We want to use the event of the 50th anniversary of the moon landing to give some updates on the KOSMoS project we are currently working on. Together with partners from the industry, university institutions and software development, we are continuously making one step after another to reach our goal, to deliver a blockchain-based solution which allows manufacturing companies to make use of dynamic leasing contracts with their customers, to get a valid and tamperproof maintenance documentation for their machines and to control the quality of the products based on predefined requirements.
In the beginning of July, teams from inovex, Ondics, University of Furtwangen and Datarella met at a workshop hosted and moderated by the Institute for Control Engineering of Machine Tools and Manufacturing Units (ISW) from the University Stuttgart. Once there, we discussed possible interfaces between the machines, the edge gateway, the analysis tool, the global KOSMoS platform, and the blockchain. We were able to agree on a basic infrastructure plan. Going into greater detail, we also agreed upon how data to be transferred from one instance to the next one. Based on this infrastructure we are currently planning to develop a pilot that demonstrates a data workflow from an oil-pressure sensor of a machine over the blockchain to the cloud platform. This pilot should be finished within a few weeks.
Decision on Blockchain Technology and Consensus Algorithm
Moreover together with the Frankfurt School Blockchain Center, we decided to use Hyperledger Fabric technology as the underlying blockchain for the KOSMoS project. In addition to the fact that Hyperledger Fabric is very suitable for consortial blockchains, another big argument for using Hyperledger Fabric is channel functionality. Assuming we want only one single Blockchain for all the use cases, we need to make sure that the privacy concerns of the industrial partners are being respected. In Hyperledger Fabric, it is possible to channel connections between organizations in such a way, that the transactions are hidden from other participants on the blockchain. This protects the data from unintended sharing with others.
Another advantage of Hyperledger is the separation of the consensus in three phases ‘endorsement’, ‘ordering’ and ‘validation’. This creates more transparency about the current state of the data and also enables pluggable consensus services for all phases. We assume that there isn’t full trust among all participants in the system, so we need a consensus algorithm that tolerates faulty states. Because of this, we decided to implement the RAFT Byzantine Fault Tolerance consensus mechanism. This is practical especially for the ordering part where there is the highest probability of mixing up the order of the transactions. Raft-BFT in Hyperledger also brings an out-of-the-box Kafka as a reference implementation that makes it highly compatible with the edge gateway technology.
The next steps are actually implementing the blockchain for the project and connecting it to neighboring systems like the edge gateway and the KOSMoS platform.
In casual discussions about blockchain and DLT it’s easy to mix up anonymity with pseudonymity. People often use the one term when they mean the other. There is a small but important difference we’ll explore in this post.
On the one hand anonymity describes the situation when the identity of an acting party is completely unknown. When the acting party is truly anonymous, there is no way to link the anonymous identity to a real world person. On the other hand pseudonymity describes the situation when an acting party has a consistent identifier that is not the real name but which might be linked with the real world identity of the person behind the pseudonym. As long as the link between the two isn’t known no one knows who the real identity behind the pseudonym is. But if those two can be linked, the identity is publicly known forever. An easy to understand example is the use of pen names by artists or authors who wish to address a market segment not usually associated with works published under their own names. Stephen King for instance published many books under his pseudonym, Richard Bachmann.
What does this mean for Blockchain?
Most blockchain technologies like Bitcoin or Ethereum rely on transparency and persistency. This means that the balance of every address and every transaction is publicly visible and irreversible. The addresses are the identifiers of the identities, and are anonymous until used. When used, the address takes on more pseudonymous characteristics. When a public / private key pair is created, the public address, is the pseudonym of the identity. But if the pseudonym got linked with the transacting party’s real world identity, all transactions will be linked to that identity.
Some blockchains have much more limited transparency and higher anonymity. Monero and ZCash are both examples of such chains. The identities used in those systems are mathematically non-identifiable, unreachable and untraceable due to the use of zero-knowledge proofs. These proofs only prove information about the fact that a transaction occurred without leaking any information about which actors or addresses took part.
Moreover blockchains can be implemented as either public or private chains. In contrast to public blockchains where information is publicly visible, private blockchains open the transactions only to parties authorised to use and see the information. This option is mostly used for blockchains operated between industry partners.
In the end analysis, most blockchains aren’t anonymous but rather pseudonymous. Addresses represent an identity that isn’t publicly known by default but theoretically could be linked. Despite this, zero-knowledge proofs offer a chance to keep the maximum level of anonymity possible in open blockchain ecosystems.
If you have more questions about anonymity and pseudonymity in blockchains, feel free to contact us.
People often ask us if our our blockchain solutions are energy efficient.There’s a lot of articles and good research out there indicating that the most famous blockchain, Bitcoin, uses as much energy per year as a small country. Let’s take a quick look at the myths and the reality in industrial settings.
The Myth: “All blockchains use large quantities of energy.”
The Reality: All blockchains DO NOT use large quantities of energy. Not all blockchains are the same and not all use cases require the same “blockchain”.
