Method and distributed ledger system for supporting the sharing of travellers' digital health data in a travel environment

A distributed ledger system with blockchains and zero-knowledge proofs addresses privacy and security issues in sharing travelers' health data, ensuring comprehensive and reliable health information disclosure in travel environments.

JP7719859B2Active Publication Date: 2025-08-06NEC CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023513209
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-09-24
Filing Date
2020-12-15
Publication Date
2025-08-06
Estimated Expiration
2040-12-15

AI Technical Summary

Technical Problem

Existing methods for sharing travelers' digital health data in a travel environment face challenges in ensuring privacy and security while providing reliable health information, particularly during pandemics, as they may allow individuals to selectively disclose sensitive information or omit test results, compromising safety.

Method used

A distributed ledger system comprising a global identity blockchain, security blockchains for specific travel segments, and a health blockchain is used to manage and authenticate entities, with health data records stored against hashed access keys and verified using zero-knowledge proofs to ensure privacy and integrity.

Benefits of technology

The system provides secure and privacy-preserving sharing of travelers' health data, ensuring that all required health records are disclosed and verified, thus enhancing safety and compliance with health policies in travel environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007719859000037
    Figure 0007719859000037
  • Figure 0007719859000038
    Figure 0007719859000038
  • Figure 0007719859000039
    Figure 0007719859000039
Patent Text Reader

Abstract

A method for supporting the sharing of travelers' digital health data in a travel environment, where travelers' identities are managed using a distributed ledger system, the distributed ledger system including a global identity blockchain, several security blockchains, and a health blockchain, the method comprising: sending a request to share a predetermined number of health data records from the security blockchain to the traveler; receiving, by the security blockchain, successive access keys for the requested health data records and a zero-knowledge proof from the traveler; verifying, by the security blockchain, the zero-knowledge proof received from the traveler, where the zero-knowledge proof is used to verify a most recent access key among the access keys provided by the traveler; upon successful verification of the zero-knowledge proof, retrieving, by the security blockchain, the health data records from the health blockchain based on hashed access keys, where the hashed access keys are generated from the access keys provided by the traveler; and verifying, by the security blockchain, the access keys provided by the traveler using the hashed previous access keys included in the retrieved health data records to check whether the traveler has provided the necessary access keys for the health data records as requested. Further, a corresponding distributed ledger system is disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for supporting the sharing of travellers' digital health data in a travel environment.

[0002] Furthermore, the present invention relates to a distributed ledger system for supporting the sharing of traveler digital health data in a travel environment. [Background technology]

[0003] For example, airports are highly complex systems through which millions of people move every day. This complexity has reached a point where travelers have little understanding of what is happening behind the scenes. What appears to be a simple workflow—checking in, passing through a metal detector, boarding a plane, disembarking, and collecting luggage—is actually made possible by many processes working in concert to make it all happen. One such process is identity management. Indeed, the identity of every passenger / traveler must be verified to ensure that the traveler is not a risk and is truly who they claim to be. Thus, at each checkpoint, travelers must present some form of valid ID (e.g., a passport), a valid airline ticket, and possibly a valid entry visa (e.g., ESTA, Electronic System for Travel Authorization) if required by the destination country.

[0004] Furthermore, in this context, during a potential pandemic, obtaining reliable information about travelers' health may be required, such as to ensure that they are free of infection and / or up-to-date on vaccinations. Currently, in the midst of the COVID-19 pandemic, many countries require a negative PCR test performed no more than 48 hours before departure. However, this may not provide sufficient information. Furthermore, false-negative tests could jeopardize the safety of all passengers. To prevent this, there has been much discussion between governments and airlines about how passengers may attest to their health. One example is the creation of so-called "health passports" that provide assurances to visiting countries about the passenger's health status. This health passport would include a health certificate verifying the validity of test results performed in a privacy-preserving manner, and upon request, travelers could reveal the results of the most recent test performed to indicate their risk of carrying the virus.

[0005] Sharing privacy-sensitive health information poses unique challenges for individuals, governments, and industry. Protecting individual privacy is paramount and may be intended to address some of the key challenges, which may be identified as follows: - Ensure strong data privacy, such that individuals have complete control over their health data. For example, health data and / or transactions should not be able to be linked to their owner by an outside party. Furthermore, even if a user shares some of their data, future data and data insertions should be completely unlinkable to the individual again. Health data verifiers, such as industry, health authorities, and immigration authorities, can independently check the authenticity of health information. For example, a verifier can check whether the health data presented actually belongs to the individual presenting the data, and that it has not been tampered with or falsified. -Health data is presented completely and without omissions. For example, individuals submitting data cannot omit any adverse health results. Once an individual consents to sharing their data, complete and up-to-date data over a set period of time (e.g., the past two weeks) is automatically presented.

[0006] Recently, there have been approaches to building and deploying identity solutions pursued by providers in the market, such as Sovrin (more information can be found at https: / / sovrin.org) and Evernym (more information can be found at https: / / www.evernym.com). These providers offer completely self-sovereign user-based solutions, i.e., users have complete control over the data and credentials they share, and as a result, users can choose not to reveal any undesirable consequences. While verifiable credentials are adequate for proving static use cases, such as proving someone is over a certain age, they face limitations in dynamic use cases, such as health data, where the state is constantly evolving.

