Method of encrypted communication using a decentralized computing system
The decentralized computing system enhances data security in public networks by anonymizing IP addresses, dividing tasks into subtasks, and using metadata node tracking to secure data transmission and processing, addressing the vulnerability of existing methods.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- OBSHCHESTVO S OGRANICHENNOJ OTVETSTVENNOSTYU TKHEOOL
- Filing Date
- 2024-10-31
- Publication Date
- 2026-05-07
AI Technical Summary
Existing data exchange methods over public data networks lack sufficient security, allowing for unauthorized access and interception due to untrusted or compromised infrastructure.
A decentralized computing system employs double IP address replacement in primary router nodes, task division into subtasks executed by multiple nodes, and metadata node tracking to enhance security, using encryption and smart contracts for secure data transmission and processing.
This approach significantly increases data security in distributed networks by anonymizing IP addresses, ensuring reliable task execution, and preventing unauthorized access, even on untrusted infrastructure.
Smart Images

Figure RU2024000331_07052026_PF_FP_ABST
Abstract
Description
[0001] A METHOD OF ENCRYPTED COMMUNICATION USING A DECENTRALIZED COMPUTING SYSTEM
[0002] FIELD OF TECHNOLOGY TO WHICH THE INVENTION RELATES
[0003] This technical solution relates to the field of information security and data protection from unauthorized activity, in particular to a method of encrypted communication using a decentralized computing system.
[0004] LEVEL OF TECHNOLOGY
[0005] The prior art includes information source WO 2015 / 164521 A1, published on 29.10.2015, which discloses methods for managing protected content with digital rights management (DRM) in a networked secure environment for the collective exchange of computer data through a secure exchange medium managed by an intermediate organizational entity among users of a plurality of other organizational entities, where the computer content of the data and the access rights to the computer content of the data are shared by the first and second users, the computer content of the data and the access rights to the computer content of the data are converted into protected computer content of the data with DRM through communication with a DRM mechanism, where the DRM mechanism is selected based on the content type of the computer content of the data, and the DRM mechanism is provided by an entity other than the intermediate organizational entity and other than any of the plurality of other organizational entities.
[0006] In addition, the prior art discloses information source RU 2707715 C2, published on 28.11.2019, which discloses a method for transmitting packets containing digital data through a cloud that contains a network of media nodes.The method comprises: scrambling a packet by changing the order of data segments in the packet in a first media node in accordance with a first scrambling algorithm; transmitting the packet to a second media node; descrambling the packet in the second media node, in order to restore the order of the data segments in said packet before said scrambling in said first media node; scrambling the packet in said second media node in accordance with a second scrambling algorithm after said descrambling in said second media node and transmitting said packet to a third media node, wherein said second scrambling algorithm differs from said first scrambling algorithm, so that the order of the data segments in the packet, when the packet arrives at the third media node, differs from the order of the data segments in the packet, when the packet arrives at the second media node.
[0007] Also known in the prior art is information source US 2020 / 0274711 A1, published August 27, 2020, which discloses systems and methods for secure data exchange. A processor generates two or more shared data sets encrypted with a symmetric key, each data set associated with a first user device, and causes the encrypted shared data sets to be stored separately from one another in at least one remote storage location. The processor generates first and second encrypted keys by encrypting data indicating a symmetric key with a first asymmetric key of first and second pairs of asymmetric keys associated with the first user device and second user device, respectively, and causes the encrypted key to be stored in at least one storage location.To recover a data set, a predetermined number of two or more common sets of encrypted data and at least one of the second asymmetric keys of the first and second pairs of asymmetric keys are required.
[0008] The prior art discloses information source WO 2012 / 021734 A1, published on February 16, 2012, which discloses systems and methods for transmitting data for secure storage. For each of two or more data sets, a plurality of shares is generated containing a distribution of data from an encrypted version of the data set. The shares are then stored in a shared storage device, in which the data set can be recovered from a threshold number of associated plurality of shares using an associated key. Systems and methods for providing access to secure data are also provided. The plurality of shares containing a distribution of data from an encrypted version of the data set are stored in the storage device. A client is provided with a virtual machine that specifies the plurality of shares and the ability to recover the data set from the plurality of shares using the associated key.
[0009] WO 2012 / 024508 A2, published February 23, 2012, discloses systems and methods for protecting data in virtual machine computing environments. A request for a security operation is received from a first virtual machine running in the host operating system of a first device. In response to the request, a first security module executes the security operation, the first security module being implemented in the kernel of the host operating system. The result of the security operation is provided to the first virtual machine.
[0010] Finally, prior art includes US 2018 / 0309786 A1, published October 25, 2018, which discloses systems, methods, and devices for securely routing and encrypting network data flows passing through a network switch and connected IoT devices. Specifically, the disclosure relates to systems, machine-readable media, and methods for ensuring the security of IoT-based devices using moving target protection by periodically generating and providing randomized port identifiers that are valid for a limited period of time.