Bitcoin uses a consensus mechanism known as Proof-of-Work (PoW) to secure the network. While this approach has some advantages, there are other options for both, private and public blockchains, which don’t cost significant energy and still result in a secure network. For industry, it usually makes sense to utilize a private consortium blockchain with Proof-of-Authority (PoA) validators operated by consortium members. This approach effectively cuts the electrical consumption to almost zero. The level of decentralization, trustlessness and security that Bitcoin provides is way over the top for the vast majority of practical blockchain applications in industrial settings.
Additionally, even in situations where a public permissionless system is needed, there are a myriad of options regarding the choice of consensus algorithms which don’t consume exorbitant amounts of energy. Modern Proof-of-Stake (PoS) systems secure the network by requiring network validators to put up a “stake” (i.e. reserve) of tokens which can be automatically taken away or “slashed” if validator nodes attempt to cheat the system.
Bottom line: energy consumption isn’t an issue for us when working with industry partners. Consider the myth debunked.
Companies soon will be held responsible by the EU for environmental, social and governmental (ESG) impact. Hence, Datarella proudly presents its latest addition to the XSC Smart Wallet: Coins for Climate. With Coins for Climate, employees are automatically rewarded for saving CO2 – by walking in stead of driving.
As I am writing this, the window of my office is wide open: It is Friday afternoon, the sun is shining and the day is sporting a pleasant 25°C. A few years back, under the same conditions, we would hear the motors of Porsches and Ferraris howling up and down Munich’s most loved strip for fancy cars, the Leopold- and Ludwigstrasse. Not anymore.
Munich’s fancy cars are caught up in the jam that has been haunting Munich streets for the last years. Traffic. Has. Gone. Up. A lot. Earlier today, there were very different sounds to be heard on the street: The shouts and chants of a „Fridays for Future“ crowd, a movement of young people throughout the country and continent protesting against exactly what I am witnessing this very moment outside my office window: CO2 increase.
2019 is the year of climate. CO2 awareness has been around a long while, but never as present and pressing as now. Finally. Companies are being pressured by the European Union to address environmental, social and governmental (ESG) issues.
XCS Smart Wallet with “Coins for Climate”
We at Datarella felt it is time to let our XSC Smart Wallet play a role in saving CO2 emissions. The UN estimates that we have just 12 years to limit climate change catastrophe and ensure that our children can thrive on planet earth. The ‘Avoid-Reduce-Compensate’ approach to CO2 emission increases the awareness of climate-saving activities and can be embedded by everyone into their lifestyle.
This approach isn’t just for private individuals but also for companies. Even financial Institutions – specifically Asset Managers – will be held responsible by the EU for the ESG impact of their investment portfolio.
Asset Management companies are already starting to adapt to the new mindset by saving CO2 on an internal basis – such as having CO2 saving challenges. “Coins for Climate” helps your company increase awareness of climate-saving activities and fulfill the ESG-Criteria. Companies offering Coins for Climate to their employees help demonstrate CO2 awareness first hand:
Earn coins by saving CO2 every day.
Every walk instead of using a car counts.
Walk the last kilometer(s) to work.
Go to lunch by foot and burn some extra calories.
Take out the backpack and go shopping for daily needs without a car.
I will soon swing by the jams of the city on my bike to head home – arriving home an hour earlier than all I pass on the way. And I am very much looking forward to have bike rides included in Coins for Climate!
And for those of you who are anticipating Coins for Climax: It will be a long wait.
The number of and capital raised through ICOs have been in steep decline since mid-2018. Non-existing regulatory frameworks, fraud, and the decline of cryptocurrency prices were among the reasons. So called security token offerings promise to fill the gap approaches to compliant offerings based on actual assets. Will asset-backed STOs initiate a second wave of token offerings? How do typical STO projects look like, and where will security tokens be traded? For this meetup, we invited Richard Olsen, Founder, and CEO of Lykke as well as Dr. Markus Kaulartz, Senior Attorney at CMS Hasche Sigle to talk about the impact of security tokens on financial assets markets and regulatory aspects of STOs, respectively.
After the hype about ICOs in 2017 with billions of dollars raised, ICOs became less popular in 2018 due to missing regulatory frameworks as well as quite a number of fraudulent projects and the decline of overall cryptocurrency prices. ICO’s were initially attractive to projects because they enabled project teams to raise relatively large amounts of capital in an unregulated environment mostly based on white papers and promises of future project/product development. This changed rapidly following the beginning of the “Crypto Winter”.
Since then, security tokens have become more popular as token-based capital markets have continued to mature. In contrast to utility tokens from “traditional” ICOs, security tokens represent real physical value, such as a share in the company who issued them or specific assets like a power plant for instance. Security Tokens are comparable to actual shares on the stock markets, which represent partial ownership, have a price and sometimes provisions for profit sharing schemes such as dividends.
Richard Olsen
The first speaker of the event was Richard Olsen, Founder, and CEO of Lykke, a Swiss-based exchange for financial assets targeting B2B and B2C clients. He presented the development of the Lykke exchange and its transformation from a ‘prototypical startup’ to a mature ‘regulated entity with global potential’.
Richard calls himself the “grandfather” of crypto both due to his age and his experience. Richard can boast of decades of experience on the leading edge of global finance. He founded the forex company, Oanda in 1985 with the goal of forecasting financial markets using computers, before moving into innovating the provision of second by second interest payments and some of the earliest frequency trading facilities.
