to DNSLink in IPFS, see https: / / docs.ipfs.io / guides / concepts / dnslink / . However, generally speaking, these sacrifice some elements of decentralization in order to provide a 1-1 mapping, see https: / / hackernoon.com / ten-terrible-attempts-to-make-the-inter-planetary- fiile-system-human-friendly-e4e95df0c6fa
[0277] Vanity Address
[0278] The public key used as the address of a metanet node is not a human-readable object. This can make the search, reference, and input activities of human users error-prone and slow. However, a human-recognizable public key address - a vanity address P vanity - which includes a plaintext prefix that can be directly interpreted by the user. Vanity addresses are known in the prior art.
[0279] The difficulty of creating such an address depends on the character length of the required prefix. This means that a human-recognizable vanity address can be used as a node address that depends only on the creation effort of the owner rather than a central publication. For a given prefix, there are many different vanity addresses due to the remaining characters in the suffix, so many node addresses can share a common prefix while still remaining unique.
[0280] Examples of vanity addresses with the required prefix are:
[0281] P bobsblog : bobsblogHtKNngkdXEeobR76b53LETtpyT
[0282] Prefix: bobsblog
[0283] Suffix: HtKNngkdXEeobR76b53LETtpyT
[0284] The above vanity address can be used to sense-check the mapping from the name 'bobsblog' to the node index ID bobsblog and assist the metanet nodes through the searchability of the address. It should be noted that the prefix is not unique here, but the entire address itself is a unique entity.
[0285] The selected address P vanity in combination with the TxID forms an ID node which is also beneficial because it means that there is no central publisher of domain names (TxIDs are generated by decentralized proof-of-work), and the names are recoverable from the blockchain itself. Advantageously, there are no longer points of failure existing within the Internet DNS.
[0286] Since the metanet domain already provides a permission system (public key), there is no need to publish credentials to prove ownership. It has been explored, for example, in Namecoin ( https: / / namecoin.org / ) to use the blockchain for this purpose. However, according to the present invention, there is no need to use a separate blockchain for this function because everything can be achieved within one blockchain.
[0287] Compared with the prior art, this significantly reduces the amount of resources (hardware, processing resources, and energy) required by the present invention. In terms of the arrangement of device and system components, it also provides a completely different architecture.
[0288] The advantage of this naming system is that users can identify the top-level domain in the metanet by memorable words (e.g., company names) instead of hash digests. This also makes domain search faster because search keywords are faster than hash digests. This also reduces input errors, thus providing an improved search tool for the data stored in the blockchain.
[0289] Given the mapping from domain names to node indices, we can establish a resource locator similar to the Internet's Uniform Resource Locator (URL). We call this the metanet URL (MURL), and it has the following form
[0290] MURL ='mnp:' + ' / / domain name' + ' / path' + ' / file'.
[0291] Each component of a URL - protocol, domain name, path, and file - has been mapped to the structure of an MURL, making the object more user-intuitive and enabling it to integrate with the existing structure of the Internet.
[0292] This assumes that each node has a name associated with its public key (address), which is unique at the level within the domain tree. This name is always the rightmost component of the MURL for a given node. If two nodes at the same level in the tree have the same name, they will have the same public key, and thus the latest version is taken.
[0293] The following table gives an analogy between the Metaweb protocol and Internet protocols:
[0294]
[0295]
[0296] Table: Summary of the analogy between Internet protocols and Metaweb protocols
[0297] Search Meta-Network
[0298] We have defined the Metaweb graph structure of the exemplary embodiments such that each node has a unique index and can have a name attributed to it. This allows content to be located using an MURL. To also implement a fast search function, we allow additional keywords to be attributed to nodes.
[0299] The fixed attributes of a node are the index and the index of the parent node, and the optional attributes are the name and keywords.
[0300] Node attributes
[0301]
[0302] In one example, a utility method for searching the Metaweb could be to first trawl through the blockchain using a block detector and identify all transactions via Metaweb flags, check if they are valid Metaweb nodes, and if so, record their indexes and keywords in a database or other storage resource. The database can then be used to efficiently search for nodes by the required keywords. Once the index of a node is found by the required keyword, its content can be extracted from the block detector and viewed.