[0011] A common drawback of the known state-of-the-art solutions is the weak level of security when exchanging data over open and public data networks.
[0012] Thus, solutions known in the prior art do not allow subscriber devices to exchange data in a public data transmission network protected from unauthorized access or interception, the infrastructure of which may be untrusted or compromised.
[0013] The proposed solution differs from the solutions known from the prior art in that in a decentralized computing system for encrypted communication, a double replacement of the IP addresses of the subscriber device is performed in two primary router nodes, the task of acting on data is divided into subtasks and at least two execution nodes are assigned to each subtask, as well as tracking in the metadata node the execution of the subtask in each of the execution nodes.
[0014] ESSENCE OF THE INVENTION
[0015] The technical problem addressed by the claimed technical solution is to eliminate the shortcomings of the prior art. The technical result achieved by solving the above technical problem is increased data security in a distributed data transmission network.
[0016] According to one embodiment of the invention, a method for encrypted communication using a decentralized computing system is proposed. According to the proposed method: a transmitting subscriber device establishes an encrypted connection with a metadata node through at least two primary router nodes and one secondary router node of the decentralized computing system for transmitting a stream of data packets, wherein the stream of data packets is divided into corresponding parts between the primary router nodes and the length of each transmitted packet is shorter than the encryption period, in each of the primary router nodes the IP address of the transmitting subscriber device is replaced with a primary temporary IP address when routing data packets, in the secondary router node the primary temporary IP address is replaced with a secondary temporary IP address,and the metadata node is the closest of the available metadata nodes with respect to the secondary router node; in the metadata node, data packets with a request to perform a task are received from the transmitting subscriber device via the established encrypted connection, the task is divided into subtasks, at least two available execution nodes are assigned to each subtask, data related to the task are received from the transmitting subscriber device via the established encrypted connection, the received data related to the task are distributed between the subtasks, an encrypted portion of the distributed data is sent to each of the execution nodes according to the assignment of the subtasks; the execution of each subtask by the corresponding execution device is monitored, and the result of the task execution based on the execution of all subtasks is provided either to the transmitting subscriber device via the established encrypted connection, or to another subscriber device,having previously established a new encrypted connection with the metadata node.
[0017] In a particular embodiment of the proposed method, a task includes one of: a data storage task, a data processing task, or a data forwarding task. In a particular embodiment of the proposed method, providing the task execution result includes at least one of: transmitting the task execution result based on the execution of all subtasks either to the transmitting subscriber device via an established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node; or providing access to the task execution result based on the execution of all subtasks either to the transmitting subscriber device via an established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node.
[0018] In a particular embodiment of the proposed method, the provision of the task execution result is carried out using task identifiers.
[0019] In a particular embodiment of the proposed method, a specific number of assigned actuator nodes is specified in the transmitting subscriber device by setting the redundancy coefficient.
[0020] DESCRIPTION OF DRAWINGS
[0021] The invention will be further described in accordance with the accompanying drawings, which are provided to illustrate the invention and in no way limit its scope. The following drawings are attached to the application:
[0022] Fig. 1 illustrates a block diagram of an exemplary decentralized computing system according to one embodiment of the present invention;
[0023] Fig. 2 illustrates a block diagram of an implementation of user and access management in a metadata management system (MDS) according to one embodiment of the present invention.
[0024] DESCRIPTION OF THE INVENTION
[0025] The following detailed description of the invention includes numerous implementation details intended to provide a clear understanding of the present invention. However, one skilled in the art will readily appreciate how the present invention may be utilized with or without these implementation details. In other instances, well-known methods, procedures, and components have not been described in detail in order to avoid unnecessarily obscuring the features of the present invention.
[0026] Furthermore, it will be clear from the foregoing description that the invention is not limited to the embodiment described. Numerous possible modifications, changes, variations, and substitutions, while preserving the spirit and form of the present invention, will be apparent to those skilled in the art.
[0027] The proposed encrypted communication can be applied to a decentralized computing system. In a particular embodiment, the decentralized computing system according to the present invention can be the system shown in Fig. 1.
[0028] A decentralized computing system can be a peer-to-peer distributed storage and processing system for protected information (system), designed primarily to eliminate information security (IS) threats targeting servers, central computing nodes, and network subscriber workstations. It represents a distributed operating system, each node of which contributes its computing resources (storage subsystem, central and graphic processors, RAM) to the system and has no independent significance. However, there is a distinction between nodes in their functional purpose: a subscriber node (which simultaneously functions as a storage node), a storage node, and a metadata node. The purpose is determined during the implementation phase of the system node.Data storage in the system is accomplished by dividing each user's data block (file) into N identical packets, encrypting them, and sending them to K N network nodes for storage in encrypted form (K is the redundancy factor). The list of nodes storing the blocks is placed in a metadata block, which is in turn encrypted and stored on the metadata nodes. No one, including the owner, knows which nodes are storing parts of the file at a given time, except the subsystem with access to the metadata.
