EP4463776A2 - Digitale konsolidierung - Google Patents

Digitale konsolidierung

Info

Publication number
EP4463776A2
EP4463776A2 EP23740767.1A EP23740767A EP4463776A2 EP 4463776 A2 EP4463776 A2 EP 4463776A2 EP 23740767 A EP23740767 A EP 23740767A EP 4463776 A2 EP4463776 A2 EP 4463776A2
Authority
EP
European Patent Office
Prior art keywords
information
digital
document
unique
objects
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP23740767.1A
Other languages
English (en)
French (fr)
Other versions
EP4463776A4 (de
Inventor
David Leigh Donoho
Matan GAVISH
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Digital Consolidation Inc
Original Assignee
Digital Consolidation Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Digital Consolidation Inc filed Critical Digital Consolidation Inc
Publication of EP4463776A2 publication Critical patent/EP4463776A2/de
Publication of EP4463776A4 publication Critical patent/EP4463776A4/de
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/50Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3218Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using proof of knowledge, e.g. Fiat-Shamir, GQ, Schnorr, ornon-interactive zero-knowledge proofs
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash

Definitions

  • Embodiments of the invention teach that there is a way to create a shared information reality which is radically new, and radically different to any other in history. This way can be implemented using presently available information technology – computer networks, hardware, and software. It offers a wide array of advantages and improvements over current practice and provides very substantial value and benefits. This way is the inevitable next stage of the digital revolution; In fact, all around us are subtle signs that we are already well on our way towards this next stage. Embodiments of the invention address the problem of reliable and trustworthy information exchange, which can enable enduring multiparty cooperation, from first principles.
  • This problem is complicated, in part due to its distinct but partially overlapping aspects: (i) an algorithms and software aspect - how to properly record, store and communicate information properly in digital form; (ii) a formal / mathematical aspect - as verification and validation of information and facts, for example in an accounting process or in a bureaucratic process, follow formal structures; and (iii) a human-interface / human-computer interaction aspect – since, when all formal and information-technology aspects are said and done, trust in information is still a human decision, and the primary factors determining the value of information exchange are still based on human-machine and human-information interactions.
  • Figure 3 shows the two axes of information flow: a cross-stakeholder (“horizontal”) information flow and a source-to-user (“vertical”) information flow.
  • Figure 4 shows examples for human-readable results.
  • Figure 5 shows the irreversible trajectory of digital consolidation.
  • Figure 6 shows horizontal and vertical information flows using different shared information realities.
  • Figure 7 shows the Tower of Babel by Pieter Bruegel the Elder.
  • Figure 8 shows properties of data under the current state of the art.
  • Figure 9 illustrates horizontal digital fragmentation on the two-axes diagram:
  • Figure 10 shows an accounting ledger from the early days of double-entry bookkeeping, side-by-side with a modern accounting software user interfaces
  • Figure 11 shows industries along the vertical information flow, where the purpose of many services is to reconstruct vertical information flows lost due to digital fragmentation.
  • Figure 12 shows information from the annual report of Enron, Inc for the year 2000.
  • Figure 13 shows an account statement from Madoff Securities International.
  • Figure 14 compares the World Wide Web, document shared reality, digital fragments and unique digital reality.
  • Figure 15 compares digital information transfer under digital fragmentation with digital information transfer with UDR, the latter being an enabler of digital consolidation.
  • Figure 16 compares vertical (source-to-user) information flow using digital files to the vertical information flow using UDR.
  • Figure 17 shows the different unique digital objects created during a Verifiable Execution of a procedural program
  • Figure 18 is a concept illustration that shows how the method of verifiable computational results creates a permanent digital explicit unambiguous connection between machine program code used to generate important results, the execution event in which the results were created, and the publication where the results are presented, thus consolidating the vertical information flow from data through processing to presentation of results.
  • Figure 19 shows the explicit permanent digital connection made using the method of verifiable computational results between published results, underlying data, and underlying code.
  • Figure 20 is an illustration of computational science workflow under current state of the art, where data is loaded from a local file and result is exported to a local file.
  • Figure 21 shows a schematic representation of the stages of vertical information flow in the field of scientific research and publication in the state of the art.
  • Figure 22 shows a schematic representation of the stages of vertical information flow in the field of scientific research and publication under the discipline of file-based reproducibility, in which the data files and code files are preserved for published results.
  • Figure 23 is an illustration of computational science workflow using verifiable computational results.
  • Figure 24 shows a schematic representation of the stages of vertical information flow in the field of scientific research and publication under the verifiable computational results method.
  • Figure 25 is a schematic example of typed citation constrains that may be defined in SICCL.
  • Figure 26 provides a schematic illustration of the SICCL script execution on a collection of six information objects, for the purpose of automatic verification of certain ICC conditions by the collection.
  • Figure 27 describes a method for information presentation on user interfaces that is decoupled from preceding steps in the vertical information flow.
  • Figure 28 shows how machine-readable and human-readable universal identifiers on various user interfaces link the presentation of a digital object to the actual digital object in Unique Digital Reality.
  • Figure 29 is an illustration of Visual Trustworthiness and a collection of unique digital objects that create Visual Trustworthiness for a document, such as a financial report.
  • Figure 30 compares scientific publications with and without visually recognizable “verifiable result” symbol and machine-readable code.
  • Figure 31 compares entangled information and visualization in the current state-of-the-art with detached information and visualization in embodiments of the invention.
  • Figure 32 provides a schematic illustration of the concept of Outlets.
  • Figure 33 describes an example of the process of ad-hoc information representation on a user interface.
  • Figure 34 shows a Jacket providing an amalgamated publication of several different information objects
  • Figure 35 is an illustration of the notion that visually recognizable machine-readable and human-readable codes in publications and user interfaces turn the publication into an entry point into a much larger body of machine-accessible information objects, namely the collection of unique digital objects – representing data, processing, and results - underlying the presented results.
  • Figure 36 shows an interaction between a user and a document using an Augmented Reality (AR) device.
  • Figure 37 shows examples of possible verifiable interactions between a personal identification device and other digital devices.
  • Figure 38 describes possible uses of personal identification device in conjunction with unique digital reality.
  • AR Augmented Reality
  • Figure 39 shows various possible ways to establish verifiable consent using user Interfaces and/or personal identification devices
  • Figure 40 shows an example of the creation process of a verifiable interaction digital object, demonstrated through the case of interaction achieving verifiable consent.
  • Figure 41 describes a process whereby two individuals, each using a device (such as a smartphone, a smart watch, a screen, or a personal identification device) interact with the same information object (such as a document presented in hard copy or on-screen).
  • Figure 42 shows a protocol for verifiable interaction in a preferred embodiment.
  • Figure 43 describes an example for co-signing an information object using an Outlet, verifiable interaction, and personal identification device, in which a contract is signed (executed) using an on-screen Outlet and personal identification devices.
  • Figure 44 describes an example for co-signing an information object using an Outlet, verifiable interaction, and personal identification device, in which a contract presented using a hard-copy (physical document) Outlet is signed (executed) using personal identification devices with user interface.
  • Figure 45 shows different objects represented as documents (Contract and Appendix) and related interaction (consent) objects in UDR, which may be used to verify that both parties agreed to both the contract and the appendix.
  • Figure 46 shows several possible counterparties, to which an individual may elect to grant access privileges to their personal information stored as unique digital objects on UDR.
  • Figure 47 shows examples of data assets created by an individual.
  • Figure 48 shows certification of geographical location using the cellular tower triangulation method.
  • Figure 49 is a schematic view of an illustrative method for determining location of a stationary or mobile user, e.g. and agent of a UDR device at one or more times, based on GPS satellite data.
  • Figure 50 is a schematic view of an illustrative method for determining location of a stationary or mobile user, e.g. and agent of a UDR device, based on continuous monitoring of location and a continuity of location at subsequent times.
  • Figure 51 shows possible uses of Omnicodes in various objects in physical, augmented, and virtual reality.
  • Figure 52 describes an example of injection of artificial friction into a process that has been digitally transformed and automated using UDR.
  • Figure 53 shows artificial friction for cyber-security using an air-gapped apparatus.
  • Figure 54 shows a method for verifiable Standard Query Language (SQL) requests using an SQL witness service.
  • Figure 55 is an illustration of spreadsheet software plugin turning specific cells in a spreadsheet into verifiable unique digital objects that may be embedded in other documents while maintaining audit trail.
  • Figure 56 shows a financial report document that contain machine-readable and human- readable unique identifiers of unique digital objects, whose payload is a verifiable spreadsheet where numbers in the report were computed.
  • Figure 57 shows an implementation of the method of verifiable HTTP Query using a UDR-enabled HTTP proxy.
  • Figure 58 shows verifiable HTTP request using an HTTP witness service.
  • Figure 59 describes a method for UDR-based ownership over media items.
  • Figure 60 shows an illustrative timeline for a UDR-enabled media asset, by which the creation, modification, ownership, sale, or transfer of the UDR-enabled media asset is readily accessed.
  • Figure 61 shows examples of physical object and devices and their mirror unique digital objects in UDR.
  • Figure 62 shows a physical object and its user interface, available through its unique digital object twin.
  • Figure 63 shows two related physical objects, and a connection between their mirroring unique digital objects.
  • Figure 64 shows a physical device and its user interface as it is accessed through various AR-enabled devices.
  • Figure 65 shows a schematic representation of bulk processing and data mining of all measurements and user interactions related to mirroring unique digital objects.
  • Figure 66 shows a unique digital object mirroring a physical object, and images of the physical object presenting its unique identifier.
  • Figure 67 shows the connections enabled by an embodiment of the invention between physical objects (documents, objects, and devices), their mirroring unique digital objects in UDR, the data measured by them, and user interactions with them.
  • Figure 68 illustrates the merits of the described embodiment for devices, objects and documents.
  • Figure 69 shows a typical document exchange using current state-of-the-art: PDF documents, e-mail, instant messaging, cloud sharing services, e-signing services, and so on.
  • Figure 70 shows the aftermath of the process described in the previous figure, including the applications and platforms used, and the copies left in various systems.
  • Figure 71 shows a schematic view of a possible appearance of an NGD, with its various features and properties.
  • Figure 72 shows the main elements of a Next Generation Document.
  • Figure 73 provides another view of the structure of a Next Generation Document, emphasizing the notion that the different elements complement each other.
  • Figure 74 is an artist’s illustration of one of the fundamental merits of an NGD over state- of-the-art: the fact that NGD is new document medium that combines legacy document form with highly advanced digital capabilities.
  • Figure 75 shows a metaphorical description of the creation of a Next Generation Document using presently familiar notions.
  • Figure 76 shows a possible user interface for creation of a contract Next Generation Document, based on a print-dialogue user interface.
  • Figure 77 shows a possible user interface for creation of an invoice Next Generation Document, based on a print-dialogue user interface.
  • Figure 78 shows a possible design for access control of a Next Generation Document from within its user interface.
  • Figure 79 shows a schematic representation of different Twins of a Next Generation Document, showing that all Twins refer to the same unique digital object in UDR.
  • Figure 80 shows an Outlet of a Next Generation Document presented on the screen of a laptop computer.
  • Figure 81 shows the appearance of a Next Generation Document opened in a document- reading interface without access permissions.
  • Figure 82 shows a possible design for Augmented Reality (AR) user interface of a Next Generation Document.
  • Figure 83 demonstrates the concept of a uniform document interaction surface and a uniform document experience.
  • Figure 84 provides another illustration of the concept of a uniform document interaction surface: the user interface as it appears on Augmented-Reality enabled glasses, tablet device and desktop screen is the same.
  • Figure 84A shows a user interface design for a Next Generation Document form, which guides a form user, authorized to fill the form, through specific fields the user is asked to fill.
  • Figure 84B shows an alterative user interface design for a Next Generation Document form, which presents a form user, authorized to fill the form, with a questionnaire collecting the necessary information required in the form.
  • Figure 84C shows a user interface design for Next Generation Document, which summarizes the validity and trustworthiness status of the document in a single symbol (lower left corner); and itemizes the various high-level (or overall) notions of validity, verifiability and trustworthiness implemented by the Next Generation Document.
  • Figure 84D shows a user interface design for Next Generation Document, which offers a detailed, itemized visual status of a specific notion of validity, verifiability or trustworthiness implemented by the Next Generation Document.
  • Figure 84E shows a user interface design for Next Generation Document, which shows low-level (or maximally detailed) complete report of a specific aspect of specific notions of validity, verifiability, and trustworthiness information a detailed visual status of specific notions of validity, verifiability and trustworthiness implemented by the Next Generation Document.
  • Figure 85 illustrates the difference between state-of-the-art digital documents (e.g., PDF files) and Net Generation Documents, in terms of availability to information technology systems.
  • Figure 86 shows a possible interface design for setup and monitoring of a simple automated document workflow, from within the Next Generation Document user interface.
  • Figure 87 provides an illustration of automated document workflows enabled by Next Generation Documents.
  • Figure 88 illustrates the use of Next Generation Document in real-time compliance verification
  • Figure 89 shows an interconnected graph of Next Generation Documents unique digital objects citing or referencing each other.
  • Figure 90 shows a possible user interface design for Next Generation Document that refers to a geo-location unique digital object.
  • Figure 91 shows a possible user interface design for Next Generation Document that refers to a voice recording unique digital object.
  • Figure 92 shows a possible user interface design for Next Generation Document that refers to a spreadsheet unique digital object, and specifically, cites a cell from the spreadsheet in the document.
  • Figure 93 shows a possible user interface for signature interaction, when signing a Next Generation Document on any medium, including desktop document reader, smartphone application, Augmented Reality interface overlayed on a hardcopy document, and so on.
  • Figure 94 shows a few futuristic movie sets, such as Star Trek, which do not show a single piece of paper, or a single pen, or even a single pocket.
  • Figures 95 through 102 describe “A Day at the Hospital” – an illustrative story used to demonstrate the merits of embodiments of the invention, as well as possible products and services that flow from possible embodiments.
  • Figure 103 shows some uses of a digitally transformed identity.
  • Figure 104 shows a few types of personal information which, once digitally transformed, are controlled by the individual who generated them.
  • Figure 105 shows medical information areas that, once transformed, become objects in digital shared reality.
  • Figure 106 describes digitally transformed insurance.
  • Figure 107 is a block diagram illustrating an example of a processing system in which at least some operations described herein can be implemented.
  • the timeline of Digital Transformation essentially consists of only three major milestones: • The invention of digital information storage and digital information processing; • The invention of the Internet and World Wide Web (WWW); and • The invention of mobile Internet, smartphones, and cloud computing.
  • Revenue of Internet companies has dwarfed revenue of personal computing and enterprise software companies.
  • Even as, unlike physical products, the marginal cost of software is near-zero, enterprise software may still be considered old-school business by today’s standard.
  • Non- orthodox astronomical valuations for losing companies e.g. WhatsApp and other social media startups
  • Horizontal information flow to be the flow of information between different stakeholders.
  • the horizontal flow enables insight.
  • Vertical information flow to be the flow from objects, states, and events (including physical, financial, legal, and IT reality), to information objects representing these objects, states, and events, to processing of these information objects into results, into presentation of results in human-readable form.
  • the vertical flow enables cooperation, because by tracking the vertical flow certain information objects can (potentially) be verified and achieve the status of facts, placing the objects, states, and events they refer to, or the results of processing they refer to, in consensus. In most societal process, the flow happens in both these axes at once – for example, processing is applied to information objects that originate from different stakeholders.
  • the first link along the vertical information flow chain is between objects, states, and events to their representation in information objects.
  • symbols in information objects encode meaning that represents – mirrors - objects, states, and events.
  • Relations between information objects e.g. a contract citing a property title, mirror relations between the objects, states, and events they mirror. The more objects, states, and events information objects can mirror, the more they can be used to achieve cooperation.
  • Information Processing Computation vs Information Consistency and Compliance (ICC):
  • ICC Information Consistency and Compliance
  • Vertical Digital Consolidation leads to a fully digital shared information reality where the vertical flow – the links between observed information objects to the information objects deduced from them and to the processes that were used to deduce from them, and from deduced information objects to their human-readable visual presentations – are explicitly exposed in digital format.
  • Vertical Digital Consolidation revolutionizes consensus, cooperation and trust that are enabled by digital information exchange. Indeed, cooperation and consensus are achieved by traversing the vertical flow to verify results that are presented for human eyes. Consolidation of the steps along the vertical information flow – from capturing an event and representing it as a digital information object; to processing a collection of information objects; to presenting it on a user interface –enables efficient and comprehensive verification of information exchanged by human users.
  • Horizontal digital consolidation leads to a fully digital shared information reality, in which information objects (both observed and deduced) are permanently accessible to arm’s-length stakeholders (with access privileges) through a uniform interface.
  • Horizonal Digital Consolidation will revolutionize artificial intelligence, Business Intelligence (BI) processes, data mining, and data science. Indeed, insight is achieved by traversing the horizontal layers across the boundaries between stakeholders and information sources. Consolidation of the horizontal layers – even just the horizontal layer of information objects - will unlock value of astronomical proportions for training AI models and obtaining insight from digital information. Simultaneous Horizontal + Vertical Digital Consolidation.
  • Digital Consolidation across both axes of information exchange ushers in a world where measurements, user interface interactions, digital representation of objects, states and events, computations used to process digital information, the results of these computations, and information presentations on user interfaces – across arm’s length stakeholders - are all unified under a single, coherent discipline of information technology.
  • Digital Consolidation across both axes of information exchange thus creates and enables markets, products and services which defy the current limits of imagination. This last statement is factual rather than melodramatic - indeed, the Google search engine, and more generally the full impact of the “Internet+WWW digital consolidation”, is today’s everyday ordinary reality, but lie well beyond the 1980’s limits of everyday imagination.
  • Horizontal consolidation enables mining all the world’s digital information for insight; vertical consolidation enables automatic verification and radically efficient cooperation.
  • the mathematical product of horizontal and vertical consolidation means the following: there is a systematic, software-accessible digital footprint to all capturing of objects, states, and events into digital information objects; to all processing applied to digital information objects and their inter-dependencies and interconnection; to all presentation of information objects on user interfaces. This enables services such as searching for all publications that used, directly or indirectly, a certain dataset; and getting answers to questions such as: • What would happen if I applied my algorithm to their data? • What would happen if I applied their algorithm to my data? • How would results presented in a scientific paper change if I change tuning parameters?
  • the blockchain can support small-scale horizontal digital consolidation, e.g. between a small group of stakeholders transacting limited amounts of information, but not large-scale digital consolidation. Importantly, the blockchain does not have anything to do with vertical consolidation or any notion of integration of the information flow from reality to presentation; it is focused on the horizontal information objects slice.
  • One evidence that the blockchain frenzy is riding on a vague feeling that “something big is coming” and that this vague feeling indeed points to digital shared information reality (and not to, decentralization) is the recent hype around Nonfungible Tokens (NFTs).
  • NFTs Nonfungible Tokens
  • the digital file an elementary concept in all operating systems, Web protocols and user interfaces, and a fundamental concept in design of computer information systems since the dawn of the digital age – is in fact a historical relic from our ancestral paper legacy and underlies all digital fragmentation (see below).
  • the digital file is the “original sin” of the information revolution, making information fragmented, siloed, obfuscated, and impossible to own.
  • the file is inherently a local creature, which can be copied at zero cost or deleted and hence exists everywhere and nowhere, detached from any possible identity and alien to any notion of ownership, usage tracking, audit trail or provenance trail.
  • the unique digital object is a universally unique, permanently accessible, immutable, committed, universally uniquely addressable, and machine-readable digital object.
  • unique digital objects enable both horizontal and vertical digital consolidation. It is a key enabler of digital transformation.
  • the unique digital object offers uniformity of interface and expression as well as access control and definite ownership over digital objects, necessary for horizontal consolidation; It offer uniformity of interface and expression in digital representation of processing (computation and ICC) and explicit, full provenance trails from observation through processing to presentation, necessary for vertical digital consolidation.
  • UDR Unique Digital Reality
  • UDR is a system for uniform interface and expression of unique digital objects.
  • Several embodiments of the invention taught herein are based on the concept of UDR, which is disclosed in detail below.
  • unique digital reality enables digital consolidation and indeed the endgame of digital transformation; it unlocks the full value of digital information and create a huge number of new markets, products, and services, such as those mentioned above.
  • individuals can rent out their entire digital history; corporate accounting becomes a software problem; the physical world merges with its digital footprint; the act of software execution becomes a tangible object that can be sold; and much more.
  • Unique digital reality is uniformly software accessible, enabling the effortless flow of digital information, automatic validation and verification, and software-provided obvious trustworthiness, as well as new levels of insight mining and artificial intelligence.
  • UDR Implementation using Enduring Network Interfaces As mentioned, shared- ledger technology cannot possibly support large-scale unique digital reality (think all the digital information created by everyone). There is however one mature technology that can support it at scale, indeed the same technology that supports all internet traffic today: the Internet server. Below, we teach how to implement unique digital reality using server interactions and mostly presently available information technology. In our implementation, a unique digital object is implemented as an enduring network interface, namely, an internet service that is permanently available over the network using universally unique identifier and offering an API.
  • Verifiable Code Execution is crucially important events in information technology reality. Under the existing state of the art, they cannot be mirrored in information objects, and as a result, the vertical flow of information exchange could never be consolidated – as results of computations (code executions) could not be connected to the information objects they were applied to (on the one hand) or to their results as displayed and presented to human users (on the other hand).
  • UDR enables Verifiable Code Execution – the mirroring of code execution events as collections of unique digital objects in UDR. To achieve this, unique information objects recording the progression of computation – including code executed; input and output data structures; interim variables; and key results intended for human users – are created by the same machine, virtual machine or interpreter executing the code.
  • Standard Information Consistency and Compliance Language SICCL
  • the processing stage of the vertical information flow consists of one of (or a combination of) computation or ICC.
  • Verifiable execution mirrors computation in UDR and thus enables consolidation of a vertical information flow including computation; however vertical information flows that include ICC are currently not even digitized in the state-of-the-art, and instead carried out by manual human effort.
  • SICCL Standard Information Consistency and Compliance Language
  • Horizontal Digital Fragmentation is the process of dividing the digital world into an ever- increasing number of disjoint (fragmented) information systems, each using idiosyncratic storage formats and protocols, each user-facing and not designed for software interoperability across time and space, and each isolated from the rest of the world.
  • Horizontal fragmentation lines lie between organizations and corporations and between different information systems of an individual organization.
  • Digital information kept separate from the rest of the world – in the private databases and idiosyncratic storage formats of corporations, banks, healthcare providers, insurance companies, and governments — cannot be not part of any shared reality and cannot be form the basis of any new products or services.
  • Shared reality is essential for any societal process – such as business, legal, and financial processes.
  • documents, or PDFs, or emails which are direct emulations of paper-based information exchange using envelopes, mail and physical paper.
  • Files are instrumental in encouraging horizontal friction, as each stakeholder must protect their files from copying and is encouraged to hoard them, as information in files cannot have a definite owner. Files are also instrumental in vertical friction because files are inherently incompatible with computational provenance and digital audit-trails: when a computation creates a file, its provenance is immediately lost.
  • the Trajectory of Digital Transformation Increased digital fragmentation is not consistent with the endgame of digital transformation, as the latter requires complete consolidation of all digital information exchange. In fact, full Digital Consolidation is the endgame of Digital Transformation. We conclude that further breakthroughs in digital consolidation are inevitable – the only question is when and how.
  • the human capacity to maintain a consistent shared world view via exchange of information is fundamental enablers of all aspects of civilization – such as society, politics, economy, and culture. Any revolution in the ways in which we exchange information, in the use of information to maintain a consistent shared world view, and in the way, information is processed to achieve insight, necessarily implies a revolution in society, politics, and economy.
  • Digitization is affecting jobs, privacy, bureaucracy, personal autonomy, democracy, finance, healthcare, law, economy, community, childhood, relationships – in short, every aspect of society as a whole and of an individual’s everyday life. This is a process of vast historic significance.
  • Evidence as to how far along the process of digitization has advanced came when the 2020 Covid-19 pandemic hit: using information technology (notably websites, smartphone apps, and voice-over-IP teleconferencing technology) the economy of western world continued to function even when most of the world was in lockdown – a situation that would be considered utterly impossible even a decade or two ago.
  • Digital Transformation is the ongoing process of moving all human affairs, memories, communications, transactions, societal processes and business processes to software and computer-based processes, computer interactions and digital media.
  • information exchange we mean the methods and protocols (agreed upon explicitly or universally adopted implicitly), using which we create, store, communicate, copy, distribute, access, exchange, present, inspect, verify, cite, own, and archive information of all kinds – from contracts to medical test results, from geo-location of individuals to Internet server logs, from salary slips to entertainment content. More importantly, we mean the underlying mindset and core concepts that shape how we think about information, how we use it, and the key roles it plays in society, business, economy, and the human condition. In this text, we use the term information broadly to include, for example, all kinds of physical and digital documents, photographs, contracts, books, videos, Virtual Reality (VR) entities, and digital files; a more comprehensive list of example appears below.
  • VR Virtual Reality
  • Knots on a rope, coal inscriptions on cave walls, letters etched in clay or stone, sounds spoken by vocal cords, rhythmic drumbeats, films stored on a roll of super-8 celluloid, Morse signals over RF radio signals, strings of binary bits stored on magnetic digital media, binary light flickers over fiber-optic cables – are all examples of symbols.
  • symbols systems spoke words
  • others letters on clay or knots on a rope
  • Some drumbeats
  • Some can only communicate over a relatively short distance while others (Morse codes over radio frequency signals) can be communicated over very long distances.
  • a paper page printed with certain language is taken to mean a contract transferring ownership over a house; a plastic card with a binary string coded in a magnetic stripe – a credit card – is taken to mean identity that could authorize payment; a collection of bits in Portable Document Format is taken to mean a health questionnaire form; and so on.
  • the protocols then define the meaning of certain actions associated with information objects. As an example, take the act of consent by an individual. A protocol may specify, for instance, that to consent to a contract printed on a page the individual must sign with a blue pen; to authorize payment the individual must hand her credit card to the merchant to be swiped; to declare good health the individual must click certain boxes in the Portable Document Format (PDF) shown in a PDF viewer and save it; and so on.
  • PDF Portable Document Format
  • IT reality Information Technology (IT) reality.
  • Objects in IT reality are pieces of digital data stored on digital storage devices.
  • Events in computational reality are computations (code executions) and network communications. Both code executions and network communication create digital data and change digital data.
  • code executions code executions and network communication create digital data and change digital data.
  • IT reality is not physical, it is certainly a reality with tangible existence – all individuals with access to a certain storage device agree on its content.
  • Some information systems have a much wider range of expression – namely, can mirror a wider range of things, states and events in a wider range or reality – than others.
  • the information system determines the cost (in terms of time, effort, resources) required for information exchange and for achieving consensus, and the fundamental limits of trust, consensus and cooperation that are made possible by a certain information system.
  • an information system consisting of documents can mirror a person’s identity (using an ID card) and the event of purchasing an item at a store (using a receipt). It is not able to mirror events in Information Technology reality, such as logging into a server.
  • a VAT tax liability (a legal object) regarding a payment (a financial object) for sale of a tomato (a physical object).
  • Information Realities have certain expressive power. They can be able (or unable) to express – to mirror – objects in the underlying reality, and connections between these objects.
  • Figure 2 shows schematically objects, states and events in reality, and their relations, being mirrored in information reality:
  • An object 201 in reality (for example, an agreement between parties) is mirrored by an information object 204 – a contract document.
  • a person 203 in reality is mirrored by an identity document 203 – for example, a driver’s license.
  • the contract document 204 may mention the person 203 using his or her legal name, address and driver’s license number as shown in license 205.
  • GAAP Generally accepted accounting principles
  • GAAP requires the corporation to keep records of all stages in this complicated multi-stage process. It includes objects in legal reality (ordering corporation and goods-providing corporation), objects in financial reality (bank accounts), events in financial reality (funds transfer, issue of invoice), objects in physical reality (goods delivered) and events in physical reality (delivery). Notice that the GAAP requirements corporation to keep records of all stages in this process amounts to keeping records that represent – mirror - the different objects, states and events in all reality layers involved. Shared information realities. It is useful to think of a system of information objects, for example the system of clay tablets, or the system of paper documents, or the system of PDF documents, as a layer of shared reality in its own right – one that is separate from the layers of shared reality it mirrors or represents.
  • the notion of an Original Document implies that a certain object carrying information is “A Thing” – a tangible, universally unique, uniquely addressable, uniquely locatable Thing.
  • a court can subpoena an original document; the holder of an original title has proof of ownership; etc. This notion has a profound impact on the way we think about facts and information. As an information object, the original document enjoys a privileged status for being tangible and universally unique. Notaries: Copying in Document Shared Reality.
  • the system for exchanging facts is a hybrid. It certainly contains many elements of the Document Shared Reality system – we still completely rely on documents - yet these elements are implemented using a mixture of physical paper and digital means. Indeed, the digital document, such as the Portable Document Format (PDF) file, the word processor file, and the e-mail, are strange creatures. In many ways they are like paper (physical) documents: they are intended for human access (as opposed to machine access) and have ad-hoc formats; they are however much easier to copy and communicate. While they are copied instantly and communicated instantly – the hallmark of digital information – they are treated and used exactly like the ancient physical documents.
  • PDF Portable Document Format
  • a receipt is a document (physical or PDF – no matter) representing an exchange of goods or services for payment.
  • the exchange includes several simultaneous events: a physical exchange (in the case of physical goods) or digital exchange (in the case of digital goods); a financial exchange; a tax event; and a legal consent event (customer agrees to pay, vendor agrees to sell, with legal implications according to local law regarding sales, etc.).
  • the receipt has many different uses.
  • the information displayed on the receipt includes identity of seller (name, address, phone, and possibly tax ID), date-time of payment, description of goods or services purchased, amount paid, payment method (including payment information, such as credit card number or bank account), tax collected, and possibly references to other relevant documents, such as invoice, purchase order, credit card slip, etc.
  • JSON JavaScript Object Notation
  • SQL Standard Query Language
  • a system of information – language for example – has syntactic rules (form) and semantic rules (meaning) so that we can use it to pour meaning into well-defined forms.
  • information contains symbols about reality.
  • the objects and events to which information symbols refer can exist in physical reality - but also in imagined (intersubjective) reality.
  • information refers to • Physical reality • IT reality (what happened in computers – what is stored, what has been accessed, which programs have been executed) • Legal reality (criminal law, civil law – contracts, tax law, corporate law) • Financial reality (money, financial instruments, financial markets, lending, credit, payments) What is information used for? Like language, we use it to communicate. Information consists of elaborate structures, built using language and other information representation systems, with their own rules. Its most important use is to reach consensus and cooperation regarding what is and what has happened – to reach a shared view of reality. In fact, for imagined (intersubjective) realities, information is the only means to reach consensus and cooperation – the existence of intersubjective realities depends on information. Examples. Consent and agreement are terms in legal reality.
  • a signed original document is a symbol of an event – consent and agreement.
  • This object can be stored, presented, exchanged, inspected, verified – to reach consensus and cooperation regarding the event in legal reality to which it refers.
  • the document is a symbol.
  • the receipt is a symbol for an event in financial reality – payment
  • the tax invoice is a symbol for an event in legal (tax law) reality – tax obligation due to payment.
  • a payment object in financial reality
  • a payment is made from one entity, e.g. an object in legal reality if a company, and both legal and physical reality if person, to another entity, in exchange for something, an object in physical or legal or financial reality. All these entities are connected to the payment object.
  • So information is a language, a system of symbols, used to describe – to refer to – objects in different layers of reality. Sometimes, the identification between the object and the symbol is so complete that we don’t distinguish between them – for example, someone may say that the document (the symbol) is the contract. But it isn’t. It’s just the symbol. The contract is the thing that is written on the document, the thing that has been agreed upon.
  • a Shared Information Reality is a self-contained system of symbols and a collection of symbolic objects. Yes, shared information reality also contains objects – such as documents, computer files, printed pictures, videos, etc. These objects are symbols and they are separate from the objects in realities to which they refer. Like language, a Shared Information Reality has expressive power.
  • An ideal Shared Information Reality will have enough expressive power to represent – to capture- everything that is and everything that happens in physical, legal, financial computational, political realities. For example, to express that a computation has happened; to express identities of physical people; to express that a specific person has opened a cabinet; etc.
  • a shared information reality also represents – or fails to represent – the connections the relations between the objects it refers to. It may have symbolic representation for them, or it may not be rich enough to represent them.
  • An ideal Shared Information Reality will have enough expressive power to also represent all connections between underlying objects.
  • the graph of facts in the Shared Information Reality is mirroring the graph in the underlying reality.
  • the graph in the underlying reality can be events in order as they happened; flow of information from user interface into UDR and back; structural connection between facts in a bundle; etc.
  • the mechanics of a shared information reality The information reality enables us to store, exchange, present, verify information to reach consensus and cooperation.
  • the different information reality systems differ in how they implement these. To present to someone in the document system I must send them the document – even the original document. So every information reality needs to be looked at and examined step by step in how it supports the different activities. Verification.
  • any Shared Information Reality comes with syntactic and semantic rules.
  • the verifier must have capabilities for the following: • Access the object being verified • Know, understand and be able to execute the steps and rules for verification • Be able to figure out connections between the object being verified to underlying and related objects • Be able to locate and access the related objects
  • the Document Shared Information Reality only people can read documents, so only people can verify. Moreover, connections and relations are often implicit, and it takes human intelligence to infer them from context.
  • software could have been able to verify, but: (i) The steps to execute are not specified in a formal language, (ii) Some documents are only human-accessible, (iii) Connections are not explicit, and (iv) Due to fragmentation, it is not possible to access related objects. Intelligence.
  • This axis traverses the global social, economic, financial, and political ecosystems; we call it “cross-stakeholder” or “horizontal.” Information that flows along this axis is exchanged at arm’s length between individuals or legal entities. Roughly speaking, the overarching goal of horizontal information exchange is insight that can be extracted by combining information from different sources.
  • Source-to-user (“Vertical”) Information Flow The second axis is information exchange that occurs as information is captured, recorded, processed, and presented. This axis points from objects, states, and events in various shared realities, to the information objects that represent them in shared information realities, to the processing of information objects, to the presentation of processing results on a user interface. Information that flows along this axis moves through different stages of representation, processing, presentation, and verification.
  • Figure _3_ shows the two axes of information flow: a cross-stakeholder (“horizontal”) flow of information between different stakeholders 301, 302 and 303, and a source-to-user (“vertical” fow through different stages of information processing: objects, states and events in reality 304, being mirrored in information objects 305, being processed by computation or ICC 306, and being presented 307.
  • Source-to-user (“Vertical”) Information Flow The vertical information flow consists of several stages: Vertical Flow, Stage 1: Objects, States and Events in Reality Objects, states, and events in different shared realities, e.g.
  • information objects are used to mirror, or represent, objects states and events in shared reality.
  • Information objects carry symbols with shared meaning. There are three kinds of possible meaning in information objects: observed, deduced by computation, and deduced by information consistency and compliance.
  • observed information objects are created which mirror objects, states, and events. Observed information objects. An information object which represents an observation about reality; specifically, that an object exists, a state has been observed, or an event happened in shared reality (such as physical, legal, financial or IT reality). Examples (with document information objects): • A property title document mirrors a state of ownership in legal reality.
  • Such information objects reference (explicitly or implicitly) the underlying information objects, to which the deductive reasoning process has been applied; and describe (implicitly or explicitly) the deductive reasoning process itself.
  • a deduced information object stipulates that processing has been applied to specified existing information objects and produced the stated result.
  • There two different purposes for processing information 1.
  • Computation processing One is to perform computations based on data to summarize it, transform it, and arrive at conclusions. This has become mainstream.
  • Numerous computational platforms including machine readable languages (such as C, Python, Java, R, Ruby, etc.) has been developed to implement this.
  • a computationally deduced information object stipulates that the specified arithmetic steps have been applied to the specified existing information objects and produced the specified result.
  • a corporate income statement reports the total (yearly, income. This is the result of an application of an arithmetic computation to underlying documents, e.g. invoices and receipts for income and expense.
  • a US federal tax return reports the total tax owed – result of the application of a complicated computation applied to underlying documents, including salary slips, corporate dividend notices, expense invoices, and previous year’s tax return forms.
  • An investment portfolio valuation reports the total portfolio value as of a given point in time – the result of a simple arithmetic calculation applied to underlying information objects which include assets owned in the portfolio mirroring states in financial and legal reality and, the present valuation of each asset.
  • a scientific report may report the result of a complicated deductive reasoning process, namely, statistical analysis performed by executing computer code, which has been applied to experimentally observed data.
  • Information Consistency and Compliance (ICC) processing The other purpose of processing is to verify information consistency and compliance. Information regarding financial transactions, tax, legal processes, property and goods ownership and transactions, service transactions, etc. is required to uphold various rules and regulations.
  • a mortgage loan application summarizes information regarding the requested loan, including the real-estate property to be bought; current property ownership; current owner identity; tentative sales agreement; property valuation; property insurance; applicant financial situation, credit rating and income; loan agreement; and so on.
  • a passport application summarizes information regarding an individual, including proof of identity, past passports issued, and so on.
  • a property insurance claim summarizes information regarding the insured individual identity, insured property, insurance policy, damage event, property inspection, and repair appraisal.
  • Document package for corporate M&A including corporate cap table; employment, IP and options agreements with founders, board, officers, employees; IP; financial reports.
  • the same information object may include results both of both computation and ICC processes – for example, financial reports contain both calculation and GAAP audit ICC results.
  • Figure 65 shows the processing stage. Process execution as a stand-alone entity.
  • the processing stage of the vertical flow consists of execution of well-defined processes and algorithms – either computations which have defined inputs, computations steps and outputs or ICC verifications which have defined inputs and requirements.
  • a process – whether by a machine (a numerical computation or data analysis), or by a human (verification of ICC requirements), is a stand-alone entity. It is executed by a specified machine, or set of machines, or by a human, or set of humans, at a certain time and produced certain results such as new information objects.
  • An information object in consensus is a fact.
  • a fact is an object, state, or event or the result of a deductive reasoning process, which is in consensus.
  • facts are those information objects in a shared information reality, regarding which there is consensus.
  • Characterization of the Fact status The fact status of an information object enables cooperation, as the information represented by the object enters shared reality. How can we characterize this exalted status in terms of the information object representing it? 1. Permanent: A fact an information object that can be stored indefinitely if needed – in case it needs to be presented to some interested third party at an unknown moment in the future. 2.
  • A is an information object that can be presented to for inspection by any interested third party.
  • Verifiable The validity and authenticity of the fact, as defined within the context of the shared information reality, can be verified by a third party who inspects the information object that represents it.
  • Immutable A fact is an immutable information object – in other words, the contents of the fact, and hence the symbols on the information object that represents it, do not change after it has been created.
  • Authentic and signed The identity of the entity which produced the information object is known. It can be verified that the information object remains unchanged since created by the entity.
  • Citable A fact can be dependent on other underlying facts for validity, and in turn can be depended upon for validity by other facts.
  • the information object representing a fact cites, in some way defined by the shared information reality, the information objects representing the underlying facts.
