SELECTIVE STABLE STATE TRANSITION OF PARTIALLY CONFLICTING OFFLINE DIGITAL VALUE OBJECTS. PRUNING AND CANONICAL LOCAL RESTRUCTURING METHOD AND SYSTEM
Patent Information
- Application Number
- TR202613261
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-08-05
- Publication Date
- 2026-08-21
Smart Images

Figure 00000026_0000 
Figure 00000027_0000 
Figure 00000028_0000
Abstract
Description
1 TARIFF SELECTIVE STABLE STATE TRANSITION OF PARTIALLY CONFLICTING OFFLINE DIGITAL VALUE OBJECTS. PRUNING AND CANONICAL LOCAL RESTRUCTURING METHOD AND SYSTEM Technical Area 5 The invention relates to secure electronic transaction systems and tamper-resistant secure transaction elements. offline digital value transfer between devices, cryptographic digital value objects, double spending, and resolving derivation mismatches, safe state management in limited hardware memory, and It relates to the areas of conflict-free digital asset protection after the connection is re-established. Invention Specifically, only one 10 of a digital value object previously transferred offline If the section becomes conflicting, instead of canceling the entire object... the conversion of the conflict-free section into new canonical objects within the secure processing element provides. State of the Art In offline digital value systems, security generally depends on the balance or 15 in the secure transaction element. Transaction limit setting, key deletion ensuring the digital value object can only be used once. or counter mechanisms, representing divisible value objects with a tree or scope structure. and when the connection is re-established, a central reconciliation of duplicate spending records This is ensured through determination within the unit. In known solutions, when incompatible operations derived from the same root are detected, the value is usually 20. The entire object, the associated wallet, or a broad value family is invalidated; conflict-free. New objects must be re-issued by the central unit so that the value can be reused. This requires verification or real-time transaction confirmation. An object can only have a specific value. If the domain is conflicting, the limited-resource secure transaction element of the non-conflicting complement. its deterministic reconstruction within, the old object and the new objects together 25 prevention of unauthorized use and offline authorization capacity The requirements for non-reproduction are not being adequately met. The Technical Problem That the Invention Aims to Solve The technical problem that the invention aims to solve is, in part, a conflicting offline digital value. while preventing the reuse of the conflicting part of the object, the non-conflicting part, agreement 30 additional real-time communication with the node and centralized re-export for each remaining piece. 2 without requiring, a secure, deterministic and resource-limited processing element within a secure processing unit. The goal is to make it available in a way that is resistant to interruptions. Purpose and General Description of the Invention The primary purpose of the invention is to extend the quarantine scope specified in a signed overlapping section certificate to local 5 Selectively removing the digital value object from its scope creates a conflict-free residual space that is deterministic. separating into canonical sub-scopes, digital recovery in the secure processing element for each sub-scope creating value objects, relating to the amount of digital value and offline authorization capacity. to verify separate preservation conditions and simultaneously process the old object and the salvaged object. It is about performing a permanent state transition that prevents it from remaining usable. 10 Another objective is to ensure the safe processing element recovers all memory or object socket resources. If it is not sufficient to hold its objects, a conflict-free but not yet activated value field. to protect under a non-expendable deferred recovery commitment and then the old object The goal is to enable recovery from reactivation. Brief Description of Figures 15 Figure 1 shows the general architecture of the digital value transfer and consensus system. Figure 2 shows the functional units of the secure transaction element. Figure 3 shows an example data structure of a digital value object. Figure 4 shows an example data structure of a collision section certificate. Figure 5: Identification of incompatible derivation records in the reconciliation node and certificate 20 It shows the process of its creation. Figure 6 shows the non-intersecting, full coverage, and partial coverage scenarios. Figure 7: Conversion of a conflict-free residual field into a binary prefix-based canonical scope set. It shows. Figure 8: Shows the flow of creating local selective pruning and recovery objects. 25 Figure 9: Digital value and offline authorization capacity protection controls. It shows. Figure 10 shows the interrupt-tolerant steady-state transition. Figure 11: Establishing resource-limited recovery and deferred recovery commitments. It shows. 30 Figure 12 shows the end-to-end offline transaction, reconciliation, and local recovery message sequence. 3 Reference Marks No. Element No. Element 100 Digital value transfer and reconciliation system 110 Secure transaction element 111 Secure processor 112 Protected persistent memory 113 Cryptographic validation unit 114 Value scope processing unit 115 Canonicalization Unit 116 Permanent State Transition Manager 117 Monotonic period counter 118 Authorization capacity manager 119 Secure communication interface 120 Main device 130 Reconciliation node 131 Derivation record receiver 132 Root commitment grouping unit 133 Causality verification unit 134 Incompatibility detection unit 135 Overlap section calculation unit 136 Canonical quarantine scope producers 137 Certificate production units 138 Evidence commitment repository 139 Certificate signing unit 140 Counterparty processing device 150 Communication network 160 Certificate distribution channel 170 Primary digital value object 171 Root object commitment 172 Proof of derivation 173 Value coverage identifier 174 Digital value quantity 175 Valuation matching rule 176 Offline authorization capacity 177 Object status indicator 178 Protocol version 179 Integrity verification data 180 Collision section certificate 181 Certificate type 182 Root object commitment in certificate 183 Certificate period 184 Certificate protocol version 185 Quarantine scope descriptors set 186 Inconsistent derivation records as evidence commitment 187 Capacity and recovery policy identifier 188 Certificate issuer identifier 189 Certificate digital signature 190 Recovery digital value object 191 Scope identifier 192 Amount of digital value recovered 193 Assigned authorization capacity 194 Updated proof of derivation 195 Previous object link commitment 196 Recovery object status indicator 200 Deferred recovery commitment 201 Deferred scope set commitment 202 Amount of deferred digital value 203 Deferred authorization capacity 204 Linked certificate period 205 Delayed recovery status indicator 210 Permanent reconfiguration log 211 Preparation log 212 Old object consumption mark 213 Completion record 214 Post-interruption recovery signal 4 Detailed Description of the Invention
[0001] The invention relates to the management of offline transferable digital value objects, and in particular to a digital only a specific portion of the value space represented by the value object becomes conflicting In this case, selective removal of the conflicting part and safe processing of the non-conflicting part 5 It relates to converting elements into reusable objects within the system.
