Distributed database structure for anonymous information exchange
A decentralized information exchange platform with a distributed database structure addresses the challenge of sharing product data anonymously and securely, enhancing the circular economy by facilitating the reuse and recycling of products.
Patent Information
- Application Number
- JP2025192180
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2018-06-15
- Filing Date
- 2025-11-12
- Publication Date
- 2026-02-10
AI Technical Summary
In a circular economy, products must be properly reincarnated into the next generation of products, but information about a product's previous life is often unavailable due to confidentiality concerns, and verifying authenticity is difficult, hindering effective information exchange between parties.
A decentralized information exchange platform using a distributed database structure allows anonymous information sharing while maintaining accountability, enabling participants to exchange product data flexibly and securely through a network of manifests linked by labels.
This platform ensures anonymous yet accountable information exchange, facilitating the reuse and recycling of products by maintaining data integrity and security, and allowing flexible control over information access and propagation.
Smart Images

Figure 2026021567000001_ABST
Abstract
Description
[Technical Field]
[0001] cross reference
[0001] This application claims priority to U.S. Provisional Patent Application No. 62 / 685,781, filed June 15, 2018, the entire contents of which are incorporated herein by reference. [Background technology]
[0002] background
[0002] Currently, much of the global economy moves in one direction: raw materials are mined, products are assembled, more products are assembled from other products, products are consumed, and products are discarded. A circular economy strives to reinject as many "consumed" products as possible into the economy, rather than using them once and then throwing them away. Reinjection can occur through repair, reuse, modification, and recycling of products that would previously have been discarded. Summary of the Invention [Problem to be solved by the invention]
[0003] overview However, for a circular economy to be effective, products must be properly reincarnated into the next generation of products. To achieve this, it is essential that information about a product's "previous life" (or lives) be available to comply with regulations (e.g., to avoid health and environmental risks) when processing the product for reintroduction into the economy. Many parties involved in a product's life cycle are unwilling to provide such information because one party (who has the information) does not want to directly contact another party (who needs the information) for fear of breaching confidentiality or losing control of the information if it is disclosed to a single entity. Even if information is provided, verifying the authenticity of such information is difficult. Therefore, this specification recognizes the need for an information exchange platform that maintains anonymity while keeping information providers accountable. This specification provides a database structure, system, and method for an anonymous, decentralized information exchange platform. Participants in the information exchange platform can exchange information anonymously while remaining accountable for the content. Past and present parties (e.g., users, businesses, etc.) associated with the subject of information (e.g., products) can flexibly exchange information on the information exchange platform by identifying networks of data to find answers to questions or to find participants who are likely to have answers to questions. [Means for solving the problem]
[0004]
[0004] In one aspect, a method for distributed information exchange regarding a product is provided, the method including: (a) using a detector to scan a label on the product, the label being associated with a first manifest stored in a distributed data structure; (b) accessing a network of anonymous manifests including a plurality of manifests in the distributed data structure including the first manifest by following one or more network links associated with the first manifest; and (c) obtaining an answer to a query regarding the product by (i) identifying an existing answer to the query in a relevant manifest from the plurality of manifests, or (ii) identifying a creator of a relevant manifest from the plurality of manifests that is likely to provide an answer to the query, and querying the creator of the relevant manifest via a secure communication channel.
[0005] In some embodiments, the creator of the first manifesto is anonymous.
[0006] In some embodiments, the creator of each of the multiple manifestos is anonymous.
[0007] In some embodiments, the query is a push query and one of the manifests includes an existing answer.
[0008] In some embodiments, the query is a pull query, and none of the plurality of manifests contains an existing answer. In some embodiments, the relevant manifests are identified at least in part by filtering the plurality of manifests by a subject of the query. In some embodiments, the answer is validated by a commitment to the subject.
[0009] In some embodiments, the first manifest includes incomplete information about the product.
[0010]
[0010] In some embodiments, the network of anonymous manifests includes multiple manifest linked nodes.
[0011] In some embodiments, the method further includes verifying an association between the requester of the answer and the first group, wherein the association manifest grants access privileges to one or more groups including the first group. In some embodiments, the association manifest denies access to users not associated with the one or more groups.
[0012] In some embodiments, the answers are validated using one or more of tracing, a mass balance system, and tokenized proof.
[0013] In some embodiments, the validity of the answers is pre-checked.
[0014] In some embodiments, the validity of the answers is checked after the fact.
[0015] In some embodiments, the answer is binary.
[0016] In some embodiments, the answer is non-binary.
[0017]
[0017] In another aspect, there is provided a system for distributed information exchange regarding products, the system including a distributed data structure including a plurality of manifests and one or more processors, the one or more processors being individually or collectively programmed to: access a first manifest of the plurality of manifests in the distributed data structure, the first manifest being associated with a product; and follow one or more network links associated with the first manifest to access a network of anonymous manifests including the plurality of manifests in the distributed data structure that includes the first manifest; and obtain an answer to a query regarding the product by (i) identifying an existing answer to the query in an associated manifest of the plurality of manifests, or (ii) identifying a creator of an associated manifest of the plurality of manifests that is likely to provide an answer to the query, and querying the creator of the associated manifest via a secure communications channel.
[0018]
[0018] In another aspect, there is provided a system for distributed information exchange regarding products, the system including one or more processors that are individually or collectively programmed to, upon scanning a label on the product, access a first manifest of a plurality of manifests in a distributed data structure to which the label is associated, and follow one or more network links associated with the first manifest to access a network of anonymous manifests including a plurality of manifests in the distributed data structure that includes the first manifest, to obtain an answer to a query about the product by (i) identifying an existing answer to the query in an associated manifest of the plurality of manifests, or (ii) identifying a creator of an associated manifest of the plurality of manifests that is likely to provide an answer to the query, and querying the creator of the associated manifest via a secure communications channel.
[0019]
[0019] In another aspect, a distributed information exchange system is provided, the system including one or more processors, the one or more processors being individually or collectively programmed to access a network of anonymous manifests including a plurality of manifests in a distributed data structure including the first manifest by following one or more network links associated with a first manifest, and obtain an answer to a query by (i) identifying an existing answer to the query in an associated manifest of the plurality of manifests, or (ii) identifying a creator of an associated manifest of the plurality of manifests that is likely to provide an answer to the query, and querying the creator of the associated manifest via a secure communications channel.
