Authentication method

The method uses a distributed ledger to authenticate data representations by linking them to independent data sources, addressing the issue of biased environmental performance reports by ensuring transparency and reliability.

WO2025181499A1PCT designated stage Publication Date: 2025-09-04DYNAMICLEDGER SOLUTIONS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/GB2025/050415
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-01
Filing Date
2025-02-28
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

Existing methods for generating and verifying environmental performance reports are prone to manipulation, as companies can present biased information due to lack of control over data sources and difficulty in verifying the authenticity of data records.

Method used

A method of authenticating representations of processed data using a distributed ledger, which includes a representation identifier and data source identifiers, allowing verification of data sources and ensuring transparency by referencing data records on the ledger.

Benefits of technology

Ensures the authenticity of data representations by linking them to transparent and independent data sources, making it difficult for entities to manipulate data and providing a reliable audit trail.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure GB2025050415_04092025_PF_FP_ABST
    Figure GB2025050415_04092025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a method (100) of authenticating a representation of processed data. The representation is generated from one or more data sources and comprises a representation identifier and one or more data source identifiers. The representation identifier is an identifier for the representation of processed data. The one or more data source identifiers is / are identifier(s) for the one or more data sources. The method comprises: receiving (110) at least one of: the representation identifier and the one or more data source identifiers; obtaining (120) data associated with the representation identifier and the one or more data source identifiers from a distributed ledger; and determining (130) that the representation of processed data is authentic based on the obtained data.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] AUTHENTICATION METHOD

[0002] Field of the invention

[0003] The present invention relates to methods of authentication of representations of data, and generation of representations of data, and apparatus for performing such methods. The invention further extends to a computer-readable medium encoding instructions to perform the methods. to the invention

[0004] It is known to generate a report, conveying performance against a target. The performance is represented through one or more data sources. For example, where the report is an environmental performance report for an energy company, the report can use data sources indicating an amount of energy purchased from each of several sources, being wind turbine farms, solar panel farms, coal power stations and nuclear power stations. In this way, the report can present data allowing the environmental footprint of the energy company to be assessed.

[0005] Typically, at least some of the sources of energy are owned by an entity different to the energy company. An objective assessment of the environmental impact of the energy company is often difficult to make from the environmental performance report, and the energy company has an interest in presenting their environmental performance as positively as possible. It can often be difficult to verify the information given in such reports.

[0006] Distributed ledgers are also known and involve multiple copies of the same records being stored simultaneously, typically in different locations. Records can only be added, modified and deleted from the ledgers using agreed processes by consensus of at least a majority of nodes in a network. Importantly, when an authorised change is made to one ledger, it is also propagated to all other ledgers. Where a data discrepancy is identified in one ledger, unless this is part of an authorised change, the ledger is changed so that it agrees with the other ledgers. In this way, it becomes difficult to modify records on the ledger in unauthorised ways, because any changes would need to be made to all ledgers at the same time. Distributed ledgers are used for digital finance applications, such as cryptocurrency ledgers, where new tokens are mined using vast processing power (which limits the rate at which new tokens are awarded).

[0007] It is in this context that the present inventions have been devised.

[0008] Summary of the invention

[0009] In accordance with an aspect of the present invention, there is provided a method of authenticating a representation of processed data. The representation is generated from one or more data sources and comprises a representation identifier and one or more data source identifiers. The representation identifier is for the representation of processed data. The one or more data source identifiers are for the one or more data sources. The method comprises: receiving at least one of: the representation identifier and the one or more data source identifiers; obtaining data associated with the representation identifier and the one or more data source identifiers from a distributed ledger; and determining that the representation of processed data is authentic based on the obtained data.

[0010] Thus, where a representation of processed data is provided to a user, they can verify that the information being presented is accurately based on records on a distributed ledger. Importantly, the representation of processed data has a record, as do the one or more data sources used to generate the representation of processed data. In this way, not only can the representation of processed data be authenticated using its associated record on the distributed ledger, but so too can the data sources used. Typically, the entity providing (or instructing the provision of) the representation of processed data to a user or entity seeking to authenticate the representation of processed data does not control all (or even a majority) of the nodes in the distributed ledger. Furthermore, typically, the entity does not control the asset(s) generating at least one (e.g. a majority, such as all) of the one or more data sources. In this way, many if not all of the one or more data sources can be considered to be independent of the entity.

[0011] It will be understood that the data associated with the representation identifier and the one or more data source identifiers will be considered to be obtained from the distributed ledger even where the data is obtained indirectly. For example, the data may be obtained from a further system, which further system is in direct data communication with the distributed ledger to obtain the data. In other examples, it may be that the data is obtained directly from the distributed ledger.

[0012] By authenticating the representation of processed data in this way, it becomes difficult for an entity to manipulate data and generate representations of processed data which are misleading. The underlying data sources are transparently available for inspection.

[0013] It will be understood that an identifier (e.g. the representation identifier and the one or more data source identifiers) is any data which can lead to the associated data. Identifiers may be unique identifiers, though this is not always essential.

