Method and system for tamper resistant event sourcing using a distributed ledger

The method and system provide tamper-resistant event sourcing by using cryptographic functions and a blockchain to securely store and verify state data, ensuring immutability and reliable detection of corruption.

JP2026021339APending Publication Date: 2026-02-10MASTERCARD INT INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025170068
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-11-04
Filing Date
2025-10-08
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing event sourcing systems lack tamper-resistance, making them vulnerable to corruption or malicious alteration, which can lead to system state corruption and detection difficulties.

Method used

A method and system for tamper-resistant event sourcing using cryptographic functions and a blockchain to store and verify state data, ensuring immutability and detect any tampering by comparing hash values stored on the blockchain with computed hash values.

Benefits of technology

Ensures the state data is tamper-resistant and verifiable, allowing for secure and reliable detection of any corruption or alteration, maintaining the integrity of computing objects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026021339000001_ABST
    Figure 2026021339000001_ABST
Patent Text Reader

Abstract

To provide a method for verifying the state of an object through tamper resistant event sourcing.SOLUTION: The method includes receiving, by a receiver of a processing server, state data for a computing object and an identification value associated with the computing object, applying, by a processor of the processing server, a one way encryption function to the received state data to generate a comparison hash value, identifying, by the processor of the processing server, a published hash value stored in a blockchain with the identification value, and verifying, by the processor of the processing server, a state of the computing object with the state data based on a match between the generated comparison hash value and the identified published hash value.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This disclosure relates to event sourcing, and in particular to cryptographic functions and blockchains. The use of distributed ledgers such as applications or systems to This paper relates to tamper-resistant event sourcing for object classes.

[0002] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of U.S. Patent Application No. 17 / 518,755, filed November 4, 2021 No. 60 / 699,992, the entire contents of which are incorporated by reference for all purposes. [Background technology]

[0003] An event sourcing system processes incoming events, and each event System (e.g., application program, operating system, or This will result in a change in the resulting state of the entire computing system. If a rebuild or restore of a previous configuration is required, In order to be able to retrace events, such as A record of the event is stored in the Logging events is only useful if it is possible to

[0004] In addition, if an event in the event history is corrupted or maliciously altered, the system The resulting state is corrupted. In some cases, especially when malicious intent is involved, Such damage may be difficult or impossible to detect, and may be a vulnerability or This can leave other problems to the object. Information about the state of the object must be stored in a tamper-resistant location, and The data must be stored in such a way that any tampering with the data can be easily identified. However, at present, no system has been developed to accomplish such a task.

[0005] Therefore, the storage and verification of state data for computing objects is There is a need to bring about technical improvements in this area. Summary of the Invention

[0006] The present disclosure provides a method for tamper-resistant event sourcing and The present invention provides a system and method for verifying the state of an object through a computing device. State information about a computing object is stored for each event that affects the object. The status information may be obtained after each event or at other regular intervals. and the cryptography applied to the transformed state data. As a result, the hash function stored in a distributed ledger such as a blockchain a flash value and a computing object such as a timestamp or event identifier and / or an identifier associated with the current state. For the state of the object, apply a hash function to the state of the object, and and compare the resulting value with the value stored in the blockchain. Because the blockchain is immutable, tampering with the state data is impossible. It cannot be changed in any way and data cannot be hashed. This ensures that data is protected even when the blockchain is public. Additionally, if state data is provided, any entity may validate the state. This allows for greater security and reliability. The historical state data of each object is recorded on the blockchain. So if an entity has a version of an object that has become corrupted The corruption points are calculated by verifying the state data for each interval until the verification fails. Therefore, the state data about the object is It is tamper-resistant and allows verification and error detection with complete immutability.

[0007] The method for tamper-resistant event sourcing of objects is as follows: Thus, state data about a computing object and the state data of said computing object are stored. receiving a processing object and an associated identification value; applying a one-way encryption function to the received state data to generate a hashed value; generating a value by a transmitter of the processing server; and publishing the hash value and the identification value on the blockchain.

[0008] How to verify the state of an object via tamper-resistant event sourcing: The server's receiver receives state data about the computing object, and receiving the computing object and an associated identification value; and; one-way encryption by the processing server's processor to generate a comparison hash value. applying a function to the received state data; , identifying a public hash value that is stored in the blockchain along with the identifying value. and comparing the generated hash values ​​by the processor of the processing server. and the identified published hash value, according to the state data. and verifying the state of the computing object.

[0009] A system for tamper-resistant event sourcing for objects includes: a processing server; The processing server stores state data about the computing objects and a receiver that receives a routing object and an associated identification value; a processor that applies a cryptographic function to the received state data to generate a hash value; A transmitter that publishes the generated hash value and the identification value on a blockchain. This includes the following:

[0010] A system that verifies the state of an object via tamper-resistant event sourcing: a processing server that processes state data for computing objects; and an identification value associated with the computing object. a receiver and a processor that performs a one-way cryptographic function to generate a comparison hash value. to the received state data, and storing the identification value in a blockchain together with the identification value. and identifying the public hash value stored in the generated comparison hash. and based on a match between the state data and the identified published hash value, verifying the state of the computing object; and , including. [Brief explanation of the drawings]

[0011] The scope of the present disclosure is defined by the following description of exemplary embodiments when taken in conjunction with the accompanying drawings. The invention is best understood from the detailed description, which includes the following figures:

[0012] [Figure 1] FIG. 1 is a block diagram illustrating a high-level system architecture for tamper-resistant event sourcing, according to an example embodiment. [Figure 2] 2 is a block diagram illustrating a processing server of the system of FIG. 1 for enabling tamper-resistant event sourcing for computing objects, according to an exemplary embodiment. [Figure 3] 2 is a flow diagram illustrating a process by a processing server in the system of FIG. 1 for storing state data about computing objects in a tamper-resistant manner, according to an exemplary embodiment. [Figure 4] 2 is a flow diagram illustrating a process for verifying the state of an object using tamper-resistant event sourcing in the system of FIG. 1 according to an example embodiment. [Figure 5] 1 is a flow diagram illustrating an example method for tamper-resistant event sourcing for an object, according to an example embodiment. [Figure 6] 1 is a flow diagram illustrating an example method for verifying the state of an object via tamper-resistant event sourcing, according to an example embodiment. [Figure 7] FIG. 1 is a block diagram illustrating a computer system architecture, according to an exemplary embodiment.