[0002] The digital value transfer and reconciliation system (100) shown in Figure 1 has at least one secure Processing element (110), a master containing or communicating with the said secure processing element. device (120), a reconciliation node (130), optionally a counterparty transaction device (140), a It includes a communication network (150) and a certificate distribution channel (160). 10
[0003] Main device (120); mobile communication device, payment terminal, smart card reader, wearable electronic device, transportation card, portable security key, vehicle control unit, charging controller module, in the form of an industrial machine control unit or internet of things device applicable.
[0004] Secure transaction element (110); embedded secure element, smart card chip, SIM or eSIM 15 The security section provides secure hardware that works in conjunction with a trusted execution environment, preventing tampering. in the form of a rugged microcontroller, secure access module, or hardware security module applicable.
[0005] The expression “offline” or “connection-free operation” refers to the reconciliation of the secure transaction element. 20 without transaction-based real-time confirmation from the node regarding a digital value object a study that can perform verification, transfer, storage or reconstruction operations It describes the situation.
[0006] Offline operation means the device has no communication capability. It won't arrive. The secure transaction element can connect to the reconciliation node at specific times, certificate. You can receive, send, or synchronize status. 25
[0007] Certificate distribution channel (160), overlap section certificate (180) direct reconciliation from a node or an intermediate terminal, peer device, access point, physical transmission medium or It can be transmitted to the secure processing element via the delayed message repository.
[0008] As shown in Figure 2, the secure transaction element (110) is a secure processor (111), protected permanent memory (112), cryptographic verification unit (113), value scope processing unit (114), 30 canonicalization unit (115), permanent state transition manager (116), at least one monotonic period It includes the counter (117), authorization capacity manager (118) and secure communication interface (119).
[0009] The mentioned units can be implemented as separate hardware blocks or as a secure processor (111) secure software modules, microprograms or combinations thereof executed by It can also be implemented in this way.
[0010] Protected persistent memory (112), main processor or operating system outside the secure processing element 5 a memory that cannot be directly modified by the system and retains its contents when the power is cut off It is the field.
[0011] Digital value objects in protected permanent memory (170), accepted certificate periods, reconfiguration log records (210), authorization capacity information and security Policies can be kept secret. 10
[0012] Cryptographic verification unit (113), digital signature, message verification code, commitment decryption, It is structured to verify proof of membership, proof of descent, or a combination thereof.
[0013] Value scope processing unit (114), intersection, union, difference, base of scopes It performs operations that determine the relationship, overlap, and separation of the elements.
[0014] The canonicalization unit (115) canonicalizes a specific value space, under the same protocol version, the same 15 It converts the resulting sequence into non-overlapping scope descriptors.
[0015] Persistent state transition manager (116), recovery by invalidating the previous object the activation of objects, the same old and new objects after power or process interruption It manages it in a way that prevents it from becoming disposable at the moment. This application is in a stable state. transition; power outage, process interruption, restart or 20 of the same reconfiguration process If executed again, the old digital value object and the salvaged digital value generated from it... the simultaneous availability of objects and their total digital value or offline The situation is dependent on protected persistent status records, which prevents the increase of authorization capacity. It signifies a transition.
[0016] The digital value object (170) shown in Figure 3 is the 25 of the secure transaction element. enabling the generation of a transfer or usage authorization based on the object It is a verifiable electronic data structure.
[0017] Digital value object (170), at least one root object commitment (171), proof of derivation (172), value coverage identifier (173), digital value amount (174), valuation matching rule (175), Offline authorization capacity (176), object status indicator (177), protocol version (178) 30 and includes integrity verification data (179). 6
[0018] Root object commitment (171) defines the root value family from which the digital value object is derived. Root object commitment, a hash value, cryptographic commit, Merkle root, export record identifier. or in the form of a signed root reference.
[0019] Proof of derivation (172) is that the digital value object is one or 5 allowed from the root object in question. This confirms that it was obtained as a result of further transformations.
[0020] Proof of inheritance; Merkle path, parent commitment chain, signed parent linkage, cryptographic accumulator proof of membership, one-way key derivation proof, or a combination thereof. may include.
[0021] Value scope descriptor (173), which 10 in the root value space of the digital value object It states that it represents atomic value units.
[0022] Value scope identifier; one or more numeric ranges, binary prefixes, tree nodes reference, bit mask, Merkle subtree root, or verifiable cluster membership in the form of applicable.
[0023] The amount of digital value (174) indicates the total value represented by the object. Digital value 15 The amount can be a monetary sum, or it can be a usage loan, energy right, transportation right, or service unit. or it could be another divisible electronic right.
[0024] The valuation matching rule (175) represents the atomic value coverage descriptor. It determines the deterministic relationship between units and the amount of digital value.
[0025] In an application, each atomic unit has the same value. For example, 1.024 atomic units = 20 An object containing these could be worth 1,024 TL, with each atomic unit representing 1 TL.
[0026] In another application, the weights of the atomic value units are different from each other. This In this case, the valuation mapping rule uses a weight that is cryptographically bound to the root object commitment. It may include a table or a verifiable value function.
[0027] Offline authorization capacity (176), kept separate from the amount of digital value and secure 25 transfer or reconfiguration that the processing element can create in a disconnected environment It is a technical resource that limits its authority.
[0028] Offline authorization capacity is another representation of the monetary value of the object. No. Two objects carrying the same amount of digital value have different offline authorization requirements. They may have the capacity. 30
[0029] Object status indicator (177); active, prepared for reconfiguration, locally It can represent quarantined, invalidated, postponed, or recovered statuses. 7
[0030] The active state is a valid expenditure, usage of the secure transaction element based on the object. or the situation where it allows the generation of transmission verification data.
[0031] Invalidated status, a new expenditure of the secure transaction element based on the object, This is the situation where it refuses to generate usage or transfer verification data. 5
[0032] The overlap section certificate (180) shown in Figure 4 is based on the same root object commitment. The quarantine value area for a detected conflict is transferred to the secure transaction element. It is a signed data structure that ensures verifiable transmission. Conflict; causally. Comparing inconsistent derivation records, a verified system state mismatch, or 10 based on another verifiable collision record accepted by the consensus node It can be determined.