[0007] While fully self-sovereign identities are interesting for users / travelers, they offer travelers the possibility to selectively disclose the information they want, potentially hiding sensitive information such as positive test results for infectious diseases, which is undesirable in many use cases. [Prior art documents] [Patent documents]

[0008] [Patent Document 1] PCT / EP2020 / 055478 [Patent Document 2] PCT / EP2020 / 055479 [Non-patent literature]

[0009] [Non-Patent Document 1] https: / / sovrin.org [Non-patent document 2] https: / / www.evernym.com Summary of the Invention [Problem to be solved by the invention]

[0010] It is therefore an object of the present invention to improve and further develop methods and systems of the type initially described for supporting the sharing of travellers' digital health data in a travel environment in such a way that traveller privacy is provided whilst improving the provision of some security for different entities. [Means for solving the problem]

[0011] According to the present invention, the aforementioned object is achieved by a method for supporting sharing of traveler's digital health data in a travel environment, wherein traveler's identity information is managed using a distributed ledger system, the distributed ledger system includes a global identity blockchain, several security blockchains, and a health blockchain, the global identity blockchain is used as a registry for authenticating entities in the distributed ledger system, the security blockchain is used for a given travel segment such that the security blockchain is accessible by entities in the distributed ledger system involved in the given travel segment, the health blockchain is used for sharing traveler's health data in a key-value store of the health blockchain, health data records are stored against hashed access keys, the health data records include hashed previous access keys and health data information, the method includes: sending a request from the security blockchain to the traveler to share a predetermined number of health data records; receiving, via a security blockchain, from the traveler, a sequential access key for the requested health data record and a zero-knowledge proof; verifying, by a security blockchain, the zero-knowledge proof received from the traveler, wherein the zero-knowledge proof is used to verify the most recent access key among the access keys provided by the traveler; If the zero-knowledge proof verification is successful, retrieving the health data record from the health blockchain based on a hashed access key by the security blockchain, where the hashed access key is generated from the access key provided by the traveler; verifying, via a security blockchain, the access key provided by the traveler using the hashed previous access key contained within the retrieved health data record to check whether the traveler provided the access key required for the health data record as requested; Includes.

[0012] The aforementioned object is further achieved by a distributed ledger system for supporting sharing of travelers' digital health data in a travel environment, the distributed ledger system including a global identity blockchain, several security blockchains, and a health blockchain, the global identity blockchain being used as a registry for authenticating entities in the distributed ledger system, the security blockchain being used for a predetermined travel segment so that the security blockchain is accessible by entities in the distributed ledger system involved in the predetermined travel segment, the health blockchain being used to share the travelers' health data in a key-value store of the health blockchain, health data records being stored against a hashed access key, the health data record including a hashed previous access key and health data information, the security blockchain being used to share a predetermined number of health data records. the security blockchain is configured to receive from the traveler successive access keys for the requested health data record and a zero-knowledge proof; the security blockchain is configured to verify the zero-knowledge proof received from the traveler; the zero-knowledge proof is utilized to verify a most recent one of the access keys provided by the traveler; upon successful verification of the zero-knowledge proof, the security blockchain is configured to retrieve the health data record from the health blockchain based on the hashed access key; the hashed access key is generated from the access key provided by the traveler; and the security blockchain is configured to verify the access key provided by the traveler using the hashed previous access key included in the retrieved health data record to check whether the traveler has provided the access key required for the health data record as requested.

[0013] The present invention first recognizes that significant improvements in the context of sharing travelers' digital health data in a travel environment may be achieved by providing range queries over the travelers' unlinkable, consecutive health data stored on a specific health blockchain. According to the present invention, a distributed ledger system is used, including a global identity blockchain, several security blockchains, and a health blockchain. Travelers' identities are managed using the distributed ledger system. The global identity blockchain is used as a registry for authenticating entities / actors in the distributed ledger system. Therefore, the global identity blockchain is accessible by all entities / actors in the distributed ledger system, so that entities / actors are registered and authenticated in the global identity blockchain. With regard to the security blockchain, the security blockchain is used for a given travel segment, so that the security blockchain is only accessible by the distributed ledger system entities involved in that given travel segment. The health blockchain is used to share travelers' health data records in the health blockchain's key-value store. The health data records are stored against a hashed access key, and the health data records include a hashed prior access key and health data information as values in the health blockchain's key-value store.

[0014] Taking this configuration into consideration, according to the present invention, the security blockchain sends a request to the traveler to share a predetermined number of the most recent health data records. The traveler then sends successive access keys for the requested health data records to the security blockchain along with a zero-knowledge proof for the access keys. The security blockchain verifies the zero-knowledge proof received from the traveler, and the zero-knowledge proof is used to verify the latest (newest) access key among the access keys provided by the traveler that is not yet linked in the health blockchain. In this regard, the latest (newest) access key that is not yet linked in the health blockchain means that the hash of this latest access key has not yet been inserted / recorded in the health blockchain. In other words, the zero-knowledge proof is used to verify the legitimacy of the new access key to add to the health blockchain. If the verification of the zero-knowledge proof is successful, the security blockchain retrieves the health data records from the health blockchain based on the hashed access key. The hashed access key is generated from the access key provided by the traveler using a predetermined hash function. The security blockchain then verifies the (remaining) access keys provided by the traveler that are already linked in the health blockchain. In this regard, access keys already linked in the health blockchain mean that the hashes of these access keys have already been inserted / recorded in the health blockchain. Verification of the remaining access keys is performed by deriving the actual stored key using a one-way function, such as a hash function. The value associated with the derived key may then be retrieved in the health blockchain, which further provides information to verify the link with the previous derived key. Thus, verification may be performed using the hashed previous access key contained within the retrieved health data record. Thus, it may be checked and ensured that the traveler has provided all the necessary access keys for all health data records as required by the security blockchain.The health blockchain does not have any interpretable links, however, to verify the links stored in the blockchain, there is a hidden hash chain so that the links can only be seen when you are in possession of the data.