  • We call verified observed information objects “Observed Facts.” Verification of an observed information object means using the symbols on the information object to achieve consensus regarding the object, state, or event it represents. Examples: • A property title document mirrors a state of ownership in legal reality. Verification of the document enables consensus regarding the state of ownership. • A property sales contract mirrors an event in financial reality. Verification of the contract enables consensus regarding the event, e.g. sale, transaction and change of ownership. • A water meter reading mirrors a state in physical reality. Verification of the reading means consensus regarding the reading. • A hand signature mirrors legal consent - an event in legal reality.
  • Verification of the signature means consensus regarding the event of consent by a person.
  • Verification of a deduced information object depends on the mode of processing used to deduce it.
  • Verification of information objects deduced by computation means achieving consensus regarding: (i) The validity of the underlying information objects; (ii) The validity of the deductive reasoning process itself; and (iii) The correct application of the reasoning process to the underlying information objects.
  • Examples for verification of information objects deduced by computation A corporate income statement reports the total (yearly, income. This is the result of an application of an arithmetic computation to underlying documents, e.g. invoices and receipts for income and expense.
  • Verification of an income statement means: (i) achieving consensus that the underlying invoices and receipts are valid, namely – as above – achieving consensus that they faithfully represent all income and expense financial events for the company; (ii) achieving consensus that the deductive reasoning process – an arithmetic calculation which includes accounting judgement and considerations – upholds the generally accepted accounting practice (GAAP); and (iii) achieving consensus that the deductive reasoning has been correctly applied, namely, that the arithmetic has been done right.
  • Other financial reports, such as balance sheets, are of a similar nature.
  • Verification of the tax return means: (i) achieving consensus that all underlying documents are valid; some of them represent observed facts (such as invoices and dividend notices) so that verifying them means achieving consensus regarding the mirrored objects, states, or events, such as expense payment sent or dividend payment received; and some of represent deduced facts, such as previous year’s tax returns, so that verifying them means recursive application of the process described here; (ii) achieving consensus that the deductive reasoning process (tax calculation) - an arithmetic calculation which includes accounting judgement (such as which expenses are tax-deductible) and tax brackets in effect – upholds the tax code and its accepted interpretations and rulings; and (iii) achieving consensus that the deductive reasoning process has been correctly applied, namely that the tax calculation including arithmetic and location of tax bracket
  • a scientific report may report the result of a complicated deductive reasoning process, namely, statistical analysis performed by executing computer code, which has been applied to experimentally observed data. Verification of the paper conclusions often boils down to verification of the deduced fact at its crux – which means: (i) achieving consensus regarding the underlying observations; (ii) achieving consensus regarding the statistical methodology applied and its correct implementation in computer code; and (iii) achieving consensus that the computer code has been correctly executed and applied to the underlying data. Verification of information objects deduced by ICC: An ICC-deduced information object summarizes, or repeats, information on other information objects which are referred to. It is a package containing references to existing information objects.
  • Verification of such an information object means: (i) verifying all information objects referred to; (ii) verifying the correctness of the consistency and compliance requirements applied; and (iii) verifying that the requirements are indeed fulfilled.
  • Most bureaucratic forms are of this kind. Many important institutions, at the foundation of modern civilization, were developed out of a need to verify ICC information objects before they are accepted facts and enter shared reality. Bureaucracy posits that we need people whose job is to review documents and collections of documents for consistency and compliance with certain rules. Accounting audits posit that we need people whose job is to review financial documents for consistency and compliance.
  • a mortgage loan application summarizes information regarding the requested loan, including the real-estate property to be bought; current property ownership; current owner identity; tentative sales agreement; property valuation; property insurance; applicant financial situation, credit rating and income; loan agreement; and so on.
  • Consistency and compliance requirements include consistency between identities of persons and properties on the different documents; compliant value-to-loan ratio; compliant income-to-payment ratio; etc.
  • a passport application summarizes information regarding an individual, including proof of identity, past passports issued, and so on. Consistency and compliance requirements include, for example, passport eligibility.
  • a property insurance claim summarizes information regarding the insured individual identity, insured property, insurance policy, damage event, property inspection and repair appraisal. Consistency and compliance requirements include consistency of person and property identities on the various documents, etc.
  • Document package for corporate M&A including corporate cap table; employment, IP and options agreements with founders, board, officers, employees; IP; financial reports. Consistency and compliance requirements include, for example, best practices for contracts signed with employees, customers, and service providers; compliance of cap table and stock issue board decisions; etc.
  • Facts in Document Shared Reality As an example, let us evaluate whether, and how, the Document Shared Reality system meets the five criteria for facts mentioned above. Recall the abstract characterization of facts in a shared information reality, mentioned above. 1. Permanence. Information on documents survive if all copies survive physically. 2. Communication. Communicating information, exchanging, and presenting facts, is achieved by physically exchanging documents – for example by sending paper over the mail or by couriers. 3. Verification.
  • Some digital documents are assigned a Digital Object Identifier (DOI); however the typical digital document cannot be explicitly and unambiguously cited any more than physical documents.
  • DOI Digital Object Identifier
  • the stakeholder who performed the processing creates an affidavit, typically in the form of a document, and the affidavit is exchanged.
  • Canonical examples for this are scientific reports and external auditor-signed financial reports.
  • the result of a statistical analysis is exchanged by communicating a verbal description of the procedure performed, and a verbal description of the result obtained.
  • the result itself (for example in the form of digital files) is not exchanged.
  • This object can be an observed information object – mirroring an object, state, or event in some reality, or can be a deduced information object – containing result of processing applied to other information objects.
  • the two parties are interested in achieving consensus regarding the information object, namely, in establishing that this information object represents a fact. They thus engage – either the fact receiver attempts to verify the information object, or the fact presenter attempts to prove its validity.
  • a key constraint that shapes the fact exchange cycle is that the identity of an eventual fact receiver is not known a priori, and typically not known at the time of creation of the information object.
  • a court of law receiving a signed contract document can evaluate its validity even if the contract was not disclosed to the court at the time of its creation and execution;
  • a potential landlord wishing to inspect a proof-of- income from a potential tenant can inspect historic salary slips printed by a past employer, even when (obviously) the slips were not presented to her upon salary payment.
  • observation information objects and “deduced information objects”
  • verification of information objects is a formal procedure. For deduced information objects Inherently involves traversing the vertical flow, identifying underlying information objects, gaining access to them from the stakeholders owning or storing them and verifying them.
  • Horizontal digital consolidation along the three vertical levels will unlock value of astronomical proportions for training AI models and obtaining insight from digital information.
  • AI and machine learning models require large amounts of high- quality training information.
  • Horizontal digital consolidation will make it possible to create cross-stakeholder datasets for training of broad AI.
  • Source-to-user (“Vertical”) Digital Consolidation means a fully digital shared information reality, where the vertical flow – the links between observed information objects to the information objects deduced from them and to the processes that were used to deduce from them, and from deduced information objects to their human-readable visual presentations – are explicitly exposed in digital format.
  • Consolidation of the steps along the vertical information flow – from capturing objects, states, and events, and representing them as a digital information object; to processing a collection of information objects; to presenting processing results on a user interface – will make all stages of the vertical flow, and the inter-connections between them, available over a uniform interface. For example, it will make available over a uniform interface a computation process executed; explicitly identify the information objects to which the process has been applied; explicitly identify the result of the computation process; and explicitly link the result to any of its presentations on a user interface. This kind of consolidation will enable efficient and comprehensive verification of information exchanged by human users. Certainly medical billing, tax, and corporate accounting, auditing and many aspects of legal practice will be eaten by software when this happens. Elements to be consolidated along the vertical flow.
  • An Identity is the unique identity of a person, a legal entity, an organization, or physical object.
  • Every identity (an object in physical or legal reality) must correspond to a unique digital object.
  • the identity object contains encrypted information which allows unique unambiguous identification of the individual / organization, such as secret passwords, cryptographic keys and / or biometric information.
  • the identity object contains – when possible – unique information corresponding to the physical object, such as a serial number, a MAC address, etc. 2.
  • a User Interface is any means for a computing system to interact with a human user in physical reality. This includes devices able to authenticate users, namely, to obtain identification credentials from human users, and devices able to make biometric measurements. This also includes devices able to display and present information to human users and / or to get measure their input. This includes screens, mobile devices, mobile phones, credit cards, fixed or mobile biometric scanners, tiny biometric scanners, biometric scanners embedded in other systems, touch screens, keyboards, gesture pads, smart watches, etc. In some embodiments, a user interface can have a unique corresponding unique identity digital object containing means to identity it uniquely.
  • a user interface is not necessarily a computing device – for example, a piece of paper can be considered a user interface (even have its own unique identifier) as it is a physical object able to display information. It is important to distinguish the representation of information on an information object from the information itself; for example, certain representations may show combined information from several different information objects; or may show selected partial information from an information object.
  • a Physical Interface is any means for a computing system to interact with physical reality. This includes sensors, measurement devices, cameras, and all other analog and digital input devices; This also includes controllers, digital or analog switches, and any other output device. In some embodiments, a physical interface can have a corresponding unique Identity digital object, containing means to uniquely identify it. 4.
  • An Interaction is a specific exchange of information, in close-range physical space, between two interfaces.
  • the exchange of information can occur based on physical touch (such as touching a screen), exchange of close-range radio signals (such as Bluetooth handshake), exchange of acoustic signals, exchange of visual signals (such as scanning a QR code), or any other means for close-range physical information exchange.
  • This can be an exchange between two user interfaces when two persons meet and exchange information, or an exchange between two user interfaces when a person interacts, through a personal identification device, with a fact through a fact representation appearing on a user interface.
  • This can also be an exchange between A user interface and a physical interface, such as passing identity credentials from a personal identification device (a user interface) to a door lock (a physical interface).
  • Every interaction corresponds to a unique digital object documenting, among other things, the identities of the interfaces involved in the interaction. 5.
  • a code execution is the unique act of running a specific computer program or compute code, on a specific computer, computing platform, computing device or distributed computing system, using specific inputs, producing specific outputs and/or commands to user interfaces and/or commands to physical interfaces.
  • An execution is represented by a collection of unique digital objects. Every different execution of a program corresponds to a different execution digital object: for example, if the same computer program is executed twice against the exact same inputs, producing the exact same outputs, there will be two distinct execution unique digital objects. 6.
  • Machine-readable information consistency and compliance requirements are computer programs and/or machine-readable code specifying conditions for consistency, compliance or acceptability of a process or a piece of information.
  • the conditions under which a legal contract or is correctly signed and correctly legally executed can be specified as a protocol; the conditions under which a loan application includes, or references, the required list of supporting information such as proof of income, proof of identity, etc.; the conditions under which a corporate annual financial report is valid according to GAAP and includes, or references, the required list of supporting information such as financial statements, issued and collected invoices, bank statements.
  • Horizontal consolidation enables mining all the world’s digital information for insight; vertical consolidation enables automatic verification and radically efficient cooperation.
  • the product of horizontal and vertical consolidation means the following: there is a systematic, software-accessible digital footprint to all capturing of objects, states, and events into digital information objects; to all processing applied to digital information objects and their inter-dependencies and interconnection; to all presentation of information objects on user interfaces.
  • Figure 6 shows horizontal and vertical information flows using different shared information realities: information flow between stakeholders (horizontal) and from source to user (vertical) may occur using various shared information realities, including document shared information reality 604, hybrid shared information reality 603, digital (file based) shared information reality 602, or Unique Digital Reality (UDR) 601, to be discussed below.
  • Software and Artificial Intelligence (AI) Here are some products, services and capabilities that will become possible in the field of AI and machine learning because of horizontal and joint two-axes digital consolidation: • “Data blame” – which training data points are responsible for a model test malfunction? • Proof of reasonable precaution – proving to the regulator or to a court that certain AI model or software tests were performed, and that certain results have been observed in these tests.
  • digital fragmentation is the process by which digital assets become more siloed, more obfuscated, less accessible, and less uniform; user interfaces, software interface, and formats become more idiosyncratic; it is harder for stakeholders to communicate using digital information exchange; there is more friction in the flow of information; communication is less clear; information is less software accessible – especially between parties at arm’s length; there is more obfuscation regarding the audit trails and sources of information, and it is harder to cite them clearly; the digital universe is divided into walled gardens that cannot communicate with each other; there is less provenance and less clarity regarding data sources; audit trail recovery is resembles a forensic activity; there is more fallback to documents as primary means to establish cooperation, to manual work as primary means to perform information verification and to manual work as the primary means to extract insight from information.
  • AI systems are software systems that draw conclusions and generalizations from large collections of information: for example, they learn how to recognize human face by processing large collections of face images.
  • the highly fragmented nature of information today implies that most AI systems – other than those developed by the huge multinational Internet corporations - are trained narrowly for highly specific tasks on mostly privately collected datasets.
  • the promise of broad AI, namely, systems that draw broad conclusions from a large variety of interlinked information sources, remains largely unfulfilled.
  • Figure 7 shows the Tower of Babel by Pieter Bruegel the Elder. We call this situation Digital Fragmentation.
  • This paradigm emphasizes idiosyncratic storage systems, software systems that are only human-facing and not machine-facing, information technology concepts that prioritize user interfaces to software-accessible interfaces, idiosyncratic identity and access control systems, and idiosyncratic formats, and idiosyncratic user interfaces.
  • Each organization determines idiosyncratic standards for storage, identity management, access control, digital formats, and user interfaces; each application stores its digital information siloed away in idiosyncratic formats and inaccessible storage; each entity hoards its own data and obfuscates it from the rest of the world.
  • the first barrier to automation is our existing notion of a document – both physical and digital - which leads to the lack of software accessibility and lack of unambiguous digital citability.
  • the second barrier to automation is the lack of machine-readable instructions for verification and validation.
  • the third barrier to automation is ad hoc social protocols that specify how information is presented to stakeholders.
  • Digital Fragmentation is a failure of imagination. We cannot escape the conclusion that the current situation of radical digital fragmentation represents a massive failure of imagination on behalf of all of us who design and build digital information systems. Indeed, digital fragmentation is caused by a failure of imagination, not by any technological hurdle: there is basically nothing in the core design principles of current information technology systems – including networking, cryptography, storage, and end-user devices and interfaces– which mandates digital fragmentation.
  • Digital fragmentation is a result of the frantic, explosive pace of the advance of early-stage digital transformation, and market incentives that keep digital transformation stuck in a local minimum: once a consolidation event such as appearance of the WWW occurs, it is irreversible, but before it occurs, market incentives can cause us to spend years in a fragmented limbo. Business models developed on top of digital fragmentation and market incentives led the whole information technology industry to be stuck in a local minimum, so to speak. As the next stage of digital transformation, digital consolidation requires a re-imagining of the ways in which we use presently available information technology and the ways in which societal processes building on information exchange are using computers, computer networks, and human-computer interfaces.
  • Fragmentation of payment methods Presently, each person carries several credit cards to prove financial identity to vendors and uses multiple other payment methods, such as PayPal accounts, Apple Pay, Google Pay, etc. Fragmentation of financial information.
  • An individual’s financial information is fragmented across a potentially large number of entities: every bank where the individual has (or had) a bank account; investment firms; pension funds; mutual funds; stockbrokers, federal and state tax agencies, and so on.
  • Each of these entities has an account for the same individual on its private information universe; the individual has no simple way to build a complete personal financial profile, must keep track of different accounts simultaneously, and cannot communicate financial information directly between institutions where accounts are held.
  • personal medical information including medical files, test results, medical imaging scan results, medical opinions, visit history, procedure and hospitalization history, prescription given and administered, etc., is fragmented across many computing systems in various hospitals, clinics, HMOs, physician offices, and medical insurance companies.
  • the individual does not control – nor owns – their medical information.
  • the individual cannot directly present their personal medical information from being used for research purposes, nor can they volunteer their entire medical information for any purpose.
  • Personal medical information is not an asset that can be given by bequest, monetized, sold, rented, etc.
  • Fragmentation of personal digital information Storage of information, both personal information and enterprise information, is fragmented between multiple providers.
  • Google docs Microsoft 365, Apple iCloud, Dropbox, Box, local files in multiple computers, multiple smartphones and other mobile devices, document e-rooms, Facebook, SAP, Amazon, bank accounts, PayPal, Apple Pay, and multiple other payment systems, credit card companies, WhatsApp, Slack, messenger, investment management accounts, HMO accounts, multiple calendar accounts, multiple email accounts with Google, Apple, Yahoo, etc.
  • Google docs Google docs
  • Microsoft 365 Apple iCloud
  • Dropbox Box
  • local files in multiple computers, multiple smartphones and other mobile devices
  • document e-rooms Facebook, SAP, Amazon, bank accounts, PayPal, Apple Pay, and multiple other payment systems
  • credit card companies WhatsApp, Slack, messenger
  • investment management accounts HMO accounts
  • calendar accounts multiple email accounts with Google, Apple, Yahoo, etc.
  • Each of these locations uses its own identity management system, has its own user interface and its own API (if any). Fragmentation of Artificial
  • Modern artificial intelligence (AI) systems are trained on vast datasets to perform a specific task, for example – face recognition; speech recognition; speech generation; natural language translation; etc. These systems are fragmented in the sense that they are trained on datasets stored separately on fragmented systems and privately owned by separate entities; similarly, the trained AI systems are fragmented. Fragmentation of software services. We are seeing a proliferation of software services which perform essentially identical functions. For example, Ride sharing (Uber, Lyft), Videoconferencing (Zoom, Skype, Webex, WhatsApp, Google hangout, Amazon chime). Use patterns of information under Digital Fragmentation An attempt to analyze and understand the state of the art, namely, the present stage along the trajectory of digital transformation, must consider both the technological aspect, e.g.
  • the current state of information technology and the human use-pattern aspect, e.g. the social agreements and use patterns that govern how information technology is used to exchange information and achieve cooperation.
  • the fundamental characteristics of digital files - inherently easy to replicate, not unique, impossible to own, easy to alter, and cannot be uniquely and universally addressed – place severe constrains on the use patterns and social norms for human cooperation through exchange of digital files.
  • Figure 8 shows properties of data under the current state of the art. Under the current state of the art, our society struggles with questions such as: • Why don’t I own my data? And who does? • Who has access to my personal/private information or data about me? • Which news on social media is fake? • Because almost everyone has access to professional-level photo editing software, how can we trust the contents of any image or PDF document presented to me? Horizontal Digital Fragmentation.
  • Horizontal digital fragmentation is a process curtailing the possibility of digital information exchange between different (internal) software systems belonging to an individual stakeholder and between arm’s length stakeholders.
  • information cannot be exchanged in machine-readable format: it must be downgraded to human-readable format, e.g. a document, to be exchanged.
  • humans who read the documents created by one system and manually type it into the user interface of another system, carry the digital information on their shoulders from one system to the other instead of letting it flow in digital format from one system to the other.
  • FIG. 9 illustrates horizontal digital fragmentation on the two-axes diagram: a stakeholder 903 in possession of digital information 901 is interested in sending information to another stakeholder 904. Under horizontal digital fragmentation this is impossible as digital systems of stakeholder 903 are siloed away from those of stakeholder 904. Stakeholder 903 must therefore convert (and downgrade) the information to be transferred to physical documents or PDF documents 902, which can be reliably exchanged between the stakeholders.
  • Stakeholder 904 receives the documents and must then convert the information back to digital form in its own systems, converting the human-readable information in the documents back to machine-readable format.
  • Inefficiency of communication - horizontal digital fragmentation As storage systems are separate and idiosyncratic and as storage formats are also idiosyncratic, often, information cannot be exchanged digitally between entities – even though each entity is using digital information storage exclusively. As a result, information must be communicated by first downgrading the information from digital format to paper (or PDF) format – which is human readable but much less machine readable then the original digital storage format, then communicating the paper (or PDF) document – then loading the information from paper format into the digital format used by the receiving entity.
  • dark matter refers an enormous mass of matter assumed to exist unseen in the universe. There is evidence that in fact most of the matter in the universe is dark. Borrowing from this notion, we suggest the term dark information to describe information that is briefly digitized but then disappears forever or remains perpetually locked and inaccessible. Tremendous amounts of digital information are created every day. Due to digital fragmentation, most of the digital information in existence is dark information – not accessible outside of the organization owning it, and often, inaccessible even within that organization. Information can be described as dark information due to format, too. PDF and scanned documents are dark information. A document is conveying information that is not amenable to digital processing. In a digitally transformed world, there is no dark information.
  • friction In the context of information exchange, we define friction as the cost in terms of resources, time, manual labor, effort of information exchange or information processing, which are not inherent, but rather mandated by the medium used for information exchange and by the use patterns and agreements surrounding the system of information objects. For example, parties communicating information regarding bank accounts and investment portfolios must today exchange documents and PDF files, which are not machine-accessible, and whose verification is often a tedious manual process – even though the parties on both ends use sophisticated digital systems to store the information locally - each in their own corner of the fragmented digital reality. Interestingly, we are so accustomed to friction that we hardly notice it. We find it hard to imagine a state-of-affairs where exchange and verification of information between different legal entities, is typically smooth and effortless. Fragmentation causes Friction.
  • Figure 10 shows an accounting ledger from the early days of double-entry bookkeeping, side-by-side with a modern accounting software user interfaces. Not much has changed: the new digital medium imitates the old paper one and makes software verification of financial reports – though feasible using current information technology – practically impossible. Vertical Digital Fragmentation.
  • a key characteristic of the current state of the art in use of information is that trustworthy information is only available for human access and human inspection.
  • a collection of documents such as a collection of contracts, receipts, purchase orders, financial reports, tax filings, salary slips, etc. Regardless of whether the documents are physical or digital, only humans can inspect the collection; only humans can draw conclusions; only humans can verify and validate the information and facts represented there.
  • a document references another document, for example when a financial report references a receipt or a different financial report, only humans can follow the reference and inspect the referenced document.
  • the entire activity of inspecting, verifying, or validating the collection, or of drawing conclusions from the collection is by design restricted to humans and, by design, unavailable to software.
  • Figure 11 shows industries along the vertical information flow, where the purpose of many services is to reconstruct vertical information flows lost due to digital fragmentation.
  • Inefficiency of verification under digital fragmentation One of the most crucial inefficiencies under digital fragmentation is related to verification.
  • To verify a piece of information it is necessary to obtain access to its underlying facts or pieces of information.
  • To verify a corporate financial report it is necessary to obtain the incoming and outgoing invoices and receipts underlying the financial report.
  • Under digital fragmentation most of the underlying information is either difficult to obtain – cannot be obtained by an automated process – and difficult to process. This implied that verification, under digital fragmentation – is necessarily a human-manual process that is often time- consuming, costly, fraud-prone, and error-prone.
  • Figure 12 shows information from the annual report of Enron, Inc for the year 2000.
  • Figure 13 shows a securities account statement from Madoff Securities International. It was later discovered that the numbers in both documents were complete fabrications; however, to learn this thorough investigations was needed. These are glaring examples of the dangers of vertical fragmentation. These auditing failures occur because the network of information objects, underlying the information presented, remains completely implicit. Documents refer to other documents implicitly; arithmetic calculations are performed and then discarded, leaving only their bottom-line result; nothing in the provenance chain is machine verifiable. Similar failures have been observed in the scientific literature, where both scientific fraud and/or material error are extremely difficult to discover using manual reconstruction of the published results from underlying data, which resembles painstaking forensic work. Files.
  • digital files are the “root of all evil”.
  • the digital file, folder and directory structure follows a mental model fundamentally predicated on the old world of physical documents.
  • the digital file is mutable, is not permanently accessible, cannot be owned, can be copied, and replicated at zero cost, does not have a definite owner, does not have a unique address, is not citable, and is therefore not a thing.
  • the fact that the file is the primary vehicle for storage and exchange of digital fragmentation is behind much of horizontal digital fragmentation and related to vertical digital fragmentation. Files cannot cite each other explicitly across parties at arm’s length – causing horizontal fragmentation; they cannot permanently cite each other on the same system – causing vertical fragmentation.
  • the intense interest in the blockchain is in fact an intense interest in the prospect of a fully digital shared information reality.
  • the blockchain mania is especially interesting considering the obvious fact that the blockchain, as a technology, is not able to support or enable a fully digital shared information reality and has indeed found very few real-world applications, especially when compared to the interest and resources invested.
  • the primary contribution of the blockchain is a preliminary sign that something bigger is coming – that it is possible to rethink and reimagine the prevailing shared information reality system.
  • something bigger is in fact UDR, a technology that can indeed deliver a fully digital shared information reality on a global scale.
  • a the blockchain is a decentralized, shared, distributed database, and a protocol that allows a community of stakeholders to maintain a state of consensus regarding the contents and change history of the shared database, a full copy of which all stakeholders must store.
  • the stakeholders participate in a peer-to-peer network. Each participant maintains a local copy of the entire database. Updates to the database are collected in blocks, and stakeholders provide proof-of-work to validate blocks and publish them, whereby adding them to the chain.
  • a consensus mechanism ensures that, unless more than half the stakeholders in the network collaborate maliciously, all stakeholders can agree on the current state of the database, as well as on the entire change history.
  • the original use of the blockchain was as a ledger to support and enable cryptocurrency. So far this is the only viable wide-spread application of this technology.
  • the blockchain answer to the question “How can we use digital information technology to bridge time?” is: (i) Commitment is by proof-of-work; and (ii) everyone keep all the records of everyone else, hence no need for a designated trusted record-keeper.
  • the blockchain hasn’t taken over the world (i) because this paradigm doesn’t scale; (ii) because the protocol is inherently designed to support peer-to-peer transactions, not more general permanent digital information objects; and (iii) because the user-interface angle has received very little attention in the blockchain arena.
  • a blockchain is small-scale, low-volume digital shared information reality. Stakeholders participating in a certain the blockchain agree on the contents of their shared database. In other words, they share a world view consisting of database entries.
  • the database contains ownership information over a set of assets, such as allocation of a cryptocurrency
  • ownership information such as allocation of a cryptocurrency
  • all stakeholders share a world view of who-owns- what, as well as all history of transactions that lead to the current ownership state.
  • the database contains information regarding events, then all stakeholders share a world view of what-happened. And so on.
  • the most celebrated property of the blockchain networks is that they are decentralized – namely that no single node in the peer-to-peer network holds any special power over the shared database – a closer look at the intense interest by industry shows that this is not in fact such a crucial property for most applications.
  • We claim that the deeper reason for intense interest in the blockchain is simply that it was the first fully functioning example of a digital shared information reality.
  • the blockchain and shared ledger technologies cannot support large-scale digital consolidation, including, for instance, all financial transactions, all continuous geo locations, all server queries, all code executions – it is very to have all stakeholders store everyone’s information since the dawn of time and maintain permanent consensus over everyone’s information.
  • the blockchain was simply not designed for this.
  • the blockchain’s popularity cannot be explained by the decentralization meme – centralization has worked fine, both throughout history in general and for digital transformation.
  • the blockchain allows stakeholders to maintain consensus over facts using purely digital means, for the first time giving us a glimpse of the world beyond document-based consensus.
  • the blockchain can support small-scale horizontal digital consolidation between a small group of stakeholders transacting limited amounts of information, but not large-scale digital consolidation.
  • the blockchain does not have anything to do with vertical consolidation or any notion of integration of the information flow from reality to presentation; it is focused on the horizontal information objects slice.
  • Evidence that the blockchain frenzy is riding on a vague feeling that something big is coming, and that this vague feeling indeed points to digital shared information reality (and not to, decentralization) is the recent hype around Ethereum contracts known as nonfungible tokens (NFTs).
  • NFTs nonfungible tokens
  • An NFT can be assigned definite ownership and be exchanged and sold. Indeed an NFT can be auctioned, like a painting or the original declaration of independence.
  • Endgame digital transformation means that arm’s length counterparties can use purely digital information for reliable information exchange – that does not depend on paper or paper-like digital applications. Necessarily, this requires universally available layer of digital information that transcends the idiosyncrasies of digital systems – a fully digital new medium of information exchange.
  • Bitcoin is the first-ever widely adopted fully digital shared information reality. It is indeed the first sign of what’s to come – but not in the sense decentralization but in the sense of digital transformation. Bitcoin (and other popular cryptocurrencies) is a shared information reality anyone can partake in, and it’s completely digital. That has never happened before on such a scale.
  • NFTs Nonfungible Tokens
  • the blockchain was designed specifically for crypto-currency and thus its design revolves around the notion of a transaction, and the requirement for full consensus – all stakeholders in the network agree of the entire world view at any given moment.
  • digital transformation as discussed above, a tiny number of the stakeholders will ever be interested in any fact published to the network: having everyone store everything simply makes no sense.
  • the fact that each stakeholder holds a copy of the ledger makes it fundamentally incompatible with endgame digital transformation: it’s as if every person in the country held a copy of every company accounting book since the year 1600.
  • the requirements for decentralization and full consensus mandates proof of work or proof of stake – and is thus hard to impossible to scale. In proof of work the computation is made intentionally hard – not a scalable design choice.
  • Embodiments of the present invention posit that there is a way to exchange information – a system of information objects - which is radically new, and radically different to any other in history.
  • This way can be implemented using presently available information technology – computer networks, hardware, and software. It offers a wide array of advantages and improvements over current practice and provides very substantial value and benefits. This way is the inevitable next stage of the digital revolution. In fact, all around us are subtle signs that we are already well on our way towards this next stage.
  • Unique Digital Reality UMR.
  • Currently available information technology makes available a radically more advanced system of information objects than the ones presently used; this advanced system of information objects enables radically wider mirroring, radically more trust and cooperation, with radically reduced costs in terms of time, effort, and resources.
  • a unique digital object may contain the machine-readable code that validates it, consistent with the digital transformation principle verification happens.
  • Unique digital objects are things. For example, they can be named, owned, transferred, rented, cited, and exchanged. They are as real and as unique as a physical original document. can be owned, referenced, organized, and used. Data stops being a nebulous entity and becomes a concrete, named resource.
  • software processes that process unique digital objects produce results that are themselves unique digital objects. In this sense, software acting on unique digital objects, resources are a transformative power in human history: First, finance, auditing, law, insurance, and healthcare all become software endeavors. Second, we can process data in a systematic way that transforms human life.
  • UDR is a collection of information objects, along with the use patterns and protocols that govern creation, exchange, and verification of these objects, namely turning them into facts.
  • UDR allows wide expressive power for mirroring and verb implementation that is much more advanced than anything presently available.
  • UDR enables digital consolidation and the full benefits of endgame digital transformation, as discussed above Recall that any shared information reality implements what we called verbs.
  • verbs Let us examine the verbs of Unique Digital Reality – see Table 2. Table 2 – The Verbs of Unique Digital Reality
  • UDR allows information to flow easily and be created, stored, exchanged, and inspected by software at dramatically lower costs than presently used shared information realities; it also supports and enables radically new ways to extract insight from information.
  • Commitment is the only way to create immutable digital objects.
  • the digital world still uses documents (some of them digital documents) as information objects for arm’s-length information exchange, and not machine-readable files or Web pages.
  • a fundamental enabler for any digital shared information reality is thus the ability to create and exchange immutable digital information objects. This in turn is enabled by the act of committing new digital objects before all potential stakeholders – so that any interested stakeholder (a fact receiver in the fact exchange cycle) can compare the information object presenter to it with the committed version and verify that the object has not been altered – essentially making the object immutable.
  • Commitment schemes are examples of committing new digital objects before all potential stakeholders – so that any interested stakeholder (a fact receiver in the fact exchange cycle) can compare the information object presenter to it with the committed version and verify that the object has not been altered – essentially making the object immutable.
  • the main design choice that must be made is: How does the fact receiver know that the object has been committed at the purported time with the purported digest? This choice affects the entire architecture of the digital shared reality based on the choice of commitment scheme. Essentially, either the fact receiver receives all available digests ever created by all other stakeholders, so that they can verify themselves by checking when they received it, or else the fact receiver must ask someone they trust and who has received it. the blockchain follows the first choice – all stakeholders hold a copy of the shared ledger, which contains all digests ever created by any stakeholders since inception of the blockchain.
  • the fact receiver should ask the fact presenter and receive both the digest of digests, which can be trusted, either by seeing it on her ledger or by asking a trusted witness, and the block of digests for which the digest of digest has been calculated.
  • This is essentially the idea behind 2 nd -layer the blockchains, e.g. Ethereum rollups – where only a digest of digests is stored on the public the blockchain; verification of a digest requires a verification server that can respond to a request and provide the full digest block.
  • Privacy-preserving commitments - separating the digest storage from payload storage.
  • Objects in physical reality are represented by unique digital objects that contain a unique object identifier (such as a serial number).
  • the object in physical reality may display a machine-readable code (such as a barcode) that contains a universal identifier, unambiguously connecting it to the corresponding unique digital object.
  • unique digital objects are software accessible, software processes can be used to track an inventory of physical objects. (See description of the Omnicodes embodiment below.)
  • Events in physical reality are represented by unique digital objects created by UDR-enabled measurement devices or sensors.
  • Such devices may make measurements, e.g. camera or alarm motion sensor, or may sense other measurement devices, e.g. door access card reader, handshake device. These devices may have biometric capabilities to identify a human user. These devices may have operating system-level UDR access and are able to generate a stream of unique digital objects, each signed by the device and containing other details such as identity of human identified; interaction details with other measurement device; GPS coordinates; etc. • Objects in legal reality. Legal entities, contracts, and other objects in legal reality are represented by unique digital objects. The inter-citation of these objects mirrors the connections in legal reality, e.g. a contract unique digital objects cites the unique digital objects corresponding to individuals and entities who signed the contract, unique digital objects representing e.g.
  • the community of stakeholders is the entire Internet, and in this case, UDR becomes a new layer of reality accepted universally and globally.
  • This new layer is similar in nature to more familiar artificially constructed realities such as the legal reality where the objects are laws, rulings, corporations, contracts, and so on, and the financial reality where the objects are monetary sums, accounts, financial transactions, debt notes, and so on.
  • the legal and financial realities, and in particular the universal recognition of artificial objects in these realities have enabled growth and creation of wealth of unimaginable proportions.
  • the disclosure herein teaches how a Unique Digital Reality enables creation of significant growth and wealth, including new products, new services, new occupations, and dramatically more efficient implementations of societal and business processes.
  • UDR poses a concrete, systematic and standardized alternative to the current state of the art in handling all aspects of digital information in our society. Moreover, UDR specifies standardized interfaces for accessing digital information and operating on digital information. UDR specifies standardized protocols and meta-protocols – based on a novel, comprehensive conceptual framework – for creation, storage, indexing, access control, exchange, inspection, version control, updating, verification, validation, reconciliation, citation, amalgamation, ownership assertion, and inter-connecting of digital information.
  • Pieces of digital information turn from isolated entities, which exist on separate platforms and therefore have no shared existence, into universally accessible shared entities with universally accepted properties.
  • the transition from the existing state of the art into UDR is like connecting the world’s computers using the Internet, whereby advancing from isolated entities into a universal network of inter-connected, universally accessible entities.
  • UDR it is possible to cite, reference, inspect ,and reconcile any piece of information, or fact, previously deposited to UDR, regardless of when the fact was created and regardless of the system on which it was created.
  • Standard software interface With UDR, each piece of digital information exhibits a standard interface, through which it can be accessed, manipulated, and verified. In a preferred embodiment, this interface is an API - a software interface.
  • UDR Under UDR, a complete provenance trail of a fact is often available, including both underlying facts and underlying deductive reasoning processes, which is amenable to automatic verification. In other words, a fact in UDR exposes the means to verify it automatically.
  • Error prevention Facts in UDR cite each other using a universally unique identifier. New facts are often created from previous facts by software rather than manually. This reduces the probability of human error and makes it possible to verify, often automatically, that an error did not occur.
  • Fraud prevention Basically all forms of fraud, for example in banking, insurance, healthcare, and finance, are possible due to lack of sufficient scrutiny and verification.
  • UDR Digital civil rights.
  • UDR turns digital civil rights from an abstract debate into a concrete reality, which can be readily implemented in software.
  • Data ownership A fundamental property of information in UDR is ownership. In the existing state of the art, data ownership is vague at best; and large internet companies hoard and trade personal information given to them for free by the population of users. Under UDR, each piece of digital information is attributed to the individual or person who created it. • Free data markets.
  • UDR makes it possible for an individual to rent or sell their data on the free data markets that will be formed. This implements a basic civil right that is being discussed but cannot be enforced under the current state of the art – the individual’s right to control and monetize information. It can be argued that data locked away in the systems of a few large companies and organizations has become the world’s largest untapped resource, holding untold economic value; UDR specifically addresses this point and enables the society to tap into this resource. • Data access tracking. Due to UDR access control, a data access event in UDR is itself documented on UDR. As a result, the owner of a piece of digital information has complete knowledge of the piece’s access history. 4. A new frontier of technological possibilities.
  • UDR enables a wide array of completely new products, services, markets, business models, occupations, and social interactions, none of which is possible (or even conceivable) under the current state of the art.
  • Inter-operability of the entire digital ecosystem Under UDR, it is possible to design and implement systems which operate on the entire digital ecosystem, namely, process information and draw conclusions from a wide array of information sources, across legal entities. This allows completely new ways of discovery, verification, reconciliation, and automatic deductive reasoning based on digital information from diverse sources.
  • Software execution as a fact UDR makes it possible to address the very act of software execution as a fact or a new piece of digital information.
  • the digital ecosystem includes, in addition to raw pieces of information, facts pertaining to execution of code against these pieces of information.
  • Smart contracts • Broad Artificial Intelligence.
  • a key property of present-day artificial intelligence systems is that they are trained for a very specific task. A fundamental bottleneck in development of these systems lies in the need to obtain large amounts of training data; for the typical individual, research organization or company this is usually impossible.
  • UDR makes it possible to develop systems, which specifically address and alleviate certain obvious high-profile shortcomings of the current state of the art in information handling, such as fake news; data citation and ownership; financial fraud; credible citation of scientific data and scientific research; election reporting; validity of postings on social networks; validity of corporate public disclosures; data privacy and acceptable use of personal information; and much more.
  • UDR versus state-of-the-art systems of information objects.
  • UDR is a consolidated system of uniformly software-accessible and permanent information objects. All three attributes (consolidated system, uniformly software-accessible objects, permanent objects) are crucial for vertical digital consolidation.
  • Figure 14 compares the World Wide Web (WWW), document shared reality, digital fragments and UDR: objects in WWW 1401 are uniformly software accessible - but not permanent; documents (both physical and digital) 1402 are permanent – but not software accessible; and fragmented software systems 1404, e.g. enterprise software systems, are locally software-accessible, but not uniformly so.
  • UDR 1403 is consolidated system that consists of uniformly software-accessible and permanent objects. Examples Here are a few examples of how UDR is used in various contexts. • Physical sensors record measurements directly on UDR through an embedded module. This makes measurement trustworthy as they are signed and committed now of measurement. Measurements in UDR can then be accessed for analysis or verification by any third party with access credentials, at any later point in time.
  • UDR User Data record information directly into UDR. It is owned by the patient with access privileges to the medical staff. This information can be used during care for automatic verification of care protocols, and later for medical billing, medical insurance claim processing, auditing, and retrospective medical studies.
  • Social networks All personal information is recorded on UDR under the ownership of the person owning it, not under the ownership of a social network service. This includes personal content such as personal photos, videos, location check-ins, etc.
  • the service provided by a social network Internet company is a user interface makes accessible some personal information recorded on UDR to other social network users. Enduring Network Interfaces.
  • a presently preferred implementation of UDR is based on server interactions – a technology that is basically running the digital world today. It is scalable enough to support large-scale digital transformation.
  • UDR enables “horizontal” digital consolidation.