[0033] Collision section certificate (180), at least certificate type (181), root object in certificate commitment (182), certificate period (183), certificate protocol version (184), one or more Scope set including quarantine scope descriptor (185), commitment to evidence (186), rescue It may include a policy identifier (187), a regulatory identifier (188) and a digital signature (189). 15
[0034] Certificate period (183), reuse of an older certificate or a newer one It is used to reduce the risk of the disputed situation being changed back to a previous situation.
[0035] Secure transaction element, certificate period monotonic period in protected memory. It compares it with its counter (117) and rejects the old certificate according to the security policy.
[0036] Certificate protocol version (184), interpretation of scope descriptors, 20 canonicalization order, valuation mapping rule, state transition rules, and authorization. It can determine capacity policy.
[0037] Commitment to evidence (186), explicit derivation records used in determining the conflict. cryptographic linking to those records without having to add their contents to the certificate. It provides. 25
[0038] Evidence commitment, dispute record hash combination, Merkle root, cryptographic This may be in the form of an accumulator value or a signed inspection record reference.
[0039] The certificate is designed to prevent other types of messages from being used as collision certificates. a field that includes certificate type, protocol field, network identifier, and protocol version It can be signed with the separation data. 30
[0040] Signed representation of the certificate, fixed order of fields, unique coding of numbers, a deterministic approach that determines the ordering of scopes and the removal of duplicate scopes It can be created using a coding rule. 8
[0041] The reconciliation node (130), the derivation record receiver (131), and the root commit shown in Figure 5. grouping unit (132), causality verification unit (133), inconsistency detection unit (134), overlap section calculation unit (135), canonical quarantine scope producer (136), certificate producer It may include unit (137), evidence commitment repository (138) and certificate signing unit (139). 5
[0042] Derivation record receiver (131), from one or more devices after offline operations It retrieves the reproduction records.
[0043] Each derivation record includes: root object commit, record identifier, parent derivation commit, Value scope identifier, object state transition proof, secure transaction element validation data, The other party may include a session commitment and registration signature. 10
[0044] Root commit grouping unit (132), records associated with the same root object commit are the same It places it in the analysis group.
[0045] Causality verification unit (133), valid parent-child relationship of two derivation records, same whether the valid branch is a successive process or whether the sister derivations do not overlap. determines. 15
[0046] The same scope of value can exist in a parent object and its valid child object A mere coincidence is not acceptable on its own. The causality verification unit is therefore the scope. In addition to comparison, it confirms the relationships between object consumption and derivation.
[0047] Incompatibility detection unit (134), records are linked to the same root, valid for each other The conditions of not having a causal continuation and the value scopes containing common atomic units are 20 If both occur simultaneously, it classifies the records as inconsistent.
[0048] Collision section calculation unit (135), value ranges for each mismatched record pair Calculates the intersection.
[0049] If there is more than one incompatible record pair, the calculated intersections are combined and A normalized quarantine value range is obtained. 25
[0050] Normalization is the process of combining overlapping scopes, repetitive This may include removing scopes and sorting scopes according to the protocol version.
[0051] The canonical quarantine scope generator (136) gives the normalized quarantine value space a or converts it into more quarantine scope descriptors.
[0052] Certificate production unit (137), the quarantine scope identifiers and 30 It creates a conflict section certificate that includes the evidentiary commitment of the records on which the dispute is based. 9
[0053] Certificate signing unit (139), certificate can be verified by secure transaction elements He / She signs with an authorized private key.
[0054] The reconciliation node creates recovery objects one by one or each recovery object It does not need to generate a separate transaction confirmation. The conflicting area is 5 in the secure transaction element. Provides the certificate that identifies it. Example of certificate generation flow described in paragraphs
[0041] –
[0053] . It is an application that involves selective pruning and canonical local re-processing in the secure transaction element. The configuration process is not tied to a specific certificate generation algorithm.
[0055] As shown in Figure 6 and Figure 8, the safe processing element has a collision section certificate. It verifies the signature, period, protocol version, and root object match. 10
[0056] If verification fails, the certificate is rejected and local re-application based on the certificate is initiated. No configuration is performed.
[0057] When validation is successful, the value scope processing unit (114) processes the local digital value. The value space S represented by the object is the combination of the quarantine scopes in the certificate, Q. It determines the intersection between them. 15
[0058] If there is no intersection between S and Q, the object is not affected by the certificate and security It is left in effect to the extent permitted by policy.
[0059] If the domain S is completely covered by the combination of quarantine domains Q The object is invalidated, and no recovery object is created for it.
[0060] If the intersection is not empty and the quarantine area does not encompass the entire value space of the object 20 The partial intersection condition is determined.
[0061] In the case of partial intersection, the conflict-free residual space R = S \ Q is determined by the set difference operation. It is calculated.
[0062] Determining the residual value field, new atomic value units belonging to the quarantine area Ensures that it is not represented in any of the recovery objects. 25
[0063] The canonicalization unit (115) shown in Figure 7 connects the residual value space with each other. non-overlapping and ordered residual scope descriptors whose unions are equal to the residual scope. It transforms.
[0064] Canonicalization function, same residual space, same root space size, same protocol It produces the same sequential scope set for the same version and the same security policy entries. 30
[0065] In an application, the residual value space is divided into complete subtree blocks represented by binary prefixes.
[0066] In the application in question, the most aligned to the beginning of an interval and not exceeding the end of the interval A block of size that is a power of two is selected, added to the output set, and the remaining space is processed. It is repeated.
[0067] Two adjacent scopes that are children of the same parent prefix, their combination is quarantine area 5 If they don't intersect, they can be combined under a single superscript.
[0068] In another implementation, the field is now represented by ordered and discrete numerical intervals. Another In practice, Merkle subtree roots or verifiable cluster memberships are used.
[0069] A recovery digital associated with the same root object commitment for each residual scope descriptor. The value object (190) is created. 10
[0070] Recovery digital value object; scope identifier (191), recovered digital value amount (192), allocated offline authorization capacity (193), updated derivation proof (194), previous object link commitment (195) and recovery object status indicator (196) may include.