[0020] In some embodiments, the creator of the first manifesto is anonymous.
[0021] In some embodiments, the creator of each of the multiple manifestos is anonymous.
[0022] In some embodiments, the query is a push query and one of the manifests contains an existing answer.
[0023]
[0023] In some embodiments, the query is a pull query, and none of the multiple manifests contains an existing answer.
[0024] In some embodiments, the relevant manifests are identified at least in part by filtering the plurality of manifests by the subject of the query.
[0025] In some embodiments, answers are validated by their commitment to the subject matter.
[0026] In some embodiments, the first manifest includes incomplete information about the product.
[0027]
[0027] In some embodiments, the network of anonymous manifests includes multiple manifest linked nodes.
[0028]
[0028] In some embodiments, the one or more processors, individually or collectively, are programmed to verify an association between the party requesting the answer and the first group, and the associated manifest grants access rights to one or more groups including the first group.
[0029] In some embodiments, the association manifest denies access to users who are not associated with one or more groups.
[0030] In some embodiments, the answers are validated using one or more of tracing, mass balance systems, and tokenized proofs.
[0031] In some embodiments, the validity of the answers is pre-checked.
[0032] In some embodiments, the validity of the answers is checked after the fact.
[0033] In some embodiments, the answer is binary.
[0034] In some embodiments, the answer is non-binary.
[0035] In some embodiments, the system further includes a detector configured to scan a label on the product, the label being associated with the first manifest.
[0036]
[0036] In some embodiments, the detector is an optical detector.
[0037] In some embodiments, the detector is a non-optical detector.
[0038]
[0038] Further aspects and advantages of the present disclosure will be readily apparent to those skilled in the art from the following detailed description, which shows and describes only exemplary embodiments of the present disclosure. As will be understood, the present disclosure is capable of other different embodiments, and several details can be modified in various obvious respects without departing from the present disclosure. Therefore, it should be noted that the drawings and descriptions are illustrative in nature and not restrictive.
[0039] Citation by reference All publications, patents, and patent applications mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent, or patent application was specifically and individually indicated to be incorporated by reference. In the event that the publications and patents or patent applications incorporated by reference conflict with any disclosure contained herein, it is intended that the present specification supersede and / or supersede such conflicting material.
[0040] BRIEF DESCRIPTION OF THE DRAWINGS
[0040] The novel features of the invention are set forth with particularity in the appended claims. A better understanding of the features and advantages of the present invention will be obtained by reference to the following detailed description and the accompanying drawings (hereinafter also referred to as "figures") that disclose illustrative embodiments, in which the principles of the invention are utilized. [Brief explanation of the drawings]
[0041] [Figure 1]
[0018] A schematic diagram of information storage and exchange is shown. DETAILED DESCRIPTION OF THE INVENTION
[0042] Detailed Description
[0041] While various embodiments of the present invention have been shown and described herein, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. Numerous variations, modifications, and substitutions will occur to those skilled in the art without departing from the invention. It is understood that various alternatives to the embodiments of the invention described herein may be employed.
[0043]
[0042] Provided herein are database structures, systems, and methods for anonymous information exchange platforms. The information exchange platforms described herein may include a blockchain structure, a distributed network, peer-to-peer technology, cryptographic technology, and / or a combination thereof. Advantageously, participants in the information exchange platform can exchange information anonymously while maintaining accountability for the content. Past and present parties (e.g., users, businesses, etc.) associated with the subject of the information (e.g., a product) can flexibly exchange information on the information exchange platform. In some examples, the information exchange platform can store product data for the product. If a portion of an original product is (or becomes) part of a derived product, the information exchange platform may be associated with each product data of the original product and the derived product.
[0044] A product may generally refer to any tangible object (e.g., a television, a screw, etc.). In some examples, a product may also refer to an intangible object (e.g., a software package, a computer program, open source code, etc.). A product may be an assembly, packaging, combination, collection, and / or set of multiple individual objects. A product may be or include one or more parts or elements (e.g., a display screen, a chip, a drive engine, a frame, a panel, a screw, etc.). A derived product may be derived from another product. For example, a derived product may be a repaired, reused, modified, recycled, assembled, disassembled, improved, updated, or otherwise manipulated version of another product (e.g., a motherboard with a chip on it may be a derivative of the chip, a napkin made from recycled waste may be a derivative of the waste, etc.). In some examples, a derived product may be derived from an original product. In some examples, a derived product may be derived from another derived product. For example, a derivative product may be a first derivative product (e.g., from the original product), a second derivative product (e.g., from the first derivative product), a third derivative product (e.g., from the second derivative product), etc. A derivative product may be derived from multiple other products, such as when it includes a first portion from a first other product and a second portion from a second other product.
[0045] A value chain may represent the life of a product. A value chain may include multiple nodes. Each node in the value chain may be associated with a party or activity related to the product. For example, a product may move downstream along upstream value chain nodes, with "upstream" being closer to the raw resource extraction process in the product's manufacture and "downstream" being closer to its use by the end user (or its final transfer to a recycler or waste disposal company, etc.). Alternatively or additionally, the direction from "upstream" to "downstream" may refer to a chronological direction. In one example, in the value chain of an example product, the example product moves from a first node associated with a refiner and the refining process, to a second node associated with a manufacturer and the manufacturing process, to a third node associated with a retailer and retail operations, to a fourth node associated with a user and the act of use, and to a fifth node associated with a recycler party and the recycling process.
[0046]
[0045] A party in a product's value chain may refer to any individual or any business. A party may be a group of individuals or a group of businesses. For example, a party may include a consumer, a user (e.g., intermediate user, end user, etc.), a recycling company, a manufacturer, a retailer, a distributor, a packaging company, etc.
