Agricultural product certification system
Patent Information
- Application Number
- EP2024715793
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-28
- Filing Date
- 2024-03-28
- Publication Date
- 2026-02-11
AI Technical Summary
Current agricultural product certification systems are costly and invasive for smallholders, particularly in less developed countries, and compromise data privacy, as they require extensive auditing and data disclosure, leading to an information advantage for certification authorities that can be exploited for financial gain.
A computer-implemented method for authenticating agricultural harvests using a machine learning model to determine a confidence score, allowing for the issuance of harvest certificates without full control over cultivation steps, thereby reducing privacy concerns and maintaining data sovereignty.
This approach reduces the costs and privacy concerns associated with certification, allowing for efficient and trustworthy authentication of agricultural products while maintaining data privacy and sovereignty for farmers, enabling them to control the disclosure of their information.
Smart Images

Figure 000036 
Figure 000037 
Figure 000038
Abstract
Description
[0001] AGRICULTURAL PRODUCT CERTIFICATION SYSTEM
[0002] The present invention is concerned with the field of agricultural product certification. In particular, the invention is concerned with a method of authenticating a harvest of an agricultural product. Authentication and thus the issuance of a harvest certificate depends on a computer-implemented validation that the harvest was indeed obtained from a previously certified quantity of a corresponding agricultural starting material, preferably by the determination of a respective confidence score. The confidence score is obtained using a computer model, preferably a machine learning model. The result of the method can be stored preferably in a tamper evident database. Furthermore, the invention is concerned with the updating of the model of an authentication method, the merging and splitting of harvest certificates, and apparatuses, computer systems storage media etc. useful for or used in one of the aforementioned settings.
[0003] BACKGROUND OF THE INVENTION
[0004] Certification of agricultural products has been described as a valuable means not only to ensure trust in value chains, for example of organic food and feed, but also to improve farmers' access to new markets. For example, the Committee on Sustainability Assessment has found in a study in 2013 that certified producers of coffee and cocoa had, on average, a higher level of access to training, increased on-farm biodiversity, increased yields and a significantly higher household income. Correspondingly, certification systems have also been described in patent literature, for example in WO2011124951 , WO2012047834 and WO2022140465. Agricultural product certification can, in principle, be done using conventional, for example paper-based, certificates. However, issuance of digital certificates is preferred.
[0005] Certification systems generally entail complete traceability of all relevant agronomic steps throughout the certified section of the value chain. This is generally achieved by tagging each individual certified item by an individual certificate and recording its path through the value chain, for example in terms of physical locations over time or the application of treatment methods such as pest control, irrigation and so on, and adding the tracked information to the original certificate or issuing new certificates for such new information. While such methods may be sufficient for end products such as trees which are planted once and are then grown until the end of their lifetime, agricultural production poses an innate challenge: one of the main purposes of agriculture is the multiplication of agricultural products. For example seeds, after being sowed, essentially cease to exist. They turn into plants which produce respective fruit, e.g. new seeds. Thus, the certificate issued for the starting material ceases to be relevant; instead, a completely new certificate for the harvested material is required. Issuance of a new certificate, however, again requires recording of extensive data.
[0006] Since the emergence of certification system it has become apparent that certification is so far linked to several problems. For example, participation in a certification system comes with a rather high cost, particularly for smallholders in less developed countries. The costs arise mainly due to the need for complex auditing and documentation procedures. Furthermore, particularly smallholders become imprisoned in only one certification system due to the inherent costs and oftentimes conflicting plant cultivation criteria prescribed by different certification providers. However, certification systems also create problems for participants on a more profound level: participation in a certification system involves total or near-total disclosure of all agriculturally relevant data by the participants to a central certification authority. In effect, participants are effectively fully transparent to the certification authority, they lose privacy and "data sovereignty". Due to the acquisition of data from all participants in the value chain segment (seed providers, farmers, processors (e.g. mills, roasters, merchants etc.) the certification authority has gained an information advantage over each participant. This information advantage can be leveraged by selling data to interested entities for their private financial benefit without providing any compensation to the certification system participants who provide those data in the first place. Thus, the built-in lack of privacy and data sovereignty essentially favours actors other than, for example, seed providers and farmers.
[0007] Publication CN108416600 describes a crop anti-counterfeiting method, wherein the crop status of the same crop varieties in a farming area based on the stored growth templates of each crop variety is compared, and if the similarity between the crop status of the crop variety in the cultivated area and the corresponding growth template stored on the platform is less than a preset value, it is confirmed that the cultivated crop variety information uploaded by the grower is inconsistent with the actual crop variety. However, this system depends on comparing crop status data obtaining by several farmers, such that crop variety information is uploaded by various farmers, and corresponding crop variety information corresponding to the platform accounts of various farmers is stored; each farming area is also equipped with real-time monitoring cameras for recording various farming operation and thus forms a complete surveillance system. The method thus does not overcome the aforementioned privacy concerns.
[0008] Publication US2010023430 describes a system and method for coordinating production, processing and utilisation of seed. The publication is not helpful for authenticating harvests outside of a closed loop and complete surveillance system. Publication CN111221906 describes another plant seed management system.
[0009] Publication US2021378161 describes a farm management system and related apparatus and operations including providing environmental monitoring and control systems, tracking seed sources, managing cultivation, growth, and harvest, improving enclosure operations, and managing system data. The management system is concerned with improving management of an individual farm and does not address the needs of an independent authentication authority tasked with authenticating harvested material.
[0010] It was thus the goal of the present invention to ameliorate, reduce or abolish one or more of the above-mentioned disadvantages of current digital or non-digital agricultural product certification systems.
[0011] SUMMARY OF THE INVENTION
[0012] The invention provides a computer-implemented method of authenticating a harvest of agricultural material, comprising the steps of i) providing seed certificate data associated with a starting material, wherein the seed certificate data comprises a designation of the type of starting material, a designation of the quantity of starting material, and preferably a designation of the recipient of the starting material, a request for a harvest certificate, and context data associated with harvested offspring material, wherein the context data comprises a designation of a type of harvested material, a designation of a quantity of harvested material, a designation of the requester of the harvest certificate, and optionally a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested offspring material, ii) validating the request for the harvest certificate based on the seed and context data, iii) providing the result of the validation.
[0013] The invention furthermore provides a method of updating a model of an authentication method of the invention by machine learning, comprising the steps of i) receiving one or more model parameters of the model, ii) inferring, based on context information and / or verification information provided in said authentication method, a change in at least one corresponding model parameter, and iii) updating the at least model parameter by the inferred changes.
[0014] Also provided according to the invention is a computer storage medium storing computer-readable instructions which, when used on a computing node, allows the computing node to execute a program for performing the steps of a computing node of the authentication method of the invention.
[0015] And the invention provides a computer system comprising one or more authentication computing nodes configured to perform the method of the invention.
[0016] Furthermore, the invention provides an apparatus comprising i) a data providing interface configured to provide seed certificate data comprising a designation of the type of starting material, a designation of the quantity of starting material, and preferably a designation of the recipient of the starting material, a request for a harvest certificate, and context data associated with harvested offspring material, wherein the context data comprises a designation of a type of harvested material, a designation of a quantity of harvested material, a designation of the requester of the harvest certificate, and optionally a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested offspring material, ii) a validation engine configured to validate the request for the harvest certificate based on the seed and context data, iii) a data providing interface configured to provide the result of the validation.
[0017] Further technical teachings also provided by the invention are described in the detailed description of the invention including the examples’ section hereinafter.
[0018] DETAILED DESCRIPTION OF THE INVENTION
[0019] Correspondingly the invention provides a computer-implemented method of authenticating a harvest of an agricultural product. Within the present disclosure the term "authenticating", "authentication" and the like refer to a key step in any certification system, namely the decision whether or not to issue a certificate. Thus, according to the present invention a harvest certificate is or is not issued. The harvest certificate certifies that a respective harvest, i.e. a physical quantity of a harvested agricultural product, indeed conforms to applicable certification criteria.
[0020] The authentication method comprises i) providing, seed certificate data associated with a starting material, wherein the seed certificate data comprises a designation of the type of starting material, a designation of the quantity of starting material, and preferably a designation of the recipient of the starting material, a request for a harvest certificate, and context data associated with harvested material, wherein the context data comprises a designation of a type of harvested material, a designation of a quantity of harvested material, a designation of the requester of the harvest certificate, and optionally a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested material, ii) validating the request for the harvest certificate based on the seed and context data, iii) providing the result of the validation.
[0021] The invention advantageously allows to certify a harvest without having full control and supervision over all cultivation steps, thereby alleviating privacy concerns inherent in common certification schemes.
[0022] According to the invention, reference is made to "certificates" and corresponding "certificate information". The term certificate means a proof of a one-to-one relationship between a physical object and the record, in a database, of information pertaining to said physical objects (certificate information). Thus, one and only one certificate can be validly issued for the same physical object. Even though several copies (also called "instances") of the certificate information may be recorded, e.g. in separate databases for example for backup purposes, each certificate information record is accessible by the same identifier ("token") and contains the same values of certificate information. Depending on context, the term "certificate" can thus be used to mean that said one-to-one relationship between an object and a database record of certificate information exists; the term can however in other contexts refer to the identifier or token which allows to look at the certificate information recorded in the database.
[0023] Certificates can be revoked. Revocation could be performed by deletion of the certificate information from the database in all copies thereof. Preferably, however, revocation is performed by creating a further database record to indicate the end of the certificate's validity. The further record can be written to the same database as the certificate information record or to a further database (control database). The advantage of creating a further record instead of deleting the recorded certificate information is that the original certificate information can, in principle, still be inspected. Furthermore, particularly in tamper-proof databases like blockchain databases record deletion is impossible or requires a lot of effort for synchronisation over all copies of the database.
[0024] Correspondingly, a certificate can be updated, that is, the certified information can be changed, by updating all copies of the certificate information in the database(s). Preferably, however, updating is performed by revoking the original certificate and issuing a new certificate, i.e. recording the updated certificate information in a new database record and creating a unique identifier (the certificate or token) to enable access to the certificate information. Preferably the updated certificate information contains a link to the certificate information of the revoked certificate, thereby allowing to trace the history of certified information. Updating a certificate by issuing a new certificate is particularly advantageous in tamper-evident databases like blockchain-type databases, because it is extremely laborious or impossible due to the tamper-evident nature of the database to alter recorded information.
[0025] According to the present invention, the agricultural product can be of essentially any kind. In particular, the agricultural product can be an animal- or plant-based product. Examples of animalbased agricultural products are individual animals or sets of animals. The animals can be of any kind or life stage. For example, the animal can be cattle, pigs, poultry, fin fish or shellfish. However, according to the invention it is preferred that the harvest certificate applies to a plant-based agricultural products. Further preferably, the harvest certificate applies to a set (also called a quantity) of individual plant-based materials. In particular, the harvest certificate can apply to a quantity of seed. The term "seed" is meant herein to designate any plant-based material which is essentially consumed as described above in the production of new plant-based material of the same kind. It is particularly preferred that "seed" refers to kernels, grains or other plant seeds. The respective plant can be of any kind. In particular, the plant can be a food, feed and / or ornamental plant. Thus, all mentions of agricultural products, agricultural starting material, offspring material and the like are to be understood to refer, most preferably, to seeds as described above.
