Blockchain Overwatch
Abstract
Various embodiments of the present technology provide a distributed overwatch system that allows transactions with government-grade privacy and security. The security and privacy can be achieved by a combination of distributed trusted proxies, to which anonymous users connect with the overwatch of a variety of network security engines. The structured ecosystem provides mechanism for the blockchain to be monitored by an overwatch capability combining big data analytics, intelligent learning, and comprehensive vulnerability assessment to ensure any risks introduced by vulnerabilities are effectively mitigated. The system may include multiple proxy servers geographically distributed around the world. Each proxy can be associated with local network security engines to probe and analyze network traffic. Each proxy can mask sensitive data (e.g., personally identifiable information) within the transaction before it is stored. Various embodiments can interface with most blockchain or distributed ledger technologies that support multi-signature transactions and/or smart contracts.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
a distributed multi-ledger system (DMLS) having a set of block producers that can validate transactions to be added to a distributed ledger; a proxy assigned to a group of endpoints,
wherein each proxy endpoint within the group of endpoints routes all transactions and communications through an assigned proxy; and
an overwatch agent configured to receive network traffic routed through the assigned proxy and to identify threat vectors.
2 . The system of claim 1 , wherein the proxy includes a masking agent to identify and encrypt sensitive data within the transactions before transmitting the transactions to one of the set of block producers.
3 . The system of claim 2 , wherein the proxy includes a routing agent to randomly select, for each of the transactions, a block producer from a set of block producers to which each of the transactions is routed.
4 . The system of claim 1 , wherein the overwatch agent includes:
an ingestion interface to receive the network traffic; a monitoring engine to monitor the network traffic and identify threats; a machine learning engine to identify a baseline network model and classify network traffic; and an alert system to communicate threats identified by the monitoring engine to the proxy or DMLS.
5 . The system of claim 1 , wherein the transactions include cryptocurrency transactions.
6 . The system of claim 1 , further comprising one or more miners to tap the network traffic by passive tapping or inline tapping.
7 . The system of claim 1 , wherein the overwatch agent is further configured to assess both transaction data submitted by an endpoint for recordation on a blockchain of the DMLS, and a point of interaction with the blockchain of the endpoint.
8 . The system of claim 7 , wherein the overwatch agent is further configured to identify threat vectors in the absence of any intermission in routing transactions and communications.
9 . A system comprising:
a distributed multi-ledger system (DMLS) having a set of block producers for validating transactions to be added to a distributed ledger; a proxy assigned to a group of proxy endpoints,
wherein each proxy endpoint within the group of proxy endpoints routes all transactions and communications through an assigned proxy, and
wherein at least one proxy endpoint of the group of proxy endpoints connects to the assigned proxy as an anonymous endpoint; and
an overwatch agent configured to receive network traffic routed through the assigned proxy and to identify threat vectors.
10 . The system of claim 9 , wherein at least some of the transactions and communications contain personally identifiable information (PII) associated with users of proxy endpoints in the group, and wherein the overwatch agent is further configured to identify information in the network traffic constituting a PII misappropriation threat.
11 . The system of claim 9 , wherein the assigned proxy is configured to: classify content in the network traffic according to a generated policy score for the content, and add the content to a blockchain of the DMLS in response to a compliant policy score being generated for the content.
12 . The system of claim 11 , wherein the policy score is generated for the content by an artificial intelligence engine.
13 . The system of claim 11 , wherein the content is classified and scored according to a presence or absence of at least one of: copyrighted content, PII content, and indecent content.
14 . The system of claim 11 , wherein the assigned proxy is further configured to randomly select content from the network traffic for classification and scoring.
15 . The system of claim 9 , wherein the assigned proxy server is configured to anonymize at least some of the data of the transactions and communications by masking PII associated with a user of the at least one proxy endpoint.
16 . A system comprising:
a distributed multi-ledger system (DMLS) having a set of block producers that can validate transactions to be added to a distributed ledger; a plurality of proxy servers respectively assigned to endpoint groups,
wherein each endpoint within an endpoint group routes all transactions and communications through an assigned proxy server, and
wherein at least one endpoint of the endpoint group connects to the assigned proxy anonymously; and
an overwatch agent configured to receive network traffic routed through the assigned proxy and to identify threat vectors.
17 . The system of claim 16 , wherein the transactions and communications are routed from each endpoint through the assigned proxy server as messages to one or more block producers of the set of block producers.
18 . The system of claim 17 , wherein at least some of the messages contain personally identifiable information (PII) of a user associated with the at least one endpoint, and wherein the assigned proxy server is configured to mask the PII prior to routing the at least some of the messages to the one or more block producers.
19 . The system of claim 18 , wherein the assigned proxy server is further configured to mask the PII before transaction data contained in the at least some of the messages is recorded in a blockchain of the DMLS.
20 . The system of claim 18 , wherein the PII includes at least one of: a name, a credit card number, a telephone number, and a social security number.
21 . The system of claim 16 , wherein two are more of the plurality of proxies are assigned to one or more of the endpoint groups.
22 . The system of claim 16 , wherein the transactions and communications of each endpoint are routed through the assigned proxy in the absence of sharing data of the transactions and communications with proxies other than the assigned proxy.
23 . A system comprising:
a distributed multi-ledger system (DMLS) having a plurality of block producers for validating transactions to be added to a distributed ledger; a plurality of proxy servers in communication with the block producers, and endpoints of the plurality of proxy servers, and configured to determine whether a message sent by a proxy endpoint was intended for a respective proxy server,
wherein the message sent by the proxy endpoint is routed to the DMLS through an assigned proxy server selected from a subset of the plurality of proxy servers in response to determining that the message was intended for one or more of the proxy servers of the subset, and
wherein the assigned proxy server is configured to anonymize at least some of the data contained in the message prior to routing the message to the DMLS; and
an overwatch agent configured to receive network traffic routed through the assigned proxy server and to identify threat vectors.
24 . The system of claim 23 , wherein the message contains transaction data, and wherein the assigned proxy server is further configured to select one of the plurality of block producers for routing the transaction to.
25 . The system of claim 23 , wherein the message contains transaction data, and wherein the assigned proxy server is further configured to anonymize the at least some of the data contained in the message by masking personally identifiable information associated with a user of the proxy endpoint in the at some of the data.
26 . The system of claim 23 , wherein the assigned proxy server is further configured to select one of the plurality of block producers for routing the message to.
27 . The system of claim 26 , wherein the assigned proxy server is further configured to randomly select the one block produced from among the plurality of block producers.
28 . The system of claim 23 , wherein the subset of the plurality of proxy servers is selected from a fixed set of two or more proxy servers of the plurality of proxy servers.
29 . The system of claim 28 , wherein a composition of proxy servers of the fixed set is changed over time.
30 . The system of claim 23 , wherein the subset of the plurality of proxy servers is randomly selected from two or more of the plurality of proxy servers.Join the waitlist — get patent alerts
Track US2020204524A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.