[0013] Further areas of applicability of the present disclosure will become apparent from the detailed description provided hereinafter. This description is intended for illustrative purposes only and is not intended to necessarily limit the scope of the present disclosure. Not yet. DETAILED DESCRIPTION OF THE INVENTION

[0014] Glossary Blockchain: A public blockchain-based currency that stores all transactions. One or more computing devices can use the blockchain to create a public ledger. This may include a blockchain network, which may be part of a block in the blockchain. It may be configured to process and record transactions. Once a block is complete, The block is added to the blockchain, thereby updating the transaction record. In many embodiments, a blockchain is a chronological ledger of transactions. or presented in any other order suitable for use by the blockchain network. In some embodiments, transactions recorded on the blockchain may The token may contain a destination address and a currency amount. This allows the blockchain to determine how much In some embodiments, the transaction records which currency belongs to a particular address. The information may or may not be financial and may include additional or different information (e.g., software). In some embodiments, the block Blockchains can additionally or alternatively store almost any type of data in the form of transactions. This may include a continuously growing collection of data hardened against tampering or revision. What is or needs to be placed in a distributed database that maintains a list of records Alternatively, blockchains may use proof-of-work (PoW) and / or by any other suitable verification technique associated with the blockchain network. In some cases, for a given transaction, This data is furthermore a direct part of the transaction attached to the transaction data. In some cases, such data may be blocked. Inclusion in the chain can constitute a transaction. The blockchain can be used to exchange a particular digital currency, virtual currency, fiat currency, or other type of currency. It does not have to be directly related to

[0015] A system for tamper-resistant event sourcing Figure 1 illustrates the use of cryptographic hashing and blockchain to securely store and process computer-generated data in a tamper-resistant manner. SYSTEM 100 FOR EVENT SOURCING FOR NETWORKING OBJECTS This is shown.

[0016] The system 100 may include a processing server 102, which is described in more detail below. The management server 102 obtains state data about the objects and also provides tamper-resistant and exposes the state data in a secure manner to allow for validation and verification of the object's state data. Allows identification of errors or corruption in events associated with objects In the system 100, the processing server 102 may include a computer such as a state machine 104. The state machine 104 can receive state data about the object. It can be a holistic computing system that sources data, or Application programs, operating systems, and young people sourcing state data In some embodiments, the computer The processing object is part of or interfaces with the processing server 102. The status data can be transmitted electronically from the status machine 104 by the processing server 102. The status data may be obtained via communication or using any other suitable method. It can be useful for the operation of a computing object or for its later verification. It can include any data about the state of a computing object. The state data is based on the type of computing object, the associated entity, For example, the application program for email communication may The state data can be different from the state data of the operating system.

[0017] In some cases, state data about a computing object may be stored in a The state of the event sourcing system used for the routing object For example, an operating system (OS) can store information about the operation, such as event logs. Event tracking that allows you to track all actions and events that can affect your operating system. In such a case, the processing server 102 may include an event sourcing system. Using data from event logs or other event sourcing systems as state data State data for computing objects can be stored in any suitable It can be stored in any format, for example as part of the state machine 104. Cloud storage accessible within or by a memory or database It can be stored in a memory such as a memory card.

[0018] As mentioned above, the term "computing object" includes hardware, software, and software components, application programs, data objects, or For example, to take one example, The object can be a state machine 104. As a second example, An object can be an operating system. The computing object can be data associated with a bank account, The state data can include, for example, account-related events, which can be This may include opening an account, transferring funds to the account, making payments from the account, or other charges. In other words, the computing object can be a database of the supply chain. The status data may include, for example, the date of manufacture of the product, information about product validation or inspection, packaging, This may include a tagging date, shipping date, sale date, expiration date, etc.

[0019] The processing server 102 receives an identification value associated with a computing object. The identification value can be numeric, alphanumeric, etc. In some cases, the identification The other value can be unique with respect to the computing object. In some cases, the identification value may be unique with respect to the computing object, It can also relate to a particular state of a computing object. In such cases, each state of the computing object is represented by a different unique identifying value and Identification values ​​can be associated with computing objects regardless of their state. If the value is unique to the computing object, the processing server 102 A second identifier associated with the state of the device can be received. In such a case, the processing server 102 may create a unique The identification value for the computing object that is the Receive a state identifier that is unique across all states for the routing object. For example, the computing power executed by or on it can be Each action or event associated with a logging object has its associated The state identifier may have a value (e.g., a numerical order for the event) that is assigned to the state identifier. As another example, the state identifier may be used to indicate when state data changes to the current state. It can be a timestamp of when the change was made.

[0020] The processing server 102 can receive the state data and use cryptographic techniques, such as a one-way hash function. A function can be applied to the state data. The application of a cryptographic function results in a hash value In an exemplary embodiment, a collision-resistant cryptographic hash function can be used. The resulting hash value can be arbitrarily chosen to be of sufficient size and complexity. conflicts of opinion (e.g., the same hash occurs when a function is applied to two different sets of data) It can be made highly resistant to the effects of heat (the occurrence of heat shock). For example, the cryptographic function is Secure Hash Algorithm 256 (SHA-256). The cryptographic function can be a one-way function, which can be expressed as The original state data is hashed via any algorithm, function, or other mechanism using a hash value. This means that you cannot obtain

