Guarantee of Secure Provisioning of Blockchain Infrastructure
A shared secure provisioning ledger among consignment nodes continuously updates ledger nodes, addressing the challenge of secure and scalable blockchain provisioning by ensuring uniform security compliance across the network.
Patent Information
- Application Number
- JP2023516607
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-09-14
- Filing Date
- 2021-09-13
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-09-13
AI Technical Summary
Ensuring secure, consistent, and scalable provisioning of blockchain resources across permissioned and permissionless networks is challenging due to rapid shifts in security vectors, with conventional updates being periodic rather than continuous.
Implementing a shared secure provisioning ledger among consignment nodes that continuously update ledger nodes, ensuring compliance with security criteria through consensus, and enabling the propagation of updates to maintain uniform security standards across the blockchain network.
This approach enhances security and immutability by ensuring all nodes comply with the latest security updates, preventing vulnerabilities, and maintaining uniform security standards across the blockchain infrastructure.
Smart Images

Figure 0007710815000001 
Figure 0007710815000002 
Figure 0007710815000003
Abstract
Description
Technical Field
[0001] This disclosure generally relates to the field of blockchain infrastructure, and more specifically, to ensuring secure provisioning of blockchain infrastructure.
[0002] A blockchain generally refers to a shared immutable ledger that facilitates the recording of transactions and processes (such as asset and currency tracking within a business network). Implementations of blockchain infrastructure are becoming increasingly widespread, and new useful applications for blockchain are continuously being developed.
Summary of the Invention
[0003] Embodiments of this disclosure include a method, a computer program product, and a system for improving the security of blockchain infrastructure.
[0004] Multiple ledger nodes within a blockchain infrastructure are continuously updated via a set of consignment nodes. The set of consignment nodes shares a secure provisioning ledger. The secure provisioning ledger includes a set of updates related to the blockchain infrastructure. Each consignment node within the set propagates the set of updates to a subset of the multiple ledger nodes.
[0005] The above summary is not intended to describe every embodiment or all implementations shown in this disclosure.
Brief Description of the Drawings
[0006] The drawings included in this disclosure are incorporated herein and form a part thereof. They illustrate embodiments of this disclosure and, together with this specification, serve to explain the principles of this disclosure. The drawings merely exemplify typical embodiments and do not limit this disclosure.
[0007]
Figure 1
[0008]
Figure 2
[0009]
Figure 3
[0010]
Figure 4
[0011]
Figure 5
[0012]
Figure 6
[0013] The embodiments described herein are capable of various modifications and alternative forms, and specific details thereof are shown by way of example in the drawings and described in detail. However, it should be understood that the specific embodiments described are not to be taken in a limiting sense. Instead, it is intended to cover all modifications, equivalents, and alternatives within the scope of the present disclosure.
Mode for Carrying Out the Invention
[0014] Aspects of the present disclosure generally relate to the field of blockchain infrastructure, and more specifically, to ensuring secure provisioning of blockchain infrastructure. While the present disclosure is not necessarily limited to such applications, various aspects of the present disclosure may be appreciated through consideration of various examples using this context.
[0015] As the number of blockchain networks increases, it is an important issue to ensure that the provisioning of blockchain resources is secure, consistent, and scalable. This can apply to both permissioned and permissionless blockchain networks. Developers and administrators may be interested in ensuring that the latest and most secure software, hardware, and core code are included in or utilized by virtual machines, containers, or other units of the blockchain infrastructure.
[0016] Conventionally, network administrators have maintained security and consistency by means of regular security updates (e.g., in a permissioned blockchain) or by imposing penalties on the owners / operators of specific nodes / containers in some way that encourages consistency with other nodes / containers (e.g., in a permissionless blockchain).
[0017] Since security vectors shift rapidly, operating system (OS) providers, container providers, and cloud computing providers may issue continuous updates regarding the runtime and container stack. By preventing vulnerabilities such as nodes and containers running less secure software / updates / code, security is increased and the immutability of the architecture is improved by rationalizing compatibility between blockchain infrastructure components.
[0018] Embodiments of the present disclosure contemplate a method and model for ensuring secure and scalable provisioning of blockchain infrastructure. Conventional blockchain models are typically only periodically updated, for example when authenticating a new transaction. However, a continuous update model can use a special shared secure provisioning ledger to keep track of updates to the blockchain infrastructure. The shared secure provisioning ledger may be shared among special condit nodes, which can further propagate the recorded update requirements to the blockchain's ledger nodes. In some embodiments, each entity participating in the blockchain can use the condit nodes to manage the shared secure provisioning ledger and propagate updates to one or more ledger nodes utilized / owned by the entity. In this way, various enterprises / entities can participate in the blockchain network while ensuring that all of their own ledger nodes as well as the ledger nodes of their blockchain peers all comply with the ubiquitous standards regarding security updates such as software / hardware / firmware / etc.
[0019] In some embodiments, the entity may be a unique enterprise, but in some embodiments, the entity may be an organization (e.g., a bureau, a department, etc.) within a unique enterprise.