[0015] Thus, the present invention provides a method and system for supporting the sharing of travelers' digital health data in a travel environment, providing traveler privacy while improving the provision of some security for different entities.

[0016] Travel environments may include, but are not limited to, airport, train, and / or watercraft (such as ferries and / or cruise ships) travel.

[0017] The term "travel segment," particularly in the claims and preferably in this specification, may be understood as a term typically applied to a portion of an itinerary in which a traveler stops at multiple cities along the way. For example, the term "travel segment" may be or include a flight segment in the context of an airport travel environment. A "flight segment" may be understood as a term typically applied to a portion of an itinerary in which a traveler stops at multiple cities along the way. However, strictly speaking, all flights may have at least one flight segment, and on a direct flight, a segment is from the departure city to the final destination. Furthermore, a flight segment in an air travel may be defined by an airline as the entire journey, including all legs and stopovers listed under the same flight number in an itinerary. Essentially, no matter how many times a passenger boards or disembarks the same aircraft, a flight segment may be defined as the journey from when the traveler / passenger first boards the plane to when the traveler / passenger disembarks at the destination, as long as the traveler / passenger is on the same aircraft and the flight number remains the same. The number of segments in a traveler / passenger's travel plan may be the same as the number of flight numbers in the traveler / passenger's itinerary.

[0018] The terms "entity" and "actor" may be used interchangeably, particularly in the claims and preferably in this specification, and each may include a device adapted to perform computations, such as a personal computer, a tablet, a mobile phone, a server, etc., where the device comprises one or more processors having one or more cores and may be connectable to a memory for storing one or more applications adapted to perform one or more corresponding steps of the embodiments of the present invention. Any application may be software-based and / or hardware-based, installed in the memory on which the processor can operate. The device, entity, etc. may be adapted so that corresponding steps to be computed are performed in an optimized manner. For example, different steps may be executed in parallel on different cores of a single processor. Furthermore, entities may be identical, forming a single computing device. A device may also be instantiated as a virtual device running on a physical computing resource. Thus, different devices may be executed on said physical computing resource. In other words, the terms "entity" above should each be understood as any kind of physical or virtual computing entity, and may include, but are not limited to, the following: an application running on a computer, a microprocessor, a single-core processor, a dual-core processor, a quad-core processor, or an octa-core processor, etc., or a computer with memory, a processor, etc. The application, computer, or processor may have one or more interfaces, ports, etc. for communicating with other devices, entities, ports, interfaces, etc.

[0019] The term "transaction" should be understood in its most general sense, particularly in the claims and preferably in the present specification, to refer to information sent or transmitted over a network, e.g., to nodes connected to the node sending said transaction. Said transaction may be provided in the form of a message, a data packet, etc., and may include information about the recipient of said transaction.

[0020] The term "blockchain," particularly in the claims and preferably in this specification, may be understood as a distributed database that maintains a continuously growing list of data records that are hardened against tampering and revision even by operators of data storage nodes that host the database. Blockchains, for example, include two types of records: so-called transactions and so-called blocks. Transactions may be the actual data to be stored in the blockchain, while blocks may be records that confirm when and in what order certain transactions were journaled as part of the blockchain database. Transactions may be created by participants, and blocks may be created by users, who may use dedicated software or equipment specifically designed to create blocks.

[0021] Blockchains may also provide smart contract functionality. A smart contract is a piece of software that runs on the blockchain and provides an interface for interacting with the data. Smart contracts are typically enforced by nodes / entities in a distributed ledger system. Because they require the consent of a majority of participants, a single entity cannot bypass the rules defined by a smart contract. A key advantage of smart contracts is their ability to automate an organization's business logic. This automation, in turn, negates the impact of human error and misunderstandings that can lead to legal disputes. While legal contracts or laws may be subject to individual interpretation, software is deterministic and leaves no room for subjective interpretation. While smart contracts may typically be issued by any entity in the system, techniques implemented for embodiments of the present invention may authorize only a subset of entities to issue smart contracts in a distributed ledger system.

[0022] According to embodiments of the present invention, it may be provided that a prior access key contained as a hash (i.e., as a hashed prior access key) within a traveler's health data record represents the access key for the traveler's prior health data record on the health blockchain. In this regard, the prior health data record may be addressed by generating a hash of this (prior) access key.

[0023] According to an embodiment of the present invention, a first hash function may be used to calculate a hashed access key that is used as a key for a health data record in a health blockchain key-value store. A second hash function may be used to calculate a hashed previous access key that is stored as a value in a health data record in the health blockchain key-value store. In this regard, two different hash functions, Hash and Hash', may be used, which achieve all the properties of a cryptographic hash function. For example, Hash(x) and Hash'(x) may be instantiated as sha256(x) and sha256("prefix"+x), respectively, for any given "prefix" string. Thus, privacy of a traveler's health data on the health blockchain may be provided in an efficient manner.

[0024] According to an embodiment of the present invention, the traveler provides the doctor entity with the secret information and a zero-knowledge proof π for the secret information. n Therefore, the physician entity may provide the confidential information provided by the traveler. n , h n-1 To verify this, we use the zero-knowledge proof π n If the proof is correct, the doctor entity can use the secret information h to register a new health data record (i.e., the nth health data record for the traveler) on the health blockchain. n , h n-1 can be used.