[0021] In some embodiments, the processing server 102 may also include a cryptographic function to store the state data. To format the status data, the processing server 10 2. First, the state data of the computing object is stored in JavaScript Object Notation. In some cases, it can be converted to an object notation representation such as a JSON representation. , the conversion may be based on the location of the state data as obtained by the processing server 102 or 102, other current representation of the state data as obtained by After converting the state data to its object notation representation, the processing subprocess The server 102 can transform the state data into a canonical representation. If the object notation representation is a JSON representation, the transformation of the state data follows the JSON normalization scheme. (JCS, JSON Canonicalization Scheme) rules. In other cases, Any applicable rules or conventions can be used to transform state data into a canonical representation. In such an embodiment, the canonical representation of the state data is a representation of the cryptographic function applied to the state data. It can be used when

[0022] The processing server 102 manages the computing objects and their associated states. Once a hash value is generated, it can be published on the blockchain. The blockchain is managed and maintained by a blockchain network108. Each blockchain network 108 may be comprised of multiple different blockchains. Each blockchain node 110 may comprise a blockchain node 110. 2 and 7 configured to perform functions related to the processing and management of the block chain. and described in detail below, e.g., Examples may include: blockchain data value generation, proposed blockchain Validating transactions, verifying digital signatures, generating new blocks, validation of the transaction, maintaining a copy of the blockchain. The server 102 is a blockchain node 110 within a blockchain network 108. It may be.

[0023] A blockchain can be a distributed ledger that comprises at least a number of blocks. Each block may contain at least a block header and one or more data values. The lock header contains at least a timestamp, a block reference, and a data reference. Good. The timestamp can be the time when the block header was generated, and It can be represented using any suitable method (e.g., UNIX timestamp, DateTime me notation, etc.). A block reference value is a reference to a previous block in the blockchain (e.g., In some embodiments, the block The block reference value in the block header is the block reference of the most recently added block preceding each block. It may be a reference to a block header. In an exemplary embodiment, the block reference value is: Generated by hashing the block header of the most recently added block Similarly, the data reference value can be the block reference value including the block header. The data value may be a reference to one or more data values ​​stored within the block. In , a data reference value is a hash generated by hashing one or more data values. For example, a block reference value can be created using one or more data values. It can be the root of the generated Merkle tree.

[0024] As a result of using a block reference value and a data reference value in each block header, The blockchain can be immutable. Any attempt to change a data value requires that the blockchain A new data reference value needs to be generated for the lock, which requires the block of the subsequent block to be A new lock reference value needs to be generated, and then a new one for each subsequent block. To make the change permanent, you need to create a valid block reference value. Before a new block is generated and added to the blockchain, the above is Execute and update each blockchain node 110 in the network 108 The limitations of computing and communication capabilities make such changes extremely difficult. This can be a difficult or impossible task, hence the immutability of blockchain.

[0025] In the system 100, a blockchain node 110 (e.g., a processing server 102) A hash value for a computing object and its associated state Any identifying information (e.g., identifying values ​​and states for computing objects) The hash value and associated identification information may be stored in a suitable manner. It is generated and included in a new block that is generated and added to the blockchain using the The new block can be stored in the new blockchain data value that is being created. Distributed to all blockchain nodes 110 in the blockchain network 108 If the blockchain can be a public blockchain, new The blocks are made accessible by any interested entity, such as the state machine 104. This ensures that the state data is properly stored in the tamper-resistant blockchain.

[0026] The processing server 102 may continue to generate hash values ​​at regular intervals. In this case, an action or event that affects the state of a computing object Each time a new event occurs, a new hash value is computed using the updated state data. In other cases, a new hash value can be generated for the It can be generated periodically (e.g., after a predetermined period of time (e.g., hourly, daily, weekly, etc.) (which may depend on the object and state changes), a predetermined number of actions or events after a certain number of events, after a certain number of state-changing actions or events, etc.

[0027] In the system 100, a processing server 102, a state machine 104, or another interested entity The entity or system (e.g., the verification system 106) may There may be interest in verifying state data about the object. For example, If the computing object is an operating system, the validation system 106 utilizes the operating system and updates to the operating system. The validation system 106 may apply the updated operating system. The intent may be to ensure that the information is valid and has not been tampered with (e.g., to prevent malicious activity). (When malicious update data is provided to the verification system 106 by a malicious entity.) The verification system 106 directly verifies the appropriate hash value stored in the blockchain. either directly or via the processing server 102. The system update status can be verified.

[0028] In an exemplary embodiment, the verification system 106 may include a Current status data about the device can be electronically transmitted to the processing server 102, A unique identification value for the operating system and an operating system Any identifying information such as a version number can be sent as a state identifier for The processing server 102 receives the status data and the identification information from the verification system 106. The processing server 102 can then transform the state data accordingly and apply a cryptographic function to the state. The processing server 102 can apply the hash value to the provided data to generate a new hash value. Using the identification value and state identifier, a computing object is created in the blockchain. The processing server can then identify the public hash value for the object. 102, the verification system 106 has the state of the computing object You can verify it and check the new hash value generated against the published hash value. If the values ​​match, the computing object (e.g., the updated operator) The processing server 102 may optionally configure the verification system 10 6, and the verification system 106 can provide information to the operating system. If the hash values ​​do not match, the processing server 102 The instance can be provided to the verification system 106, and the verification system 106 06 is to restore a computing object to a previous state where validation was successful. As a result, any entity can Immutable hash values ​​can be used to verify the state of computing objects. This makes the status data completely tamper-resistant.