[0047]
[0046] Products may have associated product data. The term "product data" is used interchangeably with the term "manifest" herein. In some examples, each product may be tagged with a unique label. The label may be linked to the product's product data. In some examples, the label may be a tangible label (e.g., printed, drawn, or affixed to the product or a different object associated with the product, etc.). In some examples, the label may be an intangible label (e.g., digitally rendered or stored as metadata, etc.). For example, the unique label may be a code (e.g., one-dimensional (1D), two-dimensional (2D), three-dimensional (3D), quick response (QR), barcode, encrypted, alphanumeric, etc.), marker, identification number, etc. The label may be an optical code. The label may be a non-optical code (e.g., audio, electronic, tactile, etc.). The label may be scanned and linked to the manifest. For example, the label may be scanned using a scanner or other optical detector. A scanner or other optical detector may be communicatively coupled to a user device (e.g., a cell phone, laptop, tablet, wearable device, etc.). Labels may be detected using detectors, including different types of sensors (e.g., microphones, etc.) or non-optical detectors. In some examples, labels may be selected using hyperlinks.
[0048]
[0047] Product data may include data and / or metadata about a product. For example, product data may include information about a product's value chain network (e.g., node order, actor attributes, activity details, etc.), information about the product (e.g., raw materials, manufacturing process or method, manufacturing date and time, chemical exposure, shelf life, flammability, chemical composition, tensile stress, etc.), and / or attributes of a user who knows a particular type of information. For example, a product may include product-specific information (e.g., physical properties, hazardous ingredients, toxicity, hard data, etc.) and process-specific information (e.g., working conditions, sustainability indicators, soft data, etc.). A party in a product's value chain may know or can create or update one or more pieces of product data. For example, each party may know attributes of the party immediately preceding it (e.g., supplier) and the party immediately following it (e.g., customer) in the value chain. In another example, each party may know details of the activities performed by each party. In some examples, a party may know only incomplete product data. In some examples, a party may know complete product data. In some examples, different portions of the product data may be associated with different nodes. In some examples, the product data for a derived product may include or be associated with each product data for the product(s) from which the derived product is derived. For example, the value chain network for a derived product may include or be otherwise associated with portions of the value chain networks of the product(s) from which the derived product is derived.
[0049]
[0048] Particular parties in a product's value chain may require product data for a product that is not available to them in order to process the product. For example, a recycler (e.g., the final party in the value chain) may require chemical composition information (e.g., product data) for a battery (e.g., a product) in order to properly reuse (e.g., process) the battery. Such product data may not be readily available in traditional situations because the identities of parties upstream from the recycler are unknown to the recycler, there are too many parties to keep track of (e.g., the supplier of the supplier of the battery), different parties know different parts of the product data, intermediaries are unwilling to participate in the information exchange, and / or the reliability of the information obtained is questionable, etc.
[0050]
[0049] The information exchange platform described herein provides an information exchange channel between a first user requesting a specific piece of information (e.g., a portion of product data) and a second user having the specific piece of information. Users of the information exchange platform may be referred to as "participants." A smart question and answer protocol is provided herein.
[0051]
[0050] Centralized data storage solutions, in which all information is stored and accessed from a central location and managed by an external central management system, can encounter technical drawbacks, such as limited granularity in controlling when users access which data, limited privacy for users who provide specific data to the system (e.g., risk of user attributes being leaked to the recipient), and limited security for stored data (e.g., risk of data tampering). In contrast to centralized data storage solutions, the disclosed information exchange platform allows information to be housed in distributed nodes (e.g., different users). The information exchange platform can provide a channel between a first node and a second node to exchange information while maintaining the anonymity of user attributes associated with the two nodes. An advantageous feature of such distributed information storage (and access) is that it allows flexible control over information propagation, e.g., which users gain access to information, exactly which information or portions of information, and when (or for how long) they access the information. A distributed information platform is also less susceptible to security breaches of protected data. Furthermore, maintaining anonymity between two users (sender and receiver nodes) during information exchange will motivate an intermediary connector (intermediary node) to act as a proxy connecting two users who are otherwise separated; without such anonymity, an intermediary would be less willing to do so, for example, for fear of losing their job or because they would be obligated to maintain confidentiality of the attributes of either party.
[0052] In some examples, keeping a log or record of all information transfers can maintain the authenticity of the exchanged information so that users cannot later contradict the log or record and deny that an information exchange activity occurred or, if any, what information was exchanged. Such logs or records can be particularly useful for auditing purposes. In some examples, the authenticity of the exchanged information can be maintained by associating a user's digital attributes with the user's real attributes and by making such association public.
[0053]
[0052] The information exchange platform can implement one or more question and answer protocols, whereby a first user asks a question about a product and another user who is familiar with the product pre-provides or responds to the answer to the question, facilitating the exchange of information.
[0054] In some cases, product data may be pre-validated before, during, or after production. In some cases, product data may be post-validated by performing reverse engineering or testing procedures. In some examples, process-specific data associated with a product may be pre-validated. In some examples, product-specific data associated with a product may be post-validated. Product data may be validated (e.g., pre-validated, post-validated) by a validator. The validator may be a third party to the information requester and the information recipient. Validated data may be validated without being bound by a reasonable doubt standard or other standards (e.g., preponderance of the evidence, etc.). Systems and methods for validation are described elsewhere herein.
[0055] 1 shows a schematic diagram of information storage and exchange. It shows a first product 110 including an assembly of parts 151, 152, and 153, along with a first label 110A and associated first product data 110B. Each of the parts 151, 152, and 153 may itself be a product with its own label and associated product data 151B, 152B, and 153B, respectively. The first product data 110B may include portions of data distributed across the first node 111, the second node 112, the third node 113, the fourth node 114, and the fifth node 115 in the value chain. The first product data 110B may further include or be associated with (e.g., overlap with) some or all of the product data 151B, 152B, and 153B. For example, first node 111 may include or be associated with product data 151B for part 151, product data 152B for part 152, and product data 153B for part 153.
[0056] As shown, different portions of product data can be stored on different nodes in a blockchain network. The blockchain network may include a distributed data structure. The blockchain may include a secure, distributed ledger of transactions. In some embodiments, the blockchain is a data structure that stores a list of transactions, forming a distributed electronic ledger that records transactions between source and destination identifiers. Transactions are bundled into blocks, and every block (except the first block) references or is linked to the previous block in the chain. Different nodes maintain the blockchain and verify the validity of each new block and transaction included in the blockchain. The integrity of the blockchain is maintained because each block references or contains the cryptographic hash value of the previous block. Therefore, if a block references the previous block, it becomes difficult to change or tamper with the data (e.g., transactions) included in the previous block. This is because even small changes to the data affect the hash value of the entire block. Each additional block makes it more difficult to tamper with the contents of the previous block. Therefore, even if everyone can see the content of the blockchain, the content will be immutable.