[0020] In some embodiments, the shared secure provisioning ledger may enforce explicit criteria (e.g., specifying a particular version of software / hardware / OS / firmware / etc.) or minimum criteria (e.g., specifying version X or later). In the event that the resources used to embody a particular tenant or ledger node cannot comply with the criteria, that / those node(s) may be rejected from registration on the blockchain network. In some embodiments, a grace period may be used. The grace period may include the amount of time that the components of the blockchain network need to perform an update and come into compliance with the criteria in the shared secure provisioning ledger.
[0021] In this way, the cross - entity blockchain network may use non - centralized, continuously available immutable security criteria for its infrastructure components, and each entity may be confident that every other entity maintains exactly the same level of security.
[0022] Referring now to FIG. 1, an exemplary computing environment 100 is shown for a blockchain infrastructure according to an embodiment of the present disclosure. In this example, three separate entities maintain their own segments 115A - C of the blockchain network. In some embodiments, segments 115A - C may all exist on the same server, across multiple servers, in the same cloud environment, or in separate cloud environments.
[0023] Each of the partitions 115A - C may contain at least one Conjure node 105A - C. The Conjure nodes 105A - C, as described herein, may share a special secure provision ledger to maintain a record of security criteria for provisioning components of the blockchain networks of the ledger nodes 110A1 - 3, 110B1 - 3, and 110C1 - 3. In some embodiments, the KUBERNETES architecture may be used to manage the shared secure provision ledger among the Conjure nodes 105A - C.
[0024] The shared secure provision ledger may be updated by consensus among the Conjure nodes 105A - C and may further contain security criteria regarding the ledger nodes 110A1 - 3, 110B1 - 3, and 110C1 - 3. Each Conjure node 105A - C may communicate and control the provisioning of the ledger nodes within the associated partition 115A - C of the blockchain network. For example, Conjure node 105A may propagate the security criteria within the shared secure provision ledger to the ledger nodes 110A1 - 3 to disable any ledger node that does not comply with those security criteria. In some embodiments, the shared secure provision ledger may dictate the minimum security criteria for the entire blockchain network, and each Conjure node 105A - C may further include additional security criteria regarding the ledger nodes 110A1 - 110C3 within their respective partitions 115A - C. In some embodiments, the Conjure nodes 105A - C may use parallel techniques such as single instruction multiple data (SIMD) techniques to propagate both sets of security criteria to their respective ledger nodes 110A1 - 110C3.
[0025] In some embodiments, the decommissioning of a leisure node may include procedures for creating an image or snapshot of the leisure information within the node, procedures for identifying a new leisure node (or in some embodiments, procedures for generating a new container) that can comply with security standards, and procedures for installing the image / snapshot on the new leisure node / container. In some embodiments, the new leisure node / container may be inspected to ensure compliance prior to registration and incorporation into the blockchain network.
[0026] The leisure nodes 110A1 to 110C3 can track assets or other objects / resources among various other leisure nodes 110A1 to 110C3 of the blockchain network using an immutable shared ledger.
[0027] This example shows three sets of three segments 115A - C, three consignment nodes 105A - C, and leisure nodes 110A1 to 110C3, but it should be understood by those skilled in the art that any number of segments, consignment nodes, and leisure nodes may be used. The examples given herein should not be construed as limiting the number of components (e.g., nodes / containers / segments) in any way.
[0028] Referring now to FIG. 2, an exemplary method 200 for ensuring secure provisioning of a blockchain infrastructure according to an embodiment of the present disclosure is shown. The exemplary method 200 may begin at 205, where the leisure nodes are continuously updated via the consignment nodes. In some embodiments, this may include updates regarding the operating system, hardware, software, firmware, or any other security - related aspect of the blockchain network components.
[0029] At 210, it is determined whether a new leisure node is to be added to the blockchain network. If so, at 215, it is also determined whether a new consignment node is to be added to the blockchain infrastructure (e.g., when a new entity is attempting to participate in the blockchain). If no consignment node is added, the process proceeds to 230.
[0030] At 215, if it is determined that a new consignment node is to be added to the blockchain, the consignment node is checked at 220 for compliance with the criteria in the shared secure provisioning ledger. At 220, if the consignment node fails the compliance check, the user attempting to add the leisure node and the consignment node is notified of the failure at 245.
[0031] However, if the consignment node passes the compliance check at 220, at 225, the new consignment node is added to the set of consignment nodes within the blockchain infrastructure and begins participating in the blockchain / sharing the secure provisioning ledger with any existing consignment nodes.
[0032] At 230, any updates required for the new leisure node to achieve compliance with the shared secure provisioning ledger are provided via the consignment node associated with the leisure node.
[0033] At 235, the new leisure node is checked for compliance. The compliance check may include procedures such as matching or checking the software / hardware / firmware version against the criteria within the shared secure provisioning ledger.
[0034] At 235, if it is determined that the new leisure node does not comply, the user who attempts to add the leisure node is notified of failure at 245, and the new leisure node is rejected from registration in the blockchain network.
[0035] However, at 235, if it is determined that the new leisure node complies with the criteria in the shared secure provisioning ledger, the new leisure node is added to the blockchain network at 240. In this way, the integrated security criteria can be used and propagated across all nodes and entities participating in the blockchain network.