[0029] If new hash values ​​are published periodically for computing objects, When a validation fails, the local state data of the computing object (e.g. Validate your system (operating system version) to identify if it is corrupted For example, a verification system can use publicly available hashed state data. The 106 operating system has been successfully verified with version 12. You have been using the operating system for some time, over several updates, and If you try to verify using operating system version 18 and the verification fails, If this is due to receiving tampered update data between versions 12 and 18, After version 18 fails on the validation data, the validation system 106 Server processing status data about version 17 of the operating system 102 to attempt another validation. If that validation fails, In this case, the verification system 106 will not continue to run the operating system until the verification is successful. For example, version 15 can continue to test the If the verification fails but version 14 is successful, the verification system 106 It can be determined that the update data for 15 has been tampered with. can be reverted to version 14, for example, from the state machine 104 or from another entity. Get valid updates directly from the entity and When the system is updated, new validations can be performed. 106 provides the processing server 102 with version 12 of the operating system. And, the update data for each version up to version 18 (for example, in other examples The processing server 102 may also provide the following: Update the state data with the updates for version 13 and then upload it to the blockchain. Validate the updated state data with the associated hash value in Continue updating and verifying the updated operating system until the verification fails. Therefore, the management server 102 or any other entity may report a validation failure for the state data. You can follow the trace in either direction to identify when the tampering that caused the loss occurred. .

[0030] In another example, the state machine 104 may be a database of a financial institution such as a bank. The computing object can be a bank account, and the data for the bank account can be In this example, the status data for a bank account is stored in a database. When opening an account, depositing, withdrawing, etc., the data is hashed and published on the blockchain. The published state data may be the state of the account at a given point in time (e.g., It can be used to verify the status of an account (balance). By disclosing the data, deposits on the account or payments on the account are verified. For example, a dispute may arise between an account holder and a business operator, and the business operator may The account holder may claim non-payment by the creditor. This can be hashed and published on the blockchain as a state data. data and use it to verify the state that it is claimed to be in before payment. The account holder can present the post-payment account, which is hashed again and The business operator or the verification system 106 can independently verify the payment. It will be established that the amount of the loan is being paid and the account is reflected accordingly.

[0031] According to the described method and system, an image of a computing object is Storing ventsourcing data or status data in a completely tamper-resistant manner This will allow for the creation of transactions that are fully verifiable at the same time. The use of a rule ensures that state data cannot be tampered with, while verification still requires The use of cryptographic hash functions also allows verification. publicly accessible without compromising the inclusion of any sensitive or confidential data. This allows applications to store state data in a distributed ledger that can be accessed by the application. Entities that have application programs available will continually update their status data. and published on the blockchain, allowing all customers to easily and securely access the application. This allows you to verify the version of the application program. Any tampering with the local copy can be easily and quickly identified. Therefore, the described method and system uses cryptographic functions and blockchain technology. Technical considerations regarding event sourcing and state data storage and validation through the use of Brings improvement.

[0032] Processing Server FIG. 2 illustrates an embodiment of a processing server 102 (e.g., processing server 102 in system 100). Those skilled in the art will recognize that the embodiment of processing server 102 shown in FIG. 2 is for illustrative purposes only. All possible processing servers 102 are provided and suitable for performing the functions of the present disclosure. It is self-evident that this is not an exhaustive description of the various configurations. The computer system 700 described in detail is a suitable configuration for the processing server 102. That's fine.

[0033] The processing server 102 may include a receiving device 202. The receiving device 202 may be connected to one or more networks. configured to receive data over one or more networks via a network protocol In some examples, the receiving device 202 may be a radio frequency, local area network, Wireless area networks, cellular communication networks, Bluetooth, the Internet, etc. Through one or more communication methods, the state machine 104, the verification system 106, the blockchain node configured to receive data from the network 110 and other systems and entities. In some embodiments, the receiving device 202 may receive data from multiple devices (e.g., different networks). different receiving devices receiving data on the network (e.g., data on a local area network) and a second receiving device that receives the data over the Internet. The receiving device 202 may receive the transmitted electronic data signal. Upon reception of the data signal by the receiver 202, data is superimposed on the data signal. , decoded, parsed, read, or otherwise obtained. The device 202 analyzes the received data signal to obtain the data superimposed thereon. For example, the receiving device 202 may include an analysis module for receiving the received data signal. and converting it into usable input for a function performed by a processor in accordance with the present disclosure. The method and system may include an analysis program configured to implement the method and system.

[0034] The receiving device 202 receives the data electronically transmitted by the blockchain node 110. The data signal may be configured to receive a blockchain signal. Data values, blocks, blockchain transaction data, etc. are superimposed or encoded. The receiving device 202 may also receive status data, event sourcing data, and update data. data, event or action data, identification values, state identifiers, etc. 104, which may be configured to receive data signals electronically transmitted by the state machine 104. The receiving device 202 may also be configured to receive status data, an identification value, a status identification, It is superimposed or encoded with identifiers, update data, event or action data, etc. configured to receive a data signal electronically transmitted by the state machine 104, It can also be done.

[0035] The processing server 102 may also include a communications module 204. The communications module 204 , modules, engines, databases, for use in performing the functions of the present disclosure; The memory may be configured to transfer data between other components of the processing server 102. The communication module 204 may include one or more communication types and may be used by a computing device. Various communication methods may be used for communication within the device. For example, the communication module 204 may It may include buses, connecting pin connectors, wires, etc. In some embodiments, the communication module The management server 204 also manages the internal components of the management server 102 and the external components of the management server 102. (e.g., externally connected databases, display devices, input devices, etc.) The processing server 102 may also include a processing unit. This is readily apparent to those skilled in the art. In some embodiments, the processor performs one or more functions of the processor. Multiple engines and / or modules (e.g., query module 2) specifically configured for 14, generation module 216, verification module 218, etc. The term "module" refers to a program that receives input and performs one or more operations using that input. and providing an output. The inputs, outputs, and processing performed by the various modules may be implemented in accordance with the present disclosure. and is obvious to those skilled in the art.

[0036] The processing server 102 may include blockchain data 206, which may be used by the processing server. The data is stored in the memory 212 of the processing server 102 or in a separate area within the processing server 102. Blockchain data 206 may include a blockchain, which may comprise multiple blocks, The blockchain may be associated with a blockchain network 108. Data 206 may be in addition to or in place of any data associated with the blockchain. Alternatively, this may include: cryptographic key pairs, blockchain Network identifiers, encryption algorithms, formatting, etc. for the network 108 rules, signature algorithms, etc.

