Methods for providing status channels

By establishing state channels between entities through the SSI mechanism and using decentralized tokens and public keys to achieve direct encrypted communication, the problem of low efficiency of state channels in DLT systems is solved, and fast, secure communication connections and privacy protection are achieved.

CN114374731BActive Publication Date: 2026-06-30ROBERT BOSCH GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ROBERT BOSCH GMBH
Filing Date
2021-10-14
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

In existing distributed ledger technology (DLT) systems, the establishment of state channels and the execution of transactions are inefficient, making it impossible to achieve fast and secure communication connections without relying on DLT systems.

Method used

By using the Self-Sovereign Identity (SSI) mechanism, decentralized tokens and public keys are exchanged between entities using peer-to-peer protocols, establishing secure state channels and enabling direct encrypted communication connections, thus avoiding transactions through DLT systems.

Benefits of technology

It enables fast and secure exchange of state information between entities, reduces transaction costs, provides privacy protection and scalability, and simplifies the transaction process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114374731B_ABST
    Figure CN114374731B_ABST
Patent Text Reader

Abstract

This invention relates to a method for providing a state channel. The invention relates to a method for providing a state channel (140) between a first entity (110) and a second entity (120) in a network (100) to exchange messages about transactions using a distributed ledger technology, wherein the first entity (110) and the second entity (120) each have decentralized tokens (112, 122) and instructions (113, 123) for operating the decentralized tokens in the network (100), wherein, in order to establish the state channel (140) according to a peer-to-peer protocol (115, 125) for the decentralized tokens of the first entity (110) and the second entity (120), a new decentralized token as a user token and a public key (116, 126) for the corresponding user token are exchanged between the first entity (110) and the second entity (120), and wherein, by means of the user token and the public key (116, 126), the exchange of messages containing information representing the state between the first entity (110) and the second entity (120) is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for providing a state channel, and a computing system, network, and computer program for performing the method. Background Technology

[0002] The term "Distributed Ledger Technology" (DLT) describes a form of database system characterized by shared and synchronized data maintenance and continuous cryptographic links to the data in a peer-to-peer network. Blockchain represents a specific construction of this technology. Other constructions include Directed Acyclic Graphs (DLTs). Here, information is stored in blocks, cryptographically linked together, and redundantly stored on every node of the network via a peer-to-peer protocol, meaning the same information or data exists at every user's location on the network. This distributed network of independent computers (nodes) communicating and synchronizing with each other verifies and confirms these blocks via a so-called consensus mechanism. The most commonly used consensus mechanism in Bitcoin and Ethereum blockchains is called "Proof of Work." Furthermore, various alternative consensus mechanisms exist, each offering certain advantages and disadvantages depending on the specific construction scheme of the DLT network.

[0003] Furthermore, most second-generation DLT solutions offer the possibility of defining and using so-called "smart contracts." Smart contracts are program code that can be written into the DLT and correspondingly executed redundantly or verifiably by all users on the DLT network. Thus, DLT can not only be used for secure data storage but also for mapping and executing business logic. With the aid of so-called "state channels" (in this case, involving a (secure) communication connection), such "smart contracts" can be executed without communication with the relevant database ("Ledger") while still retaining guaranteed characteristics. Once a "state channel" is created or established, "smart contracts" can be efficiently (in the best case, even in real-time) concluded and executed between the creators. Summary of the Invention

[0004] According to the present invention, a method for providing a state channel, as well as a computing system, a network, and a computer program for performing the method are proposed. Advantageous construction schemes are then described.

[0005] This invention explores providing a state channel and a secure communication connection via it between a first entity and a second entity in a (e.g., decentralized) network, particularly the “state channel” mentioned at the beginning, for exchanging messages about transactions related to distributed ledger technology using a peer-to-peer protocol for decentralized tokens, particularly according to the SSI mechanism (“Self-Sovereign Identity”).

