US2021044426A1PendingUtilityA1
Aws identity - blockchain for cloud based audit services
Est. expiryJun 28, 2036(~9.9 yrs left)· nominal 20-yr term from priority
Inventors:Matthew John Campagna
H04L 9/50H04L 63/123H04L 9/3239H04L 9/3247H04L 9/0643H04L 67/1097H04L 9/0637H04L 67/02
57
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
One or more systems implement a plurality of blockchains to track event data. The plurality of blockchains are arranged in tiered form, and the content and/or integrity of blockchains in higher tiers depends on, or at least derives from, the content and/or integrity of the blockchains in lower tiers. Depending on the specific structure and implementation, assurances, verifications, and the like may be provided for services and other resources using such blockchains in a repeatable manner.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method, comprising:
under the control of one or more computer systems configured with executable instructions,
generating audit logs pertaining to operations of a computing resource operated in connection with the one or more computer systems;
committing the audit logs to one or more blocks of a private blockchain, the blockchain accepting the audit logs on a condition that the audit logs are accompanied with a first proof of work that implies a first integrity verification of the audit logs;
committing data associated with the one or more blocks of the private blockchain to a provider blockchain, the provider blockchain accepting the data on a condition that the data is accompanied by a second proof of work that implies a second integrity verification of the data; and
providing, to a requestor, one or more integrity assurances for at least a subset of the audit logs based at least in part on generating a confirmation of the second integrity verification.
2 . The computer-implemented method of claim 1 , wherein the first integrity verification is iteratively generated using a cryptographic hash function until the result meets one or more criteria set for the private blockchain, the one or more criteria set such that the iterative generation of the first integrity verification is of a specified computational difficulty.
3 . The computer-implemented method of claim 2 , wherein the cryptographic hash function is SHA-256.
4 . The computer-implemented method of claim 2 , wherein the data includes the first proof of work.
5 . A system, comprising:
at least one computing device configured to implement one or more services, wherein the one or more services are configured to:
generate a first private blockchain to capture event data associated with the one or more services, such that the first private blockchain captures the event data only if integrity of the event data is verified;
capture the event data in one or more blocks of the first private blockchain;
process the one or more blocks of the first private blockchain to generate verification data for the first private blockchain, the verification data excluding at least private data within the event data;
cause the verification data for the first private blockchain and second verification data of a second private blockchain to be committed to one or more blocks of a provider blockchain, the provider blockchain only allowing commission of data thereto if integrity of the data is verified; and
provide an interface that, in response to a verification request, performs one or more integrity verification operations on the one or more blocks of the provider blockchain to determine integrity of the subset of the event data.
6 . The system of claim 5 , wherein the integrity of the event data is verified by inclusion of a first proof of work indicating completion of a first set of one or more cryptographic computations.
7 . The system of claim 6 , wherein the integrity of the data committed to the provider blockchain is verified by inclusion of a second proof of work indicating completion of a second set of one or more cryptographic computations.
8 . The system of claim 7 , wherein the first set of one or more cryptographic computations involves a first cryptographic hash function and the second set of one or more cryptographic computations involves a second cryptographic hash function.
9 . The system of claim 6 , wherein the integrity of the event data is verified by authenticating the event data via inclusion of a digital signature as a condition for inclusion in the one or more blocks.
10 . The system of claim 9 , wherein inclusion of the signature reduces a required difficulty of the first set of the one or more cryptographic computations to be completed, relative to exclusion of the signature.
11 . The system of claim 5 , wherein the event data includes audit logs generated from operations associated with the one or more services.
12 . The system of claim 5 , wherein the one or more services are further configured to process the one or more blocks of the first private blockchains by including at least a proof of work submitted with the audit logs and included in the one or more blocks.
13 . A non-transitory computer-readable storage medium having stored thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to at least:
configure a multi-provider blockchain to accept blockchain data on a condition that the blockchain data includes or is accompanied by verification information indicating integrity of the blockchain data; cause a plurality of providers to generate blockchain data, each provider of the plurality of providers generating a respective portion of the blockchain data, each respective portion of the blockchain data being associated with a respective private blockchain of a plurality of private blockchains that, by virtue of including event data within the private blockchain, implies verification of integrity of the event data; cause the plurality of providers to each submit blockchain data associated with the respective private blockchain for addition to the multi-provider blockchain; generate the verification information based at least in part on the submitted blockchain data; and provide an indication regarding integrity of the submitted blockchain data based at least in part on an outcome of storing the submitted blockchain data in the multi-provider blockchain.
14 . The non-transitory computer-readable storage medium of claim 13 , wherein the verification information includes one or more outputs of a hash function as computed against one or more blocks of at least a subset of the plurality of private blockchains.
15 . The non-transitory computer-readable storage medium of claim 14 , wherein the one or more blocks include one or more outputs of an integrity check of at least a portion of the plurality of private blockchains.
16 . The non-transitory computer-readable storage medium of claim 13 , wherein the plurality of blockchains are associated with operation of one or more services provided by the plurality of providers.
17 . The non-transitory computer-readable storage medium of claim 13 , wherein the verification information is generated using at least a cryptographic hash function.
18 . The non-transitory computer-readable storage medium of claim 17 , wherein the cryptographic hash function is SHA-256.
19 . The non-transitory computer-readable storage medium of claim 13 , wherein the indication is provided via an application programming interface provided by the computer system.
20 . The non-transitory computer-readable storage medium of claim 13 , wherein the outcome of storing the submitted blockchain data is a verification of a proof of work associated with the storing of the submitted blockchain data.Join the waitlist — get patent alerts
Track US2021044426A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.