[0037] The processing server 102 may also include a memory 212. The memory 212 may implement the functionality of the present disclosure. Data (e.g., public key, private key, pair) for use by the processing server 102 when executing The memory 212 may be configured to store various data, such as a key, a name, and a password. The data may be configured to be stored using any suitable method and schema, and may be stored in any suitable format. The memory may be any memory (e.g., read-only memory, random access memory, etc.). The memory 212 stores, for example, cryptographic keys and algorithms, communication protocols and standards, data formats, and mat standards and protocols, program code for modules and processor applications application programs, as well as the programs used by the processing server 102 in performing the functions of the present disclosure. This will be apparent to those skilled in the art after reading this disclosure. In some embodiments, the memory 212 uses a structured query language (SQL). A relational database may be included to store and identify the stored structured data sets. , modify, update, access, etc. The memory 212 may store, for example, cryptographic keys, salts, nonces, , communicating information to other computing systems, cryptographic functions, formatting It may be configured to store binding rules, expression data, cryptographic key pairs, canonicalization schemes, etc.

[0038] The processing server 102 may also include a query module 214. The query module 4 may be configured to perform a query on the database to identify the information. The module 214 may receive one or more data values ​​or query strings and, based on , and the indicated database (e.g., the blockchain data 206 of the processing server 102) ) to identify the information stored there. The engine 214 then routes the identified information to the appropriate engine of the processing server 102 as needed. The query module 214 may output the query to a blockchain or other module. Querying the data 206 and publishing using the provided identification value and state identifier Identify the generated hash value and compare it to the generated hash value to validate the given state data. You can confirm it.

[0039] The processing server 102 may also include a generation module 216. The generation module 216 , generating data used by the processing server 102 when performing the functions of the present disclosure. The generation module 216 may receive instructions as inputs and may be configured to The data may be generated based on the instruction and the generated data may be sent to one or more of the processing servers 102. For example, the generation module 216 may generate a cryptographic and the method may be configured to apply a genetic function to generate a hash value; For example, applying a one-way cryptographic hash function to event sourcing or state data to generate unique The processing server can generate a stable and / or collision-resistant hash value. If the node 110 can be a node 110, the generation module 216 can generate a cryptographic key pair or digital Generates a signature, generates blockchain data values, and creates new blocks. It generates blocks and data references, aggregates state changes, and The device may also be configured to generate a check record, etc.

[0040] The processing server 102 may also include a validation module 218. 8 is configured to perform validation for the processing server 102 as part of the functionality described in this disclosure. The verification module can be configured as follows: It can receive as input instructions that may be included, and can perform verification on demand, and verification The results of the verification can be output to another module or engine of the processing server 102. Rule 218 may be configured, for example, to validate the received status data. , hash the state data and store the resulting hash value on the blockchain. This can be done by comparing the hash value published in some cases. The validation module 218 performs a series of validations that result in a failed validation. Determine the actions or events and identify the actions or events that may have been tampered with. It can be identified.

[0041] The processing server 102 may also include a sending device 220. The sending device 220 may include one or more configured to transmit data over one or more networks via the network protocols In some examples, the transmitting device 220 may be configured to transmit over a local area network, wireless One of the following: Wire Area Network, Cellular, Bluetooth, Radio Frequency, Internet, etc. Through the above communication methods, the state machine 104, the verification system 106, and the blockchain node The data may be configured to be transmitted to the network 110, as well as to other entities. In this embodiment, the sending device 220 may transmit data to multiple devices (e.g., on different networks). a different transmitting device for transmitting (e.g., transmitting data over a local area network) and a second transmitting device for transmitting data over the Internet. The transmitting device 220 may transmit the superimposed data to the receiving computing device. In some embodiments, the data signal may be transmitted electronically with the data being analyzed by the In the example, the transmitting device 220 superimposes, encodes, or converts data into data suitable for transmission. It may include one or more modules for formatting the signal.

[0042] The transmitting device 220 electronically transmits the data signal to the blockchain node 110. The data signal may be configured to include a blockchain data value, Blockchain transaction data, proposed genesis block record , state database data, smart contract state data, confirmation messages, etc. The transmitter 220 electronically transmits the data signal to the state machine 104. The data signal may be configured to include the generated hash value, the block Notification of on-chain data values, publication of state data, state data or event sourcing The sending device 220 may be superimposed or encoded with a request for data, etc. and may be configured to electronically transmit a data signal to may be superimposed or combined with notifications about performed verifications, requests for status or identification data, etc. It can be encoded.

[0043] Processing for publishing tamper-resistant event sourcing data FIG. 3 illustrates a tamper-resistant state or event system on a blockchain within system 100. Regarding the process 300 executed by the processing server 102 to publish the data of the show.

[0044] At S302, the receiving device 202 of the processing server 102 receives the computing object State data or event-sourced data about the The identification value associated with the object and the state identification associated with the given state data. The identification data of the child or other person may be transmitted to the state machine 104 or other device using any suitable communication network and method. In step S304, the processing server 102 receives the received Determine whether the received state data is properly formatted for hashing The determination may be performed by any suitable component of the processing server 102. The received status data can be stored in the processing server 102 or accessed by the This may involve comparison to one or more accessible standards, guidelines, etc. If the data is not formatted, in step S306, the generating module of the processing server 102 The rule 216 can convert the state data into an object notation representation such as a JSON representation. However, other options are available. Then, in S308, the processing server 10 The second generation module 216 converts the state data from its JSON representation to a canonical representation. This can be done, for example, using JCS or another normalization scheme.