[0026] Preferred agricultural products are plants and / or seed including those of: durum and other wheat, rye, barley, triticale, oats, rice, or maize (fodder maize and sugar maize I sweet and field corn); beet, e.g. sugar beet or fodder beet; fruits, such as pomes, stone fruits or soft fruits, e.g. apples, pears, plums, peaches, nectarines, almonds, cherries, papayas, strawberries, raspberries, blackberries or gooseberries; leguminous plants, such as beans, lentils, peas, alfalfa or soybeans; oil plants, such as rapeseed (oilseed rape / canola), turnip rape, mustard, olives, sunflowers, coconut, cocoa beans, castor oil plants, oil palms, ground nuts or soybeans; cucurbits, such as squashes, pumpkins, cucumber, melons or water melons; fiber plants, such as cotton, flax, hemp or jute; citrus fruit, such as oranges, lemons, grape fruits or mandarins; vegetables, such as artichoke, eggplant, spinach, lettuce (e.g. iceberg lettuce), chicory, cabbage, asparagus, cabbages, carrots, onions, garlic, leeks, tomatoes, potatoes, cucurbits or sweet peppers; lauraceous plants, such as avocados, cinnamon or camphor; energy and raw material plants, such as corn, soybean, rapeseed, sugar cane or oil palm; tobacco; nuts, e.g. walnuts; pistachios; coffee; tea; bananas; vines (table grapes and grape juice grape vines); hop; sweet leaf (also called Stevia); natural rubber plants or ornamental and forestry plants, such as flowers (e.g. carnation, petunias, geranium / pelargoniums, pansies and impatiens), shrubs, broad-leaved trees (e.g. poplar) or evergreens, e.g. conifers; eucalyptus; turf; lawn; grass such as grass for animal feed or ornamental uses. Particularly preferred are canola, soybean, cotton, wheat and maize.
[0027] As each step of the authentication method of the present invention is performed as part of a computer-implemented method, the invention is also described herein by reference to computing nodes performing one or more method steps. A reference to a computing node performing any particular method step or set of steps allows, but does not imply, that a separate computing hardware or computer program module or function is dedicated to the performance of the particular method step or method steps, respectively. In particular, the authentication method of the present invention can be performed in a distributed computing type of way, such that some computing hardware is in a first location is dedicated to performing one or more method steps, and transmits its results to one or more other computing nodes on respective one or more other locations performing other method steps.
[0028] Each computing node may be a single node or maybe a node comprised in a network of computer nodes. Networks of computer nodes are well-known particularly in the field of distributed computer systems and distributed platforms. It is a particular advantage that the authentication method of the present invention is not dependent on the functioning of a single central computing authority. Instead, the method can be performed locally by distributed computing nodes. This facilitates a rapid decision whether or not to issue a harvest certificate. It also makes the authentication method more resilient against connection issues which might otherwise impede the transmission of data required for issuing of the harvest certificate.
[0029] The hardware implementation of the computing node is not limited as long as the computing node is able to perform the method steps. Thus, a computing node could be anything from a specialised microcontroller to a generic computer comprising generic processors. In particular, a computing node can be implemented on a handheld device or, more preferably, on a generic computer.
[0030] According to the method of the invention, input as described in greater detail further below is received and validated. For validation, the input is analysed automatically to determine the credibility or plausibility that a given harvested material had been obtained by cultivation of a given seed material. As validation is performed automatically, the input preferably is analysed using a model as described in further detail below to determine a confidence score (also described below in greater detail). By comparing the calculated confidence score against a predefined confidence threshold, a decision is obtained whether or not to issue the desired harvest certificate. An outcome of the method is provided and is preferably recorded by a computing node, preferably in a tamper- evident database. It is to be understood that each of the aforementioned steps can be performed by the same computing device. However, individual computing nodes on individual devices may be used to perform one or more of these steps. Preferably at least the determination of the confidence score and the comparison of the confidence score to the confidence threshold is performed by the same computing node, e.g. by having one or more input processes running on the same computer hardware as a decision process implementing a decider computing node for comparing the confidence score and the threshold.
[0031] According to the authentication method, information of at least one seed certificate is provided, preferably to an input computing node. These seed certificate data are associated with a starting material. A seed certificate certifies that a quantity of an agricultural starting material existed in individualised form. Most preferably the seed certificate also certifies that the starting material had been legitimately in possession of the person or entity requesting the harvest certificate (hereinafter also called “requester”, "farmer" or "grower") as described herein. Thus, each seed certificate is issued only for an individual physical object or set of objects. For example, a seed certificate can be issued for an individual bag of seed. This bag of seeds can then be tracked to the planting of said seed. However, instead of applying a seed certificate to an individual package of starting material, the certificate can also be issued in viewofa defined non-individualised quantity of starting material. For example, seed certificate could be issued in view of a defined quantity of several generic seed packages or to a defined quantity of lose seed. Thus, the seed certificate is not limited to a particular real-world instantiation of starting material. Instead, what is required for a seed certificate is that (a) for each seed certificate there exists one and only one physical counterpart (e.g. a bag of seeds or a specific truckload of seeds), and (b) for each physical, real-world item of respective starting material there exists at most one seed certificate.
[0032] In view of these requirements, the seed certificate information comprises a designation of the type of starting material, and a designation of the quantity of said starting material. Preferably, the seed certificate information also comprises a designation of the owner or recipient of the starting material.
[0033] The designation of the type of starting material indicates what kind of starting material is covered by the seed certificate. Thus, the seed certificate allows to differentiate one kind of starting material from another according to its type. The type designation can be of any degree of granularity. For example, the type may be the designation of a particular taxon, e.g. family, subfamily, clade, tribe, genus, species, subspecies or variety. Where the type designation is a taxon, preferably the type designation is that of a species, even more preferably the lowest applicable taxonomic level (which usually is a species, subspecies, variety or, in the case of hybrids, a designation of the lowest applicable taxonomic level of the respective parents). The type designation can also be based on other designation criteria. In particular, the type designation could identify a plant variety and / or a particular quality or other property of the starting material.
[0034] The designation of quantity of starting material refers to the amount of certified individuals starting material as described above. Thus, the quantity designation may be e.g. the number of seed packages, the number of individual seed, the total seed weight or the length of seed-impregnated bands. It is a particular advantage that the present invention is not limited to a particular type of starting material and can thus be performed on ornamental plants and staple food and / or feed plants. It is a particular advantage of the present invention that the seed certificate information already allow to roughly estimate the yield of offspring material achievable from cultivating the respective starting material.
[0035] The seed certificate information may also comprise further information, e.g. data associated with seed coating, mixture with fertilising and / or plant protection agents etc., lot number, time of harvest, harvest location and so on. It is an advantage that the method of the present invention is capable of handling a diverse set of data pertaining to agricultural products. The seed certificate data is provided preferably such that the input computing node receives the seed information. The seed information can be comprised as such in the seed certificate. For example, the seed certificate information could be provided in a human and / or machine readable form in a package of starting material and / or in an invoice pertinent to the sales of the respective starting material. The farmer could then input the seed certificate information for example when requesting a respective harvest certificate. The farmer could also pre-emptively have the seed certificate information recorded in a database accessible to the input computing node. In addition to or instead of the farmer, seed certificate information can also be provided by the originator (also called "grower" or "vendor") of the starting material. This is the preferred way of making seed certificate information available for being received by the input computing node.
[0036] The originator could make the seed certificate information available to the input computing node after being advised of a request to issue a harvest certificate. However, preferably the originator pre-emptively has some, most preferably all, seed certificate information recorded in a database accessible to the input computing node. Where the seed certificate information is pre-emptively stored in a database from which the input computing node can receive the seed information, the authentication method of the present invention advantageously can proceed processing a harvest certificate request without having to wait for farmer or originator making the seed certificate information available. In this regard it is particularly advantageous when, in a network of distributed input computing nodes, the seed certificate information is pre-emptively made available to one or more input computing nodes which are likely to process the harvest certificate request, e.g. to input computing nodes located in the region of the recipients of starting material. This further reduces latency and reduces the likelihood of communication delays or communication errors that could occur if the input computing node would have to collect seed certificate information stored remotely. Instead, the input computing node can be connected to a local database storing the seed certificate information or a copy of seed certificate information stored in a remote master database. Where the input computing node stores seed certificate information as a copy of seed certificate information stored in a master database, the local database preferably contains an indication of conformity of the locally stored information with the information stored in the master database.
[0037] Furthermore, a request for a harvest certificate is provided for the method and is preferably received by the same or another input computing node. The harvest certificate is to certify that a quantity of harvested offspring material was obtained from cultivating the starting material, that is, the agricultural product to which the one or more seed certificates apply. Thus, a harvest certificate can only be issued in view of harvested material that can be obtained as fruit (in the widest sense) of the starting material. As described above, the starting material is fully consumed in the production of the harvested material and thus necessarily is no longer extant at the time of harvest. Instead, the quantity of starting material is effectively transformed into and replaced by the harvested material. Several relationships can be pertinent to the quantity of starting material and of harvested material:
[0038] The quantity of harvested material could be the same or less than the quantity of starting material. This is in conformance with expectations for example when the quantities of starting and harvest material refer to individual agricultural items, e.g. a number of seed and a number of corresponding plants or parts thereof. This is particularly relevant where roots or turnips are harvested, because in this case one item of starting material (preferably seed) results in, more or less, one item of harvested material, that is one root or turnip.
[0039] The quantity of harvested material could be the same or higher than the quantity of starting material. This is in conformance with expectations in particular where the quantities of starting and harvest material refers to grain or seed. In this case, one item of starting material, e.g. one seed, results in the production of several harvested seed or grains. Further provided are context data associated with harvested offspring material, and preferably an input computing node receives such context information regarding the harvested offspring material. The input computing node receiving the context information preferably is the same input computing node receiving the request for a harvest certificate. This advantageously facilitates data entry by the requester. For example, upon receiving context information the input computing node could infer that the requester intends to request a harvest certificate and could treat the context information as an implicit request for a harvest certificate.
[0040] The context data comprises a designation of the type of harvested offspring material. Insofar, the explanations given in view of the designation of the type of starting material apply accordingly. In particular, the type of harvested material can be the designation of the lowest taxonomic rank applicable to the harvested material and / or could be the designation of a plant variety. In those cases where several different types of starting material have been grown and harvested together or are merged into one heap of harvested material, the designation of the type of harvested material comprises a designation for each sort of harvested material combined to form the harvest in question.
[0041] The context data also comprises a designation of the quantity of harvested offspring material. Again, the explanations in view of the designation of the quantity of starting material apply mutatis mutandis. Furthermore, in those cases where the harvested material consists of separately quantifiable sorts or types of materials (e.g. a mixture of several plant varieties or plant species material such as seed and so on), the designation of the quantity of harvested material comprises a designation for each sort of harvested material.
[0042] The context information also comprises a designation of the requester of the harvest certificate. The designation of the requester allows to identify the person or legal entity responsible for the request for a harvest certificate. The requester can be identified by any means to the satisfaction of the authority in charge of supervising or providing the authentication method of the present invention. As seen below, the confidence score can depend on the history of harvest certificate requests by a requester such that a historically unreliable requester is awarded a worse confidence score than a historically reliable requester, or the unreliable requester may be required to meet a stricter threshold than a historically reliable requester.
[0043] In those preferred cases where the seed certificate information already comprises a designation of the recipient of the starting material, the chain of transfer of starting material covered by a seed certificate and the requester of the harvest certificate can be easily verified. Where the seed certificate information does not comprise a designation of the recipient of the starting material, legal ownership of the starting material by the requester may be supposed and accepted. However, preferably in such cases the context information also comprises information to prove or at least to make plausible that the requester has indeed legitimately obtained the starting material designated by the seed certificate from the rightful provider of the starting material.