[0303] For example, consider Figure 14 branch P1, where the nodes corresponding to public keys P0, P1, and P 1,1 represent the home page, topic page, and sub-topic page respectively. These nodes are given the names 'bobsblog','summer', and 'caribbean', and their attributes are as follows:
[0304] Home page node P0
[0305]
[0306]
[0307] Topic page node P1
[0308]
[0309] Subtopic page node P 1,1
[0310]
[0311] In this example, the leaf node P 1,1,1 , P 1,1,2 and P 1,1,3 They are given the names 'beaches', 'nightlife', and 'food', and are used to store individual blog posts. The complete domain structure is shown in the diagram overleaf at the end of the page, including the MURL search paths associated with each node in the tree.
[0312] We should note that the Metanet can also be incorporated into the Content Addressable Network (CAN) by storing the hash of the content stored by the node transaction as an additional attribute. This means that Metanet nodes can also be indexed and searched by content hash.
[0313] The naming and addressing method described above provides numerous technical advantages over existing technologies, including:
[0314] 1. Public Key Addresses - The system uses the same public-private key pairs as the blockchain to assign node addresses. This means the same set of keys is used for both token management and content data licensing. This provides an efficient and secure solution.
[0315] 2. Decentralized Domains - Domain names are published by including TxIDs that can only be generated by proof of work node Domain names can also incorporate human-readable public keys P that achieve fair distribution of required domain public keys. vanity (Vanity address). Again, this solution provides enhanced efficiency and security.
[0316] 3. Graph Structure - The naming and addressing architecture specifies a graph that can be constructed from a subset of blockchain data, including metanet nodes. This design uses an ordered structure to map the complexity of the Internet to the blockchain, allowing the blockchain to fully replicate its functionality and scalability while maintaining security.
[0317] Blockchain Search Engine
[0318] Search Engine - Prior Art
[0319] Search engines (SEs) known in the prior art rely on powerful web crawlers to locate, index, and rate web content based on user queries. (The same basic principle can be extended to third-party blockchain SEs that crawl the meta web).
[0320] The SE searches for relevant HTML meta tags and content by keywords in the query. The crawl results are then indexed, where any embedded images / videos / media files are analyzed and cataloged. Then, the most relevant results in the index are programmatically rated, taking into account the user's location, language, and device.
[0321] A typical SE should have the following functionality:
[0322] 1. Crawling - Identify Internet data and crawl it with relevant metadata such as domain names, linked pages, and relevant keywords. Discover new Internet content through existing content and also crawl for any relevant information.
[0323] 2. Indexing - Analyze and catalog content data. This information is stored in a database.
[0324] 3. Serving and Rating - Rate the content index in order of relevance to the user query.
[0325] Block Explorer
[0326] The closest blockchain analogue to an Internet search engine (SE) is a blockchain explorer, which is sometimes referred to as a 'block explorer' or 'blockchain browser'. A blockchain explorer is a web application that enables user-friendly queries of a blockchain at a high level and functions similarly to a web browser, but connects to the blockchain instead of the Internet.
[0327] In most cases, these explorers allow blocks (indexed by the hash of the block header), transactions (indexed by TxID), addresses, and unspent transaction outputs (UTXOs) to be input and searched for. Many explorers also provide their own application programming interfaces (APIs) for retrieving raw transaction and block data. See https: / / blockexplorer.eom / a p i-ref .
[0328] Block detectors, while varying in capabilities, are generally useful for cataloging transactions in a user-friendly form for extraction and displaying their basic information - for example, the monetary value of the transaction, coin confirmations and history, and addresses. Many detectors also allow viewing of individual inputs and locking scripts of transactions, although there is an inconsistency between these detectors and how more advanced sites (e.g., Blockchair https: / / blockchair.com / ) choose to present this information.
[0329] Recently, there have been many extensions to basic blockchain detectors for running web applications based on blockchain data. These applications (e.g., Memo.cash https: / / memo.cash / protocol and Matter https: / / www.mttr.app / home ) catalog and organize blockchain transactions containing specific protocol identifiers, as well as display the data encoded within those specific transactions, much like block detectors.
[0330] However, there are two important problems with using blockchain detectors, and embodiments of the present invention solve these problems:
[0331] 1. Generalizability - Currently, there is no industry standard for browsing content data stored in transactions. Content data refers to any data that does not pertain to the protocols used to create and secure the underlying blockchain.
[0332] 2. Keyword search - The content data stored in transactions needs to be retrievable by human-readable keywords. This is generally not a function of current block detectors, as current block detectors are used to query the protocol-based nature of transactions (e.g., block height, TxID, and address), rather than using keywords as search inputs. (However, some detectors, such as Blockchair, can search for words if they are directly included in the transaction's script).
