Devreal

Trust but verify: a missing link between IoT and a trustworthy, computationally verifiable reality

Event: Blockchain: Rethink Trust

Rethink Trust 2018: Roman Shaposhnik, Trust but verify— a missing link between IoT and true reality

Recording: Rethink Trust 2018: Roman Shaposhnik, Trust but verify— a missing link between IoT and true reality

thank you so much for the great introduction thank you so hi everyone today I will be talking about something that is slightly different because all of the previous speakers you know talked about you know the blockchain itself right you know the different applications of the blockchain I mean like Alex said I'm coming to this ecosystem from slightly different vantage point basically I've been in sort of enterprise computing for all of my life you know helped with some of the database systems but I think maybe a few years ago we started noticing something that was pretty unusual and I think I'm going to share it with you and hopefully I can maybe impart some of the excitement that we see in this next wave of computing so with that let me actually give you this obligatory slide how many of you have seen this slide before or something similar to it okay one two three okay so let me at least very quickly go through it right you know this is this typical positioning of you know different industrial revolutions you know that has happened throughout human history and what's interesting is you know everybody's agreeing that right now we're the phase of the fourth Industrial Revolution and the key thing that makes it different from you know the previous one which is basically sort of the electronics and you know computers and automation is that all of a sudden we're connecting cyber and physical so cyber physical systems finally become reality and I would venture to say that you know when you say cyber physical physical is the new aspect to it right because we've been doing cyber for quite some time if you think about it though our whole industry is basically this constant movement between difference you know phases of how we think about computing rates and this pendulum has been swinging you know ever since I guess 50s maybe even before that just a few milestones that we all can recognize because I don't think you know any of us is old and after actually you don't remember the mainframes you know maybe some are but we definitely can recognize the 80s right you know alias was a period when the enterprise computing appeared you know Microsoft Windows was the sort of epitome or a personal computing right you know everything was actually if you think about it sort of decentralized because people had computers and desktops they started digitizing their business they moved from paper to digital and then all of a sudden cloud computing happened right so all of the same powers started being concentrated in the data center most of the applications were delivered as software as a service we now have this enormous concentration of power between Google Amazon Microsoft you know some of the smaller cloud players and it feels like it's impossible to do anything that would radically challenge that but I actually submit to you that yet another set of computing is actually already here we just don't notice it in fact there was a gardener report a few years ago and they have calculated that the amount of compute power available outside of a data center started to dwarf the amount of compute power available inside of the data center and think for it you know think about it for a moment again all of these giants of the industry concentrating power in their data centers and yep that is in nowhere close to the amount of computing that's available just all around us and I'm talking about things that are you know here in the city right you know things that attach to the light poles things that are attached to the you know traffic lights you know small computers helping automate the factory chemical plans you know stuff like that so we call it the edge computing you know some people used to call it AI UT I don't like the term iut because somehow it invokes the consumer aspect of it so I like the industrial aspect of it much more so let's call it h computing and let's agree that what it means is it has to be ubiquitous it has to be real-time and it has to be cyber-physical so all of these compute devices actually have to be attached to something that can either change the real world or get input from the real world and if you assume this viewpoint then it's actually very easy to understand why the model that we all are used to in the cloud computing space will not actually work out for us anymore so the model so far has been that even for the IOT even for the smart connected devices the best thing that we can do is just get the data points and send them to the cloud as quickly as possible because remember all of the real compute is actually still happening in the cloud so what we're proposing is what you know I would like to introduce to you is that I think you know starting basically from about now a lot of the same computation will actually start happening the edge itself right so the day of tomorrow will be yes there will still be some data points you know going back to the cloud but you will see a lot of autonomous behavior you know happening on the edge itself because you know at the end of the day the real world is autonomous right you know you don't want your smart light to not operate you know because your Smart Switch actually has to send data through the Amazon Cloud and only then your smart light can actually switch on and off so if you assume that this is what's going to happen then the real question that you will be asking is like well but does the technology that would actually allow us to do this type of autonomous behavior exist today