[0044] Optionally the context data also comprises a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested offspring material. This is particularly advantageous where a farmer has not fully used up the whole quantity of starting material to which a seed certificate applies in the creation of the harvested offspring material. For example, a farmer may obtain a large quantity of starting material, sow several fields and / or greenhouses and later may want to receive separate harvest certificates for the respective fields and / or greenhouses. The reason for this might be that the farmer applies different treatments to the plants growing from the starting material on said different fields or in a greenhouse such that for example one harvest certificate applies to organically grown offspring material and another harvest certificate applies to conventionally grown offspring material obtained from the same starting material. It is a particular advantage that the present invention offers this kind of flexibility to the requester of a harvest certificate and does not require him to fully consume all starting material before a harvest certificate is issued. If a harvest certificate is issued and only a fraction of the starting material of a seed certificate has been consumed, then the respective seed certificate is updated accordingly to preserve mass balance and avoid that one physical starting material (preferably seed) is invoked more than once to obtain several harvest certificates.
[0045] The request for a harvest certificate is validated based on the seed certificate data and context data. As described herein, validation determines if it is credible that the harvested material for which the harvest certificate is requested was indeed obtained by cultivating the starting material associated with the corresponding seed certificate. As described hereinafter, validation can be based on the context and seed certificate data, but it can also include supplementary information, for example, climate records of the cultivation region, yields of other farmers using the same type of seed material in comparable cultivation conditions, historic yield data of the requestor of the harvest certificate and so on.
[0046] Validation will typically be performed by a computer model in the widest sense. Typically, as described in preferred explanations below, such model analyses the input provided thereto, in particular seed certificate and context data, using suitable metrics, wherein the model is, wholly or partially, pre-trained and / or manually configured. Training is preferably performed in supervised and / or unsupervised learning steps. Manual configuration is preferably performed by setting, based on expert knowledge, appropriate thresholds or other model parameters. For example, manual configuration could be used to provide an untrained model with a set of suitable starting parameters which are then optimised using supervised or unsupervised training to obtain the model. Either way, training and / or manual configuration is performed using suitable training data such that the model can discriminate between credible and non-credible input.
[0047] The model is preferably trained to emit a validation decision, that is, a decision whether or not the type and quantity of harvested material to which the harvest certificate request pertains was obtained from the type and quantity of the starting material.
[0048] To obtain such decision, the model is preferably trained or configured, in an authentication method of the present invention described below, to determine a confidence score which is then used to decide whether the harvest certificate request can be validated based on the seed certificate data and context data. An indication of the validation decision is preferably recorded in a database. The confidence score may or may not be emitted outside of the model. For example, the confidence score may be a vector created by a layer of a neural network, and a further part of the model, e.g. a further layer of the same or another neural network, translates this vector into the validation decision.
[0049] According to the preferred authenticating method, a determination computing node determines a confidence score. As described above, the determination computing node may be implemented by the same device as one or more of the input computing nodes. In particular, the determination computing node may be implemented in the form of a determination process running on a computer which also runs one or more input processes implementing one or more input computing nodes. An advantage of implementing an input computing node on the same hardware as the determination computing node is that transfer of the data received by the input computing node to the determination computing node is straightforward, safe and fast, thereby avoiding data communication errors or delays. However, it is a particular advantage that the present invention is not limited to a particular hardware configuration. Instead, input computing nodes can be implemented on less sophisticated hardware than a determination computing node, because the input computing nodes do not require the operations involved in using a model to derive the confidence score. In particular, an input node could be implemented as an app on a conventional smartphone or other handheld computer, and the determination computing node could be a central server processing seed certificate information, requests and context information obtained by several input computing nodes. According to the invention, the confidence score is indicative of the likelihood that the seed certificate information and the context information match, i.e. that the respective harvested material was indeed obtained by cultivating the respective seed material. The term likelihood is to be interpreted broadly, the confidence score thus is an indicator of how trustworthy or plausible the request for a harvest certificate is, given the circumstances as collected by the one or more input computing nodes. The confidence score can conform to any suitable metric. In particular, the confidence score can be a score on a ordinal / categorial / enumerated scale (e.g. a 1-5 star rating or a simple yes-no-type rating) or on a numerical scale, which may be a limited (e.g. a floating point number in the 0-1 interval) or unlimited numerical scale. As the authentication method of the present invention is not limited to a particular metric of the confidence score, the confidence score can be constructed such that a high value indicates a high confidence in the legitimacy of the harvest certificate request, given the available information. However, the confidence score may instead follow a different metric such that a low confidence score value indicates that the request for the harvest certificate is not surprising given the information collected by the one or more input computing nodes. In this case, a high likelihood that the seed certificate information and context information match would be expressed by a low confidence score. It is only required that the metric employed in the determination of the confidence score (high values indicate high likelihood of match, or low values indicate high likelihood of match; the same applies to confidence scores constructed according to an ordinal metric) must be known when comparing the confidence score with a confidence threshold as described below. It is a particular advantage of the present invention that the determination of the confidence score is not dependent on a particular metric. This allows to use the easiest way of determining the confidence score in view of the type of model employed. For example, processing of the seed certificate information and context information by the model might result in a simple yes / no response, which could already be taken as the confidence score, while another model could provide a more complex score, for example a vector wherein each component is an individual score according to an individual criterium (e.g. a prediction of yield of harvested offspring material, an indication of the difference between the quantity of harvested material as given in the context information and a floating average of the historical yield achieved by the requester, etc.).
[0050] The confidence score is determined based on a model. The model can be of any type suitable for allowing to determine the confidence score. However, the model must meet the requirements for accuracy needed to determine a value useful as a confidence score in the authentication method of the present invention. The model can be a single model or may comprise or consist of several sub-models designed to model selected aspects or criteria (parameters) used in the determination of the confidence score. Preferred model design considerations and architectures are described further herein.
[0051] The model is provided with input by the one or more input computing nodes and outputs one or more modelled values. The model may furthermore be provided with cultivation and verification information as described below. The model (or any sub-model thereof) may use its input as such or may apply any suitable data reduction technique. For example, some or all inputs could be passed through a filter for outlier removal. Some input, e.g. time series data, could be replaced by a corresponding weighted or unweighted moving average, an exponential average or the result of an autoregressive model, a filter, e.g a Stratonovich or Kalman filter. Furthermore dimensionality reduction techniques can be applied to some orall of the input, for example factor analysis, principal component analysis, latent discriminant analysis, t-SNE and so on.
[0052] The model (or a sub-model thereof) can be classifying (also called "clustering"), i.e. it can provide, as output result value, an assessment into which class of a set of classes the input provided to the model fit, and optionally also to which degree the input fits to one or more classes. Preferred classification techniques are any of conditional random fields, hierarchical clustering, k-means, fuzzy clustering, clustering using representatives, Dirichlet process mixture models and expectation maximisation. The model (or a sub-model thereof) can be predictive, i.e. can estimate, infer or deduce one or more output result parameters on the basis of input provided to the model. For example the model could predict an estimate of the yield of a requester given the seed certificate information and context information, and the yield prediction can be compared to the designation of the quantity of harvested material given in the context information. The model could also estimate, infer or deduce the reliability (e.g. by providing a confidence interval) of a parameter, e.g. the reliability of a prediction of an output result (e.g. yield) obtained by the same or another model or sub-model thereof. The model could also provide upper and lower bounds of a modelled parameter which suffices the confidence threshold. In this case, the input received by the one or more input computing nodes can be compared to the upper and / or lower bound to determine the confidence score. Preferred prediction, estimation, inference or deduction techniques are Bayesian statistics (preferably using copulas), evidence based prediction according to Shafers-Dempster (particularly useful for plausibility assessments), support vector machines, random forests, linear regression and logistic regression.
[0053] The model can have any suitable architecture. In particular, the model can be a network, for example a Bayesian network or and evidence network. Preferably, the model uses a neural network architecture. Neural networks are particularly suitable for machine learning, they are easy to train and their applicability to diverse machine learning tasks has been convincingly shown. Preferred neural network architectures are autoencoders, convolutional neural networks, generative adversarial networks, multilayer perceptrons, recurrent neural networks, restricted Boltzmann machines, self organising maps and transformer networks.
[0054] The model returns one or more output values. To determine the confidence score, it is preferred that the model returns a single value which can be used as the confidence score. However, it is also possible that the model returns one or more values which are then compared to the data available for assessing the harvest certificate request, in particular the one or more values can be compared to seed certificate information, context information, cultivation information, verification information and / or to historical yields achieved by the requester. The confidence score is then obtained by a predefined algorithm, for example in the form of a weighted sum of differences between the model output and the data used for assessing the harvest certificate request. However, as indicated before it is most preferable that the model returns the confidence score. This advantageously allows to make all steps in the determination of the confidence score accessible to machine learning techniques without requiring human intervention, e.g. for recalibrating the weights in the aforementioned weighted sum of differences.
[0055] The confidence score is then compared to a confidence threshold by a decider computing node. Preferably, the decider computing node is implemented on the same device as the determination computing node, for example such that one computer runs both a process implementing the determination computing node functions and a process implementing the decider computing node functions. This configuration is particularly advantageous because maintenance of the decider computing node and the determination computing node is facilitated. Any changes to the model used by the determination computing node may also require changes in the way the confidence score is compared to the confidence threshold. When the same device is used for implementing the determination node functions and the decider node functions, then the roll-out of updated programs is facilitated compared to a setting where different hardware instances, potentially on a remote network, need to be updated.
[0056] As described above, the confidence score can consist of one or more values. Correspondingly, the confidence threshold can also consist of one or more values. For example, the confidence score could comprise a value indicating the trustworthiness of the claimed yield of harvested offspring material (yield is herein defined as the quantity of harvested offspring material per unit quantity of starting material and will generally be calculated by dividing the quantity of harvested offspring material by the quantity of starting material invoked in the seed certificate information). A further value of the confidence score could indicate the reliability of the requester, e.g. if an audit performed on a random basis of the requester has uncovered any reasons for doubting his general statements, or if the requester had previously obtained a harvest certificate based on a barely plausible yield of harvested offspring material.
[0057] In any case, the one or more confidence values are compared against the applicable one or more confidence threshold values by the decider computing node. Only where all confidence score values suffice all applicable confidence threshold values the decider computing node decides that the confidence score in total suffices the confidence threshold. Otherwise, the decider computing node decides that confidence score does not suffice the confidence threshold.
[0058] The confidence threshold can be set by the authority in charge of implementing or supervising the authenticating method of the present invention. In such case, the confidence threshold can be set to any value to the satisfaction of said authority. The confidence threshold may be changed by the authority over time if a demand occurs to implement more strict or more lenient confidence thresholds. Amendments to the confidence threshold can be advantageously easily implemented by modifying the decider computing node accordingly.
[0059] The authentication method of the present invention also allows, in addition to or instead of manually setting the confidence threshold, to automatically set the confidence threshold. It is a particular advantage of the present invention that the confidence threshold can be dynamically adapted to an observed change in the behaviour of providers of starting material and / or harvest certificate requesters, for example using machine learning techniques. For example, the confidence threshold can be set such that a predefined target percentage (preferably 1 to 10%) of harvest certificate requesters are required, in one growth season, to submit more detailed context information as described below (in particular one or more items of cultivation information) or even to undergo an audit. In this case an automatic system for adapting the confidence threshold would preferably do a statistical analysis of historical data of one or more previous growth seasons (i.e. the seed certificate information, context information including cultivation information and independent verification information obtained during said one or more previous growth seasons), and would set the confidence threshold such that for the data considered in said analysis the confidence threshold would conform to the target percentage, i.e. the number of hypothetical objections / negative decisions of a hypothetical decider computing node using said historical data would conform to the target percentage. Most preferably the confidence threshold is automatically adapted only within a predefined range. This has the advantage that unacceptably low or high confidence threshold are avoided which might otherwise go unnoticed if the confidence threshold could be set automatically to any value.