[0014] Typically, the representation of processed data is generated from multiple data sources. The one or more data source identifiers may comprise a single data source identifier, for plural data sources, such as a single data source identifier for all of the data sources. Alternatively, the one or more data source identifiers may be a data source identifier for each data source (resulting in multiple data source identifiers). It may be that the method is a computer-implemented method, carried out by one or more processors using instructions stored on a computer-readable memory (such as a non-transitory computer-readable memory). The method may be carried out on a user device.

[0015] The at least one of the representation identifier and the one or more data source identifiers may be received by way of user input.

[0016] Determining that the representation of processed data is authentic may comprise comparing the obtained data with the representation of processed data. In some examples, the representation of processed data comprises the obtained data, and the comparison is to check that the data included in the representation of processed data is identical to the obtained data. Alternatively, the obtained data is not directly included in the representation of processed data, but can be determined from the representation of processed data, such as by simple calculation. It may be that the obtained data comprises at least one of (e.g. all of) the one or more data source identifiers. The obtained data may comprise the representation identifier.

[0017] The comparison may be performed visually by a user. Thus, the comparison can be completed simply, even when the representation of processed data is not in electronic form, such as when the representation of processed data is a hard-copy document. The comparison may be performed algorithmically using a computer.

[0018] The data associated with the representation identifier may comprise at least one of: the owner name; the owner unique identifier; the issue date of the representation of processed data; the expiration date of the representation of processed data; a status of the representation of processed data; data associated with one or more data sources used to generate the data associated with the representation identifier; and one or more data source identifiers for the one or more data sources used to generate the data associated with the representation identifier. Thus, the representation identifier can be a wide variety of information. Nevertheless, the representation identifier is a means of identifying the representation of processed data. In some examples, the representation identifier may be a unique identifier for the representation of processed data. Thus, the representation identifier uniquely identifies the representation of processed data among all other data stored on the distributed ledger.

[0019] The method may comprise receiving the representation identifier. The method may comprise receiving at least one of the one or more data source identifiers. The method may comprise receiving each of the one or more data source identifiers.

[0020] The data associated with the one or more data source identifiers may comprise at least one of: a description of the data source(s); one or more collection dates for the data source(s); a total number of data sources; at least a subset of the data from the data source(s); and a status of the data source(s). Thus, the one or more data source identifiers can be a wide variety of information. Nevertheless, the one or more data source identifiers is / are a means of identifying the one or more data sources. In some examples, the one or more data source identifiers may be unique identifier(s) for the one or more data sources. Thus, the one or more data source identifiers uniquely identify the one or more data sources among all other data stored on the distributed ledger.

[0021] Obtaining data associated with the representation identifier and the one or more data source identifiers from the distributed ledger may comprise transmitting the at least one of the representation identifier and the one or more data source identifiers. The method may further comprise receiving the data associated with the representation identifier and the one or more data source identifiers. Thus, the data associated with the representation identifier and the one or more data source identifiers is obtained, following a request, using received data. In this way, data from the representation of processed data can be used to check that the data stored on the distributed ledger matches the representation of processed data. Transmitting the at least one of the representation identifier and the one or more data source identifiers may be directly or indirectly to a node of the distributed ledger. It may be that the representation identifier is used to address the correct item on the distributed ledger. Receiving the data associated with the representation identifier and the one or more data source identifiers may be directly or indirectly from the distributed ledger. For example, it may be that the data associated with the representation identifier and the one or more data source identifiers is accessed or generated based on data stored on a further database, separate from the distributed ledger, and that the relevant entry of the further database is accessed using information stored on the distributed ledger.

[0022] The representation of processed data may be a report. The representation of processed data may be a physical object, such as a printed document. The representation of processed data may be an electronic data file, such as a PDF document. Thus, the representation of processed data can be authenticated, whether in hard-copy form, or in electronic form. Thus, even a paper-copy report can be authenticated using the present invention, by comparing information in the paper-copy report with information stored on a distributed ledger. In some examples, a signature of the data used in the representation of processed data can be compared with data on the distributed ledger, so as to avoid having to directly compare many different data points. In this case, the signature is calculated simply using the data available in the representation of processed data. For example, a simple arithmetic calculation may be used.

[0023] The present disclosure extends to a method of generating a representation of processed data. The method comprises: receiving a request to generate a representation of processed data, the request comprising a data record identifier to identify a data record on a distributed ledger; transmitting a data request, comprising the data record identifier; and receiving the representation of the processed data, including a representation identifier indicative of the data record, and one or more data source identifiers indicative of one or more data sources used to generate the representation of the processed data.

[0024] Thus, instead of authenticating a representation of processed data already generated, a representation of processed data can be generated making use of information stored on the distributed ledger. The representation of processed data includes one or more data source identifiers indicative of one or more data sources used to generate the representation of the processed data. Typically, the one or more data source identifiers are identifiers of one or more further data records on the distributed ledger, the one or more further data records being for the one or more data sources used to generate the representation of the processed data. By including the identifiers of the one or more data sources in the representation of processed data, this allows further users, who are subsequently sent the representation of processed data to authenticate the representation of processed data, using the identifiers included in the representation of processed data.