[0036] Here, referring to FIG. 3, an exemplary method 300 for ensuring secure provisioning of a container according to an embodiment of the present disclosure is shown. In some embodiments, the KUBERNETES architecture is used between the concierge node and the leisure node and can ensure compliance with blockchain network policies such as security criteria defined within a shared secure provisioning ledger as described herein.
[0037] Method 300 may begin at 305, where the developer / user adds a Dockerfile for a potential KUBERNETES container to be added to the blockchain network (e.g., as a leisure node). In some embodiments, the Dockerfile may contain information such as container layer versions and specifications or policies to determine when a container or layer within the container should be replaced to improve the security of the container.
[0038] At 310, potential container layers are analyzed using a Dockerfile. In some embodiments, various policies may be defined. For example, if any vulnerabilities are found within a container layer, the layer should be upgraded, or if it cannot be upgraded, the container may be replaced with a compliant container policy.
[0039] At 315, if a vulnerable layer is found, at 320, a compliant layer may be substituted or the vulnerable layer may be upgraded. In some embodiments, a peer within a blockchain network may perform a check / inspection at 330 to determine whether the layer or container has been replaced or has become compliant, or both. For example, a replaced layer may be inspected against an existing continuous integration and continuous delivery (CI / CD) DevOps system.
[0040] In some embodiments, layer replacement (e.g., at step 320) may be implemented using a Dockerfile as well as commands related to LABEL, MAINTAINER, and ONBUILD. For example, the LABEL command may add metadata to a container image. LABEL may be, for example, a key-value pair used to handle layer replacement when a vulnerability is detected (e.g., VULNERABILITY_DETECTED=ANY).
[0041] In some embodiments, the MAINTAINER command may set the author field of the generated image to specify the user / developer to be notified of a vulnerability or layer replacement, or both (e.g., MAINTAINER=JOHN_DOE@DOCKERFILE.COM).
[0042] In some embodiments, the ONBUILD instruction may add a trigger instruction to be executed when the image is used as a basis for another build (e.g., a replacement layer / container). In some embodiments, this may be used to replace the base layer and to perform an inspection when the image is used to build a replacement layer / container, in addition to providing a trigger to notify a designated author.
[0043] However, if there was no layer substitution / upgrade prior to the check / inspection, the user or developer may be notified of a failure at 325. Similarly, if the container layer fails the inspection performed at 330, the check to determine pass / fail of the inspection at 335 may prompt the user / developer to be notified at 325.
[0044] However, for the check of pass / fail of the inspection, if it passes at 335, the container may be added to the blockchain network registry at 340.
[0045] Although this disclosure includes a detailed description of cloud computing, it should be understood that the implementation of the teachings described herein is not limited to a cloud computing environment. Rather, some embodiments of the invention can be implemented in conjunction with any other type of computing environment now known or later developed.
[0046] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services), which can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model can include at least five characteristics, at least three service models, and at least four deployment models.
[0047] The characteristics are as follows:
[0048] On-demand self-service: Cloud consumers can provision computing capabilities such as server time and network storage automatically, on their own, as needed, without the need for human interaction with the service provider.
[0049] Broad network access: The capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).
[0050] Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to demand. Consumers generally have no control or knowledge over the exact location of the provided resources, but there is a sense of location independence in that they may be able to specify location at a higher level of abstraction (e.g., country, state, data center).
[0051] Rapid elasticity: The ability can be provisioned quickly and elastically, in some cases automatically, to scale out rapidly and can be released quickly to scale in, so as to scale out quickly. For consumers, in many cases, the available capacity for provisioning appears limitless and can be purchased in any amount at any time.
[0052] Measured services: Cloud systems utilize metering capabilities at an appropriate level of abstraction for service types (such as storage, processing, bandwidth, and active user accounts) to automatically control and optimize resource usage. The amount of resource usage can be monitored, controlled, and reported, thereby providing transparency to both the provider and the consumer of the services utilized.
[0053] The service model is as follows:
[0054] Software as a Service (SaaS): The ability provided to consumers is to use the provider's applications running on the cloud infrastructure. The applications are accessible from various client devices through a client interface such as a web browser (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even the individual application capabilities, except for limited user-specific application configuration settings as possible exceptions.
[0055] Platform as a Service (PaaS): The capabilities provided to consumers are to deploy consumer-generated or acquired applications created using programming languages and tools supported by the provider on a cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, which includes networks, servers, operating systems, or storage, but control the deployed applications and, in some cases, the application hosting environment configuration.
[0056] Infrastructure as a Service (IaaS): The capabilities provided to consumers are to provision processing, storage, networks, and other fundamental computing resources. Consumers can deploy and run any software that may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but control the operating systems, storage, deployed applications, and, in some cases, perform limited control of select networking components (e.g., the host firewall).
[0057] The deployment models are as follows:
[0058] Private cloud: The cloud infrastructure is operated solely for a single organization. The private cloud may be managed by that organization or a third party and may exist on-premises or off-premises.
[0059] Community cloud: The cloud infrastructure is shared by several organizations and supports a specific community that shares interests (e.g., mission, security requirements, policies, and compliance considerations). The community cloud may be managed by those organizations or a third party and may exist on-premises or off-premises.