[0060] Further preferably some noise may be applied to the seed certificate information, context information, confidence threshold and / or the confidence score. This advantageously allows to ensure that each requester faces a minimal probability of being required to submit more detailed context information (in particular one or more items of cultivation information) or even to undergo an audit. Random sampling of human actors for deeper inspection is a proven way to increase honesty and compliance. Even though the authentication method of the present invention is an automatic method and thus is computer implemented, it can take into account potential human misbehaviour not only by adapting confidence scores and / or confidence threshold is but also by adding noise.
[0061] Finally, the result of the validation is provided, preferably to a user and / or, more preferably, to a database. Preferably a recorder computing node records, in a database, an indication of the decision of the decider computing node. Preferably the database for recording the decision is a tamper evident database. As described above, recording of the decision allows to apply a confidence threshold or confidence score for individual requesters based on their previous behaviour. Furthermore, when one or more negative decisions are recorded for a requester during a period of observation, for example 1-4 months, this may indicate an acute need for training of the requester. In particular, the requester could be provided help by a counsellor to use a user interface provided for the authentication method of the present invention, or to collect and transmit the required data (in particular the context information and / or cultivation information) in a required format.
[0062] All databases for use by an input computing node, a determination computing node and / or a recorder computing node could be maintained locally at the respective node could be accessible by the respective node via a wireless or cable-mediated data exchange network. As described above, preferably one or more input computing nodes may maintain local copies of seed certificate information. For example, an input computer node could maintain a copy of the seed certificate information pertaining to potential requesters (normally growers identified in seed certificate information can be expected to be potential requesters of harvest certificates) of a certain region. A request for a harvest certificate could then advantageously be referred to the input computing node which already is in possession of the relevant seed certificate information applicable or most likely applicable to the requester of that region.
[0063] When seed certificate information is distributed over or copied to several databases, care must be taken to maintain data consistency. Thus when a harvest certificate is issued the seed certificate must be invalidated in all database copies. This can be performed by synchronising local databases with a master database or by sending messages to all computing nodes maintaining local database copies. However, to prevent erroneous or fraudulent harvest certificate requests invoking the same seed certificate in a short time or before synchronisation could be completed, it is preferred that the determination computing node and / or the decider computing node also track which seed certificates have been fully or partially used in previous harvest certificate requests. When more than one harvest certificate request is thus based on the same seed certificate or on a no longer available quantity of starting material, the harvest certificate requests are refused, preferably by setting the confidence score and / or the confidence threshold such that the decider computing node decides that the confidence score does not suffice the confidence threshold. Furthermore, if in such case a harvest certificate had already been issued, the harvest certificate may be revoked and / or the requester of said harvest certificate may face a stricter confidence thresholds for further harvest certificate requests.
[0064] According to the present invention, a tamper evident database is a database which, by its design, would make it, by any practical definition of the words, impossible to conceal an illegitimate change of database contents. Best known tamper evident databases are blockchain-type databases. The method of the present invention is, however, blockchain agnostic and is thus independent of the actual implementation of the tamper evident database. Implementations of tamper evident databases and particularly blockchain-type databases are described, for example, in W02020150185 and WO2022140465.
[0065] Tamper evident databases have been criticised for being slow when recording new data and requiring a disproportionate amount of energy for entering a new record to the database. It is thus a technical advantage of the present invention that the use of tamper evident databases can be limited to record the data which require a high probative value lest the trust in the respective certificates is compromised. In particular, the present invention allows to limit dependency on tamper evident databases for recording seed and harvest certificate information. Further information, e.g. cultivation information and verification information described further herein can be stored in a conventional database, for example a relational database. Because the seed and harvest certificate information is not going to be changed often (ideally, a seed certificate would only once be needed to be decommissioned when it has been successfully invoked for issuing a harvest certificate), the speed of recording corresponding certificate records and the energy required to do so are thus effectively no longer of concern. The present invention provides, in particular, several technical benefits: all method steps have been devised such that the method can be performed on a computer system using distributed computing nodes. Furthermore, the tasks of the computing nodes have been defined such that differentiated hardware can be used for implementing the computing nodes. In particular, computing nodes like input computing nodes, but also decider computing nodes and recorder computing nodes are not charged with computationally intensive tasks and can thus be implemented on less sophisticated hardware compared to, for example, a determination computing node. But even the determination computing node can be implemented on one or more microcontrollers or generic personal computer hardware, because the determination computing node is relieved from the tasks of user interaction and communication. Furthermore, the definition of the determination computing node is essentially agnostic of the model used for determining the confidence score. This advantageously offers freedom to assign the computation of the model to any suitable type of hardware, be it one or more microcontrollers, FPGAs, PLAs, graphic cards or any other kind of suitable hardware. Furthermore, the method of the present invention allows, as described herein, to store the required information (in particular seed certificate information, harvest certificate information and verification information) in a distributed database, which reduces latency and allows data recovery in case one database instance is lost or corrupted.
[0066] It is furthermore a technical advantage of the authentication method of the present invention that the amount and degree of detail of information required to obtain a harvest certificate is reduced to a minimum without compromising the trustworthiness of the harvest certificates. As described above, it is generally a problem of certification systems that a certificate refers to one physical object, and when the object no longer exists, the certificate ceases to describe the physical reality and is no longer valid. By the very nature of agricultural processes, the generation of offspring material, particularly in the field of farming of plants, requires the transformation and thus effectively the destruction of the starting material. It is not possible to sow a seed, have it grow into a plant and still have the same seed available for growing another plant. From the perspective of a certificate issued for a quantity of seed, there is thus no connection between the certified seed and the offspring obtained from cultivating plants. A further problem not treated in the prior art is that no one-to-one relationship exists between the agricultural starting material and the harvested offspring material. A single seed may not give rise to any offspring at all, or may result, so to say, in the harvest of thirty- sixty- or a hundredfold. The prior art thus did not address the problem of seed destruction during cultivation. Instead, to maintain trust throughout a value chain, recourse had to be had to a full tracking of all steps performed using the starting seed and anything generated therefrom. This results, on the one hand, in a lack of any single data record certifying that a particular harvested material indeed did originate from the supposed starting material. Instead, the correspondence between starting material and harvested offspring material could only be inferred by aligning e.g. geo-referenced data certifying the place were seeds had been actually sowed and further geo-referenced data certifying the place where harvested material had actually been harvested. This renders the farmer completely transparent to any person who requests prove that the harvested material was obtained from a specified type of starting material. Third parties could thus easily obtain a full picture of the individual farmer’s economic situation and of the means available to him for performing farming operations.
[0067] By using a model as described herein, the aforementioned shortcomings of the prior art are ameliorated or overcome. The model allows to decide on a harvest certificate request and to issue, in case of a positive decision, the desired harvest certificate, and the harvest certificate itself is sufficient evidence of the origin of the harvested offspring material. A third-party auditing the farmer would for example merely need to be allowed to test the database comprising harvest certificates for the existence of the harvest certificate without learning all or part of the harvest certificate information. It would then be in principle the farmer's decision if and to which extent harvest certificate information is also disclosed. Preferably the authentication method further comprises the step of issuing a harvest certificate by an issuer computing node if the decider computing node decides that the confidence score suffices the confidence threshold. Preferably, the issuer computing node is implemented in the same device as the decider and / or recorder computing node. According to the invention, issuing of a harvest certificate involves recording the harvest certificate in a database, preferably a tamper-evident database. According to the invention, the harvest certificate thus allows access to a database record of harvest certificate information, as described above for certificates in general and similar to seed certificate information. In particular, the harvest certificate information comprises a designation of the type of harvested material, a designation of the quantity of harvested material, a designation of the harvest certificate requester and / or the beneficiary of the harvest certificate request, and preferably a designation of the corresponding seed certificates and, for each seed certificate, the corresponding fraction of starting material that has been consumed in the production of the harvested offspring material.
[0068] Generally the requester of the harvest certificate can be the person or legal entity in possession or ownership of the harvested offspring material. However, it is possible to treat every person or computer acting on behalf of the person legitimately in possession or ownership of the harvested offspring material as a harvest certificate requester on their own right. This allows, for example, that employees file harvest certificate requests for their respective employer. In those cases where the requester of the harvest certificate is not the beneficiary of the harvest certificate, the confidence score determination and / or the confidence threshold applied are preferably not based only on the information provided by the individual requester (in particular the seed certificate information and context information including cultivation information) in the process of requesting a single harvest certificate. Instead, the decision of the decider computing node is also based on the harvest certificate requests and corresponding information performed on behalf of the same beneficiary, thereby effectively treating all harvest certificate requests and corresponding information (in particular context information and cultivation information) as being submitted by the same (virtual) requester, i.e. the beneficiary. Refusals to issue a harvest certificate request by a recorder computing node in this case can not only indicate a need for additional support and / or training of an individual requester person, but can also indicate the need for support and training to improve the processes of the beneficiary for submitting harvest certificate requests.
[0069] Furthermore according to the invention, issuing of a harvest certificate involves updating of the corresponding seed certificate information to indicate consumption of the respective quantity of starting material. Thus, whenever a harvest certificate is issued, care is being taken to prevent issuing two harvest certificates based on the same starting material.
[0070] The harvest certificate is preferably stored in a tamper evident database, that is, the harvest certificate information is stored in a record of a tamper evident database and a token or identifier, the harvest certificate, is created to allow retrieval of the harvest certificate information from the database.
[0071] Preferably the recording of the harvest certificate serves, in step iv), as the indication of the decision of the decider computing node. Thus, in addition to recording the harvest certificate, no further actions are required to record, by the recorder computing node, an indication of the decision of the decider computing node.
[0072] Further preferably, the database containing seed certificate information and / or harvest certificate information is a distributed tamper evident database. As described above, it is an advantage of distributed databases that they allow to organise the distribution of data such that latency of database access can be reduced by storing data applications that are easily and swiftly accessible by a computing node in need of access to those data. In particular, data in a distributed database can be maintained in the form of local copies, and / or data can be maintained in the form of local "shards" or partitions.
[0073] Particularly preferably the database containing seed certificate information is a distributed tamper- evident. An advantage of such configuration is that an input computing node could process a harvest certificate request with low latency and communicate both context information and seed certificate information to the determination computing node.
[0074] Further preferably the seed and harvest certificate information are stored together in one, preferably distributed, tamper-evident database. This facilitates look-up of required seed certificate information in the process of authenticating a harvest certificate request.
[0075] It is particularly preferred that seed and / or harvest certificate information recorded in the respective database, respectively, is encrypted. Database encryption allows to maintain privacy even if the database in total or parts thereof happen to become accessible by non-authorised entities.
[0076] The database can be encrypted in total by a single encryption key. An advantage of this configuration is that the computing node accessing the database only needs to perform one decryption operation for all required accesses. In particular, an input computing node would only need to perform one decryption to access the seed certificate information of all seed certificates invoked when processing a request for a harvest certificate.
[0077] The database could also be individually encrypted on a field by field basis such that each field of seed certificate information and / or harvest certificate information, respectively, requires for decryption and individual key different from one or more other such fields. Such individual encryption is particularly preferred according to the present invention. Individual encryption allows to implement access rights and thus advantageously maintains data sovereignty and privacy for the entities submitting seed certificate information and / or context information. Thus, seed providers and farmers can individually decide which information to disclose to whom and under which circumstances. The provider of starting material could thus ensure that only the legitimate person (e.g. the rightful buyer of seed) can access the corresponding seed certificate information and base a harvest certificate request thereupon. This, for example, prevents the authority in charge of maintaining the database comprising seed certificate information from analysing the database to obtain a report of the volume and type of starting material handed over by the provider of starting material to respective customers (e.g. farmers), thereby stealthily obtaining insight into each starting material provider's economic success and web of business relationships. Likewise harvest certificate requester's could ensure that only legitimate persons (e.g. retailers or wholesale markets) can access corresponding harvest certificate information. This, for example, prevents the authority in charge of maintaining the database comprising harvest certificate information from analysing the database to obtain a report of the quantity and type of harvested offspring material and the individual farmer's yield, thereby stealthily obtaining insight into each farmer's economic success and web of business relationships.