After an “Aha” moment in 2011 where he realized that bitcoin wasn’t just bitcoin but rather the first DLT and a concept which would transform the world, Richard began planning to build the Lykke exchange. Since Oanda’s board wasn’t ready to enter the world of crypto, Richard needed to raise money. Of course, he then looked to crypto. Once the market was ripe the Lykke STO was ready to go. While most projects were offering promises of future development in exchange for money as part of their ICOs, Lykke was already doing an STO. Few people can report from first-hand experience about the benefits and risks of executing a security token offering. Richard has done this three times in as compliant a manner as possible. Lykke’s first STO was with the LKK token which promises the delivery of Lykke company equity to bearers of the token. The first STO brought in 1.8 million USD. Further rounds included LKK-1y and LKK-2y forwards which raised more than 4 million additional USD.
Licenses, Liquidity and High-Frequency Trading
Richard brought up a very important question – namely, why were they allowed to sell these security tokens? In this case, they were selling their own equity. In order to provide an exchange for third-party security tokens, they will need an Organised Trading Facility (OTF) license which Richard sees as the next logical step for the company. OTF licenses are part of the MiFID II EU financial regulations and according to the Dutch Authority for the Financial Markets (AFM), OTF’s are intended level the playing field between the various venues for the execution of orders.
Specifically, once Lykke obtains an OTF license, they will be “a multilateral trading venue in which third-party buying and selling interests in bonds, derivatives or structured products are able to interact in the system in a way which results in a contract”. OTF’s have all the compliance regulations of an investment firm. In contrast to multilateral trading facilities (MTF) however, according to AFM, the “definition of OTF is intentionally broad, so that it can contain as many (future) forms of organized execution of transactions as possible”, which leaves space for innovation by exchanges and market makers such as Lykke.
Richard also discussed the macroeconomic aspects of the current financial system, in particular pointing out that liquidity and transparency are sorely lacking in much of the system and that blockchain-based solutions can make processes faster, easier and more transparent. Richard claimed, that tokenization will get more and more popular as soon as regulation catches up with the technology Everything that can be tokenized is going to be tokenized. One of the reasons for this is that tokenization enables risk sharing. Exchanging tokens instead of cash spreads the risk on multiple parties. That’s why it’s so important that any token be exchangeable for any other token. The more liquid the market the greater the likelihood that systemic risks are shared widely and unwound quickly before they grow to massively disruptive proportions.
He also dispelled a myth about high-frequency trading or rather clarified it with a metaphor. A question came up about whether or not high-speed trading was necessary or could be healthy for a system. Richard argued essentially that while the high-speed arbitrage-based trading of the past years was quite destructive, overall, trading in a financial system is much like blood circulation in a human body. Just as blood needs to move relatively rapidly through the body to enable waste removal and homeostasis, a financial system needs deep markets with lots of high-speed trading in order to clear the gunk and keep things competitive.
At the exchange level, he noted, the key is liquidity, which means that there should be enough tokens available to trade. This is currently made by bots all over the exchange business but there’s a lot of inefficiency in this model. Richard argues for well-designed matching engines which efficiency earn their keep. Moreover, people should be empowered through technology and crowd intelligence while staying within the legal system. Richard pointed out the self-regulatory success of Airbnb’s reputation system as a model for this kind of feedback system. He further emphasized that the laws and regulations have to be designed to incentivize the right behavior in spite of the corrupting effect of money.
In the same vein, Richard cautioned that at the moment it is difficult to determine which actors in the STO market are legit and which may be rather dubious. Essentially many say that they are issuing an STO but due to the lack of clear standards and transparency, it’s difficult to separate the wheat from the chaff. According to Richard, investors should pay attention to the jurisdiction of the asset, the reputation of the company issuing the asset, the rigor of the regulatory structures where that company is based and finally the question of where the secondary market for the asset takes place. If these aspects aren’t all covered within a reputable regulated environment, it’s pretty clear that something may be fishy with the STO or the platform involved.
If you want to learn more about Lykke and its products, go on their website or download the Lykke wallet.
Markus Kaulartz
Following Richard’s presentation, Dr. Markus Kaulartz presented the legal implications of STOs as the second speaker of the night. He is a senior attorney at CMS Hasche Sigle and specializes in IT-Law, IT-Security, and Privacy.
Markus firstly explained that tokens generally always incorporate a connection between the token and a representation of ‘something else’, for example, a voting right, shares or licenses. In the case of security tokens, the underlying asset is generally either equity in an enterprise or debt. The only exception to this is tokens and coins which serve a pure currency function with no underlying value underlying utility or asset.
First a Slight of Hand
As a result, a critical legal issue is the separation between the token itself and the rights “granted” by the token. It may be possible that the token and the rights associated with it might be separated.
Markus illustrated this with a simple example involving his physical leather wallet. For his example he let the leather wallet stand-in in for a security token and a 5 euro bill inside illustrate an underlying security. He noted that if he as the token issuer were to sell the wallet with it’s included right to the underlying security (and thereby dividends) to someone it might be possible that they could subsequently sell the token onward to a third party (Just the empty wallet) without also passing along the underlying linked security. That would result in a situation with two potential claimants for the dividends issued by the security issuer. In such a situation, the token issuer might end up paying a dividend twice.