[0025] It may be that the data request is transmitted to the distributed ledger. It may be that the representation of the processed data is received from the distributed ledger. It may be that the representation of the processed data is received from a further system in data communication with the distributed ledger.

[0026] The representation of the processed data may be a document. The representation identifier and the one or more data source identifiers may be provided on a page of the document. In other words, typically, the document includes a plurality of pages, including an identifier page, and one or more further pages, and the representation identifier and the one or more data source identifiers are provided only on the identifier page.

[0027] The present disclosure extends to a device configured to carry out one or both of the methods described hereinbefore. The device may be a user device. The device may be a server device.

[0028] The present disclosure further extends to a computer-readable medium encoded with a data structure to be stored on a distributed ledger. The data structure has a plurality of records. Each record comprises: an identifier field, storing a unique identifier of the record; and a data field storing data associated with the record. At least one record of the plurality of records further comprises a reference field, storing one or more reference identifiers, each referencing a further record in the data structure. The data stored in the data field of the at least one record is generated based on data associated with the data fields of the further records referenced by the one or more reference identifiers stored in the reference field.

[0029] Thus, a data structure of this form, which cross-references to other records stored on the distributed ledger, allows the data record to be used to authenticate not just the data in the present data records, but also to act as an audit trail to authenticate the data used to generate the data record. The data fields of the records typically include a signature of the data associate with the data record. In other words, the data fields typically do not contain the full data set, but instead include a signature which can be used to authenticate that the data set is authentically associated with the data records. For example, the data field may be arranged to include a hash code, generated using a hash function of the data set. Typically, the hash function cannot be used to recompute the data set from which the hash code was generated. In this way, the distributed ledger need not store the whole data set, but can still be used to authenticate the representation of processed data. It will be understood that a signature of the data is any alphanumeric code calculated based on the data, typically shorter than the data and used to determine authenticity of a further copy of the data.

[0030] The data stored in the data field of the at least one record may be generated further based on data associated with the data fields of any recursively referenced records from the reference identifiers in the reference field. Thus, a record may recursively refer to multiple layers or generations of records to establish a full, authenticatable audit trail of the data sources used.

[0031] The data stored in the data field of each record may be read only. Thus, the data cannot be modified. It may be that other fields of the record can be modified (such as a log field storing a log of access requests for the data record, or an owner field storing an indication of an owner of the dataset associated with the record).

[0032] In some examples, a request to modify the data stored in the data field may cause a new record to be generated, having the modified data in the data field, and including a reference to the record storing the previous data, for audit purposes.

[0033] In some examples, the representation of the processed data is stored in a data field of a first record, which references a second record. The data represented by the representation of the processed data is stored using the second record. Thus, the representation of the processed data can include a representation identifier, being the identifier for the second record. This is suitable where the data field of a record cannot be modified once the record is created. In other examples, the data field of a record stores the representation of the processed data. The record can be created without the data field being initially populated, allowing the representation of the processed data to be generated including the representation identifier, and for the data field of the record to subsequently be populated with the representation of the processed data.

[0034] In some examples, the data field comprises a set of variables or instructions, allowing a representation of processed data to be generated using a separate generating system, following a template process. The set of variables or instructions may comprise references to further records in the data structure.

[0035] The reference field may be write-once. Thus, it may be that although the record can be generated with no data in the reference field, a subsequent operation can be performed on the distributed ledger to populate the reference field with a reference to a further record on the distributed ledger. Once populated, the contents of the reference field cannot be changed. It may be that the record comprises a plurality of reference fields, each of which can be write-once.

[0036] The record may comprise a deleted field for storing data indicative of whether the record has been set to deleted. The deleted field may be write-once. In other words, once a record has been set to deleted, the status cannot be changed further. Thus, where mistakes are made, or where circumstances change, the record can still remain on the distributed ledger, though the record is now marked as deleted. This means that no functionality is required on the distributed ledger to completely delete records, as records are never deleted, only marked as deleted if necessary.

[0037] The present disclosure extends to a set of functions to govern the creation and modification of records on the data structure. The functions are computer-implemented methods. The methods may be implemented on a server, acting as a node of the distributed ledger. The methods may be implemented on further servers or user devices, in data communication with the distributed ledger, but different from any of the nodes storing the distributed ledger. The distributed ledger may be formed from a plurality of nodes, distributed across a geographic region. Each node may store a local copy of the distributed ledger. As is standard in distributed ledger implementations, any authorised changes to the distributed ledger may only be made where enough (e.g. a majority of) nodes of the distributed ledger agree that the change satisfies one or more pre-determined criteria. Furthermore, the nodes may be configured to check that the local copy of the distributed ledger stored on the node matches the local copy of the distributed ledger stored on one or more other nodes of the distributed ledger. Where a difference is identified, it may be that the node or nodes which have stored thereon local copies of the distributed ledger that differ from a majority of the local copies of the distributed ledger, amend their copies to match the majority of the local copies of the distributed ledger.