[0078] For individual encryption it is particularly preferred that decryption rights are implemented based on the role of the entity requesting decryption. For example, a farmer could decide that decryption of harvest certificate information is possible for every entity in the role of a retailer or consumer, even if the farmer cannot beforehand enumerate all retailers or consumers that might want to verify the legitimacy of a harvest certificate. Furthermore, role-based decryption rights can be granted selectively for each information. For example, a person in the role of an auditor would be able to fully decrypt all seed certificate information corresponding to a seed certificate and / or all harvest certificate information corresponding to a harvest certificate, whereas persons in the role of a retailer or consumer would only get limited access to information. The database can also be encrypted in total by a single encryption key and, in addition, be individually encrypted on a field by field basis.
[0079] The context information preferably includes cultivation information. Cultivation information may be provided by the harvest certificate requester together with the above-mentioned general context information, for example on a voluntary basis. However, context information can also be submitted by a harvest certificate requester after receiving the decision of the decider computing node that the confidence score determined on the basis of previously submitted context information does not suffice the respective confidence threshold. In particular, an exceptionally good harvest might result in an insufficient confidence score, but is awarded a sufficient confidence score when corroborating cultivation information is provided to the determination computing node and its model. The degree of detail of cultivation information thus may depend on the circumstances of each individual case. This is an advantage of the present invention, because the request of a harvest certificate according to the present invention is not obliged to submit information unless there is a real need to do so. In particular, the model could be made transparent to potential requesters to allow them to understand what is, or is not, considered plausible by the model. By providing noise, as described above, some residual uncertainty would be maintained, thereby incentivising harvest certificate requesters not to access the borders of the plausible region.
[0080] The cultivation information preferably includes one or more planting information parameters selected from location of cultivation, time of cultivation, and treatment information, wherein treatment information can comprise any of time, type and intensity of starting material treatment (e.g. seed treatment), soil treatment (e.g. time, type and intensity of fertilisation, time, type and intensity of watering), plant treatment (e.g. time, type and intensity of pest control measures (e.g. application of fungicides, insecticides, helmithicides, rodenticides, bactericides), harvest information (e.g. type of harvester used, information certified by the harvester machine and so on), harvest treatment (e.g. storage conditions of harvested offspring material), sunshine duration, time and amount of irrigation, soil temperature, air temperature.
[0081] The cultivation information preferably includes one or more productivity information parameters selected from Soil Rating for Plant Growth (SRPG) rank (Soil Survey Staff, 2000), productivity index (Pierce et al., 1983), soil texture (e.g. clay, silt, loam, sand, humus content), water holding capacity, nutrient content, topography (e.g. sloped terrain), soil depth, drainage and water access, climate zone, average sunshine, average soil temperature, average air temperature.
[0082] The model takes into account the cultivation information so that the determination computing node obtains a confidence score indicative of the likelihood that the context information including the cultivation information matches the seed certificate information.
[0083] Preferably the determination computing node receives verification information relating to the context information, preferably the cultivation information, and the model takes into account the verification information. Verification information is information not provided by the requester of the harvest certificate, but is obtained from other sources.
[0084] In particular, verification information can contain the results of an audit of the harvest certificate requester. This allows to increase or decrease the weight given by the model to the context information provided by the requester in general or to selected parts of such context information. For example, when context information comprises an indication of the location of cultivation, an independent audit could verify that cultivation on the specified location is indeed by the harvest certificate requester.
[0085] Verification information can contain independently obtained information on planting information parameters and productivity information parameters. Verification information can be obtained e.g. by analysing local land registries, satellite data, visual inspections and weather observation authorities.
[0086] Verification information may comprise a ranking of individual fields or regions for productivity of a class of starting material, e.g. average productivity of canola, soybean, cotton, wheat and maize. Furthermore, planting regions can be ranked for climate parameters in a given period, for example according to time and intensity of rainfall, sunshine periods, bad weather conditions like the appearance of thunderstorms or hail. For example, when context information comprises an indication of the location of cultivation, productivity and / or planting information parameters of verification information could be used by the model to increase the weight of context information provided by the harvest certificate requester when the context information fits to the planting and / or productivity information parameters applicable for the respective region. Likewise, the weight of context information provided by the harvest certificate requester can be decreased where the information does not fit to the applicable planting and / or productivity information parameters of the verification information.
[0087] It is a further advantage of the present invention that, where cultivation and / or context information is missing, the model can take into account an estimate of the missing information, preferably based on verification information. Thus, when a harvest certificate request is not accompanied by all information to be taken into account by the model, the request could be treated as if it were made by a hypothetical average requester and be based on corresponding estimates. This allows to limit refusals of harvest certificate requests mainly to those cases where the laws of nature (as evidenced by statistics) give rise to seriously doubting the context information submitted together with the harvest certificate request. This reduces the frequency of falsely negative decisions by the decider computing node without requiring full disclosure of all available information by every harvest certificate requester.
[0088] Preferably the model is updated using machine learning based on any of the context information, the cultivation information, the verification information and / or the decision of the decider computing node. Further preferably, the estimates are updated using machine learning based on the information provided for accepted harvest certificate requests and / or verification information.
[0089] It is a particular advantage that the present invention allows to modify the conditions upon which a decision by the decider computing node is reached when new information have become available without requiring manual intervention. In particular, the model and / or verification information and / or estimates can be updated by learning from past mistakes or to take into account trends, for example a slow improvement or deterioration of productivity, soil quality, a change of irrigation needs due to climate change, soil exhaustion due to overly intensive cultivation, increases in salinity due to overapplication of fertilisers, general changes in productivity in a region due to the emergence of infestations by pests and so on. Changes of the model preferably are implemented by changing of weights attributed by model components to information analysed by the model. For example, where a model employs a neural network architecture, the weights applied by individual "neurons" to their respective input can be adopted. Suitable machine learning techniques applicable to the various models are known to the skilled person. For example, back propagation is a common technique for updating neural networks. Methods for updating estimates are also known to the person skilled in the art and comprise, among others, moving averages. Verification information can be updated by deleting old information and writing new information to a database comprising verification information, or by overwriting outdated verification information in a database comprising verification information.
[0090] The harvest certificate is preferably only issued if sufficient context information has been provided that the harvested offspring material suffices a business quality requirement. It is a further advantage that the authentication method of the present invention is not compelled to issue a harvest certificate merely because, as described above, the context information is sufficient to show that the harvested offspring material designated in the context information has indeed been derived by cultivating the starting material designated in the seed certificates invoked. To make issuing of a harvest certificate dependent on conformity of the context information to a business quality requirement, the model could have embedded therein parameters for assessing such conformity, and / or the decider or issuer computing node could comprise a module for assessing such compliance. For example, such model could require that information certified by agricultural machinery is provided to show the type of treatment applied during cultivation. Business requirements could be of any type, for example production according to an organic farming standard, the application or lack of application of certain treatments during all or part of the cultivation period and so on.
[0091] The invention also provides a method of updating a model of an authentication method as described herein. The updating method comprises the steps of i) receiving one or more model parameters of the model, ii) inferring, based on context information and / or verification information provided in said authentication method, a change in at least one corresponding model parameter, and iii) updating the at least one model parameter according to the inferred change.
[0092] As described above, methods for updating models, in particular by machine learning, are known in the art. It is a particular advantage that the model employed in the authentication method of the present invention can be updated and thus adapted to changing conditions in the physical world and to new insights obtained by context information and / or verification information provided in said authentication method.
[0093] It is a further advantage that the present invention allows to issue recommendations for farmers. In particular, yield data can be used to issue such recommendations. According to the invention, yield data are obtained by comparing the amount of starting material of a respective seed certificate with the amount of harvested offspring material of one or more respective harvest certificates and / or harvest certificate requests. In particular, by comparing yield data of a harvest certificate requester to peer yield data (i.e. yield data associated with other harvest certificate requests or, more preferably, with issued harvest certificates), a computer-implemented recommendation method determines that the yield of said harvest certificate requester is higher than, equal or lower than to be expected.
[0094] Preferably, the recommendation method comprises the steps of providing auxiliary data in addition to yield data, consuming the yield and auxiliary data by a model to determine one or more yield impact factors, wherein the model is trained to recognise one or more yield impact factors, and outputting the one or more yield impact factors.
[0095] Auxiliary data can be context data and / or verification data as described above. The auxiliary data preferably comprise yield formation data, yield protection data and / or yield quality data.
[0096] Yield formation data describe physiological parameters of the starting material which influence yield. Preferred yield formation data are data describing nutrient use efficiency, in particular nitrogen, phosphorus, potassium and / or water efficiency. If a yield according to the recommendation method is lower than expected, nutrient use efficiency data can indicate a lack of one or more nutrients during a growth season. For example, for a starting material with low nitrogen use efficiency, the model of the recommendation method may determine, in view of other auxiliary data, that lack of nitrogen appears to be a prominent factor impacting yield and may issue a corresponding recommendation, i.e. outputting unsatisfied nitrogen demand as a yield impact factor.
[0097] Further preferred yield formation data are abiotic stress data describing the tolerance of the starting material to abiotic stress factors. Preferred abiotic stress data are drought tolerance, temperature tolerance, wind tolerance, rain tolerance, soil salinity tolerance and soil compaction tolerance. The model of the recommendation method may identify one or more of these factors as a prominent influence on yield, in particular when the model takes into account climate data of the growth season at the respective growth location and / or soil survey data at the respective cultivation location.
[0098] Yield protection data describe biotic stress parameters which influence yield. Preferred yield protection data are weed management data describing the competitiveness of the starting material against weeds and / or the impact of weed management methods on yield. Also preferred yield protection data are pest and disease management data describing the competitiveness of the starting material against pests / diseases and / or the impact of pest / disease management methods on yield. The model of the recommendation method, taking into account reported weed, pest or disease outbreaks at the cultivation location, may identify such outbreak as a prominent yield affecting factor and output the corresponding one or more factors.
[0099] Yield quality data describe how well harvest material conforms to specifications. Preferred yield quality data are harvest uniformity data and harvest composition data. Harvest uniformity data describe the intrinsic variability of harvested material, for example the variability in oil content, oil composition, starch and / or sugar content, protein content and / or protein composition, per seed. Harvest uniformity data can be applied by the model to adjust significance thresholds of other auxiliary data, such that for example the model takes a low harvest uniformity as an indicator that a nutrient demand has not been satisfied.
[0100] The recommendation method may also consume seed certificate data and auxiliary data to identify factors that will, in a given growth season, strongly influence yield at a given cultivation location. For example, the recommendation method may consume weather forecast data to decide if additional irrigation is advised.
[0101] By providing recommendations, the method of the present invention advantageously guides the participants in agricultural production to improve several agricultural indicators. Using yield formation data, the method can highlight factors to improve nutrient use efficiency, intrinsic yield and / or abiotic stress tolerance, thereby improving farm output, in particular to improve primary product yield, farm output quality, in particular to improve the average quality (e.g. composition, nutrient content), the level of uniformity and consistency of products and the time to reach maturity is improved, soil, in particular to improve carbon retention, eutrophication, acidification and leaching are improved, air, in particular to improve carbon dioxide equivalents per unit of primary product, water, in particular to improve irrigation demand and reduce unwanted leaching of nutrients into streams, lakes or rivers, energy consumption, in particular to improve the number and intensity of required interventions on a field or in a greenhouse and to improve the amount of energy required per unit of product, biodiversity, in particular to improve land use efficiency.