One legal approach is to limit the original buyer contractually and prevent them from selling the rights to the underlying token to a third party without also selling the token. There is not however currently any clear solution to this problem at a systemic level inside the German legal system. It’s currently being discussed on both the legislative and regulatory levels but is not yet solved. Essentially you can issue a security token at this time but it’s not possible to definitively link the token to the security it represents without some significant contractual acrobatics. Markus is hoping for changes to the law which would essentially make blockchain transactions equivalent legally to a written contract transaction transferring ownership of a given security.
Prospectus or No Prospectus? That is the question.
Markus also outlined the legal options available currently for organisations who wish to issue a security token. The first significant question for prospective STO issuers is whether or not they will need a prospectus for the project. This prospectus contains potential risk factors, information about the issuer and a description of the security as well as deep financial disclosures about the issuing company. Such documentation must be approved by Bundesanstalt für Finanzdienstleistungsaufsicht – BaFin (German Federal Financial Supervisory Authority).
The process is pretty much the same as for issuing any other kind of stock or blond and is very expensive. Legal costs for producing such a document are likely to exceed 100,000 Euros at a minimum and getting a prospectus approved by BaFIN often takes months of waiting and working through numerous drafts prior to approval. The idea of a prospectus is that it is a document which contains reliable information regarding the risks and benefits of an asset and serves to protect “mom and pop” investors from unknowingly spending too much money on projects they know essentially nothing about. The major advantage for issuers if they choose to issue a security with a prospectus is that it can be rapidly “passported” into all other EU jurisdictions and traded in a compliant manner without further examination by the individual member states.
Exceptions, Alternatives and SPVs
The alternative to this process is to issue the STO under one of three exceptions designed to allow funds to be raised without offering consumers the “protection” of a prospectus. The rules are designed to protect the mass of average investors and there is some flexibility for situations which don’t have a substancial impact on everyday asset consumers.
Exception 1: If the token will be sold to less that 150 people. This is intended to support startups by allowing investment by small groups of friends and family.
Exception 2: If the token is sold exclusively to investors who each invest over 100,000 euros. Individuals rich enough to invest more than 100k are deemed to be defacto professional investors who don’t require state protection and “know what they’re doing”.
Exception 3: If the token sale raises less than 8 million euro. This is the exception under which most crowd investing happens. The logic is that at this level the damage from such an issuance can’t become significant at a structural level.
Lastly, Markus described the process of buying tokens and approaches to token issuance. Classical approaches follow the simple structure that the investor buys and gets the token and the right directly from the emitter who runs the business.
One new approach to token issuances uses a Special Purpose Vehicle (SPV) which has the right from the emitter to sale the tokens. For the issuer, this guarantees that the emitter is completely disconnected from the investor in a contractual manner. Despite the fact that this strategy reduces the risks for the token issuer, it increases the risks to the investor because the investor has no legal claim on the underlying assets being securitized. Markus essentially said that the use of an SPV could be a red flag for investors especially when in conjunction with the issuance of STOs from jurisdictions with lax regulatory oversight.
Another approach is to securitize subordinated loans either with or without an SPV. This is a common approach within the crowdinvesting area but it’s rapidly being adopted for STOs as well due to the relatively lax regulations on this type of debt and to the established procedures / regulatory framework for ordinary subordinated debt. Investors should be aware however that subordinated debts are services last behind all other commercial obligations in the case of a bankruptcy.
Thank you very much to Richard and Markus for giving these interesting presentations! Also, thank you to Deloitte for hosting our Meetup. Also, a big thank you again to our community for coming and participating! We hope you enjoyed the meetup and we encourage you to give feedback over the known channels!
Our next meetup will be about Blockchain in PropTech on July 23rd and we would love to see you again there!
The successful XSC Wallet for Android and iOS just got a new pedometer function! You can now incentivise your employees to move more and stay healthier with automatic coin rewards.
Everyone knows regular physical activity is good for your health. The more a person moves on a daily basis, the healthier she tends to be. Exercise helps to reduce stress, makes you happy and promotes mental as well as physical performance.
Using the XSC-Wallet with Pedometer results in more movement, more health and more fun at work:
Integrated pedometer gives feedback on your own activity
Stay motivated by earning coins when you meet your goals
Higher health, lower absenteeism due to sick days
Staggered goals reward the employee with XSC
Office workers quickly fall into the trap of living a largely sedentary lifestyle. Everyone wants healthy innovative employees but we all easily fall into just sitting in front of the computer all day. The extra kilos pile on and employee health and innovation are slowly eroded.
With the new pedometer function of the XSC Smart Wallet employees can be motivated to be more active both at work and during their leisure time.The XSC Smart Wallet uses sensor data to determine the number of steps a user takes over the course of the day.
The great thing about this is that after a certain number of steps, rewards are given out to the employee in the form of coins, which can then, for example, be exchanged for coffee, smoothies, or other benefits in the company cafeteria.
This simple and clear incentive encourages employees to move. In addition to the benefits of improved health and wellbeing, employees enjoy trading their coins in for perks like free coffee or fruit.