[0038] Where authorised changes are made to a local copy of the distributed ledger stored on a single node, it may be that this causes the same authorised changes to be made on one or more of, such as a majority of, such as all of, the other nodes of the distributed ledger.

[0039] At least one record in the data structure may comprise an owner field. It may be that each record in the data structure comprises an owner field. The owner field is configured to store data indicative of the entity owning the asset associated with the record. The asset may be a non-fungible asset. The asset may be the representation of the processed data, or a certification associated therewith. The certification may be official. The certification may be independent of the entity owning the asset.

[0040] The present disclosure extends to a method of setting an owner of the asset, such as a smart contract. The method comprises receiving an owner input, indicative of the owner to set as the owner of the asset, and a request to set the owner of the asset to the owner input. It may be that receipt of the owner input provides the request. The method may comprise checking whether the request was received from an authorised entity, such as the current owner of the asset. It may be that the owner field of the asset is updated with the owner input in dependence on whether the request was received from an authorised entity. Thus, the owner of the asset can be changed only by authorised entities. It may be that the method is a function of the asset on the distributed ledger. The present disclosure extends to a method of providing an owner of an asset. The method comprises requesting details of the owner of an asset, and outputting data indicative of the owner of the asset. Thus, the owner of the asset can be determined. It may be that the data indicative of the owner of the asset is the address of the owner. The address may be the physical address of the owner. It may be that the method comprises receiving asset identifier data indicative of the asset for which the owner is to be provided.

[0041] The present disclosure extends to a method of providing a prefix associated with assets related to a smart contract under which one or more assets may be or have been minted. The method comprises returning a contract identifier used to designate records as being associated with a particular smart contract. Thus, assets associated with the smart contract can be easily identified. It may be that the contract identifier is stored in a contract field in the data structure for records indicative of assets associated with a particular smart contract.

[0042] The present disclosure extends to a method of setting a minter for an asset. It will be understood that a minter is an entity authorised to generate new records on the distributed ledger, the new records indicative of assets. The method comprises receiving a minter input, indicative of the entity to set as the minter of the asset, and a request to set the minter of the asset to the minter input. It may be that receipt of the minter input provides the request. It may be that the method comprises checking whether the request was received from an authorised entity, such as the current owner of the smart contract, or the current minter. It may be that the minter field of the asset is updated with the minter in dependence on whether the request was received from an authorised entity. Thus, the minter of the asset can be set or changed only by authorised entities. It may be that the method is a function of the asset on the distributed ledger.

[0043] The present disclosure extends to a method of providing a minter of an asset. The method comprises requesting details of the minter of an asset, and outputting data indicative of the minter of the asset. Thus, the minter of the asset can be determined. It may be that the data indicative of the minter of the asset is the address of the minter. The address may be the physical address of the minter. The present disclosure extends to a method of minting (sometimes referred to as creating) new assets. In other words, the method is a method of generating new records on the distributed ledger. The method comprises receiving data to be stored in the new asset. It may be that the method comprises checking whether the request was received from an authorised entity, such as the current minter. It may be that the new asset is created in dependence on whether the request was received from an authorised entity. Thus, the asset can be created (i.e. minted) only by authorised entities. It may be that the method is a function of the asset on the distributed ledger. The new asset may be a new record on the distributed ledger. It may be that the data is stored in a data field of the new record. In other examples, it may be that the method comprises processing the received data to determine signature data to store in the data field, the signature data being uniquely indicative of the data for which it is a signature. The owner field of the record may be set to the authorised entity creating the new asset.

[0044] The method may further comprise receiving data of a new owner to set as the owner of the asset. The method may comprise, if new owner data is received, setting the owner field of the new record to be the new owner.

[0045] In some examples, the owner of an asset can authorise a third party to manage the asset on their behalf. Thus, it may be that the data record includes an authorised party field indicative of the authorised third party to be considered an authorised party in addition to the owner. The authorised party field can be set by the owner or the current authorised third party. It may be that functions that can normally only be performed by the owner, can also be performed by the authorised third party on behalf of the owner.

[0046] It may be that a lock field of the asset is set to indicate that the asset is locked when the asset is created. In some examples, the present disclosure extends to a method of locking an asset. It may be that the distributed ledger is configured to prevent functions being performed on records having a lock field indicative of the asset being locked, other than an unlock function to unlock the asset. It may be that the lock and / or unlock function can only be run by the owner of the asset. It may be that the asset being locked prevents any changes from being performed on the asset (other than unlock). In other examples, it may be that the asset being locked prevents even any functions which are configured to output information associated with the asset. In some examples, the asset may be locked until after a transfer of ownership has been completed and will then be unlocked.

[0047] The present disclosure extends to a method of burning an asset. The method may comprise receiving an identifier of the asset to set as burned, the identifier indicative of a record on the distributed ledger to be set as burned. The method further comprises setting a burned field of the record associated with the identifier to indicate that the asset is burned. It may be that the distributed ledger is configured to prevent any further changes being made to records having a burned field indicative of the asset being burned. Unlike a locked function, assets cannot be changed out of the burned state once this is set. It may be that the burn function can only be run by the owner of the asset.