[0102] Using yield protection data, the method can highlight factors to improve weed management and / or pest and disease control management, thereby improving farm output, in particular to improve yield of harvested offspring material (primary product yield), farm output quality, in particular to improve purity of primary product by reducing contamination by weed material, food safety (e.g. by reducing the amount of mycotoxins), product appearance (e.g. reducing “brown spots”, bruises and blemishes) and product uniformity, soil, in particular to reduce soil contamination and leaching of plant protection agents and to reduce drift of plant protection agents or dust, air, in particular to improve or reduce drift and greenhouse gas emissions, water, in particular to improve or reduce contamination of water by plant protection agents, energy consumption, in particular by advising on good timing for and frequency of intervention to improve efficacy, biodiversity, in particular to improve specificity of treatment und reduce avoidable side effects.
[0103] Using yield quality data, the method can highlight factors to improve farm output quality and the usefulness of the harvested material for its intended application, thereby improving farm output, in particular to improve yield of harvested offspring material (primary product yield), farm output quality, in particular to improve conformity to quality parameters, e.g. content and profile of proteins, starch / carbohydrates and oils / fatty acids, soil, in particular to improve nutrient retention by non-harvested offspring material, air, in particular to improve carbon dioxide binding in improved photosynthesis, water, in particular to improve water consumption per unit of offspring material, biodiversity, in particular to improve land use and enable optimal crop rotation.
[0104] This invention also provides a method of merging harvest certificates. Merging two or more harvest certificates into one new harvest certificate allows the farmer (or any other beneficiary of harvested offspring material) to have individual harvests of offspring material certified by individual harvest certificates and later to sell them in bulk while providing only one certificate to the buyer of the combined harvested material.
[0105] Merging of harvest certificates is accomplished by a computer implemented method which comprises receiving, by a merger computing node, a request to merge two or more harvest certificates obtainable or obtained by an authentication method of the present invention, and merger information comprising a designation of each harvest certificate to be merged, and a designation of the requester.
[0106] The merger information allows the merger computing node to decide if the requester is the same person or beneficiary as recorded in the harvest certificate information. To perform the merging, the merger computing node receives the harvest certificate information of each harvest certificate to be merged.
[0107] When the merger computing node decides that the requester of the merger is entitled to such request, then an issuer computing node issues a new harvest certificate containing the combined harvest certificate information of each original harvest certificate, revokes each of the original harvest certificates and records both the new harvest certificate (including the new harvest certificate information) and the revocation of the original harvest certificates in a tamper evident database, preferably in the same database as the original harvest certificates.
[0108] Correspondingly, the present invention also allows a method of splitting a harvest certificate. In those cases where a farmer (or any other beneficiary of harvested offspring material) has obtained a harvest certificate but does not want to hand over all of the corresponding harvested offspring material to a single buyer, the farmer can have a new harvest certificate created for the fraction of harvested offspring material to be transferred, and the remainder of the harvested offspring material covered by the original harvest certificate is automatically adjusted accordingly.
[0109] The invention also provides a computer storage medium storing computer readable instructions which, when executed on one or more computing nodes, allows the one or more computing nodes to execute a program for performing the steps of the respective node(s) of the authentication method of the present invention. As described above, it is a particular advantage of the present invention that the authentication method is a computer implemented method. Thus, devices for performing the authentication method of the present invention can be easily deployed. Furthermore, the authentication method of the present invention as described above is not dependent on particular hardware. This allows to create software for performing the method without particular constraints resulting from hardware needs. Instead, the instructions can be executed by any suitable processor to implement the respective node's functions.
[0110] As described above, functions within the authentication method of the present invention can be performed by one or more computing nodes, in particular one or more input computing nodes, determination computing nodes, decider computing nodes, recorder computing nodes, issuer computing nodes, merger computing nodes and / or splitter computing nodes. Thus, the computer storage medium can comprise the corresponding computer readable instructions for performing a program to implement the functions of one or more of the aforementioned computing nodes.
[0111] The computer storage medium can be of any desired type suitable for executing the computer readable instructions encoded therein by a processor. The medium is inherently non-transitory and thus does not consist of a material transporting transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire. Instead, the computer storage medium may include volatile and non-volatile, and removable and non-removable tangible media implemented in any method or technology for storage of information. Computer readable storage media include, among others, RAM, ROM, EPROM, static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), flash memory or other solid state memory technology, portable compact disc read-only memory (CD-ROM) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage ("hard dives") or other magnetic storage devices, or any other medium that can be used to store the desired information and which can be read by a computer.
[0112] The computer readable instructions can be transferred to a computer comprising a computer storage medium by downloading, e.g. from a remote location via a network (e.g. the internet, a local area network, a wide area network and / or a wireless network), or from a removable computer storage medium (external storage device) temporarily or permanently connected to the computer. The computer readable medium can contain executable files, libraries and / or data which can be accessed by the processor for implementing the respective computing node's function. When the instructions are executed on the processor, it allows the processor to execute a program which, in turn, implements the computing node's functions. The instructions typically include programming language statements which tell the processor how to process data, make decisions and execute tasks.
[0113] The invention further provides an apparatus comprising i) a data providing interface configured to provide seed certificate data comprising a designation of the type of starting material, a designation of the quantity of starting material, and preferably a designation of the recipient of the starting material, a request for a harvest certificate, and context data associated with harvested offspring material, wherein the context data comprises a designation of a type of harvested material, a designation of a quantity of harvested material, a designation of the requester of the harvest certificate, and optionally a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested offspring material, ii) a validation engine configured to validate the request for the harvest certificate based on the seed and context data, iii) a data providing interface configured to provide the result of the validation.
[0114] Preferably, the apparatus further comprises iv) a database connection to record the result of the validation, preferably in a tamper-evident database.
[0115] Thus, the invention furthermore provides a computer system comprising one or more computing nodes configured to perform the authentication method as described herein. As indicated above, it is a particular advantage that the present invention provides an authentication method that can be provided on a distributed computer system such that one or more computing nodes are implemented on separate hardware communicating at least to the next computing node. Thus, for example the user interaction functions of input computing nodes could be delegated to the personal computers or handheld devices of users, while other computing nodes may be implemented regionally or even centrally. The authentication method of the present invention can, however, also be implemented in a fully centralised way such that one server performs the functions of all of the aforementioned computing nodes.
[0116] Preferably the system comprises one or more database nodes, wherein the database nodes together maintain the tamper evident database. As described herein, a distributed database, i.e. a database distributed over more than one database nodes, is particularly useful for implementing tamper evident databases, because gaining control of and tampering each database node is made practically untenable.
[0117] Preferably, one or more of the database nodes maintain a partition or shard of the database. As described above, this allows to maintain a copy of fraction of those data, in particular seed and / or harvest certificate information, in proximity to the location where they may be used most. For example, by maintaining a regional database partition containing the seed certificate information of starting material handed over to farmers of that region, latency of recalling the required information when performing the last word processing a harvest certificate request can be kept low.
[0118] The invention is herein further described by way of examples and accompanying figures.
[0119] EXAMPLES
[0120] Figure 1 illustrates a non-limiting example diagram of a section or part of a database 1. The database 1 is represented by a band. The upper and lower end of the band is ragged to indicate that only a fraction of the full database 1 is shown. The database 1 comprises several individual records, three of which (10, 10', 20) are shown in more detail.
[0121] Records 10, 10' pertain to one seed certificate. Both records 10, 10' comprise several fields, including a record identifier 11 , 1 T. The record identifier 11 , 1 T ("token") allows to look up the respective record 10, 10' in the database 1 to access its contents. Record look up is preferably implemented by way of an index. Further indices may be created in view of other fields of records. The record identifier 11 , 1 T can be used as the respective seed certificate's token. For convenience, the respective token 11 , 1 T (and mutatis mutandis also the respective token 21 described further below) is also referred to as the seed certificate.
[0122] As described above, the seed certificate is issued to certify the existence and preferably the compliance to a business quality requirement of a defined quantity of agricultural starting material. The seed certificate records 10, 10' thus further comprise a field 12, 12' containing a designation of the type of starting material, and a field 13, 13' containing a designation of the quantity of the starting material as described above. In the example shown in figure 1 , the records 10, 10' furthermore contain a designation 14, 14' of the recipient of the starting material. As described above, this facilitates proving an unbroken chain of ownership starting from the provider of the starting material up to the requester of a corresponding harvest certificate. Additionally a further field may be provided to contain a designation of the provider of the starting material.
[0123] Records 10, 10' also contain further fields 15, 15' and 16, 16' in the example shown in figure 1. The further fields can contain further information regarding the starting material, for example location of cultivation, time of cultivation, time of harvest, treatment of plants from which the starting material has been derived and so on. The further fields 15, 15' and 16, 16' and also the fields 12, 12', 13, 13' and 14, 14' can be individually encrypted such that only a person with a legitimate need to know may decrypt the fields' contents. Thus, for example fields 12, 12', 13, 13' and 14, 14' may be encrypted in such way that an input computing node can decrypt the respective fields so that the seed certificate information can be used for processing a request for a harvest certificate. Fields 15, 15' may, for example, be only decryptable by the recipient of the starting material and may contain private information concerning the date and price of purchase. Fields 16, 16' may, for example, be only decryptable by the recipient and an entity in the role of a business quality supervision authority. For example, the fields may contain information concerning the treatment of plants from which the starting material has been derived such that the seed certificate is an assertion that no pesticides disapproved of by the business quality supervision authority had been applied.
[0124] Records 10, 10' pertain to a single seed certificate. In this case, record 10 is the originally issued seed certificate and record 10' documents that the original seed certificate has expired because the starting material referred to in the seed certificate had been consumed in the production of harvested offspring material (which, in turn, is documented by a harvest certificate described with regards to record 20 below). In this case, preferably the content of fields 11 , 11 ' is identical such that by searching for the seed certificate token in the database 1 all records 10, 10' pertaining to the seed certificate can be found in a single database search operation. However, it is also possible to limit the results of a database search to only the most recent record 10' pertaining to the seed certificate. It is also possible that the contents of fields 11 , 11 ' differ from each other but can be found using the seed certificate token. For example if the token is "X", then the content of field 11 may be "X-issued" and the content of field 11 ' may be "X-revoked". Furthermore, any of the other fields of record 10' may differ from the corresponding field of record 10, preferably to document further changes. For example, the starting material may have been sold to a first entity and was then transferred to the requester of the harvest certificate, and the unbroken chain of transfer was proven by context information submitted together with a harvest certificate request. In this case, the designation 14, 14' of the recipient of the starting material would differ, because the designation 14' may have been automatically adjusted in the processing of issuing a harvest certificate.
[0125] Record 20 pertains to a harvest certificate. Its structure mimics that of a seed certificate records 10, 10'. Record 20 comprises several fields 21 , 22, 23, 24, 25, 26 and 27. Field 21 contains a record identifier (“token”). The record identifier 21 allows to look up record 20 in the database 1 to access its contents. Field 22 contains a designation of the type of harvested offspring material, and a field 23 contains a designation of the quantity of the harvested offspring material. Field 24 contains a designation of the requester of the harvest certificate. Field 25 contain the record identifier 11 , 11' of the corresponding seed certificate. If the harvest certificate is based on more than one seed certificate, then the harvest certificate contains such further seed certificate tokens. Fields 26 and 27 can contain further information about the harvested offspring material and / or the steps performed in cultivation of the starting material to obtain the offspring material, for example location of cultivation, time of cultivation, time of harvest, treatment of plants from which the offspring material has been derived and so on. Corresponding to a seed certificate record 10, 10', each field 22, 23, 24, 25, 26 and 27 may be individually encrypted such that only a person with a legitimate need to know (e.g. a person having assumed a legitimate role) may decrypt the fields' contents. For example, fields 26 and 27 may only be decryptable by an auditor, thereby granting the auditor full access to the further information about the harvested offspring material and / or of the steps performed to obtain it, while only field 26 is also decryptable by a retailer or consumer.