[0071] Updated derivation proof, recovery object from previous object and verified 15 It indicates that it is derived from an authorized reconstruction process based on a collision section certificate.
[0072] The secure transaction element fully recovers each conflict-free atomic value unit from its objects. as a result of a delayed recovery in one of the cases or in a resource-limited restructuring it is represented in the commitment (200) and no quarantine atomic value unit recovery It confirms that it is not represented in the objects or deferred recovery commitment. 20
[0073] With the amount of digital value represented in the recovery objects, as shown in Figure 9, If any, the total amount of digital value represented in the deferred recovery commitment, former obtained by subtracting the value corresponding to the section intersecting with the quarantine area from the value of the object. It should be equal to the value obtained.
[0074] The valuation matching rule is 25 for determining the digital value of each scope part. This applies equally to both old and salvaged objects.
[0075] Authorization capacity manager (118), with the capacity allocated to recovery objects, if any, in the deferred recovery commitment, capacity held and restructuring process the total amount of consumed technical authorization allowance for the old object's available offline It confirms that it has not exceeded its authorization capacity. 30
[0076] Technical authorization share, number of recovery objects created, number of persistent memory writes, from parameters such as cryptographic verification count, derivation depth, or hardware security profile. It can be determined according to one or more factors. 11
[0077] Unused offline authorization capacity is permanent according to the signed security policy. It can be consumed as is, frozen locally, or only a currently authorized capacity can be restored. It can be made reusable with a certificate of achievement.
[0078] If any of the value and capacity checks fail, recovery objects 5 not enabled and secure operation element reconfiguration process is a secure error terminates in that case.
[0079] By invalidating the first digital value object (170) as shown in Figure 10. Enabling recovery of digital value objects (190), permanent reconstruction log This is carried out as part of a disruption-resistant state transition using (210). 10
[0080] Permanent reconfiguration log (210), at least one preparation log (211), an old object consumption mark (212), a completion record (213) and an optional after-failure recovery It contains the symbol (214).
[0081] Preparation record (211) contains a process identifier specific to the reconstruction process, first The integrity commitment regarding the digital asset is provided by the hash 15 of the implemented collision segment certificate. its value, commitments for the planned recovery of digital asset objects, recovery the total planned digital value amount and the total offline value planned to be allocated It includes authorization capacity.
[0082] Preparation record (211) recovery digital value before writing to protected permanent memory The items are not made expendable or transferable. 20
[0083] After the preparation record is written, the spending authorization of the first digital value object, The old object is invalidated by means of the consumption mark (212).
[0084] Old object consumption signal (212); one-way object status bit change, expenditure Secure deletion of the key, spending key evolution with one-way key evolution to a different one. at least 25 of the methods of switching to the current state or increasing the monotonic counter dependent on the object. It can be done with someone.
[0085] After the creation of the old object consumption sign (212) to the first digital value object Based on this, new transfer authorization data is generated by the secure transaction element. It will be rejected.
[0086] Recovery of digital value objects only with the protected permanent 30 of the old object consumption mark It is activated after verification in memory.
[0087] Completion record when activation of recovery digital value objects is complete. (213) is written to protected permanent memory. 12
[0088] Completion record (213), integrity of activated recovery digital value objects commitments, total recovered digital value, total allocated offline authorization It includes its capacity and the period of the completed state transition.
[0089] Permanent state transition, first digital value 5 after any power or operation interruption. The object and the digital value objects derived from it can be simultaneously spent or It prevents it from being in a transferable state.
[0090] Persistent state transition manager during safe operation element restart (116), by examining the permanent restructuring log (210), found an unfinished restructuring Determines whether a configuration process exists. 10
[0091] If preparation record (211) is not found, the secure transaction element is the first digital value It preserves the object's verified state prior to the operation.
[0092] In cases where the preparation record is present, but the old object consumption mark is missing. Temporary recovery objects are deleted or rendered inaccessible, and the primary digital value object... It is left in the active state. 15
[0093] Preparation record and old object consumption mark found, but completion record If it is not present, the secure transaction element will re-enter the first digital value object. It does not activate.
[0094] In the case specified in paragraph
[0093] , the secure transaction element is only in the preparation record. It recreates or completes the recovery of digital asset objects that have commitments. 20
[0095] If a completion record exists, the secure operation element, recovery objects compares it with the record of completing the integrity commitments and invalidates the first digital value object. It maintains its status.
[0096] Post-interruption recovery is idempotent; multiple instances of the same log records can be performed. Running it a second time does not generate any additional digital value objects or additional offline authorization capacity. 25
[0097] In an application, each reconfiguration operation is a monotonically increasing sequence of operations. a number is assigned and a previously completed transaction sequence number is re-executed. The secure transaction is rejected by the security agent.
[0098] The residual scope produced as a result of the canonicalization process is shown in Figure 11. The number of identifiers is the maximum number of objects that the secure transaction element can effectively hold, or 30 It may exceed the permanent memory capacity allocated for the operation. 13
[0099] The secure operation element canonical residual scope count, available object slot count, the projected number of persistent memory writes and the permitted techniques for the reconfiguration process. It compares the authorization share.
[0100] If it is not possible to convert all residual scopes into a recoverable digital value object 5 Only a specific portion of the scopes has a deterministic priority defined by the protocol version. It is selected according to the rule.
[0101] Deterministic priority rule; scopes representing the highest amount of digital value are prioritized. scopes with a short binary prefix, scopes with the lowest initial numerical value, or This may include prioritizing the selection of the scope class specified in the signed recovery policy. 10
[0102] Same input value space, same device resource status, same protocol version and same recovery This ensures that the same scopes are selected for the policy.
[0103] Recovery digital value objects (190) are created for selected scopes and unselected scopes Non-conflict scopes are not directly converted into expendable objects.
[0104] Unselected conflict-free scopes under a deferred recovery commitment (200) 15 It is protected cryptographically.
[0105] Partial conversion only of the safe processing element active object socket or persistent memory not due to a lack of resources; but a phased approach determined by a signed security policy. Activation, process prioritization, device power or process budget threshold, certificate scope. 20 A specific subset of linked temporary restriction or recovery objects must be enabled first It may also be carried out due to another protocol requirement. In these cases, recovery is digital. Delayed recovery commitment for conflict-free scopes not converted to value objects (200) It is protected underneath.