[0333] Importantly, as described above, the powerful naming and addressing structure of the present invention facilitates and enables the construction of blockchain detectors that are more complex than those known in the art.
[0334] Proposed Meta-Network Search Engine
[0335] The browser wallet application communicates with a third-party search engine to discover node identities (ID node ). It is envisioned that this third party can provide a powerful and versatile service that replicates the capabilities of existing Internet search engines.
[0336] The meta-web search engine third party maintains a database of all meta-web transactions mined into the blockchain that can be identified by meta-web protocol flags. This database can catalog all meta-web nodes through a range index including ID node , node name, keyword, TxID, and block height.
[0337] There already exist services such as Bit DB https: / / bitdb.network / that continuously synchronize with the blockchain and maintain transaction data in a standard database format. The browser wallet transfers the responsibility of crawling, indexing, serving, and rating metaweb transactions to this third party and connects to its service when locating content stored on the metaweb graph.
[0338] Efficiency can be saved by having a database dedicated solely to metaweb data. Different from Bit DB, this database will not store data associated with all transactions, but only those containing the metaweb flag. Some databases such as non-relational databases like MongoDB may be more efficient in storing the graph structure of the metaweb. This will allow for faster queries, lower storage space, and more efficient association of relevant content within the metaweb domain.
[0339] Figure 15 Illustrated is how the browser wallet interacts with a third-party search engine when a user searches for content within the metaweb infrastructure. Importantly, it should be noted that, in contrast to the Internet, there is no need for routing, so the present invention provides significant advantages in terms of efficiency, speed, processing, and required resources.
[0340] The process is as follows:
[0341] 1. The end user enters a keyword in the browser wallet search bar.
[0342] 2. The browser wallet sends the keyword query to the third-party SE.
[0343] 3. The SE checks the keyword against its database and returns the IDs of any metaweb nodes containing relevant content node . The third party may also return other indexes on each node to the user and provide suggestions for relevant content.
[0344] 4. The browser wallet constructs an MURL using the node identifier and the domain name associated with it.
[0345] 5. The browser wallet requests the content belonging to the specified node from any network peer having a full copy of the blockchain.
[0346] 6. The network peer provides the requested content to the browser wallet. Since the peer has a copy of the blockchain, it must also have a copy of the content, so only one request is made and the request is never forwarded to other network peers.
[0347] It should be emphasized that the third-party SE is only responsible for indexing and maintaining the property records of the metaweb nodes, while the original content data stored on the nodes is stored by network peers (e.g., full-copy peers, miners, archives) having a full copy of the blockchain.
[0348] Content Display - Meta-Network Browser
[0349] The browser wallet application emulates the same front - end capabilities that any typical web browser should provide. These functions include, but are not limited to:
[0350] 1. Search - Provide access to a search engine (SE) to locate content.
[0351] 2. Retrieve - Communicate with the server to facilitate the transfer of content using known protocols (e.g., Hypertext Transfer Protocol (HTTP)).
[0352] 3. Interpret - Parse the raw code (e.g., in JavaScript) and execute it.
[0353] 4. Render - Efficiently display the parsed content for the end - user to view.
[0354] 5. User Interface (UI) - Provide an intuitive interface for the user to interact with the content, including action buttons and mechanisms for user input.
[0355] 6. Storage - Local temporary storage capacity for caching Internet content, cookies, etc., to improve repeated access to content.
[0356] In some embodiments, the software component of the browser wallet application that is responsible for acting as a web browser is capable of performing the above - mentioned functions on the meta - web content embedded in the blockchain, which is searchable (using SE) and retrievable (from peers) using its attributes.
[0357] Reorganization, Decompression and Decryption
[0358] According to certain embodiments of the present invention, the web browser software component of the browser wallet application is capable of handling all the operations required to be performed on a given meta - web content. Generally speaking, there are many such operations to be performed, but we assume that at least the following operations are performed by the application using the meta - web protocol and infrastructure.
[0359] Re - assembly - In the case where the meta - web content needs to be fragmented and inserted into multiple separate node transactions, the application will request the content from all relevant nodes and reconstruct the original content. The sorting and structure of the fragmented content can be encoded using additional flags in the attributes of each node.
[0360] De - compression - In the case where the content data is stored in compressed form on the blockchain, a flag indicating which standard compression scheme has been used should be included to the browser wallet. The application will decompress the content according to this flag.