[0126] Figure 2 illustrates a non-limiting example diagram of a process in which a seed certificate is issued. The process starts by a seed vendor 600 identifying himself to a certification system 200. Identification of the seed vendor 600 preferably is performed using two factor authentication. The seed vendor 600 sends an identification message 602 to the certification system 200. The certification system 200 obtains via message 202 from a database system 100 information to verify that seed vendor 600 is correctly identified.
[0127] Seed vendor 600 sends a message 604 providing a designation of the farmer (“grower” 700) who obtained the starting material to which the seed certificate shall pertain. The certification system 200 obtains via message 204 information on the grower 700 which is already contained in the database of database system 100. For example, message 204 could contain a customer identification number of grower 700 that had not been known to the seed vendor 600. If the grower is not yet identified in the database of database system 100, a new record with grower identification data can be created.
[0128] Seed vendor 600 also sends, by a message 606, seed certificate information. The seed certificate information contains a designation of the type of starting material handed over to grower 700 and a designation of the respective quantity of starting material.
[0129] The certification system 200 then combines the seed certificate information transferred via message 606 and the grower information obtained via message 604 and / or 204 and creates (206) a data structure containing the combined information. During creation step 206 the certification system 200 may in particular encrypt some of the information obtained in messages 604, 204 and 606 and / or information derived therefrom such that only persons acting with a given role can decrypt the respective information. For example, certification system 200 may encrypt the names and addresses of seed vendor 600 and grower 700 and additionally include hashes of such information (or the respective customer identification numbers of seed vendor 600 and grower 700). Thus, for example a retailer would learn from the hashes, by inspection of the database of database system 100, only that an unbroken chain exists between the seed vendor 600 and grower 700, but would not automatically learn their names, addresses and / or other private information. An auditor, on the other hand, may be allowed to decrypt (or have decrypted) decrypt the encrypted information this example to dispatch an auditor to the seed vendor 600 or grower 700 if the need for it occurs.
[0130] The data structure created in step 206 is then sent via message 208 to database system 100 for recordal thereof. Certification system 200 furthermore creates (210) a seed certificate identifier. The seed certificate identifier could be created already in step 206 and be incorporated in the data structure sent to the database system 100 via message 208. The seed certificate identifier, however, could also be created based on a response to message 208 by database system 100 and received by certification system 200. In particular, database system 100 may return a record identifier of the data structure sent by a message 208, and certification system 200 could take the record identifier as seed certificate identifier.
[0131] Certification system 200 returns the seed certificate identifier ("token") via message 212 to seed vendor 600. Seed vendor 600 then forwards the seed certificate identifier via message 612 to grower 700. However, the certification system 200 may also automatically forward the seed certificate identifier to grower 700. The grower may, preferably, confirm by a further message to the certification system 200 that the starting material in question has been received by him. As shown above, the seed certificate comprising a seed certificate identifier and seed certificate information is stored in a database of a database system 100. The required information is collected and processed by a certification system 200 and the provider of starting material (seed vendor 600) provides required information.
[0132] Figure 3a illustrates a non-limiting example diagram of the process in which a harvest certificate is issued. The process starts by a grower 700 identifying himself to a certification system 200. Identification may be performed by contacting an input computing node of the certification system 200. Grower 700 is preferably identified using two factor authentication. The certification system 200 obtains, via message 222 from a database system 100, information to verify that grower 700 is correctly identified.
[0133] Grower 700 furthermore sends a message 704 containing one or more seed certificate identifiers to certification system 200. Certification system 200 (preferably an input computing node thereof) then receives, via message 224, seed certificate information corresponding to each seed certificate identified by grower 700 in message 704. The seed certificate information comprises, for each seed certificate, a designation of the type and quantity of starting material which the grower used to generate harvested offspring material. Preferably, the seed certificate information also contains a designation of the recipient of the starting material. This would provide additional proof that grower 700 is eligible for requesting a harvest certificate based on the seed certificates identified by a message 704.
[0134] Grower 700 furthermore sends a message 706 containing context information to certification system 200 (preferably an input computing node thereof). As described above, context information may already comprise cultivation information.
[0135] Certification system 200 (preferably a corresponding input computing node) then has all information available to conclude that a harvest certificate request has been made by grower 700 on the basis of the information obtained in messages 702, 222, 704, 224 and 706. In particular, a harvest certificate request could be filed by using a corresponding request form on a website provided by the input computing node of certification system 200.
[0136] Certification system 200 then starts determining a confidence score indicative of the likelihood that the seed certificate information and context information match. To this end, certification system 200 (or the input computing node concerned with collecting the harvest certificate request) sends a message 226 to a model system 300 (implementing a determination computing node) containing the relevant information obtained in messages 702, 222, 704, 224 and 706. Model system 300 then determines (320) a confidence score by feeding the information received in message 226 to a model. Furthermore, model system 300 receives upon request (not shown) verification information in message 326 from database system 100 and feeds the verification information to the model, too.
[0137] For determining a confidence score, the model may estimate a typical yield obtainable from the starting material based on, for example, the type of starting material, the time of cultivation, location of cultivation, productivity parameters pertinent to the cultivation location (for example soil type, water content and climate zone) contained in verification information obtained by message 326. The model may for example also take into account reported yields on fields in the same region where the harvested offspring material had been generated. The model could then compare the estimated yield with the context information provided by grower 700 and return the probability that the reported yield is obtained given the information considered by the model (for example, the model could return an indication that the reported yield is within a 95% confidence interval of possible yields). When determining the confidence score in step 320, the model system 300 may also take into account past indications of honesty or dishonesty of grower 700 and adjust the confidence score accordingly. Model system 300 then returns the confidence score via message 328 to the certification system 200 (preferably to a decider computing node thereof). In step 228, certification system 200 (preferably in the form of a decider computing node) then compares the confidence score to a confidence threshold. In the process shown in figure 3a, the confidence score suffices the confidence threshold and certification system 200 (preferably the decider computing node thereof) decides to issue a harvest certificate (preferably by an issuer computing node thereof).
[0138] Issuing of the harvest certificate involves updating (234) the seed certificates relied on in the harvest certificate request as indicated in message 704. In particular, the certification system 200 sends, via message 236, an indication to database system 100 that the respective seed certificates have expired because the corresponding starting material has been consumed in the production of the harvested offspring material designated via message 706. Database system 100 then updates the respective seed certificate records in a database containing seed certificate information. Referring back to figure 1 , this preferably leads to the creation of a record 10', thereby indicating that record 10 no longer reflects the current status of the respective seed certificate.
[0139] Certification system 200 (preferably the issuer computing node thereof) furthermore creates (238) a harvest certificate. To create the harvest certificate, certification system 200 combines the required information regarding the grower, seed certificates and context including cultivation information into a data structure. The data structure may, like the seed certificate information described with regards to figure 2, comprise encrypted information such that certain information is only decryptable for persons or entities which legitimately may assume a certain role.
[0140] The data structure is then sent via message 240 from certification system 200 (preferably the issuer computing node thereof) to database system 100 for recordal. Certification system 200 furthermore creates (242) a harvest certificate identifier. Corresponding to the seed certificate identifier described together with figure 2, the harvest certificate identifier could be created already in step 238 and be incorporated in the data structure sent to the database system 100 by message 240. The harvest certificate identifier, however, can also be created based on a response to message 240 by database system 100 received by certification system 200. In particular, database system 100 may return a record identifier of the data structure sent by message 240, and certification system 200 could take the record identifier as harvest certificate identifier.
[0141] Certification system 200 returns the harvest certificate identifier ("token") by a message 246 to grower 700. The authentication method for authenticating a harvest of agricultural material is thus concluded. The database of databases to 100 comprises correct information of the starting material in form of correctly updated seed certificates and comprises correct information of the harvested offspring material in form of the harvest certificate. Furthermore, grower 700 is in possession of the harvest certificate token.
[0142] Figure 3b illustrates a nonlimiting example diagram corresponding to the process described with regards to figure 3a. The process described in figure 3b differs from that of figure 3a in that in step 228, the confidence score does not suffice the confidence threshold. All previous steps, in particular the meaning of messages 702, 222, 704, 224, 706, 226, 326, 328 and the determination step 320 are the same as described in figure 3a.
[0143] When certification system 200 (preferably a decider computing node thereof) decides that the confidence score does not suffice the confidence threshold, a message 230 is sent to the harvest certificate requester (grower 700) to request corroborating data. In particular, the certification system 200 could indicate which information is missing to successfully process the harvest certificate request.
[0144] Grower 700 then responds by providing, in message 710, corroborating data in the form of additional or corrected context information. In particular, the information provided in message 710 may, for the first time in the process depicted in figure 3b, contain cultivation information, e.g. planting information parameters and / or productivity information such as the location and time of cultivation, time, type and intensity of irrigation and / or pest control measures, and so on.
[0145] In view of the data obtained via message 710 (preferably by an input computing node), certification system 200 then initiates, via message 232, a new determination of the confidence score by model system 300 (preferably by a determination computing node thereof). Model system 300 then aligns (330) the corroborating information provided in message 710 and, in so far as they have not been corrected by the corroborating information, the information provided in message 226. Furthermore, for this alignment 330 model system 300 receives (upon request, not shown herein) further verification information by a message 332 from database system 100 if such further information is required by model system 300.
[0146] If the aligned information so requires, the model can be updated (334) as described above and updated model parameters can be stored in a database of database system 100 by sending a corresponding message 336.
[0147] Model system 300 (or the determination computing node) can then again determine in step 320 a confidence score using the model on the basis of the available information. The process then continues as described in view of figure 3a. If, however, the newly determined confidence score still does not suffice the confidence threshold, the process described above in view of figure 3b can be repeated by requesting further corroborating data and processing it accordingly.
[0148] Figure 4 illustrates a non-limiting example diagram of a process in which a third party (800, for example a commodity trader or a consumer) verifies the correctness of a harvest certificate and of information allegedly contained in a harvest certificate.
[0149] The trader or consumer 800 sends, preferably after having identified himself to the verification system 400 (not shown), a harvest certificate identifier via message 802 to a verification system 400. The verification system 400 may then request, from a database system 100, an indication that the harvest certificate identifier submitted in message 802 belongs indeed to a harvest certificate recorded in a database of database system 100. The verification system 400 could then inform the trader or consumer 800 accordingly.
[0150] In the process shown in figure 4, however, the trader or consumer 800 also sends, by message 804 to verification system 400, further information which allegedly is comprised in the harvest certificate identified in message 802. Verification system 400 then receives (412) from database system 100 (upon request of verification system 400, not shown) the required fields of the harvest certificate identified in message 802. If the trader or consumer 800 is eligible for decryption, the verification system 400 then internally decrypts the fields of the harvest certificate transmitted in message 412. Of course, such decryption is not necessary when the corresponding fields of the harvest certificate have not been encrypted before, for example because the respective grower agreed to have the information recorded in unencrypted form.
[0151] Verification system 400 then compares the (possibly decrypted) information of the harvest certificate fields transmitted in message 412 with the alleged content transmitted in message 804. Verification system 400 will then return a verification statement via message 418 to the trader or consumer 800 to indicate if the harvest certificate identified in message 802 does or does not contain the alleged information identified in message 804. It is a particular advantage that this process prevents illicit uncovering of private data, because the person requesting a verification statement must already know the information that is to be verified and cannot really ask for information not known to him. A process for the verification of a seed certificate and / or of seed certificate information would be implemented accordingly.