Employers gain an extremely cost effective tool for improving employee morale, encouraging innovation though greater employee fitness and engagement and perhaps most importantly by reducing employee absenteeism due to sickness.
On the basis of our humanitarian supply chain project with the UK Government, we explore how to combine security and UX best practices.
A question we have in each of our blockchain projects is that of the user-friendliness of having a decentralised architecture. In fact, it’s not only us having that problem but, according to a survey of 160 DApp projects in 2018 by the good people at Fluence Network, 75% of all mentioned new user onboarding as a major hurdle for adoption of blockchain. Additionally, the second biggest pain points for Dapp developers was “Bad UX of crypto”. In the following post I would like to show how we solved the largest of the issues with UX in blockchain, the key management.
For a couple of months, we have been building a Proof-of-Technology as part of the Frontier Technology Livestreaming (FTL) programme of the UK Department for International Development (DFID). The technology to be “proven” in this case is blockchain, specifically within the setting of humanitariansupplychain management — here’s a link to a medium post for more on the topic.
We’ve been advancing according to plan, successfully finishing our first sprint and working hard to finish the second. This will be the final sprint before we enter the live test phase, where we will field-test the system with a real life humanitarian logistics supply chain. The “real life”-test in this case will mean tracking a regular shipment of goods to a disaster-stricken area, using the application we are building. In this post, I’d like to share some of our experiences in trying to make blockchain as user-friendly and safe as possible, two goals normally seen as diametrically opposed.
Firstly, the most basic user-experience (UX) consideration when implementing a permissioned (more on what this means: here) blockchain solution is: if and through what medium does the user interact with the blockchain system? One can imagine solutions ranging from a completely “authoritative” system where the end-user is happily ignorant of any blockchain activities going on in the background, much like few internet users are aware of exactly how passwords are checked when logging in to a service, to products where each user is trusted (and in some cases required) to set up and run their own node, manage keys, interact through API calls and verify all activities. We attempt to find some middle-ground by reasoning about what our users are actually likely to use and appreciate in a system.
In our case, the users range from technologically savvy, well-connected DFID professionals with up-to-date hardware down to logistics service provider personnel with limited connectivity and first generation android smart phones. Since we are working in a PoT, with a relatively limited scope and time frame, we decided to make some assumptions on the user constraints. Roughly, we assume all of our users:
Speak and read English
Have a device (mobile or not) with an updated browser installed
Have a working Internet connection with sufficient bandwidth to serve a React-based web application (React is one of the most common web programming frameworks for UI’s)
These assumptions allow us to target a very wide audience, and to extend functionality in the future to cover, for example, off-line use cases.
We do this by building a progressive web application — meaning that it is reliable, fast and flexible enough to be used on mobile or desktop — with a simple login procedure to separate user types from each other. The application is hosted on our cloud provider which connects to a database as well as our — wait for it — blockchain!
This means that a logistics planner in the offices of DFID can access the web application by opening a standard browser typing in the address of the application in the URL window and can then login using his or her personal username and password. Similarly, a user on the “ground” can accept an order for his or her leg of the shipment by logging in to the application over a browser on a mobile device.
After having established the point of access for the users to the blockchain, we needed to determine which actions a user should be required or allowed to take with respect to the blockchain system. Our aim was to empower the users to have as much control of the most critical parts in the supply chain as possible. This was partly to ensure trust in the system — the purpose of having a blockchain is to remove a single point-of-control of the data — and partly to communicate clearly to the user exactly what information comes onto the blockchain.
We’re working with an Ethereum-based system, which allows for smart contracts. This means that we could encode large parts of the business logic, such as in the chain, if we would like to. But, the more functionality which is on-chain, the more users have to interact with the blockchain. The interactions which affect the complexity on-chain are operations where the user needs to add new information. More interactions lead to more signing of messages or transactions to the chain. More signing means more usage of the key pair of the user, which is mostly quite awkward and non-intuitive for users.
This is why we opted for a solution where the user still has full possession of the private key, and no one else can manipulate signed information posted to the blockchain by them. By helping the user generate a new key pair upon registration and then allowing them to store it locally on their device, we hope to give as much responsibility to the user as they would like, while still keeping security risks to a minimum.
So, when does the user have to sign transactions?
So, when does the user have to sign transactions? Exactly then, when custodianship is changed. The absolutely critical information, which must not be corrupted, is thereby secured the most. Custodianship change contains two steps: first, it needs to be handed over by the current custodian, and secondly, it has to be accepted by the custodian-to-be. Before both those transactions have been signed, custodianship still lies with the previous user. We try to make the “signing” as non-invasive as possible, by applying known procedures like “Username and password” plus a special key-file which needs to be provided by the user. It’s shown in a simplified form below:
A simplified chart of the authentication process.
The risk of such a system of user-controled keys is that the user loses the private key, but in our case, since we are working within a permissioned setting, there is a mitigation. Access to the platform is dependent on verifying the real identity of each user. Therefore, in the case of a lost key, the user has to re-register, but the information isn’t lost. The user will then have to re-verify the identity to regain access to the account, where a new key-pair can be generated.
In a future solution, there should not be a central authority to reset a password without the identity checks having been verified, but for the PoT it is acceptable.