[0048] Typically, the status of assets on the distributed ledger can be queried, which will output information such as whether the asset is burned and / or locked.

[0049] In some examples, assets include a next owner field, indicative of a next owner to take over ownership of the asset, for example at a predetermined time and date, or in response to a release function, releasing the asset for transfer to the new owner. The present disclosure extends to a method of setting a next owner of an asset. The method comprises receiving a next owner input, indicative of the next owner to set as the next owner of the asset, and a request to set the next owner of the asset to the next owner input. It may be that receipt of the next owner input provides the request. It may be that the method comprises checking whether the request was received from an authorised entity, such as the current owner of the asset. It may be that the next owner field of the asset is updated with the next owner input in dependence on whether the request was received from an authorised entity. Thus, the next owner of the asset can be set or changed only by authorised entities. It may be that the method is a function of the asset on the distributed ledger. The predetermined time and date can be set subsequently, using a dedicated function which can only be completed by an authorised entity, such as the current owner. It may be that the asset can be transferred to a new owner immediately, simply by requesting the transfer and providing a new owner identifier. Typically, the transfer request can only be completed by an authorised party, such as the current owner, and therefore includes the checked described hereinbefore.

[0050] When an asset is transferred to a new owner, the owner field is changed to match the new owner, and any data in the next owner field is removed. Any data in the field indicative of the date on which the transfer is to complete is also removed, as is data in any authorised third party field.

[0051] The present disclosure further extends to a method of outputting a history of an asset. Thus, the asset stores a log of all actions performed on the asset since the asset was created and can output that log in response to a request.

[0052] The present disclosure extends to a method of setting the data in the data field of the asset. If the data field of the asset already contains data, it may be that the method comprises retaining a record of the previous data field entry in a further field, before updating the data in the data field, so that no data is overwritten or deleted. In some examples, it may be that the data field can only be set once.

[0053] It may be that data in the data field of the asset can be accessed on request. Similarly, data from any other field of the asset can typically be accessed on request. It may be that only authorised parties may be able to request access to data in fields of the asset, though typically this will be more than just the owner of the asset.

[0054] The present disclosure extends to a method of verifying the data stored in the data field of the asset. In one example, the method compares a received data signature to a data signature determined using the data stored in the data field of the asset. In another example, the method outputs a data signature determined using the data associated with the asset, such as the data in the data field, for use in verifying a further representation of the processed data associated with the asset.

[0055] The present disclosure extends to a method of linking the asset to a further record in the data structure. The reference field in the asset is populated with a reference identifier indicative of the further record in the data structure (e.g. in the distributed ledger) to which the asset should be linked. If the asset is already linked to one or more assets, the reference field is expanded to reference an additional asset. Typically, this method can only be used by an authorised entity, such as the current owner of the asset.

[0056] The present disclosure extends to a method of unlinking the asset from a further record in the data structure. Instead of removing the asset from the reference field, this simply updates metadata for the asset in the reference field, to indicate that the asset should be considered unlinked. In this way, the audit trail of the asset is retained. Typically, this method can only be used by an authorised entity, such as the current owner of the asset. It may be that the method comprises receiving an unlink reason, which can be stored in the asset in the metadata for the reference field.

[0057] In addition to the methods which can be performed on assets held on the distributed ledger, as described hereinbefore, it is also possible that changes to the distributed ledger can cause events to be emitted, either directly from one or more nodes of the distributed ledger, or using separate systems, configured to monitor the distributed ledger. An event being emitted will be understood to be the outputting of a data packet in response to a determined change on the distributed ledger.

[0058] The data packet may comprise details of a change in the distributed ledger associated with at least one of: minting of a new asset; changing of a minter for a smart contract; creation of a new smart contract; changing of a state of an asset (e.g. locked, unlocked, burned); an attempt to change an asset while the asset is locked; changing of an owner or a next owner of an asset; setting, changing or revocation of an authorised party of an asset; setting or changing of a release date of an asset; changing of referenced assets for a given asset. The data packet may comprise metadata associated with the change.

[0059] The term asset and record have both been used hereinbefore and are understood to be interchangeable. A record may be indicative of an asset.

[0060] Description of the Drawings An example embodiment of the present invention will now be illustrated with reference to the following Figures in which:

[0061] Figure 1 shows a flowchart illustrating an example of a method of authenticating a representation of processed data according to the present invention.

[0062] Figure 2 shows a flowchart illustrating an example of a method of generating a representation of processed data according to the present invention.

[0063] Figure 3 is a schematic representation of a data structure in accordance with the present invention.

[0064] Figure 4 shows a flowchart illustrating a further example of a method of generating a representation of processed data according to the present invention.

[0065] Figure 5 shows a schematic representation of references between a set of records stored on a data structure according to the present invention.

[0066] Figures 6A, 6B and 7 show flowcharts illustrating methods to be performed on data records of a data structure according to the present invention.

[0067] Figure 8 shows a flowchart illustrating a further example of a method of authenticating a representation of processed data according to the present invention.

[0068] Figure 9 shows a page from a report generated according to an example of the present invention.