[0029] The system is implemented so that at each discrete moment in time, significant volumes of information are transferred between system nodes at high speed, while also undergoing encryption and decryption procedures. It should also be noted that an additional information flow consists of distributed ledger service blocks (metadata), which contain information about nodes writing / reading data packets and information from the data access management system. The system ensures sufficient data access speed, comparable to the average read / write performance relative to the user using existing network storage systems.
[0030] A decentralized computing system for secure communications is a decentralized high-speed cloud of servers (DCS) running software modules. This cloud implements an overlay environment for processing protected information, preventing providers and server owners from accessing the data. Servers can be connected to the cloud by any owner. When connecting a server to the cloud, specialized software modules are installed and configured. Together, the server and properly configured software modules form the technical node of the service or system. Subscribers to the communications service are hardware devices configured with software modules (subscriber nodes). Subscriber devices include computers and mobile devices (smartphones, tablets).
[0031] The core of the DSO is the software of a decentralized high-speed server cloud, which implements the DSO's control algorithms and serves as the foundation for the functioning of an open community in the organizational form of a decentralized autonomous organization (DAO) with open participation, serving the interests of user associations with a distributed geographic and / or organizational structure. Open participation in a DAO DSO means that any person, regardless of organizational form, geographic location, etc., who has met the participation requirements established by the DAO DSO algorithm, can become a member of such a DAO. Thus, the DAO DSO fully implements the ideology embedded in the concepts of Web3 and DAO.
[0032] The DSO architecture shown in Fig. 1 implements decentralized services on the DSO servers: a computing cloud for running user decentralized applications (UDA); data storage; a search subsystem; an integrated payment system - a metadata management system (MMS); technical subsystems (automatic machines for maintaining data integrity and availability, automatic machines for optimizing the PCI7RU2024 / 000331 data cloud operation in terms of performance and reliability). Distributed ledger technology is used to ensure the integrity of metadata.
[0033] The DSO information security system (DSO information protection system) is designed to prevent leakage of protected user information when working with DSO. Protected information here refers to any data and metadata privately (not for public use) posted by users to DSO, either knowingly or as a result of using DSO (their digital footprint).
[0034] Users (participants) of such a DAO DSO are classified according to the role they perform into three categories:
[0035] 1. owners of computing resources (suppliers);
[0036] 2. content owners (customers);
[0037] 3. content consumers (subscribers).
[0038] Each of the three roles generates a set of data about the user, which, in accordance with the definition adopted above, must be classified as protected information.
[0039] The DSO organizes and maintains an environment for its participants, customers and subscribers, who interact across geographically remote locations. This environment provides the same level of security as if they were working within the same building on a local network isolated from public networks (the internet). All work is performed directly over public networks, eliminating the need for dedicated data transmission channels and / or any filtering or security systems for traffic and data processed within the DSO. In other words, the DSO provides participants with a private network space and complete control over their digital footprint.
[0040] Devices included in the DSO can be assigned two primary functions: user node (subscriber device) and / or technical (executive) node. These two functions can be combined within a single hardware device. Technical nodes form a computing resource cloud—a peer-to-peer network of data storage, processing, and access nodes. The DSO essentially runs on the computing resource cloud, and subscriber nodes access it as a server. Since the DSO is primarily designed for building highly secure, geographically distributed corporate automated information systems with low information security and infrastructure maintenance costs, the PC17RU2024 / 000331 system provides performance comparable to its centralized counterparts.Therefore, the DSO includes built-in mechanisms for assessing the performance of technical nodes and competition between nodes for user tasks through the billing system, which is an integral part of the integrated payment system. These mechanisms encourage owners of technical nodes to supply the DSO with high-performance hardware devices (servers) on broadband data transmission channels and maintain high availability.
[0041] The architecture of the TheOoL DSO includes the following components:
[0042] 1. Communications execution subsystem.
[0043] 2. A subsystem for decentralized secure data storage.
[0044] 3. Decentralized search subsystem.
[0045] 4. Built-in payment system - a metadata management system (MMS) on the blockchain.
[0046] 5. Technical subsystems that perform automatic functions to maintain data integrity and availability and optimize the operation of the data cloud in terms of performance and reliability.
[0047] All DSO data is stored and transmitted in encrypted form. The DSO software implements the four upper layers of the OSI network model: application, presentation, session, and transport layers. The transport protocol uses a proprietary masking data transport and routing protocol, which ensures covert data transfer between nodes through a network of proprietary routers, making it difficult to identify DSO node traffic in the general flow.