  • horizontal digital consolidation requires that digital information objects (both observed and deduced) would be permanently accessible to arm’s-length stakeholders (with access privileges) through a uniform interface.
  • UDR enables horizontal digital consolidation as it mirrors all vertical sections, including observed information objects, deduced information objects and their deduction processes; furthermore different stakeholders can grant and gain access to each other’s unique information objects, and access them through a cross-platform stable software interface. This is consistent with the information flows principle of endgame digital transformation.
  • Figure 15 compares digital information transfer under digital fragmentation with digital information transfer with UDR, the latter being an enabler of digital consolidation: entity 1501 wishes to communicate digital information to entity 1502. Under digital fragmentation, and using e.g. digital files, the information object 1503 to be sent must be copied during transfer. A new copy 1504 is created during transfer, and the process results in two independent copies (e.g. of digital files) 1503 and 1504. In contrast, when an entity 1505 communicates to a different entity 1506 a unique digital object 1506, the object is not copied, and remains unchanged. Instead, entity 1505 grants entity 1506 access to the unique digital object 1506 on UDR. UDR Enables “Vertical” Digital Consolidation.
  • vertical digital consolidation requires the vertical information flow – the links between observed information objects to the information objects deduced from them and to the processes that were used to deduce from them, and from deduced information objects to their human-readable visual presentations – will be explicitly exposed in digital format.
  • UDR enables vertical digital consolidation because it allows explicit, stable citations that mirror the links along the vertical flow in unique digital objects and mirrors all elements of the vertical flow from observed information objects that mirror objects, states, and events in physical, legal, financial and IT realities to processes, deduced information objects and their presentation on human-readable user interface.
  • Figure 16 compares vertical (source-to-user) information flow using digital files to the vertical information flow using UDR: with digital files, information objects 1601 do not have unique identifiers and cannot be unambiguously connected with other information objects; the processing stage 1602 (whether computation or ICC processing) cannot be recorded in digital form; the presentation of results 1603 is siloed away from any other digital information, namely, presented results cannot be connected with the processes and information object that created them.
  • information objects 1604 represented as unique digital objects
  • processing stage 1605 can be recorded in digital form (e.g.
  • Verifiable Code Execution V/X
  • Verifiable code execution is a method for mirroring the event of code execution in information objects, and in unique information objects.
  • the environment executing machine readable instructions, a virtual machine, an interpreter or even the operating system itself includes a V/X module that is active and performs operations in parallel to the code execution process. These operations include capturing the source code executed, the input data structures, the output data structures, the course of execution (including any subroutine calls and library calls), and intermediate data structures such as inputs and outputs to certain subroutine calls.
  • the code itself may include specific instructions to the V/X module. These instructions do not alter the execution of the code – rather they can be used to regulate the operation of the V/X module.
  • instructions to the V/X module may flag an important subroutine call so that its own inputs and outputs will be recorded at runtime; or may flag a certain variable as a variable of special importance that can later be presented as a result on a user interface.
  • the V/X module gathers information at runtime, effectively recording the course of the computation, and then creates a collection of interconnected information objects.
  • these information objects are unique digital objects on UDR: variables and data structures, as well as source code, are each contained in unique digital objects; the inter-connections and inter-citation of these unique digital objects spells out the course of the entire computation.
  • V/X enables vertical digital consolidation of flows whose processing stage includes a computation. Without V/X there is no way to mirror a computation in shared information reality; and without mirroring there is a crucial disconnect between the results of computations, as they are advertised in human-readable form, and between the process which created those results and the underlying information upon which the process was based. This disconnect has some highly visible consequences today: for example, the 2008 housing crisis was essentially caused by an inability to connect numerical results (results of risk models, to underlying information – auditing these numerical results required recovering the underlying computation and data which was a near-impossible computational forensics task.
  • V/X enables data refineries, standard-grade data markets and standard preprocessing procedures. When code execution is not mirrored in information objects, and the results of code execution are fragmented away from the computational process that produced them, there is no way to know for certain the details of preprocessing steps that were applied to data at hand. Conversely, V/X allows to connect data to the preprocessing steps that were applied to it; this enables exchange of data that has verifiably passed certain quality tests, verifiably upholds some quality standards. This in turn enables data refineries as services that produce UDR objects that contain data of a known quality grade, and markets to trade such objects. • V/X enables computation markets.
  • a computation can be a costly thing: for example a computation that required 10,000 hours and applied specified code to specified inputs to produce its outputs, is a valuable resource.
  • V/X effectively caches computations on UDR and turns code execution into an object that can be traded – the object specifying in full detail the inputs used, the process applied these inputs, and the results obtained.
  • V/X enables counter-factual execution and other kinds of re-use of computational results.
  • a counter-factual execution asks how would results of a computation change if we changed some of the computation parameters, some of the methods implemented, or some of the computation inputs.
  • a collection of unique information objects created by V/X can be used to re-execute the computation.
  • counter-factually executing a computation that produced a given result is possible.
  • V/X enables dataset amalgamation. Amalgamation of data gleaned from different sources is a difficult and important problem in data science. There are various choices made during dataset amalgamation, and when the computation performing the amalgamation is not recorded, there is effectively no way to know how it was performed.
  • V/X With V/X recording the amalgamation process and explicitly connecting the amalgamated dataset to the original datasets, and to the amalgamation code executed, it is possible to inspect the amalgamation process and the original dataset before using the amalgamated dataset.
  • V/X makes it possible to extract massive amounts of new insight and knowledge from the scientific literature and from financial reports. It is customary to summarize results of complex numerical computations with a few numbers, figures, or charts that appear in human-readable form.
  • a scientific publication for example, often summarizes results on incredibly complicated computations and data analyses in human readable form accompanies by some descriptive text. However it is the underlying data and the computational process that holds the real value that can be extracted from the scientific research reported in a publication; the language of the publication itself is of little value.
  • V/X makes it possible to explicitly connect published results to their underlying computation and data, such enabling to harvest using software processes underlying data.
  • V/X enables regulation of the software industry and in particular testing mandates and testing standards for mission-critical software systems and AI systems. Regulation of software systems has been a long time coming; it boils down to mandating software tests that assert quality assurance, safety, fairness, etc. of software that is put forth for public use. If computations are intangible things, this is not possible; however with V/X recorded code execution, it is possible to represent to a regulator, conclusively, that certain tests have been performed.
  • V/X enables reverse citation of data sources that underly results on human- readable user interfaces (such as scientific and financial results). See above.
  • V/X enables “the experience of having data.”
  • large datasets are required to train high-quality machine learning models. Entities compete as data hoarders because the owner of a large data set is in a better position to train better machine learning and AI models.
  • the owner of a dataset can, however, train a machine learning model for another entity for a fee; it is privacy concerns that often prohibit the owner of a dataset (a medical organization, from transferring it to a party that would be interested in these data for the purpose of training a machine learning model.
  • V/X and UDR make it possible for the data owner to train a model on a third party’s behalf on their own data, then proving to the third party that the model has been indeed properly trained.
  • V/X enables markets for trained AI models.
  • a trained AI model may be small in terms of information storage; it represents the value of the training data, including the cost required to collect the training data and/or label it, and the value of the computation required to train the model, which may be substantial.
  • GPT3 and similar trained models are well-known examples of trained models delivered for us without access to the training data used for their training.
  • V/X makes possible markets for trained AI models; for example, the trained AI model can be a unique digital object, V/X can be used to prove that training did indeed take place, and zero-knowledge proof methods can be used to prove that it was indeed trained on the claimed training dataset – without disclosing the dataset itself.
  • V/X enables “data blame.”
  • the reliability of traditional (procedural) software systems depends only on the quality of the code.
  • AI models are different – their reliability depends on the quality of the training code but also on the quality of the training data.
  • a model trained by noisy data may produce unreasonably wrong predictions even when the training code itself is perfect. For this reason, debugging AI models requires access to the training data that was used to train them. If computations are disconnected from their results, the connection between the trained model and the training data it was trained on is implicit and in fact the training data may be lost or deleted.
  • this connection is explicit – for example, the unique digital object that contains the final trained model is connected to the objects that represent the training computation, which are in turn connected to the object(s) that contain the training data.
  • Standard Information Consistency and Compliance Language SICCL is a characterization of machine-readable form to express consistency and compliance requirements in an array of information objects. It can take the form of a machine-readable language or may be defined using existing computer languages, e.g. Python. Entities in SICCL are unique information objects, they various data fields and inter-citations. It makes it enables definition of allowable values and semantic types given fields in an information object can take; relation requirements to be satisfied by two given fields of two information can have; and so on.
  • a SICCL script can be executed on a SICCL interpreter or an interpreter / virtual machine of the host language in which it is implemented.
  • the primary goal of SICCL is to cast information consistency and compliance requirements – such as those that make up a bureaucratic process - so far only understood by humans and not cast in machine-readable format.
  • ICC verification is an inherently linear, algorithmic task, which is a perfect candidate for automation in software, and explain how limitations in the present information systems prevent such automation.
  • SICCL verification of information consistency and compliance becomes a software problem and is readily automated in software.
  • SICCL is both machine- and human- readable, so that requirements written in SICCL can be understood by non-technical users as well.
  • Embodiments of the invention teach how to create unique information objects on UDR, which make it possible to verify that an interaction has taken place, and to embed these key observed facts into digitally consolidated vertical information flow.
  • UDR enables technological Artificial Intelligence (AI).
  • AI Artificial Intelligence
  • the future is much more than just about efficiency and cutting costs.
  • the future is something the possibility of completely new products, services, markets, and occupations.
  • the mature digital age is about creating new kinds of knowledge, which is based on digital records of everything that happens.
  • Such a mature digital age will be enabled by shared digital information reality representing, in software-accessible digital form, everything we have learned, everything we have experienced, and everything we have known, and will usher in a new level of artificial intelligence. Indeed, when computers can draw on all human experience everywhere, AI systems can be trained in ways that are not even raised as a possibility today. AI systems today are simplistic, in part because of the limited access to information – each AI system is trained for a very specific task, on a very specific and narrow dataset. AI with access to a complete UDR could be much more sophisticated. The computer age is developing toward our ability to excavate knowledge, to learn and to sense and to experiment against reality in a multi-modal way.
  • a universal addressing system may be like Universal Resource Locators (URLs) or even consist of URLs; or it may be based on the blockchain shared ledger entries.
  • Storage may be implemented as a single system of servers (HTTP or others), where a single central entity is responsible for storage and content serving; or it may consist of a network of competing serviced providers all following a single protocol that is like HTTP website storage.
  • Servers respect an API for access privilege control to information objects.
  • Each object exposes an API with various methods and properties, particular to its type, for example an image information object exposes methods for displaying it in various formats, while a contract information object exposes methods for retrieving contract party identities, etc.
  • information objects are digital objects and are decoupled from any visual or graphical representation – they may be displayed, visualized, or embedded in different contexts or formats.
  • access is changed.
  • Digital and physical documents / files must be sent – indeed the notion of e-mail is just an extension of physical mail, which assumes that the information object must be sent from sender to receiver.
  • an enduring network interface is universally accessible pending access privileges – so to exchange it I just need to grant access. I can never lose it – as it is immutable and permanent. This in turn implies nothing short of a revolution in information exchange because it means that digital information objects become things. Each has a unique, permanent existence and a name.
  • Information objects as assertions are either observed meaning that they make an asserting regarding a thing, state, or event, in reality (physical or other), or else they are deduced, meaning that they assert that a certain deductive reasoning process has been applied to previous information objects and obtained the asserted result.
  • the water meter reading on 1/1/2000 in so-and-so’s apartment is an observation, as is the assertion that $100 was transferred from account X to account Y on time Z.
  • the government owes me $1000 tax return for the tax year 2020 is a deduced fact – it was deduced by a specified reasoning process (a calculation based on tax law) applied to previous information objects (my income, my tax payments, etc.).
  • Each is syntactically and semantically labeled, e.g. the identity object is marked as identity.
  • the loan application is not a PDF or a sheet of paper, rather it is structured information, such as: Buyer: a.com/123 Seller: a.com/456 Property title: a.com/789 Sale contract: a.com/999 Appraisal report: a.com/111 Loan sum: 600 Loan sum currency: USD Above, the URLs such as a.com/123 are all permanent URLs that act as universal identifiers and access addresses to enduring network interfaces. Verification: (i) Manual verification – consistency, e.g. the party on the loan contract is the same identity as party on the sale contract; the property on the sale contract is the same property on the appraisal report; etc.
  • enduring network services have definite ownership and are unique – they exist in a consolidated digital universe much like WWW.
  • Systems, products, and services can use information in enduring network interfaces across boundaries of organizations, governments, and individuals – given appropriate access permissions.
  • Universe of stakeholders. Enduring network interfaces serve a collection of stakeholders. They may be implemented on a local corporate network in which case they only serve local stakeholders; or they may serve arbitrary stakeholders such as anyone with an Internet access.
  • An enduring network interface is implemented as a RESTful Web interface. Server interactions are HTTP client-server interactions.
  • the permanent unique identifier is in the format of a SHA256 output, e.g.: “e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b85 5”.
  • Interface authority An enduring network interface exists indefinitely, namely, responds to queries at an address associated with its unique identifier indefinitely. The entity responsible for the continued service availability of an enduring network interface is called the interface authority responsible for it. In a universe of stakeholders, there may be one or more interface authority.
  • the interface authority operates an HTTP Web server serving all the Web interfaces that exist under the responsibility of the authority.
  • the authority operates through the fictitious DNS domain facts.com.
  • a central interface registry running from a root domain (for example, the fictitious domain “registry.com”) may hold a table connecting a universal identifier of an enduring interface to the authority responsible for this interface. For example, it associates the enduring interface with identifier “ae3c” with the domain of the authority responsible for this interface.
  • ae3c identifier “ae3c”
  • one authority may use an HTTP server (as above), while another authority may implement a parallel system using FTP and do on – all implementing the same protocol for creation and use of enduring interfaces.
  • the notion of an interface authority is analogous to that of a bank in the financial system, and a digital object that is served by an authority is analogous to a bank account.
  • a stakeholder To create enduring interfaces, and / or access existing interfaces, a stakeholder must have an identity registered in advance with the interface authority. Each registered stakeholder is allocated a universally unique identity identifier.
  • the identity credentials themselves are stored as enduring network interfaces, whose payload is the authentication credentials – so that the identity identifier is in fact the unique identifier of an enduring network interface.
  • the interface authority provides an authentication service wherein a stakeholder can authenticate, that enables authenticated server interactions.
  • the authenticating interface authority issues an access token to the authenticated stakeholder, which is then used in server interactions with that authority. Identities can be assigned to natural persons – people – or to legal entities.
  • An identity assigned to a natural entity can be related to identities of people – e.g. officers of a company.
  • the interface authority enables stakeholder registration using either an API or a www page.
  • a new registered stakeholder is issued a universal identity identifier and a password.
  • An enduring network interface is created for each identity, whose payload contained the hashed password; the universal identifier of the interface is the identity identifier for this stakeholder.
  • the interface authority enables login through a secure API, where universal identity identifier is submitted and an access token is returned. The token is then attached to any further server interaction with the authority.
  • the access token is implicit in the running example below – see Table 3.
  • the interface authority enables registration which includes collection of biometric identification.
  • the biometric identification information is stored on the payload of the enduring network interface created for the new identity.
  • the interface authority enables login through a secure interaction with a biometric device, where universal identity identifier and biometric scan are submitted, and an access token is returned. The token is then attached to any further server interaction with the authority.
  • Table 3 - Server interactions in authentication In all server interactions described below, the stakeholder is assumed to have an access token prior to the described interaction. Universality of identity. The universe of stakeholders – all possible stakeholders in the network – is a single pool. In the case of multiple responsible network authorities, all authorities must share a single identity system.
  • each interface authority maintains its own authentication and while the identity identifier for a stakeholder is unique and recognized by all authorities, a stakeholder must authenticate with each authority separately.
  • Network address Each interface is accessible through a network address associated with its unique identifier. In some implementations the address itself is hard-coded upon creation of the interface and becomes permanent; in other implementations an address resolution system (analogous to domain name server - DNS) can be used to dynamically resolve the network address based on the universal identifier. For example, in implementations when more than one authority exists, a global resolution system may keep a database of all allocated identifiers of all existing interfaces and resolve the network address of each interface at its own responsible authority. This design allows change of authority or multiple authorities (see below).
  • Stable network address In some cases, it would be required to provide a stable network address for an enduring interface, namely, as address that will remain unchanged even if the interface migrates between interface authorities. If a central registry is used, the network address of the central registry can serve as a stable address prefix for all enduring interfaces, redirecting to the address of the authority as shown in the central registrar table. Running example – continued.
  • the network address associated with a permanent network interface is the authority domain, followed by ‘/’ and the universal identifier, e.g.
  • the authority domain is “facts.com” and the universal identifier for a fact under the responsibility is “ae3c” then the network address is “facts.com/ae3c.”
  • the RESTful API HTTP commands are available at this address, e.g. “GET https://facts.com/ae3c/get_payload.”
  • the central registry associates the interface with identifier “ae3c” with the domain of the authority responsible for this interface.
  • the central registry also runs an HTTP Web server; it will redirect all requests to “registry.com/ae3c” (a request stating the universal identifier “ae3c” without specifying the responsible interface authority) to the address at the correct authority, namely, “facts.com/a3ec.” If the interface “a3ec” migrates from the authority “facts.com” to another authority, the request to “facts.com/a3ec” can return a “HTTP permanent redirect” response pointing to, “registry.com/ae3c.”
  • the payload of an enduring interface is the core immutable data made permanently available through the enduring interface. Payload can consist of arbitrary binary data; or may be one of pre-specified data types and formats.
  • the authority maintains a defined list of possible payload types, which may be extended from time to time, and for each payload type, a list of possible formats.
  • Primary format In a formatted payload, one of the available formats is defined by the interface authority as the primary format. In an embodiment, the payload is stored by the storage authority in the primary format. Running example – continued.
  • the payload type “image” allows the possible formats “jpeg,” “png,” “gif.”
  • the primary format for “image” is defined as “jpeg.”
  • the uploaded payload is converted to format “jpeg” and stored by the authority in this format. Another embodiment.
  • the primary format is the format in which the payload has been originally uploaded – namely, the payload is stored in the same format in which it was created and uploaded.
  • Access privileges An interface authority is potentially responsible for serving a very large number of enduring network interfaces; the number of enduring interfaces can only increase with time.
  • An enduring interface includes specification of access control, specifying by universal identity identifiers those stakeholders that are allowed access.
  • different access levels are possible, for example read access can allow access to all API including payload access, while header access can only allow access to parts of API that respect payload privacy, for example allowing access to time-of-origin, owner identity, payload digest, etc.
  • Access control specifications are considered a mutable part of the enduring interface – rather than properties of the interface authority.
  • access privileges may be changed by owner using API calls. If the enduring interface migrates to a different responsible authority (see below), the access control specification migrates with it. Another embodiment.
  • some access privileges are defined permanent upon creation, so that the owner cannot withdraw them later.
  • Metadata - mutable meta-information The payload of an enduring network interface is committed upon interface creation and may not consecutively be changed. However, optionally, an enduring network interface may store mutable meta-information attached to the interface, such as machine-readable code for verification of the information contain in the payload, encryption keys, etc.
  • the enduring interface may enable API commands to update, inspect metadata, such as comment to inspect or execute verification code. Ensuring uniqueness of new universal identifiers.
  • interface authorities are responsible for coordinating namespaces or address spaces to prevent collision of universal interface identifiers. Another embodiment.
  • Each authority has a hard-coded predefined prefix for identifiers. Each authority allocates a new, unused identifier with its own prefix, so that identifier collisions are prevented. Another embodiment. Collisions are prevented using a central identifier registry. Prior to allocating a new universal identifier for a new interface, each authority verifies with the central registry that the desired identifier is free, registers the new identifier with the central registry, where it is also associated with the authority that created it. See Table 4. Table 4 - Server interactions: ensuring uniqueness of a new universal identifier (in another embodiment) Allocation of a new universal identifier.
  • the identifier allocated to a new interface is the hash (for example, SHA256) of its payload in its primary format. If this address is taken, namely if an interface with the same payload, an alternative identifier is used. Digital Signatures.
  • the payload of a new enduring interface is digitally signed upon interface creation by the stakeholder creating the interface (the owner). To sign, the stakeholder first creates a public key enduring interface associated with his identify identifier, which publishes a public key. During creation of a new enduring interface, the signature created with the public key, and the identifier of the public key interface are attached to the payload and included in the immutable component of the enduring interface.
  • an enduring interface is created by a stakeholder (a hospital, but is owned by another stakeholder (the patient).
  • a preferred embodiment enables a stakeholder A (patient) to grant permission to stakeholder B (hospital) to create enduring interfaces on their behalf.
  • the payload is signed by stakeholder B (hospital)
  • the interface owner is stakeholder A (patient) with access privileges (possibly permanent and irrevocable) to stakeholder B (hospital).
  • the payload of an enduring interface often includes citations of existing enduring interfaces.
  • a payload consisting of HTML, word processor, or spreadsheet content may include numbers, images, and tables which are cited from a payload, or parts of a payload, of an existing enduring interface.
  • importing such information pieces (such as numbers or images) is never done by copying them, but by citing the identifier of the enduring network interface where they appear.
  • an import convention or a plugin used to implement linked import from an existing enduring network interface Citing an enduring interface. Enduring network interfaces cite each other, and enduring network interfaces may be cited by other resources.
  • An enduring interface can be imported in many ways – in some cases (such as when the payload is an image) the entire payload can be imported in a natural way.
  • the API can implement a default response to an empty or default API command (a command that specifies the interface identifier and nothing more).
  • the import uses an API command to specify which specific information from the interface payload is being imported.
  • the commands can specify a format, other parameters, such as image requested width and height in pixels, or fields identified through the object’s API.
  • Example - An enduring interface citing another using network address The payload of some enduring interface may contain a list of linked imports to other enduring interfaces.
  • Running example (continued) importing the content of an enduring interface.
  • the central registrar “registry.com” forwards any HTTP requests to “registrar.com/a8qs” of an enduring interface whose identifier is “a8qs,” to the correct domain of its responsible authority “facts.com/a8qs.”
  • Amalgamation enduring interfaces In another embodiment, the enduring interface protocol supports a special kind of interface, with are amalgams of existing enduring interfaces.
  • the payload of the amalgamation interface contains universal identifiers and possibly also digital digests of contained existing enduring interfaces.
  • the amalgamation may be simple, in which case the amalgamation is just a list of existing enduring interfaces packaged together, or may involve code execution, in which case the amalgamation interface may cite an enduring interface mirroring the code execution that created the amalgam. Example.
  • An amalgamation enduring interface may contain in its payload the union of the list (removing duplicates); a citation of the two underlying interfaces; and a citation of an enduring interface created with verifiable execution, which recorded the code execution merging the two lists.
  • Digital information is by nature mutable; creating permanent, immutable digital objects is not a trivial task.
  • Commitment is a crucial stage in the process of creating a new enduring interface.
  • Commitment – the act of publishing the object or a cryptographically secure digest of the digital object – is essentially the only way to create immutable digital objects.
  • a third party which is later interested in verifying that a given digital object has remained unchanged since its purported creation time in the past – must have access to a trusted record from the purported object creation time, containing the fact or its digital digest. It follows that choosing a commitment scheme boils down to choosing a system for trusted record management.
  • the universal identifier is the SHA256 digest of the payload in the primary format, meaning that the universal identifier is identical to the secure one-way digest published for commitment.
  • the digest used for commitment is the SHA256 of the payload in the primary format, possibly with an added digital signature element.
  • Stakeholders who note the publication can themselves record the universal identifier of the new interface, the published hash, the time at which they received the publication, and, if published, the owner identity. They can late use this information to validate the integrity, time-of-origin, and owner identity of the interface (see below). Stakeholders who do not record all commitments published must rely on a trusted record of published commitments.
  • the commitment e.g. digital digest, such as a hash, and new universal identifier are published on a the blockchain or other shared ledger and are available to all network stakeholders. Any stakeholder with access to the shared ledger, and who trusts the records on the shared ledger, can use it to verify a past commitment.
  • the commitment is achieved using a server interaction. This embodiment is based on server interactions to establish trusted records of commitments, and specifically uses witness servers.
  • witness servers can exist in a network of trust, whereby when a one server is notified of a commitment – whether directly upon object creation or indirectly through a trusted witness server on the network – it notes the commitment in its records and notifies any witness servers that trust it.
  • the witness server can be operated by an interface authority (and in fact be the same server used to serve the enduring interfaces) or can be independent of any authority; any stakeholder in the network can operate a witness server.
  • a witness server accepts two kinds of requests: ⁇ a request to register a new interface (consisting of the universal identifier, the payload digest, and possibly the owner identity); upon receiving such a request the witness records the received information along with the timestamp at which it was received ⁇ a request to validate an existing interface (consisting of the universal identifier and the payload digest). Upon receiving such a request the witness performs a lookup for the universal identifier and digest; if found, it returns the time as recorded; if not found, it returns a “not found” response. Listeners, or secondary witnesses.
  • Witness servers can register as listeners with other witness servers; when a witness server records a new interface, it propagates the new record to all witness listening to it.
  • witnesses form a trust network analogous to the cascade of trust in SSL certificates.
  • a witness listens to any other witnesses it trusts; so that record of any new interface propagates through the trust network.
  • the interface is validated (see below).
  • Table 6 - Server interactions Another embodiment – batch commitments:
  • enduring network interfaces are committed in batches. This may occur when an end device that accumulates observed information objects is not network connected or has limited network connectivity; in this case the device only goes online periodically to commit a batch of new observed information objects.
  • a storage device (the end device, stores the commitment, e.g. the digests, of multiple enduring interfaces, and only published to the network or to the trusted record system a single digital digest of the record of all digital digests of these interfaces.
  • the verifier will have to obtain, e.g. from a witness server, the record of all digital digests in the batch; they can they verify that the digest of the record of digests has been committed at the purported time, and that the digest of the object of interest is indeed included in the record of all batch digests.
  • Batch commitments e.g. the digests, of multiple enduring interfaces, and only published to the network or to the trusted record system a single digital digest of the record of all digital digests of these interfaces.
  • an authority can create an amalgamation interface for a collection of new enduring interfaces and commit the amalgamation interface without committing each of the new interfaces separately. Because the payload of the amalgamation interface contains the digital digests of the each of the new interfaces, a committed amalgamation interface effectively commits of the interfaces it contains, as a verifier can first verify the committed amalgamation interface, and then proceed to verify each of the interfaces it contains using their digests, found in the amalgamation interface’s payload. Clock synchronization between stakeholders. Determination of time-of-origin for an enduring interface is key.
  • Time-of-origin and payload validation One of the key principles of information exchange using enduring network interfaces is that interested third parties (sometimes called “fact receivers” elsewhere here), who are interested in verifying a certain existing enduring interface, are not known at the time of creation of the enduring interface.
  • the commitment scheme must enable a third party, which examines an enduring interface of interest, to validate its payload integrity and time- of-origin. The validation method depends on the commitment scheme.
  • the validating party will: (i) use the interface API to retrieve the time-of-origin and payload in original format; (ii) calculate the payload digest; (iii) locating the universal identifier of the interface of interest on the blockchain; and (iv) compare the time-of-origin retrieved from the interface API and the calculated digest to those noted in the blockchain entry.
  • the validating party uses the interface API to retrieve the time-of-origin and payload in original format; (ii) calculates the payload digest; (iii) locates a trusted witness server and query it with the universal identifier of the interface of interest, and the calculated digest; and (iv) compares the time-of-origin retrieved from the interface API to that noted by the witness.
  • the validating party uses the interface API to retrieve the time-of-origin and payload in original format; (ii) calculates the payload digest; (iii) locates a trusted witness server and query it with the universal identifier of the interface of interest, and the calculated digest; and (iv) compares the time-of-origin retrieved from the interface API to that noted by the witness.
  • pseudo-code implementing the above.
  • a third party is interested in validating payload integrity and time-of-origin for enduring interface with identifier “ae3c.”
  • the responsible interface authority for this interface is found to be “facts.com.”
  • the trusted witness is implemented as an HTTP server in the domain “witness.com”.
  • an enduring interface may store in its mutable meta-information machine-readable instructions that implements verification for that interface. These instructions may be updated, inspected, audited, and executed without any change to the (immutable) payload.
  • API access The most common way to use an enduring interface is to invoke its API. The API allows an authorized stakeholder to retrieve interface properties such as time-of-origin, identity of the interface owner, and most importantly, elements of its payload in various formats.
  • a stakeholder with access privileges can invoke HTTP requests such as: • GET https://facts.com/ae3c/list_API_commands (return a JSON with all available API commands in the default API version) • GET https://facts.com/ae3c/owner_id (get the universal identifier of the enduring interface for the identity of the current owner) • GET https://facts.com/ae3c/original_owner_id (get the universal identifier of the enduring interface for the identity of the original owner) • GET https://facts.com/ae3c/creation_time (get the purported time of creation of this enduring interface) • GET https://facts.com/ae3c/digital_signature (get the digital signature attached to the enduring interface at creation time) • GET https://facts.com/ae3c/list_all_owners (get a JSON with list of all owners, with time where ownership was established, where owners are specified using the universal identifier of the
  • Any enduring interface includes fixed API commands to list available API version numbers; list commands for a given version; invoke commands in any specified version; and a default to invoke commands in the default (current) version.
  • a preferred embodiment allows any enduring network interface to include in its payload, possible in addition to other kinds of information, a key-value struct or dictionary that is available through its API.
  • Any payload includes a JSON with key-value content;
  • the standard enduring interface API offers methods to list available fields and get the value of a specified field, e.g.: GET https://facts.com/ae3c/list_fields GET https://facts.com/ae3c/get_field/seller_id Interface Access Control.
  • the API of an enduring interface includes commands to query, grant, and revoke access privileges.
  • Running example (continued) The following RESTful API calls are used to query, grant, and revoke access to an enduring interface.
  • users are specified using the universal identifier of the enduring interface of their identity.
  • GET https://facts.com/ae3c/access_list return a JSON list of access rights
  • PUT https://facts.com/ae3c/revoke_access?id w8x0 (revoke access to stakeholder with universal identifier w8x0)
  • an enduring interface with access rights that cannot be revoked by the owner. For example, consider a perpetual IP assignment that grants a certain entity access rights to some digital object in perpetuity, or digital objects that must be accessible to the government by law. In these cases the owner can specify access rights in a perpetual rights field, and these access rights cannot be denied later. Automated access policies. A stakeholder may create automatically by software a large stream of new enduring interfaces. Access privileges cannot be configured manually to such a large of interfaces; this must be implemented in policies responsive to the creation context of the interface.
  • the software generating enduring interfaces includes policies for grant access upon interface creation to certain groups of stakeholders; all enduring interfaces collected at a hospital, for example, may define the patient as owner but automatically grant full access to the primary care physician, HMO, and medical insurance provider.
  • the responsible storage authority may provide a service allowing definition of policies, such that interfaces are created with appropriate access privileges.
  • automated change of access privileges according to policies can be implemented by external software or the interface authority. Change of ownership; special ownership scenarios.
  • One of the key characteristics of enduring network interfaces is that they are unique permanent information objects, with a definite ownership status. The original owner of an interface is the stakeholder who authenticated upon interface creation.
  • enduring interface can be the legal owner of its payload – within the meaning of ownership in copyright law, intellectual property law, etc.
  • it can be sold, rented, bequeathed, or undergo temporary or permanent change of ownership.
  • enduring interfaces can have ownership definitions which are more elaborate than a single owner.
  • an enduring interface can be owned by several stakeholders such that any one of them enjoys full owner permissions; or such that only all of them together can authorize certain operations such as ownership change.
  • a primary-secondary ownership structure is possible — for example when an enduring interface is the property of a legal entity (a corporation, but a secondary owner is a natural person (an employee with effective control.
  • an enduring interface does not maintain a record of its ownership trail – change of ownership just changes the owner identity, with no record of the change.
  • an enduring interface maintains full record of ownership change – including the time of ownership change, the stakeholder who authorized the ownership change, and the new owner.
  • temporary change of ownership is allowed, such that the identity of the primary owner is maintained, while noting a temporary owner, e.g. to enable rent/lease.
  • an owner can create a will specifying conditions under which the interface is bequeathed, namely, change ownership to a specified heir.
  • a guardian or custodian can obtain effective ownership over an enduring interface even though such change of ownership is authorized by some legal function and not by the interface owners themselves.
  • the payload of enduring interfaces can be a complex and composite object, which consists of multiple values of data. When some of these values can be specifically names with a key identifier, it is possible to access specific components of the payload of an enduring interface instead of inspecting the entire payload.
  • a sub-address is a naturally defined key for a part of the payload. Examples include cell in spreadsheet; frame in a video; value in a form; etc. These do not have to be defined up-front; the enduring interface API can simply support API access to parts of the payload. Running example (continued). Consider an enduring interface whose payload is a spreadsheet.
  • the API of the enduring interface may implement a specific method such as: GET https://facts.com/ae3c/cell/G8
  • An Access hook in an enduring network interface with a composite payload is a key- value pair (a property) of the enduring interface that is defined up-front at creation time and attaches a key (property name) to a particular element in the payload.
  • Running example continuously).
  • an enduring interface whose payload is a document, representing an employment contract. Access hooks can be defined for important values in the contract, such as employee name and address; salary; start date; etc. The value of the hooks may be entered manually; or alternatively, the word processor that was used to create a document may indicate keys of hooks as part of the document.
  • contract details may be accessed through a hook such as: GET https://facts.com/ae3c/payload_hook/employee_first_name An embodiment.
  • XML-type tags may be used to define access hooks.
  • SaaS applications enterprise desktop applications, or mobile apps
  • idiosyncratic storage whether locally on an idiosyncratic database, as in the case of enterprise desktop applications, or idiosyncratic storage servers, as in the case of smartphone apps, and each only having user-facing user interface and no extensive software API to its data.
  • Enduring network interfaces enable a different paradigm, where all application data storage is consolidated, uniform, and software-accessible on unique digital reality, and where all applications make their data transactions with enduring network interfaces. This separates data layer from application layer and enables data owners to own their data instead of nominally owning their data where in effect its data fragment is owned by the application provider.
  • enduring network interface Part of the core functionality of enduring network interface is that they cannot be deleted.
  • An enduring interface may include, in its mutable meta- information, tags such as “marked for end of life.” However, an interface cannot be deleted and will continue to respond to API requests indefinitely.
  • Permanent address aliases and namespaces The universal identifier and associated network address of an enduring network interface are permanent. They are not human- readable, however.
  • an interface authority allows stakeholders to register permanent universally allocated namespaces, as well as aliases for enduring interfaces, associated with a certain existing enduring interface, under their stakeholder- assigned namespace. Running example (continued).
  • the interface authority enables registration of stakeholder namespace; for example, a stakeholder may claim the namespace “hanover_institute” if it is available.
  • An enduring interface owned by this stakeholder For example, interface with identifier “j2p9” may then be assigned a human-readable alias under this namespace “hanover_institute/2020_annual_report.” Any API request to, “facts.com/hanover_institute/2020_annual_report” is redirected to “facts.com/j2p9.” If this enduring interface is migrated to a different authority, its alias migrates with it because the stakeholder namespace is universal. Namespaces and aliases are a service provided by an interface authority. Tags.
  • the metadata of an enduring interface may include tags – mutable free text fields that facilitate search, bookkeeping, and organization of a collection of enduring interfaces.
  • the interface authority or an external index service may then implement methods for searching enduring interfaces with specific tags. Versions, chains, and branches.
  • Enduring interfaces are permanent and immutable; hence their payload cannot be updated if newer versions of the same logical object become available.
  • the semantic relation between enduring interfaces which indicates that one is a newer version of the other, can be included in the payload.
  • the payload includes the identifier of an existing enduring interface, which is the older version updated by the new enduring interface.
  • an implementation may define an alias that moves to the newest version in a chain of enduring interfaces.
  • the alias “2024_reports/CURRENT” is allocated to object with id “h7qq.”
  • a newer version becomes available, namely whenever an enduring interface is created indicating as “previous_version” the one currently pointed at by the alias “CURRENT,” the alias moves to point to the newer version.
  • Running example (continued): In this case, the following will be a valid API call: GET https://facts.com/2024_reports/CURRENT/get_primary_format Syntactic sugar can also enable direct access to the previous version of an enduring interface, instead of first getting its id and then invoking a second API call, e.g.: GET https://facts.com/h7xk/access_previous_object/get_primary_format Which in this example invokes the API method “get_primary_format” of the enduring interface indicated as previous version of “h7xk,” instead of “h7xk” itself.
  • each enduring interface includes a list of payloads – not just a single payload; and its API enables a version update by the owner depositing a new version of the payload.
  • All previous versions of the payload are stored and available over the API; there may be rules enforced about the changes allowed from one version of payload to an updated version, for example if the enduring interface instantiates a class (see “classes”) the updated payload can be required to conform to the same class.
  • an API call can specify which payload version it should be invoked on, and citations of enduring interface make it possible to explicitly mention the payload version. Tracking use of payload and payload access.
  • One of the key advantages for using enduring network interfaces for information exchange, instead of files, is that the file – an inherently local object, whose access cannot be tracked – is replaced with a network service.
  • the responsible interface authority servers track every time a payload of an enduring interface is accessed and know the identity of the accessing stakeholder. This implies that ownership over an enduring network interface is like ownership over physical objects: access can be tracked, monetized, etc. Royalties can be collected for the use of payloads just like they are collected in a music streaming service.
  • the access history to an enduring network interface can be stored by the responsible authority for various purposes; the event of payload access may even be mirrored and recorded as a new enduring interface. Failure of responsible authority or suspended authority service.
  • the system of enduring network interfaces is designed to support large-scale digital transformation, including creation of very large quantities of enduring network interfaces. This information cannot possibly be stored on a shared database, hence the notion of an authority responsible for the storage and continued availability of an enduring interface.
  • the header of an enduring interface including owner identity, time of creation, and digital digest of payload, is stored on a shared database or propagates through a system of trusted witnesses. This way even when the payload itself is lost, integrity of collections of enduring interfaces citing the lost objects is maintained.
  • the responsible authority When the responsible authority charges money for the storage service, in the event of non-payment that leads to suspended service, the authority can keep the headers of enduring interfaces and still serve them as stubs, namely interfaces without payload.
  • Migration Changing the interface authorities responsible for an existing enduring network interface. The owner of an enduring interface can choose to move the interface between responsible authorities. This can happen for multiple possible reasons.
  • there is a market for the service of responsible authority and stakeholders can choose to migrate their entire collection of digital assets, stored as enduring interfaces, to a different authority.
  • Another example is corporate M&A, where the merging company chooses to migrate its entire collection of digital assets to the authority handling the digital assets of the acquiring entity.
  • Running example (continued): Suppose that enduring interface with universal identifier “wq87” moved from the responsible authority with domain “old_authority.com” to new responsible authority with domain “new_authority.com.”
  • enduring interfaces Software using information from enduring interfaces can negotiate a format – namely inspect available formats and choose the most appropriate one.
  • the payload is stored in the primary format of the enduring interface, and when a different format is requested the interface authority is responsible for converting the payload to the requested format and responding to the API request.
  • Storage authorities can make public the conversion code they use to convert between given formats.
  • enduring interfaces expose an API method to permanently convert the payload into one of the available formats; this results in verifiable execution of the conversion code executed on the responsible authority servers which in turn results in a new enduring interface, whose primary format is the requested new format.