[0045] After the state data is converted to a canonical representation, or in step S304, the processing server 102 converts the state data If the processing server 102 determines that the data is already properly formatted, Module 216 applies a cryptographic hash function to the formatted state data. Cryptographic hash functions provide sufficient complexity to be collision-resistant, while A cryptographic function can be applied to the formatted state data. When used, it yields a hash value for the state of the computing object. In S312, the sending device 220 of the processing server 102 sends the generated hash The value, the identification value, and the state identifier are sent to the blockchain in the blockchain network 108. The new block can then be sent electronically to the new node 110, which will then include the new block. The purpose is to publish the data in the blockchain data value, and the new block is confirmed and In some embodiments, the processing server 102 adds the hash A notification message indicating that the value has been successfully published is sent to the state machine via the sending unit 220. 104, which may include the hash value and / or the block It may contain any confirmation data received from the chain node 110. The value is used to validate the state of the computing object. , can be stored in a tamper-resistant blockchain.

[0046] Processing to verify the state of a computing object Figure 4 shows how event sourcing or state data can be made resistant via blockchain. for verifying the state of computing objects using tamper-resistant storage - Patent Application 20070122967 1 illustrates a process 400 executed by a processing server 102 in the system 100. The process 400 is implemented by a processing server 102 receiving multiple events and executing each event to execute a command. Examples of when validation can be performed on computing objects can be given. Those skilled in the art will appreciate that a single set of state data may be implemented, or may not have any associated Some set of state data is provided to the processing server 102 without accompanying event data. It will be apparent that the process 400 may differ depending on the case.

[0047] At S402, the receiving device 202 of the processing server 102 receives the computing object The event data can be received from multiple different It may include actions or events that are performed by a computing object. When applied or executed, they can change state data. The event data includes a specific order of application for the action or event data. In some cases, each action or event in the event data may be processed. It may have a state identifier associated with it that is provided to the server 102. The data is received from the verification system 106 using any suitable communication network and method. It is possible.

[0048] In S404, the processing server 102 determines whether any action or event is being verified. It can determine whether one or more events remain in the received event data. If there are any remaining actions or events, the processing server 102 selects the next event in step S406. The processing server 102 may execute events or actions in the order, timestamp, etc. The next event or action can be identified using the event or action. Execution of the program can update the state data, which is equivalent to directly modifying the state data. and / or applications that modify application programs or associated data. By performing actions using application programs and by storing state data In step S408, the generating module of the processing server 102 The controller 216 may apply a cryptographic hash function to the state data. The hash function should be a one-way hash function that provides sufficient complexity to be collision-resistant. Applying a cryptographic function to the state data can In some embodiments, the processing may yield a hash value for the state of the project. The management server 102 performs the steps S306 and S308 shown in FIG. , first the state data can be formatted.

[0049] When the hash value is generated, the processing server 102 starts the blockchain network in S410. In the blockchain associated with the network 108, The published hash value for the object and the execution of the S406 event or action The published hash value can be used to identify the state produced by the row. The identification value associated with the event or event executed in S406 can be identified using the state identifier associated with the action. At 2, the processing server 102 determines that the status of the computing object is successful. This can be done, for example, by the processing server 102. This is done by the validation module 218 performing the validation. Checking whether the hash value matches the identified and published hash value This is done by:

[0050] If the verification is unsuccessful, such as if the two hash values ​​do not match, the processing server 102 The device 220 electronically sends a notification message to the verification system 106 indicating that the verification failed. In some cases, notification messages may include a status identifier or a failed detection. The authentication may include other information that indicates events or actions that were performed prior to the authentication. In such cases, notification may allow the verification system 106 or other entity to determine when the access Whether or when event sourcing data was altered It is possible to identify the following.

[0051] If the verification at S412 is successful, the process 400 returns to S404, where the processing server 102 determines whether there are further actions or events to perform in the received event data. If so, the processing server 102 returns to step S406 to continue the process 400. Next, as long as the verification is successful, each action or event is processed. When it is determined that all actions or events have been executed and all validations have been completed, If successful, and the management server 102 determines that no further actions remain to be taken Then, the process 400 can proceed to step S416, where the processing server 1 The transmitting device 220 of 02 sends a notification message to the verification system indicating that all verifications have been successful. The verification system 106 can then electronically transmit the verification result to the computer. No tampering has been made with the Event Sourcing object or its Event Sourcing data. You can trust your computing objects.

[0052] Exemplary Methods for Tamper-Resistant Event Sourcing Figure 5 shows the computation of a computing object through the use of cryptographic functions and blockchain. 5 illustrates a method 500 for tamper-resistant event sourcing for a project.

[0053] In S502, the state data and the computing object are The identification value associated with the processing object is 102) can be received by a receiver (e.g., receiving device 202). In 04, the one-way encryption function is executed by a processor of the processing server (e.g., a generation module 21 6) is applied to the state data received by In S506, the generated hash value and identification value are processed on the blockchain. The information can be published by a transmitter (eg, sending device 220) of the server.

[0054] In one embodiment, the method 500 further comprises: The processor (e.g., the generation module 216) converts the state data into an object notation table. In a further embodiment, the object notation representation can be It can be expressed in JSON (JavaScript Object Notation). In this embodiment, the method 500 further comprises: prior to application of the one-way encryption function, For example, a generation module 216) converts the transformed state data into a canonical representation. In a further embodiment, the transformed state data may be in JSON (JSON format). JavaScript Object Notation (JCS) normalization scheme can be converted according to the Anonicalization Scheme.

[0055] Exemplary Method for Validating Object State Figure 6 shows the concept of tamper-resistant event sourcing computing via blockchain. 6 illustrates a method 600 for validating the state of a logging object.

[0056] In S602, the state data and the computing object are The identification value associated with the processing object is 102) can be received by a receiver (e.g., receiving device 202). In 04, the one-way encryption function is executed by a processor of the processing server (e.g., a generation module 21 6) is applied to the received state data to generate a hash value. can.

[0057] In S606, the public hash value stored in the blockchain together with the identification value is are identified by a processor (e.g., query module 214) of the processing server. In S608, the computing object according to the state data is The status of the hash is determined based on a match between the generated comparison hash value and the identified published hash value. and be validated by a processor (e.g., validation module 218) of the processing server. This can be done.