We’ve now seen some of the challenges of usability we’ve been facing in building a humanitarian supply chain blockchain-solution within FTL. Usability and accessibility is an immense problem for blockchain in general. It strives to empower people but it is at risk of confusing and alienating people with complicated key management procedures and lacking interfaces. At Datarella, we don’t see the point in building technology that the end user can’t understand properly or feels uncomfortable using. Especially when the users are strapped for time, trying to help others in dire need, we have a responsibility to create technology which does not obstruct but enables our users.
Cryptography vs Cryptocurrency – one enabling the other
For many, the word ‘crypto’ brings Lamborghini’s, neckties with Bitcoin signs printed on them or really bad hip-hop, but up until some years ago, the original meaning was not crypto-currency, but cryptography. That is also the topic of this blogpost. Consider it a gentle introduction into a very specific branch of cryptography – zero-knowledge proofs (or ZKP) – and why blockchain has helped bring them back into vogue.
What are ZKP – intuition
So, let’s start off with the basics, what are zero-knowledge proofs? I’ll explain it through three common analogies with varying complexity, they all describe the same concept but appeal to different audiences.
1. This analogy is from StackExchange. Imagine your friend, Alice, tells you that she has a super-power. An amazingly useless super-power, but still. She can count all the leaves on a tree in your garden in front of your house in a few seconds! Of course, you don’t believe her, so you ask Alice to prove it. We’ve now created two roles that are omnipresent in ZKP, a prover (your friend Alice) and a verifier (you in this case). She proposes that she closes her eyes, you can then choose to either remove a leaf from the tree or not, and finally she can open her eyes. Now, to prove her super-power, she has to tell you whether or not you removed a leaf from the tree. If she’s wrong she failed to prove anything, but if Alice is right, you realise that she had a 1/2 chance to guess correctly and was just lucky. So you repeat the experiment, now if she’s right again, she would have had to have been right two times in a row, meaning her odds of being guessing correctly were 1/4. (At least assuming independence of events). This goes on and on until you are sufficiently convinced of her super-power being real. In this scenario, you didn’t learn HOW she does her magic counting of leaves, but you’re very sure that she know how to do it. There was ZERO KNOWLEDGE transferred from Alice to you regarding the procedure itself. Additionally, there was no, or a very small possibility for you, being honest, of not believing in Alice’s capability, and she couldn’t have convinced you without actually having the super-power. These three criteria are called ‘zero-knowledge’, ‘completeness’ and ‘soundness’, respectively, and are a part of all ZKP.
2. This one is from the booklet “Applied Kid Cryptography or How To Convince Your Children You Are Not Cheating” by Naor, Naor and Reingold. It relies on the game called “Where’s Waldo?” or “Where’s Wally?” in the UK-version. The goal of the game is to find the image of Waldo on a page filled with other things and figures. Let’s assume Alice and yourself are playing this game together. All of a sudden, Alice exclaims “I found Wally!”. Aggravated with jealousy you scream out “So prove it!”, (first the revelation of the leaf-counting super-power and now this!?). So how can Alice prove her knowledge of where Waldo is, without revealing to anyone else where he is? Simple, she takes a big cardboard with only a cut-out in the middle, just the size of a Waldo-image. As you close your eyes, Alice places the cardboard over the open pages of the Where’s Waldo?-book exactly so that only Waldo can be seen through the cut-out. You can verify that Alice knew where Waldo is, without learning where on the page he is. Again, this satisfies our three properties of zero-knowledge, completeness (you have to believe Alice found Waldo given the information she presented to you) and soundness (Alice couldn’t cheat by randomly placing the cardboard on the book except by being extremely lucky).
3. Now, my favourite example from a highly recommended blogpost by Jeremy Kun is more in the theoretical space. Instead of a difficult problem like counting leaves or finding Waldo, we now have the provably difficult and more formally defined problem of proving that two graphs are isomorphic. Let’s unpack that:
– A graph, G, is defined by a number of edges connecting the vertices of the graph. Thus a graph G = (V,E)
– Each edge can be represented as the tuple (u,v), where u and v are integers between 1 and the number of vertices of G, n.
– Given two graphs G = (V,E) and G’ = (V’,E’), they are isomorphic if there exists a couple of functions f: V->V’ and g: E->E’ such that f associates each value in V with exactly one element in V’ and vice versa. Correspondingly, g associates each value in E with exactly one value in E’ and vice versa.
source: Jeremy Kun’s blog on Math and Programming – https://jeremykun.files.wordpress.com/2015/11/gi-example.png?w=587&zoom=2
Intuitively, this means that graphs are isomorphic if we can transform one into the other by simply moving around the vertices, not adding or removing any edges and ending up with two identical figures. This is not exactly rigorous, but still somewhat accurate for our purposes.
Now, for the zero-knowledge part! Given two graphs, there’s no easy or efficient way of finding out if they are isomorphic. (If you find a way, let me know.) So, let’s say Alice knows that there exists an isomorphism between them, but she doesn’t want to reveal her isomorphism to you. She does this by taking e.g. G and mixing V. Then she sends you her newly formed isomorphic graph, called H. Alice additionally saves the permutation she did on G for later.