[0152] Figures 5a and 5b each illustrate a non-limiting example diagram of a reporting process in which a seed vendor 600 obtains a report from a reporting system 500 based on information pertaining to a grower 700.
[0153] According to the process depicted in figure 5a, a seed vendor 600 identifies himself to a reporting system 500 via an identification message 602. The reporting system obtains, by message 502, data from a database system 100 which allow to verify the credentials sent by message 602. Preferably, seed vendor 600 identifies himself to the reporting system 500 using a secure identification process, preferably by two-factor authentication.
[0154] Seed vendor 600 also sends, by message 604, an indication of the grower 700 whose data shall be used in the final report. Reporting system 500 then receives, where necessary, by message 504 any further information stored in the database of database system 100 to identify the data of grower 700.
[0155] Seed vendor 600 furthermore specifies the kind of desired report by sending a message 606 to reporting system 500.
[0156] Reporting system 500 then examines (510) the report request of the seed vendor600. In particular, reporting system 500 would examine if grower 700 has already given consent that the data of his harvest certificates can be used to create the requested report for seed vendor 600. In particular, grower 700 might have defined that only the provider of the original starting material used to generate the harvested offspring material to which the harvest certificates pertain is allowed to receive a report of a certain type, for example a report on harvest yields. A corresponding process involving such pre-released information access rights is depicted in figure 5b and is described in more detail below.
[0157] However, in the process depicted in figure 5a reporting system 500 concludes, upon examination 510, that it does not have sufficient rights to access the data of grower 700 to create the report requested by seed vendor 600. Reporting system 500 then requests, by message 512 to grower 700, that grower 700 consents to the use of harvest certificate information of his harvest certificates in the preparation of the desired report to seed vendor 600. Preferably, reporting system 500 would not only ask for such access rights summarily but would also explain to grower 700 which harvest certificate information is to be used in creating the desired report and would also identify seed vendor 600 as recipient of the report. For example, seed vendor 600 may have requested a report on the yields obtained by grower 700 in a particular growth season by cultivating starting material of seed vendor 600. In this case, reporting system 500 could explain to grower 700 that only the designation of harvested offspring material of the harvest certificates of the desired growth season and the corresponding designation of starting material quantities in the corresponding seed certificates would be used to generate the desired report.
[0158] Grower 700 may refuse to give consent (not shown). In this case, reporting system 500 would refuse to create the requested report and instead send a message to seed vendor 600 that creation of the report was not possible due to lack of information access rights. The process would then end.
[0159] However, in the process shown in figure 5a grower 700 sends, by message 720 to reporting system 500, an indication of consent to use the required data to create the requested report. Consent could be given on a one-time basis or also for any future generation of such reports by vendor 600. Reporting system 500 then documents the consent of grower 700 for information access by sending a corresponding message 514 to database system 100. Reporting system 500 would also retrieve, by message 516, the required information from database system 100 to create the report (517).
[0160] Reporting system 500 finally sends the report by message 518 to seed vendor 600 and optionally also sends a message 520 to grower 700 describing the created report, for example by indicating which harvest certificate information has been used in the generation of the report to seed vendor 600.
[0161] The report asked for by seed vendor 600 is not limited to a particular form, nor is the report, by principle, restricted to be based only on particular information. Seed vendor 600 could for example ask, by message 606, for a report of the yield obtained by grower 700 using starting material provided by seed vendor 600. In this case, the reporting system 500 would identify the seed certificates of seed vendor 600 pertaining to grower 700, it would also identify the harvest certificates of grower 700 which are based on these seed certificates, and it would then create the corresponding report. Seed vendor 600 could also ask the reporting system for a comparison of yields obtained by grower 700 based on seed vendor 600's starting material and starting material of other seed providers. In this case, the reporting system would not only examine that grower 700 has given consent to the use of such information, but would also examine if the respective other seed vendors have given their consent to the use of seed certificate information of their seed certificates. Only if the information accessed consent is given by all concerned parties, reporting system 500 would be able to create the requested report.
[0162] It is further to be noted that the reporting process is by no means limited to data of a single grower 700. Seed vendor 600 could also have indicated in message 604 to reporting system 500 that he wants to receive a report based on data stored in database system 100 in connection to the use of his starting material, preferably by limiting the reported use to a particular growth season, region and / or variety of the starting material. In that case, reporting system 500 would have to identify on its own which data are required to create the requested report and which persons, in particular one or more growers 700, need to give consent to the use of their data.
[0163] As described above, seed and / or harvest certificate information can be individually encrypted to prevent unwanted disclosure thereof. In view of the reporting capabilities indicated herein, encryption has the further advantage that not even a fraudulent reporting system 500 would be able to create reports using the respective encrypted seed and / or harvest certificate information. Thus, the whole system of seed and harvest certificates as described herein has the further technical advantage of increasing privacy, data sovereignty and voluntary access control by all concerned parties.
[0164] Figure 5b shows a variant of the reporting process described in view of figure 5a. The explanations given above in view of figure 5a and the corresponding reporting process thus also apply to the process of figure 5b, with the following deviations:
[0165] In the reporting process described above in view of figure 5a, grower 700 had indicated, by message 720, consent to information access only after being asked to do so by reporting system 500 in a message 512. In the process shown in figure 5b, however, grower 700 already sends message 720 to reporting system 500 before seed vendor 600 even begins to ask for the creation of a report involving data pertaining to grower 700. In particular, such consent can be given by the grower already on the occasion of the creation of a seed certificate. In that case, reporting system 500 could directly receive message 720 from grower 700 or could indirectly receive message 720 by a corresponding message of the certification system 200 (not shown herein). At any rate, the type and scope of consent of grower 700 is saved in database system 100 by sending a corresponding message 514 by the reporting system 500 and / or the certification system 200 (not shown). In particular, the consent of grower 700 to the generation of one or more types of reports by seed vendor 600 could be stored already in a field of the corresponding seed certificate records prepared by the certification system 200 (not shown), storage of consent in this way would constitute a message 514. The process of report generation then proceeds as described above in view of figure 5a. Here, the reporting system 500 would conclude, in step 510, that all required information access rights have already been recorded in the database of database system 100. Instead of asking grower 700 for consent as described above for figure 5a, reporting system 500 would proceed and read the required information covered by the information release of message 720. Again, reporting system 500 would document, by message 514 to database system 100, the information that has been accessed and the reason for such access, i.e. the generation of the desired report for seed vendor 600. Reporting system 500 creates (517) the desired report, sends it by message 518 to seed vendor 600 who requested the report and optionally informs, by message 520, grower 700 that data pertaining to him (e.g. seed and / or harvest certificate information) have been used to generate the report for seed vendor 600.
Claims
CLAIMS1. Computer-implemented method of authenticating a harvest of agricultural material, comprising the steps of i) providing seed certificate data associated with a starting material, wherein the seed certificate data comprises a designation of the type of starting material, a designation of the quantity of starting material, and preferably a designation of the recipient of the starting material, a request for a harvest certificate, and context data associated with harvested offspring material, wherein the context data comprises a designation of a type of harvested material, a designation of a quantity of harvested material, a designation of the requester of the harvest certificate, and optionally a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested offspring material, ii) validating the request for the harvest certificate based on the seed and context data, iii) providing the result of the validation.
2. Method according to claim 1 , further comprising the step: iv) recording the result of the validation in a database, wherein the database preferably is a tamper-evident database.
3. Method of authenticating a harvest of agricultural material according to claim 1 or 2, comprising the steps of i) receiving, by an input computing node, information of at least one seed certificate, wherein the seed certificate information comprises a designation of the type of starting material, a designation of the quantity of starting material, and preferably a designation of the recipient of the starting material, a request for a harvest certificate, and context information regarding the harvested offspring material, wherein the context information comprises a designation of the type of harvested material, a designation of the quantity of harvested material, a designation of the requester, and optionally a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested offspring material, ii) determining, by a determination computing node based on a model, a confidence score indicative of the likelihood that the seed certificate information and context information match, iii) deciding, by a decider computing node, if the confidence score suffices a confidence threshold, and iv) recording, by a recorder computing node, an indication of the decision of the decider computing node in a database, wherein the database preferably is a tamper-evident database.
4. Method according to any of claims 1 -3, further comprising the steps of issuing a harvest certificate by an issuer computing node if the decider computing node decides that the confidence score suffices the confidence threshold, and by a recorder computing node recording the harvest certificate in a harvest certificate database and updating the corresponding seed certificate in the seed certificate database, wherein preferably the recording of the harvest certificate serves, in step iv), as the indication of the decision of the decider computing node, and wherein preferably the harvest certificate database is a tamper-evident database.
5. Authentication method according to any of the preceding claims, wherein the database containing seed certificate information is a distributed tamper-evident database.
6. Authentication method according to any of the preceding claims, wherein seed and / or harvest certificate information recorded in the database, respectively, is encrypted such that the recipient and / or the provider of the starting material can decrypt the information.
7. Authentication method according to any of the preceding claims, wherein the context information includes cultivation information comprising any of planting information parameters selected from one or more of location of cultivation; time of cultivation; treatment information, wherein treatment information can comprise any of time, type and intensity of starting material treatment, soil treatment, plant treatment; harvest information; harvest treatment information, sunshine duration, time and amount of irrigation, soil temperature, air temperature and / or productivity information pertaining to the location of cultivation selected from one or more of Soil Rating for Plant Growth rank, productivity index, soil texture, water holding capacity, nutrient content, topography, soil depth, drainage and water access, climate zone, average sunshine, average soil temperature, average air temperature.
8. Authentication method according to any of the preceding claims, wherein the determination computing node receives independent verification information relating to the cultivation information and the model takes into account the verification information.
9. Authentication method according to any of the preceding claims, wherein the model is updated using machine learning based on any of the context information, the cultivation information, the verification information and / or the decision of the decider computing node.
10. Authentication method according to claim 9, wherein, where cultivation and / or context information is missing, the model takes into account an estimate of the missing information, wherein preferably the estimates are updated using machine learning based on the information provided for accepted harvest certificate requests and / or verification information.11 . Authentication method according to any of the preceding claims, wherein the harvest certificate is only issued if sufficient context information has been provided that the harvested material suffices a business quality requirement.
12. Method of updating a model of an authentication method according to any of claims 1-11 by machine learning, comprising the steps of i) receiving one or more model parameters of the model, ii) inferring, based on context information and / or verification information provided in said authentication method, a change in at least one corresponding model parameter, and iii) updating the at least model parameter by the inferred changes.
13. A computer storage medium storing computer-readable instructions which, when used on a computing node, allows the computing node to execute a program for performing the steps of a computing node of the authentication method of any of claims 1-12.
14. A computer system comprising one or more authentication computing nodes configured to perform the method of any of claims 1-12.
15. An apparatus comprising i) a data providing interface configured to provide seed certificate data comprising a designation of the type of starting material, a designation of the quantity of starting material, and preferably a designation of the recipient of the starting material, a request for a harvest certificate, and context data associated with harvested offspring material, wherein the context data comprises a designation of a type of harvested material, a designation of a quantity of harvested material, a designation of the requester of the harvest certificate, and optionally a designation of the fraction of starting material certified by a seed certificate that has been consumed in the production of the harvested offspring material, ii) a validation engine configured to validate the request for the harvest certificate based on the seed and context data, iii) a data providing interface configured to provide the result of the validation.
16. Apparatus according to claim 15, further comprising iv) a database connection to record the result of the validation, preferably in a tamper-evident database.
17. Computer system according to claim 14 or apparatus according to claim 16, wherein the database is a distributed database such that for each seed and / or harvest certificate at least one database instance contains the corresponding seed or harvest certificate information.