[0058] In one embodiment, the method 600 includes, by a processing server, receiving, applying The steps of identifying, identifying, and verifying are performed as a computing object. Iterating through a plurality of states of the object, each of which is performed for state data. In a further embodiment, the state of the computing object The verification for may fail in one of several conditions. The processing server then sends a notification message identifying one of several conditions that caused the failed validation. transmitting the signal by a transmitter (e.g., transmitting device 220) of the server. do.

[0059] Computer System Architecture FIG. 7 illustrates a computer system 700 in which embodiments of the present disclosure may be implemented. Parts thereof may be implemented as computer-readable code. For example, the processing subroutines of FIGS. The server 102 may include hardware, a non-transitory computer-readable medium having stored instructions, , or a combination thereof, may be implemented in computer system 700 using one or more The hardware may be implemented in a computer system or other processing system. embodies modules and components used to implement the methods of FIGS. It is possible.

[0060] Where programmable logic is used, such logic may be implemented as executable software. It runs on a commercially available processing platform configured with hardware code and It may be a dedicated device or a special purpose device (e.g., a programmable logic array (P A person skilled in the art would understand the disclosed subject matter. It will be appreciated that embodiments can be implemented on a variety of computer system configurations. The system configuration is a multi-core multi-processor system, a minicomputer, and a main Frame computers and linked or clustered computers with distributed functionality and general-purpose or miniature computers that can be implemented in virtually any device. For example, at least one processor unit and memory may be used to implement the above embodiments. may be used for

[0061] A processor unit or device of the present disclosure may be a single processor, multiple processors, or A processor unit may have one or more processor "cores." "Computer program medium" and "non-transitory computer-readable medium" in this disclosure and the term "computer-usable medium" generally refers to tangible media (e.g., removable storage unit 718, removable storage unit 722 and hard disk The term "hard disk drive" is used to refer to a hard disk drive (such as a hard disk installed in hard drive 712).

[0062] Various embodiments of the present disclosure are described with reference to this exemplary computer system 700. After reading this disclosure, those skilled in the art will recognize that other computer systems and / or It is obvious how to implement the present disclosure using a computer architecture. Although disclosed as sequential processing, some operations may in fact occur in parallel and simultaneously. The program code may be executed in a single processor and / or in a distributed environment. Locally or remotely for access by single or multi-processor machines Furthermore, in some embodiments, the order of operations may be stored in the disclosed It may be rearranged without departing from the spirit of the matter.

[0063] Processor unit 704 may be a special purpose or The processor unit 704 may be a general-purpose processor unit. 706 (e.g., buses, message queues, networks, multi-core message path skips) The network may be connected to any suitable network suitable for performing the functions of the present disclosure. The network may be a local area network (LAN), a wide area network (WLAN), Network (WAN), wireless network (e.g. Wi-Fi), mobile communication network , satellite networks, internet, fiber optics, coaxial cable, infrared, radio frequency (RF) or any combination thereof. Other suitable network types and configurations The configuration of the computer system 700 will be apparent to those skilled in the art. 08 (e.g., random access memory, read-only memory, etc.) and may also include The secondary storage device 710 may include a hard disk drive 712. and a removable storage drive 714 (e.g., a floppy disk drive, a magnetic tape drive, etc.). The storage device may include a hard disk drive, a hard disk drive, an optical disk drive, a flash memory, etc.

[0064] The removable storage drive 714 may be a removable storage unit, in a known manner. Unit 718 may be read from and / or written to. The removable storage unit 718 includes a removable storage drive 714. This includes removable storage media that can be read and written by For example, if the removable storage drive 714 is a floppy disk drive, If the removable storage unit 718 is a flash drive or USB port, In one embodiment, the storage device may be a hard disk or a portable flash drive. The removable storage unit 718 may be a non-transitory readable recording medium.

[0065] In some embodiments, secondary storage 710 includes alternative means for storing computer programs. RAM or other instructions are stored in the computer system 700 (e.g., removable storage 622 and An example of such a means is ( Program cartridges and cartridge inserts (e.g., found in video game systems) interface, removable memory chips (e.g., EEPROM, PROM, etc.) and associated The attached socket, other removable storage unit 722 and interface 72 This may include 0. This is obvious to those skilled in the art.

[0066] The computer system 700 (e.g., the main memory 708 and / or secondary storage device) The data stored in 710 may be stored on any type of suitable computer readable medium (e.g., For example, optical storage (compact discs, digital versatile discs, Blu-ray discs) or magnetic tape storage (e.g., hard disk drive) The data can be stored in any type of suitable database structure (e.g., a relational database). , Structured Query Language (SQL) databases, distributed databases, object databases Suitable configurations and storage types will be apparent to those skilled in the art. be.

[0067] Computer system 700 may also include a communications interface 724. The interface 724 allows software and data to be exchanged between the computer system 700 and external devices. An exemplary communication interface 724 may allow data to be sent to and received from the device. , modem, network interface (e.g., Ethernet card), communication port, P The communication interface 724 may include a CMCIA slot and card. The software and data transmitted may be in the form of signals. The signal forms may be electronic, electromagnetic, The signal may be electrical, optical, or other signal as would be apparent to one skilled in the art. 726. The path is configured to carry the signal and may be wire, cable, optical It may be implemented using fiber, telephone lines, cellular phone links, radio frequency links, and the like.

[0068] The computer system 700 may further include a display interface 702. The interface 702 allows data to be transmitted between the computer system 700 and the external display 73 0. An exemplary display interface The 702 supports High-Definition Multimedia Interface (HDMI), digital visual Interface (DVI), Video Graphics Array (VGA), etc. Display 730 may be any suitable type of display and may be used in conjunction with a computer system. 700 via the display interface 702 of the system 700, Cathode ray tube (CRT) displays, liquid crystal displays (LCDs), light emitting diodes (LEDs) ED (Electro-optical Display), Capacitive Touch Display, Thin Film Transistor (TFT) Display This includes displays, etc.