[0025] According to an embodiment of the present invention, the secret information h n , h n-1 is the access key h n and the previous access key h n-1 Both keys may be used to register new health data records on the health blockchain, and the access key h n Hash H n may be used as a key in the health blockchain key-value store.n-1 hash H' n-1 may be used as a value to establish and deposit a link to a previous health data record in the health blockchain.

[0026] According to an embodiment of the present invention, the doctor entity uses the health blockchain to acquire the secret information h provided by the traveler. n , h n-1 has not already been used, thus supporting data integrity of the health data to be stored in the health blockchain.

[0027] According to an embodiment of the present invention, it may be provided that a multiplicative cyclic group G of prime order q with public generation operators g and h is used to share traveler health data on a health blockchain. The generation operators (such as g and h) in a cyclic group with operation * may be elements that have the property that, when subsequently applying a group operation to itself, iterates over all elements of the group. In other words, every element of the group may be represented using the generation operator (i.e., g or h) and the number of times that operation * should be performed (i.e., g 1,2,3,... or h 1,2,3,... ) The traveler's private key x is a random

number

number

number

number

number

[0028] According to an embodiment of the present invention, the confidential information (h) provided by the traveler to the physician entity n , h n-1 ) consists of the following steps: -By travelers

number

number

number

[0029] therefore,

number

[0030] According to an embodiment of the present invention, the health blockchain may receive a registration transaction from a physician entity to add a new health data record for a traveler to the health blockchain. The registration transaction may include a hashed access key, a hashed previous key, and health data information. Thus, it may be provided that the new health data record is stored against the hashed access key, and the hashed previous key and health data information are stored as values for the new health data record in the health blockchain's key-value store. Thus, secure and privacy-preserving handling of the traveler's health data may be provided.

[0031] According to an embodiment of the present invention, it may be provided that the health data information includes a sample number used to identify a new health data record. Thus, for example, a laboratory entity may update a new health data record on the health blockchain. Specifically, for example, upon receiving an update transaction from the laboratory entity, the new health data record on the health blockchain may be updated to include updated health data information related to the hashed access key with which the health data record is associated. In this regard, a suitable workflow may be performed as follows: The doctor can then take a sample from the patient, i.e., from the traveller, - Traveler samples are recorded on the health blockchain using confidential information provided by the traveler and pre-verified, - The traveller's sample is sent to a laboratory, i.e., a laboratory entity, for analysis; -The laboratory will update the traveler's health data record and add the traveler's test results.

[0032] According to embodiments of the present invention, the traveler's health data information and / or the traveler's updated health data information may include information related to the traveler's health data. For example, the health data information may include general medical health test results, such as virus test results, vaccination information, and / or information related to viral infections, viral colds, etc.

[0033] According to embodiments of the present invention, a security blockchain may verify that a traveler's health data meets a predetermined policy setting. For example, a national health authority may determine a policy for mandatory testing for travelers. Thus, according to embodiments, a blockchain smart contract may use the test output (i.e., the traveler's health data) obtained for each access key from the health blockchain to ensure that the traveler has performed all mandatory testing and apply the policy of the country of arrival. If the traveler's testing matches the policy, the traveler is considered healthy and free of infection.

[0034] According to an embodiment of the present invention, it may be provided that the sequential access keys provided by the traveler, together with the associated health data records, represent a time frame. Thus, the sequential access keys represent a list of access keys that are exhaustive and sequential. Furthermore, this list of access keys (together with the associated health data records) may represent the time frame to which information in the health data records (such as test results) refers. Thus, the traveler may effectively create proof that all of the traveler's tests were performed over a particular period of time.

[0035] According to an embodiment of the present invention, it may be provided that the physician entity verifies the credential information provided by the traveler using the global identity blockchain to authenticate the traveler at the physician entity.

[0036] At least one embodiment of the present invention may take into account the following characteristics. -To achieve a reliable chain of events with no leakage between events, we utilize zero-knowledge proofs in combination with hash chains in the blockchain to achieve range queries in O(log(n)). -Insert an empty health data record for each query, commit that record in the hash chain, and include it in the zero-knowledge proof to prove the "freshness" of the proof.

[0037] Embodiments of the present invention may enable selected range queries to be performed in a privacy-preserving manner from the blockchain, which may guarantee continuous responses over a defined period of time without any gaps in knowledge or any omissions of intermittent records.

[0038] Because traveler health certificates contain sensitive data about end users, embodiments of the present invention should provide each user with self-sovereign control of this data. Furthermore, because these health certificates need to be trusted by many different governments, a trusted, decentralized platform is required, and thus the use of blockchain is sought, which meets all previous requirements. An additional requirement in embodiments is a high level of privacy for users, since end users should not be allowed to cheat, and a high degree of security for entities requesting information. Indeed, since no test has 100% accuracy, a sick person should not be able to perform as many tests as possible until one test is false negative and then present only this one test. To this end, end users are forced to present all consecutive tests during a given period, effectively providing an authenticated range query during the given period.

[0039] According to embodiments, the above challenges may be addressed by using blockchain technology and introducing a novel zero-knowledge proof procedure. To illustrate such embodiments, this applies, for example, to the CoVID-19 testing process and how these results may be shared.

[0040] Thus, embodiments of the present invention describe a privacy-preserving solution that uses zero-knowledge proofs to enable range queries over unlinkable, continuous data stored on a blockchain. The output of this range query is proven to be continuous (undroppable) and up-to-date. Embodiments of the present invention may be particularly useful in the context of digital health passports in safe travel systems that require travelers to share test data to ensure they are infection-free or their vaccinations are up-to-date.

