论文标题
AgapeCert:具有审核,自动化,自动化,增强隐私的认证框架的oblevious智能合约
AGAPECert: An Auditable, Generalized, Automated, Privacy-Enabling Certification Framework with Oblivious Smart Contracts
论文作者
论文摘要
本文介绍了Agapecert,这是一种可审核,广泛的,自动化的,具有隐私性的,确保认证的框架,能够在私人数据上执行可审核的计算并报告实时汇总认证状态,而无需披露基本的私人数据。 Agapecert利用可信赖的执行环境,区块链技术和基于图形的API标准的新颖组合来提供自动化,遗忘和可审计的认证。我们的技术使具有隐私意识的数据所有者可以在自己的私人数据上在自己的环境中在自己的环境中运行预先批准的智能合同代码,以生成私人自动化认证。这些认证是可验证的,纯粹的可用数据功能转换,使第三方可以相信私人数据必须具有必要的属性才能产生结果认证。最近,已经提出了多种用于供应链的认证和可追溯性解决方案。这些通常遭受重大隐私问题的困扰,因为它们倾向于采用“共享,复制的数据库”方法:网络中的每个节点都可以访问所有相关数据和合同代码的副本,以确保完整性和达成共识,即使在存在恶意节点的情况下也是如此。在这些需要全球协调的认证背景下,Agapecert可以包括一个区块链,以确保订购事件,同时保留核心隐私模型,而在数据所有者自己的平台之外未共享私人数据。 Agapecert贡献了一个开源认证框架,该框架可以在任何受监管的环境中采用,以使敏感数据保持私密,同时启用可信赖的自动化工作流程。
This paper introduces AGAPECert, an Auditable, Generalized, Automated, Privacy-Enabling, Certification framework capable of performing auditable computation on private data and reporting real-time aggregate certification status without disclosing underlying private data. AGAPECert utilizes a novel mix of trusted execution environments, blockchain technologies, and a real-time graph-based API standard to provide automated, oblivious, and auditable certification. Our technique allows a privacy-conscious data owner to run pre-approved Oblivious Smart Contract code in their own environment on their own private data to produce Private Automated Certifications. These certifications are verifiable, purely functional transformations of the available data, enabling a third party to trust that the private data must have the necessary properties to produce the resulting certification. Recently, a multitude of solutions for certification and traceability in supply chains have been proposed. These often suffer from significant privacy issues because they tend to take a" shared, replicated database" approach: every node in the network has access to a copy of all relevant data and contract code to guarantee the integrity and reach consensus, even in the presence of malicious nodes. In these contexts of certifications that require global coordination, AGAPECert can include a blockchain to guarantee ordering of events, while keeping a core privacy model where private data is not shared outside of the data owner's own platform. AGAPECert contributes an open-source certification framework that can be adopted in any regulated environment to keep sensitive data private while enabling a trusted automated workflow.