[0060] Public cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services.
[0061] Hybrid cloud: The cloud infrastructure remains a single entity but is a combination of two or more clouds (private, community, or public) joined by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting that balances the load between clouds).
[0062] Cloud computing environments are service-oriented, emphasizing statelessness, loose coupling, modularity, and semantic interoperability. At the core of cloud computing is an infrastructure that includes a network of interconnected nodes.
[0063] Referring now to FIG. 4, an exemplary cloud computing environment 50 is shown. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 that can communicate with a local computing device used by a cloud consumer, such as, for example, a personal digital assistant (PDA) or cellular telephone 54A, a desktop computer 54B, a laptop computer 54C, or an automotive computer system 54N, or a combination thereof. The nodes 10 can communicate with one another. The nodes 10 can be physically or virtually grouped within one or more networks, such as a private cloud, a community cloud, a public cloud, or a hybrid cloud, or combinations thereof, as described above herein (not shown). Thereby, the cloud computing environment 50 can provide infrastructure, platform, software, or combinations thereof, as a service such that a cloud consumer does not need to maintain resources on a local computing device. The types of computing devices 54A - N shown in FIG. 4 are for illustration only, and it should be understood that the computing nodes 10 and the cloud computing environment 50 can communicate with any type of computerized device through any type of network or network addressable connection (e.g., using a web browser) or combinations thereof.
[0064] Referring now to FIG. 5, a set of functional abstractions provided by the cloud computing environment 50 (FIG. 4) is shown. It should be understood in advance that the components, layers, and functions shown in FIG. 5 are for illustration only and that some embodiments of the invention are not limited thereto. As shown, the following layers and corresponding functions are provided:
[0065] The hardware and software layer 60 includes hardware components and software components. Examples of hardware components are: mainframe 61; servers 62 based on RISC (Reduced Instruction Set Computer) architecture; server 63; blade server 64; storage device 65; and network and networking components 66. In some embodiments, software components include network application server software 67 and database software 68.
[0066] The virtualization layer 70 provides an abstraction layer with the following examples of virtual entities: virtual server 71; virtual storage 72; virtual network 73 including a virtual private network; virtual applications and operating systems 74; and virtual client 75.
[0067] In one example, the management layer 80 may provide the functions described below. Resource provisioning 81 provides for the dynamic procurement of computing resources and other resources utilized to execute tasks within a cloud computing environment. Metering and pricing 82 provides for cost tracking when resources are utilized within a cloud computing environment and for billing or invoicing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides for authentication of identification information for cloud consumers and tasks and for the protection of data and other resources. The user portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides for the allocation and management of cloud computing resources such that required service levels are met. Service level agreement (SLA) planning and fulfillment 85 provides for the advance preparation and procurement of cloud computing resources in anticipation of future requirements in accordance with the SLA.
[0068] The workload layer 90 provides examples of functions that can be utilized in a cloud computing environment. Examples of workloads and functions that can be provided from this layer are: mapping and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analysis processing 94; transaction processing 95; and guarantee of secure provisioning of blockchain infrastructure 96.
[0069] Referring now to FIG. 6, there is shown a high-level block diagram of an exemplary computer system 601 that can be configured to execute various aspects of the present disclosure, including, for example, methods 200 / 300 as described in FIGS. 2 and 3. The exemplary computer system 601 can be used in implementing one or more of the methods or modules, and any associated functions or operations, described herein in connection with embodiments of the present disclosure (e.g., using one or more processor circuits or computer processors of a computer). In some embodiments, exemplary components of the computer system 601 include one or more CPUs 602, a memory subsystem 604, a terminal interface 612, a storage interface 614, an I / O (input / output) device interface 616, and a network interface 618, all of which may be coupled directly or indirectly for inter-component communication via a memory bus 603, an I / O bus 608, and an I / O bus interface unit 610.
[0070] The computer system 601 may include one or more general-purpose programmable central processing units (CPUs) 602A, 602B, 602C, and 602D, collectively referred to herein as CPU 602. In some embodiments, the computer system 601 may include multiple processors, typical of relatively large-scale systems, while in other embodiments, the computer system 601 may alternatively be a single CPU system. Each CPU 602 may execute instructions stored in the memory subsystem 604 and may include one or more levels of on-board cache. The memory subsystem 604 may include instructions 606 that cause the processor 602 to perform some or all of the functions described above with respect to FIGS. 2-3 when executed by the processor 602.
[0071] In some embodiments, memory subsystem 604 may have a random access semiconductor memory, a storage device, or a storage medium (volatile or non-volatile) for storing data and programs. In some embodiments, memory subsystem 604 may represent all of the virtual memory of computer system 601 and may also include the virtual memory of other computer systems coupled to computer system 601 connected via a network. Memory subsystem 604 may conceptually be a single monolithic entity, but in some embodiments, memory subsystem 604 may be a more complex configuration such as a hierarchy of caches and other memory devices. For example, the memory may exist in multiple levels of cache, and these caches may further be functionally divided such that one cache holds instructions while another holds non-instruction data used by the processor(s). As is known in any of various so-called non-uniform memory access (NUMA) computer architectures, the memory may further be distributed and associated with various CPUs or sets of CPUs. In some embodiments, main memory or memory subsystem 604 may include elements related to the control and flow of memory used by CPU 602. This may include memory controller 605.