[0048] The computing cloud, shown in Fig. 1, consists of hardware servers with installed DSO software—technical nodes connected in a peer-to-peer network. The technical nodes perform the functions of data storage and computational task executors, and the SMS nodes, which perform the DSO management function. An integral part of the SMS is the DSO blockchain and the DSO payment system. The SMS stores and processes information about all tasks issued to technical nodes, their requesters, and the terms of their execution, including payment for the nodes' services (billing). The data for each task is linked within an individual smart contract, which includes a request to complete a task or assignment. Tasks are divided into two types: data placement and storage tasks and computational tasks.In the second case, the executive node receives the initial data, and the software module that performs the calculation launches a dedicated software thread in which the necessary calculations are performed and returns the result to the node - the customer, which can be another technical node (or a metadata node) executing the DSO process, which awaits the corresponding result, or a subscriber node (device), if a specific software task prepares data for direct display in the graphical user interface.
[0049] Information leakage can occur through:
[0050] 1. Channels external to the DSO: Internet providers, communication operators that ensure the transmission of data from the subscriber to the ISI and their personnel;
[0051] 2. Channels within the DSO itself, namely:
[0052] 2.1. Owners of computing resources and their personnel (Providers).
[0053] 2.2. Developers of DSO.
[0054] Leak channels can be created both as a result of intentional actions and errors. Therefore, the design and implementation of a data protection system (DSO) addresses the problem of completely blocking leak channels 1 and 2.1 and minimizing the likelihood of leakage through channel 2.2 during content processing in the DSO. This invention does not address information security risks arising directly on user nodes of all categories, including the safety of key user information, protection of their subscriber nodes from unauthorized access, and antivirus protection.
[0055] Leakage channel 1 is partially blocked by the DSO cryptographic subsystem and the DSO transport protocol. The DSO transport protocol masks DSO traffic and implements its own built-in routing algorithm (periodically changing routers within a session). Therefore, network infrastructure owners (leakage channel 1) face problems identifying DSO traffic and its nodes, making traffic interception difficult.
[0056] To protect traffic from being read in the event of router compromise, data in the DSO is processed by the built-in cryptographic subsystem of the DSO, which is an integral part of the SMS. One of the functions of the SMS, as shown in Fig. 2, is to manage user accounts and access to DSO data. From the perspective of the SMS io, a user is nothing more than a unique identifier (Unique User Identifier, UUld), which is rigidly linked to a key pair (private / public). A user can be either a human subscriber or any software module executed in the DSO. UUld is generated by hashing the public key with the SHA256 function (Secure Hash Algorithm Version 2256 bit) or the hash function GOST 34.11-2018 for use in Russia. Keys are generated on the elliptic curve SECP521 R1 and are used in elliptic curve cryptography (ECC).DSO uses ECC in digital signature algorithms (ECDSA) and secure key transfer for the Diffie-Hellman stream cipher algorithm (ECDH).
[0057] Cryptographically secure and computationally inexpensive block ciphers (BCs) such as the Advanced Encryption Standard (AES) and its Russian equivalent, GOST 34.12-2018 "Kuznechik," are used as the basic encryption algorithms for direct data transmission and storage. These ciphers utilize uniquely generated one-time encryption keys. The relatively low computational complexity of these BCs allows for the transmission of multimedia streams to the DSO without significant delays.
[0058] As can be seen from the SMS architecture shown in Figure 2, each user has one primary and an unlimited number of secondary UUlds. The primary UUld is linked to an account in the integrated payment system (DSO). Secondary UUlds are generated for each group interaction (from two participants). They are divided into persistent and session-based. Persistent UUlds are stored in the user's key set and used in persistent, recurring interactions, such as when working collaboratively with data stored in the DSO. Session-based UUlds are used in one-time, real-time interactions to generate one-time ECDH keys, such as when conducting audio and video conferences. Access to the set of UUlds and associated keys is provided through a file stored locally on the key storage device by the user. This file, in addition to key information, contains references to data indexes available to the user in the DSO cloud, accounts, and smart contracts of the payment system and the billing subsystem.The information in the file is protected by BSH encryption with a constant key—a password—known only to the user. Therefore, it is critical for the user to preserve the key file (KF) and its password, as losing it completely disables access to the data, the ISI algorithms, and the funds blocked in the DSO integrated payment system account. Compromising the KF and its password is equally dangerous.
[0059] Managing interactions through the key file allows the user to mask their online activity and fully manage their digital footprint in the DSO, as linking their activities in different groups is only possible if both the key file and password are compromised. By creating a complex, long (512 bits or more), and unique (not included in known dictionaries) key / password, if only the key file is compromised, reading the key file's contents is extremely difficult for an attacker. This is due to the high cryptographic strength of the key file, the only known effective method for cracking which is brute-force attack. This gives the user, at a minimum, sufficient time to take measures to clean up their account and its traces in the DSO.