[0361] Decryption - In the case where the content is encrypted, a flag shall be used to indicate the encryption scheme. The application shall locate the key from its decryption key wallet (discussed below) and decrypt the content data for use according to the encryption scheme employed.
[0362] When performing these operations on the content data, the flag can be used to indicate to the browser wallet that a given operation needs to be performed. This applies to any other operation for which a suitable <operation_flag> can be included as part of the attributes of the node to which the operation is applied.
[0363] Cache
[0364] The caching of local files and cookies is a common and important feature of typical web browsers. The browser wallet application also uses local storage in a similar way to optionally save records of IDs related to the content of interest node and other node attributes. This allows for more efficient lookup and retrieval of content from frequently accessed metaweb nodes.
[0365] The metaweb addresses the inherent problem of caching Internet data, which is variable and can be changed or pruned by web browsing software according to the provider. When caching metaweb data, the user can always easily verify that the data is in the same state as when it was initially included in the blockchain as an immutable record.
[0366] Hierarchical Deterministic Key Management
[0367] The deterministic key Dk is a private key initialized from a single "seed" key. The seed is a randomly generated number that acts as the master key. A hash function can be used to combine the seed with other data (e.g., an index number or "chain code") (see, HD Wallet - BIP - 32 / BIP - 44) to derive the deterministic keys. These keys are related to each other and can be fully recovered from the seed key. If a user wishes to use an external wallet in combination with the metaweb browser wallet, this seed also allows for easy import / export of the wallet between different wallet implementations, thus giving additional freedom.
[0368] Hierarchical Deterministic (HD) wallets are a well - known method for deriving deterministic keys. In an HD wallet, a parent key generates a series of child keys, which in turn generate a series of grandchild keys, and so on. This tree - like structure is a powerful mechanism for managing several keys.
[0369] In a preferred embodiment, the HD wallet can be incorporated into Figure 15 the metaweb architecture as shown. Advantages of using an HD wallet include:
[0370] 1. Structure can use different branches of a child key to express additional organizational meanings for different purposes. For example, a user can dedicate different branches (and their corresponding child keys) to different types of data.
[0371] 2. Security A user can create a series of public keys without the corresponding private key, enabling the HD wallet to have a receive-only capability and be suitable for use on an insecure server. Moreover, since fewer secrets need to be stored, the risk of exposure is lower.
[0372] 3. Recovery If a key is lost / damaged, it can be recovered from the seed key.
[0373] Bypass Network Server
[0374] The present invention allows a new mechanism for a browser (client) and a web server to communicate and exchange information through distributed peer-to-peer Internet communication bypassing the Domain Name System (DNS) server and typical network routing programs. See http: / / www.theshulers.com / whitepapers / internet_whitepaper / The present invention provides a new network architecture including peers that maintain a full copy of the blockchain, from which content can be provided to a browser wallet application.
[0375] Local Full-Copy Peer
[0376] Consider a system of local peers in each geographical area (e.g., postal district, town, city). We assume that within this local area network, at least one peer maintains a full copy of the blockchain, and we refer to this peer as the Local Full Copy Peer (LFCP). For our purposes, the LFCP only needs to store blockchain transactions including the meta-network flag, but is not limited to this.
[0377] All users by default send 'get' requests to the LFCP. Since the peer maintains a complete and up-to-date copy of the entire blockchain, all requests can be satisfied because any node ID queried will be available to the LFCP. It should be noted that if the SE is powerful and large enough to store meta-network content and perform the main functions of a typical SE, the meta-network search engine can also act as the LFCP.
[0378] In the simplest case, each LFCP will have the same storage and disk space overhead, as each will need to be able to store the entire blockchain (about 200GB at the time of writing). The difference between each LFCP is that the LFCP should expand its capabilities to respond to the requirements of local requests from MetaNet users. Thus, if by default every MetaNet user in the world queries their closest LFCP, each LCFP should strive to expand its operating capabilities to meet its local requirements. Populated areas such as cities will require LFCP operations that include many cluster servers, while sparsely populated areas such as small towns will require fewer LCFP operations.
[0379] It is important to note that the disk space requirements are general, while the CPU requirements for each LFCP adapt to the local area network needs. This is an example of an adaptive network, for example, Freenet - see https: / / blockstack.org / papers / .