After having received H, you flip a coin with equal probabilities and depending on the outcome you give Alice a challenge. Heads, and Alice should provide you with the inverse, or backwards, permutation which gave her H. It should then give you G. If tails, Alice should provide you with her secret isomorphism, f composed with the permutation. This should now give you G’ when applied to H.
Given either of those permutations, you should now be able to verify that Alice possesses a ‘secret’ isomorphism. Additionally, you haven’t learned anything about the solution since you only received a uniformly random permutation or two uniformly random permutations composed which gives another uniformly random permutation.
Why ZKPs are interesting to blockchain
Ok, now that we’ve understood a bit what ZKP means, let’s see why it is interesting for blockchain technology. The most obvious area of application is of course privacy. Being able to prove something without having to reveal any information about the subject sounds like utopia for almost everyone with an eye on the current state of affairs in big data applications of corporates and states. A second, less obvious type of application is for scaling in blockchains. This relies on the fact that a proof of knowledge can be more succint, from a storage point of view, than the information it’s proving. Let’s look at some use cases of both application areas in more detail:
One of the first live applications of ZKP in blockchain for privacy was by ZCash – a cryptocurrency where the ‘knowledge’ being proven is that the sum of outgoing transactions are equal to the sum of incoming transactions (ZCash uses a UTXO model), that the sender has the authority to spend the coins being sent and finally that the private keys of the incoming ‘notes’ are effectively locking the whole transaction from being modified without the keys in question.
Another use case of ZKP for privacy is by Sovrin, who mainly uses regular public key cryptography and a fairly clever protocol to issue verifiable credentials such as “possession of a valid driver’s license in EU”. Then they apply a type of ZKP called accumulators to prove non-revocation of that very credential in a very succint manner. This was initially researched by IBM in the so-called idemix, back in 2007, but lacked an adequate platform to store the non-revocation lists in a persistent, trustless manner. Until blockchain arrived.
Generally speaking, ZKP can be used for a wide range of privacy-preserving applications, especially when it comes to the topic of identity, things such as range-proofs whereby it can be proven that one’s age is within a certain range (e.g. 18-65) without revealing the actual age. Or it can be proven that one is a resident of the EU without revealing in which country exactly.
One of the most pressing issues of public blockchains these days (and admittedly since some time) is that of scalability. Interestingly, ZKP may have a solution for this. Like ZCash, another privacy-focused cryptocurrency Monero implemented ZKP. However, Monero was using a different algorithm called RingCT to hide transaction information. It didn’t rely on the often criticised ‘trusted setup’ of ZCash (more here) but therefore had a very large transaction size resulting in low throughput. This was improved greatly by the application of so-called bulletproofs (also a type of range-proofs actually) in October 2018. This meant that the average transaction size was reduced by at least 80%, and the fees accordingly.
Even more extreme measures are being built by the coda team who aim to recursively compress an entire blockchain into a 20kB ZKP. Their CTO Izaak Meckler called it “A picture of a picture of a picture of a picture.”. It works by using a ZKP to prove the knowledge of a ZKP, which proves the knowledge of a ZKP, etc. This effectively leads to a constant-size blockchain which can be verified by anyone easily, not like in many existing public blockchains where the more users a blockchain has, the more difficult it gets for the average user to verify. Coda does, interestingly, not use ZKP at all for privacy. Yet.
We’ve seen a few examples to intuit what ZKP means and why they are interesting to apply in blockchain technology. It is part of what we are working on at Datarella, implementing industrial blockchain solutions for clients and in RAAY. If you would like to dig deeper into some of the topics we’ve learned about today, here are some resources:
Privacy is one of most central topics of this internet connected era. People want their private data to be protected from third parties which, for instance, resell the collected information to promote personalised advertisements or worse to do things like manipulate elections with what amounts to weaponised data science. In the past it was often the case that privacy was a mere afterthought when designing an online application. That’s not the case anymore. In the wake of scandals such as Cambridge Analytica, it has become increasingly clear that system design needs to put privacy front and center if we want to avoid dystopian outcomes in our society. Thus, “Privacy by Design” was the topic of our meetup on on March 19, 2019.
Our audience at the meetup “Privacy by Design?”
The first person we invited to give some insights about this topic was Andrew Tobin, Managing Director of Evernym. Evernym is a US-based software company which develops decentralised, self-sovereign identity applications. Andrew talked about how Evernym developed and open sourced the Sovrin protocol to manage the secure and private issuance, holding and verification of digital credentials in a decentralised manner.
By using Sovrin, anyone can verify claims made by identity owners including the following four aspects of data validity without any contact with the credential issuer. This eliminates the risk that anyone can draw a correlation about private activities of credential holders based on the claims they make to verifiers.
Who issued the data to the holder?
Was it issued only to the holder, and not to anyone else?
Has the data been tampered with between issuance and time of claim?
Has the issuer revoked the credential?
He also pointed out that Sovrin is not limited to human credentials making highly useful for the M2M economy. It can also be used to issue and verify credentials for organisations and things empowering proofs for stuff like part numbers of machine components, company records or tax returns.