[0072] In FIG. 6, the memory bus 603 is shown as a single bus structure providing a direct communication path between the CPU 602, the memory subsystem 604, and the I / O bus interface 610. However, in some embodiments, the memory bus 603 may have a plurality of different buses or communication paths, which may be arranged in various forms, such as point-to-point links in a hierarchical, star, or web configuration, multiple hierarchical buses, parallel and redundant paths, or any other suitable type of configuration. Further, although the I / O bus interface 610 and the I / O bus 608 are shown as single respective units, in some embodiments, the computer system 601 may include a plurality of I / O bus interface units 610, a plurality of I / O buses 608, or both. Additionally, although a plurality of I / O interface units separating the I / O bus 608 from various communication paths reaching various I / O devices are shown, in other embodiments, some or all of the I / O devices may be directly connected to one or more system I / O buses.
[0073] In some embodiments, the computer system 601 may be a multi-user mainframe computer system, a single-user system, or a server computer or similar device that has little or no direct user interface but receives requests from other computer systems (clients). Further, in some embodiments, the computer system 601 may be implemented as a desktop computer, a portable computer, a laptop or notebook computer, a tablet computer, a pocket computer, a telephone, a smartphone, a mobile device, or any other suitable type of electronic device.
[0074] Note that FIG. 6 is intended to show exemplary components of an exemplary computer system 601. However, in some embodiments, individual components may be more or less complex than those represented in FIG. 6, components other than or in addition to those shown in FIG. 6 may exist, and the number, type, and configuration of such components may vary.
[0075] The present invention may be a system, method, or computer program product, or a combination thereof, integrated at any possible level of technical detail. The computer program product may include computer-readable storage media (s) having computer-readable program instructions for causing a processor to execute aspects of the present invention.
[0076] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing, but is not limited thereto. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile discs (DVDs), memory sticks, floppy disks, punch cards, or mechanically encoded devices such as raised structures within grooves in which instructions are recorded, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed to be a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire.
[0077] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to respective computing / processing devices, or may be downloaded from an external computer or an external storage device via a network, such as, for example, the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage on a computer-readable storage medium within each respective computing / processing device.
[0078] The computer-readable program instructions for carrying out the operations of the present invention may be source code or object code written in any combination of one or more programming languages, including assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or object-oriented programming languages such as Smalltalk® or C++, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on a user's computer as a stand-alone software package, partially on a user's computer, partially on a user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) can execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit in order to carry out aspects of the present invention.
[0079] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0080] These computer-readable program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that includes instructions for implementing the functions / acts in the manner specified in one or more blocks of the flowchart and / or block diagram, such that the computer-readable storage medium is a manufacture comprising instructions for causing a computer, programmable data processing apparatus, or other device or combination thereof to function in a particular manner.
[0081] Alternatively, the computer-readable program instructions may be loaded onto a computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, such that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0082] Flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions that include one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the drawings. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It should also be noted that each block of the block diagrams or flowchart diagrams, or combinations of blocks in the block diagrams or flowchart diagrams or both, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.
[0083] The description of the various embodiments of the present invention has been presented for purposes of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the described embodiments. The terminology used herein was chosen to best explain the principles of the embodiments, the practical application, or technical improvement in the marketplace, or to enable others of ordinary skill in the art to understand the embodiments disclosed herein. 。 [Item 1] A method for improving the security of a blockchain infrastructure, comprising continuously updating a plurality of ledger nodes in the blockchain infrastructure via a set of commit nodes, wherein the set of commit nodes shares a secure provisioning ledger, wherein the secure provisioning ledger has a set of updates to regulations regarding the blockchain infrastructure, and each commit node in the set of commit nodes propagates the set of updates to a subset of the plurality of ledger nodes. Method. [Item 2] Determining that a new ledger node is added to the blockchain infrastructure, wherein the new ledger node is associated with a first commit node; Providing the set of updates regarding the blockchain infrastructure to the new ledger node via the first commit node; Determining that the new ledger node is applying the set of updates; and Adding the new ledger node to the blockchain infrastructure The method according to item 1, further comprising. [Item 3] Determining that a new ledger node is added to the blockchain infrastructure, wherein the new ledger node is associated with a new commit node; Confirming that the new commit node complies with the set of updates regarding the blockchain infrastructure; Adding the new commit node to the set of commit nodes in the blockchain infrastructure, wherein the new commit node has the shared secure provisioning ledger; Providing the set of updates regarding the blockchain infrastructure to the new ledger node via the new commit node; Determining that the new ledger node is applying the set of updates; and Adding the new ledger node to the blockchain infrastructure The method according to item 1, further comprising. [Item 4] applying one or more new updates regarding the blockchain infrastructure to the shared secure provisioning ledger; determining that one or more of the plurality