[0006] In other words, a "State Channel" can be referred to as a state channel that, particularly without using a DLT system or said DLT system, enables the exchange of messages containing state or information representing state between at least two parties or entities. A "State Channel" is a logical connection using an SSI channel as the technical connection. Therefore, different states or corresponding information can be exchanged relatively quickly via a State Channel without requiring corresponding transactions in the DLT system. Consequently, transactions executed via a State Channel can also be called "off-chain" transactions. For example, exchanging new state updates; in the case of payment channels, this is digital bookkeeping.

[0007] Inspired by DLT, decentralized solutions for digital tokens or identities have been developed, including important standards such as so-called "Verifiable Credentials" (VCs) and so-called "Decentralized Identifiers" (DIDs, in this case involving decentralized tokens). These technologies can be summarized under the term SSI ("Self-Sovereign Identity"). The main characteristic of SSI is a peer-to-peer scheme secured by public and private keys through cryptography, representing a paradigm shift away from user account schemes with centralized or federated identity models.

[0008] Existing decentralized tokens can be, in particular, “decentralized identifiers” (DIDs), which contain characteristics and interfaces, especially those of so-called SSI agents. It acts as a trustee for, for example, an entity (or a holder of a token or identity), and includes, for example, a cryptographic key embodying delegated authorization and interacting with, for example, a suitable protocol. The invention will then be explained in more detail, exemplarily, based on this particular type of communication connection, decentralized token, and network.

[0009] For example, an entity can be a computing system or computing unit, such as a computer, but it can also be such a computing system or computing unit assigned to a device within the scope of the Internet of Things (IoT). Communication in a (decentralized) network utilizes communication interfaces, such as via the transport layer, such as Bluetooth, WLAN, NFC, email, or other suitable protocols.

[0010] Within the scope of this invention, according to a peer-to-peer protocol for decentralized identifiers of a first entity and a second entity, new decentralized identifiers are exchanged between the first entity and the second entity as user identifiers, and public keys for the corresponding user identifiers are also exchanged. The user identifiers and public keys are preferably components of data records used for decentralized communication, which may, for example, identify the corresponding entities, and these data records may be, for example, so-called "DID documents," and by exchanging the relevant data records, especially the user identifiers and public keys, the exchange of messages containing information representing the state between the first entity and the second entity is guaranteed, and this is then carried out entirely in an encrypted manner.

[0011] As a peer-to-peer protocol, the so-called "Peer DID Method" is particularly under consideration, which is a protocol built on the aforementioned DID and specifically designed for peer-to-peer communication between two entities (i.e., without any intermediary or central entity). Each user (in this case, the first and second entities) must also act according to the rules of this protocol. In this context, the data record can also be referred to as "DID: Peer Document".

[0012] Specifically, according to the "sibling DID method," but also commonly in peer-to-peer protocols, the first entity may first extend an invitation (not yet encrypted) to the second entity to provide a state channel or communication connection. The second entity then sends a (subsequently encrypted) connection query to the first entity, which includes, for example, the aforementioned data record for the second entity. In response, the first entity then sends a connection acceptance, which includes, for example, the aforementioned data record for the first entity. In this case, the respective public keys can be used as user identifiers.

[0013] In this way, these entities can agree on a secure communication connection, particularly with a defined identifier, such as a so-called "State Channel ID" (SCID), and thereby create an initial state. The initial state specifically includes the initial conditions within a state channel, for example, in the case of a payment channel, containing the initial balance to be collected by two entities or parties in a "Funding Protocol." Both entities execute the corresponding establishment protocol or "Funding Protocol" for the communication connection or "channel." This can be entirely independent of the SSI infrastructure or decentralized network used, as communication with the DLT network is required.

[0014] Both entities can use a secure communication connection established in this way, such as a "DID: peer" communication channel, to exchange encrypted information or "status" signed with corresponding keys. This (especially using the aforementioned "DID: peer") ensures that the content can only be decrypted by separate entities and can be verified using the relevant keys.