[0106] Deferred recovery commit (200), at least the root object commit, deferred scope set commitment (201), deferred digital value amount (202), deferred offline 25 authorization capacity (203), associated certificate period (204), protocol version and deferred Includes recovery status indicator (205).
[0107] Deferred scope commitment (201), unselected conflict-free scope A Merkle root that binds to all of its identifiers, hash-based ordered cluster commit, This can be in the form of a cryptographic accumulator value or a verifiable interval commitment. 30
[0108] Deferred recovery commitment, direct payment, transfer or expenditure authorization It cannot be used for production. 14
[0109] Establishing a deferred recovery commitment, unselected conflict-free value domains This prevents the loss of these value areas; however, sufficient resources or current authorities are not available for these value areas. It remains unspendable until the certificate is provided.
[0110] Deferred digital value amount, 5 not selected using valuation matching rule It is calculated from conflict-free atomic value units.
[0111] Delayed offline authorization capacity, according to the signed security policy. They can be kept frozen, awaiting recovery, or permanently consumed.
[0112] Delayed recovery when sufficient resources become available in the secure transaction element. The commitment can be reprocessed locally. 10
[0113] Enabling deferred recovery in an application by the consensus node A signed, current recovery activation certificate is required.
[0114] Delayed scopes during delayed recovery process more current quarantine It is checked whether their scopes intersect.
[0115] Delayed scopes not intersecting with the current quarantine area, canonicalization 15 With this function, the recovered digital values can be converted into physical objects.
[0116] The related recovery digital asset is not rendered exhausted before the deferred recovery commitment is exhausted. The objects are not rendered expendable.
[0117] Delayed recovery process, previously invalidated first digital value object It does not reactivate. 20
[0118] Secure transaction element, accepted for each root object commitment or certificate issuer domain. It can store the most recent certificate period in secure memory.
[0119] If the period of the received certificate is smaller than the most recent period stored, the certificate will be renewed. It is considered an attempt at manipulation and is therefore rejected.
[0120] If the period of the received certificate is the same as the stored period, but the certificate content is different, then it is secure 25 Processor certificates may indicate a racing or conflicting authorization situation.
[0121] In the case in paragraph
[0119] , the relevant digital value object is temporarily quarantined locally. can be obtained and reinstated until a higher-term dispute resolution certificate is received. Configuration may not be possible.
[0122] If the same certificate is obtained more than once, the certificate serial number and certificate hash 30 The value or transaction sequence number is used to determine if the certificate has been processed previously.
[0123] Reprocessing of the same certificate previously successfully applied, additional digital recovery It does not generate a value object or additional offline authorization capacity.
[0124] Certificate signature includes certificate type, protocol version, network domain, issuer identifier and By linking to the certificate period, messages configured for another protocol and network can be re-enabled. Area separation can be ensured against its use.
[0125] If the certificate issuer key is changed, the secure transaction element will be replaced with a new one. the key with a key pass certificate signed by the previous authorized key holder or It may require verification with a securely pre-installed trust root.
[0126] Certificate signature, period, root match, protocol version or scope encoding 10 If it cannot be verified, the secure transaction element will not apply the certificate and the existing digital value object will be removed. It does not create a new recovery object.
[0127] Secure transaction against certificates created by a forged or unauthorized regulator. The element is a regulator verified only by a registered or authorized key chain in the trust root. He accepts their keys. 15
[0128] Incorrect ordering or repetition of quarantine scope identifiers within the certificate, They are insecure if they conflict with each other or are coded in a way that does not conform to the protocol version. The processing element scopes can be normalized or the certificate can be modified according to the security policy. They can refuse.
[0129] Normalization is not performed before digital signature verification; signature, 20 It is verified on the canonical representation created by the regulator. Thus, the attacker's different This prevents the encoding from being interpreted as the same content.
[0130] A certificate with a mismatched root object commitment is considered a valid certificate, even if the certificate signature is valid. It does not apply to digital value objects.
[0131] When the integrity verification of the valuation matching rule fails, the secure transaction 25 The element no longer calculates the digital value of the scopes and safely stores the object in case of failure. amount.
[0132] Permitted scope ends, atomic unit indices or digital value quantities If the numerical limits are exceeded, overflow-controlled arithmetic is used, and if the validation fails... The transaction is rejected. 30
[0133] Canonical no longer represents the same atomic value unit multiple times within its scope. If this is detected, recovery objects will not be activated. 16
[0134] If the combination of the scope set is no longer equal to the calculated conflict-free residual area, it is incomplete or The restructuring process is terminated to prevent the creation of excess value.
[0135] Secure operation even if the operating system or application software of the main device has been modified. Object states, capacity records, and regulatory trust roots in the element's protected memory 5 It cannot be directly modified by external software.
[0136] The main device loads an old memory image into the secure processing element, thereby restoring the object state. When attempting to undo, it does so via monotonic counters or integrity-bound state versions. The attempt to acquire it is detected.
[0137] If two reconstruction operations are started simultaneously for the same old object, persistence status 10 The transition manager assigns a specific lock, transaction sequence number, or one-time status token to the object. This allows only one of the processes to enter the preparation phase at a time.
[0138] A higher-period overlap segment while a restructuring process is underway. If the certificate is obtained, the secure transaction element can complete the current transaction in a secure intermediate state. or you can revoke it and apply the new certificate in the next transaction. 15
[0139] According to the security policy, multiple current certificates cover quarantine scopes. By creating a monotonic combination, it can be transformed into a single viable scope set.
[0140] Only authorized disputes regarding the narrowing of the quarantine scope in the new certification period Permission may be granted upon verification of the solution or release certificate.
[0141] Release certificate, directly re-release the old object that was previously invalidated 20 It does not activate; it only activates new recovery for deferred or frozen non-conflict scopes. It allows them to be converted into objects.
[0142] If physical tampering is detected in the secure transaction element, the spending keys objects can be deleted, locally quarantined, or offline authorization capacity can be enabled. It can be reset. 25
[0143] Re-matching the digital value amount with the central register after physical tampering, It may undergo a separate safe rescue process.