of ledger nodes are unable to comply with the one or more new updates; and disabling the one or more ledger nodes from the blockchain infrastructure The method according to item 1, further comprising. [Item 5] The step of disabling the one or more ledger nodes comprises identifying new ledger nodes, the new ledger nodes being compliant with the one or more new updates; generating a snapshot of a set of blockchain information associated with the one or more ledger nodes; replicating the snapshot onto the new ledger nodes; and adding the new ledger nodes to the blockchain infrastructure The method according to item 4, further comprising. [Item 6] Each of the set of consensus nodes is owned by a unique entity, the method according to item 5. [Item 7] The method according to item 1, wherein software is provided as a service in a cloud environment to provision the blockchain infrastructure. [Item 8] A computer program product for improving the security of a blockchain infrastructure, the computer program product comprising a computer-readable storage medium having program instructions embodied thereon, the program instructions executable by a device to cause the device to continuously update a plurality of ledger nodes within the blockchain infrastructure via a set of consensus nodes, the set of consensus nodes sharing a secure provisioning ledger, the secure provisioning ledger having a set of defined updates regarding the blockchain infrastructure, and each of the set of consensus nodes propagating the set of updates to a subset of the plurality of ledger nodes, computer program product. [Item 9] The program instructions further cause the device to Cause a determination that a new leisure node is added to the blockchain infrastructure, where the new leisure node is associated with a first consent node; Cause the set of updates regarding the blockchain infrastructure to be provided to the new leisure node via the first consent node; Cause a determination that the new leisure node is applying the set of updates; and Cause the new leisure node to be added to the blockchain infrastructure, The computer program product according to item 8. [Item 10] The program instructions further cause the device to, Cause a determination that a new leisure node is added to the blockchain infrastructure, where the new leisure node is associated with a new consent node; Cause the new consent node to confirm compliance with the set of updates regarding the blockchain infrastructure; Cause the new consent node to be added to the set of consent nodes within the blockchain infrastructure, where the new consent node has the shared secure provisioning ledger; Cause the set of updates regarding the blockchain infrastructure to be provided to the new leisure node via the new consent node; Cause a determination that the new leisure node is applying the set of updates; and Cause the new leisure node to be added to the blockchain infrastructure, The computer program product according to item 8. [Item 11] The program instructions further cause the device to, Cause one or more new updates regarding the blockchain infrastructure to be applied to the shared secure provisioning ledger; Cause a determination that one or more of the plurality of leisure nodes are unable to comply with the one or more new updates; and Cause the one or more leisure nodes to be deactivated from the blockchain infrastructure, The computer program product according to item 8. [Item 12] The procedure for deactivating the one or more leisure nodes is, A procedure for identifying a new leisure node, the new leisure node conforming to the one or more new updates; A procedure for generating a snapshot of a set of blockchain information associated with the one or more leisure nodes; A procedure for replicating the snapshot on the new leisure node; and A procedure for adding the new leisure node to the blockchain infrastructure The computer program product according to item 11, further comprising. [Item 13] The computer program product according to item 12, wherein each of the consensus nodes in the set of consensus nodes is owned by a unique entity. [Item 14] The computer program product according to item 8, wherein software is provided as a service in a cloud environment to provision the blockchain infrastructure. [Item 15] A system for improving the security of a blockchain infrastructure, the system comprising: A memory subsystem having program instructions included thereon; and A processor communicating with the memory subsystem The program instructions cause the processor to: Continuously update a plurality of leisure nodes in the blockchain infrastructure via a set of consensus nodes, The set of consensus nodes share a secure provisioning ledger, The secure provisioning ledger has a set of updates to the regulations regarding the blockchain infrastructure, and Each consensus node in the set of consensus nodes propagates the set of updates to a subset of the plurality of leisure nodes. System. [Item 16] The program instructions further cause the processor to: Determine that a new leisure node is added to the blockchain infrastructure, where the new leisure node is associated with a first consensus node; Provide the set of updates regarding the blockchain infrastructure to the new leisure node via the first consensus node; Determine that the new leisure node is applying the set of updates; and Add the new leisure node to the blockchain infrastructure. The system according to item 15. [Item 17] The program instructions further cause the processor to determine that a new leisure node is added to the blockchain infrastructure, where the new leisure node is associated with a new consent node; cause the new consent node to confirm compliance with the set of updates to the blockchain infrastructure; add the new consent node to the set of consent nodes within the blockchain infrastructure, where the new consent node has the shared secure provisioning ledger; cause the set of updates to the blockchain infrastructure to be provided to the new leisure node via the new consent node; determine that the new leisure node is applying the set of updates; and add the new leisure node to the blockchain infrastructure. The system according to item 15. [Item 18] The program instructions further cause the processor to apply one or more new updates to the blockchain infrastructure to the shared secure provisioning ledger; determine that one or more of the plurality of leisure nodes are unable to comply with the one or more new updates; and disable the one or more leisure nodes from the blockchain infrastructure. The system according to item 15. [Item 19] The procedure for disabling the one or more leisure nodes includes procedures for identifying a new leisure node that complies with the one or more new updates; generating a snapshot of the set of blockchain information associated with the one or more leisure nodes; replicating the snapshot onto the new leisure node; and adding the new leisure node to the blockchain infrastructure. The system according to item 18, further comprising [Item 20] Each consent node within the set of consent nodes is owned by a unique entity. The system according to item 19.