[0015] If no longer needed, a secure communication channel or "state channel" can be closed or terminated by one of the entities, for example, directly via DLT using a "smart contract." The same applies to so-called "dispute handling." This communication does not occur via a secure communication channel or "DID: sibling" between entities.

[0016] Therefore, this invention uses SSI, representing a decentralized foundation for identity, which thus acts as a so-called "Common Trust Layer," that is, a layer or foundation for common secure communication, or more precisely, a layer or foundation for very different applications. Since it is already possible, in principle, to establish a so-called "persistent connection" between two entities (see also "Preukschat, Dred (2020): Self-Sovereign Identity" (Manning)) via SSI, these entities are cryptographically secured and explicit, thus these entities are already endowed with "out-of-the-box" or pre-built characteristics for secure communication connections or so-called "state channels," such as explicit user identifiers. Compared to persistent connections, state channels are a logically direct connection with the possibility of sending transactions directly, rather than via DLT. State channels require a transport layer, in this case, for example, the DID: peer of SSI.

[0017] Furthermore, SSI-based communication connections or channels are implemented as direct connections between entities, which adds value to "state channels" because these "state channels" can use existing connections and are therefore already secured. Moreover, through the SSI mechanism, certain characteristics between entities can be secured, such as privacy, scaling (see also "Daniel Hardman et al. (2020): Peer DID Method Specification"), or "Know-Your-Customer" (KYC).

[0018] Furthermore, because specific generation of "DID: sibling" is required for each desired communication connection, it becomes more difficult from the outside to understand who maintains the secure communication connection or "state channel" with whom, since the user identifier for each connection is explicit. This represents a type of "key rotation." This mechanism can be used to reconcile the protection of privacy with security guarantees achieved through cryptographic methods. For this purpose, a (currently) dedicated key can be used for different application scenarios, or the key can be changed over time to prevent the association between the key and the identifier (or identity). "Key rotation" is discussed here if a new key pair is used in a defined application at a specific location over time.

[0019] Specifically, the present invention therefore relates to a scheme in which a "state channel" is established between a first entity and a second entity when using a peer-to-peer DID method, and then messages about DLT transactions are exchanged via this "state channel". In particular, an interface is provided between the "state channel framework" and the adopted peer-to-peer DID method.

[0020] This interface consists of two parts: "interface integration" for communication with SSI agents to send and receive messages; and integration of current "DID:sibling" parameters, such as an explicit "public ID" for the state channel, contained in the DID:doc (specification). This interface can be used as a "Participant ID" (user identifier) ​​within the "state channel." This ensures that the "state channel" is established with whom.

[0021] Next, messages specific to the "state channel" are exchanged via the interface, such as an initial state, which describes what each party must provide via DLT. Furthermore, new states can also be exchanged, which must be formed and signed by both parties.

[0022] The "state channel framework" is primarily composed of smart contracts running on DLT or similar platforms. These smart contracts implement specific protocols and procedures for establishing a "state channel," and also cover situations involving disputes. Furthermore, the required parameters are specified in detail, relating to states that must be signed by both parties to be considered valid.

[0023] The "State Channel Framework" executes DLT messages to establish a channel. Furthermore, the "State Channel Framework" sends necessary messages, such as new states that must be acknowledged, to other entities via the "DID:Sibling" channel.

[0024] This invention also relates to a computing system with a communication interface, having a decentralized identifier and instructions for operating the decentralized identifier in a decentralized network. The computing system is configured to provide a state channel or secure communication connection via the decentralized network to another computing system with a communication interface, wherein the other computing system also has a decentralized identifier and instructions for operating the decentralized identifier in the decentralized network. Here, the computing system for establishing the state channel is configured to generate and transmit a new decentralized identifier as a user identifier and a public key for that user identifier to the other computing system according to a peer-to-peer protocol for the decentralized identifier, and to receive the decentralized identifier as a user identifier and the public key of the other computing system, thereby ensuring message exchange with the other computing system regarding the state channel using the user identifier and the public key. In particular, the computing system can here perform all other steps performed by one of the entities according to the foregoing description.