[0041] Personal health information is highly private and, until now, has only been shared with a highly selective and trusted group of people in the current state of the art. Embodiments of the present invention enter a new paradigm in which society and individuals need to share such data with a broader group of participants to ensure a safe and secure travel and work environment. This broader group may be authorities, companies, or transaction parties. In a post-pandemic world, it will become commonplace for individuals to carry their health information along with their identifying information. As a result, many existing processes will require some modification and digitization and become part of safety protocols in public places and while traveling. Some examples of new types of health data that will be shared include: i) test results for viral and contagious diseases; ii) personal health data for identifying high-risk individuals; and iii) vaccination history. Managing these new forms of digital health data and ensuring privacy and authenticity poses unique challenges. Embodiments of the present invention have identified that blockchain technology, combined with novel encryption methods, offers unique advantages. The embodiments may be applied to sharing any form of health data; for example, to demonstrate an exemplary solution, we will focus on the COVID-19 virus testing process. In this process, incoming passengers submit proof of their current health status, which is verified by health authorities or immigration authorities. To achieve this in a trustworthy manner, a blockchain-based solution is proposed that allows doctors in each country to securely and privately record medical test results on the blockchain. In a second step, when traveling to a country, each passenger can reveal that the last tests they performed were all negative. To be trustworthy, the solution must ensure that travelers / passengers always reveal their most recent tests and that passengers cannot omit some of their test results. The solution may also offer a high level of privacy for end users.An embodiment of the present invention may be an updated blockchain architecture to a blockchain-based seamless air travel system (disclosed in the applicant's not-yet-published PCT / EP2020 / 055478 and PCT / EP2020 / 055479, the contents of which are incorporated herein by reference in their entireties), and may provide users with a high degree of privacy and security through a novel zero-knowledge proof structure. PCT / EP2020 / 055478 and PCT / EP2020 / 055479 disclose a seamless air travel system in which passengers can choose to make their entire travel history public, or not to make their travel history public at all.

[0042] According to embodiments of the present invention, the security blockchain may do one or more of the following for each traveler in the corresponding travel segment: -The security blockchain sends the traveler a request to share the most recent t tests they have performed (where t is the number of tests mandated by the country / region's health authority). -Blockchain has inspection access key h n-t , ..., h n+t and the proof of correctness π. -A smart contract on the blockchain verifies the proof π and, if correct, continues processing the traveler. -Then the smart contract executes Hash(h n-t ), ..., Hash(h n+1 ) n-t , ..., H n+1 Given, we obtain the output of the health blockchain. -The security blockchain smart contract uses this output to further verify the validity of the provided key to ensure that the traveler has not skipped any checks. -A smart contract on the security blockchain uses the test output for each key to ensure that the traveller has performed all mandatory tests and enforces the policies of the country of arrival. If all steps are performed correctly and the traveler's test is consistent with policy, the traveler is considered healthy and free of infection.

[0043] There are several ways to advantageously design and further develop the teaching of the present invention. For this purpose, reference should be made on the one hand to the patent claims dependent on patent claim 1 and on the other hand to the following description of an embodiment of the invention shown by way of example in the figures. In connection with the description of an embodiment of the invention with the aid of the figures, general embodiments and further developments of the teaching are explained. [Brief explanation of the drawings]

[0044] [Figure 1] FIG. 1 is a schematic diagram illustrating the workflow of a method according to an embodiment of the present invention. [Figure 2] FIG. 1 is a schematic diagram illustrating a zero-knowledge proof workflow of a method according to an embodiment of the present invention; [Figure 3] FIG. 1 is a schematic diagram illustrating a workflow for sharing traveler health data, according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0045] FIG. 1 shows a schematic diagram illustrating the high-level workflow of a method according to an embodiment of the present invention.

[0046] In this embodiment, we assume that a set of government agencies have already created and are using a blockchain-based seamless travel system. This system (which is a distributed ledger system) may have two different types of blockchains: one unique "global identity blockchain" used to provide self-sovereign identity for all travelers, and multiple "security blockchains" per flight segment used to record all information required for the successful processing of a flight segment. The security blockchain may also include immigration authorities in the arrival country to provide pre-approved entry and facilitate traveler processing.

[0047] Embodiments further augment this by adding a new type of blockchain: a national "health blockchain" used to record the results of different medical tests in each country. The health blockchain may include the country's primary health agency, as well as the government's health department and ultimately the laboratories approved to perform the tests. The government's health department may be the department that approves laboratories and doctors (i.e., physician entities) on the blockchain. Each licensed doctor / physician may also be registered on the health blockchain without having a full node. The arrival government's national health agency is further required to join this health blockchain in order to add the health passport to the per-segment security chain. Each government can then issue regulations on the mandatory amount of testing and the time frame for it. For example, a country may require three negative tests in the two weeks prior to arrival, with one of them being performed no later than 48 hours before departure. Automating this check may then be done using smart contracts, ensuring that all travelers / passengers on a flight validate their requests.

[0048] In the following, we first describe the architecture of seamless travel based on blockchain, followed by a detailed architecture of a further developed embodiment regarding an added health blockchain.