[0060] Access to content is provided through indexes (Fig. 2), which form the basis for the operation of the TheOoL search engine (Fig. 1). Three types of content indexes are available in TheOoL: personal indexes (DPI), group indexes (GDI), and a single public index (Public Data Index, PDI) for all UUlds.
[0061] DPIs are linked to a specific UUld and contain links and tags for content published for exclusive use. DPIs are accessible exclusively to the owner of the associated UUld. GDIs contain information about content intended for use within a specific user group and accessible only to members of that group. The GDI also contains a list of group members and information about the access level of the UUld members to the content (read / modify / own). GDIs are accessible to members of the associated groups. Accordingly, for content published "public," a PDI is used, which is accessible to all UUlds without exception.
[0062] When publishing content to the DSO, the user defines the content usage mode and the groups from which such content will be accessible. By default, the entry is added to the DPI of the current user's UUld. At this point, new entries are added to the corresponding indexes. The entry is entered with the content unit identifier and its user-defined name (e.g., document title). An automatic list of tags for indexing is generated, if possible, and user-defined tags are requested. The automatic indexing algorithm is then launched. Upon completion of the automatic indexing procedure, the DPI and GDI indexes are encrypted and stored in the DSO's SMS. Index encryption is performed by the BS. Encryption keys are randomly generated by the group owner / creator and transmitted to participants using ECDH. Encryption keys associated with UUld indexes and groups are stored in their respective CFs.
[0063] Before publishing, content is encrypted and then divided into blocks of equal length (at least two). Each block is assigned a unique identifier, which is placed in the index of a specific content unit. Next, an offer to store the blocks is generated in the form of a smart contract (master contract), signed by the customer. It contains the parameters for processing and storing the data block: storage period, execution parameters (for the executable algorithm), redundancy factor (determines the number of simultaneously existing backup copies), desired access speed, number of simultaneous requests, etc. This offer is accepted by available technical nodes, for each of which a separate, child smart contract is generated, which does not contain any information about the content owner. Each technical node can enter into no more than one child smart contract within a single master contract.Indexes are stored in the DSO in the same manner, with the only difference being that DPI and GDI index block identifiers are stored in the CF of authorized UUlds. Smart contracts are executed by the DP SUM (Fig. 1), one of whose functions is billing and the transfer of rewards from customers to performers. Additional protection against access to the protected information of a specific UUld is provided by the block and task identifier conversion functions embedded in the SUM. As a result, performers and customers receive different identifiers for the same block, ensuring complete abstraction between the content and the technical nodes servicing it. Thus, leakage channel 2.1 is completely blocked during content storage and processing tasks.
[0064] When a technical node is tasked with performing a computational task, the owner of the technical node will not be able to identify the user and / or software process requesting the computations. However, they will receive the initial computation data and their results, since the computations require processing data in decrypted form. To minimize the risk of data collection on the computations being performed or the substitution of computation results, the DSO includes a number of protective measures that do not require increasing the computational complexity of the tasks: 1. Software modules are published as a set of small tasks implemented as microservices. The main process that orders the computations and assembles the computational results is executed on the subscriber node of the user who requested the computations. Thus, the owner of the technical node receives a small portion of the computations.
[0065] 2. When a specific microservice performs long-term (more than 10 minutes) calculations, the DSO has a built-in “Mobile Virtual Servers” system (Fig. 1), which, after the allotted time has elapsed, removes the instantaneous state of the microservice and transfers its execution to another technical node.
[0066] 3. Technical nodes for performing specific computing tasks are selected based on the priority of the smart contract's execution, i.e., essentially randomly. The more technical nodes in the DSO computing cloud and the greater the degree of decentralization among technical node owners, the lower the probability that all computing tasks within a single master contract will be assigned to technical nodes belonging to a single owner.
[0067] 4. The standard software for the DSO technical node blocks data collection, and additional protection against the use of modified software for the technical node is built into the SUM system. To access the offer pool (and receive a reward for work), the technical node registers with the SUM billing subsystem upon startup. To do this, it receives and launches the SUM microservice, which verifies the node's compliance with the original.
[0068] Thus, a Type 2.1 leak by a malicious node owner is fundamentally possible. However, such an attacker will not be able to link the obtained data to a specific user or obtain a complete, coherent computational result. Furthermore, the likelihood of a Type 2.1 leak is lower with the number of nodes and the degree of decentralization of cloud computing resources by node owner and geographic location. The ideal scenario is the organization of an international network of nodes, in which each node has its own independent owner.