[0057] At each node, each product can be tagged with a label that links it to a product-level manifest (e.g., product data) stored on the blockchain. The manifest may contain anonymized attributes of the manifest creator, information used to answer questions, and network links to other manifests. By following the network links from one manifest, information about many manifests (located at different nodes) can be obtained, and by following these links in turn, an anonymous representation of the product's value chain can be gradually built. The manifest can provide the structure of the network and anonymized attributes of the nodes in the network, but it does not provide the true attributes of the individual nodes. For example, a value chain involving three manufacturers, two repair shops, one retailer, and two brokers may reveal which parties transact with which parties, but not their true attributes. Within this value chain network, only the manifest creator's direct contact (existing contact) reveals the manifest creator's actual attributes in the real world; i.e., suppliers and customers who transact directly know each other's attributes.
[0058] In some examples, the manifest may be at the product line level, for example, containing information about the product line or brand. This avoids the need to modify the manifest for each individual product. Higher level manifests can be linked via product links.
[0059] 1 , the second product 120 may include an assembly of parts 152, 154 along with a second label 120A and associated second product data 120B. The part 154 may itself be a product with its own label and associated product data 154B. The second product 120 may be a derivative of the first product 110 in that the part 152 is recycled from the first product. The second product data 120B may include distributed portions of data at the first node 121, the second node 122, the third node 123, the fourth node 124, and the fifth node 125 in the value chain. The second product data 120B may also include or be associated with (e.g., overlap with) some or all of the first product data 110B, such as a portion of the first product data (e.g., product data 152B) related to the part 152. The second product data 120B may also include some or all of the product data (e.g., product data 154B) for another product, such as a product from which the part 154 is derived. That is, one or more nodes of the second product data 120B may be linked to one or more nodes of the first product data 110B. For example, as shown, the fifth node 115 is linked (via a network link) to the first node 121.
[0060] The third product 130 may include an assembly of parts 153 and 155, along with a third label 130A and associated third product data 130B. The third product 130 may be a derivative of the first product 110 in that the part 153 was reused from the first product. The third product data 130B may include data at the first node 131, the second node 132, the third node 133, the fourth node 134, and the fifth node 135 in the value chain. The third product data 130B may also include or be associated with (e.g., overlap with) some or all of the first product data 110B, such as part of the first product data related to the part 153 (e.g., product data 153B). The third product data 130B may further include some or all of the product data (e.g., product data 155B) of another product, such as a product from which the part 155 is derived. That is, one or more nodes of the third product data 130B may be linked to one or more nodes of the first product data 110B. For example, as shown, the fifth node 115 is linked (via a network link) to the first node 131. As shown in FIG. 1, a value chain may track the assembly or disassembly of different elements and / or different products.
[0061] Information can be obtained from the manifest during an information exchange session via questions and answers. Provided herein are systems and methods for a smart question and answer protocol. For example, a user accessing node 125 from a label on product 120 can find information about part 152 from a user accessing node 111 by opening a secure communication channel 180 through the extended network of manifests while maintaining the attributes of both users.
[0062]
[0061] Questions are pre-defined, and answers about the product are linked to the questions by participants. Questions may be free-form strings that must be answered manually. Questions may include metadata about the subject (e.g., whether the question is about mercury or not) and may be used by participants to validate the answer (e.g., using commitments as described elsewhere herein). Alternatively or additionally, questions may be in the form of queries. For example, a query may be in the form of "Does the product contain substance X?", to which the answer is known to be either "yes" or "no." Queries may be compatible with binary answers (e.g., true / false, 0 / 1, yes / no) or non-binary answers (e.g., strings, characters, words, numbers, etc.). Questions may also be in other query formats. In some examples, the platform may implement one or more algorithms to parse the query language (e.g., implementing natural language processing (NLP)). Questions may be push questions, to which participants have previously answered, or pull questions for which no existing answers exist. Both types of questions involve adding information to the manifest.
[0063] For example, a push question may include a question to which an answer is required by law to be disclosed. A push question may include any other customized question set by another participant. Push questions are useful when an answer is required to be available at any future point in time, even if the participant that provided the answer leaves the network. For push questions, the answer is stored directly in the manifest and then propagated downstream as the label moves along the value chain. This allows anyone with access to the manifest and the correct authorization (i.e., belonging to the correct group) to access the answer. A push question may form a question / answer pair (QA) with a corresponding answer in the manifest. A QA pair may be a pair of a pointer and a string. For example, asking a push question can trigger verification of the authorization to view the answer by examining data associated with the push question.
[0064] Pull questions are useful when participants want additional or more detailed information or when the answer is more sensitive. Pull questions can be posed to anyone in the value chain. The network formed by the manifest can be used to find and select the appropriate anonymized participant to ask the question. If the selected party knows the answer and accepts the questioner's authority (e.g., membership in a legitimate group), they can respond via a secure communication channel. If a participant believes that an answer to a push question should be included by updating their manifesto, they can convert the pull question to a push question. This is useful, for example, when a question was not mandatory in the past but will become mandatory in the future. Some questions may have associated subject / commitment pairs (TC pairs) that can be used to verify answers to these questions. TC pairs may contain more general information than QA pairs generated for specific questions. TC pairs focus on storing verifiable information about the subject, not the specific question. Commitments may contain numerical values. For example, a commitment to "content amount" can be used to answer (verifiably) the exact content amount, threshold, or range of content amounts. Even if the specific questions that will be asked in the future are unknown, there may be a subset of answers that can be verified based on commitments provided in the past. Answering pull questions with existing commitments is not required, but it can increase the reliability of the information.
[0065]
[0064] The information exchange platform may include many smart contracts that implement some of the information exchange protocols described herein, which allow participants to exchange information with other participants.
