Confidential Total Ordering Service for Blockchain Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Decentralized blockchain networks face challenges in achieving consensus and managing ordering services, particularly due to security risks, technical expertise requirements, and compliance issues, especially when third-party ordering services are involved, leading to potential exposure of sensitive information and vendor lock-in.

Innovation Solution

Implementing a confidential total ordering service (TOS) with multiple TOS gateways that generate and split symmetric keys, allowing only key shares to be distributed among participating organizations, ensuring secure encryption and autonomous operation without exposing unencrypted transaction information, even when a third-party manages the service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized database is used for transaction processing, then security and ease of management are improved, but decentralization and vendor lock-in risks are worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddecentralization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the centralized ordering service into multiple distributed TOS gateways that participate in a consensus mechanism. Each gateway holds only a portion of the encryption key (key share), and no single gateway can access unencrypted transaction information alone. This segmentation enables decentralization while maintaining security through distributed key management and consensus-based ordering.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If third-party ordering services are used, then technical expertise requirements are reduced, but security risks and vendor lock-in are worsened

Engineering Contradiction:
Improvetechnical expertise requirementsVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent enables organizations to operate their own TOS gateways autonomously, managing their own key shares and participating in the consensus process. This self-service approach eliminates dependency on third-party ordering services while maintaining ease of operation through standardized protocols and automated key management. Each organization controls its own gateway, reducing security risks associated with external service providers.

Inventive Principle:
Principle #25Self-service

3Reliability

If symmetric keys are distributed among multiple gateways, then security and resistance to collusion are improved, but key management complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management service as an intermediary that facilitates secure key share distribution and reconstruction. This service enables gateways to obtain their key shares and reconstruct symmetric keys without direct peer-to-peer key management complexity. The intermediary handles the cryptographic operations and coordination, reducing the burden on individual gateways while maintaining security through distributed key shares.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If unencrypted transaction information is exposed for ordering service, then processing efficiency is improved, but confidentiality and security are worsened

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidconfidentiality
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies different quality characteristics to different parts of the system: TOS gateways operate with encrypted transaction information to maintain confidentiality, while the consensus mechanism and ordering process work with cryptographic proofs and key shares that do not require decryption. This local quality approach allows processing efficiency to be maintained through optimized cryptographic operations while confidentiality is preserved by never exposing unencrypted sensitive data during the ordering process.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11736456B2Consensus service for blockchain networks
Publication Date: 2023.08.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11736456B2 patent drawing
  • US11736456B2 patent drawing
  • US11736456B2 patent drawing

AI summary

A computer-implemented method for establishing consensus in a blockchain network, a total ordering service for a blockchain network, and a computer program product. One embodiment may comprise providing a first total ordering service (TOS) gateway for an organization in a blockchain network, generating a symmetric key at the first TOS gateway, splitting the symmetric key to generate a plurality of key shares, and distributing at least one of the plurality of key shares to a second TOS gateway in the blockchain network. The TOS gateway in some embodiments may have read/write access to a shared message queue that makes messages available to each other TOS gateway in the blockchain network. Some embodiments may further comprise recovering the symmetric key by requesting one of the key shares from the second gateway in the blockchain network, and reconstructing the symmetric key using the one of the key shares.