  • Running example (continued): Suppose that enduring interface “gq8k” is an image, with JPEG as primary format.
  • the responsible authority may choose to cache secondary formats for an existing enduring interface – the converted payload may be stored on the metadata of the object, without changing its payload in primary format.
  • Update of primary format Over the life of an enduring interface is it possible that a digital format used as a primary storage format will become outdated or even deprecated by popular software systems. This is a significant event for enduring network interfaces that use the format declared as outdated as their primary storage format: the payload is stored in the primary formats and converted to other formats only upon API requests to retrieve the payload in other formats.
  • the payload in primary format is used to calculate the digital digest of an enduring interface, and the digest in turn is used to commit the enduring interface.
  • a verification request intended to verify integrity and consistency of the enduring interface compares the digest of the payload in primary format, as calculated by a verifier that retrieved the payload for verification, with the digital digest committed for the enduring interface upon creation.
  • the only way to update the primary format is to create a new enduring interface referring to the previous-version enduring interface as an older version (see “versions” above).
  • a conversion code is executed using verifiable execution, with the old object as input and the new object as output; the conversion code can be inspected and verified; and the new enduring interface is committed with its primary format being the new format. De-referencing a citation from a key-value pair in an enduring network interface.
  • the payload of any enduring interface includes a struct / dictionary of key-value pairs. Some of these values may contain citation of other enduring interfaces – either using their universal identifier or, in some embodiments, their network address.
  • the API of an enduring interface may offer syntactic sugar to dereference a cited enduring interface and access its fields without having to obtain the universal identifier in a first API call and invoke the API of the cited enduring interface in a second API call.
  • the API can allow dereferencing like so: GET https://facts.com/ae3c/get_field/seller_id/get_field/first_name that retrieves in a single API call the value of the first “first_name” of interface “aqw8.”
  • Enduring network interfaces expose API methods, and in some embodiments have as part of their payload a set of key-value pairs, namely, properties. This makes them like objects in the object-oriented programming paradigm.
  • a new enduring interface can then be created as an instance of this class, specifying the class by the universal identifier of the class object – namely of the enduring interface specifying the class, and the properties of the new instance (the new enduring interface).
  • An enduring interface created as a class instance may hold in its payload or as a key-value pair the universal identifier of the class it instantiated.
  • Class inheritance can be defined by the primary format is a word-processing document and specify key-value pairs for the identities of the contract parties and the universal identifiers of enduring interfaces mirroring the consent (signature) events.
  • class inheritance whereby a class is defined as a subclass or inherited class from an existing class – making it easier to define new classes based on existing ones.
  • Standard classes In this possible embodiment, it is also possible to have community- agreed standard classes for typical types of enduring interfaces – such as images, contracts, Python code execution events , and so on.
  • Class-wide API updates Recall that API versions may be updated for an existing enduring interface. Manually updating interfaces may not be practical; however if each enduring interface is an instance of a class, in a possible embodiment, the API of the class may be updated, which results in API update for all enduring interfaces instantiated from it.
  • Class constructors Recall that API versions may be updated for an existing enduring interface. Manually updating interfaces may not be practical; however if each enduring interface is an instance of a class, in a possible embodiment, the API of the class may be updated, which results in API update for all enduring interfaces instantiated from it.
  • a class can define rules regarding allowable values for its key-value properties and regarding over parts of its payload; this code can be executed by the responsible authority at interface creation time to validate the new payload, rejecting the creation request if the new payload does not conform to these rules. Verification of time-of-origin of an existing enduring network interface. Each enduring interface makes available through its API its time of origin and original owner, i.e. the identity of the owner who created the enduring interface.
  • the verifier follows the steps of: • Obtain the public key from the enduring interface of the identity mentioned as original owner; • Verify that the digital signature available on the enduring interface has indeed been signed by this public key; • Obtain the payload digest as committed from a trusted record (see “commitment” above) – for example from a trusted witness server or a shared ledger; • Inspect the payload in original format and calculate its digest using the same algorithm used to calculate its digest at commit time; and • Compare the two digests and compare the time noted on the trusted record to the time available on the APi of the enduring interface.
  • enduring interfaces can be assigned semantic types. This is useful, e.g. for the purpose of automatic verification of compliance and consistency (see “SICCL” below).
  • the creator of an enduring interface can assign a semantic type at creation time.
  • Types are typically immutable, and in this case, the type can simply be a key-value field as part of the payload.
  • the type can be “drivers_license,” “property_sales_contract,” or “nondisclosure_agreement,” etc.
  • Privacy design considerations in enduring network interfaces Stub interfaces. In a normal creation of an enduring interface the payload is fully disclosed to the responsible authority and is stored in the storage of the authority. The payload of an enduring network interface may contain sensitive information.
  • a stakeholder could be interested in creating an enduring interface without disclosing the actual payload.
  • the interface creator calculates a digest of the payload, store the payload without transmitting it to the authority, and only includes the digest – not the payload – when creating the new enduing interface.
  • a stub interface exposes an API method that allows to upload the actual payload, turning it into a standard enduring interface. The payload can be verified to have the same digest as the one committed during original creation time.
  • Stub enduring interfaces expose all the API of a similar standard interface – except for payload access methods.
  • Stringent privacy Self-Authority Vs. Private unique digital reality Vs. Private payload authority.
  • an entity may be interested in creating a stream of enduring network interfaces (a standard use pattern of participants in unique digital reality) but may not want to disclose any payload to a responsible authority. This can be the case for example for a financial institution that can benefit from storing all its data on unique digital reality but is prohibited by regulation or by privacy concerns from disclosing any payload data to a third-party responsible authority. There are three possibilities open to such an entity: 1.
  • Self-Authority Establish the entity as a responsible authority.
  • Private unique digital reality The entity can opt out, for the purpose of the enduring interfaces that should be kept private, of the shared digital reality, and establish its own private digital reality, which would be shared only internally. In this case an entire system of enduing interfaces is set up, isolated from the outside world.
  • Private Payload Authority is a middle way between joining a shared unique digital reality and using a private unique digital reality.
  • the entity can join the shared unique digital reality but only create stub enduring interfaces, that delegate payload storage to a private payload authority ran by the entity on the entity’s servers or by a trusted provider.
  • each stub enduring interface which may be a third party authority, and each stub interface specifies that the payload itself is stored with a specified private payload interface;
  • the private payload interface can be a storage facility for payloads identified by the unique identifier of the stub interface they correspond to or may be a fully-functional responsible authority, where each stub interface stored by the external authority corresponds to a full enduring interface (with payload), with the same unique identifier, stored by the private payload authority.
  • Zero knowledge proofs Verification of payloads of a stub collection by simple zero knowledge proof.
  • an entity may create a collection of stubs enduring network interfaces with a responsible authority.
  • the payloads are simply not submitted; in other cases they can be stored by the entity, e.g. on a private payload authority.
  • a simple scheme allows a verifier to verify that the creating entity does indeed have the payloads. This scheme may be implemented ad hoc, or e.g. in the embodiment of private payload authority, implemented as part of the enduring interface responsible authority core implementation and be available through an API. In the scheme, a small subset of stubs is selected at random or is selected by the verifier.
  • the entity storing the payloads that are not disclosed to the authority responsible for the stubs then responds by disclosing the specific payloads for the selected subset.
  • the verifier can verify that the digital digests on the stubs indeed correspond to the disclosed payloads; because the subset was not selected by the entity, the verifier can become satisfied that all payloads are stored by the entity.
  • the authority responsible for the stubs can select one stub at random every minute or some determined time interval and challenge the private payload authority, presenting the universal identifier of the selected stub; the private payload identifier then responds by disclosing the payload.
  • Embedded UDR modules IoT.
  • enduring interfaces representing observed facts are created automatically by measurement devices.
  • a measurement device such as a sensor, an IoT unit, a smartphone, a card reader, etc., contains an embedded UDR module configured to communicate, over a network connection, with a responsible enduring interface authority.
  • Interface creation may happen through API calls to the authority, issued by the embedded UDR module, or by the authority itself, based on preexisting registration configuration, or by a remote unit receiving raw data from the embedded module and issuing API requests to the responsible authority.
  • the embedded module sends a stream of measurements or request that create a stream of enduring interfaces that mirror the physical events measured by the device or sensor.
  • the module periodically transmits a digitally signed short message, consisting of the registered device identifier, which may itself be the universal identifier of an enduring identity interface for the device, measured time, and measured GPS coordinates to the authority.
  • the authority creates an enduring interface for each message received.
  • the stream of geo-locations enables an eventual verifier to verify location of the device by inspecting the consistency of the location trail (see “certification of geo-locations” below for more advanced techniques).
  • Shared authority and decentralized design In the embodiments discussed so far, a single storage authority is responsible for each enduring interface.
  • an enduring interface is committed upon creation, there is never any dispute regarding the contents and payload of an enduring interface — the only question is whether it is available for access and who is responsible for making sure it is permanently accessible.
  • This responsibility can be shared: in another embodiment, multiple storage authorities can share responsibility for serving an enduring interface.
  • the authorities keep a collection of enduring interfaces synchronized between them, using the commitments to verify that each is storing the authentic enduring interface, and using the same universal identifier to an interface even as it is offered by potentially several responsible authorities through several network addresses.
  • the interface is still universally unique; however it may be accessed through different endpoints (the authorities) over different network addresses. In this case the responsibility for ensuring permanent accessibility does not lie with any one authority.
  • a responsible authority serving enduring interfaces stores in its storage payloads of enduring interfaces containing all sorts of sensitive information.
  • payloads and metadata are stored in encrypted form and security protocols are in place make payload accessible to authorized access only.
  • the authority may not hold the encryption key to the payload of certain enduring interfaces – which makes them effectively stubs (see above). Discussion
  • Enduring network interfaces enable a paradigm shift in digital information technology. They make it possible to define every value once, horizontally across stakeholders, and make all other uses of the value by reference to single point of value definition.
  • An enduring interface representing their current legal name can cite this unique interface representing their identity; systems using identity can use the universal identifier of the identity enduring interface for the unique identity, and the universal interface representing mutable details such as the legal name of the person (or their social security number, as they were at the time of a transaction; version chain (see above) can be used to update a person’s name. In this way there is a single point of failure for identity and a single point of failure for a legal name.
  • internal version chains can be used to include the legal name inside the enduring interface representing identity, with internal version updates to update legal name changes.
  • Another analogy is the banking financial system where an account can move between banks.
  • Server interactions Enduring network interfaces are an implementation of the concept of unique digital objects based on server interactions. Server interactions are used at essentially all stages of the lifecycle and use of an enduring interface: a) creation; b) commitment; c) validation and verification ; and d) content access. While other implementations of unique digital objects may be based on some technology that has not yet been developed, it may be argued that under existing information technology any large-scale implementation of unique digital objects must rely on server interactions. Indeed, a digital object can only be made permanent and immutable through commitment to a trusted record. the blockchain represents one possible solution – namely that all records of all digital objects ever created by any stakeholder are stored on a shared ledger.
  • Such an image can be embedded in a web page, a digital document, a physical document, a presentation, etc. – using a direct embedding command that does not involve copying the image file.
  • the embedded image as shown on a user interface is explicitly linked to the enduring interface for the purpose of ownership assertion, access control, per-access monetization, etc.
  • the enduring interface can be rented or sold.
  • the image stored and made accessible through an enduring is fundamentally not a file – it cannot be copied. It also transcends file formats, as image formats can be automatically negotiated through the API of the enduring interface. • Data object.
  • An enduring interface whose payload is a data object - for example, a data object in HDF5 format - makes the data object payload unique, universally accessible, and universally reusable. Bindings into data analysis platforms such as Python or R, spreadsheets, etc. allows reuse with explicit citation – maintaining an explicit audit or provenance trail.
  • the enduring interface containing a data object can be explicitly linked to the execution event that created this data object - for example, by citing an enduring interface representing a verifiable execution event.
  • a data object stored and made accessible through an enduring is fundamentally not a file – it cannot be copied. It also transcends file formats, as data formats can be automatically negotiated through the API of the enduring interface. • Form.
  • An enduring interface whose payload is a filled form has a payload that essentially consists of key-value pairs.
  • the values may reference other enduring interfaces, or key-value fields contained in the payload of an enduring interface.
  • the form enduring interface is separate from its visual rendering or representation and may contain SICCL instructions that verify the consistency and compliance of the form’s contents, or of the form in the context of a form portfolio.
  • Applications developed on top of unique digital reality. Third parties may develop applications that use digital objects in UDR. Here we examine a few possible applications that can be developed. To give concrete examples we consider UDR implemented by enduring network interfaces: • Self-published content platforms. • Copyright assertion. • Search. • Robotic data brokers.
  • Citation counters for data, code, publications, news, social media, images, content Enduring network interface as an OS primitive.
  • Operating systems have primitive interfaces to files over a mounted drive.
  • an operating system can be extended to include primitive (native) interfaces to enduring network interfaces, which allow creation, verification, and access to enduring network interfaces. How is this different to storing files in the cloud?
  • An enduring network interface is fundamentally different to a file stored on a cloud storage service.
  • An enduring interface is unique, committed, explicitly owned, immutable and permanently accessible over a universal address. A file stored on a cloud service possesses none of these properties. Implications of enduring network interfaces Usage of digital information is based on server interactions, not local file access.
  • Example Embodiments 1 A method for creating an enduring network interface, wherein information is submitted to a network server acting as an enduring interface authority, and wherein said authority allocates a new permanent universal address to the created enduring network interface, and wherein the created enduring network interface is accessible through the enduring interface authority. 2.
  • enduring network interface implements a unique digital object whose existence, ownership, properties and validity are verifiable by either human users or machine-executable code.
  • Certification and Verification of Unique Identity Embodiments of the invention teach a method, communication protocol, communication standard, and technical specifications for certification and verification of unique identity, and more specifically, of unique, consolidated, shared, and software accessible identity. Identities can pertain to natural persons, legal entities, organizations, physical items, as well as to characters, digital avatars, and items or objects in virtual reality or augmented reality.
  • core identifying details for example, cryptographic keys, secret passwords, or biometric information, are deposited into Unique Digital Reality (UDR) as a unique identity digital object.
  • UMR Unique Digital Reality
  • the core identifying details are presented in response to a challenge and verified against the identity digital object in UDR.
  • An event of identification, authentication or identity verification can itself be deposited as a new unique digital object in UDR, mirroring that event.
  • embodiments of the invention ensure that no two separate identity objects in UDR are created for the same entity. Identities of legal entities or organizations are linked to individual identities of officers, signature right holders, etc.; identities of characters in virtual or augmented reality may be linked to identities of natural persons; identities of items and objects in virtual or augmented realities may be linked to identities of physical objects or devices. Need: In the state-of-the-art, there is no unified notion of identity. Each person has several identities, fragmented across numerous computing systems.
  • Every digital system assigns identities to users and stakeholders, independently of other systems, and each maintains its own idiosyncratic identity system. Every website, every mobile app, every public utility company, every service provider, every government agency – all use their own home- grown identity system. Identities do not belong to a shared reality. Different stakeholders cannot share identity systems. This enables attacks such as identity theft, impersonation attacks, and phishing, which pose serious problems to individuals and organizations. The lack of a unique, consolidated, shared and software-accessible identity prevents ownership of digital assets, digital objects, and data.
  • a small hand-held network-connected device with a personal biometric scanner is used to authenticate identity of human users and can record the authentication event in UDR.
  • user interfaces (screen, smartphones, etc.) have similar capability namely are equipped with a biometric authentication device. This can practically eliminate the use of passwords, two-factor authentication, government-issued identity cards and passports, software logins, website logins, keys, access cards, membership cards, credit cards, hand signatures, company stamps, and notary wax seals – all of which are simply mechanisms for proving identity or affixing identity. Summary. An identity is a represented as a unique digital object UDR.
  • Each entity in a UDR ecosystem can have a most one associated unique digital identity object in the ecosystem.
  • the universal identifier of the identity object serves as a unique identifier for the mirrored stakeholder (person / device/ etc.).
  • the unique digital identity object contains authentication information used to authenticate the stakeholder; for example, an identity object for a device, which has a private cryptographic key hard-coded, may contain the corresponding public key; an identity object for a person may contain a secure digest of their biometric markers. Creating Identities.
  • an entity’s identity is captured as a fact in UDR that is permanent, immutable, and unique at least within a network of stakeholders.
  • an identity can include any combination of identifying biometric information such as face, fingerprint, retinal scan, or genetic information, secret information known to the person such as a private cryptographic key, or a unique item possessed by the person such as a one-time password token, fob, or application; an identification card; or an image with a randomly distributed dot pattern.
  • identity can be defined at the highest level of the organization such as an identity of a company or a department of a government, at one or more lower levels in the organization such as departments within a company or agencies within a government department, or both.
  • identity can include information unique to the device, such as device fingerprint or a unique, encrypted key stored on the device.
  • the identity of a device includes information about properties or behaviors of the device or specifies parameters defining how the device is to be used. The parameters specifying use of the device can be represented as a digital birth certificate, indicating a date the device was manufactured, registered, or added to a network. This information can be used, for example, to verify that a fact was created by a specified device.
  • the parameters can also be represented as a death certificate, specifying a lifespan for the device or an amount of time the device is to be allowed access to a particular network. For example, if a device is temporarily added to a network, e.g. a visitor to a company adds his mobile device to the company network for the duration of his visit, the digital death certificate can specify that the device is to be disallowed access after a certain period. If the device attempts to authenticate itself to the network after the expiration of the specified time-period, the identity validation fails.
  • identity fact generator that creates and commits identity facts generates a hash of the identifying information.
  • the identity fact generator can then deposit the hash, instead of the identifying information itself, into the identity fact data structure.
  • the identifying information may therefore never be directly stored.
  • Identity may be used in a variety of manners in a UDR ecosystem, from identifying a person, organization, or device for access control purposes, to verifying other facts, to deducing new facts.
  • an entity uses an identity to accomplish a task. These tasks can include, for example, gaining access to a physical space or an electronic resource, signing a contract, or voting.
  • an entity performing the task e.g. granting access
  • a system that controls access to a physical space may verify a person’s identity by receiving, from the person, the unique address of the person’s identity fact and biometric measurements.
  • the biometric measurements can optionally be received in an air-gapped sandbox device to preserve the person’s privacy.
  • the system generates a hash of the biometric measurements, accesses the identity fact using the address supplied by the person, and compares the hash against the hash stored in the fact. If the hashes match, the system grants access to the person.
  • an entity uses an identity to create a fact or attest to its authenticity. For example, if a device is recording an event, such as a sensor measurement at a certain time, the device may create the fact for the event by signing the fact with the device’s identity and thereby attesting that the device observed the event.
  • the identity should be conclusively and uniquely identifiable such that future fact verifiers can verify the identity specified in the fact commitment.
  • One example implementation used to conclusively identify an entity is by digital signature: a public key is committed to UDR, along with any other identifying information, when the identity is established, and a private key is used to generate a secret to prove identity.
  • a person’s identity can be established by collecting one or more biometric markers and committing a hash representing the markers into UDR.
  • a device collects the biometric markers from the person and deposits a hash of them into UDR with the rest of the fact being committed.
  • the fact is verified, the hashed features collected when identity was established are compared against the hashed features deposited with the fact.
  • UDR ecosystem The ability of the UDR ecosystem to establish a person’s identity and prove conclusively that a person who appeared in two or more different instances, possibly at different times and locations and verified by different systems, is the same person is important in numerous interactions and transactions that may occur in society – from healthcare and finance to commerce and legal proceedings.
  • Some embodiments herein teach a method, based on UDR, for submitting biometric information to UDR in a manner that protects and preserves privacy.
  • Information can be stored in UDR in an encrypted form, where the person whose information is provided has exclusive access privileges to control by whom or what and when the information can be accessed. Based on the stored identity fact, a person can also prove to a third party that they are the same person whose information has been initially submitted.
  • a method for establishing the identity of an individual comprising: providing individual-specific information that is unique to the individual; issuing a cryptographic keypair for the individual, consisting of a public key and private key; hashing the individual-specific information with a hash function, wherein the hashed information is digitally signed and encrypted with the private key for the individual creating a unique digital object containing the hashed individual-specific information and the public key issued to the individual 2.
  • the method of 1, wherein the individual-specific information is a passphrase or a password 3.
  • the method of 1, wherein the individual-specific information consists of biometric measurements 4.
  • the method of 1, wherein the individual is a natural person. 5.
  • the biometric information includes any of facial information, ocular information, fingerprint information, or genetic information.
  • authenticating the identity of the individual is achieved by obtaining response to a challenge regarding the individual-specific information and comparing the hash of the response with the hashed information storaed in the unique digital object 7.
  • a second unique digital object is created, which includes (i) the unique identifier of the identity unique digital object, and (ii) a digital signature, computed using the private key, which pertains to the interaction.
  • Detailed Description - Verifiable Code Execution Embodiments of the invention teach a method, communication protocol, communication standard, and technical specifications for certification of individual events of code execution, namely, events where a computing device or a collection of computing device executes a specified computer program against specific inputs, resulting in specific outputs.
  • an inter-connected collection of unique digital objects is created in UDR; each object mirrors one aspect of the course of the code execution or computation, such as a variable, a function call, a result, an instruction to an external interface, etc., and the entire collection mirrors the entire event of code execution. Uses for recorded executions.
  • This inter-connected object collection can be later used for different purposes.
  • it can be used to certify and prove that the code execution did indeed take place, using certain inputs and yielding certain outputs; it can be used for manual inspection of inputs and outputs for an indefinite amount of time after the execution has completed; in some cases allow re-execution of the code – repeating the execution event; it can be used for counter-factual execution, running the same code on other inputs or running a different code on the same inputs; it can be used for citation and reverse-citation, tracking the use of certain information objects as they form the basis for vertical flows that eventually appear, e.g.
  • Figure 17 shows the different unique digital objects created during a Verifiable Execution of a procedural program: schematic representation of program code shows main function 1701 which takes argument variable 1702, makes a subroutine call 1705 with argument variable 1719 and returns output in a return statement 1708.
  • Execution unique digital object 1704 records the entire code execution event.
  • Input unique digital object records 1703 records the argument 1702 passed to the main function upon execution.
  • Unique digital object 1706 records the subroutine call 1705, with object 1707 recording the arguments 1719 passed to the subroutine call.
  • subroutine 1710 takes input argument 1712.
  • Object 1706 records its execution and object 1707 records the input argument it received when invoked; the statement "public key_results” (or “publish key_results”) causes the local variable “key results” to be published as a unique digital object 1717, since that local variable has special importance as an output of the overall computation.
  • the subroutine returns with “return” statement 1715, creating a unique digital object 1716 recording the value of the returned argument.
  • Unique digital object 1709 records the output variable 1708 returned to the operating system when the main function exists. All unique digital objects are recorded in perpetuity in unique digital reality 1718. Data import and export.
  • Data is imported from an existing variable object, already stored on a VCR repository.
  • data is imported from importable unique digital objects; the API of a unique digital object may implement an API method to import it into various software environments.
  • the VCR clients implements this by calling an API method of the specified enduring interface by invoking the HTTP command: GET https://facts.com/aqws/import/matlab Which requests the object in .mat (HDF5) format, downloads it, and imports it into the variable ‘myvar’ matlab workspace.
  • the input variables and output variable are created as VCR objects, as well as the function invocation itself.
  • each function invocation creates a new VCR object; for example, making two recorded function calls: record myfunc(in1,in2) record myfunc(in1,in2) would result in two different VCR objects, one for each invocation.
  • Parallel computing executions When a recorded computation is executed in parallel, each thread in the parallel execution can be recorded, or a few of the threads can be recorded. Loops.
  • VCR repository When a recorded function call occurs in a loop, the VCR repository may be overwhelmed with new recorded function objects.
  • the VCR client may choose to only record some of the iterations.
  • Library / standard package function calls Sometimes, there is no point in recording function calls. This can happen when the function call is a standard library function, or a function with precompiled machine code, where no source code is locally available.
  • the language may include a keyword for recorded function call, so that the programmer may indicate which function calls should be recorded.
  • Running example using enduring network interfaces Before the execution, the programmer authenticates with an interface authority. All objects are created as enduring network interfaces with this authority. There are no files used during a recorded execution.
  • VCR Client handles all VCR calls during the execution – including recording repository login, recorded function invocation, variable import from any repository, and variable export to the recording repository.
  • the client can work offline – caching new VCR objects created until they can be uploaded to the recording repository over a network connection; and caching imported variables.
  • Example Embodiments 1 A method for verifying execution of code in a programming environment, comprising: creating a plurality of UDR objects, each uniquely corresponding to an event of machine code execution for a computer program; and subsequently verifying that the computer program was run using one or more specified inputs and produced one or more specified outputs. 2.
  • the method of embodiment 1, wherein the creating the plurality of UDR objects includes, during execution of the computer code, depositing source code corresponding to each event or function call in UDR, including all relevant variables for each event or function call. 3.
  • the method of embodiment 2, wherein the computer code is executed in a procedural programming language.
  • the relevant variables comprise any of input variables, output variables, and intermediate variables.
  • the method of embodiment 5, wherein the details corresponding to the execution environment comprise any of interpreter version, installed packages.
  • the subsequent verification comprises inspecting the UDR objects with software. 8.
  • Verifiable computational results in the scientific literature In an application of verifiable execution, the computational process that is used to analyze data and produce publishable scientific results is recorded using verifiable execution.
  • Each publishable result created during computation (number, table, figure, image, etc.) is a unique digital object on UDR.
  • Presentation of a result on a user interface such as an article in PDF format, an article printed on physical paper, a website, a lecture slide deck, a poster, etc., is presented with the universal identifier of the corresponding unique digital object.
  • This approach offers multiple benefits: • A scientific result cannot be presented without also sharing the computation that created it; and through the computation, all underlying data sources.
  • Figure 18 is a concept illustration that shows how the method of verifiable computational results creates a permanent digital explicit unambiguous connection between computer program code used to generate important results, the execution event in which the results were created, and the publication where the results are presented, thus consolidating the vertical information flow from data through processing to presentation of results: report 1806 (such as a printed scientific paper, a web page, a blog post, a post on social media, or a PDF with scientific paper) presents a result 1804 (such as a plot, a chart, a table or an important number).
  • the result 1804 is presented with a visually recognizable unique identifier 1805 that is human and/or machine readable.
  • This identifier is the unique identifier of a unique digital object created at the “publish result” instruction 1811 in a recorded computation.
  • the object 1811 is related to the verifiable execution object 1801 that represents the entire computation, which includes the code 1802 that performed the calculation that lead to the creation of result 1811.
  • a user interface of any kind 1807 shows a result with unique identifier 1808, it may be used to inspect the computation 1810 that lead to the result including its program code, input and output variables as observed in execution time, and any intermediate variables and subroutine calls.
  • User interface 1809 can be used by a user to inspect the computation or analyzed automatically in software as all unique digital objects involved are machine- readable.
  • Figure 19 shows the explicit permanent digital connection made using the method of verifiable computational results between published results, underlying data, and underlying code: publication 1901 contains a published result 1903 shown with unique identifier 1902 which may be human and/or machine readable.
  • the identifier 1902 is the unique identifier of a unique digital object describing the result as it was created during the recorded execution. That unique digital object is connected to program code 1905 used in the recorded execution, represented by an “execution” unique digital object with unique identifier 1905, and to data 1906 used in the recorded execution represented by a unique digital object with identifier 1907.
  • Figure 20 is an illustration of computational science workflow under current state of the art, where data is loaded from a local file and result is exported to a local file.
  • FIG. 21 shows a schematic representation of the stages of vertical information flow in the field of scientific research and publication in the state of the art.
  • Figure 22 shows a schematic representation of the stages of vertical information flow in the field of scientific research and publication under the discipline of file-based reproducibility, in which the data files and code files are preserved for published results.
  • Figure 23 is an illustration of computational science workflow using verifiable computational results: the “repository” command specifies a universal identifier namespace or the equivalent of an enduring interface authority where unique digital object can be accessed. Data is not loaded from a local file but by specifying the unique digital identifier of the data unique digital object; result is not exported to a local file but to a unique digital object (using a keyword such as “verifiable”, “public” or “publish” as above).
  • the verifiable execution does not create local files; rather it creates unique digital objects and returns a unique identifier to result unique digital objects and the execution unique digital object.
  • the result is embedded in the text not by loading a local file but by specifying the unique identifier of the result object; the document graphics is rendered such that the result identifier is shown visually. This consolidates the vertical information flow and maintains an explicit permanent connection between visualization of published results, underlying recorded execution, underlying code and data used in the execution.
  • Figure 24 shows a schematic representation of the stages of vertical information flow in the field of scientific research and publication under the verifiable computational results method: data digital objects are represented as unique digital objects; recorded execution events are represented as unique digital objects that maintain explicit permanent digital connection (by citing unique identifiers of unique digital objects) to the data used in the computation and to results produced in the computation.
  • Results visualized in publication present machine and/or human readable unique identifiers to result unique digital objects, which are in turn connected to the recorded execution objects representing the executions that created them.
  • SICCL Standard Information Consistency and Compliance Language
  • An external auditor is required by law to verify the compliance and consistency of corporate financial records underlying its annual financial statement; this includes a large set of documents consisting of invoices, receipts, contracts, salary slips, bank statements, credit card statements, tax forms, etc.
  • An entity acquiring a corporation is interested in verifying that the corporation’s books and records are in order.
  • the bank is required to verify compliance and consistency according to some requirements and interested to verify according to possibly additional requirements.
  • a tax return form is submitted to the tax authority, the latter should verify consistency and compliance of the set of documents which consists of the tax return form and any attached documents such as salary slips, previous year’s tax return forms, invoices, receipts, etc.
  • a corporate human resources department is interested in verifying compliance with government employment regulations. This means, in part, that every employee must sign certain forms, and corporate HR management must sign certain forms with regards to the employee.
  • the buyer is interested in performing legal due diligence on the acquired / merged entity. This means, in part, verifying a long list of contracts, such as shareholder agreements and employment contracts; verifying consistency of financial statements; verifying consistency of equity cap tables with signed equity allocation contracts; etc.
  • contracts such as shareholder agreements and employment contracts
  • verifying consistency of financial statements verifying consistency of equity cap tables with signed equity allocation contracts
  • There is a de facto industry dedicated to information consistency and compliance This industry is not recognized as such, as it is dispersed throughout numerous sectors such as healthcare, medical billing, accounting, insurance, legal services, government corporate compliance, etc. The service provided by this de facto industry revolves around verification that requirements are satisfied in collections or documents.
  • Consistency and compliance requirements revolve around key-value pairs in the set of information objects in question, and around syntactic types of these objects.
  • a requirement may concern key-value pairs in a single object, or key-value several pairs across several information objects, e.g. several forms. For example, a consistency requirement will require that value of a pair in one object is equal to value of a pair in another object.
  • ICC Information Consistency and Compliance
  • Content values of the information objects in the set for example: the field “per- diem reimbursement” in this form cannot be higher than 150 Euro.
  • Syntactic type of the information objects in the set for example: this document must be an employment agreement.
  • SICCL can be implemented using existing computer languages, such as Python, while in others it can be a new machine-readable language. It is possible to create such a language, where machine-readable instructions resemble a human-readable language, such as English.
  • a SICCL script is executed against a given collection of information objects, it results in either (i) confirmation that all requirements are met in the given collection of information objects, or (ii) a list of requirements that are not met (with details).
  • the collection of information objects is a collection of unique digital objects on UDR; however the invention transcends any system of information objects. Preferred embodiment with unique information objects. Automatic verification of consistency and compliance is possible with unique information objects.
  • Figure 25 is a schematic example of typed citation constrains that may be defined in SICCL: Information object 2501 has a unique identifier 2502 and a defined semantic and/or syntactic type 2503. In this example, a SICCL specification mandates that it must contain citations to two different object types. Information object 2504 satisfies the first requirement, while information object 2505 satisfies the second requirement. Information object 2504 in turn must also refer to objects of specific types, and so on. An embodiment with enduring network interfaces.
  • the values can consist of string, number (or other relevant data types), pointer (universal identifier to other enduring interfaces), pointer + field (referencing a field in another object), arrays of values or key-value lists. In the two latter cases, the allows value types are recursively defined.
  • An embodiment (running example): Object-oriented Standard Information Consistency and Compliance Language (SICCL) resembling Java.
  • SICCL Object-oriented Standard Information Consistency and Compliance Language
  • an object-oriented language is used to define an enduring interface with key-value fields; create an enduring interface with key-value fields; and define consistency and compliance requirements.
  • Other embodiments are described below.
  • syntax resembling that of the Java programming language however our description is general and does not depend on any implementation or choice of syntax.
  • class members of a non-native type are references (pointers) which fits well the notion that a unique digital object can refer to other unique digital objects.
  • pre-defined (native) syntactic types there are pre-defined (native) syntactic types.
  • User-defined classes can be defined to create new syntactic types.
  • a user-defined class inherits from either a native or a user-defined class (syntactic type).
  • a class defines class members, i.e. key-value fields that each instantiated object has.
  • Values are typed; they can be numbers of strings, or from a syntactic type, in which case the value is a reference, or pointer, to another object; or structs/lists of key-value pairs.
  • SICCL SICCL running example
  • An enduring interface can implement a user-defined class in our SICCL language. All class members are contained in the payload of the enduring interface; however the payload can contain other pieces of information beyond the class members.
  • Rent contract A rent agreement specifies the identity of a property owner, the identity of the renter, the property being rented, the monthly rent, the duration of contract, the maximum delay in rent, the penalty incurred for late rent, and so on.
  • our SICCL Java-like language includes the following pre-defined syntactic types: • ID (unique identity of a person) • PROPERTY (unique identity of a real estate property) • CURRENCY (US Dollar amount, • ABSTRACT_CONTRACT (an abstract type defining a contract) As well as the primitive types: • INTEGER (non-negative whole number) • DATE (a calendar date)
  • any value that takes a user-defined class value is known as a reference and contains the memory address of an object that instantiated that class.
  • any value that takes a user-defined class value contains the universal identifier of an enduring interface instantiating the specified class.
  • Java objects live on the heap of a specific execution process, (in the memory of a specific machine), SICCL objects in this implementation live as permanent objects on UDR as enduring interfaces. This enables horizontal consolidation, as many different stakeholders at arm’s length can each write code that interacts with these objects.
  • the types ID and PROPERTY are syntactic types, hence the value must be a universal identifier of enduring interfaces of the correct type.
  • SICCL constructs allow declarations such as the following, making sure that the values fields obey the stated constraints: ASSERT end_date > start.date If a constraint fails to be satisfied, the fact language script will either fail to complete successfully or will complete successfully and add the unsatisfied constrain to a list of violations returned (as in the above example). Assume, for example, that a law prohibits late rent fees per day to be more than ten times the going rent per day.
  • any SICCL user_defined object implements a method ‘verify_requirements()’ that returns true or false, or, in more advanced implementations, returns a list of errors in which the constrains are not satisfied: verify_requirements () ⁇ ... ⁇
  • violation_list verify_requirements() ⁇ ASSERT end_date > start.date
  • ASSERT penalty_for_each_day_late_after_max_delay > 0
  • penalty_for_each_day_late_after_max_delay 10*(self.mothly_rent/30)
  • ICC requirements are applied to mutable objects, or to a unique digital object referred to by a latest-version pointer (see description of enduring interfaces above). This may be the case, for example, if an ICC requirement concerns some stock price; each tick may be published as an enduring interface with version control, and a name can be assigned to the latest version, or in this case, the enduring interface that contains the most updated tick.
  • the ICC satisfaction can change over time: a change in the state of an object from valid to invalid (in terms of SICCL constrains) can cause a dependent object to become invalid. It is often of interest to know the current validity status of a fact. When executing a valid script, we get the up- to-date status.
  • any change in validity of facts upon which we depend will be reflected in an update of the status of the dependent fact.
  • the rent fact object is no longer valid if the property title stops being valid or if the property changes ownership.
  • the rent agreement object can have a status that changes in real time to reflect on-time payment status.
  • the rent agreement object will have the array of payments made, where each entry in the array contains the universal identifier of the payment object (again, in Java style): PAYMENT[] payments; When a payment is made, the universal identifier of the last payment is appended to the end of the list.
  • This script may return different results when executed in different times, so that real-time verification status is important; it can be visualized on a user interface (see ‘presentation of information’ below).
  • a fact’s status implies the actions that were taken. If rent was not paid, the agreement can specify that renter’s key card can now not open the door to the property.
  • the contract class defines the rent_payments_too_late method that checks that all payments have been made, and that the last payment is not too late. Then an action can be defined in the ‘valid’ method: If self.rent_payments_too_late() door.renter_key.invalidate() This is an action that depends on the fact status.
  • the script specification could be: real_estate_transaction_requirements(Document1,Document2) ⁇ Document1 (hereafter “sale contract”) must be of type “contract” Document2 (hereafter “Property title”) must be of type “title” Contents of “seller” field in “rent contract” must equal contents of “owner” field in “property title” ⁇
  • script execution could be: >> binder (“facts.com/swq9”,“facts.com/lkw3”) >> verify real_estate_transaction_requirements on binder Storing SICCL class definitions in unique digital objects. Class definitions themselves can be objects in UDR (the code is the payload) so that UDR is the codebase.
  • a SICCL interpreter gets the identifier of a class and instantiates it.
  • SICCL wrappers An enduring interface whose payload includes a composite object such as a document, a spreadsheet, or a presentation, can expose key-value fields granting software access to specific values in the object.
  • word processors allow the user to specify a key corresponding to a value that appears as part of the document.
  • SICCL scripts can then explicitly refer to key-value fields embedded in the document or composite object.
  • Type hierarchy can be included in object specification: e.g. requirement “contract” is satisfied by “rent_contract.”
  • the class (syntactic type) ‘RENT_CONTRACT’ can be sub-typed to represent a specific type of rent contract, e.g.: class OFFICE_RENT_CONTRACT(RENT_CONTRACT) ⁇ ⁇ Using SICCL with Verifiable Execution.
  • a SICCL script or program may be used to define validity and/or compliance of a collection of information objects, such as a collection of machine-accessible documents (see for example “Next Generation Documents” below).
  • SICCL scripts or programs are machine-executable; in an embodiment, SICCL interpreter, compiler or virtual machine allows execution of SICCL scripts against a specified collection of information objects, such as a specified collection of unique digital objects in UDR.
  • the SICCL execution will then proceed to check the various conditions regarding types, typed citations, key-value fields, information consistency, value constrains, etc, defined in the SICCL script or program.
  • the output of the SICCL execution is either an “all clear” output, meaning that all constrains and conditions are met, or otherwise a list of specified violations of constrains and conditions in the information object collection.
  • Figure 26 provides a schematic illustration of the SICCL script execution on a collection of six information objects, for the purpose of automatic verification of certain ICC conditions by the collection: the collection consists of information objects 2601-2606.
  • SICCL conditions are checked using a depth-first search (DFS) algorithm, such that SICCL conditions pertaining to information objects 2601-2603 are checked first, followed by conditions pertaining to information objects 2604, 2605 and 2606.
  • DFS depth-first search
  • Verifiable Execution V/X be used in conjunction with SICCL to create unique digital objects that record the execution of a SICCL script, thus enabling verification that a given set of unique information objects satisfy a given set of ICC requirements.
  • V/X Verifiable Execution
  • SICCL allows definition of ICC requirements through a machine-readable language.