Sovrin enables the storage of verifiable credentials in a digital wallet. Compared to a physical wallet, there are a number of additional benefits. Backup- and recovery functionality, the ability to revoke credentials remotely and a selective disclosure functionality for the individual data points making up your identity are all made possible using this technology. The trouble with paper credentials is that they’re pretty stupid. Passports can get lost or stolen, if you show your drivers license to someone you have to show them the entire document, not just the relevant details, and if an issuer wants to revoke a credential they’re pretty much out of luck when using a traditional paper identity document. With self- sovereign identity all of these scenarios are no longer problematic.
If you want to learn more about Evernym, their solutions and tools behind it, check their website or Andy’s slides here and here.
Andrew Tobin presenting Sovrin, a self-sovereign identity solution
The second speaker of the event was Kevin Leuthardt the new Steward of Governance Working Group of the European Blockchain Association (EBA). He briefly presented the founding of the Working Group Governance in the EBA and explained how decentralised organisations can rely on a suitable governance model.
If you are interested in governance in decentralised organisations and have a law background we would appreciate if you could take a couple of minutes to fill out this survey. Thank you very much in advance.
Kevin Leuthard presenting an update on the EBA Working Group Governance
As the final speaker of the day, we invited Dr. Elad Verbin to the stage. Elad is a Berlin-based computer scientist specialising in blockchain technologies, algorithm engineering, and predictive modelling. In blockchain space, he works on blockchain filesystems, governance, and macro-cryptoeconomics. At this meetup Elad shared some insights about “Privacy on the Blockchain – Zero Knowledge Proofs and their Future Use”.
First of all he explained why people should care about privacy on the blockchain.
The first reason to do so is that privacy on the blockchain is broken. In the early bitcoin days people were buying pizza online with the same addresses they used to buy drugs on Silk Road. Even if it wasn’t clear to the users at the time, what is clear now is that the buyer of the pizza is also the buyer of the drugs. There’s a whole industry of players such as Chainalysis and BitCluster cropping up with products dedicated to tracing these transactions out there “in the clear”.
The second reason to care about privacy of the blockchain is that private computation is necessary for Web3. It is not desirable to for all transactions made on the blockchain to be public. That notwithstanding we still want the benefits that data availability provides. As a result we’re increasingly turning to computation on encrypted data, for example homomorphic encryption, to restore privacy while maintaining the availability of data sets for computational tasks.
The third reason is that more privacy establishes more trust in the system which automatically leads to more shared information and therefore more value all around for everyone.
The second aspect, Elad pointed out is the so called Secure Multiparty Computation (SMPC).
In SMPC, every player in the system learns only about their own input into the system and the output of the system without knowing the input of the other players so that privacy comes first. The special thing about SMPC is that it can be done for any function given enough time for computation and every task that can be computed can also be computed securely.
In an ideal world there would be a trusted middleman who could compute those functions. The middleman could collect all the input of the players and simply publish the result back to the players. We all know however that the trusted middle man approach usually fails due to the untrustworthiness of the “man in the middle”. SMPC protocols functionally simulate the trusted middleman scenario without actually requiring any trusted party.
As a third point he introduced applications of private computation.
Private computation has been used in a number of productive contexts already and it is starting to seep into consumer applications like such as the chat platform Telegram. The same goes for Zero Knowledge Proofs nowadays.
As a first practical example, Elad presented a case study about Sugar Beet Auctions in Denmark from 2008. The problem there was, that the participating parties in sugar beet auctions needed a secure technical means of simulating a “trusted middleman” without actually having such a party and also without revealing private bids or the demand curve of the commodities purchasers. After deploying a SMPC-protocol-based auction system, the parties only knew how much they each sold without learning anything about the overall auction results while still arriving at an efficient market clearing price at the market level.
Based on this success governments started using private computation for radio frequency spectrum auctions resulting in more efficient and more fair auctions for these public goods. Telecommunication companies didn’t have to make the prices paid for spectrum rights public and simultaneously the state received an efficient economic outcome from the auction.
Another potential use case is for private computation would be an algorithmic redistribution of wealth whereby individuals could make their finances and demographic information available in an encrypted format for algorithmic analysis. The idea here is that if the data were made available due to the advent of widespread trust in private computation, algorithmic design including reinforcement learning, control theory and optimisation theory could give us substantially better results and public policy than is available today. In the future, there will be more and more libraries available for private computation. Compared to today, the computation will also be cheaper and faster.
The last major point in Elad’s presentation was regarding practical issues in adopting this technology.
The first issue is the challenge of replacing the trusted middleman with a protocol. How is the function f defined and how to keep the privacy over time?
The second issue is the speed of SMPC. The speed of SMPC is pretty slow right now. But compared to some years ago it became significant faster.
The third issue is the current general lack of trust in SMPC. It’s a big challenge for a new innovation to gain trust of the users. It takes some time for people to trust innovations and adapt to new technology.
Dr. Elad Verbin presenting Zero Knowledge Proofs and their future use
We want to thank the speakers for their very interesting presentations at this Meetup about “Privacy by Design?”. We also want to thank Deloitte for hosting our event at their facilities and of course we want to thank our guests for coming to our meetup and asking high quality questions.
We would appreciate seeing you again at our next meetup about “The State of Secutity Token Offerings” on May 21st, 2019.