[0069] To completely eliminate the possibility of interception of calculation data by an unscrupulous server owner, the DSO has a built-in capability for using fully homomorphic encryption (FHE) algorithms to perform calculations without decrypting arguments and directly obtaining an encrypted result.
[0070] DSO is an open source project, the functionality of the DSO software is controlled by the participants of the DSO DAO.
[0071] The DAO is configured through a rules management system (an integral part of the SMS) based on the DSO blockchain consensus, which distributes network governance between the community of DSO governance token holders and the community of DSO technical node holders. This system maximizes decentralization of DSO governance and prevents DSO developers from violating security rules, as any changes must first be accepted (voted) by the community.
[0072] An approximate embodiment of the functioning of the invention
[0073] The encrypted communication method according to the present invention is performed in a decentralized computing system.
[0074] The transmitting subscriber device (subscriber node) establishes an encrypted connection with the metadata node through at least two primary router nodes and one secondary router node of the decentralized computing system to transmit a stream of data packets.
[0075] The router nodes and the metadata node are technical nodes and reside in a decentralized computing system, which can also be called a cloud.
[0076] The first technical node (router node) to which a connection is established becomes the gateway for the subscriber node. At least two such gateways are allocated to distribute data transmissions, so that transmission occurs over different channels rather than a single one.
[0077] A technical node in the cloud is selected randomly. There is a set of pre-defined nodes with known IP addresses (reference IPs), from which a list of available technical nodes can be obtained. The subscriber device receives a set of known IPs from the developer's website or from other network participants (from established sources). For example, when configuring a subscriber node, the subscriber device automatically selects this routing node through which communication is established.
[0078] Two routing nodes are required to ensure that no single node can receive the entire flow, thereby ensuring data anonymization.
[0079] Thus, the subscriber device initially establishes a connection with two such nodes (from 2 to 5).
[0080] At the subscriber's end, the data packet stream is encrypted and split into appropriate portions between the primary router nodes, with the length of each transmitted packet being shorter than the encryption period.
[0081] Each router node receives packets shorter than the encryption period. This is done to ensure that, in the event of a compromise, the node receives packet blocks that are complete and cannot recover the encryption key (from such a short packet).
[0082] In each of the primary router nodes, the IP address of the transmitting subscriber device is replaced with a primary temporary IP address when routing data packets. In the secondary router node, the primary temporary IP address is replaced with a secondary temporary IP address. Thus, these two router nodes hide the true (original or "white") IP address of the subscriber device from the computing nodes.
[0083] If the cloud is large enough (it has available technical nodes), a second technical node is created for forwarding. This leaves the subscriber node with two "hops" to the computing node (processor). More precise duplication (incorporating a third router node) eliminates the possibility that all three router nodes will belong to a single compromised owner. After the second hop, the computing (execution) nodes are located. The computing node can perform various roles depending on the workload. In particular, it can serve as a metadata node.
[0084] The metadata node is the closest available metadata node to the secondary router node.
[0085] The metadata node receives data packets from the transmitting subscriber device via an established encrypted connection, requesting a task. A task may include one of the following: data storage, data processing, or data forwarding. The metadata node maintains a list of nodes capable of performing the requested task. The metadata node collects requests and offers (i.e., offers to "sell" computing resources from technical nodes). The metadata node creates a smart contract between technical nodes and subscriber nodes. For example, the transmitting subscriber node issues one smart contract for a requested task, such as saving a file of a specific size, file access conditions (simultaneous number of subscriber devices), or performing computational operations.
[0086] The metadata node divides this task into subtasks and forms mini-contracts with technical nodes.
[0087] The metadata node assigns at least two available execution nodes to each subtask. The specific number of assigned execution nodes is specified in the transmitting subscriber device by setting the redundancy factor.
[0088] A technical node in the system can act as a router, a storage and / or computation node, or a metadata node. Metadata refers to smart contacts.
[0089] A router node routes packets. The primary purpose of routing is to conceal the subscriber's true IP addresses and metadata from the external circuit.
[0090] The metadata node works with user task metadata. The metadata node receives the subscriber address from the routing node in modified form. Technical nodes work only with the metadata node. The technical node also specifies the data retention period, receives packets in encrypted form, acknowledges their receipt to the metadata system (metadata nodes), and then reports its activity to the metadata system.
[0091] The task is assigned with a redundancy factor of 2 (or higher, at the user's discretion). This means that a task performed by 5 technical nodes is assigned to 10 nodes, thereby ensuring redundancy and guaranteed task completion. If one of the executive (technical) nodes fails, its task is assigned to another technical node and copied from the backup node.
[0092] The metadata node receives task-related data via an established encrypted connection from the transmitting subscriber device, distributes the received task-related data between subtasks, sends an encrypted portion of the distributed data to each of the executive (technical) nodes according to the assignment of the subtasks, monitors the execution of each subtask by the corresponding executive device, and provides the result of the task execution based on the execution of all subtasks either to the transmitting subscriber device via the established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node.