[0025] The (decentralized) network according to the invention comprises two computing systems with communication interfaces, and is particularly configured in terms of programming technology to execute the method according to the invention.

[0026] This invention is suitable for providing secure communication between two users, or for providing any type of communication connection in which secure message exchange is expected or necessary. The invention is also suitable for providing secure communication, for example, in cases of economic interaction between entities that require payment.

[0027] Depending on the type of implementation, the required processes can be performed partially manually or automatically via a so-called intelligent agent, simply by informing the agent of whom to establish a state channel. Then, the "DID: sibling" protocol is executed first, followed by the remaining "state channel" protocols. This intelligent agent can be implemented as software in any computing unit, such as in the control device of any device (in smart devices, such as mobile phones, tablet PCs, home appliances, such as refrigerators, consumer electronics, but also in machines and facilities or vehicles).

[0028] An embodiment of the method according to the invention, in the form of a computer program for performing all the method steps or a computer program product having program code, is also advantageous because it results in particularly low costs, especially when the control device performing the execution is also used for other tasks and is therefore already present. Suitable data carriers for providing the computer program are, in particular, magnetic, optical, and electrical memories, such as, for example, hard disks, flash memory, EEPROM, DVDs, and others. The program may also be downloaded via a computer network (Internet, intranet, etc.).

[0029] Other advantages and construction methods of the present invention will become apparent from the specification and the accompanying drawings. Attached Figure Description

[0030] The invention is schematically illustrated with reference to the embodiments shown in the accompanying drawings, and is described below with reference to the drawings.

[0031] Figure 1 The following network is schematically illustrated, in which the method according to the invention can be performed.

[0032] Figure 2 The process of the method according to the invention in a preferred embodiment is illustrated schematically. Detailed Implementation

[0033] exist Figure 1 The diagram schematically illustrates a network 100 in which the method according to the invention can be executed, and in a preferred embodiment, the network 100 can also be constructed as a network according to the invention. The decentralized network 100 exemplarily includes two computing systems 110 and 120, which are interconnected to the entire network 100 via suitable communication interfaces 111 and 121 and corresponding communication connections 130. Even though computing systems 110 and 120 are shown separately here, they belong to (only schematically depicted here) network 100.

[0034] Network 100 can be a so-called DLT network or "distributed ledger technology" network, and communication connection 130 is a corresponding DLT communication connection.

[0035] In the context of this invention, the computing systems 110 and 120 of the first entity 110 and the second entity 120 can be viewed as each having a so-called DID as a decentralized identifier 112 and 122, and instructions or smart agents 113 and 123 for operating the corresponding decentralized identifier in the network 100 to implement the SSI mechanism. The DID in this case is not necessarily related to the DLT network to be used; the DID can be anchored in an identity network, which can be a DLT, but is not necessarily a DLT. The DLT shown is, for example, related to state channels or smart contracts. For this purpose, suitable software is executed on the computing systems, for example, to provide or represent these functions. For example, the software can also be used to execute or implement peer-to-peer protocols 115 and 125.

[0036] Furthermore, each computing system has a data record with at least one public key 116 or 126 and appropriate "service endpoints" 117 or 127. In this case, for example, a network address (e.g., an HTTP URL) is involved where business operations targeting entities are performed.

[0037] Using point-to-point protocols 115 and 125, computing systems 110 and 120 can now establish or provide state channels or secure communication connections 140, or so-called "State Channels," through which direct and encrypted communication about the state channels is possible. For example, the DID:Sibling Protocol is executed here to establish direct communication. If this direct communication is established, the connection is created as a state channel, that is, messages related to the state channel are exchanged via this channel.

[0038] Therefore, in Figure 2 The diagram illustrates the flow of the method according to the invention in a preferred embodiment, and more specifically, in view of establishing the aforementioned secure communication connection or state channel. Exemplarily, a first entity or computing system 110 transmits an invitation 200 to a second entity or computing system 120, using the second entity or computing system 120 to inquire about or request the establishment of a secure communication connection. This invitation may be transmitted in an unprotected or unencrypted manner.