[0066]
[0065] The protocol can support the publication of groups. Each participant can decide who can be trusted with information by limiting access to that information to one or more predefined groups with authorization. For example, a manufacturer can trust answers to certain sensitive questions only to a specific group of certified recyclers. Any participant can organize and manage groups of participants. Groups may be given labels (e.g., "Trusted Recyclers"). When a participant shares a piece of information, they can choose which groups have authorization to view that information. Groups can be organized by an initial set of members. The organizer of a group may be responsible for selecting the members of the group. An asymmetric key pair may be generated, and the public key may be published along with other group metadata (owner, members, and group name). However, the private key is not immediately distributed to potential participants. Members may confirm the conditions for joining the group before obtaining the private key. Potential participants must confirm their desire to be part of the group before obtaining the private key. The platform can verify that participants are members of the group when cross-verified. That is, a participant verifies that they belong to a group, and a group verifies that a participant is part of a group. A participant can own (e.g., organize) multiple groups.
[0067]
[0066] Participants can belong to multiple groups. Interactions regarding the formation, modification, and deletion of groups are facilitated on the blockchain via smart contracts and are transparent to anyone with access to the public ledger of transactions. Every group can have an asymmetric key pair that can encrypt answers so that only members of the group can access them. A public key can be used to encrypt data only for members of the group to which the members have access to the associated private key. In some examples, a creator can add pointers to other groups, adding members of the other groups to the creator's group. For example, if a group GA contains a pointer to another group GB, members of GB are also considered members of GA. The same is true if GB points to group GC; members of GC are also considered members of GA. All of these members (direct and indirect) are given access to the private key paired with the public key of group GA.
[0068]
[0067] The protocol can support adding or removing participants from groups. Such operations may require additional management of group keys, for example to prevent members who leave a group from later accessing new information encrypted for members of that group. A new key pair may be generated each time the composition of the group changes.
[0069] The protocol allows for the management of questionnaires. Any participant can create a questionnaire and become the question manager for that list. Other participants may have the option to subscribe to the list, for example, to gain access to all questions in the list. The list can be stored on a blockchain to prevent tampering. A questionnaire can incorporate questions from other questionnaires. Only the question manager can update a questionnaire. Updating a questionnaire can create a new version of the list. Participants can specify the version of the questionnaire to which they wish to subscribe. In some examples, subscriptions to a list may span different versions. In other examples, subscribers may confirm whether they wish to subscribe to new versions of a list. This allows users to continue subscribing to previous versions because updated versions may include new questions that they do not wish to answer. For example, an auditor may create a questionnaire and become the question manager, updating the list as audit interviews progress. In some examples, a questionnaire may include questions that participants are required to answer. For example, these questions may include questions that subscribers are legally obligated to answer.
[0070] The protocol can manage subscriptions to question lists. Participants may subscribe to question lists to indicate their willingness to answer questions. The manifest may contain the list of subscriptions and permission information about which groups are authorized to read the answers. Whenever a question list is updated, a notification can be pushed as an event to the smart contract. Participants can subscribe to multiple lists and / or multiple versions of the same list.
[0071]
[0070] The protocol can support publishing and modifying manifests. Participants can publish new manifests or modify existing manifests they own. For example, participants can create empty data structures and insert information such as general product information, push questions and answers, links to other manifests, subscribed question lists, and anonymized proprietary information. Each participant can select secret and anonymous attributes each time they create a manifest. Each participant may own a secret registry containing a list of all secret attributes corresponding to the manifests they have published.
[0072]
[0071] A manifest may be linked to a label (e.g., on a product) and published on the blockchain. The manifest can be used by questioners and answerers to obtain information for questions and answers. It can also be used to verify answers. Published manifests can be viewed by any participant, but the creator's attribution may be anonymized and sensitive information such as answers to push questions and product links may be encrypted. Information in a manifest can be changed by the creator. The blockchain can provide an immutable history so that each previous and changed version remains available on the blockchain.
[0073]
[0072] The manifest may contain entries such as push QA pairs, bills of materials combined with commitments (e.g., TC pairs), pointers to sets of question lists, pointers to product line manifests and model manifests (e.g., product links), pointers to parent-child product manifests (e.g., network links), manifest holder, manifest creator (e.g., anonymous address), true attributes of the manifest creator encrypted with the holder key, and any other metadata (e.g., serial number).
[0074]
[0073] A manifest can have any number of holders, where a holder is any party that has or has had physical access to the label associated with the manifest, whose private key is stored. Anyone with access to the label can use the private key and is therefore identified as the label's owner. Parties are required to save the private holder key when they view it, so that they can continue to act as the owner even after they no longer own the label. This is especially important for audits, as it is the only way to identify the manifest creator. The manifest creator's anonymous attributes are recorded in the manifest, allowing the creator to claim ownership of the manifest if necessary. Because a new anonymous attribute is used for each manifest, it cannot be directly linked to the respondent's public attributes without additional information. The creator's true attributes are also stored in the manifest, encrypted with the owner public key. The owner (typically a direct client) can disclose the creator's public attributes.
[0075]
[0074] The information contained in a manifest may have different security levels: some information may be public knowledge, while other information may be intended for a more specific recipient and therefore encrypted to a specific group.
[0076]
[0075] The manifest may contain TC pairs to answer pull questions. These commitments are created for the bill of materials. If the list of materials is confidential in addition to the quantity, adding false TC pairs, i.e., commitments with a value of 0, to the manifest for materials not included in the product may confuse the information. The commitments allow auditors to verify the authenticity of complaints from participants.
[0077] Network links are used to point to child and parent manifests. A parent manifest is a manifest of components and raw materials involved in the production of a product (upstream). A child manifest is a manifest of any product(s) of which the product is a material or component (downstream). In manufacturing, there is typically only one child. For example, a network link for a motherboard manifest may point to manifests for all chips present on the motherboard, along with manifests for laptops manufactured using the motherboard. For some parties, such as manufacturing companies, many of the products produced will have very similar information in their manifests. For example, all products from a product line may have the same material composition and user manual. To avoid this unnecessary duplication of information, a manifest may include a reference to a virtual manifest containing information for the entire product line, which in turn may point via a link (e.g., a product link) to a manifest containing a warranty common to all electronic products of the company. Product links can be encrypted to maintain the anonymity of the manifesto creator.