[0093] The delivery of task execution results to subscriber devices is carried out in the system using task identifiers.
[0094] Providing the result of completing the task includes at least one of: transmitting the result of completing the task based on completing all subtasks either to the transmitting subscriber device via the established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node; or providing access to the result of completing the task based on completing all subtasks either to the transmitting subscriber device via the established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node.
[0095] The metadata system then checks the number of subscriber devices accessing the task result (if there were 5 possible ones, then the sixth one will be denied access).
[0096] An approved subscriber device receives data at the speed specified in the smart contract. The smart contract owner can make changes to the contract, including canceling it, which frees up resources.
[0097] During a communication session (call), only routing nodes are used.
[0098] In a broadcast connection, a backbone node broadcasts messages to recipients. The backbone node periodically changes randomly. Metadata nodes also periodically "migrate," meaning that control is transferred from one metadata node to another.
[0099] When different portions of data are sent to different technical nodes, different encryption keys are used there.
[0100] Execution nodes can also "migrate," i.e., transfer a task from one execution node to another. Each metadata node is aware of all available nodes in the decentralized computing system. All technical nodes are aware of each other's existence. As soon as a node assumes the function of a metadata node, it receives information about all currently active metadata nodes.
[0101] The proposed invention is used to organize secure processing of audio-video-text communications data in public networks (including communications between components of the Internet of Things (IoT)) on an untrusted or compromised infrastructure.
[0102] The proposed invention prevents leakage (collection) of protected information during internet communications (transmission of video, audio, and arbitrary-format data, including in IoT networks) on elements of the telecommunications and computing infrastructure (leaks from providers, telecom operators, communications service owners, and owners of servers servicing the service). In other words, secure network communications are ensured using an insecure infrastructure for use by various dedicated autonomous distributed structured groups (DADSGs) and the organization of secure interactions between them.
[0103] The proposed invention provides for increased data security in a distributed data transmission network, which is achieved through the following:
[0104] - Double substitution of the subscriber device's IP addresses in two primary router nodes (which increases anonymity and, therefore, reduces the risk of interception of flow messages)
[0105] - Dividing the task into subtasks and assigning at least two execution nodes to each subtask (which also increases the reliability and security of processing transmitted data)
[0106] - Tracking in the metadata node the execution of a subtask in each of the execution nodes.
[0107] - Technically guaranteed exclusion of access to data by owners of network infrastructure and owners of executive nodes, which allows processing and transmission of data on untrusted or compromised infrastructure - Control and provision of the established level of quality of service (QoS), which allows for a pre-determined level of performance and availability of the system, unlike other peer-to-peer systems
[0108] - Management of identifiers and encryption keys on unique identifiers and sets of keys for each individual task, which significantly increases the complexity of possible data interception and reduces the likelihood of subscriber unmasking;
[0109] - A built-in subsystem for searching and accessing information based on individual and group indexes and smart contracts, which allows for the management of group work with data and tasks to be organized as flexibly and securely as in centralized systems;
[0110] - Masking routing and data transport, which exclude mutual detection or unmasking of subscribers and servers by addresses;
[0111] - Preliminary preparation of data and computing tasks, during which data and tasks are encrypted with cryptographically strong algorithms, broken down into small elements, each of which is transferred for storage or execution to a separate server (no server receives more than 1 piece of 1 task);
[0112] - Secure execution of computing tasks by servers, which blocks the server owner's access to the arguments and results of calculations through the use of homomorphic encryption algorithms (allowing the encrypted result of processing to be obtained directly from encrypted arguments without decrypting them)
[0113] - An algorithm for abstracting subscribers and servers using smart contracts, which prevents mutual disclosure of personal data (including the disclosure of "digital traces") when subscribers pay for server services, allowing server owners to receive rewards, and subscribers to use the service without the possibility of deanonymization using payment details;
[0114] - An algorithm for the mutual transformation of metadata of servers-executors and subscribers-customers, which prevents mutual unmasking by metadata of computing tasks;
[0115] - High quality of service (QoS), achieved by using high-performance servers for data processing and motivating their owners through a billing system; - Monitoring the consistency of server firmware, which is performed by network participants (subscribers and server owners) through the consensus algorithms of the integrated blockchain service.
[0116] A server in the context of the present invention is an electronic computing device for processing and storing data on which software is installed and operates and which is designed to exchange data with other electronic computing devices via a data transmission network.
[0117] An electronic computing device, including subscriber devices, is any known electronic computing device, including a user electronic device, a mobile phone, a tablet computer, a laptop computer, a desktop computer, etc., designed with the ability to execute user applications, as well as communicate via a data transmission network with a server.