[0144] In case of message loss in the certificate distribution channel, the system will not have existing objects It does not have to be automatically invalidated; however, as defined in the security policy... It may apply offline periods or capacity limits. 30
[0145] The reconciliation node is temporarily unavailable, a valid agreement was previously received. This does not prevent the local implementation of certificates. 17
[0146] If any verification, protection or persistent state condition cannot be met The system applies safe failure behavior; this behavior occurs when a new digital value or a new offline value is obtained. This involves refusing to generate authorization capacity.
[0147] Value scope descriptors include numerical ranges, binary or multiple prefix trees, sparse Merkle 5 trees, range trees, Patricia trees, cryptographic accumulator memberships or any of these They can be represented by their combinations.
[0148] In an application where scopes are required to be kept confidential, instead of open lists of atomic units December commitments, zero-knowledge membership or intersection proofs, and privacy-protecting cluster commitments. Available. 10
[0149] In a privacy-protecting application, the secure transaction element is local to the certificate's quarantine area. obtains sufficient evidence to verify the relationship between the scope of the object; the parties' explicit transaction The amounts are not required to be included in the certificate.
[0150] Digital signature and hash algorithms, known at the time of application or developed later. Secure algorithms can be selected; protocol version algorithm IDs and key 15 It can determine their lengths.
[0151] Certificate signature and proof of derivation in an application requiring post-quantum security, Post-quantum digital signatures or hash-based commitment mechanisms may be included.
[0152] Certificate distribution channel (160); NFC, Bluetooth Low Energy, ultra-wideband, wired connection, cellular data, wireless local area network, optical link, QR-based data transfer or physical 20 It can use a secure data carrier.
[0153] Obtaining the certificate and implementing local restructuring is the same communication It does not have to be in the session; the certificate is stored in protected memory for later use. It can be applied before the procedure.
[0154] Secure transaction element, not yet implemented when a payment or transfer request is received 25 You can check if a more up-to-date certificate is available.
[0155] Consensus node single server, server supported by hardware security module It can be implemented in the form of a cluster or a community of distributed consensus nodes.
[0156] Collision section certificate, threshold in an application using multiple consensus nodes The signature may include multiple signatures or common authentication data from a majority of authorized nodes. 30 18
[0157] Recovery policy identifier (187), capacity allocation, maximum recovery object A signed profile that selects the number, deferred recovery behavior, and certificate period transition rules. It may include a reference.
[0158] Technical authorization margin fixed value, linear value according to part number, stepped threshold 5 It can be calculated using a function selected according to the function or device hardware class.
[0159] Technical authorization share in an application C_T = c0 + c1·N_O + c2·N_W + c3·N_V + It can be determined by the relation c4·D_max, where N_O is the number of recovery objects created, and N_W is the number of recovery objects created. Number of writes to protected persistent memory, N_V number of cryptographic verifications, D_max maximum Degeneration depth and 10 determined by protocol version c0 to c4 or signed hardware security profile. These represent coefficients. The relationship in question is illustrative and may be constant, piecewise linear, or threshold. Other determination functions based on this principle can also be used.
[0160] Capacity allocation to recovery objects is proportional to the amount of digital value, depth of coverage This can be done according to a fixed distribution rule determined by a weighted or signed security policy.
[0161] To reduce the number of salvage objects, only those adjacent to each other and their combinations 15 Areas that do not overlap with the quarantine zone can be combined.
[0162] The computation time or memory usage of the canonical scope set is safe operation. If the element exceeds the resource threshold, the transaction is directed to the deferred recovery mechanism.
[0163] Digital value object: electronic money, prepaid value, closed-loop credit, energy usage rights, right to transportation, data usage quota, right to operate industrial machinery or divisible digital rights 20 It can represent licensing rights.
[0164] In the energy use rights application, atomic value units represent energy quantities; transportation In the application of the right to operate machinery, the units are journey or distance; in the application of the right to operate machinery, the units are duration. or they can represent transaction cycle units.
[0165] In non-monetary uses of the invention, the term “expenditure” means the depletion of the related digital right, 25 It means transfer or authorization.
[0166] The main device and the counterparty processing device are directly offline between two secure processing elements. can transfer or process transactions between a secure processing element and a trusted terminal. can accomplish it.
[0167] Offline transmission protocol, receiver-generated random value, temporary public key, 30 The session counter or counterparty session commitment is entered into the derivation record of the digital value object. can connect. 19
[0168] In an example application, the local value space S = [0,1023] and the normalized quarantine space Q It is determined as = [173,499].
[0169] In this case, the conflict-free residual area is R = [0.172] ∪ [500.1023].
[0170] Remaining space in binary prefix-based canonicalization application; [0,127], [128,159], [160,167], 5 It can be divided into the following categories: [168,171], [172,172], [500,503], [504,511] and [512,1023].
[0171] When each atomic unit is worth 1 TL, the old object is worth 1.024 TL, the quarantine area is worth 327 TL and The total recovery value will be 697 TL.
[0172] The secure operation element ensures that the scopes of the eight generated recovery objects are interconnected. that they do not overlap, their combined area is now equal, and their total value is 697 TL. 10 truths.
[0173] If the device has sufficient resources for a maximum of five active recovery objects, in the protocol version According to the defined deterministic priority rule, five scopes can be enabled and the remaining three scopes It can be protected under a deferred recovery commitment.
[0174] Technical authorization share consumed during recovery operation and allocated to five active objects 15 The sum of the acquired capacities cannot exceed the usable capacity of the original object.
[0175] Later, when sufficient resources are provided or the current recovery activation certificate is available When received, the three deferred scopes can be converted into new recovery objects.
[0176] Second application of the same deferred recovery commitment, transaction sequence number and It does not produce additional objects or value due to its consumption status. 20
[0177] In another example, the certificate may contain multiple separate quarantine scopes Q1, Q2 and Q3 and The remaining area is calculated by subtracting the combination of those scopes from the S area.
[0178] Normalization of multiple quarantine scopes, overlapping scopes It allows for the unification of the concepts and ensures that the same scope is applied only once.