  • GUI graphical user interface
  • ICC requirement verification with SICCL vs. prior art a comparison Government audits, corporate due diligence, corporate external audit. In current state of the art, audits, and verification of compliance with regulation is mostly verified manually. Using SICCL, it can be verified automatically.
  • Real-estate transactions Real estate transactions essentially consist of a collection of documents that satisfy a long list of ICC requirements: for example, the identity of the seller, the identity of the owner, the identity of the buyer, the identity of the property, the sale price, taxes paid, regulatory requirements met, etc. If a mortgage or bank financing is involved, the list is even longer. In a digitally transformed world, every real estate parcel is mirrored by a unique digital object on UDR.
  • the primary party is the fact presenter, who is interested in presenting the entire cycle, including all facts it uses, for verification by a fact receiver. Verifying the entire collection or cycle requires more than verifying each individual fact or interaction: there are consistency rules that must be fulfilled. When all of them are fulfilled, we can say that the cycle is complete and has passed verification.
  • the primary party in the receipt cycle is the company purchasing an item or a service.
  • the minor parties are the supplier (seller of the item or service), the bank or credit card company clearing the payment, and, optionally, the delivery company.
  • the fact receiver/verifier is typically a government tax agency as the purchasing company submitted the expenses as part of their business costs.
  • the dominant party may be the supplier collecting the payment; the minor parties are the customer/buyer, the bank, and the delivery service, and the fact verifier is the government tax agency as the supplier reported revenue generated by the sale.
  • the interactions can be placed on a time axis. See Table 7.
  • Table 7 -Purchasing Interactions Verifying the cycle may include: • Verifying each document. • Verifying that the cycle is complete; all the required steps have been accomplished. • Verifying consistency – The price on the quote, proforma, payment, invoice, receipts, etc. all match, the item serial number on all the documents match, and so on. • Verifying constraints — The document advances in chronological order, for example the delivery date is not earlier than the purchase order date.
  • the primary party in the receipt cycle is the company purchasing an item or a service.
  • the minor parties are the supplier (seller of the item or service), the bank or credit card company clearing the payment, and, optionally, the delivery company.
  • the fact receiver/verifier is typically a government tax agency as the purchasing company submitted the expenses as part of their business costs.
  • the dominant party may be the supplier collecting the payment;
  • the minor parties are the customer/buyer, the bank, and the delivery service, and the fact verifier is the government tax agency as the supplier reported revenue generated by the sale.
  • the minor parties are the airline, the airport handling services, and the bank or credit card company used for payment.
  • the verifying party is a company, the corporate auditor, or the government if the travel is considered a business expense.
  • the interactions can be placed on a time axis. See Table 8. Table 8 – Airline Interactions Example: Medical care cycle. The period spent in a hospital, from hospitalization to patient discharge, is a complete transaction collection. It includes an atomic unit for medical purposes and an atomic unit for medical billing purposes. Documents/facts can include, for example, admittance documents, examinations by physicians, drugs administered, blood work and other tests, medical imaging, etc.
  • a primary source of headache in business accounting is business travel.
  • An employee (the primary party) interacts with airlines, banks, taxis and public transportation, restaurants, hotels – possibly in multiple currencies.
  • the employee collects receipts, tickets, stubs, boarding passes, etc., and fills in and submits an expense report.
  • the auditor at the controller’s office needs to verify that the dates match, that all the required documents have been included in the report, such as boarding passes, flight tickets, hotel receipts, that the amounts match between receipts and report, and so on. This is a demanding manual inspection task.
  • the business can instead execute a fact language script that automatically retrieves the verified facts that identify amounts spent whether for meals, hotels, transportation, or other purposes.
  • the script can automatically apply business policies to the expenses, for example to determine whether the amounts were less than a specified budget, received approval from the correct supervisor, complied with designated business goals, or met other criteria defined in the script.
  • the process of accounting for business travel expenses can therefore be accomplished nearly instantaneously, with verified data.
  • Current practice In current practice, facts are submitted, usually in the form of documents, such as receipts, for verification as a collection. The connections between the documents are implicit. There are rules about consistency, which documents are required, the time order of the documents, etc., but these rules are also implicit. Responsiveness to concerns.
  • Embodiments of the invention enable automatic verification that a transaction cycle is complete, for example, that an invoice cycle has finished or that a patient that is being discharged has completed all necessary paperwork, tests, etc. Each cycle has an idiosyncratic protocol, and the invention enables automatic verification that the protocol has been followed.
  • Other Applications • UDR lists all cycles that are not complete. • Auditors, instead of manually checking that amounts between receipts match, can check the SICCL code that defines when a transition is complete, and, if necessary, review those cycles that are reported as incomplete. This replaces manual work for company controllers or random sample checks during audits. Verification of transaction cycles - Example Embodiments 1.
  • a method for certification of interactions and transaction cycles comprising: defining a transaction cycle, including a specification of interactions or transactions that need to occur for the transaction cycle; specifying the any of the role or identity for each participant associated with the transaction cycle; and identifying information to be specified for each of the interactions or transactions; and implementing the specification as a script; wherein the transaction cycle begins upon a creation of a transaction cycle object, which notes the script that defines the transaction cycle, and a creation of a first interaction or transaction of the transaction cycle.
  • the defined transaction cycle includes an order in which the transactions must occur within the defined transaction cycle.
  • the defined transaction cycle is a Universal Digital Reality (UDR) transaction cycle. 4.
  • UDR Universal Digital Reality
  • the identifier is a uniform resource identifier (URI) of the preceding transaction cycle object.
  • the auditing the transaction cycle comprises reviewing of the script, without directly auditing the transaction cycle.
  • 9. The method of embodiment 1, further comprising: verifying the transaction cycle, by executing the script associated with the transaction cycle object. 10.
  • verifying the transaction cycle is performed more than once by executing the script associated with the transaction cycle object.
  • the transaction cycle is marked as complete upon a verified execution (V/X) of the script associated with the transaction cycle object.
  • V/X verified execution
  • an identifier of the verified successful execution of the script is noted with the associated transaction cycle object, wherein the transaction cycle object is marked as complete.
  • the script is implemented as a standard function library (SICCL) script.
  • the defined transaction cycle is associated with a purchase of any of goods or services, includes an order transaction, an invoice transaction corresponding the order transaction, and a receipt transaction corresponding a payment transaction in response to the invoice transaction.
  • Embodiments of the invention include a method and apparatus for digital bureaucracy, namely automated receipt and inspection of documents and document collections by an office or agency.
  • an office or agency responds to requests made by customers.
  • a request is submitted as a document or a document collection.
  • Each request must conform to predefined requirements regarding the information submitted, consistency of information across documents, types of documents submitted, and so on.
  • the office or agency is responsible for verifying that the request conforms to these requirements. If there are any mistakes or unfulfilled requirements, the request is returned to the customer for correction. The corrected request is then inspected again, and this back and forth is repeated until the request passes inspection.
  • bureaucracy and ‘cycles’ in the context of the invention are quite similar – both describe methods to assert that a collection of objects follows a protocol. The difference is that ‘cycles’ describe a collection of interactions and may define the order in which they should be performed and the consistency rules between the entities that participate in these interactions. In contrast, ‘bureaucracy’ describes a collection of Next Generation Documents, facts, and/or forms and the consistency rules between them. Motivation. Bureaucratic inspection of a set of information objects, such as a collection of forms and documents, is a purely algorithmic process, involving checking constraints, consistency rules, and dependency requirements for a specific document or a complete set of documents.
  • An embodiment of the invention enables automation of bureaucratic process such as request submission, request inspection, and request verification based on SICCL (see Next Generation Documents below).
  • bureaucratic procedures • Making an insurance claim • Applying for a passport • Submitting a mortgage application • Claiming social security • Claiming disability benefits • Applying to a school • Opening a bank account • Filling in a car financing application • Requesting a construction permit • Making a real estate transaction Technical Description.
  • Bureaucratic procedures can be replaced by protocols, coded in SICCL, that authorize an action if specified facts exist and are verified. Each protocol can define types of facts that must exist for the protocol to be completed, as well as relationships among the facts.
  • a computer system When a computer system executes the protocol, it searches the fact store for facts of each type that are related to one another as specified by the protocol. For each fact, the computer system can either retrieve information about a verification of the fact or cause verification to be performed as outlined elsewhere in this application. Once all specified facts are found in the fact store and are verified, the computer system can automatically output a determination approving the associated action.
  • a method for automatically performing a bureaucratic procedure over a network comprising: receiving a request at a verifier node from a requestor node over the network, wherein the request is submitted as any of a document or a collection of documents; inspecting the received request at the verifier node to determine if the request conforms to one or more predetermined requirements; and with the verifier node, coordinating correction of any errors in the request with the requestor node until the request meets the predetermined requirements.
  • the predetermined requirements correspond to information submitted with the document or collection of documents, consistency of the information across the collection of documents, types of documents.
  • the documents are any of UDR documents or UDR forms. 4.
  • a standard fact language (SICCL) script defines any of required documents, document types, semantic fields of the documents, dependencies of documents, constraints that must be satisfied, or consistency rules between fields of one or more of the arch docs. 6.
  • the inspecting the received request includes checking any of constrains, consistency rule, or dependency requirements for the collection of documents. 8.
  • the method of embodiment 1, wherein the method is performed by a system that is based on UDR and SICCL, which enables complete automation of the request submission, request inspection, and verification.
  • the verifier node corresponds to an office or agency.
  • the bureaucratic procedure is associated with an insurance .
  • the method of embodiment 1, wherein the bureaucratic procedure is associated with a passport application.
  • the bureaucratic procedure is associated with a mortgage application.
  • the method of embodiment 1, wherein the bureaucratic procedure is associated with a social security claim.
  • the method of embodiment 1, wherein the bureaucratic procedure is associated with a disability claim.
  • the method of embodiment 1, wherein the bureaucratic procedure is associated with a school application. 16.
  • the method of embodiment 1, wherein the bureaucratic procedure is associated with a bank account opening. 17. The method of embodiment 1, wherein the bureaucratic procedure is associated with a vehicle financing application. 18. The method of embodiment 1, wherein the bureaucratic procedure is associated with a construction permit. 19. The method of embodiment 1, wherein the bureaucratic procedure is associated with a real estate transaction.
  • Detailed Description - Human-readable presentation of unique digital objects One of the two goals of information exchange is human cooperation, which is achieved through consensus regarding information objects. The digital information exchange be as it may, to achieve cooperation, eventually the information presented to a human user, whose cooperation is requested, must be presented in a trustworthy way; the user interface presenting and rendering information must allow the user to inspect the trustworthiness of the information.
  • a user interface is any means of communicating with a human user; this includes physical documents.
  • the present invention teaches two guidelines for the presentation of information objects: 1. Explicit connection: Vertical digital consolidation requires that the presentation of information objects on a user interface – both those information objects observed and those deduced by processing – will be explicitly related to the information objects whose payload is presented. 2. Decoupling: The digital information object being presented is decoupled from the various manners in which it is presented on user interfaces.
  • Figure 27 describes a method for information presentation on user interfaces that is decoupled from preceding steps in the vertical information flow: information objects 2701 that act as observed data are represented in unique digital objects 2704. These data are processed a processing stage 2702, which is represented in unique digital objects 2705. The processing results in “result” information objects 2703, which are represented by unique digital objects 2706.
  • User interfaces such as a document 2707, a computer screen 2708 or smartphone application 2709 may present the result 2706 in different ways, decoupled from the result itself, and present the unique identifier of the unique digital object 2706 representing the result.
  • the state of the art facilitates vertical fragmentation in this stage as well: information presented to users, whether on physical or digital documents, on websites or on user interfaces, is inherently disconnected from the rest of the vertical flow. Results are essentially presented by copying them into a user interface; this cuts off the provenance trail and mandates that any attempt to understand the source of the information presented, to tie it into the rest of the vertical flow, or to verify / audit the presented information is necessarily a detective-like human endeavor.
  • Embodiments of the invention teach a method to present visual and textual representations of facts and collections of facts on a visual user interface such as physical paper, a screen or a smartphone in a way that preserves the connection between the representation or visualization and the facts presented, clearly showing the verification state of the presented facts, as well as their universal identifiers. Consistent with the decoupling guideline above, embodiments of the invention teach a way to detach the information stored in a fact from any of its visual representations. Merits.
  • User interfaces can visualize and otherwise enable presentation of elements of the vertical flow underlying presented result, such as the source of measurements underlying a deduced information object.
  • Automatic software amalgamation / processing at bulk of information presented on user interfaces A collection of results presented using the discipline we present can be automatically analyzed by software: every presented result comes with the unique identifier or network address of an underlying unique information object; thus software can amalgamate or otherwise process at bulk a collection of results. For example, a large collection of digital documents, each containing results connected to their underlying information objects, can be processed by software to produce a summary. The Discipline Use of the universal identifier.
  • a server interaction for example, if unique digital objects are implemented using enduring network interfaces, the user interface makes a server call to access the enduring interface and renders the response directly into the user interface.
  • Running example using the running example of RESTful enduring network interfaces. In the running example we used to demonstrate a possible embodiment of enduring network interfaces, consider adding a graphics object. Any user interface will invoke an API call to retrieve the content of the enduring interface in some graphical format and embed the graphics directly into the user interface.
  • a specialized HTML tag or JS script can be used to specify the address or universal identifier of the enduring interface.
  • the word processing document can add a plugin to allow the author to include graphics content by specifying the address or universal identifier of the enduring interface.
  • LaTeX for example, can be extended using a library to offer a command to include graphics objects this way, without creating a local file containing the image. The same for, e.g. WordPress, smartphone apps, etc.
  • Machine vs human readable citation of the imported unique digital object. Every presentation of any part of a payload of a unique digital object must explicitly cite this object. In an embodiment, it will cite in both human-readable form and machine-readable form.
  • a key factor increasing vertical digital fragmentation is the disconnect between a result presented on a user interface (including a document) and the vertical information flow producing the result; this is standard practice in the state of the art and indeed there is no simple way to do anything other than disconnect the result from its underlying vertical flow; for once, because processes (computations and ICC) cannot be cited, so how can a result cite the process that created it?
  • unique digital object citation that appears on the user interface should be human-readable to allow human inspection of the flow leading up to the information presented; and should be machine-readable to enable advanced software processing applied to human-readable results, for example reverse citation count.
  • machine readable form e.g. a hyperlink; a tag; etc.
  • a unique digital object is verifiable if it is connected to its underlying vertical information flow, and that flow is intact; that is, the object cites the process that created it and all underlying information objects.
  • Verification status can change in real-time: consider for example a result of an ICC verification process. If one of the requirements is violated, the result is not verified; this can be presented visually on any user interface showing the result or parts of it.
  • a financial report the report can clearly show the verifiability and verification status of each number on the report, e.g. using colors, footnotes, or icons.
  • Figure 29 is an illustration of Visual Trustworthiness and a collection of unique digital objects that create Visual Trustworthiness for a document, such as a financial report: financial report 2901 is an Outlet (see below) visualized on some user interface (such as a printed hardcopy or screen). It presents a visually recognizable symbol 2904 that says “verified”.
  • the unique identifier of the Outlet (for example, the unique identifier of an Outlet of a Next Generation Document – see below) links to a unique digital object 2907 representing the report.
  • Object 2907 in turn contains a link to (or cites the unique identifier of) a unique digital object 2909 representing a recorded execution of a SICCL script.
  • a third financial report 2906 is an Outlet that shows a visually recognizable symbol that underlying errors have been detected in the results reported. It cites a unique digital object 2908 representing the underlying report, which in turn cites a recorded execution unique digital object 2910 of a SICCL verification process that resulted in “unverified” status and produced an error report unique digital object 2911 detailing conditions that were not satisfied in the SICCL verification.
  • the “error” visualization in the Outlet 2906 may link to the error report 2911. In this manner, the verification status of information presented is made clear visually, resulting in Visual Trustworthiness and completing the vertical information flow all the way to the user or information consumer.
  • Figure 30 compares scientific publications with and without visually recognizable “verifiable result” symbol and machine-readable code. The addition of a machine- readable and human readable unique result identifier next to each published result is a subtle change visually, but very far-reaching in its implications, as it provides a permanent connection between presented result and underlying data, code, and execution, which is available for human inspection and for automated processing.
  • Embodiments of the invention teach a method to present visual and textual representations of facts and collections of facts on a visual user interface such as a screen, tablet mobile device, smartphone, hardcopy physical paper, Augmented Reality (AR), Virtual Reality (VR), or billboard, in a way that preserves the connection between the representation or visualization and the facts presented, clearly showing the verification state of the presented facts, as well as their universal identifiers.
  • a visual user interface such as a screen, tablet mobile device, smartphone, hardcopy physical paper, Augmented Reality (AR), Virtual Reality (VR), or billboard
  • AR Augmented Reality
  • VR Virtual Reality
  • billboard a visual user interface
  • the information presented or visualized on a user interface is detached or separated from the digital information stored in the unique digital object being presented.
  • unique digital objects on UDR are stored as machine-readable information.
  • FIG. 31 compares entangled information and visualization in the current state-of-the- art with detached information and visualization in embodiments of the invention: in a certificate or diploma 3101, for example, in the current state-of-the-art the visualization 3101 is one and the same as its textual content 3102, authentic signature 3103 and seal of authenticity 3104.
  • the visualization Jacket 3106 may be created specifically for a presentation context and a user.
  • the unique identifier presented on the visualization 3106 is that of a unique digital object 3105 in UDR (in a possible embodiment, a server for enduring network interfaces).
  • a different Jacket 3107 may combine several diplomas in a single visualization, presenting a unique identifier to the jacket and possibly the unique identifier of each of the diplomas combined.
  • Outlets In possible embodiments of the invention, a computer program is used to prepare a context-specific and possibly user-specific visualization of a unique digital object or a collection of unique digital objects.
  • the specific visualization may adapt content, highlighting specific important information elements over others; it may hide content that the specific user or users, to who the Outlet is intended, are not authorized to see.
  • an Outlet may be used to define the nature of possible or allowable user interaction, with is specific to the information object being presented on the user interface, and to the user or users to which the presentation is intended, and to particular characteristics of the specific user interface used, and to the specific time, location and/or context of the presentation itself.
  • Embodiments of the invention thus make it possible to control, limit and track the number, form, and security level of appearances of pieces of information in human-readable on user interfaces, as well as to control, limit and track interactions of individual users or user groups with specific information objects or groups of information objects.
  • An Outlet is a specific visualization of a unique digital object or a collection of digital objects. It may contain specifically rendered graphics, and present the Outlet unique identifier (instead, or in addition to, the unique identifier of the information object it presents). As any unique digital object, it may exhibit an API that allows software interactions.
  • an Outlet is created by a computer program and is represented by a unique digital object that is separate from the digital object being presented and has its own unique identifier.
  • a presentation event a presentation of a specific digital object on a specific user interface (for example a hardcopy document, a Virtual Reality world, or a smartphone application), possibly to a specific intended user, possibly for a specific intended purpose, possibly at a specific time, possibly at a specific location.
  • An Outlet intended for the specific use of certain users may require user authentication to allow access to information, or to allow user interactions (such as signing a document). The access log of an Outlet therefore records access to the specific Outlet and not to the information object being presented in general.
  • Figure 32 provides a schematic illustration of the concept of Outlets: An information object 3201 is not presented as-is on user interfaces. Instead, each user interface, and potentially even each presentation event, is based on a different specifically created Outlet.
  • a document presentation 3202, an on-screen presentation 3203, and a mobile phone application presentation 3204 may each be based on a different Outlet.
  • Outlets may be used, for example, to: • Define on which user interfaces a digital object can be accessed – both allowed types of user interfaces and identities of specific user interfaces allowed (such as an allowed device); • Specify how and through what credentials a unique digital object can be accessed over each kind of user interface or each specific user interface; • Define the required identity authentication level on each user interface; • Limit number of access occasions through digital user interfaces; • Monitor access through each specific digital user interface; • Limit the number of paper hard copies created; • and so on.
  • a unique digital object and its payload are separated from any presentation of the payload on a user interface.
  • a unique digital object cannot be presented on a user interface using direct API calls to the object itself. Rather, an Outlet of the object needs to be created first, and the Outlet is then presented on the interface.
  • Each Outlet is uniquely identified and is related to the unique digital object whose payload it presents and to a specific user interface, such as a physical document, a specifically identified device, etc.
  • an Outlet of a unique digital object may be stored as mutable information attached to that object, while in a preferred embodiment, the Outlet is itself a unique digital object and its universal identifier is used to uniquely identified the outlet – namely that specific presentation of the digital object on a specific user interface.
  • a unique digital object may specify which outlets can be created: which user interfaces are allowed, the required identity authentication level required to access each an outlet on each type of user interface, how many outlets are allowed of each kind, and so on. Example: 1. Specifying allowable outlets.
  • an outlet field specified allowable outlets POST /create HTTP/1.1 Host: facts.com:8080/create Content-Type: application/json Content-Length: 69 ' ⁇ [other json fields related to object creation] “outlets”:” ⁇ “number_allowed”:”unlimited”, “authentication_allowed”,”biometric”, “devices_allowed”,’[“browser”,”tablet”]’, ... ⁇ ” ⁇ ' 2. Creating an outlet.
  • Outlets enable to control the devices on which information is presented, the authentication level required to access it, the number of times it can be accessed, and the nature of allowable user interactions with the information object presented.
  • Ad hoc presentation. Outlets allow creation of explicit presentations of a unique digital object on explicitly stated user interfaces, in an explicitly stated form.
  • Unique Digital Reality can also support ad hoc presentation of unique digital objects.
  • a user interface uses object’s API commands to request presentation in a specific form, without first creating an Outlet.
  • Figure 33 describes an example of the process of ad-hoc information representation on a user interface: a unique digital object stored on UDR 3301 is to be presented on a user interface 3302.
  • the user interface 3302 may present the information in a context- sensitive way: for example, when a personal identification device 3305 is detected in close proximity, the user interface 3302 may present the information ad-hoc in a manner specifically suited to the user whose identity is transmitted by device 3305.
  • the user interface device 3302 may invoke an API call to UDR 3301 asking for an ad-hoc visual representation of the unique digital object, possibly specifying the user identity in the request; UDR 3301 responds to the API call with tailor-made visualization, responsive to the access privileges of that user to the requested object, the characteristics of the user interface 3302, and potentially other considerations.
  • a visualization of the unique digital object is then shown on the user interface 3302, including graphical rendering 3303 of the unique digital object, and unique identifier 3304 in machine and/or human readable form.
  • Jackets is an Outlet combining several unique digital objects ; it may combine a number of unique digital objects together in a single representation.
  • a Jacket – an individual representation of information from UDR – may itself create a new unique digital object, whose payload contains the unique identifier of the objects combined, the unique identifier of a recorded execution used to combine them or other render the visualization, and so on.
  • Figure 34 shows a Jacket providing an amalgamated publication of several different information objects: publication 3401, publication 3402, and publication 3403 each present different figures, where each figure is stored as a unique digital object.
  • An amalgamated publication 3404 presents a Jacket that combined all three figures and may show the unique identifier of each figure, or a unique identifier of the Jacket unique digital object rather than of each figure separately.
  • Unique digital objects are permanent digital objects that do not depend on representation in legacy forms of media such as hardcopy paper, local digital file, or cloud file.
  • a unique digital object may admit proxy information objects, which are not unique digital objects, and which contain the same information as a unique digital object in a specific medium.
  • a Twin refers to a specific unique digital object by its unique identifier, enables information exchange in legacy forms, and allows the information in the unique digital object to be presented in alternative systems of information representation. While a unique digital object is by definition unique, it may admit any number of twins, each referencing it by its unique identifier.
  • Twins may come in legacy forms of information media such as hardcopy documents, local digital files, cloud files, shared ledger entries, or representations in alternative information realities such as Virtual Reality (VR) objects or entities.
  • one or more computers may each store a local file in their local file system, which is a twin of a single specified unique digital object.
  • This discipline enables simple monetization of access to digital content. Every access to a digital document is monitored, and the identity of the device through which access occurred is known.
  • applications can be developed that track usage and monetize access to digital objects such as books, articles, music, video, images, etc.
  • the unique digital reality tracks access in a uniform way. Recording access events as unique digital objects.
  • the event of human access to the content of a digital object over a specified interface is itself recorded as a unique digital object.
  • the access event in computational reality is recorded and can be used for various purposes such as monetization, billing of litigation.
  • Human-readable presentations become entry-points to the Vertical Information Flow.
  • Figure 35 is an illustration of the notion that visually recognizable machine-readable and human-readable codes in publications and user interfaces turn the publication into an entry point into a much larger body of machine-accessible information objects, namely the collection of unique digital objects that constitute the entire vertical information flow – data, processing, and intermediate results - underlying the presented results; as well as unpublished or elsewhere-published results that were created in the same vertical information flow.
  • Detailed Description - Verifiable Interactions One of the key questions in digital transformation concerns interactions between digital or electronic devices and human users. Below, an interaction may refer to: device-device interaction, user-device interaction, or, more generally, an interaction between user and an information object.
  • Embodiments of the invention include a method, based on unique digital reality, to turn an interaction between persons, devices or information objects and other persons, devices, or information objects, into an enduring, provable fact; mirror an interaction in a unique digital object; and create a permanent, citable, machine-accessible, digital proof of interaction that ties into computational workflows and automated deduction processes.
  • embodiments of the invention teach a process whereby an interaction between two individuals, two devices, or an individual and an information object (such as a document), results in creation of a new interaction UDR object certifying that interaction.
  • the interaction object uniquely specifies the identities of the parties, as well as the medium through which the interaction occurred, the identity authentication method used to identity parties to the interaction, and the nature of the interaction.
  • a device with authentication capabilities such as a smartphone or a specially designed device, to establish their identity.
  • Such a device either records their participation in the interaction and commits the corresponding fact object to UDR or enables other stakeholders and devices to do to same.
  • Embodiments of the invention make it possible to mirror an interaction event in a verifiable, software-accessible observed information object, such as a unique digital object.
  • a verifiable, software-accessible observed information object such as a unique digital object.
  • the event of granting consent, by a certain individual, whose identity has been authenticated in a certain way, using a certain mode of consent-granting interaction, to certain information contained in a certain information object, which is presented on a certain user interface in a certain form and layout - may be recorded in permanent verifiable form in an information object, and later used for different purposes.
  • the goals of verifiable interactions Two parties interact using digital means. The identity of the parties sometimes is not known ahead of time, namely, an interaction is possible and must be recorded as it occurs even without prior planning of the parties’ identities.
  • Each of the parties may be interested, later, to prove to a third party whose identity may be unknown at the time of interaction that the interaction occurred.
  • Details regarding the interaction, to become verifiable include: • The identity of the party inviting the interaction; • The identity of the party agreeing to interact; • The medium over which the interaction occurred, for example: in physical space using camera-QR code interaction, in physical space over radio frequency ID (RFID)-reader interaction, in physical space using a user interface, in physical space over close-proximity radio frequency (RF) connection, such as Bluetooth, remotely over a computer network, in shared augmented reality, in shared virtual reality, etc.; • How device or individual identities were authenticated; • Any user interface events involved; and • Any information objects related to the interaction.
  • RFID radio frequency ID
  • RF radio frequency
  • the method disclosed herein enables parties in an interaction to certify that the interaction has taken place, virtually or in physical space, to track it, and to conclusively prove it to each other or to third parties.
  • Practical examples of interactions • Agreeing to pay for goods or services • Alice agrees to sell X to Alice for Y dollars; Alice agrees to buy X from Bob for Y dollars, either virtually or physically. • Acknowledging being physically present at a specific time at a specific place • Alice and Bob are involved in a car accident. Each acknowledges the presence of the other at the crash scene. Examples of interactions between persons: • Alice signs an agreement as one of the parties. • Bob acknowledges reading and understanding a document.
  • Bob signs off on a package delivered to him by Alice.
  • • Bob is a licensed professional doctor. Alice is a patient who comes to consult with Bob. Bob displays his valid professional license to Alice, who acknowledges that the license was displayed to her.
  • • Bob is a night guard in a building. He signs that he is physically present as he enters the building.
  • Document A is labeled as a version of Document B.
  • a document is cited in another document.
  • a document is appended as Appendix to a contract •
  • a statement / claim that one document is a version of another. Examples of interactions between a natural person and a legal entity: • Alice submits a document to a government agency. The agency acknowledges having received the document.
  • Two parties As the identity of the parties may not be unknown upfront, there is always one party who offers the interaction (offering party) and another party accepting the interaction (accepting party). If one party is passive in the communication, e.g. offers a QR code, a passive RFID chip, etc., and the other active, e.g.
  • the user interface which may be equipped with an integrated identification device, is used by the offering party; the. User of the user interface is the accepting party.
  • Remotely over a computer network a server-client interaction.
  • the server is used by the offering party; the client which may be connected to a user interface is the accepting party.
  • Remotely over email or direct message The offering party sends an email or message; the recipient is the accepting party.
  • In shared augmented reality • In shared virtual reality Interaction between a user and a document.
  • a verifiable interaction consider the possibility of a verifiable interaction between a user and a document, where the document is presented on a hardcopy, a computer screen, or a mobile device.
  • a user may interact with an information object by scanning a unique identifier presented on the information object.
  • a user interface such as a web browser or Augmented Reality (AR) interface then allows the user to interact with the information object.
  • Figure 36 shows an interaction between a user and a document using an Augmented Reality (AR) device: a hardcopy document 3601 contains a contract and presents a unique human and/or machine-readable unique identifier 3602.
  • a device 3603 equipped with an optical sensor is able to read the unique identifier and presents a user interface 3604 that allows the user to interact with the document 3601.
  • an interaction may be recorded as a new unique digital object whose payload cites the unique identifier 3602, the unique identifier of the authenticated user, and the nature of the interaction that occurs.
  • Interaction using a personal identification device using a personal identification device.
  • interaction between a user and digital devices such as Internet of Things (IoT) devices such as screens, Automated Teller Machines (ATMs), and so on, is enabled by a personal identification device.
  • the device may be tiny, e.g. worn as a ring or other jewelry, or small, e.g. worn as a wristwatch.
  • the device may be a smartphone or another existing mobile computing device.
  • a device may include a network communication interface, and an identification mechanism able to positively identify the identity of the user (for example, using a biometric identification method or a passcode).
  • An interaction between the user carrying the personal device and other devices can then occur by optic communication (such as scanning a machine-readable code) or by radio frequency communication and be recorded as a verifiable interaction and represented by a unique digital object.
  • the unique digital object representing such an interaction may contain the unique identifier of all devices that participated in the interaction, and other details regarding the nature of the interaction.
  • the personal identification device is a smartphone or a smart watch; in others, it may be a low-cost simple device.
  • Figure 37 shows examples of possible verifiable interactions between a personal identification device and other digital devices: personal identification device 3701 may interact with GPS satellite to create verifiable records of geo-location; it may be used to grant consent by a user interface 3703 located on the device (see below); it may interact with screens and digital user interfaces 3708; it may interact with Automated Teller Machines 3707; it may interact with other personal identification devices 3706, enabling verifiable interactions between two persons; it may interact with doors, cabinets or other Internet of Things devices, for example in order to grant physical access. In a preferred embodiment, any such interaction is communicated and becomes a unique digital “interaction” object on UDR 3704.
  • Figure 38 describes possible uses of personal identification device in conjunction with unique digital reality. Consent as an example for interactions.
  • consent can be given by an entity (a person or a legal entity) to pay for goods or services, to abide by agreed specified terms and conditions, etc.
  • acknowledgement can be given that a specified document has been read, that credentials have been presented and verified, that a meeting between specified individuals has taken place, that a specified item has been delivered and accepted, and more.
  • Consent Prior art. There are basically two systems for consent and acknowledgement in use today. The first is the hand signature: the entity consenting or acknowledging signs a physical document. The second is a digital signature: the entity consenting or acknowledging provides a binary string.
  • Embodiments of the systems and methods described herein enable an agent, such as a natural person acting on behalf of themselves or on behalf of an entity, to give acknowledgement or consent quickly and easily, in a way that makes it easy to verify, long after the interaction has taken place, that the interaction indeed took place between the specified entities.
  • Embodiments of the invention also teach a method to verify the fact of acknowledgement or consent along with the relevant identity.
  • an interaction represents a new unique digital object created in UDR that incorporates identities corresponding to two or more parties and optionally referring to an object, a transaction, an event, or other relevant data.
  • Interactions can be facilitated by storing identifying information, sufficient to prove the identity of a person or organization, on a device possessed by a person.
  • a person interested in certifying a transaction or event may transmit his or her identifying information (for example, a personal device) to a receiving device, where a unique digital object is generated by authenticating the person’s identity and committing the identity into the unique digital object.
  • identifying information for example, a personal device
  • a personal identification device able (i) to identify the user, (ii) to communicate optically or wirelessly with other devices or user interfaces, and (iii) able to communicate over a computer network with UDR, may be used to obtain user consent and create verifiable consent interactions.
  • a verifiable consent interaction may be implemented as a unique digital object in UDR, which includes (i) the identity of the user whose consent is requested (ii) the details of the consent request – such as an identity of a document signature requested, including the unique identifier of the document and the exact location of the signature within the document; or a such as an End User License Agreement (EULA) the user is asked to consent to.
  • EULA End User License Agreement
  • the “consent interaction” unique digital object will also include (iii) the identity of the personal identification device that identified the user; (iv) the method by which the user’s identity has been authenticated (for example, face recognition, fingerprint recognition, passphrase entry, voice recognition, iris recognition, etc); (v) the identity of the user interface upon which the details of the request (e.g. the EULA) has been communicated to the user; (vi) the unique identifier of the Outlet presented to the user on the user interface; (vii) the method by which positive user consent interaction has occurred (for example, a touchscreen touch, a voice command, etc.).
  • Figure 39 shows various possible ways to establish verifiable consent using user Interfaces and/or personal identification devices: (i) a method involving personal identification device 3901 communicating with a user interface 3902. In this example the personal identification device does not have a user interfaces; while the personal identification device is used to authenticate user identity, a nearby user interface 3902 is used to obtain the user interaction and record the interaction as a unique digital object in UDR 3903. The actual consent request (such as a EULA) is presented on a nearby user interface not shown. (ii) a method involving a personal identification device 3904 with a small user interface, able to collect user interaction and record it in UDR 3903.
  • a method involving a personal identification device 3904 with a small user interface able to collect user interaction and record it in UDR 3903.
  • the actual consent request (such as a EULA) is presented on a nearby user interface not shown; (iii) a method involving two personal identification devices, for example when simultaneous consent of two different users is required.
  • Personal identification device 3906 communicates with second device 3907 to establish consent, and then communicates the interaction to UDR 3903; (iv) a method not involving personal identification device and involving a user interface able to authenticate user identity (for example, using a passcode, facial recognition camera, or fingerprint reader).
  • User interface 3908 presents the consent request 3909 (for example, a EULA), identifies the user and collects the user interaction, e.g. on a window 3910, then communicates the interaction to UDR 3903.
  • Figure 40 shows an example of the creation process of a verifiable interaction digital object, demonstrated through the case of interaction achieving verifiable consent: user 4001 uses a device 4002 (such as a smartphone, smart watch, tablet, personal identification device, etc) to authenticate their identity in an authentication stage 4009 and, separately, identify an information object, such as a physical document or on-screen digital document 4003, in a document acquisition stage 4010.
  • identity measurements may be performed using biometric identification or a passphrase; while document acquisition may be performed using methods such as optic barcode recognition, radio frequency detection, Bluetooth connection, or manual input of a unique identifier or access code of an information object.
  • the device 4002 After the consent request is presented to the authenticated user via the information object 4003, the user is required to perform an action signifying active, positive user consent 4011 with the device 4002 or another close-by user interface, such as touching a “yes” button on a touchscreen 4004, giving an “I agree” voice command, etc.
  • the device 4002 creates a unique digital object 4005 representing the consent interaction, which may include the authenticated user identity 4006 (for example, by specifying the unique identifier of an identity unique digital object), the consent request as shown 4007 (which may be a unique digital object corresponding to the information object 4003 or an Outlet through which the interaction has occurred; the time and location of the positive user confirmation event and the manner in which the positive interaction occurred 4008.
  • Cross-consent may include the authenticated user identity 4006 (for example, by specifying the unique identifier of an identity unique digital object), the consent request as shown 4007 (which may be a unique digital object corresponding to the information object 4003 or an Outlet through which the interaction has occurred; the time and location of
  • FIG. 41 describes a process whereby two individuals, each using a device (such as a smartphone, a smart watch, a screen, or a personal identification device) interact with the same information object (such as a document presented in hard copy or on-screen).
  • a device such as a smartphone, a smart watch, a screen, or a personal identification device
  • each party verifies their own identity with their own device, and also verifies their own identity with the other individua’s device; and each device acquires the information object. Then, each individual is prompted for a positive consent action in their own device.
  • two “interaction” or “consent” unique digital objects in digital reality are created, one for the consent of each individual, yet each confirming that the other person’s identity has been confirmed.
  • Technical Description Conditions for a verifiable interaction The offering party and the accepting party must both have a unique identity digital object in unique digital reality. Both offering and accepting parties must have the ability to create new objects on UDR.
  • a secret exclusively communicated over the interaction medium. How can one prove that the interaction took place over a specified medium? In the communication, the offering party discloses (offers) a secret to the accepting party, that is only communicated over the interaction medium and not in any other way.
  • This secret is not recorded in the unique digital object mirroring the interaction; only those who were able to communicate directly with the offering party over the interaction medium can know the secret. It is in the offering party’s interest to only make the secret available over the specified interaction channel. As an example, consider the passive RFID chip on a credit card; the secret - namely the credit card - number is only available over the RFID channel to a reader in sufficient proximity. It is the cardholder’s interest and their financial intuition’s interest to not disclose the card number publicly. A secret may specify intended recipients or may be used by any party who receives it. Stages in a verifiable interaction: • Stage 1: Offering party creates a secret and an offer object on UDR, which includes their identity.
  • Stage 2 Offering party communicates the secret to the accepting party over the designated interaction medium.
  • Stage 3 Receiving party creates an interaction object on UDR, which includes their identity, the secret (or some derivative thereof), and the identifier of the offer object. Verification of an interaction. An interaction is claimed to have taken place on a given time, over a given interaction medium, between two parties. The verifying party is shown the interaction object and verifies: • The identity on the interaction object belongs to one of the claimed parties; • The verified commitment time of the interaction object is identical (or within a specified margin) to the claimed interaction time; • The offer object specified in the interaction object was created by the other claimed party; • The verified commitment time of the offer object is earlier (to specified margin) than the commitment time of the interaction object.
  • three public-private key-pairs are used: a key-pair for the identity of the offering party, a key-pair for the identity of the accepting party, and a key-pair for the interaction itself.
  • both parties before the interaction starts, both parties have a unique identity digital object, each of which publishes their own public key.
  • the stages of a verified interaction are as follows: (offer creation phase) 1. Offering party (party 1) creates on offer key-pair with an offer public key (OPub) and an offer private key (Opriv). 2.
  • Offering party calculates the digital signature of OPub with their own private key (key-pair 1), to produce signature of OPub (1-signature-OPub).
  • Offering party creates a new offer unique digital object, with unique identifier offerID, which contains: the universal identifier of offering party (ID1), namely, the universal identifier of their unique identity digital object; OPub; 1-signature- OPub; any relevant side-information, such as universal identifiers of relevant unique digital objects related to the interaction; in some embodiments, a time limit for completion of the interaction; in some embodiments, the maximum number of interactions that can occur based on this offer object; in some embodiments, details of the interaction medium over which the interaction will be offered. (interaction phase) 4.