Claims
1. A method for improving the security of a blockchain infrastructure, comprising the step of continuously updating a plurality of ledger nodes within the blockchain infrastructure via a set of consignment nodes, wherein the set of consignment nodes shares a secure provisioning ledger, the secure provisioning ledger has a set of defined security updates for the blockchain infrastructure, and each consignment node within the set of consignment nodes propagates the set of defined security updates to a subset of the plurality of ledger nodes; and each consignment node within the set of consignment nodes enforces compliance with the set of defined security updates by performing a compliance check on the subset of the plurality of ledger nodes to determine that the subset of the plurality of ledger nodes has installed the set of defined security updates comprising a method.
2. A method for improving the security of a blockchain infrastructure, comprising the step of continuously updating a plurality of ledger nodes within the blockchain infrastructure via a set of consignment nodes, wherein the set of consignment nodes shares a secure provisioning ledger, the secure provisioning ledger has a set of defined security updates for the blockchain infrastructure, each consignment node within the set of consignment nodes propagates the set of defined security updates to a subset of the plurality of ledger nodes; applying one or more new updates for the blockchain infrastructure to the shared secure provisioning ledger; determining that one or more of the plurality of ledger nodes are unable to comply with the one or more new updates; and taking the one or more ledger nodes out of service from the blockchain infrastructure, identifying new ledger nodes that comply with the one or more new updates Generating a snapshot of a set of blockchain information associated with the one or more leisure nodes; Replicating the snapshot onto the new leisure node; and Adding the new leisure node to the blockchain infrastructure, including the steps comprising a method.
3. Determining that a new leisure node is to be added to the blockchain infrastructure, where the new leisure node is associated with a first consent node; Providing, via the first consent node, a set of the specified security updates regarding the blockchain infrastructure to the new leisure node; Determining that the new leisure node is applying the set of the specified security updates; and Adding the new leisure node to the blockchain infrastructure The method according to claim 1 or 2, further comprising.
4. Determining that a new leisure node is to be added to the blockchain infrastructure, where the new leisure node is associated with a new consent node; Verifying that the new consent node complies with the set of the specified security updates regarding the blockchain infrastructure; Adding the new consent node to the set of consent nodes within the blockchain infrastructure, where the new consent node has the shared secure provisioning ledger; Providing, via the new consent node, a set of the specified security updates regarding the blockchain infrastructure to the new leisure node; Determining that the new leisure node is applying the set of the specified security updates; and Adding the new leisure node to the blockchain infrastructure The method according to claim 1 or 2, further comprising.
5. Applying one or more new updates regarding the blockchain infrastructure to the shared secure provisioning ledger; determining that one or more of the plurality of leisure nodes cannot comply with the one or more new updates; and disabling the use of the one or more leisure nodes from the blockchain infrastructure The method according to claim 1, further comprising.
6. The method according to claim 2, wherein each of the set of consignment nodes is owned by a unique entity.
7. The method according to any one of claims 1 to 6, wherein software is provided as a service in a cloud environment to provision the blockchain infrastructure.
8. A computer program for improving the security of a blockchain infrastructure, the device being provided with a procedure for continuously updating a plurality of leisure nodes in the blockchain infrastructure via a set of consignment nodes, wherein the set of consignment nodes shares a secure provisioning ledger, the secure provisioning ledger having a set of regulatory security updates for the blockchain infrastructure, a procedure in which each consignment node in the set of consignment nodes propagates the set of regulatory security updates to a subset of the plurality of leisure nodes; and a procedure for enforcing compliance with the set of regulatory security updates by performing a compliance check on the subset of the plurality of leisure nodes, wherein each consignment node in the set of consignment nodes determines that the subset of the plurality of leisure nodes has installed the set of regulatory security updates to cause to execute computer program.
9. A computer program for improving the security of a blockchain infrastructure, the device being provided with a procedure for continuously updating a plurality of leisure nodes in the blockchain infrastructure via a set of consignment nodes, wherein the set of consignment nodes shares a secure provisioning ledger, the secure provisioning ledger having a set of regulatory security updates for the blockchain infrastructure, A procedure in which each consensus node in the set of consensus nodes propagates the set of the specified security updates to a subset of the plurality of ledger nodes; A procedure for applying one or more new updates regarding the blockchain infrastructure to the shared secure provision ledger; A procedure for determining that one or more ledger nodes among the plurality cannot comply with the one or more new updates; and A procedure for disabling the use of the one or more ledger nodes from the blockchain infrastructure, A procedure for identifying a new ledger node, the new ledger node complying with the one or more new updates; A procedure for generating a snapshot of a set of blockchain information associated with the one or more ledger nodes; A procedure for replicating the snapshot onto the new ledger node; and A procedure for adding the new ledger node to the blockchain infrastructure, including To cause to execute, A computer program.
10. On the device, A procedure for determining that a new ledger node is added to the blockchain infrastructure, where the new ledger node is associated with a first consensus node; A procedure for providing, via the first consensus node, the set of the specified security updates regarding the blockchain infrastructure to the new ledger node; A procedure for determining that the new ledger node is applying the set of the specified security updates; and A procedure for adding the new ledger node to the blockchain infrastructure The computer program according to claim 8 or 9, further causing to execute.