[0049] Seamless Travel System In a seamless travel system, the following minimal entities / actors are considered: -Immigration authorities of various countries -Security offices at each airport -Airlines -Travelers (external entities / actors)

[0050] All of these entities / actors are registered and authenticated on the global identity blockchain. Full entities / actors (the first three categories) who own full nodes in the blockchain system may be distinguished from external entities / actors who are only registered and can transact on the system as external parties without full access. The global identity blockchain is used as a registry to authenticate any of the entities / actors in all subsequent steps. Authentication is done through a certificate-based system. Additional entities / actors may be freely added depending on requirements. The bootstrap phase is expected to automatically register public actors (all actors / entities except travelers). Travelers may then register on a per-use basis. A system is required to ensure that each traveler registers at most once. This may be achieved through an identity-based cryptography system that uses some personal data as a reference string, or by using a national (centralized) global registry managed by the state (i.e., the Census Bureau). Upon registration, the traveler's identity may be verified using the traveler's passport to ensure correct identity. The global identity blockchain then registers each traveler's public key y=g x and stores only the hash of that document. A security blockchain for each segment is also created, which may comprise at least five entities for international flights (however, three entities may be sufficient domestically): the departure and arrival airports, the departure and arrival immigration offices, and finally the airline that performs the segment flight.

[0051] Once a traveler decides to travel, an entity may be added in the appropriate per-segment security blockchain, which records every step of the flight journey, including check-in, foreign pre-approval for entry, and baggage drop-off, until departure from the destination airport. Foreign pre-approval for entry eases handling of travelers upon departure, as airlines may be assured that travelers have all the correct documentation (visas, etc.). All of this process may be governed by a smart contract that prevents passengers from appearing if the destination country denies entry.

[0052] Health Blockchain Here, a health blockchain is introduced which is added to a seamless travel system and involves the following entities / actors, namely: -Government Health Department -Government-approved testing laboratory - Health institutions (external entities / actors) -Doctor (external entity / actor) will also be added to the global identity blockchain.

[0053] The role of government health departments may be to issue official regulations regarding requirements for direct entry into the global identity blockchain. Len(tests.since(today-14days))≧3 AND Len(tests.since(today-48hours))≧1 AND tests.All=negative It can take the form of any logical expression such as

[0054] It requires at least three tests in the past two weeks, one of which must be in the past 48 hours, and all tests must be negative. For example, these regulations may then be automated and directly enforced at the framework layer within the segmented security blockchain to ensure proper handling of travelers. Approved laboratories may be the only entities permitted to insert test result values, and doctors and health organizations are the only entities permitted to collect samples.

[0055] To ensure traveler privacy, embodiments of the present invention may introduce the following high-level scheme for registering new health data records in the health blockchain: The high-level steps for a traveler according to embodiments of the present invention may be as follows, as shown in Figure 1: 1. Traveler authentication at the medical clinic. 2. The doctor verifies the traveler's credentials with the help of the global identity blockchain. 3. The traveler then submits the proof of authenticity. n together with an access key h as (additional) secret information used to register the traveler's results in the health blockchain. n , h n-1 Confidential Information is provided to <h n ,h n-1 > may be decomposed into 4. Doctors can use health blockchain to prove their n is correct and the access key h n , h n-1 is not already in use. 5. The doctor can then take a sample from the traveller / patient. 6. The sample is generated using a traveler-provided and pre-verified access key h n Hash H n will be recorded on the health blockchain using 7. The sample is sent to a laboratory for analysis. 8. The testing station will update the traveller's record and add the test results.

[0056] All of steps 1 through 4 may be performed prior to the appointment via a mobile application service. The results stored on the health blockchain may be very brief, such as "virus test positive / negative," but the full test results will still be provided to the patient's doctor.

[0057] In this setting, the data stored on the health blockchain is: -Safety: You cannot claim another traveler's test as your own - Privacy protection: Outside parties should not be able to determine to whom inspection records belong. -Complete: Travelers should not be able to selectively disclose the tests they want to share, or malicious travelers may try to disclose only false-positive tests. It is important that

[0058] 2 shows a schematic diagram illustrating the workflow of zero-knowledge proof for a method according to an embodiment of the present invention. To achieve the aforementioned requirements for setting up the high-level scheme shown by FIG. 1, an embodiment of the present invention may use a novel zero-knowledge proof configuration, which is detailed as follows:

[0059] A hypothetical model according to an embodiment may consider a multiplicative cyclic group G of prime order q with generating operators g and h, where q is a large prime number. A generating operator g in a cyclic group with operation * is an element that has the property that, when subsequently applying a group operation to itself, it repeats all elements of the group. In other words, all elements of the group may be represented using the generating operator (i.e., g) and the number of times the operation * should be performed (i.e., g 1,2,3,...). Two different hash functions, Hash and Hash', are further utilized that achieve all the properties of a cryptographic hash function. For example, Hash(x) and Hash'(x) may be instantiated as sha256(x) and sha256("prefix"+x), respectively, for any given "prefix" string. For simplicity, the notation Hash and Hash' will be used below.

[0060] The traveler's private key x is

number

[0061] The hashed secret used in the blockchain, i.e., the hashed access key, actually consists of two parts: one hashed access key H that is used when inserting a health data record in the health blockchain (steps 6 and 8 of the high-level scheme shown in Figure 1) and one n and the hashed previous access key H' n-1 Therefore, the hashed secret information is <H n ,H' n-1 > may be decomposed into

[0062] To generate a hashed access key, a traveler first generates an access key h given the traveler's private key x. n , h n-1 of

number

number

number

number

number

[0063] The workflow of the zero-knowledge proof shown in the embodiment of FIG. 2 may be specified as follows: 1. The traveler first calculates the value h n and h n-1 Generate the access key. 2. Travelers use the access key h n , h n-1 to the physician entity. 3. Upon receiving those values, the physician entity n-1 =Hash(h n-1 ) is already being used in health blockchains, and H n =Hash(h n ) is not already in use. For simplicity, this step is only shown in Figure 2. 4.The traveler then:

number

number

number

[0064] Access Key h n is unique for a given private key x, so that the doctor entity can n If it is assured that r is calculated correctly, the physician entity knows that the traveler is not trying to hide any data.