[0179] As the certification period increases, new quarantine scopes will be monotonic with previous scopes 25 They can be combined; narrowing or loosening can only be done with separate authorized certificate types.
[0180] The invention involves centrally re-exporting the entirety of an existing digital value object without It allows for the local reuse of the non-conflict area.
[0181] A single certificate representing the conflict area, with numerous devices having their own local objects This allows the intersection to be calculated separately. 30
[0182] Canonical scope generation, different compatible safe processing elements for the same input It can reduce additional reconciliation messages by enabling the production of recovery scopes.
[0183] Completeness of scope and non-overlap checks for multiple recovery of the same atomic value. It prevents the object from being re-represented.
[0184] Offline authorization capacity preservation separate from digital value preservation, object It prevents the total offline operation authority from increasing through splitting or recovery. 5
[0185] Failure-tolerant persistent state transition, legacy after power failure or software crash and prevents new objects from remaining usable together.
[0186] Delayed recovery commitment if the memory limit of the secure processing element is exceeded. It ensures that the value of the asset is preserved in a way that is neither lost nor expendable, without conflict.
[0187] The reconciliation node does not generate recovery objects individually, certificate and message 10 can reduce the number and allow devices to perform their own recovery processes according to different local object scopes. It allows it to be realized.
[0188] Technical effects of the invention; number of central re-issuance transactions, size of certificate data, number of safe memory writes, percentage of conflict-free values recovered, post-interruption recovery time, and Active object memory usage can be evaluated by measurement. 15
[0189] A secure transaction element in an application, object before and after reconstruction. You can add the number of memory writes, the number of memory writes, and the processing time to the control log.
[0190] The audit log contains a hardware verification commitment that does not disclose the device ID. It can be transmitted to the consensus node.
[0191] Invention, banking, payment, transportation, energy, telecommunications, industrial automation, 20 It is applicable to industry in access control and divisible digital rights management systems.
[0192] Application of the invention to a specific central bank currency, crypto asset, blockchain, distributed It is not limited to a ledger or a specific financial arrangement model.
[0193] Reconciliation records are in the central database, distributed ledger, and secure audit log. or a combination of these. 25
[0194] The secure transaction element must be in the form of a card independent of the main device or inside the device. The fact that it is buried does not alter the essence of the invention.
[0195] The application methods described in the specification are technically compatible with each other. They can be used together in moderation.
[0196] The value ranges, monetary amounts, capacity values and 30 used in the figures and examples Algorithmic rankings are descriptive and do not limit the scope of protection.
[0197] The scope of the invention is not limited to the examples described in the specification, but is defined in the claims. Technical specifications and their technical equivalents are determined by these. Basic Conservation Relationships R = S \ Q 35 ⋃ Ri = R and Ri ∩ Rj = ∅ (i ≠ j) Σ V(Ri) = V(S) - V(S ∩ Q) Σ Ci + CT ≤ CS
Claims
21 REQUESTS 1. An offline transferable digital transaction performed by a secure transaction element (110). This is a method of selectively reconstructing the value object (170); a root object commitment (171) is a derivation proof that verifies valid derivation from the root object in question. (172), a first value scope identifier (173), a digital value quantity (174), value The amount of digital value in atomic value units represented by the scope identifier. a valuation matching rule (175) that determines the relationship between and the amount of digital value the first digital value object which includes a separate offline authorization capacity (176) 10 held in a secure transaction element; signed by a consensus node (130) and is related to a conflict identified based on the same root object commitment, or one or more. more quarantine scope descriptors, root object commits, certificate periods, and Obtaining a collision segment certificate (180) containing the protocol version; the certificate cryptographic signature, period, protocol version, and root object commit match Verification by the secure transaction element; the first value scope identifier is 15 quarantine scope descriptors represented by the first value domain they represent Determining the intersection between the areas; ensuring that the intersection is not empty. and the combination of quarantine areas due to the fact that it does not cover the entire primary value area Calculating a conflict-free residual value domain by subtracting it from the primary value domain; a conflict-free residual value space, a deterministic 20 that operates according to the protocol version With the canonicalization function, residual values that do not overlap and whose combinations are conflict-free. converting the area into a set of ordered residual scope descriptors equal to the area; ordered residual The same root for at least some of the scope descriptors in the scope descriptor set object commitment dependent, containing updated derivation proof and valuation mapping 25 of the recovery digital value objects (190) carrying the amount of digital value determined by the rule. creation in the secure transaction element and all scopes in the said set the combination of the remaining scopes when the recovery is not converted into digital value objects an unusable deferred recovery commitment (200) creation; recovery of each conflict-free atomic value unit from digital value objects that it is fully represented in one or a deferred recovery commitment and no 30 Confirmation that the quarantine atomic value unit is not represented in these; rescue total represented by digital assets and any deferred recovery commitments, if any. the amount of digital value corresponding to the conflict-free surplus value domain of digital value that they are equal and the total offline allocated to or held in them 22 the share of technical authorization consumed in restructuring with authorization capacity the total available offline authorization capacity of the first digital value object Verification that it has not exceeded the limit; recovery by invalidating the first digital value object. Activating digital value objects is a result of power or processing interruptions, causing the old and 5 with a persistent state transition that prevents new objects from becoming available simultaneously implementation; and recovery of digital asset objects, collision section certificate. without requiring additional real-time communication with the consensus node after acquisition It is characterized by including the steps to make it available for use in a secure transaction element. The method used. 10 2. The method is according to claim 1, and a local certificate is stored in the protected memory of the secure transaction element. the keeping of the period counter (117) and the period of the certificate received is older than the local period This includes the rejection of the certificate if this is the case.
3. This method is based on Claim 2 and applies to different instances for the same root object commit and the same certificate period. If multiple valid certificates containing the same content are obtained, the relevant digital asset will be temporarily suspended for 15 days. rendering it unusable and a higher term dispute resolution certificate This includes ensuring that the restructuring is not carried out without taking the necessary precautions.
4. The method is based on any of claims 1 through 3, where the value scope descriptors are binary. representation with prefixes and the conflict-free residual space of the canonicalization function a prefix set corresponding to complete binary blocks that do not overlap It involves creating it.