and the good news is that we actually have bits and pieces of that technology so on one hand I mean today we do have all of them compute operating somehow right you know this is known as the menos embedded computing and embedded computing started as a really tiny devices you know with real-time operating systems you know highly specialized software development cycles you know pretty much very difficult to impossible to upgrade or update so that exists today on the other hand we actually have the cloud computing which we all now know in love today and this is the software development cycle that makes us so productive as developers because we no longer even have to think about servers right you know we think about virtual machines we think about docker containers sometimes we don't even think about those because we think about lambda you know service as a function and all we focus on is our business logic right you know the rest of the concerns have been taken care of by the infrastructure itself so what if we actually try to take the best of both worlds you know take the embedded sort of close to the real world you know a viewpoint and mesh it with the kind of application development strategies that we've developed for the cloud that I would call a cloud native edge and that's in fact what sort of the company that I am now associated with is trying to do so the mission of the company division you know for the company is to create a new edge economy that allows application to run anywhere so that's a pretty bold statement but the mission is maybe even bigger we would like to be the largest compute company on earth without owning any infrastructure the same way that uber is the largest taxi company on earth without owning any taxis so I will tell you a little bit about what we're building because I think it's actually very relevant to how blockchain sort of factors into this conversation so the stack that we're building basically starts with the hardware so when all the hardware company we're a software company but we start with a central hardware that is capable of things that can guarantee trust because we want our objective reality to be trustworthy and gene actually gave a really good point when he was talking about this vault and he was talking about your driving DNA so it is absolutely important for us to have the vault that can actually store the information but ask yourself how does that information get into the vault to begin with how can you make that information trustworthy how can you make sure that whatever is plugged into your car is actually being really plugged into your car and being driven you know throughout your neighborhood as opposed to you actually giving it to your really careful body you know so that he or she improves your driving records right you need to have that trust with reality and the only way to make the trust happen as we all runs you know through the blockchain exercise is to actually make it computationally based but in order for it to be computationally based you actually have to have hardware that is essentially capable of providing you some of the cryptic cryptographic guarantees that you cannot really easily temporal with so we start with a hardware layer then on that player we basically provide essentially a layer of virtualization so virtualizing the hardware so that we can then build a layer of the platform itself and that would be very similar to let's say what Amazon or Google are running in their data centers to essentially enable all of the virtual machine management and docker management and all of this other stuff there is basically an operating system that's running on the hardware itself and we're kind of building the same so you could compare us you know very roughly because it's definitely not the same - let's say core OS but the biggest difference between us and core OS is the physicality remember I told you that the you know proverbial fourth Industrial Revolution is all about cyber physical so so far all of the technologies like Korres have been developed in the understanding that they will actually run at the data center data center is not a physical you know physically specific and in fact Dale Sentra is full of commodity computing as far as I can tell because every single server in that Trek is about the same the network doesn't really change the physical security is guaranteed by a guy you know with the machine gun in front of the data center it's a very different environment compared to the real world let's say of a city like Amsterdam where these computers are basically you know first of all they're everywhere second of all they're available to essentially physical attacks by people just walking to them with USB sticks or just trying to steal them and third of all I mean the networking infrastructure that connects them together changes all the time because it may be connected to the ethernet today and to some kind of a ZigBee or radio technology tomorrow so that changes all the time so designing this operating system layer with the physical sort of guarantees with the physical understanding in mind is very important to us and of course on that layer you know you have the apps in the very same sense that you would have them in a cloud computing environment you know the apps can migrate and just very quickly to finish this off we're targeting all of the compute devices you know that you can possibly think of in this cyber physical space so we can run on a board that is seven bucks you know based on arm you know all the way to a real server and we kind of give you the platform right you know so the platform basically provides you with security management networking and a lot of that you know today is done by various vendors in the space which is connecting it all together so the platform is there for you to use