[0069] Figure 10 shows a schematic representation of components of a device used to implement methods according to examples of the present inventions.

[0070] Detailed of an Example Embodiment

[0071] Figure 1 shows a flowchart illustrating an example of a method 100 of authenticating a representation of processed data in accordance with an aspect of the present invention. Typically, the representation of processed data is a report. The representation of processed data is generated from one or more data sources and comprises a representation identifier and one or more data source identifiers. The representation identifier and the one or more data sources are included on a page of the report in this example. The method 100 comprises receiving 110 at least one of the representation identifier and the one or more data source identifiers, obtaining 150 data associated with the representation identifier and the one or more data source identifiers by transmitting 120 the at least one of the representation identifier and the one or more data source identifiers and receiving 130 the data associated with the representation identifier and the one or more data source identifiers, and determining 140 that the representation of processed data is authentic based on the obtained data. In this example, determining 140 that the representation of processed data is authentic comprises comparing the obtained data with the representation of processed data, wherein the comparison may be one that is performed visually by a user.

[0072] The data associated with the representation identifier and the one or more first data source identifiers includes the data source identifiers, in the form of data signatures indicative of the data from the one or more data sources.

[0073] Figure 2 shows a flowchart illustrating an example of a method 200 of generating a representation of processed data in accordance with an aspect of the present invention. The method 200 comprises receiving 210 a request to generate a representation of processed data, wherein the request comprises a data record identifier to identify a data record on a distributed ledger, transmitting 220 a data request comprising the data record identifier to a node of the distributed ledger, and receiving 230 the representation of the processed data, which includes a representation identifier indicative of the data record and one or more data source identifiers indicative of one or more data sources used to generate the representation of the processed data. As in Figure 1 , the representation of processed data is a report, and the representation identifier and the one or more data source identifiers included in the report are included on a single page of the report.

[0074] Figure 3 is a schematic representation of a data structure 300 in accordance with an aspect of the present invention. The data structure 300 comprises first, second, third, fourth, and fifth records 310, 320, 330, 340, 350, represented as individual rows in Figure 3, each record comprising an identifier field 311 , 321 , 331 , 341 , 351 , and a data field 312, 322, 332, 342, 352, such that, for example, a first record 310 comprises first identifier field 311 and first data field 312, the second record 320 comprises second identifier field 321 and second data field 312, and so on for each of the five records 310, 320, 330, 340, 350. In the example in Figure 3, the first record 310 further comprises a first reference field 313 which stores first and second reference identifiers 314A, 314B. The first reference identifier 314A references the third record 330 of the data structure, and the second reference identifier 314B references the fourth record 340 of the data structure. The data stored in a data field is generated based on the data associated with the data fields of the records referenced in the associated reference field. In this example, the data stored in the first data field 312 is generated based on the data associated with the third and fourth data fields 332, 342. The fourth record 340 comprises second reference field 343, which stores a third reference identifier 344A which references the fifth record 350. The data stored in the fourth data field 342 is generated based on the data associated with the fifth data field 352. In this way, the data stored in the first data field is directly based on the data associated with the third and fourth records 330, 340, and indirectly based on the data associated with the fifth record 350.

[0075] The second, third, and fifth records 320, 330, 350 do not reference any other records, in this example.

[0076] Figure 4 shows a flowchart illustrating a group of functions governing the creation and modification of data records on two storage types 450, 460. The first storage type 450 is a secure storage 450, stored typically in a single location and suitable for retaining high volumes of data. The second storage type 460 is a distributed ledger 460, involving multiple copies of the same database of records, each held on a separate node in a networked set of nodes. For data processing and efficiency reasons, the distributed ledger 460 typically does not hold very large amounts of data, but includes references to locations in the secure storage 450 allowing large data files to be obtained from the secure storage 450 when required. Typically, the nodes of the distributed ledger 460 are owned separately by a plurality of different entities, so that no one entity controls a majority of the nodes of the distributed ledger 460; thus, the distributed ledger 460 is seen as more resilient to data manipulation by bad actors. The secure storage 450 may typically be owned by a trusted independent party, such as a regulator or an operator of the system. The group of functions 400 comprises storing 401 generated data, creating 402 a draft report, publishing 403 the report, and modifying 404 the report. Storing 401 the generated data comprises generating 410 data, typically from a data source such as an energy generator, inputting 412 the data either manually or automatically to a data structure, and storing 414 the data in the secure storage 450 and the distributed ledger 460. Typically, the raw data itself will be stored in the secure storage 450, whilst a new record will be generated in the distributed ledger 460 storing a signature of the data stored in the secure storage 450 and a location at which the data can be retrieved from the secure storage 450. Generating 402 a draft report comprises creating 420 the draft report, storing 422 data necessary to publish the report in the storage module 450 and / or creating new records on the distributed ledger 460, and linking 424 the data in the draft report to other reports and data from the distributed ledger 460. In this way, a draft report is generated for an entity to review. When they are happy with the content of the report, the entity can publish the report following the process 403 described hereinafter. In some examples, the draft report may be stored in the secure storage module 450. Publishing 403 the report comprises requesting 430 the report be published, retrieving 432 the data for use in generating the draft report from the secure storage module 450, generating 434 the published report, and creating 438 the record associated with the published report in the distributed ledger 460. The generated published report may be used to generate 436 a PDF file which is injected with the data including the identifier of the record associated with the published report in the distributed ledger 460. This PDF file may then be stored in the distributed ledger 460. The PDF file can either be stored in a new record on the distributed ledger 460, or as added data on the record created at 438. The data for use in generating the draft report may additionally or alternatively be taken from the distributed ledger 460, though this is not shown in Figure 4. Modifying 404 the report comprises updating 440 the report to modify the content therein, burning 442 the original report (marking the record on the distributed ledger 460 for the original report as burned and therefore not to be used), updating 448 the status of the old report to burnt on the distributed ledger 460, creating 444 a new report, and linking 446 the new report to the old, burnt report, then storing 449 the new report with the linked data on a new record in the distributed ledger 460.