5. According to claim 4, the method is that two siblings have the same length and are under the same superscript. If the combination of the prefixes does not intersect with the quarantine area, then the parent prefixes in question... the prefix is replaced and the output prefixes are in the order determined by the protocol version. It includes the regulation. 25 6. The method is based on any of claims 1 to 5, where the valuation matching rule applies to each atomic element. unit value rule that assigns equal value to a unit of value or to different atomic value units a weight table that assigns different values and is cryptographically linked to the root object commitment It includes the inclusion of.
7. The method is based on any of 1 to 6, with the first value field and quarantine fields being 30. If there is no intersection between them, the first digital value object remains unchanged. to be left in usable condition and the entire primary value area of the quarantine zones 23 If included, the first digital value object will be invalidated and the recovery object will be created. It includes preventing its creation.
8. Method according to any of claims 1 to 7, permanent state transition; planned recovery a preparation record (211) containing commitments of objects is stored in protected persistent memory 5 writing, creation of the old object consumption sign (212), recovery objects activation and completion including commits of activated recovery objects. It includes the steps for writing the record (213).
9. The method according to claim 8, after a power or process interruption; preparation record If not found, the previous state of the old object shall be preserved, preparation record 10 If it is present and there is no consumption sign, the preparation must be taken back, consumption If the mark is present and there is no completion record, only the preparation record is included. completion of recovery objects and, if a completion record exists, the old This includes preventing the object from being reactivated.
10. The method is according to request 8 or 9, and the one-way status bit of the old object's usage authorization is 15. changing, securely deleting the key, one-way key one of the operations of inverting the function or increasing the monotonic counter dependent on the object It involves invalidating it with a few individuals.
11. Method according to any of claims 1 through 10, with offline authorization capacity. It cannot be increased during disconnected operation and the capacity increase is only for the current period, device 20 an authorized renewal cryptographically linked by domain and root object commitment This involves verifying the certificate.
12. Method according to any of claims 1 to 11, and the technology consumed in the restructuring. The authorization share is the number of recovery objects created, transferred to protected permanent memory. write count, number of cryptographic verifications, maximum derivation depth, and hardware security 25 This involves determining the profile based on at least two of its parameters.
13. Method according to claim 11 or 12, offline and not allocated to recovery objects. authorization capacity, policy contained in the certificate or signed security profile. Permanently depleted, locally frozen, or authorized capacity only, according to its identifier. It includes making it reusable with a certificate of achievement. 30 14. The method is based on any of claims 1 to 13, and the canonical residual scope number is reliable. exceeding the maximum number of active objects that can be held in the processing unit or the persistent memory threshold 24 In this case, recovery for a portion of the scopes selected according to a deterministic order of priority. It cannot be used for creating objects and combining unselected conflict-free scopes. This involves creating a deferred recovery commitment (200) in the situation.
15. The method is according to claim 14, and the deferred recovery commitment is the root object commitment, 5 cryptographic commitment to the canonical ordered set of unselected scopes (201), total amount of deferred digital value (202), deferred offline authorization including capacity (203), associated certificate period (204) and protocol version; sufficient deferred scopes when source or current recovery activation certificate is provided 10 new recovery objects by comparing them again with the current quarantine area. conversion and exhaustion of the deferred recovery commitment includes.
16. A system for selectively reconstructing offline transferable digital value objects. system (100); protected permanent memory (112), cryptographic verification unit (113), value Scope processing unit (114), canonicalization unit (115), persistent state transition manager (116) 15 and at least one secure transaction element (110) including an authorization capacity manager (118); and root object commit, certificate period, protocol version, one or more quarantines a collision segment certificate (180) which includes the scope identifier and the certificate digital signature a consensus node configured to provide a secure transaction element (130) It includes verifying the collision section certificate of the secure processing element, local digital 20 To determine the partial intersection between the scope of the value object and the scope of quarantine. creating a conflict-free residual area by removing the quarantine scope from the local value zone. to calculate, to transform the conflict-free residual space into a deterministic canonical scope set, recovery digital value objects for at least a portion of the aforementioned canonical scope set when creating and not all scopes are converted into recovery objects, the remaining 25 conflict-free areas are unusable under a deferred recovery commitment to protect, verify the protection of digital assets and offline authorization capacity, prevents the old object and the recovery objects from being used simultaneously after performing the stable state transition and obtaining the collision section certificate Digital value recovery without requiring additional real-time communication with the consensus node 30 to make objects available for use in the secure processing element a system characterized by its structure.
17. According to claim 16, the system is the secure transaction element; the certificate digital signature (189) is evidence. commitment (186), root object commitment in certificate, certificate period and quarantine verifying that it covers the scope descriptors and the record or evidence subject to the evidentiary commitment Merkle's proof of membership, hash decryption, and cryptographic 5 demonstrate the data's adherence to that commitment. to verify through accumulator membership proof or at least one of these. a system characterized by its structure.
18. The system is in accordance with claim 16 or 17, and the secure processing element is the collision section certificate. digital signature (189); canonical encoded scope identifiers, certificate type, protocol Domain allocation data including version, network domain and certificate issuer identifier (188) 10 A system characterized by being configured to verify data through it.
19. A secure transaction device used in the system, in accordance with any of claims 16 to 18; a physically uncopyable function or securely installed hardware root at least one monotonic counter that preserves the key, certificate periods, and object states, Power outage resistant protected permanent memory and directly powered by the device's main processor 15 It must contain an immutable object state record and execute the method in Claim 1. It is characterized by its structure.
20. Secure transaction device according to claim 19, and near field communication of secure communication interface (119). (NFC), Bluetooth Low Energy, ultrawideband, wired direct device connection, or The combination of these forms a digital value object, derivation record, or overlap section. 20 It is characterized by being configured to transfer the certificate.
21. Secure transaction device according to claim 19 or 20, and secure transaction element (110) mobile device security element, smart card, SIM, eSIM, wearable device security module, payment terminal in the form of a security module, embedded Internet of Things module, or vehicle control module. It is characterized by its implementation. 25 22. When a secure transaction element is executed by its processor, that secure transaction causing the element to execute the method in any of Claims 1 through 15 stored on a computer-readable persistent medium containing commands A product of a computer program.