  • Offering party communicates Opriv and offerID, either in open-ended broadcast communication or in peer-to-peer communication directly to single or multiple intended accepting parties, over the interaction medium. 5. Accepting party receives Opriv and offerID over the communication medium 6. Accepting party creates an interaction-message and digitally signs it using Opriv to obtain Offer-signature-message. The interaction-message may derive from the side information on the offer object, obtained by the accepting party by accessing the offer object using offerID, or may include user interface activities performed on the side of the accepting party. 7. The accepting party calculates the digital signature of Offer-signature-message with their own private key (key-pair 2), to produce signature of Offer-signature- message (2-signature-Offer-signature-message). 8.
  • Accepting party creates new interaction unique digital object, which contains: the universal identifier of accepting party (ID2), offerID, interaction-message, Offer-signature-message, and 2-signature-Offer-signature-message. Verification of an interaction in the preferred embodiment.
  • Figure 42 shows a protocol for verifiable interaction in a preferred embodiment.
  • offering party 4201 Before the interaction, when identifies are being set up, offering party 4201 generates a cryptographic keypair (such as an RSA keypair) denoted “keypair 1”, publishes the public key “public key 1” 4206 of this keypair in their UDR identity unique digital object 4207, and retains the corresponding private key “private key 1” 4202.
  • a cryptographic keypair such as an RSA keypair
  • an accepting party 4204 when identifies are being set up, an accepting party 4204 generates a cryptographic keypair (such as an RSA keypair) denoted “keypair 2”, publishes the public key “public key 2” 4211 of this keypair in their UDR identity unique digital object 4212, and retains the corresponding private key “private key 2” 4205.
  • the offering party 4201 generates a new cryptographic keypair (such as an RSA keypair), dedicated specifically to the present interaction.
  • the private key in this keypair is denoted “Opriv” 4203 and the public key in this pair and broadcasts or sends the private key “Opriv” 4203 is denoted “Opub”.
  • the offering party sends or broadcasts the private key “Opriv” 4203 in a manner that only an interacting party may receive the transmission or broadcast – for example, by broadcasting it over an interaction channel such as a short-range radio frequency, Bluetooth, optical/visual presentation (so that only those present may read it), or a sound speaker (so that only those within listening range may receive it) and so on.
  • the offering party then creates an “offer” unique digital object 4208 in UDR 4216, whose payload 4209 contains an offer unique identifier, the identity unique identifier of the offering party, and the offer public key “OPub”.
  • a second part of the payload 4210 of offer object 4208 consist of a digital signature, performed by the offering party, which is obtained by signing the offer public key “Opub” using the private key 4202.
  • the accepting party is in possession of the private key “Opriv” 4203 and creates an “interaction” unique digital object 4213 in UDR 4216.
  • a first part of the payload 4214 of the interaction object 4213 consists of the unique identity of the accepting party, any message contained in the interaction, and a digital signature performed by the accepting party 4204 and obtained by signing the interaction message using the private key “Opriv” 4203.
  • a second part of the payload 4215 consists of another digital signature performed by the accepting party, obtained by digitally signing the message using the private key “Private key 2” 4205.
  • Such a verifiable interaction is claimed to have taken place on a given time, over a given interaction medium, between two parties.
  • the verifying party is shown the interaction object and performs the actions comprising: 1. Obtains the public key of key-pair-2 from object with ID2. 2. Verifies that 2-signature-Offer-signature-message is the signature of Offer- signature-message by key-pair 2 using the public key of key-pair 2.
  • This protocol covers a very wide array of possible interaction media, such as those mentioned above.
  • One-time interactions In an embodiment, only one interaction is allowed based on an offer object: the first interaction object to be committed to UDR based on a single use offer object is the only legitimate interaction, while all others will not pass verification.
  • Identity authentication When any of the parties is a device with identification capabilities, which acts as an interaction interface for a human user, the objects created may additionally include the method of authentication performed as part of the interaction.
  • the offer object may specify the method of authentication of any human user offering the interaction, and the interaction object may specify the method of authentication of any human user accepting the interaction.
  • the offer object may specify allowable authentication methods required of any accepting party.
  • Interaction through an Outlet is the identity of a specific presentation of an information object, as rendered on a specific screen at a point in time, printed on a specific sheet of physical paper, etc. While we discussed outlets in the context of information presentation (output), they also play a key role in the context of user-information object interactions (input). For example, one may be interested in verifying the exact version of a document signed, including the layout in which it was presented to the user who signed it.
  • the information object is rendered in human-readable form.
  • an outlet includes both information presentation and an opportunity for the user to interact with the information object presented, it shows the secret that enables verifiable interaction; for example, a printed document, as an outlet of a certain unique digital object, may include a machine-readable code that allows certain user interactions – not with that sheet of paper, but with the underlying unique digital object.
  • an offer object is created, which cites the outlet object or, in an embodiment the outlet object and the offer object are the same unique digital object; and the machine-readable code includes the private offer key and the universal identifier of the offer object.
  • a unique information object containing terms and conditions which is rendered on a screen with close-proximity radio frequency (RF) interaction capability.
  • the screen broadcasts the offer secret.
  • a user bringing their personal interaction device next to the screen is prompted by their device to agree / disagree; the user reaction causes their device to create an interaction object which uses the offer object and cites the outlet objects.
  • FIG. 43 describes an example for co-signing an information object using an Outlet, verifiable interaction, and personal identification device, in which a contract is signed (executed) using an on-screen Outlet and personal identification devices: first individual 4302 uses a personal device 4301 and second individual 4307 uses a personal device 4306.
  • the two devices 4301 and 4306 could be similar or different; for example, one could be a smartphone and the other could be a personal identification device).
  • Each device verifies identity of its user and acquires an Outlet 4303 displaying or broadcasting its unique identifier 4304 on a user interface 4305.
  • the Outlet and its unique identifier 4304 may be specific for the purpose of the intended interaction, namely, may only allow interaction with the pre-designated users 4302 and 4307 (identified by the unique identifier of their identity unique digital objects in UDR) or may be open to use by a pre- determined group of users, or be open for use by all users.
  • the unique identifier 4304 used for acquisition may include a private cryptographic key “Opriv” of Figure _42_ used to prove that both parties indeed interacted directly with the Outlet over a prescribed interaction channel (for example, that they were both co-present physically with the Outlet at the same time).
  • each device asks its user for a positive active consent, for example by using a user interface on the device 4308.
  • Figure 44 describes an example for co-signing an information object using an Outlet, verifiable interaction, and personal identification device, in which a contract presented using a hard-copy (physical document) Outlet is signed (executed) using personal identification devices with user interface:
  • a first individual 4404 uses a device 4405, and a second individual 4403 uses a (potentially different) device 4406.
  • Each device authenticates its user and uses an optimal sensor (such as a camera) to acquire an Outlet printed on physical hardcopy 4401 using its machine-readable unique identifier 4402.
  • the Outlet and the unique identifier 4402 may be intended for general use or may be intended for the use of a pre-determined group of people or may be specific for the individuals 4404 and 4403, specifying them through the unique identifiers of their identity unique digital objects.
  • the unique identifier 4402 used for acquisition may include a private cryptographic key “Opriv” of Figure _42_ used to prove that both parties indeed interacted optically with the printed Outlet.
  • each device asks its user for a positive active consent, for example by using a user interface 4407 on their respective devices.
  • Interactable Document Identifier A property of a document that can interact with interaction devices or be interacted with, such as QR code, an embedded watermark, and so on.
  • Physical Handshake Occurs when both sides of the interaction have a physical location and are physically co-located, for example, two persons meet.
  • Virtual Handshake Occurs when the sides interact over a network or when one of them does not have a physical location, for example, two persons interact virtually or a person interacts with a document.
  • Example Embodiment A handshake device Handshake device. At a preliminary stage, an entity (person or legal) with an existing identity on UDR pairs with a handshake device.
  • a handshake device supports the handshake process by enabling one or more of: interaction with other devices, biometric identification, active confirmation or response from user, and an ability to create a handshake object in UDR.
  • Embodiments include smartphones and cards with RF chips as handshake devices.
  • Other embodiments of the invention include specially designed small devices with network connectivity and an iris reader .
  • Some handshake devices offer positive biometric identification of their carrier; some handshake devices collect a response, such as yes/no.
  • a smartphone offers both; an RF chip card offers neither.
  • another device such as a computer may be used for either.
  • the pairing event is submitted to UDR, such that the pairing object on UDR contains the unique identifier of the carrier identity and the secret key stored on the device Extensions Logins.
  • Login to a website is done by a virtual handshake between an agent and the website access control system.
  • a person’s smart watch can be used to unlock a laptop computer, where the identifying information stored on the smart watch is authenticated against the person’s identity (stored in UDR) to prove that the person is authorized to access the laptop.
  • Having a secure and efficient handshake system means that passwords and cashiers can be eliminated. If you have a smartphone with a fingerprint or retina reader (a biometric ID), you do not have to remember passwords or credit card details. Physical access control.
  • Radio Frequency Identification Today, Radio Frequency Identification (RFID) and proximity cards are used for access control.
  • RFID Radio Frequency Identification
  • the act of presenting a digital ID, e.g. a card with RFID, is in fact a handshake. Doing it with a device that has a positive biometric ID is much more secure. I just go through the door, present my device to the door, and put my finger on the device, and reconsider – I get full-on biometric access to that room.
  • identity is universally recognized by a set of stakeholders, the same device can be usable to access offices, gyms, apartment complexes, or any other controlled-access spaces.
  • the entry is also recorded as a fact in UDR, incorporating at least the fact of a person’s identity such that the entry can be conclusively proven later. Payment systems.
  • the interaction device can be seen as a proxy of the agent. After pairing of the identity and the device occurs, any digital signature with the device’s secret key is considered an authentic interaction by the agent. Namely, the combination of the two following facts asserts the agent interaction: the pairing of the agent’s UDR identity with the interaction device and the signature by the secret key of the interaction device.
  • An extension A sequence of single-use keys goes into the device. Each interaction consumes a single key. This way, the keys cannot be stolen. Positive IDs on device. An interaction device may need a positive identification to transmit and receive, and to create a fact.
  • an identity associated with an interaction device may be verified before the device can be used for a handshake.
  • the handshake process Once the handshake process has been set up as explained above, the handshake can proceed.
  • Stage I Exchanging keys In an interaction between two interaction devices, one device (the transmitting device) provides the other (the receiving device) with a public key.
  • the receiving device creates a UDR fact with the public key that it received and its own public key.
  • Stage II Factifying the exchange
  • the receiving interaction device creates a fact in UDR, which includes: • The public key of the receiving device • The public key of the transmitting device (as received) • The time and location (if relevant) • Interaction details, e.g. payment details Inspecting and validating a handshake.
  • the fact verifier can assert at least the following: • The public keys of both entities match their interaction devices. • The interaction devices were paired to the UDR identities at the time of the interaction. Network of facts created by a sequence of interactions. Numerous societal and business processes are based on a sequence of interactions. Consider the process of corporate equipment procurement. The stakeholders are buyer, seller, financial institution, and delivery company.
  • the buyer requests a quote, then the seller sends a quote, then the buyer internally approves a purchase order, then the buyer issues and sends a purchase order, then the seller issues and sends a proforma invoice, then the buyer internally approves payment and makes payment, then seller sends equipment, then delivery company signs off of package received for delivery, then buyer receives delivery and signs off on the package, then seller issues and sends an invoice and receipt to the buyer.
  • the order of events here may change slightly, however verification of integrity of the paper trail will verify consent at different stages along the process.
  • Embodiments teach a method and apparatus for curation of personal digital information into a collection, for example, for establishing facts regarding ownership, trade, inheritance of objects, and so on.
  • the method disclosed enables an individual to search the entire collection of their digital information, to donate or sell – anonymously or by name – specified sub-collections for various purposes, such as medical or marketing research. They can consent to running AI algorithms against their set of their personal data for the purpose of training the AI algorithms and for obtaining analytics, statistics, insights, and personal recommendations from it. They would have control over knowing explicitly who is using their personal data, for what purpose, and so on.
  • Figure 46 shows several possible counterparties, to which an individual may elect to grant access privileges to their personal information stored as unique digital objects on UDR.
  • Figure 47 shows examples of data assets created by an individual.
  • data In the current data economy, data is not considered a thing or a collection of things; therefore, there is no way to establish ownership over data. Most people are not used to thinking of data that they generate as property that belongs to them or even as a concrete asset that they can or should own. This is true for pictures uploaded to social media, as well as to medical data that is collected from them during hospital visits.
  • Personal information is stored by multiple service providers, Internet companies, government agencies, healthcare providers, etc. When a person dies, his personal information may be lost forever to his family or heirs. Because data is not a thing, it cannot be passed by inheritance. Method.
  • data becomes a ‘thing’ – a concrete asset that can be owned, rented, or sold.
  • New products and services can appear that make use of the consolidated collection containing all a person’s digital information – for example, by extracting insight using artificial intelligence tools, by creating search functionality, etc.
  • Unique digital objects that contain personal information are attributed to the UDR identity of the individual who generated them or about whom they have been collected. Encryption and access control ensure that only the owner has access to their respective objects.
  • the invention teaches software interfaces and user interfaces that specify access control filters that give or revoke access to an individual’s objects according to specific criteria. Related Technology and prior art. In the present situation, none of the individual’s concerns are addressed. Data is owned by third parties.
  • An individual has no way to know what data regarding themselves has been collected, how it is being used, who buys this data from whom and for which purpose, and so much more. Concerns of a data-generating individual.
  • An individual generates massive amounts of data including: • Photos and videos • Online purchases • Medical records • Geo time series (time+location over time) • Entry to monitored public places, e.g. mass transit turnstiles • Content consumed, e.g. books, films, music • Bank statements • Purchases, e.g. credit card purchases • Personal finances, e.g. pensions, savings • Browsing history and interaction with online entities • Genetic data • And so on.
  • a method for curating digital information for a person comprising: storing one or more pieces of digital information that are generated by the person as a collection of fact objects in a universal digital reality (UDR); and attributing each of the fact objects to the UDR identity of person that generated the UDR objects; allowing secure access to the stored fact objects by the person.
  • the method of embodiment 1, wherein the access to the stored fact objects is secured by encryption. 4. The method of embodiment 1, wherein the access is provided through an interface. 5. The method of embodiment 4, wherein the interface specifies one or more filters that give or revoke access to the person’s fact objects. 6. The method of embodiment 5, wherein the filters that give or revoke access to the person’s fact objects are based on one or more criteria. 7. The method of embodiment 5, further comprising: tracking the access to the person’s fact objects. 8. The method of embodiment 1, further comprising: establishing legal ownership by the person for the data generated by the person. 9. The method of embodiment 1, wherein the person can control access to their data by other people or entities. 10.
  • the fact objects include location information for the person over a period. 18.
  • the fact objects include monitored entry information of the person at one or more places.
  • the method of embodiment 1, wherein the fact objects include content consumed by the person.
  • the content consumed by the person includes any of books, films, music, performances, speeches, or classes.
  • the method of embodiment 1, wherein the fact objects include bank statements corresponding to the person. 22.
  • the method of embodiment 1, wherein the fact objects include purchases made by the person.
  • the fact objects include personal finance information associated with the person. 24.
  • the method of embodiment 1, wherein the fact objects include any of a browsing history of the person, or interactions between the person and online entities. 25.
  • the method of embodiment 1, wherein the fact objects include genetic data corresponding to the person. 26.
  • the method of embodiment 1, wherein the fact objects include any of actions taken by the person, or milestones attained by the person.
  • Certification of Geographical Location disclose a method and apparatus for certification determining and verifying geographical location and topography. The ability to verifiably represent that a given entity (person or machine) was located at a specified location at a specified time is crucial in numerous applications. This invention discloses a few different methods that enable an agent to decisively prove their location, at a given time in the past, to an interested verifying party.
  • UDR UDR with a time commitment and, optionally, with a location commitment and/or identity commitment.
  • Embodiments of the invention teach commitment of location and verification of location as part of the UDR infrastructure. Numerous types of facts in modern society involve determining the geographic location. In a fact exchange cycle, an assertion is made on the location where a certain property is located, the location where a certain event occurred, and so on. Below are a few examples where a location is required for a fact: ⁇ Location where a contract was signed ⁇ Location where an event, e.g.
  • Verifiable Geo-location information can be recorded as unique digital objects in one of several ways: 1. Cell tower triangulation: unique digital objects contain cell tower reading obtained by the device whose location is to be verifiably recorded. 2.
  • GPS Global Positioning System
  • unique digital objects contain cell GPS signal readings obtained by the device whose location is to be verifiably recorded.
  • Wi-Fi network and Bluetooth signals unique digital objects contain wi-fi and Bluetooth reading obtained by the device whose location is to be verifiably recorded.
  • Continuous geo trail– unique digital objects contain GPS reading obtained by the device whose location is to be verifiably recorded; however unique digital objects are created and committed continuously.
  • Method 1 Cellular tower triangulation Method Summary. A mobile phone with an Internet connection records for cell tower data received from towers, uploads the data to UDR (encrypted). The mobile tower operators independently upload the cell tower authentication strings to UDR. The fact that the two match is partial proof that the agent was physically located near the claimed towers.
  • FIG.23 is a schematic view of an illustrative method for determining location of a stationary or mobile user, e.g. and agent of a UDR device at one or more times, based on cell tower triangulation.
  • Figure 48 shows certification of geographical location using the cellular tower triangulation method. Instead of triangulating from cell towers, in some embodiments a person’s location can be triangulated based on other wireless communication signals, such as Wi- Fi or Bluetooth.
  • Method 2 GPS satellite signals
  • Method Summary A mobile device with GPS antenna and internet connections, records GPS data received from satellites, and commits it to UDR, possibly in encrypted form. Independently, fixed ground stations continuously upload GPS satellite signals they record to UDR.
  • Figure 49 is a schematic view of an illustrative method for determining location of a stationary or mobile user, e.g. and agent of a UDR device at one or more times, based on GPS satellite data.
  • Method 3 Creation of verifiable continuous Geo trail with zero-knowledge verification Method Summary.
  • a device with GPS and internet connection continuously uploads the location (encrypted) to UDR.
  • the fact presenter provides the encryption keys to the location stamps around the time of interest. Continuity of location guarantees that the fact was accurate.
  • the fact presenter can generate Identity, time, and geo location at each stamp.
  • Figure 50 is a schematic view of an illustrative method for determining location of a stationary or mobile user, e.g. and agent of a UDR device, based on continuous monitoring of location and a continuity of location at subsequent times. For instance, for a known identity of the user of the device at subsequent times T0-T4, location stamps established for each of the subsequent locations L0-L4. Figure 50 thus shows certification of geographical location using the verifiable continuous Geo trail method. Zero-knowledge proof of location continuity. In an embodiment of the invention, two encrypted location stamps can be compared and proved to be no more than a prescribed distance apart, without knowledge of the actual geo-location contained in each stamp.
  • Example Embodiments for Method 1 Cell tower triangulation 1.
  • a method performed in conjunction with a UDR system comprising: recording cell tower data received from a plurality of cell towers at a mobile device; uploading the recorded cell tower data from the mobile device to the UDR system as encrypted data; independently uploading cell tower authentication data to the UDR system from an operator associated with the cell towers; determining confidence that an agent associated with the mobile device is at the location, based on a match between the recorded cell tower data and the cell tower authentication data. 2.
  • the method of embodiment 1, wherein the determined confidence is proportional to the number of the cell towers. 3. The method of embodiment 1, wherein the determined confidence increases based on repeated matching within a time. 4. The method of embodiment 1, wherein the mobile device is a mobile phone. 5. The method of embodiment 1, wherein the location corresponds to a location where a contract was signed. 6. The method of embodiment 1, wherein the location corresponds to a location where an event occurred. 7. The method of embodiment 1, wherein the location corresponds to a location where at least two people met. 8. The method of embodiment 1, wherein the location corresponds to a location where a photograph was taken. 9. The method of embodiment 1, wherein the location corresponds to a location path of a moving object, e.g.
  • GPS satellite signals 1 A method performed in conjunction with a UDR system, the method comprising: recording GPS satellite data received from a plurality of satellites at a mobile device having a GPS antenna and a wireless network connection; uploading the recorded GPS satellite data from the mobile device to the UDR system over the wireless network connection; independently uploading GPS signal data to the UDR system from fixed ground stations; determining confidence that an agent associated with the mobile device is at the location, based on a match between the recorded GPS satellite data and the GPD signal data.
  • Example Embodiments for Method 3 Geo-trail factification 1. A method performed in conjunction with a UDR system, the method comprising: continuously uploading location information from mobile device having a GPS antenna and a wireless network connection to the UDR system over the wireless network connection as encrypted data; and providing encryption keys to location stamps around a time of interest to verify the location; wherein continuity of location guarantees that the location fact is accurate.
  • a method performed in conjunction with a UDR system comprising: recording cell tower data received from a plurality of cell towers at a mobile device; uploading the recorded cell tower data from the mobile device to the UDR system as encrypted data; independently uploading cell tower authentication data to the UDR system from an operator associated with the cell towers; determining confidence that an agent associated with the mobile device is at the location, based on a match between the recorded cell tower data and the cell tower authentication data.
  • the determined confidence is proportional to the number of the cell towers.
  • the determined confidence increases based on repeated matching within a time.
  • the mobile device is a mobile phone. 5.
  • a moving object e.g., a vehicle, a plane, a projectile, a planet, a satellite, an individual, animal, a particle.
  • a method performed in conjunction with a UDR system comprising: recording GPS satellite data received from a plurality of satellites at a mobile device having a GPS antenna and a wireless network connection; uploading the recorded GPS satellite data from the mobile device to the UDR system over the wireless network connection as encrypted data; independently uploading GPD signal data to the UDR system from fixed ground stations; determining confidence that an agent associated with the mobile device is at the location, based on a match between the recorded GPS satellite data and the GPD signal data. 12.
  • a method performed in conjunction with a UDR system comprising: continuously uploading location information from mobile device having a GPS antenna and a wireless network connection to the UDR system over the wireless network connection as encrypted data; and providing encryption keys to location stamps around a time of interest to verify the location wherein continuity of location guarantees that the location fact is accurate.
  • IoT Internet of Things
  • internet-connected devices is one area where digital fragmentation is currently acute - and is likely to become more acute in the coming years.
  • Measured data management The continuous flow of data generated by continuous measurements of IoT devices, and by interactions of these devices with other devices and with users, is staggering. In principle, IoT measurements can be used for multiple purposes including research and insight mining, e.g. regarding individual and collective habits, verification, and validation as they constitute observed facts underlying many vertical flows, and more. In practice, IoT data is horizontally fragmented due to multiple storage formats, privacy concerns regarding personal data, and data hoarding incentives. 4. Data integrity and trustworthiness management.
  • each device is assigned a unique identity digital object in UDR upon being manufactured.
  • each device contains a hardware / hard coded key, e.g. a private cryptographic key, that unambiguously links it with its corresponding unique digital object.
  • the identity of a device is mirrored in unique digital reality; just as the physical device is a unique thing, so is its mirroring digital object.
  • the unique identity of the device does not depend on its physical location and is persistent even when software and hardware components are updated or replaced.
  • Events such as software updates, physical device access, hardware component replacement, and changing device location, are recorded in unique digital reality as digital objects related to the device identity object and include the identity of the authorized person/entity who performed the update or change.
  • the current security standards upheld by the device and the security patches applied are stored as objects in unique digital reality, allowing a clear picture of the security status of the entire network.
  • An IoT network maintains an inventory of devices on the network according to their universal identifiers and can use it to track all device on the network and query their status. The identity of a device persists even as it is moved between different IoT networks.
  • each device measurement (or batch of device measurements) creates observed unique digital objects on UDR; this enables consolidation of all measurements obtained over the network, and integration of these measurements in vertical information flows.
  • each IoT device contains a certification module that creates unique digital objects at the hardware level or system software level.
  • verification of measurements including automatic verification, relies on the fact that measurements are cryptographically signed by the device in a signature that corresponds to their unique device identity object; it is therefore clear which device took the measurement, where it was and what hardware/software it was running when the measurement was taken.
  • IoT networks include several devices that can range in the tens of thousands and more. Keeping track of the identity of the devices in the network and the exact conditions in which measurements were taken, for example the location of a device, can be a challenging problem.
  • every IoT device is manufactured with a new unique identity object.
  • the identity object is the mirror, on UDR, of the physical device: it contains serial numbers, hardware digital signatures, hardware, and software configurations, etc.
  • any software update on the device creates a unique digital object representing the software update and linked to the devices’ identity object.
  • each part may have its own unique identity object, and the identity object of the device will link to the identity objects of its sub-parts; exchanging a sub-part of a hardware results in a new device, and so, in a possible embodiment, could create a new identity object.
  • OS-level digital signature verification makes it possible to digitally sign hardware components and remotely verify the physical integrity of each device.
  • the processes and protocols describe above enable to use UDR to create a consolidated inventory of IoT devices in each physical space, organization, vehicle, property, or computer network. It enables to track their current location continuously and reliably, current hardware configuration and current software configuration.
  • IoT measurements and IoT control events (such as door access) in a consolidated way, making these measurements permanently software accessible over a uniform interface, verifiable, explicitly owned, and monetizable.
  • It enables vertical digital consolidation in the sense that conclusions drawn, using a processing stage, from measurements made by (potentially multiple) IoT devices, can be traced back and verified by accessibly the underlying verifiable IoT measurements.
  • unique digital object with universal identifier “w5kx” is a door with status sensor and open/close controller.
  • the door status can be queried through the HTTP GET command: GET http://facts.com/w5kx/get_door_status And the status can be changed through the PUT command: GET http://facts.com/w5kx/close_door
  • This event is then recorded on UDR as the device creates a new object mirroring this event.
  • this interface addresses the device through its universally unique identity and uses the UDR identity authentication mechanism. The full list of device components can be obtained e.g.
  • Unique Digital Reality makes it possible to mirror an object in various layers of reality with a unique digital object, and attached a machine-readable code, which contains the universal identifier of the mirroring unique digital object.
  • the code which we call omnicode for the purpose of this disclosure, is intended to allow human users to interact with the mirrored objects through their mirroring digital objects.
  • Connecting and signing a contract and an appendix To connect a contract and an appendix, the user simply scans the code on both documents. To sign, the user scans the code. • Ordering service for an electrical appliance. To look for a service technician for an appliance, the user scans the code on the appliance. • Connecting digital documents to physical objects.
  • the user scans the code on the appliance and the code on the document. • Creating and reviewing service records for a physical item / device. Each service provider scans the code on the device and enters a new service record; the entries are stored on UDR. Service provider scans the omnicode on the device to add a new record. Service records are immutable and permanent – stored on UDR. By scanning the omnicode on a washing machine or a car, the user can access the entire service history of the item / device – including identity of the service provider, identity of any parts replaced also connected through their omnicodes, location of the service, time/date, etc.
  • an Omnicode may be implemented using the existing standard of QR codes but is not in any way equivalent or exchangeable with the standard of a QR code.
  • the latter is a standard for optical machine-readable codes; in contrast, Omnicodes are specifically used to connect objects in various layers of reality (such as physical objects, objects in augmented reality, objects in virtual reality, information represented on screens, etc.) with unique digital objects used to mirror these objects. While a preferred embodiment of Omnicodes uses optically readable codes, other presently available embodiments may use other methods, such as RFID and other close-proximity radio-frequency standards. Attaching an omnicode. How are omnicodes attached to objects?
  • Physical omnicode a physical object is manufactured with a universally unique omnicode containing the universal identifier of its mirroring unique digital object; a physical document is printed with the code.
  • Attaching a code in augmented reality Fixed-location objects in physical reality, such as buildings, rooms, squares, statues, can be attached an omnicode without physically attaching it anywhere. The unique digital object mirroring the physical object contains an exact location and orientation in space; augmented reality applications connected to UDR can display the code when a user looks at the object through an augmented reality application.
  • An object in a shared virtual reality exists in that layer of shared reality; may display an omnicode to allow users to interact with it and connect it to objects in other layers of reality, for example a door in virtual reality may be open whenever another door in physical reality is open.
  • some physical objects present unique serial numbers – while most do not.
  • As the unique digital object linked using an Omnicode to a physical object is universally unique and permanent, it becomes possible to uniquely reference the physical object (in a contract, for example) and to create digital records of transactions involving it – for example, moving an inventory item between departments.
  • Linking objects across layers of reality • Linking documents to physical objects • Linking objects in shared virtual reality to physical objects OmniCodes are evocative of the notion of UDR.
  • An object in physical reality, is a permanent, unique thing. This is how our perception of physical reality is formed. Assignment of a code implies the existence of a digital object that is unique and permanent and corresponds to the physical object. The digital object cannot be copied just like the physical object cannot be copied. So attaching an OmniCode is equivalent, in a conspicuous way, to creating a unique digital representation / mirror of the object.
  • Figure 51 shows possible uses of Omnicodes in various objects in physical, augmented, and virtual reality. Omnicodes bring objects on physical reality, shared augmented reality, shared virtual reality, and UDR together on the same level. The same code system is used for all objects, making it possible to connect / link objects on different layers of reality. Omnicodes enable a range of applications that herald endgame digital transformation.
  • Omnicodes controlling objects and interacting with a device through Omnicodes.
  • An omnicode connects an object to a unique digital object in UDR.
  • the API of the unique digital object may enable actions on the linked object.
  • Object associations for example which books belong on this shelf; which objects belong in the same kit; etc., are implicit in human behavior.
  • Omnicodes make it possible to define these connections explicitly, e.g. by scanning codes and defining sets or associations. Interaction with an information object through Omnicodes.
  • a human user man interact with an information object, which is presented using an Outlet on a user interface, through a machine-readable code.
  • Such an interaction may include consent to information presented, verification of information presented, and so on.
  • Creating and managing inventories of physical objects and devices using Omnicodes When every physical object of a given collection of objects presents an Omnicode, the entire collection is mirrored in unique digital reality. It thus becomes possible to create and manage inventories of physical and digital objects.
  • Embodiments of the invention specifically designed to address drivers of Digital Fragmentation Part of the process of digital consolidation necessarily involves addressing the drivers of digital fragmentation mentioned above. • Data Hoarding will be naturally addressed by the overwhelming benefits of horizontal digital consolidation. Horizontal digital consolidation will necessarily increase the democratization of AI because small and medium-size players who are not the great data hoarders will be able to rent huge datasets to train their AI or buy / rent AI models already trained on huge datasets.
  • NTDs Next Generation Documents
  • unique digital objects whose payload is a PDF digital document augmented with additional key-value properties that exposes some of the information on the PDF in machine-readable format.
  • the properties can identify by unique identity identifier individuals mentioned in the PDF, such as contract parties or property owners; key numbers mentioned such as monthly rent, sale amount, etc.; geographic location; and cross-reference, using universal identifiers, other unique digital objects including other NGDs. Any presentation of an NGDs on a user interface (screen or paper) clearly displays a machine-readable code with the universal identifier of the underlying unique digital object, and a visually recognizable symbol that evokes the fact that underlying the presented digital document there is rich functionality and verifiability guarantee which are substantially different to those of regular digital documents.
  • the machine-readable codes can be used for multiple purposes, including uniquely identifying a hard copy (such as identifying the printing individual and time of the printing event); connecting two documents (for example, marking document B as appendix to document A, or as a version of document A, etc.); signing / granting consent to the contents of the document; executing verification scripts; tracking copies of a sensitive document; etc.
  • Artificial Digital Friction Embodiments of the invention teach a method and apparatus for injection of human signature rights into an automatic system for the purpose of: (i) gradual adoption of UDR based paperless, and automatic systems; (ii) gradual adoption AI systems; and (iii) cyber security. Human signature rights are injected at crucial decision junctions in systems that could have otherwise performed fully automatically.
  • the Concept of Friction The Concept of Friction.
  • An embodiment of the invention injects artificial friction (in the form of human veto rights and artificially introduced human approval stages) to bureaucratic processes that could otherwise become fully automated by transitioning from document-based human-based processes to Next Generation Documents and unique digital object-based processes, which are automates by the use of SICCL and other methods taught herein. Examples for such processes are loan application verification in banks; insurance claims processing at insurance companies; financial auditing; advertisement campaign strategy; government bureaucratic processes, and so on. In each of these processes, human veto rights can be easily injected and a human confirmation may be required at different stages along the other automatic process.
  • Figure 52 describes an example of injection of artificial friction into a process that has been digitally transformed and automated using UDR: for example, in a process based on documents in hybrid digital-document shared reality, an application form 5201 has to be filled and properly signed by the applicant 5202, before being reviewed by an approving manager 5203.
  • an application form 5201 has to be filled and properly signed by the applicant 5202, before being reviewed by an approving manager 5203.
  • the applicant grants the form access to personal information on UDR, allowing the form to be filled automatically.
  • the user may then sign the form in a verifiable interaction with a user interface, as taught above.
  • a SICCL or similar script 5204 may be used to verify correctness and compliance of the form automatically – eliminating the need for intervention by the approving manager 5203.
  • FIG. 53 shows artificial friction for cyber-security using an air-gapped apparatus: an automated process running UDR software protocols 5301 will trigger a control decision in a controller 5305. For example, verification of a set of consistency and compliance conditions might trigger a wire transfer of funds to a third party.
  • a method comprising: creating an interface for human interaction at one or more decision junctions of an automated system; wherein oversight of the automated system is provided through the interface for a person that is replaced or displaced by the automated system. 2.
  • creating the interface includes injection of human signature rights for the person, and wherein the oversight of the automated system requires receipt of an authorized signature by the person through the interface.
  • the oversight of the automated system is provided for gradual adoption of the automated system.
  • the oversight of the automated system is provided for gradual adoption of an artificial intelligence (AI) system.
  • AI artificial intelligence
  • the method of embodiment 2 is provided for cyber security. 6.
  • An embodiment of the invention addresses one of the primary user-interface operations that disturb the vertical information flow: the popular “copy-paste” operation.
  • a copy-paste operation marks digital information from one application and lands a copy of that information in a different location or document edited by the same application, or in a different application altogether.
  • a “copy-paste” operation interrupts the provenance trail and audit trails, as the pasted information is disconnected from its origin.
  • application extensions and plugins implement extended functionality that allows word processors, spreadsheets, presentation editors, and rich HTML email composers to embed UDR objects.
  • the application holds an additional content layer that notes the universal identifier of the UDR objects, such as numbers, tables, photos, text, and other content, embedded in the document, presentation, or spreadsheet.
  • the plugins extend the functionality of standard copy and paste operations such that when an embedded UDR object is copied, the clipboard notes the unique identifier of the object copied and, on performing the paste operation, it is embedded again as a UDR object. This preserves the data provenance of UDR objects across multiple documents.
  • NGD Next Generation Document
  • the contract rent amount just like all other information in the Next Generation Document, is immutable.
  • An NGD document reader may implement the extended “copy” operation described above, so that when the rent amount is selected in the reader and “copy” is pressed, the information copied to the clipboard contains not just the rent amount devoid of any context, but also the unique identifier of the NGD (as a unique digital object) and the specific key of the field “rent” that was copied.
  • the receiving application may note that extra information in the clipboard and retain the fact that the number pasted is the “rent” field of the specified unique digital object, preserving the provenance trail.
  • Embodiments of the present invention teach a method to make verifiable Hyper Text Transfer Protocol (HTTP) queries, namely, HTTP queries that are witnessed in a way that allows the query maker to prove, later, that the server had indeed returned the response as documented.
  • HTTP Hyper Text Transfer Protocol
  • Websites as they appear on browsers, have become facts to be contended with. More specifically, facts that a Web server returns in response to a specific query could be inadvertently accepted as authentic and could even appear in newspaper headlines. Examples are: • A story that appears on an online Web page • A recommendation made to a customer on an e-commerce website • An item that was shared in social media and then deleted • A hacked Web page that returned altered content as set by the hacker • And so on.
  • a UDR-enabled web proxy can be placed in-line between an HTTP client and Web HTTP servers.
  • the proxy intercepts the request and passes it to the corresponding server.
  • the server returns the query response to the proxy, which passes the response to the client and generates a fact identifying the time and content of the response.
  • a parallel HTTP witness duplicates a client’s HTTP requests and records the server responses as certified facts.
  • Verifiable SQL queries This embodiment of the invention teaches a method to run verifiable Standard Query Language (SQL) queries, giving the database owner and any recipient of the query results the ability to prove, conclusively and verifiably, that the SQL database did indeed return the specified results for the specified query at the specified time.
  • SQL Standard Query Language
  • Most production data are stored today in relational databases. Banks, hospitals, government offices, and insurance companies all hold data this way.
  • These authorities, agencies, and entities produce paper documents with the results of Structured Query Language (SQL) queries to represent the state of the database and, more specifically, the results of a specific query.
  • SQL Structured Query Language
  • the customer is given a piece of paper with printed information, which is the result of an SQL query, thus degrading the information quality from digital to bitmap.
  • a SQL witness (or proxy) operates in parallel to a SQL client and server.
  • the client sends a request to the server
  • the client also sends the request to the SQL witness to likewise query the server.
  • the witness stores the server’s response to the request as a UDR fact.
  • Figure 54 shows a method for verifiable SQL requests using an SQL witness service: SQL client 5401 makes an SQL request 5402 to SQL server 5403.
  • the client also sends an identical request 5402 along with server login credentials 5405 to an SQL witness 5408, which is a special-purpose server designed to allow verifiable SQL requests.
  • the SQL witness 5408 uses the login credentials 5405 to send a request 5406, identical to request 5402, to the SQL server 5403.
  • the server responds to both requests – the client 5401 receives a response 5411 and the witness receives a response 5407.
  • the witness creates a new unique digital object in UDR 5410, whose payload consists of information 5409 sent by the witness to UDR, namely, the request 5406 it made to the server and the response 5407 it received. This allows the client to make the verifiable claim that the request 5402 received the claimed response 5411.
  • the witness instead acts as an SQL proxy server: instead of communicating the request to the server directly, the client only sends it to the proxy.
  • the proxy (which acts as a witness) relays the request to the server, records the request and the response in UDR, and returns the response to the client.
  • any version of a spreadsheet can be recorded in immutable form as a unique digital object in UDR, where the API of the spreadsheet unique digital object allows read-only access to individual cells of the spreadsheet.
  • An application extension on top of the spreadsheet editor adds an additional layer of content on top of every spreadsheet.
  • the additional layer contains a relationship graph of dependencies between all populated cells, noting which cell is calculated from which cell.
  • the plugin colors the origin cells – cells that contain typed-in values and information.
  • the plugin also allows embedding UDR objects (primarily, numbers) in the spreadsheet and enumerating the totality of the origin numbers and values that were typed in and embedded as UDR objects. For auditing the spreadsheet, the plugin marks audited cells and unaudited cells.
  • Embodiments of the invention teach a method for efficient validation and verification of entire spreadsheets. Combining with provenance-preservation methods (see Preservation of Data Provenance Across Applications), the method allows to efficiently locate the source of the errors across multiple spreadsheets and other sources of information, and to publish the results of spreadsheet calculations (numbers, tables, and figures) as UDR objects in a manner that is verifiable and transparent.
  • Figure 55 is an illustration of spreadsheet software plugin turning specific cells in a spreadsheet into verifiable unique digital objects that may be embedded in other documents while maintaining audit trail.