[0077] Figure 5 shows a representation of how different records on the distributed ledger may be linked in accordance with the present invention. In this example, first, second, third, fourth, fifth, sixth, and seventh records 510, 520, 530, 540, 550, 560, 570 are shown. These records are linked in a “tree”. The first record references the second record 520 and the fourth record 540. The second record 520 references, and is therefore linked to, the third record 530 and the fifth record 550, and the fourth record 540 references, and is therefore linked to, the sixth record 560 and the seventh record 570. In this way, the first record 510 is linked to the second, third, fourth, fifth, sixth, and seventh records 520, 530, 540, 550, 560, 570. This creates a “tree” of linked records. Typically, no upward link is stored on the records. In other words, analysis of the third record 530 alone would not reveal any link to the second record 520 or the first record 510 (or indeed the fifth record 550).

[0078] Figures 6A and 6B show two flow charts illustrating methods of creating and amending release functions for releasing ownership of an asset in accordance with the present invention. Figure 6A illustrates a release function 600, comprising setting 610 the next owner and the date of release, checking 620 whether the release date has been reached, and, upon the release date being reached, transferring 630 the ownership of the asset to the next owner. Once a release function has been set up for an asset, the function can be modified, as shown in Figure 6B, which shows a release control modification function 602, performed by the current owner, and comprises requesting 640 a cancellation of a release, a change of the next owner, or a transfer, checking 650 the release lock state of the asset, and, if the release lock state is locked, causing 660 the request to fail, or, if the release lock state is unlocked, actioning 670 the request.

[0079] Figure 7 shows a flowchart illustrating the process 700 of requesting that an action be executed in relation to an asset, wherein the request is made by the owner or manager of the asset. The process 700 comprises requesting 710 an action be executed, checking 720 the state of the associated asset and, if the asset is locked or burnt, causing 730 the action to fail and returning 740 an error, or, if the asset is unlocked, performing 750 the requested action.

[0080] Figure 8 shows a flowchart illustrating an example process for creating and validating a certificate, for example a certificate of energy generation (e.g., a Green Energy Certificate) in accordance with an aspect of the present invention. Broadly, the process 800 comprises generating 801 a record of energy generation 819, generating 802 a representation of a certificate, and updating 803 ownership information of a record. Generating 801 a record of energy generation comprises generating energy 810, recording 812 the energy generation, wherein the recording 812 may be done via a smart meter, passing 814 the recorded data to a data structure, processing 816 the data to create an Energy Generation Record 819, and storing the data in a storage module 850 and distributed ledger 860. For a regulator from whom a user has requested a certificate and / or a representation of a certificate, the process of generating 802 a representation of a certificate comprises receiving 820 a request for a certificate, reviewing 822 data from the storage module 850 and the distributed ledger 860, and validating 824 the data. If the data is not validated, the process includes investigating 826 the erroneous data. If the data is validated, the process includes issuing 828 a certificate, minting 829A a representation of the certificate and assigning 829B the representation of the certificate to the generator of the energy, and transmitting the representation of the certificate to the storage module 850 and the distributed ledger 860.

[0081] Figure 9 shows an example of single page from a report being a representation of processed data 900. The page comprises a representation identifier 910, being an identifier of the representation of processed data (e.g. the identifier of the report). The page also comprises one or more data source identifiers 920 in the form of a data signature 920 for the data used to generate the report, said data being based on data from the one or more data sources. In this way, the data signature will be understood to be a data source identifier, as it can be used to authenticate the data of the data sources.

[0082] Figure 10 shows a schematic representation of components of a device used to implement methods according to examples of the present inventions. Specifically, the system 1000 is suitable for implementing steps in any of the processes and methods described herein. In some examples, the methods are to be implemented using multiple devices 1000 of the form shown in Figure 10, each responsible for different steps of the disclosed methods. The device 1000 comprises a communication component 1020, such as a transceiver, for communicating with other devices over a network, such as a wide area network, for example the internet. The device 1000 further comprises a controller 1020 configured to exchange data communication signals with the communication component 1020. The controller 1020 comprises one or more processors 1030 and a memory 1040. Typically, the memory is a computer- readable non-transitory storage medium. The memory 1040 stores instructions which, when executed by the one or more processors 1030, cause the device 1000 to perform at least some of the steps of the methods described herein.