[0078] The protocol can manage push questions. A questioner can find answers to push questions by using information in the product manifest associated with the label and / or by recursively following upstream or downstream network links to find the manifest containing the answer (or part of it). A participant's access to the answer to a push question depends on the group(s) of which the participant is a member and the corresponding permissions of the group(s). For each QA pair, the questioner's permissions can be verified. Answers can be public or encrypted for a specific group. For example, a customer who bought a product can only view general product information, while a verified recycler / auditor can also view complaints about the specific content of the product, i.e., manufacturing method, origin of materials, etc.
[0079] The protocol can manage pull-type questions. Participants can be questioners and / or answerers. A questioner can use information in a manifest, such as network links, to find manifests whose creators are likely to have the answer or parts of the answer. For example, a questioner can use the subject of the TC pair to follow the network links of manifests linked to a product's scanned label and filter the associations to find anonymous attributes of the relevant manifest creators. The questioner can then create a secure channel to ask questions about the anonymized attributes of the manifest creators. The attributes remain anonymous unless any participant discloses their attributes. At the same time, it is guaranteed that the questioner belongs (authoritatively) to the group they claim to belong to, and that the answerer is the true owner of the manifest in the relevant value chain. The answerer can use the questioner's associated group to determine whether they want to answer the question. For example, the questioner can provide a ring signature to prove their authority. In some examples, a Diffie-Hellman key exchange can be used to keep the answer secret from everyone except the questioner and the answerer.
[0080]
[0079] The protocol can manage the storage and validation of attributes, where the digital attributes of each participant in the information exchange platform are publicly linked to the participant's real-world attributes. However, each participant remains the sole owner of the anonymous attributes used to publish the manifest. Each participant can, for example, request names that comply with the Ethereum Improvement Proposal (EIP137). Names can be represented on the chain as hashes. There can be one public registry. Attributes can be exchanged by accessing the registry.
[0081]
[0080] By implementing the above protocol in an information exchange platform, participants can manage their product information in two ways: they can decide with whom they share information and how much information they share. Participants can control what information they share by fine-tuning when they answer questions. Similarly, they can control who gets the information by ensuring that only those in possession of the correct key (e.g., using a group) can read the answers.
[0082]
[0081] Product data may be validated (e.g., pre-validated, post-validated) by a validator. In some examples, the validator may be a third party to the information exchange participants (e.g., requester, recipient, etc.). In some examples, the validator may be an information exchange participant.
[0083]
[0082] Systems and methods for validating data using the information exchange platform described herein are provided. Data may be validated using methods such as tracing technology, mass balance systems, certificate tokenization, third-party audits, and / or combinations thereof. Tracing technology may involve marking a product with a tracer to prove that the tracer creator possessed the marked product at some point in the manufacturing process. The tracer may be an artificial or natural tracer. The tracer may be a tangible or intangible tracer. Validating data using tracing technology alone may expose the validation process to the risk of a malicious tracer creator providing the tracer to another malicious downstream party who may falsely claim that their product originated from a different party that also received the tracer from the tracer creator. A mass balance system may involve balancing the inflow and outflow of material at all manufacturing stages. For example, Source A may have certification to produce 100 tons of valid material. Up to 100 tons of material from Source A may be validated. Validation using only a mass balance system could expose the validation process to the risk that a buyer may receive material from both Source A and a third-party Source D and substitute material from Source A for material from Source D, making it appear as if all the material came from Source A. At least the above-mentioned problems of data validation can be addressed by using a combination of tracing technology and a mass balance system for data validation. Tracers (e.g., artificial tracers, natural tracers) and / or confirming this information may be included in a single manifest (or multiple manifests). Material input / output information and / or confirming this information may be included in a single manifest (or multiple manifests).
[0084] Certificate tokenization may involve converting certificate(s) into digitized units, converting certified asset(s) into digitized units, or both. Certificates may be process certificates or product certificates. Process certificates may vouch for an entire product line (e.g., permanently, with a predetermined expiration date, pending periodic audits, etc.), thus validating as many products as possible within the product line. In some examples, a certified entity may issue (e.g., "mint") tokens with the authority to "mint" tokens that are assignable or revocable by the certification entity issuing the certificate. In some examples, the certification entity may issue new tokens to manufacturers upon request (e.g., once the product is manufactured). Product certificates may certify quantifiable units (e.g., a predetermined quantity) of a product. In some examples, a certification authority may issue tokens upon request (e.g., once the product is manufactured) and assign them to a certified entity. In some examples, there may be enough tokens to tag a set of certified products. A manifest for a certified product may include such a tokenized certificate (e.g., by attaching the certificate's digital signature to the manifest, with the digital signature only being attached if the certificate is valid). A certain amount of tokens in circulation may be traceable, ensuring that a particular certificate has not been issued twice. A tokenized certificate may be a point certificate that can be transferred downstream from the node of origin by any party (e.g., including uncertified entities). For example, such a point certificate may verify the validity of data associated with the origin of a material (e.g., immutable history) and the presence of a tracer (e.g., persistent physicochemical properties). A tokenized certificate may be a flow certificate that can be transferred downstream only by a party with the identity (e.g., no child labor, carbon neutral, etc.). The presence of a tokenized certificate can be discovered using the smart question and answer protocol described herein. In some examples, each manifest may include an indication of the certificate's value along with an indication of how much of that value has been used.In some examples, the value of a product certificate may be proportional to or determined by the product weight.
[0085]
[0084] Using such a validation scheme, a user can verify whether the product data has been validated. For example, if the data has not been validated, the user may be provided with an indicator that the data has not been validated (e.g., a clear message that the data has not been validated, a lack of a tokenized certificate signature, etc.).
[0086] In one example, a manufacturer obtains a certificate for a material, purchases 10 kilograms of certified magnesium (and 10 tokenized certificates), and uses the material and magnesium to manufacture 10 product products using a trade secret recipe (e.g., secret amount of magnesium, secret presence of magnesium, etc.). The 10 product products may have 10 tokenized certificates associated with them (e.g., one tokenized certificate per 10 kilograms, etc.). The certificates and tokens associated with the product products may remain with the owner and be verified via a question and answer protocol. Depending on the query, different algorithms may be used to assemble different requested certificates. [Example]
[0087] Example
[0086] An advantageous feature is that the information exchange platform is auditable. The auditor's objective is to verify that participants are not committing fraud. For audits, the cooperation of the auditee is always required. Cooperation in audits is not enforced by the system itself. If fraud is detected, the auditor can take appropriate measures.