[0380] One advantage of such a system is that when retrieving content associated with a given ID node the user only needs to make a single (local) connection to their LFCP. The LFCP does not need to forward the request to other peers, as it is guaranteed to be able to provide the required content itself.
[0381] MetaNet offers many advantages over the Internet - for example, decentralization and deduplication - similar to other peer-to-peer (P2P) file sharing services such as IPFS. However, MetaNet improves these existing P2P models by ensuring immutability and, crucially, by removing the need to flood the network with requests for a given piece of content.
[0382] The MetaNet infrastructure is also robust to the failure of any one LFCP by employing a network of these peers. This means that if an LFCP is taken offline, the end user simply defaults to using their next closest LFCP. This can be made more efficient if the LFCPs communicate with each other to indicate which nearby peers are below or above capacity at any given time. This can allow users to send their requests to the most appropriate peer and establish a dynamic balance of request distribution between nearby LFCPs.
[0383] Global Full-Copy Peer
[0384] Now consider the scenario when the general disk space requirements become too large for smaller peers, which will happen as the MetaNet portion of the blockchain expands and grows with adoption.
[0385] In this case, the smaller LFCP should use its disk space capacity to store meta-network node transactions based on a popularity system (there is existing technology for volume of requests and essential rating content). This means that the LFCP now trims both its CPU (for request processing capabilities) and its storage allocation (for content serving capabilities) to adapt to its local geographical requirements in terms of both content volume and nature.
[0386] To address the fact that the LFCP can no longer store all meta-network transaction content, the concept of a Global Full-Copy Peer (GFCP) can be utilized. A GFCP is a full-copy peer with the following properties:
[0387] 1. The GFCP grows its disk space capacity to always maintain a full copy of the blockchain.
[0388] 2. The GFCP has considerable CPU resources such that it can handle significantly more requests compared to the LFCP. In case many LFCPs are compromised, the Global Full-Copy Peer should be able to handle a sudden increase in demand.
[0389] The GFCP has two main functions. First, it acts as a fail-safe for user requests for meta-network content when requests overflow from the LFCP. Second, the GFCP acts as an archival peer to store all meta-network content mined historically, which ensures that any meta-network node content can still be accessed even if many LFCPs omit some content from their local storage provisions.
[0390] Global database (data bank)
[0391] The concept of the GFCP is powerful and illustrates how the overall architecture of the meta-network provides a solution to an existing problem; creating a global database that encompasses everything.
[0392] Previously, it was not possible to securely construct a general and globally accessible database because a central authority was required to maintain the database. This central authority injected points of failure and trust into the system. Crucially, if we rely on one organization to store and maintain all Internet data, we need to trust that the organization operates correctly and legally without destroying the information.
[0393] Through the meta-network infrastructure, the two issues of trust and centrality are effectively removed from the concept of a global data center. Now, a GFCP can be created because it only depends on it to provide the disk space required for storage without verifying and authenticating the information to be stored.
[0394] Through the meta-network, the process of verifying the stored content is carried out by miners, so the general global database can be trusted because it cannot corrupt blockchain information. The GFCP does not need to be trusted and only needs to provide storage.
[0395] The fact that all GFCPs can store the same information that is always verifiable and provable for the blockchain itself means that information can be replicated among many such GFCPs.
[0396] This means that the problem of having a single point of failure is also solved by having many global databases exist in parallel and provably store the same information.
[0397] Figure 16 A system with two LFCPs and one GFCP is shown, and it is illustrated how each peer can support another peer in a network that is robust to the corruption of individual peers.
[0398] Aspects of the present invention that can be implemented in the embodiments of the browser wallet application described above provide many distinguishing features and advantages over the prior art, including but not limited to:
[0399] 1. Deterministic Keys - Hierarchical deterministic key management for both tokens and meta-network addresses is performed within the same wallet component of the application. This allows organizing keys by reducing their storage requirements and enabling multiple functions for key recovery.
[0400] 2. Payment Mechanism - The application allows consumers to pay merchants directly without pointing to another application or third-party payment service that would conventionally authenticate and provide trust. This allows for the purchase and delivery of digital content via the same blockchain platform.
[0401] 3. Bypass Network Servers - The application facilitates bypassing of conventional network servers that would conventionally handle large amounts of traffic, requests, and routing. This is because the application only needs to request content from a single LFCP, which ensures that requests do not need to be forwarded to other LFCPs to serve users. This reduces the total traffic and the completion time for each request.