[0083] In summary, there is provided a method (100) of authenticating a representation of processed data. The representation is generated from one or more data sources and comprises a representation identifier and one or more data source identifiers. The representation identifier is an identifier for the representation of processed data. The one or more data source identifiers is / are identifier(s) for the one or more data sources. The method comprises: receiving (110) at least one of: the representation identifier and the one or more data source identifiers; obtaining (120) data associated with the representation identifier and the one or more data source identifiers from a distributed ledger; and determining (130) that the representation of processed data is authentic based on the obtained data.

[0084] Throughout the description and claims of this specification, the words “comprise” and “contain” and variations of them mean “including but not limited to”, and they are not intended to and do not exclude other components, integers, or steps. Throughout the description and claims of this specification, the singular encompasses the plural unless the context otherwise requires. In particular, where the indefinite article is used, the specification is to be understood as contemplating plurality as well as singularity, unless the context requires otherwise.

[0085] Features, integers, characteristics, or groups described in conjunction with a particular aspect, embodiment, or example of the invention are to be understood to be applicable to any other aspect, embodiment or example described herein unless incompatible therewith. All of the features disclosed in this specification (including any accompanying claims, abstract and drawings), and / or all of the steps of any method or process so disclosed, may be combined in any combination, except combinations where at least some of such features and / or steps are mutually exclusive. The invention is not restricted to the details of any foregoing embodiments. The invention extends to any novel one, or any novel combination, of the features disclosed in this specification (including any accompanying claims, abstract and drawings), or to any novel one, or any novel combination, of the steps of any method or process so disclosed.

Claims

Claims1. A method of authenticating a representation of processed data, the representation generated from one or more data sources and comprising a representation identifier and one or more data source identifiers, the representation identifier for the representation of processed data and the one or more data source identifiers for the one or more data sources, the method comprising: receiving at least one of: the representation identifier and the one or more data source identifiers; obtaining data associated with the representation identifier and the one or more data source identifiers from a distributed ledger; and determining that the representation of processed data is authentic based on the obtained data.

2. The method of claim 1 , wherein determining that the representation of processed data is authentic comprises comparing the obtained data with the representation of processed data.

3. The method of claim 2, wherein the comparison is performed visually by a user.

4. The method of claim 1 or claim 2, wherein the data associated with the representation identifier comprises at least one of: the owner name; the owner unique identifier; the issue date of the representation of processed data; the expiration date of the representation of processed data; a status of the representation of processed data; data associated with one or more data sources used to generate the data associated with the representation identifier; and one or more data source identifiers for the one or more data sources used to generate the data associated with the representation identifier.

5. The method of any preceding claim, wherein the data associated with the one or more data source identifiers comprises at least one of: a description of the data source(s); one or more collection dates for the data source(s); a total number of data sources; at least a subset of the data from the data source(s); and a status of the data source(s).

6. The method of any preceding claim, wherein obtaining data associated with the representation identifier and the one or more data source identifiers from the distributed ledger comprises transmitting the at least one of the representation identifier and the one or more data source identifiers, and receiving the data associated with the representation identifier and the one or more data source identifiers.

7. The method of any preceding claim, wherein the representation of processed data is a report.

8. The method of any preceding claim, wherein the representation of processed data is a physical object, such as a printed document.

9. The method of any of claims 1 to 7, wherein the representation of processed data is an electronic data file, such as a PDF document.

10. A method of generating a representation of processed data, the method comprising: receiving a request to generate a representation of processed data, the request comprising a data record identifier to identify a data record on a distributed ledger; transmitting, a data request, comprising the data record identifier; and receiving the representation of the processed data, including a representation identifier indicative of the data record, and one or more data source identifiers indicative of one or more data sources used to generate the representation of the processed data.

11. The method of claim 10, wherein the representation of the processed data is a document, and wherein the representation identifier and the one or more data source identifiers are provided on a page of the document.

12. A computer-readable medium encoded with a data structure to be stored on a distributed ledger, the data structure having a plurality of records, each record comprising:an identifier field, storing a unique identifier of the record; and a data field storing data associated with the record, wherein at least one record of the plurality of records further comprises a reference field, storing one or more reference identifiers, each referencing a further record in the data structure, wherein the data stored in the data field of the at least one record is generated based on data associated with the data fields of the further records referenced by the one or more reference identifiers stored in the reference field.

13. The computer-readable medium of claim 12, wherein the data stored in the data field of the at least one record is generated further based on data associated with the data fields of any recursively referenced records from the reference identifiers in the reference field.

14. The computer-readable medium of claim 12 or claim 13, wherein the data stored in the data field of each record is read only.

15. The computer-readable medium of any of claims 12 to 14, wherein the reference field is write-once.

Citation Information

Patent Citations

  • Method for determining information integrity and computer system using the same

    EP3742367A1

  • Blockchain for open scientific research

    US20180323979A1

  • Data verification

    WO2020240170A1