[0118] An electronic computing device that provides the data processing necessary for the implementation of the claimed solution generally contains the following components: one or more processors, at least one memory, a data storage means, input / output interfaces, an input means, and network interaction means.
[0119] When executing machine-readable commands contained in the RAM, the processor of the device is configured to perform the basic computing operations necessary for the operation of the device or the functionality of one or more of its components.
[0120] Memory is typically implemented as RAM, where the necessary software logic is loaded to provide the required functionality. When implementing the proposed solution, the memory required for its implementation is allocated.
[0121] The data storage device can be implemented in the form of HDD, SSD disks, RAID array, network storage, flash memory, etc. The device allows for long-term storage of various types of information, for example, the aforementioned files with user data sets, databases containing records of time intervals measured for each user, user identifiers, etc. PC17RU2024 / 000331
[0122] Interfaces are standard means for connecting and operating peripherals and other devices, such as USB, RS232, RJ45, COM, HDMI, PS / 2, Lightning, etc.
[0123] The choice of interfaces depends on the specific device design, which may be a personal computer, mainframe, server cluster, thin client, smartphone, laptop, etc.
[0124] A keyboard may be used as a data input device in any embodiment of the system implementing the described method. The keyboard hardware may be any known device: it could be a built-in keyboard used on a laptop or netbook, or a separate device connected to a desktop computer, server, or other computing device. The connection may be either wired, in which the keyboard cable is connected to a PS / 2 or USB port located on the desktop computer's system unit, or wireless, in which the keyboard communicates wirelessly, such as via radio, with a base station, which is in turn directly connected to the system unit, such as via a USB port.In addition to the keyboard, data input devices may also include: a joystick, display (touch screen), projector, touchpad, mouse, trackball, light pen, speakers, microphone, etc.
[0125] Network communication tools are selected from a device that provides network data reception and transmission, such as an Ethernet card, WLAN / Wi-Fi module, Bluetooth module, BLE module, NFC module, IrDA, RFID module, GSM modem, etc. These tools facilitate data exchange via a wired or wireless data transmission channel, such as WAN, PAN, LAN, Intranet, Internet, WLAN, WMAN, or GSM.
[0126] The device components are connected via a common data bus.
[0127] In these application materials, a preferred disclosure of the implementation of the claimed technical solution was presented, which should not be used as limiting other, particular embodiments of its implementation that do not go beyond the scope of the requested scope of legal protection and are obvious to specialists in the relevant field of technology.
Claims
CLAUSES OF THE INVENTION 1. A method of encrypted communication using a decentralized computing system, comprising the steps of: - by means of the transmitting subscriber device, an encrypted connection is established with the metadata node through at least two primary router nodes and one secondary router node of the decentralized computing system for transmitting a stream of data packets, wherein the stream of data packets is divided into corresponding parts between the primary router nodes and the length of each transmitted packet is shorter than the encryption period, in each of the primary router nodes the IP address of the transmitting subscriber device is replaced with a primary temporary IP address when routing data packets, in the secondary router node the primary temporary IP address is replaced with a secondary temporary IP address, and the metadata node is the closest of the available metadata nodes in relation to the secondary router node; - in the metadata node: -- receive data packets with a request to perform a task from the transmitting subscriber device via an established encrypted connection; - divide the task into subtasks; -- assign at least two available execution nodes to each subtask; -- receive task-related data via an established encrypted connection from the transmitting subscriber device; -- distribute the received task-related data between subtasks; - send an encrypted portion of distributed data to each of the execution nodes according to the assignment of subtasks; monitor the execution of each subtask by the corresponding execution device; and - provide the result of the task execution based on the execution of all subtasks either to the transmitting subscriber device via the established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node.
2. The method according to claim 1, wherein the task includes one of: a data storage task, a data processing task, or a data forwarding task.
3. The method according to claim 1, wherein providing the result of completing the task includes at least one of the following steps, in which: - transmit the result of the task execution based on the execution of all subtasks either to the transmitting subscriber device via the established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node; or - provide access to the result of the task execution based on the execution of all subtasks either to the transmitting subscriber device via the established encrypted connection, or to another subscriber device that has previously established a new encrypted connection with the metadata node.
4. The method according to claim 1, in which the provision of the task execution result is carried out using task identifiers.
5. The method according to claim 1, in which the specific number of assigned actuator nodes is specified in the transmitting subscriber device by setting a redundancy coefficient.
Citation Information
Patent Citations
Dynamic secure communication network and protocol
RU2769216C2
Secure file sharing method and system
US20200274711A1
Multi-decentralized private blockchains network
US20210234702A1
Systems and methods for generating secure, encrypted communications across distributed computer networks for authorizing use of cryptography-based digital repositories in order to perform blockchain operations in decentralized applications
US20220318907A1