to utilize but are we done are we really done well even if we give you that platform I think the question that remains how can these applications communicate with each other and one way to answer it is you know well the same way that applications have communicated with each other for ages which is you know using tcp/ip and you know doing maybe HTTP requests and that's one way of doing it you know that's sort of the distributed side of it but we also feel that it would be extremely important for these applications to essentially communicate without knowing the other party right because again we're trying to build this trustworthy environment and in a trustworthy environment you actually knowing who the party is with whom you communicating is not necessarily a good property of the system a lot of times you need that communication to be anonymous between essentially the providers and consumers over certain service without disclosing the identity of those providers and consumers so the edge trust model is absolutely different and on the edge you essentially have these applications connecting the three parties right so first of all they're obviously developers you know these are guys like myself gals like you know you in the audience we're just developing software for these systems right but there's also essentially on the edge asset owners you know these are the people who have you know pretty enormous investments in the physical infrastructure so an asset owner for example could be a telco company right telcos are going to roll out 5g pretty quickly and that will be an enormous expenditure of you know capital on their part and they will be stuck with these assets you know for years and years to come so obviously they would like to be able to monetize those assets as much as you know they possibly can and in order for them to do so they actually have to make sure that those assets can not only do what they are meant to do which is basically route your phone calls but also do some of the additional functions and that's why they need access to developers but third of all you actually have businesses that are essentially trying to connect the two and make sure that you can innovate using the assets that the asset owner brings to the table the code that the developer brings to the table but then businesses are taking risk on essentially delivering the next generation applications that can actually make money you know and how the money changes hands in this ecosystem is actually very important so we feel that this ecosystem needs to be an edge market economy and as a quick aside I would actually anybody who is doing crypto or blockchain I would highly recommend reading this book that on a surface has nothing to do with any of that it's called debt the first 5,000 years it's actually written by a really good guy who is not an economist he's actually an anthropologist the insight you will get from it about you know what Trust really is I just tremendous so read the book now obviously in order to manage that trust were using blockchain you know that's that's pretty easy to understand I think the blockchain is to decentralize what Internet was to connect it remember the applications used to just talk to each other on the internet and that was the big revolution that sort of the previous industrial phase right now we're doing the centralized so again the blockchain is the same communication medium for the next generation types of applications by the way again is a quick aside you know people ask me well is it really that new and it's kind of not really that new I mean you can kind of sort of have the same concept with even relational databases if you really squint but I think you know some of the cryptographic properties that are being built into the block chains are making all the difference and of course you know the nice thing about block chains is that there's so many to choose from so I will very quickly run through this section because not enough time but just give you a couple of pointers so obviously there is you know the usual suspects then there is hyper ledger which Chris talked about you know quite nicely but we actually found something that caught our eye specifically for the kind of applications that we envision to be running on the edge and that's ears so yours was really interesting to us and I highly recommend you guys check it out because it's one of the first block chains that really took it to the next level without really trying to be just a specific block chain for one particular use case so what makes it interesting to us by the way it's not maintenance so these people are now trying to run main that that's fine there's all sorts of issues with you know governance and whatnot we're actually interested in the code not necessarily the main net because we feel that our customers will be actually running the networks themselves not necessarily participating in the maintenance so what's cool about ears so first of all the free usage meaning that you actually as an originator of the transaction you are not supposed to pay like any guess you know like you do today in the cerium so that's free the system takes care of you know managing managing the compute power you know in other ways low latency it's pretty nicely done you know again for the kind of edge applications that we have in mind it also has basically the ability to essentially communicate between the different sides of the blockchain so you can kind of have you know built right into the protocol this idea of you know having a public blockchain and a whole bunch of private blockchains rights and those will be communicating with each other but what's also very interesting to us is this focus that they have on essentially secure execution of code and that's really what made me a believer in yo s Baker's when