[0402] 4. Timed Access - The application facilitates timed access to content by synchronizing with the blockchain and using the blockchain based on its current state to enforce access permissions. This removes the need for third-party services to monitor user privileges over time while protecting the rights of the original owners.
[0403] Use Case - Decentralized Application Store (Swapp Store)
[0404] The first use case (for illustrative purposes only) of the meta-network architecture presented here is decentralized payment and distribution for applications (apps).
[0405] Consider the following scenario: app developer Alice and consumer Bob wish to transact with each other. The transaction will take the form of an atomic swap, where a token is exchanged for a secret key that grants Bob access to the app data. The encrypted app data has been made public as part of a metaweb node transaction.
[0406] The app swapped at the atomic level is called Swapp. A third - party platform (Swapp Store) can be used to catalog and advertise apps existing on the metaweb, but the payment for and transfer of the access key to the user (e.g., Bob) do not need to involve any third party and can be done directly between the merchant and the consumer.
[0407] The following section details the process for buying and selling Swapp from when Alice creates the app to when Bob deploys it. Throughout the process, Alice and Bob will use their respective browser wallets to interact with the metaweb.
[0408] Release
[0409] 1. Alice writes the application. The data that makes up the application is <app>The content represented. She also uses the secret key S k to encrypt it as <e(App)>.
[0410] 2. Alice creates a node transaction ID AliceApp to set up her first meta-domain (tree). She generates 1AliceAppHtKNngkdXEeobR76b53LETtpy(P that will be used as the node address AliceApp ).
[0411] 3. Then, Alice creates the children of the first node to form a tree that corresponds to the meta-library of her application. Alice's tree domain is shown in Figure 17 .
[0412] One of the leaf nodes on this tree corresponds to her application with index ID App <app>The node. In this node, Alice inserts the encrypted application data <e(App)> into the input script (scriptSig) of the node. Using the secret key s k to encrypt the app data using the Koblitz method.
[0413] The node transaction is as follows.
[0414]
[0415] 4. Alice publicly broadcasts the ID AliceApp , P AliceApp and the domain name 'AliceApp'. This can be achieved via social media, internet websites or by using a third-party meta website.
[0416] Purchase
[0417] 1. Bob wants to download a puzzle game and sees Alice's app listed on the meta website (Swapp Store) viewed on his browser wallet.
[0418] 2. Then, Bob uses the information from the website to communicate with Alice and sets up an atomic swap. The swap is designed such that Bob will pay Alice the agreed price and Alice will reveal the secret key s k , or neither of these events will occur.
[0419] 3. The atomic swap is completed and Bob's browser wallet stores the secret key s k in its access key / token wallet.
[0420] Deployment
[0421] Bob now has the key s k that will allow him to decrypt the application data previously released by Alice. To download and deploy the app, Bob performs the following.
[0422] 1. Bob uses the meta web search engine (SE) to find the MURL associated with the encrypted app data <e(App)>. He uses the keywords 'AliceApp' and 'App' as the input to the search bar in his browser wallet. The third-party SE parses the query and returns the following MURL:
[0423] mnp: / / aliceapp / games / puzzle / app
[0424] This locator corresponds to the unique meta web node ID App , which includes the encrypted app data in its input script.
[0425] 2. Bob's browser wallet receives the MURL and then sends a request to the nearest appropriate LFCP. This peer provides Bob with the requested data <e(App)>.
[0426] 3. The browser wallet processes the data according to the attributes of the ID App This includes decrypting the application data using the secret key sk and processing <app>。
[0427] 4. Bob will apply <app>Downloaded from his browser to his computer. Now, Bob can deploy the application locally without having to repurchase access rights.
[0428] Figure 18 Illustrates the overall process outlined in the above illustrative use case. The flowchart shows two action branches: Alice's branch (starting on the left) and Bob's branch (starting on the right). The branch corresponding to Alice shows the initial release phase and the Bob branch shows the phase of setting up a purchase via an atomic swap.
[0429] On Bob's branch, he broadcasts the following transaction TxID Bob As the atomic swap setup phase:
[0430]
[0431] In this transaction, the output is locked by a private key puzzle that requires the secret decryption key s k To be revealed to Bob so that Alice can spend.