11. On the device, A procedure for determining that a new ledger node is added to the blockchain infrastructure, where the new ledger node is associated with a new consensus node; A procedure for confirming that the new consensus node complies with the set of the specified security updates regarding the blockchain infrastructure; A procedure for adding the new consensus node to the set of the consensus nodes within the blockchain infrastructure, wherein the new consensus node has the shared secure provision ledger; A procedure for providing, via the new consensus node, a set of the specified security updates regarding the blockchain infrastructure to the new ledger node; A procedure for determining that the new ledger node is applying the set of the specified security updates; and A procedure for adding the new ledger node to the blockchain infrastructure, The computer program according to claim 8 or 9, further causing the above to be executed.
12. On the device, A procedure for applying one or more new updates regarding the blockchain infrastructure to the shared secure provision ledger; A procedure for determining that one or more ledger nodes among the plurality cannot comply with the one or more new updates; and A procedure for disabling the use of the one or more ledger nodes from the blockchain infrastructure, The computer program according to claim 8, further causing the above to be executed.
13. Each consensus node within the set of the consensus nodes is owned by a unique entity. The computer program according to claim 9.
14. The computer program according to any one of claims 8 to 13, wherein software is provided as a service in a cloud environment to provision the blockchain infrastructure.
15. A system for improving the security of a blockchain infrastructure, the system comprising: A memory subsystem including program instructions thereon; and A processor communicating with the memory subsystem The program instructions cause the processor to: Continuously update a plurality of ledger nodes within the blockchain infrastructure via a set of consensus nodes, The set of consensus nodes shares a secure provision ledger, The secure provision ledger has a set of specified security updates regarding the blockchain infrastructure, Each of the consensus nodes within the set of consensus nodes propagates the set of the specified security updates to a subset of the plurality of ledger nodes, and each of the consensus nodes within the set of consensus nodes enforces compliance with the set of the specified security updates by performing a compliance check of the subset of the plurality of ledger nodes to determine that the subset of the plurality of ledger nodes has installed the set of the specified security updates. System.
16. A system for improving the security of a blockchain infrastructure, the system comprising: a memory subsystem having program instructions stored thereon; and a processor in communication with the memory subsystem wherein the program instructions cause the processor to continuously update a plurality of ledger nodes within the blockchain infrastructure via a set of consensus nodes, the set of consensus nodes sharing a secure provisioning ledger, the secure provisioning ledger having a set of specified security updates for the blockchain infrastructure, and each of the consensus nodes within the set of consensus nodes propagates the set of the specified security updates to a subset of the plurality of ledger nodes, apply one or more new updates for the blockchain infrastructure to the shared secure provisioning ledger; cause one or more of the plurality of ledger nodes to be determined to be non-compliant with the one or more new updates; and disable the one or more ledger nodes from the blockchain infrastructure, wherein the procedure for disabling the one or more ledger nodes comprises a procedure for identifying new ledger nodes that comply with the one or more new updates; a procedure for generating a snapshot of a set of blockchain information associated with the one or more ledger nodes; a procedure for replicating the snapshot onto the new ledger nodes; and A procedure for adding the new leisure node to the blockchain infrastructure further comprising a system
17. The program instructions further cause the processor to determine that a new leisure node is added to the blockchain infrastructure, where the new leisure node is associated with a first consent node; provide, via the first consent node, a set of the specified security updates for the blockchain infrastructure to the new leisure node; determine that the new leisure node is applying the set of the specified security updates; and add the new leisure node to the blockchain infrastructure, The system according to claim 15 or 16
18. The program instructions further cause the processor to determine that a new leisure node is added to the blockchain infrastructure, where the new leisure node is associated with a new consent node; confirm that the new consent node complies with the set of the specified security updates for the blockchain infrastructure; add the new consent node to the set of consent nodes within the blockchain infrastructure, where the new consent node has the shared secure provisioning ledger; provide, via the new consent node, a set of the specified security updates for the blockchain infrastructure to the new leisure node; determine that the new leisure node is applying the set of the specified security updates; and add the new leisure node to the blockchain infrastructure, The system according to claim 15 or 16
19. The program instructions further cause the processor to apply one or more new updates for the blockchain infrastructure to the shared secure provisioning ledger; determine that one or more of the plurality of leisure nodes are unable to comply with the one or more new updates; and Disabling the use of the one or more leisure nodes from the blockchain infrastructure The system according to claim 15
20. The system according to claim 16, wherein each of the consignment nodes in the set of consignment nodes is owned by a unique entity
Citation Information
Patent Citations
Operation management method, operation management system, and operation management program
JP2019028525A
Computer-implemented method, computer system and computer program for suspending communication to / from non-compliant servers through firewall
JP2020072475A
Method, apparatus and electronic device for communication between blockchain nodes, and method, apparatus and electronic device for blockchain-based certificate management
JP2020512715A
Autonomous data exchange marketplace system and methods
US20200090188A1
Computer-implemented system and method for managing a large distributed memory pool in a blockchain network
WO2019021107A1