I read their positioning statement it was clear to me that they were positioning themselves as an operating system rather than a blockchain right because if you read it I mean this is something that would be applicable to like a general purpose operating distributed operating system there is no feel anything blockchain eor cryptocurrency or anything like that about a thread and that's what we're trying to leverage now the secret sauce behind us is obviously delegated proof of stake you know that's what makes all of the properties that were interesting to me possible I will not get into the details but check it out you know it's basically based on this idea that you have only a select group of block producers to anyone to be specific you know they're validating all the blocks but how those 21 gets selected so you don't have a centralized system you know that's actually the secret sauce that makes the whole thing go go pretty well so with us do we have enough to build what we're trying to build no there's still missing bits and pieces and that's what I'm actually working on with the team you know in my company there's also other teams working on it if any of this is interesting to you I guarantee that I will not be able to explain all of it but I need to give you just enough of pointers so you can catch me after the presentation and talk to me about you know any of this so whirlwind tour of what we're building what we're investing in so first of all we need to build a decentralized identifier you know and make it reliable and robust so we are leveraging a lot of research that's done out of the hypo ledger foundation Indy but we're applying it to ears and trying to figure out how this we can go together so with the centralized identifiers you know we need to again ensure those properties that the two participants in the transaction will disclose as little about each other as possible so and again you know one of the keynotes you know there was a really good example of how you can you know buy a pack of cigarettes without really disclosing your age you know that's exactly what I'm talking about and you know there is waste of doing it again this is a slide taken out of the indie presentation so I think they're doing pretty well we're also investing in secure enclaves based code execution because again if we're running arbitrary code because again yes to us is a distributed operating system right so we're no longer talking about smart contracts we're talking about literally running you know to recode in the system so in order to do that you have to do two things you have to protect the code from the operating system but you can also have to protect the operating system from the code the second one is much easier because that's what been happening in the data center you know for essentially at least 10 15 years by now the fact that in a public cloud coca-cola and Pepsi can run on the same computer given to them by Amazon is a testament that you can actually protect applications from each other and you can protect the host operating system from the application the reverse is actually much more difficult how do you protect the application from a malicious operating system so we are trying to solve it you know based on the cpu capabilities and there is an amazing work done by the graphene SGX team you know and also John are with Costco from Project Gollum that's actually you know a picture taken from Chris slide there's still major challenges remaining and these actually hardware challenges because what we're doing here we're trying to use Intel CPUs to essentially give us the first chain of trust so the CPU itself is now cryptographically signed you know think of it this way and from that root of trust we're trying to bootstrap the rest of the system but it's actually very difficult to do it in small steps and Intel is doing an absolutely right you know set of like they're doing actually the right job in essential sort of disclosing it's very progressively but I think we need to push on them to make it a little bit more open and a little bit more reliable and if we do all of that then what will happen is we will actually be able to build the holy grail of cyber-physical systems which is Oracles Oracle's are something that connects cyber and physical these are basically the systems that essentially inject physical properties of the real world into this blockchain that we're all operating on because the blockchain itself is completely basically virtual right you know there's absolutely nothing physical about it so if it needs to know the driving speed of your car because you know that's the part of the DNA that you know gene was talking about your driving DNA that information has to cut it has to come from an Oracle so these are that's what Oracle's are there's also a subset of Oracle's you know some people call them you know from time to time hardware PCs you know so the ledger company that's actually doing cryptographic Hardware evolved is you know calling them this way so the two terms can be used interchangeably we're trying to do at Cedella we are trying to actually get away from dedicated hardware that's what Leger is building to basically give you the capability of essentially running Oracle's on any absolutely any kind of an edge system so that's what we're really trying to build and with that you know I apparently ran out of time but I would like to leave you with this quote if there's anything that's a breakthrough next-generation you know set of things that are going to happen in the blockchain space I think that's basically the Oracles so keep an eye on Oracle's keep an eye on hardware PCs because I think that will be the last missing link between really building this truly cyber-physical system that will connect the reality with the virtual world thank you so much