[0432] The branches of Alice and Bob in this figure converge at the point where Alice successfully completes the atomic swap transaction. This is achieved when Alice broadcasts the transaction TxID Alice When:
[0433]
[0434] Once this transaction is broadcast, the action branches of Alice and Bob diverge again. Alice receives payment of x tokens, while Bob receives the secret decryption key s k And is able to retrieve and decrypt Alice's application from the metanet.
[0435] Now turning to Figure 19 FIG. 2600 provides an illustrative simplified block diagram of a computing device 2600 that can be used to practice at least one embodiment of the present disclosure. In various embodiments, the computing device 2600 can be used to implement any of the systems shown and described above. For example, the computing device 2600 can be configured to act as a data server, a network server, a portable computing device, a personal computer, or any electronic computing device. As Figure 19 As shown, the computing device 2600 may include one or more processors (collectively 2602) having one or more levels of cache memory and a memory controller, which may be configured to communicate with a storage subsystem 2606 including a main memory 2608 and a persistent storage device 2610. As shown, the main memory 2608 may include dynamic random access memory (DRAM) 2618 and read only memory (ROM) 2620. The storage subsystem 2606 and the cache memory 2602 may be used to store information, such as details associated with transactions and blocks described in the present disclosure. The (one or more) processors 2602 may be used to provide the steps or functions of any of the embodiments described in the present disclosure.
[0436] The (one or more) processors 2602 may also communicate with one or more user interface input devices 2612, one or more user interface output devices 2614, and a network interface subsystem 2616.
[0437] The bus subsystem 2604 may provide a mechanism for enabling the various components and subsystems of the computing device 2600 to communicate with each other as expected. Although the bus subsystem 2604 is schematically shown as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses.
[0438] The network interface subsystem 2616 may provide an interface to other computing devices and networks. The network interface subsystem 2616 may serve as an interface for receiving data from other systems different from the computing device 2600 and for transmitting data to other systems. For example, the network interface subsystem 2616 may enable a data technician to connect a device to a network such that the data technician may transmit data to and receive data from the device while located at a remote location (e.g., a data center).
[0439] The user interface input device 2612 may include one or more user input devices, such as a keyboard; a pointing device such as an integrated mouse, trackball, touchpad, or graphics tablet; a scanner; a barcode scanner; a touchscreen incorporated into a display; an audio input device such as a voice identification system, a microphone; and other types of input devices. Generally, the use of the term "input device" is intended to include all possible types of devices and mechanisms for inputting information into the computing device 2600.
[0440] One or more user interface output devices 2614 may include a display subsystem, a printer, or a non-visual display such as an audio output device. The display subsystem may be a cathode ray tube (CRT), a flat panel device such as a liquid crystal display (LCD), a light emitting diode (LED) display, or a projector, or other display device. In general, the use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from the computing device 2600. One or more user interface output devices 2614 may be used, for example, to present a user interface to facilitate interaction of a user with an application that performs the described processes and variations thereof, when such interaction is appropriate.
[0441] The storage subsystem 2606 may provide a computer-readable storage medium for storing basic programming and data constructs that may provide the functionality of at least one embodiment of the present disclosure. When executed by one or more processors, application programs (programs, code modules, instructions) may provide the functionality of one or more embodiments of the present disclosure and may be stored in the storage subsystem 2606. These application program modules or instructions may be executed by one or more processors 2602. Additionally, the storage subsystem 2606 may provide a repository for storing data used in accordance with the present disclosure. For example, the main memory 2608 and the cache memory 2602 may provide volatile storage for programs and data. The permanent storage device 2610 may provide permanent (non-volatile) storage for programs and data and may include flash memory, one or more solid state drives, one or more magnetic hard disk drives, one or more floppy disk drives with associated removable media, one or more optical drives (e.g., CD-ROM or DVD or Blue-Ray) with associated removable media, and other similar storage media. Such programs and data may include programs for performing the steps of one or more embodiments as described in the present disclosure and data associated with the transactions and blocks described in the present disclosure.
[0442] The computing device 2600 may be of various types, including a portable computer device, a tablet computer, a workstation, or any other device described below. Additionally, the computing device 2600 may include another device that may be connected to the computing device 2600 through one or more ports (e.g., USB, headphone jack, lightning connector, etc.). The device that may be connected to the computing device 2600 may include a plurality of ports configured to accept fiber optic connectors. Thus, the device may be configured to convert an optical signal into an electrical signal that may be transmitted through a port that connects the device to the computing device 2600 for processing. Due to the ever-changing nature of computers and networks, Figure 19 The description of the computing device 2600 depicted is only intended as a specific example for the purpose of illustrating the preferred embodiments of the device. Many other configurations with more or fewer components than the Figure 19 system depicted are possible.