[0088]
[0087] In addition to the usual inspection, auditors who audit participants can examine the auditee's manifests. First, the auditor can find out which manifests were created by the auditee. Since the true attribution of the manifest owner is a secret known only to the creator and owner, the auditor may ask the manifest creator or owner to volunteer attribution. With the manifest in hand, the content can be verified. Three types of things can be audited for a manifest: QA pairs, TC pairs, and the manifest's edit history.
[0089] For publicly accessible QA pairs, auditors can directly verify them by inspecting the values. The encrypted value of the QA pair can be revealed by the creator of the manifest or the group for whom it was encrypted. Because the creator of the QA pair created the symmetric key, the value of the QA pair can be revealed based on data stored on the blockchain. This proves that the revealed value corresponds to the value in the manifest. While it does not prove that what was encrypted to the group is the actual symmetric key, it can alert the auditor if a party obtains a fake symmetric key. For the TC pair in the manifest, the auditee can provide a hidden value and an accompanying random value. Since it is impossible to find a pair that produces the same commitment, the pair is considered original. The auditor can then verify the authenticity of the hidden value using real-world channels.
[0090] In this way, auditors can verify with a high degree of confidence that the information participants disclose about their products is true. In some instances, verified data can be marked as more reliable than unaudited data. In some instances, participants can be scored according to how frequently the information they provide is confirmed in the audit.
[0091]
[0090] The history of the manifest can be verified using the blockchain transaction history, which allows the auditee to verify whether the manifest indicates any suspicious activity, such as whether it was edited immediately prior to the audit to conceal tampering. The manifest may also contain information that can vouch for the origin of the product and its manufacturing history, some of which may be subject to regulation. The data contained in the manifest may therefore be used by auditors to determine whether the associated product was manufactured and obtained through legitimate channels and procedures.
[0092]
[0091] The traceability provided by the query protocol allows an auditor to track down the source of the erroneous information if an incorrect answer is discovered. In the case of a push query, the source's private attributes are included in the manifest from which the QA pair originates. In the case of a pull query, the source's private attributes are known the moment the communication channel is opened. In either case, the erroneous party can call an auditor to find the cause of the problem. Linking a participant to an answer is easier than finding all of that participant's manifests. Because the participant requesting the audit knows at least the attributes of the next upstream participant (its supplier in the value chain), the requesting participant has seen the manifest holder's private key, which can be used to decrypt the manifest's public attributes for the auditor. This step can be repeated for each participant in the value chain until the answerer is found.
[0093] Computer Systems
[0092] The present disclosure provides a computer system programmed to implement the methods of the present disclosure. For example, the computer system may be configured to program or otherwise implement a blockchain architecture, a distributed network, peer-to-peer technology, cryptographic technology, and / or combinations thereof to implement the information exchange platform and information exchange protocol (e.g., smart question and answer protocol) described herein. The computer system may be a user's electronic device or a computer system located remotely from the electronic device. The electronic device may be a mobile electronic device. The computer system may be a server connected to multiple electronic devices of multiple users (e.g., participants in the information exchange platform).
[0094] A computer system includes a central processing unit (CPU, also referred to herein as a "processor" and a "computer processor"), which may be a single-core or multi-core processor, or multiple processors for parallel processing. A computer system also includes memory or memory locations (e.g., random access memory, read-only memory, flash memory), electronic storage (e.g., hard disk), communication interfaces (e.g., network adapters) for communicating with one or more other systems, and peripherals such as cache, other memory, data storage, and / or electronic display adapters. The memory, storage, interfaces, and peripherals can communicate with the CPU via a communication bus, such as a motherboard. The storage may be a data storage device (or data repository) that stores data. A computer system may be operatively connected to a computer network ("network") with the aid of a communication interface (e.g., network adapter). The network may be a global Internet, a local Internet and / or an extranet, or an intranet and / or extranet that communicates with the global Internet. The network is, in some cases, a telecommunications and / or data network. The network may include one or more computer servers that enable distributed computing, such as cloud computing. The network may, in some cases, be assisted by a computer system to implement a peer-to-peer network that enables devices connected to the computer system to operate as clients or servers.
[0095] A CPU may execute a series of machine-readable instructions embodied as a program or software. The instructions may be stored in a memory location, such as a memory. The instructions may be directed to the CPU, which may then program or otherwise configure the CPU to implement the methods of the present disclosure. Examples of operations performed by the CPU may include fetch, decode, execute, and write back.
[0096]
[0095] The CPU may be part of a circuit, such as an integrated circuit. One or more other elements of the system may be included in the circuit. In some cases, the circuit is an application specific integrated circuit (ASIC).
[0097] The storage device can store files such as drivers, libraries, and saved programs. The storage device can store user data, such as user preferences and user programs. The computer system may in some cases include one or more additional data storage devices external to the computer system, such as located on a remote server that can communicate with the computer system via an intranet or the Internet.
[0098]
[0097] The computer system can communicate with one or more remote computer systems over a network. Examples of remote computer systems include personal computers (e.g., portable PCs), slate or tablet PCs (e.g., Apple® iPad, Samsung® Galaxy Tab), telephones, smartphones (e.g., Apple® iPhone, Android-enabled devices, Blackberry®), or personal digital assistants. Users can access the computer systems over the network.
[0099] The methods described herein can be implemented as machine (e.g., computer processor) executable code stored in an electronic storage location of a computer system, such as a memory or electronic storage device. The machine-executable or machine-readable code may be provided in the form of software. In use, the code can be executed by the processor. In some cases, the code may be retrieved from storage device and stored in memory for easy access by the processor. In some situations, electronic storage device may be eliminated, and machine-executable instructions are stored in memory.
[0100]
[0099] The code may be pre-compiled and configured for use on a machine having a processor adapted to execute the code, or may be compiled on the fly. The code may be provided in a programming language that can be selected to make the code executable as pre-compiled or compiled.