[0039] To fulfill an expectation or invitation, the second entity or computing system 120 sends a connection query 210 to the first entity or computing system 110. This, in particular, transmits a data record of the second entity including a public key that also serves as the user identifier for the second entity.

[0040] The first entity or computing system 110 receives the connection query 210 and then transmits a response 220. Next, it transmits, in particular, a data record of the first entity including a public key that is also used as a user identifier for the first entity.

[0041] In this way, a secure communication connection can be established, through which communication can then be conducted in a protected and encrypted manner. For this purpose, relevant keys are used, in which each entity has obtained and thereby knows the public keys of other entities.

Claims

1. A method for providing a state channel (140) between a first entity (110) and a second entity (120) in a network (100) for exchanging messages about transactions related to a distributed ledger technology. The first entity (110) and the second entity (120) respectively have decentralized flags (112, 122) and instructions (113, 123) for operating the decentralized flags in the network (100). In order to establish the state channel (140) according to the peer-to-peer protocol (115, 125) for decentralized tokens of the first entity (110) and the second entity (120), a new decentralized token is exchanged between the first entity (110) and the second entity (120) as a user token from each of the two entities, and public keys (116, 126) for the corresponding user tokens are exchanged respectively. The user identifier and the public key (116, 126) ensure that the exchange of messages containing information representing the state between the first entity (110) and the second entity (120) is guaranteed.

2. The method according to claim 1, wherein, The user identifier and the public key (116, 126) are components of the corresponding data records used for decentralized communication between the first entity (110) and the second entity (120), and are exchanged as components of the data records.

3. The method according to claim 1, wherein, In order to establish the state channel (140), the first entity (110) first sends an invitation (200) to the second entity (120) to establish the state channel (140).

4. The method according to claim 3, wherein, If a state channel is to be established, the second entity (120) sends a connection query (210) to the first entity (110) in accordance with the invitation (200). The connection query (210) includes the user identifier and the public key (126) of the second entity (120).

5. The method according to claim 4, wherein, The first entity (110) sends a response (220) to the second entity (120) in accordance with the connection query. The response (220) includes the user identifier and the public key (116) of the first entity (110).

6. The method according to any one of claims 1-5, wherein, The public keys (116, 126) are used as user identifiers.

7. The method according to any one of claims 1-5, wherein, Messages about the state channel are exchanged between the first entity (110) and the second entity (120) in a secure manner.

8. The method according to any one of claims 1-5, wherein, The first entity (110) and / or the second entity (120) are configured as a computing system having communication interfaces (111, 121).

9. A computing system having communication interfaces (111, 121), the computing system having a decentralized flag (112, 122) and instructions (113, 123) for operating the decentralized flag in a network (100), the computing system being configured to provide a state channel (140) via the network (100) to another computing system having a communication interface, wherein the other computing system also has a decentralized flag and instructions for operating the decentralized flag in the network. The computing system used to establish the state channel (140) is configured to, according to a peer-to-peer protocol (115, 125) for decentralized tokens, transmit a new decentralized token as a user token and a public key (116, 126) for the user token from the computing system to the other computing system, and receive the decentralized token of the other computing system as a user token and the public key (126, 116) of the other computing system. The user identifier and the public key (116, 126) ensure message exchange with the other computing system regarding the state channel.

10. A network (100) having two computing systems with communication interfaces (111, 121), said computing systems being configured to perform all method steps performed by an entity according to any one of claims 1 to 8.

11. A computer program product comprising a computer program that, when executed on a computing system, causes the computing system to perform all the method steps of the method according to any one of claims 1 to 8, performed by a first entity or a second entity.

12. A machine-readable storage medium storing a computer program that, when executed on a computing system, causes the computing system to perform all the method steps of the method according to any one of claims 1 to 8, performed by a first entity or a second entity.