[0065] Adding the results to the health blockchain The doctor entity has access key h n , h n-1 Proof for π n Upon verifying this, the physician entity receives the hashed access key Hn ←Hash(h n ) and the previous access key H' n-1 ←Hash'(h n-1 ) and a sample number used by the laboratory entity to identify the record. The registration transaction may be performed as follows: -Additional recording transaction (sent to health blockchain) <H n ,H' n-1 ,sampleNumber,timestamp,sig> where sig represents the signature over all previous fields using the private key of the physician entity to prove authenticity and integrity. n Use as the key, <H' n-1 ,sampleNumber,timestamp> is stored in the blockchain key-value store using the value. The timestamp may be optional. The timestamp may include time information that may be used to record when the traveler / patient sample was taken. Thus, the timestamp may include time information that may be used to record when a test or vaccination was administered.

[0066] Therefore, health blockchain is a <H n ,H' n-1 ,sampleNumber,sig> new sample of the traveler and pass it to the hashed access key H n can be stored for

[0067] Once the laboratory entity has the results from the test, it can perform an update transaction as follows: -Update record transaction (sent to health blockchain) <sampleNumber,TEST_RESULT,sig> where TEST_RESULT is the result of the virus test and sig is a signature over the previous fields using the private key of the testing lab entity. The final record is generated using H n (which is the hashed access key) and the matching value is <H' n-1 ,TEST_RESULT>.

[0068] Therefore, health blockchain is a<sampleNumber,TEST_RESULT,sig> Receive updates to the key H n Records regarding H n → <H' n-1 ,TEST_RESULT,timestamp>.

[0069] FIG. 3 shows a schematic diagram illustrating a workflow for sharing traveler health data according to an embodiment of the present invention.

[0070] Prove you're healthy For example, a traveler may be assumed to have performed three tests in the past two weeks, one of which was performed in the last 48 hours prior to the traveler's flight departure. When the traveler checks in, for example, using a mobile application on their smartphone, the traveler receives a request to share health data, which may be performed as follows:

[0071] To share health data information, a user may go through the following steps according to the embodiment shown in FIG. 1. A traveler first generates all access keys and the proofs necessary to verify those keys. It is performed as follows, assuming that the traveler must reveal information about the last t tests, which may correspond to the traveler's last t health data records stored in the health blockchain: I. Access Key

number

number

number

number

[0072] An advantage of embodiments of the present invention is that it is computationally infeasible for a client to forge a false health document because the digital signature cryptography used in this embodiment is expected to remain secure. Additionally, the arrival government is assured that the traveler has all up-to-date testing or health data records and has not obscured any testing or health data that is unfavorable to the traveler.

[0073] Furthermore, embodiments of the present invention provide complete privacy of end users to third parties, as they cannot extract any information from the health blockchain.

[0074] The embodiment illustrated by Figure 3 details how the solution can be used to share virus test results in a privacy-preserving manner over a defined period of time without the possibility of omitting any results. However, this methodology can also be used to share any type of health data, such as viral cold tests, vaccination history, or general medical health results. This can be easily done by simply assigning one generation operator per type of test (i.e., generation operator h is used for COVID-19 tests, generation operator i is used for cold tests, generation operator j is used for vaccination history, etc.). The system can then force each of those generation operators to obtain all the latest values. Then, in response to a document sharing request, the traveler must provide one attestation for each type of test required by the arrival country. Because the discrete logarithms of the generation operators are unknown, even if the traveler reveals all tests performed for a disease, the tests remain completely unlinkable.

[0075] Many modifications and other embodiments of the inventions set forth herein will come to mind to one skilled in the art to which these inventions pertain having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. It is to be understood, therefore, that the invention is not to be limited to the specific embodiments disclosed, and that modifications and other embodiments are intended to be included within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

1. 1. A method for supporting the sharing of digital health data of travelers in a travel environment, wherein identities of the travelers are managed using a distributed ledger system, the distributed ledger system including a global identity blockchain, several security blockchains, and a health blockchain; the global identity blockchain is used as a registry to authenticate entities in the distributed ledger system; the security blockchain is used for a given travel segment such that the security blockchain is accessible by entities in the distributed ledger system involved in the given travel segment; The health blockchain is used to share the traveler's health data in a key-value store of the health blockchain, and health data records are stored against hashed access keys, and the health data records include hashed previous access keys and health data information; The method comprises: sending a request from the security blockchain to a traveler's computing device to share a predetermined number of health data records; receiving, via the security blockchain, from the computing device of the traveler, a sequential access key for the requested health data record and a zero-knowledge proof; verifying, by the security blockchain, the zero-knowledge proof received from the computing device of the traveler, wherein the zero-knowledge proof is used to verify the most recent of the access keys provided by the traveler; If the zero-knowledge proof is successfully verified, retrieving the health data record from the health blockchain by the security blockchain based on a hashed access key, where the hashed access key is generated from the access key provided by the traveler; verifying, via the security blockchain, the access key provided by the traveler using a hashed previous access key contained within the retrieved health data record to check whether the traveler provided the access key required for the health data record as requested; A method comprising:

2. 2. The method of claim 1, wherein a previous access key included as a hash within the traveler's health data record represents the access key for the traveler's previous health data record on the health blockchain.