[0101] Aspects of the systems and methods proposed herein, such as computer systems, can be implemented through programming. Various aspects of the present technology may be considered "products" or "articles of manufacture," typically in the form of machine (or processor) executable code and / or associated data carried or embodied on some type of machine-readable medium. The machine-executable code can be stored in electronic storage, such as memory (e.g., read-only memory, random-access memory, flash memory) or a hard disk. A "storage" type medium may include any or all of the tangible memory of a computer, processor, etc., or associated modules, such as various semiconductor memories, tape drives, disk drives, etc., capable of providing non-transitory storage for software programming at any time. All or portions of the software may sometimes be communicated via the Internet or various other telecommunications networks. Such communication may, for example, enable software to be loaded from one computer or processor to another, such as from a management server or host computer, into the computer platform of an application server. Thus, other types of media that may carry software elements include optical, electrical, and electromagnetic waves, such as those used through physical interfaces between local devices, through wired and optical terrestrial networks, and via various air links. Physical elements that carry such waves, e.g., wired or wireless links, optical links, etc., are also considered software-bearing media. As used herein, unless limited to non-transitory, tangible "storage" media, terms such as computer or machine "readable medium" refer to any medium that participates in providing instructions to a processor for execution.
[0102]
[0101] Accordingly, a machine-readable medium such as a computer-executable code may take many forms, including, but not limited to, a tangible storage medium, a carrier wave medium, or a physical transmission medium. Non-volatile storage media include, for example, optical or magnetic disks, such as any storage device of any computer(s) used to implement the databases, etc., shown in the figures. Volatile storage media include dynamic memory, such as the main memory of such a computer platform. Tangible transmission media include coaxial cables, copper wire, and fiber optics, including the conductors that comprise a bus within a computer system. Carrier wave transmission media can take the form of electric or electromagnetic signals, or acoustic or light waves such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer readable media thus include, for example, a floppy disk, a flexible disk, a hard disk, magnetic tape, any other magnetic medium, a CD-ROM, a DVD or DVD-ROM, any other optical medium, punched cards, paper tape, any other physical storage medium with a pattern of holes, RAM, ROM, PROM and EPROM, FLASH-EPROM, any other memory chip or cartridge, a carrier wave carrying data or instructions, a cable or link carrying such a carrier wave, or any other medium from which a computer can read program code and / or data. Many of these types of computer readable media may serve to carry one or more sequences of one or more instructions to a processor for execution.
[0103] The computer system may also include or communicate with an electronic display that includes a user interface (UI) for displaying information, such as the manifests described herein. Examples of UIs include, but are not limited to, graphical user interfaces (GUIs) and web-based user interfaces.
[0104] The methods and systems of the present disclosure can be implemented as one or more algorithms. The algorithms can be implemented as software executed by a central processing unit. The algorithms can implement, for example, various protocols described herein.
[0105] While preferred embodiments of the present invention have been illustrated and described herein, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. It is not intended that the present invention be limited to the specific examples provided herein. While the present invention has been described with reference to the above specification, the description and illustration of the embodiments herein should not be construed as limiting. Numerous modifications, changes, and alternatives will occur to those skilled in the art without departing from the invention. Furthermore, it should be understood that all aspects of the present invention are not limited to the specific diagrams, configurations, or relative proportions disclosed herein, which depend upon a variety of conditions and variables. It should be understood that various variations of the embodiments of the present invention described herein may be employed in practicing the present invention. It is therefore contemplated that the present invention encompasses any such alternatives, modifications, variations, or equivalents. The following claims define the scope of the invention, and it is intended to cover methods and structures within the scope of these claims and their equivalents.
Claims
1. A system for distributed information exchange among a plurality of parties while preserving anonymity among the parties, the system comprising: a distributed blockchain network maintained by a plurality of computer nodes for storing a plurality of manifests related to an object, at least one manifest from the plurality of manifests including one or more subject and commitment (TC) pairs, each of the one or more TC pairs including a subject of information about the object and a commitment to verifiable information about the subject; one or more processors individually or collectively programmed to implement a protocol that allows the plurality of manifests to be published or modified; A system comprising:
2. The system described in claim 1, wherein the verifiable information is used to generate or verify answers to questions related to the corresponding subject matter.
3. The system described in claim 2, wherein the answers are not pre-stored in the distributed blockchain network.
4. The system described in claim 1, wherein the commitment includes a numerical value.
5. The system described in claim 1, wherein the commitment to the verifiable information is encrypted.
6. The system described in claim 1, wherein the at least one manifest further includes an encrypted anonymous identity of the creator of the manifest.
7. The system described in claim 6, wherein the true identity of the creator is not made public on the distributed blockchain network.
8. The system described in claim 6, wherein the true identity of the creator is stored in a secret registry.
9. The system described in claim 6, wherein the true identity of the creator is encrypted and recorded in the at least one manifest.
10. The system described in claim 6, wherein the at least one manifest is modified by the creator or by a member added by the creator by adding a pointer.
11. The system described in claim 1, wherein the at least one manifest further includes a pointer to a parent or child target manifest.
12. The system described in claim 1, wherein the at least one manifest further includes a pointer to another object linked to the object.
13. A computer-implemented method for distributed information exchange among a plurality of parties while preserving anonymity among the parties, the method comprising: (a) storing a plurality of manifests related to a subject in a distributed blockchain network, at least one manifest of the plurality of manifests including one or more subject and commitment (TC) pairs, each of the one or more TC pairs including a subject of information about the subject and a commitment to verifiable information about the subject; (b) one or more processors implementing a protocol that allows the plurality of manifests to be published or modified; A method comprising:
14. The method of claim 13, further comprising using the verifiable information to generate or verify answers to questions related to the corresponding subject matter.
15. The method of claim 14, wherein the answer is not pre-stored in the distributed blockchain network.
16. The method of claim 13, wherein the commitment includes a numerical value.
17. The method of claim 13, wherein the commitment to the verifiable information is encrypted.
18. The method of claim 13, wherein the at least one manifest further includes an encrypted, anonymous identity of the creator of the manifest.
19. The method of claim 18, wherein the true identity of the creator is not made public on the distributed blockchain network but is stored in a private registry.
20. The method described in claim 18, wherein the at least one manifest is modified by the creator or by a member added by the creator by adding a pointer.