[0443] It should be noted that the above embodiments illustrate rather than limit the invention, and those skilled in the art will be able to design many alternative embodiments without departing from the scope of the invention as defined by the appended claims. In the claims, any reference signs in parentheses shall not be construed as limiting the claim. The word "comprising" etc. does not exclude the presence of elements or steps other than those listed in any claim or the whole specification. In this specification, "comprise" means "include or consist of", "comprising" means "including or consisting of". The singular form of an element does not exclude the plural form of such element and vice versa. The invention may be implemented by means of hardware including several distinct elements and by means of a suitably programmed computer. In a device claim enumerating several components, several of these components may be embodied by one and the same piece of hardware. The fact that certain means are recited in mutually different dependent claims does not indicate that a combination of these means cannot be used to advantage.< / app> < / app> < / app> < / app> < / lzw> < / n> < / m> < / n> < / m> < / s> < / content> < / attributes>
Claims
1. A method for performing an atomic swap using blockchain transactions, the atomic swap revealing access data that enables access to data stored on a blockchain, the method comprising: Establishing a shared secret S known only to a first participant and a second participant; Generating, by the second participant, at least one first blockchain transaction of the blockchain, wherein first data is stored in the at least one first blockchain transaction and, without first access data, the first data is inaccessible to the first participant; and Generating, by the first participant, a second blockchain transaction of the blockchain, wherein the second blockchain transaction is spendable by the second participant using a script when the second participant broadcasts the second blockchain transaction to a blockchain network, the script enabling the first access data to be obtained on the blockchain by the first participant; Wherein: i) the first access data includes a preimage for solving a hash puzzle and the second blockchain transaction includes the preimage, wherein the shared secret S is added to the preimage; or ii) the first access data includes a private key and the second blockchain transaction includes a solution to a private key puzzle, the solution enabling the first participant to compute the private key, wherein the private key puzzle uses the shared secret S as a temporary key k0 in the computation of a component r0 of a digital signature used in the private key puzzle.
2. The method according to claim 1, wherein The at least one first blockchain transaction has at least one corresponding input that is a corresponding output of a previous blockchain transaction, wherein the output is redeemable by a corresponding private key of a cryptosystem and the first data is encrypted by the cryptosystem.
3. The method according to claim 1 or 2, wherein, The first participant's access to the first data enables the first participant to store additional data in at least one third blockchain transaction related to the at least one first blockchain transaction.
4. The method according to any one of the preceding claims, wherein, The second blockchain transaction includes second data representing at least one token.
5. The method according to claim 4, wherein, At least one of the tokens is at least one of a plurality of tokens generated by repeated application of a one-way function.
6. The method according to claim 4 or 5 further comprises: Generating at least one fourth blockchain transaction for refunding at least part of the second data without redeeming at least one output of the second blockchain transaction.
7. The method according to claim 6, wherein, At least one of the fourth blockchain transactions has at least one output that is redeemable only after a predetermined time period.
8. The method according to claim 6 or 7, wherein At least one of the fourth blockchain transactions has at least one output that is redeemable only after a predetermined number of blocks.
9. The method according to any one of the preceding claims, wherein The at least one first blockchain transaction has at least one output that is redeemable by the script, the script enabling the first access data to be obtained on the blockchain by the first participant.
10. The method according to claim 9, wherein, The script contains data enabling determination of an input to a one-way function.
11. The method according to claim 10, wherein, At least one of the one-way functions is a hash function.
12. The method according to any one of claims 9 to 11, wherein, The script contains data enabling the first participant to determine the private key in a public-private key pair.
13. The method according to any one of the preceding claims, further comprising: A first secret is securely shared between the first participant and the second participant to enable determination of data that enables the first access data to be accessible to the first participant.
14. A computer-implemented system, comprising: a processor; and a memory including executable instructions which, when executed by the processor, cause the system to perform any implementation of the computer-implemented method according to any one of claims 1 to 13.
15. A non-transitory computer-readable storage medium having stored thereon executable instructions which, when executed by a processor of a computer system, cause the computer system to perform at least an implementation of the method according to any one of claims 1 to 13.
Citation Information
Patent Citations
Determining a common secret for the secure exchange of information and hierarchical, deterministic cryptographic keys
WO2017145016A1