[0069] The computer program medium and the computer usable medium are This may refer to the main memory 708 and auxiliary memory device 710, and may be a semiconductor memory (DRAM, etc.). These computer program products may be installed in the computer system 700. It may be a means for providing computer software. The computer control logic is stored in main memory 708 and / or secondary storage device 710. Computer programs may also be received via communications interface 724. Such a computer program, when executed, may 00 may enable the computer program to perform the methods of the present disclosure. When executed, the processor unit 704 performs the operations shown in FIGS. 3-6 as described herein. Therefore, such computer programs can The program illustrates the controller of computer system 700. This disclosure is based on software The software is implemented using a removable storage drive 714, interface 720, and hard disk drive 712 or communication interface 724 7, stored in a computer program product and loaded into the computer system 700. It is okay to be downloaded.

[0070] Processor unit 704 is configured to perform the functions of computer system 700. Each module or engine may include one or more hardware components. may be implemented using hardware, and in some embodiments software (e.g., The program code or program code stored in the main memory 708 or the secondary memory 710 In such an embodiment, the program code may be Before being executed by the hardware of the computer system 700, the processor unit 704 For example, it may be compiled (e.g., by a compilation module or engine). Program code is software written in a programming language that is translated into a low-level language. It may be source code (e.g., assembly language or machine code) that is used by the processor. Any additional hardware components of device 704 and / or computer system 700 The compilation process is performed by lexical analysis, preprocessing, and syntactic analysis. Analysis, Semantic Analysis, Syntax-Driven Translation, Code Generation, Code Optimization, and Computer Systems Translating program code into a low-level language for control of the system 700 to perform the functions of the present disclosure This may include use with any other technology suitable for performing such processing. The computer system 700 is equipped with a special computer uniquely programmed to perform the functions described above. The configuration of computer system 700 will be apparent to those skilled in the art.

[0071] Techniques consistent with this disclosure include, among other features, tamper-resistant event sourcing and System and method for verifying object state via tamper event sourcing Various exemplary embodiments of the systems and methods of the present disclosure are described above. It should be understood that the following is given for illustrative purposes only and not for limiting purposes. It is not intended to limit the disclosure to the precise form disclosed. Modifications and variations may be made in light of the above teachings. Modifications and variations are possible from the implementations of this disclosure without departing from the scope or spirit of the present disclosure. can be obtained.

Claims

1. 1. A method for tamper-resistant event sourcing for an object, comprising: The receiver of the processing server receives state data about the computing object. and an identification value associated with said computing object. Tep and A processor of the processing server applies a one-way encryption function to the received state data. applying the data to generate a hash value; The generated hash value and the identification value are transmitted by a transmitter of the processing server. publishing the above on the blockchain; A method comprising:

2. The method of claim 1 further comprising: Before applying the one-way encryption function, the processor of the processing server The method includes converting the state data into an Object Notation representation.

3. 3. The method of claim 2, wherein the object notation representation is JSON (JavaScript Object Notation). Object Notation (Object Notation) representation, a method.

4. The method of claim 2 further comprising: Before applying the one-way encryption function, the processor of the processing server The method includes converting the transformed state data into a canonical representation.

5. 5. The method of claim 4, wherein the transformed state data is in JavaScript Object Access Protocol (JSON). JavaScript Object Notation Canonicalization Scheme (JCS) The method is to convert the data in accordance with the Transformation Scheme.

6. A method for verifying the state of an object via tamper-resistant event sourcing 、 The receiver of the processing server receives state data about the computing object. and an identification value associated with said computing object. Tep and A one-way cryptographic algorithm is used by the processing server's processor to generate a comparison hash value. applying a scaling function to the received state data; The processor of the processing server stores the identification value in the blockchain together with the identification value. identifying a stored public hash value; The processor of the processing server compares the generated comparison hash value with the identification value. The computer then executes the state data based on a match with the published hash value. verifying the state of the object; A method comprising:

7. The method of claim 6 further comprising: The receiving step, the applying step, the identifying step, and the and performing said verifying step on a plurality of said computing objects. iterating through states, each state of the plurality of states being A method comprising steps including different sets of steps.

8. 8. The method of claim 7, The verification of the state of the computing object is performed by Failing on one, The method further comprises: a notification message identifying said one of said plurality of conditions that caused the failed verification; transmitting by a transmitter of said processing server.

9. A system for tamper-resistant event sourcing of objects, comprising: a processing server, the processing server comprising: State data about a computing object and a receiver for receiving an object and an associated identification value; A process for applying a one-way cryptographic function to the received state data to generate a hash value. The processor and The generated hash value and the identification value are published on the blockchain. A system including a transmitter.

10. 10. The system of claim 9, wherein the processor of the processing server converting said state data into an object notation representation before applying a cryptographic function; Hmm.

11. 11. The system of claim 10, wherein the object notation representation is JSON (JavaSc A system that is a Ripple Object Notation (RIPT) representation.

12. 11. The system of claim 10, wherein the processor of the processing server converting the transformed state data into a canonical representation before applying a forward encryption function to the transformed state data; Hmm.

13. 13. The system of claim 12, wherein the transformed state data is JSON (JavaSc JavaScript Object Notation (JCS) normalization scheme A system that is transformed in accordance with the icalization scheme.

14. A system for verifying the state of objects through tamper-resistant event sourcing. So, a processing server, the processing server comprising: State data about a computing object and a receiver for receiving an object and an associated identification value; 1. A processor, comprising: applying a one-way cryptographic function to the received state data to generate a comparison hash value; and A public hash value stored in the blockchain together with the identification value To identify and A match between the generated comparison hash value and the identified public hash value verifying a state of the computing object according to the state data based on the and a processor that executes the above.

15. 15. The system according to claim 14, wherein the processing server performs the receiving, applying, and and repeating the identification and verification for multiple states of the computing object. , wherein each state of the plurality of states includes a different set of state data.

16. 16. The system of claim 15, The verification of the state of the computing object is performed by Failing on one, The processing server further identifies the one of the plurality of conditions that caused the failed verification. a transmitter configured to send a notification message to a