3. 3. The method of claim 1 or 2, wherein a first hash function is used to calculate the hashed access key that is used as a key for a health data record in the key-value store of the health blockchain, and a second hash function is used to calculate a hashed previous access key that is stored as a value in a health data record in the key-value store of the health blockchain.

4. the computing device of the traveler providing secret information and a zero-knowledge proof for the secret information to a computing device of a physician entity; 4. The method of claim 1, wherein the zero-knowledge proof is used by the computing device of the physician entity to verify the secret information, and the secret information is used to register a new health data record on the health blockchain.

5. The method of claim 4 , wherein the secret information comprises an access key and a previous access key.

6. The method of claim 4 or 5, further comprising the step of the computing device of the physician entity verifying that the secret information is not already in use in the health blockchain.

7. A multiplicative cyclic group G of prime order q with public generation operators g and h is used to share the traveler's health data on the health blockchain; The traveler's private key x is a random [Equation 1] and the traveler's public key is chosen as y=g x and [Equation 2] is the multiplicative group of integers relatively prime to q, the computing device of the traveler tracks a variable n that refers to the total number of health data records of the traveler; The computing device of the traveler obtains the access key for the nth health data record based on the traveler's private key x. [Equation 3] and calculate the previous access key as [Equation 4] Calculate as, 7. The method according to any one of claims 4 to 6.

8. The zero-knowledge proof for the secret information provided by the computing device of the traveler to the computing device of the physician entity comprises: by the computing device of the traveler; [Equation 5] r drawn uniformly at random from 1 , r 2 Using Commitment [Equation 6] generating a The traveler's computing device receives the commitment t h , t g , and t k to the computing device of the physician entity; The computing device of the physician entity receives a challenge C 1 , C 2 to the computing device of the traveler, wherein the computing device of the physician entity: [Equation 7] The challenge C is drawn uniformly at random from 1 and C 2 generating a Response s by the traveler's computing device 1 , s 2 to the computing device of the physician entity, wherein the computing device of the traveler receives the response s 1 , s 2 s 1 =r 1 +c 1 *x and [Equation 8] and generate it as [Equation 9] but [Equation 10] is equal to [0011] but [0012] is equal to [0013] but [0014] if equal to, the computing device of the physician entity accepts the zero-knowledge proof; 8. The method of claim 7, comprising:

9. The health blockchain further includes receiving, from the computing device of the physician entity, a registration transaction for adding a new health data record of the traveler to the health blockchain; the registration transaction includes a hashed access key, a hashed previous key, and health data information; the new data record is stored against the hashed access key; 9. The method of claim 4, wherein the hashed previous key and the health data information are stored as values of the new health data record in the key-value store of the health blockchain.

10. 10. The method of claim 9, wherein the health data information includes a sample number used by a computing device of a laboratory entity to identify the new health data record, and upon receiving an update transaction from the computing device of the laboratory entity, the new health data record on the health blockchain is updated such that the health data record includes updated health data information.

11. 11. The method of claim 9 or 10, wherein the health data information comprises information relating to the traveller's health data, in particular virus test results, vaccination information, and / or medical health test results.

12. 12. The method of claim 1, further comprising verifying, by the security blockchain, that the traveler's health data meets predetermined policy settings.

13. 13. The method of claim 1, wherein the successive access keys provided by the traveler represent a time frame together with associated health data records.

14. 14. The method of claim 1, further comprising: a computing device of a physician entity verifying credential information provided by the traveler using the global identity blockchain to authenticate the traveler at the computing device of the physician entity.

15. A distributed ledger system for supporting the sharing of digital health data of travelers in a travel environment, in particular for carrying out the method according to any one of claims 1 to 14, said distributed ledger system comprising a global identity blockchain, several security blockchains and a health blockchain, the global identity blockchain is used as a registry to authenticate entities in the distributed ledger system; the security blockchain is used for a given travel segment such that the security blockchain is accessible by entities in the distributed ledger system involved in the given travel segment; The health blockchain is used to share the traveler's health data in a key-value store of the health blockchain, and health data records are stored against hashed access keys, and the health data records include hashed previous access keys and health data information; the security blockchain is configured to send a request to a traveler's computing device to share a predetermined number of health data records; the security blockchain is configured to receive, from the traveler's computing device, a sequential access key for the requested health data record and a zero-knowledge proof; the security blockchain is configured to verify the zero-knowledge proof received from the computing device of the traveler, and the zero-knowledge proof is used to verify a most recent one of the access keys provided by the traveler; If the verification of the zero-knowledge proof is successful, the security blockchain is configured to retrieve the health data record from the health blockchain based on a hashed access key, the hashed access key being generated from the access key provided by the traveler; the security blockchain is configured to verify the access key provided by the traveler using a hashed previous access key contained within the retrieved health data record to check whether the traveler provided the access key required for the health data record as requested; Distributed ledger system.

Citation Information

Patent Citations

  • Identity management service using blockchain

    JP2018516030A

  • Data management system and data management application

    JP2019153130A

  • Distributed data management system and program therefor

    JP2020129760A

  • Protection of confidentiality, privacy and ownership assurance in a blockchain based decentralized identity management system

    US20190165943A1

  • Method for supporting sharing of travel history of travelers in airports

    WO2021175409A1