  • Figure 56 shows a financial report document that contain machine-readable and human- readable unique identifiers of unique digital objects, whose payload is a verifiable spreadsheet where numbers in the report were computed: document 5601 is a unique digital object presenting a unique identifier 5602. It is a financial report containing “bottom- line” numbers produced by spreadsheet 5603, which it turn depends on numbers produced by spreadsheet 5604. Using the methods described herein, both spreadsheets 5603 and 5604 are recorded as unique digital objects in UDR, and a hidden layer in the spreadsheet records the unique identifiers of numbers that were copy-pasted into cells in the spreadsheet.
  • Spreadsheet 5604 contains some cells whose content is unverified; they are marked in red.
  • all cells in spreadsheet 5603 whose content depends on the “red” cells, are automatically marked red. All numbers in the report 5601, which depend on “red” cells, are also marked in red. As a result, information consumer has visual signal on the trustworthiness of specific numbers shown numbers that rely, directly or indirectly, on unverified numbers, in any spreadsheet along the computation chain, will be clearly and visibly marked.
  • a method for preserving data provenance across an application comprising: adding a layer of content on top of a spreadsheet application that includes a plurality of cells, wherein the layer of content includes a relationship graph of dependencies between all populated cells, wherein the relationship graph notes which of the populated cells is calculated from other cells; and establishing a plugin for the spreadsheet; wherein the plugin identifies origin cells of the plurality of cells, wherein the origin cells contain any of typed-in values or information; wherein the plugin allows embedding UDR objects in the spreadsheet; and wherein the plugin allows enumerating the totality of origin numbers and values that are typed-in and embedded as UDR objects. 2. The method of embodiment 1, wherein the embedded UDR objects are numbers. 3.
  • Verifiable HTTP queries namely HTTP queries that are witnessed in a way that allows the query maker to prove, later, that the server had indeed returned the response as documented.
  • Websites as they appear on browsers, have become facts to be contended with. More specifically, facts that a Web server returns in response to a specific query could be inadvertently accepted as authentic and could even appear in newspaper headlines. Examples include: • A story that appears on an online Web page; • A recommendation made to a customer on an e-commerce website; • An item that was shared in social media and then deleted; • A hacked web page that returned altered content as set by the hacker; • And so on.
  • a UDR-enabled Web proxy can be placed in-line between an HTTP client and Web HTTP servers.
  • the proxy intercepts the request and passes it to the corresponding server.
  • the server returns the query response to the proxy, which passes the response to the client and generates a fact identifying the time and content of the response.
  • Figure 57 shows an implementation of the method of verifiable HTTP Query using a UDR-enabled HTTP proxy: HTTP client 5701 would like to make an HTTP request 5702 to HTTP server 5705.
  • UDR-enabled HTTP proxy 5703 which, acting as a standard HTTP proxy, forwards the request 5702 as a new request 5704 to server 5705, and obtains a response 5706 from the server. The response is then returned to the client 5701 (not shown in the figure).
  • the UDR-enabled proxy then sends the request and response to UDR 5708, creating a unique digital object whose payload includes the contents of the information 5707 sent to UDR.
  • the UDR-enabled proxy 5703 may cryptographically sign the request and response to ensure they are not tempered with, or otherwise uses a secure socket layer (SSL) in its communication with the HTTP server 5705.
  • SSL secure socket layer
  • a parallel HTTP witness duplicates a client’s HTTP requests and records the server responses as certified facts.
  • Figure 58 shows verifiable HTTP request using an HTTP witness service, which, analogous to the protocol described in Figure 54, does not act as proxy but rather sends a request of its own to the server, in parallel with the client’s direct request to the server, and records the response returned by the server.
  • Ownership over digital media items Embodiments of the inventions disclosed herein, including unique digital objects, Unique Digital Reality and its embodiment using enduring network interfaces, presentation of information on user interfaces, Outlets, etc., establish the notion that a digital asset can exist as a unique, permanent digital object that is separate from any of its presentations or user-interface rendering. This enables to establish ownership over digital assets.
  • digital media items such as photographs, images, audio tracks, music, artwork, video, etc.
  • they are imported into user interfaces using their universal identifiers, such that the user interface invokes an API call to embed the item, while presenting its universal identifier, such establishing ownership, and no local files are stored.
  • the digital media file can contain hidden properties, which do not alter its appearance or the user experience gained from it, or alter it subtly and imperceptibly, but which can be used to assert ownership.
  • hidden properties can include the universal identifier of the underlying unique digital object, or the permanent address of the unique digital object; a digital signature establishing ownership; and so on.
  • the hidden property can be inserted in into the media in an unobtrusive way. For image, audio or video, a watermark that does not have a perceptible impact can be inserted, which is machine-readable. If a file is created, the file header and further contain hidden properties. Each of these can be used to ascertain ownership. The location of the hidden property may be undisclosed, so that it is not tampered with. Consider for example the case of an image. The image owner chooses randomly location of a few pixels and changes them to contain a code.
  • FIG. 59 describes a method for UDR-based ownership over media items.
  • Figure 60 shows an illustrative timeline for a UDR-enabled media asset, by which the creation, modification, ownership, sale, or transfer of the UDR-enabled media asset is readily accessed.
  • Example Embodiments 1 A method for establishing or tracking ownership of a media asset over a network, the method comprising: embedding a property with the media asset; and interacting with an external device over the network with the embedded property to establish one or more aspects regarding ownership of the media asset. 2.
  • the embedded property is an embedded matrix barcode, e.g. a QR code. 3.
  • the method of embodiment 1, wherein the embedded property is an embedded watermark. 4.
  • the method of embodiment 1, wherein the embedded property is a UDR property, and wherein the external device is a UDR device. 5.
  • the method of embodiment 1, wherein the media asset is a photograph. 6.
  • the method of embodiment 5, wherein the embedded property is embedded within the photograph. 7.
  • the method of embodiment 1, wherein the media asset is a video asset. 8.
  • the method of embodiment 7, wherein the embedded property is embedded within the video asset.
  • the method of embodiment 1, wherein the media asset is an audio asset. 10.
  • the method of embodiment 9, wherein the embedded property is embedded within the audio asset.
  • the method of embodiment 1, wherein the media asset is artwork. 12.
  • the interacting establishes the original owner of the media asset.
  • the method of embodiment 1, wherein the interacting establishes the current owner of the media asset.
  • the method of embodiment 16, wherein the event includes any of a sale, a transfer, or a licensing of the media asset.
  • the method of embodiment 16, wherein the event includes a transfer of value associated with the media asset.
  • the method of embodiment 18, wherein the transfer of value comprises a payment associated with the media asset. 20.
  • an email-to-UDR service can offer a service such that every attachment sent in an email to specify addresses becomes the payload of a unique digital object and is thus committed as a fact in UDR.
  • a UDR-enabled email server receiving Post Office Protocol -3 (POP3) requests, or possibly other email protocol requests, creates a unique digital object out of any email it receives.
  • POP3 Post Office Protocol -3
  • Access control to the server may be achieved by requiring that emails be digitally signed in such a way that, for example, the email header specifies a unique identifier of an identity unique digital object, and the email attachment be digitally signed by a key corresponding to a public RSA key published at that identity object.
  • Certification of Facts Using Mobile Computing Devices Mobile computing devices (such as smartphones and tablets) are extremely common measurement devices. Measurements that they take, such as photos, videos, location measurements and biometric measurements can be recorded as unique digital objects in UDR using a special app or a native function of the mobile device operating system. In an embodiment of the invention, certain smartphone applications submit data they measure (such as camera images) as unique digital objects in UDR. This allows the application to create verifiable data logs.
  • a “legacy-to-UDR” service creates a unique digital object for each record in each public and government database, turning legacy databases into collection of unique digital objects. As a result, all these records become permanently available through a uniform software interface.
  • the alternative file management user interface system is based on information consistency and compliance, rather than on files and folders, and specifically, around the notion of requirement satisfaction.
  • the user interface manages semantic requirement statements. For example, a statement may be “I need to have a valid driver’s license”, or “I need to have all my salary slips from the year 2020”, or “we need to have all receipts from all employee business trips of 9/2020”, or “we need to have a non-disclosure agreements signed by any vendor we work with” ; these may be expressed in natural language or in a machine-readable language such as SICCL.
  • the system indexes available unique digital objects of a user based on which requirements they satisfy, rather than by managing local (or cloud) files and folders.
  • the system allows the user to define new requirements, and browse existing requirements, and from each requirement, access and browse those unique digital objects that satisfy it.
  • Shared Virtual Worlds and Augmented Reality Worlds based on Unique Digital Reality A shared augmented reality world adds a new shared layer of reality on top of physical reality; a shared virtual world is a new layer of shared reality. Both depend on the existence of a layer of permanent unique digital objects.
  • a single entity may manage a given virtual universe and maintain the underlying collection of permanent digital objects; however a digitally consolidated shared augmented reality or shared virtual reality is not managed by a single entity – it enables arm’s length counterparties to interact on the same shared reality.
  • Such a consolidated shared augmented reality or shared virtual reality requires a UDR: objects, states, and events in the shared augmented or virtual reality are unique, enduring, and universally accessible.
  • a UDR makes it possible to build shared augmented or virtual realities that are digitally consolidated – are available to different stakeholders at arm’s length, instead of being owned and managed by a single entity.
  • An augmented reality interface to physical objects mirrored in Unique Digital Reality Augmented reality makes it possible to create new interfaces for human interaction with physical objects. We have already discussed adding an Omnicode to a physical object without physically adding the omnicode, but rather by adding the code on a layer of shared augmented reality.
  • the unique digital object When a unique digital object mirrors a physical object, the unique digital object may expose a user interface on a layer of augmented reality.
  • a physical object, or a digital object presented on a user interface present a machine-readable code, in an embodiment of the invention, a new layer of content associated with the physical object, and a new layer of interactions with the physical objects, become possible.
  • an augmented reality device when an augmented reality device uniquely recognizes a location or an object (for example, using GPS location or a machine-readable code on a physical or digital object) it may present, through a user interface, any of the following: • Identities of persons who have interacted with the objects – by leaving a comment, owning it, or renting it in the past • Identities of other objects associated with it • Additional information regarding the object (user manuals, repair, and service history, etc.) • Objects in legal and financial reality associated with it (for example, contracts, liens, etc.) Examples: • The restaurant menu becomes available on Augmented reality to visitors of a restaurant. • Car information (stored on UDR) becomes available to users in or around the car.
  • the unique digital object may expose a user interface (in addition to its API) that specifies its behaviors, actions, and reactions on augmented reality.
  • Shared augmented reality and shared virtual reality require, by definition, a layer of shared digital objects – a unique digital reality.
  • Embodiments of the invention disclosed herein are fundamental to creation of permanent, unique digital objects and therefore fundamental to creation of shared augmented reality and shared virtual reality. Uses of embodiments of the invention in shared virtual reality Virtual reality consists of identities of agents, description of scenery and location of virtual objects.
  • a shared virtual reality which is managed by several (or many) stakeholders, instead of by a single entity, necessarily requires a purely digital consensus over a large collection of unique digital objects.
  • Unique Digital Reality thus enables shared virtual reality. Identities of agents in the virtual world, ownership over objects and locations, identities of objects and so on – can all be stored as unique digital objects; all objects, states and events in the shared virtual reality can be stored as unique digital objects. Certified Internationally Recognized Medical Records Shortcomings of the hybrid digital-document shared information reality were discussed elsewhere in this text. The Covid-19 global pandemic brought to light some of these shortcomings in a visceral way.
  • QR code requirement is simple: the association of a physical or digital document is associated with a website serves as an added safety element to ensure document validity – in theory at least.
  • the rationale is to provide an alternative form of digital signature of a document: in principle, if the owner of a domain provides a URL in that domain, which confirms the content of a document, then the owner has effectively blessed or signed the document.
  • a unique digital object in UDR can explicitly cite the identity of the person carrying the record, the identity of the entity which produced the record, and full details of the medical procedure or test reported.
  • the unique digital object is not a document, rather an immutable permanently accessible piece of information.
  • the record may be presented on a user interface (smartphone screen or physical paper, for example) while providing cryptographic guarantees for the authenticity of the presentation and its link to the committed, immutable unique digital object.
  • a method for creating verifiable, internationally recognized medical comprising: a) recording cell tower data received from a plurality of cell towers at a mobile device; 2. uploading the recorded cell tower data from the mobile device to the UDR system as encrypted data; 3.
  • Certifiable real estate ownership and transactions An embodiment of the invention enables certifiable, trustworthy, and automatically verifiable real-estate ownership and transactions. Five protocols are taught herein: • A protocol for establishing initial ownership of a property, the exact dimensions and location of the property, and the identity of the current owner. • A protocol for verifying that the exact dimensions and the location of the property as appear in UDR entry, match those. • A protocol for verifying the identity of the current owner.
  • the second phase of asserting initial ownership is to establish the identity of the current residents.
  • Embodiments of the invention teach the use of identity mechanisms (see Certification of Identity) to conclusively assert the identity of the primary owner.
  • facts are entered into UDR to assert the identity of the resident of the property by showing photographs of them, taken over time, in the position specified on the map, with the camera’s location and direction specified on the map.
  • Facial recognition technology enables asserting that the same people are photographed over time in different places on the property. Real estate transactions.
  • Embodiments of the invention teach a method for using UDR to record real-estate transactions, in which the universal identifier of the property is specified in a sales, rent, or mortgage contract, which is itself a Next Generation Document.
  • the system therefore allows the current owner to trace the ownership line back to the initial owner who submitted the property into the system.
  • An embodiment: Smartphone real estate application In an embodiment of the invention, a smartphone application makes use of smartphone sensors like a camera to capture photographs or videos, or sensors that take measurements, discover locations, and so on, the output of which can be used to assert ownership.
  • algorithms implemented in software by service providers implement 3D reconstruction methods for creating an exact property dimension plot from the information measured by the smartphone.
  • the invention s algorithms can receive the measurement information and verify that the measured property plot agrees with previously claimed property.
  • the present embodiment of the invention teaches a method and apparatus for running verifiable software tests, namely, software tests whose successful completion can be conclusively proved to third parties at any time later after their actual execution.
  • verifiable software tests namely, software tests whose successful completion can be conclusively proved to third parties at any time later after their actual execution.
  • An embodiment of the invention teaches a method and apparatus for creating UDR objects that correspond to an event of machine code execution for the purpose of verifiable software testing.
  • An embodiment of the invention teaches a method and apparatus for creating UDR objects that correspond to an event of machine code execution for the purpose of verifiable software testing.
  • the ability to conclusively factify the event of code execution becomes increasingly important, namely, enabling the party executing the code to conclusively prove, at a later point in time, that a particular computer program ran against specific inputs and produced specific outputs.
  • the following are instances of computer programs whose execution requires verifiable execution that should later enable verification, by a third party whose identity is unknown at time of execution of the software test. • Proving that software has been tested.
  • Mission critical software systems undergo software testing.
  • a software manufacturer is interested in being able to prove to a third party (such as a regulator), at any later point in time, that adequate and reasonable testing has been performed prior to the release of a mission-critical software system. This may be important to be able and ready to respond to negligence claims in the event of a software malfunction.
  • Proving priority of a software feature Software manufacturers face intellectual property lawsuits claiming infringement of software patents.
  • a software manufacturer may be interested in proving that a certain software feature existed (it was implemented and tested) before a certain date (such as the competitor’s patent submission date). • Proving that an AI system is fair and non-discriminating.
  • Autonomous vehicles are based on a collection of interconnected sophisticated AI systems. These AI systems are black boxes – it’s very hard or even impossible to interpret why a certain decision was made by the system.
  • governments will start regulating the AI industry and will formulate safety standards for such software, and demand that manufacturers prove to the regulator that the autonomous vehicle system conforms to standards. Because this is all a software operation, interaction with the regulator will necessarily involve verifiable code execution.
  • the software manufacturer is exposed to both civil and criminal lawsuits.
  • Embodiments of the invention teach a system based on UDR (see Verifiable Code Execution) that is fully responsive to these concerns.
  • UDR Verifiable Code Execution
  • Financial models and stress tests Financial institutions must comply to Value At Risk (VAR) requirements. These are based on stress tests and simulations. These institutions would like to represent to regulators that stress tests have been accurately performed and that VAR requirements are satisfied.
  • VAR Value At Risk
  • Credit risk systems Banks use AI systems to make credit decisions.
  • An embodiment of the invention makes it possible to create a unique identity, user interface (UI) and application programming interface for every physical object and device.
  • the unique identity allows one to maintain an inventory of household, office, or vehicle items (for example, for property insurance purposes, company inventory management, etc.
  • the UI allows, for example, inspection of object authenticity for artwork and hand made products; explicit transfer of ownership over the item; inspection of various pieces of information (such as material composition, manufacturing date, identity of manufacturer, specification of Quality Assurance procedures); and inspection of service and guarantee contracts; inspection of user manuals; and item recall procedures.
  • Physical items and objects that can be assigned a unique identity, UI and API using this embodiment of the invention include, for example: • Manufactured items and physical objects – such as household items, furniture pieces, mattresses, plumbing units, doors, rugs • Artwork and other handmade items and objects • Electronic and digital devices • Electronic appliances • Real estate parcels • Vehicles And more. Technical Description As part of production, manufacturing, or acquisition, every item or object is assigned a unique digital object in UDR, owned by the same owner as the physical object.
  • the payload of unique digital objects includes a detailed description of the physical objects (such as: serial number printed on the object; exact 3D scanning of the object and 3D measurement of the object; catalogue number of the object; picture of the object taken during manufacturing; identifying information hidden in or on the object; CAD drawing or plan; etc.). If the object or device has a machine or human-readable unique identifier visible, the payload will note this. For devices, the payload may also include public cryptographic key installed in the object hardware; version of software installed. For objects with inner components, the unique digital object may include a list of components (including unique identifiers, if they themselves have a corresponding unique digital object).
  • Figure 61 shows examples of physical object and devices and their mirror unique digital objects in UDR. Object recognition.
  • Optical sensors infrared sensors, cameras, Light Detection and Ranging (LiDAR) devices and Augmented Reality (AR) devices are able to detect an object that has a mirroring unique digital object in UDR, when it enters their field of view, based on the payload of the mirroring unique digital object.
  • LiDAR Light Detection and Ranging
  • AR Augmented Reality
  • UDR Universal User Interface
  • the unique digital object exposes an API that allows a user with access credentials to perform software operations on the digital object. It also exposes a user interface (UI) at the unique permanent URL allocated for the unique digital object.
  • Figure 62 shows a physical object and its user interface, available through its unique digital object twin.
  • Connections between unique digital objects are permanent, machine readable and explicit, as one unique digital object may refer to, or cite, a second unique digital object by citing the unique identifier of the second unique digital object.
  • connections between physical objects or devices which are of course implicit in physical reality, are made explicit as connections between the unique digital objects mirroring them.
  • the unique digital objects mirroring all artwork of a specific artist may all create an interconnected network of unique digital objects.
  • Figure 63 shows two related physical objects (for example, artwork by the same artist), and a connection between their mirroring unique digital objects.
  • a user may direct an internet browser at the URL and access a UI for the object.
  • the same UI may in certain embodiments be accessed also through an Augmented Reality (AR) system that identifies the object or item in the scene viewed by an AR device (such as a smartphone, AR glasses, or AR goggles) and overlays the UI in the AR viewport next to the item or object.
  • AR Augmented Reality
  • Figure 64 shows a physical device and its user interface as it is accessed through various AR-enabled devices.
  • the AR-enabled device will recognize the object or device when it enters its field of view and present the user interface next to the object or device in the AR field of view.
  • the following information related to physical objects and devices may be recorded as UDR objects: - User interactions with the device physical user interface (if it has one) - User interactions with the device UI exposes by the unique digital object associated with the device - device-device interactions, such as Bluetooth handshake - computations involving the object or device - documents associated with the object or device (such as legal transfer of ownership, sales document, user manual or service contract). - Data measured by the device (such as temperature measured by an IoT device with temperature sensor, or geo location measured by a device with GPS). Inventory of parts.
  • a unique digital object mirroring a composite object namely an object that consists of a multiplicity of inner parts, lists those inner parts.
  • Inner parts also have a mirror unique digital object in UDR, they will be listed in the payload of the unique digital object mirroring the composite object.
  • the unique digital object mirroring an object or device is related in UDR to the unique digital document objects (or Next Generation Documents) of e.g. its sale contract, insurance policies, user’s manual, service agreements, certificate of guarantee, service, and maintenance history, and so on.
  • This maintains an orderly collection of documents that is accessible by scanning the machine-readable identifier on the object or using an AR interface to access its user interface, which will then show all documents and other information objects related to that physical object. Inventory of objects.
  • An embodiment of the invention enables ownership registry of physical objects and devices. Unique digital objects have a native mechanism for ownership; and so, by transferring ownership of the mirroring unique digital objects, it is possible to keep explicit track of ownership of physical objects, items, and devices.
  • Supply chain monitoring, logistics, and recall procedures tracking an item from production to customer.
  • manufacturers may choose to create unique digital objects by default to mirror each individual object they manufacture.
  • the mirror object may act as a “digital twin” during production, relating the manufacturing process to information technology (IT) systems of the manufacturer, tracking production stages, lot numbers of materials used in the production of each individual object, quality assurance (QA) procedures and tests, external laboratory tests, and so on.
  • IT information technology
  • QA quality assurance
  • the same unique digital item may be used to track stock- related logistics such as warehouse storage, shipment and delivery, retail stock, up to the point of sale.
  • the same unique digital object may be used to track user satisfaction, execute recall procedures, etc.
  • Digital devices and electric appliances with no control panel or factory user interface.
  • This embodiment of the invention levels the playing field for user interface digital devices and electric appliances. Since any object or device may have a user interface, accessible using an AR-enabled device, a smartphone, etc., digital devices and appliances may be manufactured without a control panel or factory-made user interface: all their user interactions may occur through the uniform user interface disclosed herein. Bulk software processing of device sensor measurement and user interactions. Under the present state-of-the-art, sensor measurements of individual devices are fragmented and siloed, remaining inaccessible for bulk processing. Similarly, as each device has its own user interface, a user has no way to track, monitor or bulk-process his or her interactions with the dozens or hundreds of user-interfaces surrounding us at all times.
  • An embodiment of the invention records all sensor measurements by devices with a mirroring unique digital object, as well as all user interface interactions, in unique digital objects related to the mirroring digital object. This makes it possible to mine, analyze, and bulk- process all measurements and user interactions using software processes that interact with UDR.
  • Figure 65 shows a schematic representation of bulk processing and data mining of all measurements and user interactions related to mirroring unique digital objects, which may later be reflected on their universal user interfaces. Unambiguous presentation of images of physical objects. In an embodiment of the invention, images of physical objects may present the unique identifier of the unique digital object mirroring the physical object, allowing for unambiguous reference to a specific physical object.
  • Figure 66 shows a unique digital object mirroring a physical object, and images of the physical object presenting its unique identifier.
  • FIG. 67 shows the connections enabled by this embodiment of the invention between physical objects (documents, objects, and devices), their mirroring unique digital objects in UDR, the data measured by them, and user interactions with them. All these are represented in unique digital objects available for software processing over the API of these unique digital objects; results of this processing may then appear in the universal user interface of these objects.
  • Figure 68 illustrates the merits of the described embodiment for devices (bottom) objects (middle) and documents (top). All three categories have universal user interfaces.
  • PDF Portable Document Format
  • the PDF was designed for cross-platform uniform document appearance, namely, as a way to represent a digital replica of a document visual appearance in digital media. It was designed for printers and later adapted for on-screen document visualization – both before the Internet era.
  • the three main roles of a document are: 1. Medium for information transfer: A document contains information that can be deciphered by a document recipient. 2. Medium for user interaction and chain of consent: A document is an interaction surface, namely, an interface where interaction occurs between a human user and the document medium. This interface is naturally two-way: the human user reads the document on the one hand and performs document interactions on the other hands.
  • Document interactions include, among others: signature, approval, comment, form-filling, version update, sharing/sending the document, moving the document between stakeholders participating in a procedural workflow, and inspection of document authenticity, validity, and reliability 3.
  • a document is a means for achieving lasting consensus between document presenter and document receiver regarding objects, states, and events in different layers of reality – including physical, financial, and legal reality. This interaction can occur across time and space. For example, the person producing a document can be long deceased when their document is exchanged between third parties to achieve a consensus between those third parties.
  • the hardcopy (physical) document allows human users to perform all three tasks manually: information transfer occurs through reading; user interaction and chain of consent occurs through blue-ink signature and mail transfer of documents; trust and enduring fact verifiability occurs by long-standing practices of document and signature authenticity verification (e.g. forensic procedures for verification of authenticity of a passport, a birth certificate, a bank payment order, a blue-ink signature, etc.). It is more than reasonable to expect that a “digital document” medium, however implemented, would support digital (automated) implementation of these three key roles, rather than manual implementation.
  • a PDF is not a digital medium for user interaction and chain of consent.
  • a PDF is one-way, meaning, it only allows the human user to read document content. Interaction in the other direction – user interaction with the document – was never included in PDF original design, as indeed it was primarily designed to support hardcopy printing. As the PDF became ubiquitous, workarounds were created.
  • the PDF format, and PDF readers, have been extended to allow certain kinds of user interaction, such as form-filling, adding comments and annotations, and adding digital signatures.
  • document-external platforms to share the document, one attaches it to an email or stores it in cloud folders; filesharing services such as Dropbox allow document versioning; services such as DocuSign and Adobe Sign allow user signature and support certain kinds of document workflow; and so on.
  • filesharing services such as Dropbox allow document versioning
  • services such as DocuSign and Adobe Sign allow user signature and support certain kinds of document workflow; and so on.
  • DocuSign and Adobe Sign allow user signature and support certain kinds of document workflow
  • a physical (original) document is a unique, permanent, permanently accessibly, verifiable medium;
  • Hardcopy documents have several additional important properties, including privacy, security, stability, ownership, permanence, uniqueness.
  • a hardcopy can be kept private and secure: Access control is achieved using a locked document cabinet or document safe. 1.
  • the PDF was not designed with document security and privacy considerations in mind. It was designed to be a faithful digital representation of document appearance. PDF access control is currently achieved using PDF password - a single password that unlocks document encryption – or using access control to document storage platforms.
  • DX Document Experience
  • the DX of a PDF on desktop, the DX of a PDF on smartphone, the DX of a printed hardcopy, and the DX of a document presented on a digital billboard (say) are all markedly different.
  • a certain signature modality e.g. scribble with a finger on a cashier tablet
  • PDF documents are not really digital: they have neither a user interface (buttons and functionality) nor Application Programming Interface (API for machine access).
  • API Application Programming Interface
  • the PDF is quite literally a “digital brick” that predates the Internet.
  • Figure 69 shows a typical document exchange using current state-of-the-art: PDF documents, e-mail, instant messaging, cloud sharing services, e-signing services, and so on.
  • Figure 70 shows the aftermath of the process described in Figure 69: the applications and platforms used, and the copies left in various systems.
  • Digital Documents - Prior Art One prevailing approach to the challenges described above has so far focused on adding more and more document-external platform and systems. For example, to support digital- only document signatures, document-external platforms such a DocuSign have been introduced; to support workflow automation, document-external platforms such as Adobe Sign have been introduced; to support document storage and sharing cloud storage systems such as Dropbox, Box and Google Drive have been introduced; and so on. These platforms and systems all revolve around the existing PDF document format.
  • DMS Document Management Systems
  • IDR Intelligent Document Recognition
  • this medium must be fully digital and machine-readable, and support a fully digitally transformed world; yet on the other hand, it must be backward- compatible, legally binding, and provide extension (rather than abrupt replacement) of the existing PDF and physical-hardcopy document experience.
  • different methods and elements taught above – such as Unique Digital Reality and unique digital objects, verifiable interactions, universal user interface, Verifiable Code Execution, Outlets and Twins, and many others - come together to enable exactly that.
  • the embodiment of the invention we now turn to constitutes a disruptive evolution in the document medium itself.
  • NGD Next Generation Digital Document
  • a NDG is a document medium, or a document format, that includes at least: • A unique document identifier • Instructions for rendering the document in human-readable format • Key Document Information in machine-readable form
  • Figure 71 shows a schematic view of a possible appearance of an NGD, with its various features and properties.
  • the NGD is implemented as a unique digital object whose payload contains both the human-readable format and the Key Document Information in machine-readable form.
  • the NGD also includes a user interface that allows document readers to interact with the document and perform actions - such as document sharing, access control, access log review, signature, signature request, and verification – from the document itself, without “dragging” the document to an exo- document system.
  • the NGD also includes a “timeline” of all document history – for example, version updates, signature request and signature events, attachment events, access events, and so on. Infrastructure. The method and apparatus taught herein uses a Unique Digital Reality. Specifically, each NGD is a unique digital object. In a possible embodiment, NGD unique digital objects are enduring network interfaces.
  • Document Semantic Type and Document Key Information is a collection of information pieces contained in a document, which have key importance. These pieces of information may be textual or numerical, or may be identity of individuals, things, or other documents. For example, in a real estate lease contract, key information may include identity of property owner, identity of the property being leased, lease amount and payment dates, lease start and end date, penalty for late lease payment, citation of a related document (such as an appendix, a property title, or a previous contract) and so on.
  • key information may include invoice number, invoice date, customer identity, vendor identity, identity and quantity of goods or services sold, payment due date, taxes collected and so on.
  • Document semantic type is a definition of the type of the document (for example, a lease contract; a personal income tax return form with specific number; or a specific type of declaration; etc.).
  • the software producing the document (such as a word processor, an invoice generator, and so on) always has access to Document Key Information in digital form.
  • document creating software creates a PDF and loses the Document Key Information that it has in digital form.
  • the document creating software retains the Document Key Information and uses it when creating an NGD.
  • Embodiment Object-oriented Document class.
  • NGD may have a semantic type (such as “invoice”, “proof of car insurance policy” etc.), and may contain machine-readable information in key-value type. They may also implement specific methods or actions such as “sign”, “verify”, etc. All these fit into the Object-Oriented Programming (OOP) paradigm, whereby a variable has a class type, which defines key-value data fields and methods, and which can be inherited from one type to a sub-type.
  • OOP Object-Oriented Programming
  • NGD classes define semantic types, key-value fields, and methods – including validation and verification methods.
  • NGD class types are stored as unique digital objects; when an NGD is created, it specifies the class type by the unique identifier of the corresponding unique digital document.
  • Machine readable code can then access the document semantic type – defined by the class – as well as key-value fields defined by the class. Keys in key-value pairs defined by the class can be assigned to a specific location in the document, equating the corresponding value to a value that appears in the document.
  • Figure 72 shows the main elements of an NGD: a human-readable layer 7203, which can be implemented by a PDF or other standards for uniform on-screen and printed appearance of digital documents; a machine- readable layer 7202, which in some embodiments contains key-value data as described above.
  • an NGD contains an interactive layer 7204 exposing user- interface elements to the user.
  • an NGD contains a metadata layer 7201 containing mutable information such as access log, interaction history, etc.
  • the machine-readable layer 7202 contains cryptographic trustworthiness features 7206 such as digital signatures; the user interface feature visualizes trustworthiness status 7205 in a conspicuous way to the user. All these layers are contained in a unique digital object 7207 in UDR.
  • Figure 73 provides another view of the structure of an NGD, emphasizing the notion that the different elements complement each other.
  • information in the machine-readable layer 7303 is connected in an unspoofable way, and indeed structurally identical, to the information that appears in the human-readable layer and the user interface.
  • the rendering mechanism used to visualize the human-readable layer uses the exact same information that appears in the machine- readable layer, so that an NGD cannot relay different sets of information to the human user and through its API.
  • Figure 74 is an artist’s illustration of one of the fundamental merits of an NGD over state- of-the-art: the fact that NGD is new document medium that combines legacy document form with highly advanced digital capabilities. Creation of Next Generation Digital Document.
  • a software application creates a NGD by collecting two ingredients: one, a human-readable form of the document; and two, machine-readable key information pertaining to the document.
  • this information is collected in machine-readable key-value format, such as Extensible Markup Language (XML), JavaScript Object Notation (JSON), or Intermediate Document (IDOC).
  • XML Extensible Markup Language
  • JSON JavaScript Object Notation
  • IDOC Intermediate Document
  • the values in a key-value pair may be textual, numerical, or contain a unique identifier (for example, of another document, an interaction object, or an identify).
  • the software application creating the NGD passes this information to an NGD creation module, which in turns creates a new unique digital object whose payload contains both the human-readable form of the document, such as a document in Hypertext Transfer Markup Language (HTML) or Portable Document Format (PDF) formats, and the machine-readable key information.
  • HTML Hypertext Transfer Markup Language
  • PDF Portable Document Format
  • Embodiment Next Generation Digital Document Printer Since the days Apple Macintosh and Microsoft Windows, every desktop software application implements a “File Print” option, which opens a print dialogue window and sends the document to be printed by the selected print driver.
  • a special software printer is installed on desktop computers or other printing enabled devices, such that when an application sends a document to be printed on that special printer, an NGD is created instead of (or in addition to) a hardcopy or a document file in the local filesystem.
  • Figure 75 shows a metaphorical description of the creation of an NGD using presently familiar notions: the layers of an NGD, described in Figure 73, come together to become a document medium upon which the document is “printed”.
  • the NGD software printer is a software device that creates the NGD as a new unique digital object in UDR.
  • Figure 76 shows a possible user interface for creation of a contract NGD, based on a print-dialogue user interface.
  • Figure 77 shows a possible user interface for creation of an invoice NGD, based on a print-dialogue user interface.
  • add-on software components provide NGD creation functionality to existing software systems. For example, an accounting software may be augmented with an “export report to NGD” button.
  • NGD Universal Identifier A key property of Next Generation Documents is that each document has a unique identifier, which could in a preferred embodiment be the unique identifier of the corresponding unique digital object.
  • the document presents its unique identifier in either human-readable, machine-readable form, or both, when it is presented visually.
  • the NGD is represented by an enduring network interface, and the unique identifier is the permanent URL corresponding to the enduring network interface.
  • the NGD can then present a QR code with the permanent URL, and/or the URL itself in human-readable form.
  • the mutable data of an NGD unique digital object may contain information such as: document access privileges, document access log, unique identifiers of unique digital objects corresponding to document signature events, document signature requests, attachments, and so on.
  • an NGD has native access control defined by user identity, rather than by password.
  • An NGD defines access policies and keeps access logs.
  • Figure 78 shows a possible design for access control of NGD from within its user interface. An authorized user may share the NGD with specified identities.
  • an NGD may be created with a “break-glass” functionality, which defines a procedure whereby it will become available to a user without access credentials. For example, in a company board with nine seats (say) it may be defined that any seven board members (say) can elect to invoke the “break-glass” procedure and be granted limited-time access to the entirety of corporate NGD ever produced.
  • NGD User Interaction with Next Generation Digital Document
  • An NGD is an interactive document. It exposes a user interface allowing the document reader to become a document user, performing standard actions such as: sign, request a signature, grant, or revoke access, and so on; as well as custom-implemented actions.
  • an NGD has a distinct appearance representing that fact that the document is an NGD. The distinct appearance may include: the document unique identifier in human-readable and/or machine-readable format; an indication that the document in fact has a user interface; an indication that the document is valid or invalid, etc. Signing an NGD.
  • the NGD user interface allows several signature modalities: including “click here to sign” button, touch screen scribble signatures, and so on.
  • a signature request may specify not just who is required to sign where in the document, but also how they are required to authenticate and how they are required to sign.
  • a requested signature may request that the signer be authenticated using facial recognition (say) and only sign by scribbling a signature on a touch screen.
  • a signature obtained on one Twin will immediately appear on all other Twins of the NGD. Importing a blue-pen signature.
  • a blue-pen signature on a hardcopy Outlet of an NGD may be imported as a signature on the NGD itself.
  • an Outlet allows blue-pen signature import
  • the user required to sign may print a hardcopy Outlet and sign it in the appropriate box or line.
  • the user will then use a device with a camera (such as a smartphone, a tablet or AR glasses) to authenticate his or her identity, and then look at the signed document.
  • the camera will acquire the printed Outlet using the universal identifier on the Outlet, locate the blue-pen signature, extract the blue-pen signature from the image, and create a signature verifiable interaction unique digital object containing the signature image extracted from the camera image.
  • the signature will immediately appear on all other Twins of the NGD.
  • An NGD may be visually rendered in different ways.
  • an NGD admits only one visualization and appears the same on any platform (similar to a PDF).
  • an NGD may be visualized in context-dependent ways. Some visualizations may be merged with visualizations of other NGDs to create a single combined visualization for several documents. In the latter case, the combined visualization may present the unique identifiers of all documents combined for the visualization, or alternatively present a single unique identifier of a unique digital object that represents the document amalgamation and in turn contains the unique identifiers of all documents combined.
  • NGD Twins In a preferred embodiment an NGD is essentially a unique digital object, which may be accessed through its unique identifier (in some embodiments, a permanent unique URL).
  • the primary storage of a NGD is in UDR rather than as a local file or a cloud file. Instead, it enables multiple proxies or local manifestations, which act as pointers to the NGD object on UDR.
  • proxies or local manifestations may include local files in an operating system; cloud files; WWW pages; visualizable objects in Virtual Reality (VR); printed hardcopies; and more.
  • a printed hardcopy may be considered a “physical twin” of an NGD stored in UDR.
  • Figure 79 shows a schematic representation of different Twins of an NGD, showing that all Twins refer to the same unique digital object in UDR, and all Twins are essentially equivalent pointers to the unique identifier of the underlying NGD (which is, in a possible embodiment, a permanent URL).
  • NGD Outlets In the specific context of NGD, an Outlet (a concept taught in generality elsewhere in the present invention disclosure) is a specific visualization of the NGD aimed for a specific purpose, a specific display medium, and sometimes a specific target user audience.
  • an Outlet may be created for the purpose of displaying an NGD printed in hard copy on a billboard for general audience, and a different Outlet can be created for displaying the same NGD on a mobile phone for use of a specific user or group of users.
  • each Outlet will display its own unique identifier, which will be different to the unique identifier of the underlying NGD; the payload of the Outlet unique digital object will contain the unique identifier of the underlying NGD, and the user interface presented by the Outlet will be specific for its purpose and its target audience.
  • an Outlet not intended for signature will not enable signatures, whereas an Outlet intended for signature of a specific user will only present signature option (or request) if accessed by that specific user.
  • an NGD enables Twins.
  • a Twin is an instance of the NGD in any medium – including hardcopy, local file, cloud file, etc. While an NGD may in this preferred embodiment have any number of Twins (or a specified limited number of Twins), all Twins point to the unique identifier of their underlying NGD. All Twins are synchronized in the sense that when mutable NGD information is changed via one Twin (for example, a signature added, a form information field filled, a comment added, etc.) these changes will be reflected on any existing or future Twin of the NGD.
  • Figure 80 shows an NGD Outlet presented on the screen of a laptop computer. The Outlet is accessed through a mobile device, revealing the NGD user interface determined by the Outlet.
  • Embodiment NGD with privacy.
  • the NGD content when a Twin is accessed without proper access credentials, the NGD content will not appear to the unauthorized user; instead, the user will be asked to authenticate.
