Devreal

Managing confidential data on a public blockchain.

Event: Blockchain: Rethink Trust

Rethink Trust 2018: Draltan Marin, Managing Confidential Data on a Public Blockchain

Recording: Rethink Trust 2018: Draltan Marin, Managing Confidential Data on a Public Blockchain

hello everyone I'm going to talk to you about how to manage confidential data in a context of the public blockchain so my name is Trotter marine I'm the CTO of uniform Bay and I hope you enjoyed the conference by new cipher because I'm going to keep talking about proc story encryption just in a different perspective I'm going to present a use case a business use case where we are tracking confidential data and how we've managed to hope we manage to to protect the data to give control access on who can see the data so just introduce you to our use case Unicom Bay is a blocking solution for the asset management industry so what we're doing were tracking trades that are several management people will be doing on a day to day basis and and to explain you why this is interesting imagine you're an investor and you have a lot of money you want to invest that and you want someone to take care of these investments so you're looking for an asset manager but when you're comparing your different options you all you can use to choose and to to select who will be handling your money our performance metrics of asset managers or tracked records but the thing is that in classical investment these track records and performance metrics come from the asset manager themselves so you know if you can trust what they are saying if they tell a return rate of 40 percent a year or so on you have no way to to know if it's true or not so in order to in order to make a safe decision in general an investor will go to a big player because it's a big name because it's safe so that means that smaller players the smaller asset managers have buried it's very difficult for them to to access the market right so the idea is that we're going to track what other asset managers are doing and from that compute key indicators of their performance of their returns and indicators that you can use and you can trust and as an investor you can you can choose your asset manager or based on on actual numbers that you can trust right so this make better informed decisions for investors and for asset managers it opens a larger market of investors right so the kind of data we're tracking is day to day trading data so every time an asset monitor will be doing the trading operations buying or selling and stock or bonds or whether they will put the data to a blockchain okay so we we can follow their portfolio strategies we can know the composition on the opening that's our portfolio but all these are very confidential data no one wants to make this data public right at the same time we want to put that in a blockchain so we can build trust but the data is very sensitive for a world market so we need to put that in a blockchain because we need to know that when we are computing performance indicators we're considering all the data not just the gains that the asset managers are made but also the losses right we so from a technical standpoint what we are want to guarantee is data integrity access to this data and access control to is data and doing so in a way that's secure right so the main two options we were considering for our solution was okay either a private blockchain where we will be keeping a control of who can access this box chain or a public blockchain where all the data is available to everyone but we will publish only encrypt the data so we will manage with this encryption who can actually see the data right just on that a little note on scalability because we're saying we're putting a lot of data on a blockchain we are working on the internal network and as you all know there are scalability issues mainly on performance this time to the confirmation cost of grating data main and for our case what we are going to write it's a huge amount of data in blockchain standards right so we explore different solutions of scalability we know there are channels there is plasma this Jordan what we're going to do is we're going to use his sidechain where we're going to dedicate its secondary chain for asset managers so they can write data on a day to day basis and we're thinking that to the main chain pretty little so the main the the large amount of data will remain in this secondary chain and then we will publish only a small amount of data to the to the main chain mainly key performance indicator so that means we are saying we're publishing encrypted data but then how can we do to use this data right we have two main main problems here the one is how can we do computations on this data and guarantee that this competition has are correct and the other is how we can control the ISIS who can go and see the the actual data so for the first part were using secure multi-party computation is with the enigma project for those who are not familiar with that is say I'm not going very deep into that because not the subject of that but we're separating the computation of metrics into very atomic pieces very atomic chunks of calculation that we are distributing to a network of nodes that will perform computations and then aggregate their final result so we were able to complete matrix where no one had at no point access to the full data at all time nodes are just accessing very little pieces of of meaningless data and performing very little computations so however we can guarantee that the final result corresponds to the data we are were using the first place the second point is about how we can control didn't really who can access the encrypted data and there is new cipher to the road to their rescue so in classical encrypting in a classical encryption scenario alice is sending a message to Bob right and both Alice and Bob have private and public keys they send Bob sent the public key Alice encrypts the data and Bob's give the message and can't decrypt using the the private key right but in this scenario a nice knows she's sending a message to Bob right so what happens when Alice doesn't know who's she sending a message to right this is exactly our use case investors are going asset managers are going to input data in a blockchain but they don't know who will need to access this data later on right so it can be new investors subscribers to their portfolio strategies the thing is at the moment of posting the data we don't know who this will be say set up being Bob is Charlie who's who's requesting access to the data so the burning version would be okay how to do we could send a private key to Charlie but we know sharing a private key is never a good idea we could decrypt the data and we encrypt again for Charlie but then Charlie would know that is the same data or not that Alice inputted introspect so this is where were using proxy encryption the thing is Alice will publish encrypted data to the blockchain then charlie request access this is an investor or subscriber asking to follow the strategy of the asset manager and then Alice will emit a proxy encryption key every encryption key and it will this key will be sent to a proxy that will perform their own encryption so the proxy will take the encrypted message the original encrypted message that's published in the blockchain and producing encrypted message and said before the purchasing never knows what is the contents of this message right so with this we are able to track trading data into a blockchain and then the investor can be sure that the data he is receiving is coming from this broad chain through a proxy and and encrypt it for him in a way that we can track the whole the whole chain so the investor can can be sure that he's accessing the actual same data that they that the asset manager originally person right we can do that in a way that the investor has access to all the data in a given scope life could be a time span or could be for some of the asset manager strategies or so on but on this scope the investor has access to everything and can check all gain and losses and all trading operations right so that's good for for controlling who can access the data but what about revoking access so the things we're producing Rhian Krypton keys that can be revoked and this green caption keys will be splitted I said before over different notes and we can ask for the vocal of these encryption or encryption keys and that give us the the flexibility to grant access and to revoke access later on right when a when an investor is no longer working with it with an asset manager the asset manager can say okay I can revoke your key so you will no longer keep following my studies right so just to put all that together we're creating a system where we're building trust between investors and asset managers where we can compute key metrics that can be trusted this is with the enigma solution then that we can guarantee that confidential data remains private and controlled and and that we can manage to to grant and revoke access to that to the data and all that in a context of a public blockchain with cryptography solutions so thank you for listening we got to answer any questions you have and you can contact either me or or Dennis the CEO of incorporate and thank you [Applause]