  • Figure 81 shows the appearance of an NGD opened in a document-reading interface (such as a document reader or a web browser) without access permissions. On left, the document is obfuscated and requires user authentication to continue. On right, the same document after user authentication determined that the user has valid access privileges to the NGD.
  • Embodiment AR interface A NGD is a fully digital entity, in the sense that its content, creation process, citation of other NGDs and entire history of user interaction (including access and signatures) are all digitally produced, digitally recorded and digitally verifiable.
  • an NGD in order to enable an NGD to be printed to hard copy without losing its digital advantages, an NGD may be printed to a physical hard copy Twin.
  • An Augmented Reality (AR) device is used to render digital details, such as a user interface, document signatures, etc., on the hardcopy as it is viewed through the AR device.
  • Figure 82 shows a possible design for Augmented Reality (AR) user interface of an NGD.
  • NGD document is presented on hardcopy or screen (note the machine-readable unique identifier on the lower right corner).
  • NGD is viewed through an AR device: the user is presented with an interface that allows him or her to interact with the document – and perform such actions as sign, share, verify and so on.
  • the user interface is personalized and depends on the Outlet, the user identity, the device used, and so on.
  • Unified interaction surface One of the difficulties in current state of the art concerns a multiplicity of user interfaces and user interaction surface.
  • a user interaction surface (or “interaction surface” for short) is a medium through which a user interacts with the document – reads it, signs it, etc.
  • Every interaction surface is different: even though the document appearance may be uniform across interaction surfaces (such as paper hardcopy, desktop screen, tablet, smartphone, and billboard), the user document experience itself is completely different, as determined by the different properties and capabilities of the medium.
  • the document experience namely, the user experience of the document, is uniform across interaction surfaces.
  • the document user interface — not just the document appearance – is identical whether the NGD is viewed on hardcopy (through Augmented Reality device), desktop viewing application, third-party application integration, desktop internet browser, mobile phone internet browser, mobile phone application, and so on.
  • Figure 83 demonstrates the concept of a uniform document interaction surface, and a uniform document experience: for example, the user interface of an NGD as it appears on an AR device and as it appear on a desktop screen is the same.
  • Figure 84 provides another illustration of the concept of a uniform document interaction surface: the user interface as it appears on AR-enabled glasses, tablet device and desktop screen is the same.
  • Figure 84A shows a user interface design for a Next Generation Document form, which guides a form user, authorized to fill the form, through specific fields the user is asked to fill.
  • Figure 84B shows an alterative user interface design for a Next Generation Document form, which presents a form user, authorized to fill the form, with a questionnaire collecting the necessary information required in the form.
  • the Next Generation Document form auto- fills form fields from the questionnaire.
  • NGD admit Outlets or Twins in Virtual Reality (VR).
  • VR interface may visualize entire binders of NGD, with their inter-connections and inter-citations.
  • an NGD cites another NGD for example, a rent contract citing a property title, or a mortgage loan agreement citing a property sale contract
  • the VR interface may visualize such interconnections.
  • the VR interface may allow the user to browse binders or portfolios of NGDs, present Outlets of selected NGDs, and so on.
  • Embodiment Live cross-medium document interactions
  • an interaction that a user makes with an NGD is instantly reflected in all other Outlets or Twins of the same NGD.
  • NGD Forms Form documents are used to collect information from document users.
  • One of the central difficulties with forms in the state of the art involves collecting form information and transferring it digitally to databases and digital information systems.
  • a common workaround today involves HTML forms and user portals, in which a user can log in and fill in details on a web application, which in turn transfers user-entered information to a database.
  • an NGD can define fields to be filled by a document user.
  • the NGD can define which users can enter which fields – so that, for example, several users have access to a form but only one of them is able to fill in information in a specific form field.
  • the NGD can define specific workflow rules: for example, that a form may be signed by the same user who filled in the form fields, and only after all fields are filled.
  • An NGD may define field validators – similar to field validators of HTML forms, whereby the form will not accept entered values that violate specified rules.
  • the NGD may also prevent changes to user-entered fields once the form has been signed, turning it into a read-only document after signature.
  • User interaction events involving form-filling may be recorded as document interactions in UDR and reported on the NGD timeline, so that the document will reflect which user filled (or changed) which form fields, and when.
  • Visual Trustworthiness in Next Generation Documents In a preferred embodiment, an NGD exhibits a visually conspicuous symbol that summarizes its trustworthiness status – e.g. in terms of authenticity, information integrity, integrity of digital signatures; integrity of ownership status, and so on.
  • Figure 84C shows a user interface design for Next Generation Document, which summarizes the validity and trustworthiness status of the document in a single symbol (lower left corner); and itemizes the various high-level (or overall) notions of validity, verifiability and trustworthiness implemented by the Next Generation Document. Each high-level notion is either satisfied (as demonstrated by an appropriate icon) or not satisfied.
  • the summary status of document validity, verifiability and trustworthiness may be shown constantly on the document itself and may be updated in real-time as the status changes.
  • Figure 84D shows a user interface design for Next Generation Document, which offers a detailed, itemized visual status of a specific notion of validity, verifiability or trustworthiness implemented by the Next Generation Document.
  • Figure 84E shows a user interface design for Next Generation Document, which shows low-level (or maximally detailed) complete report of a specific aspect of specific notions of validity, verifiability, and trustworthiness information a detailed visual status of specific notions of validity, verifiability and trustworthiness implemented by the Next Generation Document.
  • NGD are primitive software objects, with defined software interfaces and application programming interfaces (APIs).
  • APIs application programming interfaces
  • other primitive software objects include local operating system files and Hypertext Transfer Protocol (HTTP) sockets, both of which may be accessed and used by software processes using software interfaces and APIs.
  • HTTP Hypertext Transfer Protocol
  • an NGD may be integrated in various ways into any software system.
  • an operating system may include an API to access NGD through its unique identifier; a database client, such as Standard Query Language (SQL) client, may allow SQL queries to a collection of NGD objects sharing the same key-value class type or key-value structure, in a manner that makes an NGD seem like a row in an SQL table to the client.
  • SQL Standard Query Language
  • software integrations make it possible to create, use, inspect NGDs directly from existing commercial software platforms such as Microsoft 365, SAP ECC, SAP S4, QuickBooks, or Salesforce.
  • Figure 85 illustrates the difference between state-of-the-art digital documents (e.g.
  • NGD NGD-based process automation.
  • an NGD has a defined semantic type and exposes key document information in machine-readable form over an API. This makes NGDs amenable to automation.
  • Process automation involving NGD may involve (i) automation of document workflows, and (ii) Automated verification of document binders.
  • Automation of document workflows A document workflow involve a collection of documents and forms that are exchange among a collection of individuals.
  • Each individual is required to perform actions such as fill in form information in form fields; sign; review; approve. Such actions are sometimes required to occur in a specified order. For example, the new employee must fill a form first, sign it second; the hiring manager is required to sign third and vice-president for human resources (VP HR) sign last.
  • An individual may be required to participate in a workflow as an individual acting on himself or herself, or as a formal role in an organization. In the latter case, the role is named and not the individual (for example, a contract has to be signed by “VP HR” and not by any named individual).
  • a stakeholder participating in the workflow may also be required, in addition to interactions with the primary documents of the workflow, to provide and attach additional documents (for example, a loan applicant may be asked to provide salary slip documents).
  • a document workflow thus involves creation of a specified collection of documents and forms, exchange of these documents and forms between stakeholders, interactions of stakeholders with documents and forms in the collection, attachment of other documents to the collection in specified roles, and verification of the entire collection of filled forms and signed documents.
  • Document workflows may involve stakeholders from different departments in an organization as well as stakeholders from different legal entities and arm’s length counterparties. For example, a process to order imported goods involves a vendor and customer from different countries; both countries customs and import/export control; other government agencies from both countries; and the shipping company. In this case a large collection of documents must be signed by different stakeholders in different government and companies – in a specific order – in order to successfully complete the purchase, import/export, and shipping process.
  • NGDs enable document workflow automation that is far superior to those available in the current state-of-the-art.
  • Machine readable instructions specify stakeholders and roles; identities may refer to unique digital objects representing identities, as taught elsewhere herein; NGD are exchanged using any one of many possible media twins – for example, the same document participating in a workflow may reach one stakeholder in the form of a printed hardcopy, a second stakeholder in the form of a web page, and a third stakeholder in the form of a file attached to an email message.
  • Document interactions performed during the workflow — on any document Twin - are reflected instantaneously in all Twins of that document and may automatically trigger software events.
  • Document interactions are simple and natural.
  • SICCL instructions may automate verification of different stages of the workflow, as well as validation and verification the document collection at the conclusion of the workflow. All workflow history – including document signatures, form filling events and other interactions, identities of those interacting, and the order in which interactions were performed – is recorded on the NGDs themselves.
  • NGD based automated workflow is facilitated by software processes rather than manually, concludes with an automatically verified document package of legally binding documents that can be saved in a variety of media and formats, easily incorporates arm’s length counterparties with different appetites for document digitization, allows self-contained enduring document and process verification that does not depend on any service provider, provides a uniform and simple user experience for stakeholders, and may be integrated into existing enterprise software systems.
  • Figure 87 provides an illustration of automated document workflows enabled by NGD: a contract NGD is created using an “NGD printer” and a workflow is defined.
  • Each workflow stakeholder may receive the NGD via a different means of communications (one stakeholder may receive a file Twin over email, another stakeholder may receive a permanent URL of the NGD over an SMS message and access the NGD using a web browser, and so on.
  • the interactions of each stakeholder are recorded in UDR, and the process is managed automatically until all stakeholders have completed the required steps.
  • Embodiment Automated verification of document compliance and document binder compliance.
  • SICCL or other machine-readable language is used to define validity and compliance of a document or a document binder.
  • Instructions can refer to types of documents in the binder; consistency of information among various document or fields in forms; identity and/or role of document signers; time and/or order of document signers; type, content, signature status and date of documents attached to the binder; authenticity of digital signatures on documents in the binder; issuer of digital signatures and digital certificates for documents in the binder; method by which a document in the binder has been signed; and so on.
  • automated verification may be implemented, which verifies the consistency and compliance of a binder of NGDs, and, based on the result of the automated validation procedure, triggers a software event, and/or provides a visual trustworthiness representation, etc.
  • Figure 88 illustrates the use of NGD in real-time compliance verification.
  • an NGD may present its real-time compliance status.
  • an NGD document or binder is able to show real- time compliance status, as document compliance is verified by a software process rather than by manual inspection of the document binder.
  • NGDs may specify access control and thus require user identification before document access is allowed.
  • the NGD Outlet or viewing platform (such as a web browser, a desktop document reader application, a mobile application, an Augmented Reality interface, etc.) may present a different document experience to different document users – depending on their identifies and document or workflow definitions.
  • the document user interface may appear different to different users depending on their role; or in some situations elements of the document itself may appear different.
  • ⁇ A user is asked to sign a document. Other users will not see a highlighted signature area, but the user asked to sign will see a highlighted signature area and an instruction popup ⁇
  • a user with additional interaction privileges (for example, privilege to inspect the document access log) will see additional user interface components unavailable to other users ⁇
  • a document is sent to a user than does not have security clearance to view parts of it. The parts the user is not authorized to see may be hidden, blurred, blackened, or simply not appear in the document as it is rendered for that specific user.
  • Unique Digital Reality as a massive content layer of interconnected NGDs.
  • WWW World Wide Web
  • search engine results etc. is an example of the potential power of massive collection of interconnected, machine-accessible digital information.
  • Figure 89 shows an interconnected graph of NGD unique digital objects citing or referencing each other. Connecting non-NGD unique digital objects to an NGD. Unique digital objects may cite and connect to other unique digital objects of all kinds. NGDs are no different: an NGD may connect, cite, or attach non-NGD unique digital object such as an image, a video, an audio recording, a geo location, a spreadsheet and so on. In possible embodiments of the invention, the NGD user interface may allow such various unique digital objects to be connected to the document in general, or to a specific location in the document in particular. This way, an NGD may include an inline geo-location; or a binder of unique digital objects may be formed, which consists of a combination of NGDs and non-NGD unique digital objects.
  • Figure 90 shows a possible user interface design for Next Generation Document that refers to a geo-location unique digital object.
  • Figure 91 shows a possible user interface design for Next Generation Document that refers to a voice recording unique digital object.
  • Figure 92 shows a possible user interface design for Next Generation Document that refers to a spreadsheet unique digital object, and specifically, cites a cell from the spreadsheet in the document.
  • Documents may be signed with blue-ink pen on an original document; with a print-sign-scan procedure (wherein the signer prints the document to hardcopy, signs it with a pen and scans the signed copy back to digital document format); with a web form using a “sign here” button or signature scribble panel; or using a cryptographically secure digital signature.
  • Different customs and legal requirements call for different signature modalities.
  • Signed documents are stored digitally or physically, depending on the signature modality. Ease of use. Digital signatures are not user-friendly – not for the signing party and not for the verifying party.
  • An embodiment of the invention enables every user with a smartphone or other camera-equipped, network-connected device to sign documents in a manner that is at the same time cryptographically secure, machine readable, human verifiable and backward-compatible (in the sense that the signature can be verified as a traditional pen signature by a human user).
  • An embodiment of the invention merges the all notions of a human-readable signature (including blue pen and print-sign-scan) with na ⁇ ve notions of digital signatures (such as “click here to sign” web forms) and the more advanced notions of cryptographic digital signatures: they all become one and the same.
  • the signature process is based on three unique digital object: one for the document being signed; one for the signer identity; and one for the signature interaction itself.
  • the identity is created: a unique digital object is created for the signer identity. It includes a public key (in a preferred embodiment, from an RSA keypair), universal identifier for the identity, and details of the person or entity whose identity is represented (such as a name).
  • the document includes an image of the manual signature of that person.
  • the document is created: it includes the document itself (in human-readable form, machine-readable form, or both) and a universal identifier for the document. Like any unique digital objects, both the identity object and the document object are committed, permanent and immutable.
  • a new unique digital object is created. Its payload contains: (i) the universal identifier of the identity object; (ii) the universal identifier of the document object; (iii) a digital signature calculated using the private key, corresponding to the public key contained in the identity object.
  • the signature object also includes a graphical representation of a manual signature, and a location on the human-readable document where this signature has been placed.
  • the signature unique digital object is committed, so that its time-of-origin is indisputable using whatever mechanism is in place to verify object commitments. This concludes the document signature process.
  • a visualization stage when the signed document is presented visually to a human user, the machine rendering the document verifies that the cryptographic signature on the signature object has been signed by the keypair whose public key appears in the identity object. The machine renders a visually recognizable symbol to show human users the validity of the cryptographic signature (and, in a possible embodiment, an interactive way to inspect the signature).
  • the signature object includes graphics of a manual signature
  • the graphics is rendered on the document when it is visualized.
  • a document reader is interested in verifying the signature; it may verify that the cryptographic signature on the signature object has been signed by the keypair whose public key appears in the identity object.
  • a signature device to sign a document, the signer uses a device that includes a storage unit, network connectivity, identity verification mechanism, and a camera – such as a smartphone or a smaller special-purpose device.
  • the device After the device has been configured to correspond to a specific identity unique digital object, its storage unit stores (i) the private key corresponding to the public key in that identity object (ii) access credentials such as facial recognition, voice recognition, fingerprint recognition, passcode, or passphrase.
  • access credentials such as facial recognition, voice recognition, fingerprint recognition, passcode, or passphrase.
  • the signer directs the device at an outlet or visual representation of the document to be signed, which includes a visualization of its unique identifier.
  • the device recognizes the document identifier and accesses the unique digital object corresponding to the document.
  • the device authenticates the identity of the person holding it, by presenting a challenge (such as facial recognition, voice recognition, fingerprint recognition, passcode, or passphrase) and comparing the response received from the person using the device to the access credentials stored in the storage unit.
  • a challenge such as facial recognition, voice recognition, fingerprint recognition, passcode, or passphrase
  • the device creates a new interaction unique digital object as above and the signature process is complete.
  • the identity unique digital object and the digital signature it includes comply with digital signature rules and regulations, so that the signature unique digital object represents a compliant digital signature as defined in the relevant law.
  • Merits of this embodiment of the invention Democratization and standardization of digital signatures.
  • the smartphone has become a standard payment device, it now becomes a standard, secure signature, and consent device.
  • a digital personal device finally replaces the blue pen as the go-to signature device.
  • the shortcomings of the state-of-the-art stem from the fact that documents in the state-of-the-art do not have universal identifiers, so that digital signatures can only be attached to the PDF file.
  • the method taught herein enables standardization of signature process, of signature visualization and verification; and makes cryptographic signatures one and the same with backward-compatible, human readable signatures.
  • any person using any user interface to access a NGD may gain simple visual confirmation of the validity of a digital signature.
  • the described embodiment of the invention merges all notions of signature – legacy, na ⁇ ve and digital – to a single notion.
  • a signature verifiable interaction necessarily results in a digital signature attached to the unique digital object representing the document.
  • the signature verifiable interaction arrives at the same result, which is, that the NGD is digitally signed in a manner that is easily verifiable, and that the interaction is represented by a unique digital object in UDR that allows to verify it.
  • Figure 93 shows a possible user interface for signature interaction, when signing a Next Generation Document on any medium, including desktop document reader, smartphone application, Augmented Reality interface overlayed on a hardcopy document, and so on.
  • the invention disclosed herein is of a fundamental nature. Elements of embodiments of the invention may be combined to enable radical improvements in modern information exchange and indeed enable a state we refer to as the fully digitally transformed world. or the endgame of digital transformation. We now describe possible information exchange processes enabled by embodiments of the invention. A fully digitally transformed world.
  • Figure 96 shows an illustrative embodiment of the device, which can interact with the user, such as to uniquely identify the user uniquely and determine the time and location.
  • the illustrative device seen in Figure 96 includes a processor, a memory, power, a transceiver, one or more sensors, an input/output (I/O) mechanism, and camera and typically includes audio input and output capabilities.
  • I’m a physician at Massachusetts General Hospital. As I enter the hospital, I look at my device and it recognizes my face and my iris. This is how the hospital system knows I have arrived at work. I do not carry a physician badge or a driver’s license. I identity myself to other people just using my device. At the ward, I go over to one of the screens at the nurses’ station.
  • I drive home When I take the bus, I use my device to pay when I get on board. Today I’m driving my own car. The car opens to the touch of my thumb and will not start without scanning my iris. On the way home I get pulled over by a police officer for speeding. The police officer has a mobile biometric identification device, and she uses it to identify me, and assert that I am licensed to drive.
  • information objects are available over a uniform network interface, so that they can be used during a hospital process but can also be used by third parties, e.g. the insurance company, long after the process itself ended. All this information is software accessible. Procedural and bureaucratic requirements, such as those governing medical care protocols, are encoded into the information objects, and thus enforced and verified by software. User interfaces, such as a screen or personal identification device, create information objects as they operate and are used to visually present information objects together with their formal trustworthiness status. All this results in implementation of the principles of digital transformation: information flows, verification happens, and trustworthiness is obvious.
  • Physical identification device A personal device with wireless communication capabilities, biometric identification capabilities, geo-location (GPS and indoor) tracking capability, and proximity communication with other devices or sensors. In the example above the device also features a simple user interface for granting consent.
  • Digital footprint for everything The fact that the physician has arrived at work; the interactions of people with other people, e.g. the patient, with physical objects, e.g. the drug cabinet, and with information, e.g. the screen, as well as consent given or received, all become facts in the Digital Reality.
  • a single screen contains various facts from Digital Reality, arranged and presented by a computer program according to necessity. • Interactions between individuals, and between an individual and a physical object. Using the identification device, individuals may put a personal interaction on record by proximity interactions of their identification devices. Also, individuals interact with physical objects, such as a door, a cabinet, an activation switch, a medical drug package, etc., using their device to get physical access, activate something, etc. All these interactions become facts in Digital Reality. For example, the fact that a nurse opened a drug cabinet, took out a package, and gave package to patient is recorded several times during this process, because the nurse interacted using his device with the cabinet, the package, and the patient.
  • Consent as a universal interaction. No-one signs a form to grant consent – there are no paper documents anyway – and consent depends on biometric identification by the device. Individuals are asked for consent to pay, or when offered a service, or when their consent is required for a medical procedure, or to sign a contract. Consent is given by an individual using their identity device, or by a user interface which has identified the identity device. When information needs to be given about the consent in question, it appears on a user interface (such as a screen) nearby. • Information ownership. Facts in Digital Reality belong to the individual about whom they were collected. Individuals own facts, data, and information on Digital Reality.
  • the screen identifies me by a retina scan and a user interface appears on the screen.
  • the screen asks for my consent to share specific financial information with the financing bank such as balances, income, assets, credit ranking, existing loans, and financing plans, etc. I touch the screen to give my consent.
  • the assertion regarding my financial stability is shared by my own bank to the financing bank without infringing on my privacy, as a zero- knowledge proof.
  • the details of the proposed financing plan appear. I present my thumb to agree to the overall terms. A full contract appears, which includes my identity; the terms of the loan; and details of the car that will secure the loan.
  • the contract specifies that monthly payments will be made automatically from my bank account; and that if payments are not made in schedule, ownership of the car will be automatically changed – on digital reality - to the financing bank.
  • the signed contract becomes an object in digital reality, connected with my identity and the identity of the car.
  • the fact that the car is now owned by me is registered on digital reality; the car doors now open when I present my thumb to the car doors.
  • the vehicle change of ownership transaction now appears in digital reality linked to the financial transaction; the financial transaction is linked to my financial and tax reports, as well as those of the car dealership and the financing institution.
  • a Tour of the Digitally Transformed World we present some examples of realities, products and services enabled by embodiments of the invention taught herein. Identity.
  • the act of signature (using a pen, is replaced by associating – or forming a digital interaction – the digital identity object on shared digital reality with the digital object that represents the piece of information signed such as a contract or terms of service.
  • a digital signature – an act of consent by an individual - is associated with that unique individual in a way that is irrefutable and secure.
  • digital reality shows that the identity has been compromised.
  • Figure 103 shows some uses of a digitally transformed identity. Documents and paper. There is no paper anywhere. All reading material is distributed digitally (see, for example, Magazine and Content Distribution below).
  • Paper and paper documents have no legal or financial function – contracts are information entities and objects in the shared digital reality, signed by biometric means such as mobile network- connected tiny biometric scanners.
  • biometric means such as mobile network- connected tiny biometric scanners.
  • the notion of a digital document, such the Portable Digital Format file format – PDFs, is obsolete.
  • Information is stored as software-accessible digital facts, disentangled and independent of any human-readable visual or textual representations of it. When a user interface renders or presets information in human-readable form, the form of representation of facts has been tailored to the user interface used for the display, the functionality, and the event at hand.
  • Consent Consent by an individual has been digitized.
  • the free will act, in which an individual enters agreements such as terms and conditions, a user agreement, a contract, power of attorney, receipt of medical care, payment transfer; or affidavits in which an individual makes a declaration or signs a petition – are these digital events.
  • Consent by an individual is granted by an interaction of the individual with a computing device which includes biometric identification.
  • the digital object representing an event of consent is attached to the digital identity of the individual and becomes a fact in the digital shared reality.
  • the consent fact – with the individual’s identity affixed - can only be created by use of an identification mechanism such as a biometric scan. Personal Information.
  • All information regarding an individual, collected by any entity or stakeholder, is automatically curated, and consolidated on the shared digital reality and owned by the individual, who can grant or revoke access rights. It is securely and permanently accessible to the individual, on a single user interface, from anywhere, using any computing device.
  • An individual can bequeath their data, share any part of their data permanently or temporarily with other individuals and with organizations and governments such as insurance companies, retail companies, tax authorities, court of law. Access to personal information is recorded and monitored.
  • Figure 104 shows a few types of personal information which, once digitally transformed, are controlled by the individual who generated them.
  • Content Distribution The Publishing, News and Music Industries; Distribution of Art. All content exists as content objects on the digital shared reality and can be accessed by anyone from anywhere on any device, and access can be granted, tracked, and monetized. Namely, the event of an individual listening to a specific song on specific device is represented by an object on digital reality.
  • Self-publishing of any digital content is as easy as making it open-access – because content, such as a book or a song, are just public objects in digital reality; Billing is achieved by tracking access to these objects in digital reality. Services appear which allow to consume content that is self-published in a convenient way (finding it, paying for it, accessing it). There are uniform interfaces for publishing music, for example, and paying for published music. The publishing and music industries disappear in their existing form. The service provided by online content companies such as music streaming (Spotify) and reading material distribution (Amazon Kindle) becomes decentralized — there is no need for any central provider to track access to content and everyone can monetize. Content distribution companies will focus on user interface to content, search, and indexing etc. Banking.
  • Bank accounts for government-issued currency are opened by a software process. Identification procedures for security purposes are replaced by standard biometric scanning against the identity in digital shared reality. Know-your-customer procedures in person become unnecessary – the customer is asked to share and make accessible enough of their personal information, by granting the bank access to relevant information objects with the required personal information, to verify that they eligible to open and maintain an account.
  • Anti-money-laundering rules become unnecessary as every transaction has a complete paper trail (no longer consisting of paper) or audit trail and transaction of goods and services in exchange for payment is documented through and through. Detection of illegal activity becomes a software challenge.
  • loan background checks are replaced by a fully automated procedure in which the loan applicant shares personal information, and the bank’s AI credit risk model assesses the application.
  • Regulatory requirements that the bank must satisfy are implemented by software and checking regulatory requirements amounts to verified software execution.
  • Account information is considered personal information and is owned by the account holder with permanent access to the bank.
  • the primary function of the bank as exclusive owner and guardian of the bank’s books is gone, and the bank is mostly a software outfit that develops credit risk models. Banks no longer handle data storage on behalf of their clients – all account data is on shared digital reality. As a result, the entry barrier to starting a bank is significantly reduced and the industry becomes more decentralized - but can gradually become dominated by the players with the largest computers.
  • An insurance company receives information from a potential customer seeking to buy a policy; evaluates the information; issues a policy; receives information related to an incident and a claim; and evaluates the claim information.
  • This entire pipeline is drastically simplified when all the information involved exists on digital reality anyway.
  • Personal information and property information are objects in digital reality before a potential customer engages an insurance company; a potential customer simply grants the insurance company access to get a quote. Costs of existing insurance companies go toward bureaucracy and fraud prevention – a huge amount of manual document shuffling.
  • the digitally transformed insurance company is a software outfit. Customers to the company give access to their personal information on shared digital reality and get a quote.
  • the insurance models are sophisticated AI models using a huge amount of personal information – the more information a customer is willing to share, the low their premium can be.
  • information regarding insured incidents exists on digital reality and is reviewed by the insurance company by software.
  • Fraud prevention is a software problem. Claim settlement against service providers, e.g. medical caregivers for medical insurance, mechanics for vehicle insurance, etc., is done over the shared digital reality – quotes are reviewed and approved by software; claim settlements payments are transferred by software, etc. Regulatory requirements are implemented in software. As the entry barrier becomes lower, the industry becomes more decentralized, but can gradually become dominated by the players with the largest computers.
  • FIG 106 describes digitally transformed insurance: top, the process of providing information as part of policy purchase; bottom, the claim submission and verification process.
  • Money and Payments The global financial system continues to rely on state issued currencies, or a central global currency backed up by governments. All currencies are completely digitized. A payment is simply a fact in the digital shared reality, stating identities of payer and payee, amount, currency, mode of payment, etc. The credit card and traditional payment industry in its present form disappears, and turns into a digital payment clearing industry, as all payments are digital. This industry merges with the banking industry.
  • Fraud prevention in digital payment is based on personal information in the digital shared reality. Invoices and Receipts.
  • Payment facts are digitally linked to all other facts regarding the transaction, such as facts concerning the goods or services exchanged for payment, transaction details (origin account and target account), etc.
  • informatics problems that arise on top of payments and have to do with proving facts regarding the nature of payments - such as corporate back office, receipt processing, accounting, tax returns, etc. become software problems.
  • Verification of validity and authenticity of a payment are software processes – especially, making sure that the product of service for which it was purportedly exchanged, has indeed been delivered, based on facts in digital reality regarding that product or service.
  • Money laundering and fake invoicing over state-issued currencies in its present form disappear as they become detectable using simple algorithms.
  • Sharing Economy Shared information reality makes it possible to share basically everything. Sharing economy develops considerably. It is easier and safer to share vehicles, houses and other property using background checks (see below). All activity in a vehicle and house is recorded as facts in digital reality, making it possible to establish rules regarding property usage that are monitored or even enforced by software as a contract between the property owner and the property user. Credit checks and background checks.
  • the law is implemented in software and in fact the law is software.
  • contracts are machine-readable and executable over the shared digital reality, namely implemented in software and execute in software.
  • the law mandates data sharing of certain facts by individuals, legal entities, and the government. For example, individuals are required by tax law to share certain personal information with the tax authority; publicly traded companies are required by securities law to share certain information with the public and other kinds of information with registered shareholders; the government is required by freedom of information law to share certain facts with the public.
  • These sharing laws are implemented in software, so that either the data is shared automatically, or there are warnings when data is not shared.
  • Government access to private information depends on access being granted by the owner of the data and is documented – providing a check against government use of information. Compliance. As government regulation is implemented in software, compliance becomes a software problem. Regulation is specified and implemented in software, namely, in a machine-readable format – not in any natural human language. A regulation specified conditions that must be met; execution of the relevant code is like a software test and results in either (i) a compliant response, or (ii) a non-compliant response with a list of issues. A regulated entity grants the regulating government agency access to relevant information objects in digital reality. The regulatory agency is simply responsible for maintaining the regulation code (according to legislation) and executing the code. An individual or company have continuous tracking regarding their compliance status – as does the government regulator.
  • Tax is a major informatics operation. Tax reports by the taxpayer – as well as tax audit by the tax authority – come down to managing vast amounts of information from different sources regarding income, expenses, payments, receipts, geo location for determining tax residency, past years tax reports, etc. Digitally transformed tax collection occurs automatically and continuously. All income and expenses known to the individual are stored as private information on digital reality. Software is running against facts on payments and goods/services exchanged and collecting an exact tax on an ongoing basis. Tax is a software problem. Tax experts write and review software that implements the tax code, tax regulations, etc. Tax residency is automatically calculated upon sharing of geo data. The government tax authority is granted access to all tax-related information from an individual’s or organization’s personal information.
  • the tax authority runs independent software audits. Escrow. An escrow process as part of sale and transfer of ownership / transfer of title over an item, a vehicle, or real estate property is an informatics process.
  • the seller transfers ownership to a third party, e.g. escrow agent, and conditions are set that result in either (i) ownership being returned to the owner if the transaction is unsuccessful, or (ii) ownership being transferred to the buyer if the transaction is successful.
  • Conditions are specified in machine-readable language, rather than in natural human language, and specify conditions on information objects in digital reality (for example, payment transferred).
  • the code is executed and changes the ownership to either the original owner or the buyer.
  • Corporate accounting The function of the corporate back office is obsolete, and the role of corporate controller’s office evolves to a software role.
  • Reports and representations of stress tests and risk assessments are machine-verifiable and contain user-interface features that represent their verifiability status, so that trustworthiness is evident.
  • Investment portfolio statements and public financial reports are machine-verifiable and contain user-interface features that represent their verifiability status. All information underlying a portfolio statement or financial report (assets owned, asset prices, transactions made, etc.) are available for machine inspection in unique digital reality.
  • Corporate bylaws and corporate governance decisions are enforced through software.
  • corporate governance and external third parties (such as regulatory bodies) obtain machine-verifiable reports that link to the unique digital reality of the corporation, namely, are based on the actual information as it was originally recorded – not of a retelling or affidavit of the information.
  • Medical process management Medical standard of care and medical protocols are implemented in software, and compliance with protocols is machine-verifiable since all medical records and medical care events are available in uniform digital reality. There is a machine-readable language that describes standard-of-care and care protocols.
  • Digital civil rights and GPDR Each piece of digital information is attributed to and belongs to the individual or person who created. Data bequest is standard – the complete collection of personal information is an asset that can be rented, sold, and indeed passed as inheritance.
  • Real estate Real estate ownership registrar is simply a part of unique digital reality. Real estate ownership records are maintained in uniform format over unique digital reality. Real estate transactions are recorded in perpetuity in unique digital reality. Due diligence in real estate transactions is automated and performed by executing machine code against all relevant information in unique digital reality.
  • Objects, states and events in large-scale shared virtual reality or large-scale shared augmented reality are stored as digital objects in digital reality. Ownership over virtual items, virtual real estate and other ownable assets in shared virtual reality is recorded in unique digital reality. Virtual reality or augmented reality can be used to mirror – or otherwise represent - objects, states, and events in physical reality as they are recorded in digital reality. Internet of Things. Devices and sensors store their measurements and event logs as digital objects in unique digital reality. As a result, these measurements and logs are machine-accessible and large-scale integration of information from IoT devices, across stakeholders who own the devices, locations where they are installed, and device manufacturer, is possible. Copyright. All digital content is distribution without the use of digital files.
  • Access to each digital content object is tracked so that copyright is easy to enforce and content easy to monetize.
  • Computers can become terminals for accessing information in digital reality ecosystem, rather than storing the information themselves or copying information.
  • Content is watermarked with a universal identifier pointing to its location in digital reality.
  • Liability law regarding mission-critical software systems and autonomous systems. The law requires certain software testing of mission-critical software systems. Liability law reflects these requirements. Proof of testing is achieved using digital reality.
  • a data amalgamation and reconciliation industry As digital information is stored on unique digital reality, an array of new products and services appear that provide the function of data amalgamation and data reconciliation. Services include joining separate datasets on digital reality into a single dataset on digital reality and reconciliation of differences and mismatches between different datasets on digital reality. Data-based decisions.
  • Processing System Figure 107 is a block diagram illustrating an example of a processing system 1800 in which at least some operations described herein can be implemented.
  • components of the processing system 1800 may be hosted on a computing device that includes a threat detection platform.
  • components of the processing system 1800 may be hosted on a computing device that is queried by a threat detection platform to acquire emails, data, etc.
  • the processing system 1800 may include a central processing unit (also referred to as a “processor”) 1802, main memory 1806, non-volatile memory 1810, network adapter 1812 (e.g., a network interface), video display 1818, input/output device 1820, control device 1822 (e.g., a keyboard or pointing device), drive unit 1824 including a storage medium 1826, and signal generation device 1830 that are communicatively connected to a bus 1816.
  • the bus 1816 is illustrated as an abstraction that represents one or more physical buses or point-to-point connections that are connected by appropriate bridges, adapters, or controllers.
  • the bus 1816 can include a system bus, a Peripheral Component Interconnect (PCI) bus or PCI-Express bus, a HyperTransport or industry standard architecture (ISA) bus, a small computer system interface (SCSI) bus, a universal serial bus (USB), inter-integrated circuit (I2C) bus, or an Institute of Electrical and Electronics Engineers (IEEE) standard 1394 bus (also referred to as “Firewire”).
  • PCI Peripheral Component Interconnect
  • ISA HyperTransport or industry standard architecture
  • SCSI small computer system interface
  • USB universal serial bus
  • I2C inter-integrated circuit
  • IEEE Institute of Electrical and Electronics Engineers
  • the processing system 1800 may share a similar processor architecture as that of a desktop computer, tablet computer, mobile phone, game console, music player, wearable electronic device (e.g., a watch or fitness tracker), network-connected (“smart”) device, e.g.
  • main memory 1806, non-volatile memory 1810, and storage medium 1826 are shown to be a single medium, the terms “machine-readable medium” and “storage medium” should be taken to include a single medium or multiple media, e.g. a centralized/distributed database and/or associated caches and servers, that store one or more sets of instructions 1828.
  • machine-readable medium and “storage medium” shall also be taken to include any medium that is capable of storing, encoding, or carrying a set of instructions for execution by the processing system 1800.
  • routines executed to implement the embodiments of the disclosure may be implemented as part of an operating system or a specific application, component, program, object, module, or sequence of instructions (collectively referred to as “computer programs”).
  • the computer programs typically comprise one or more instructions, e.g. instructions 1804, 1808, 1828, set at various times in various memory and storage devices in an electronic device.
  • the instructions When read and executed by the processors 1802, the instructions cause the processing system 1800 to perform operations to execute elements involving the various aspects of the present disclosure.
  • machine- and computer-readable media include recordable-type media, such as volatile and non-volatile memory devices 1810, removable disks, hard disk drives, and optical disks (e.g., Compact Disk Read-Only Memory (CD-ROMS) and Digital Versatile Disks (DVDs)), and transmission-type media, such as digital and analog communication links.
  • recordable-type media such as volatile and non-volatile memory devices 1810, removable disks, hard disk drives, and optical disks (e.g., Compact Disk Read-Only Memory (CD-ROMS) and Digital Versatile Disks (DVDs)
  • transmission-type media such as digital and analog communication links.
  • the network adapter 1812 enables the processing system 1800 to mediate data in a network 1814 with an entity that is external to the processing system 1800 through any communication protocol supported by the processing system 1800 and the external entity.
  • the network adapter 1812 can include a network adaptor card, a wireless network interface card, a router, an access point, a wireless router, a switch, a multilayer switch, a protocol converter, a gateway, a bridge, a bridge router, a hub, a digital media receiver, a repeater, or any combination thereof.
  • the network adapter 1812 may include a firewall that governs and/or manages permission to access/proxy data in a network. The firewall may also track varying levels of trust between different machines and/or applications.
  • the firewall can be any number of modules having any combination of hardware, firmware, or software components able to enforce a predetermined set of access rights between a set of machines and applications, machines and machines, or applications and applications, e.g. to regulate the flow of traffic and resource sharing between these entities.
  • the firewall may additionally manage and/or have access to an access control list that details permissions including the access and operation rights of an object by an individual, a machine, or an application, and the circumstances under which the permission rights stand.
  • the language used in the specification has been principally selected for readability and instructional purposes. It may not have been selected to delineate or circumscribe the subject matter. It is therefore intended that the scope of the technology be limited not by this Detailed Description, but rather by any claims that issue on an application based hereon. Accordingly, the disclosure of various embodiments is intended to be illustrative, but not limiting, of the scope of the technology as set forth in the following claims.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • User Interface Of Digital Computer (AREA)
  • Document Processing Apparatus (AREA)
EP23740767.1A 2022-01-11 2023-01-10 Digitale konsolidierung Pending EP4463776A4 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US202263266659P 2022-01-11 2022-01-11
PCT/US2023/060428 WO2023137289A2 (en) 2022-01-11 2023-01-10 Digital consolidation

Publications (2)

Publication Number Publication Date
EP4463776A2 true EP4463776A2 (de) 2024-11-20
EP4463776A4 EP4463776A4 (de) 2026-02-18

Family

ID=87279813

Family Applications (1)

Application Number Title Priority Date Filing Date
EP23740767.1A Pending EP4463776A4 (de) 2022-01-11 2023-01-10 Digitale konsolidierung

Country Status (5)

Country Link
EP (1) EP4463776A4 (de)
JP (1) JP2025504434A (de)
AU (1) AU2023206308A1 (de)
CA (1) CA3248071A1 (de)
WO (1) WO2023137289A2 (de)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
ES3018257A1 (es) * 2025-03-12 2025-05-14 Gamero Luis Pulgar Sistema técnico de certificación biométrica y biomecánica mediante Inteligencia Artificial o Estadística Avanzada para la certificación de identidad, geolocalización y actividad del usuario con notarización digital

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8656303B2 (en) * 2009-02-17 2014-02-18 Larry J. Hughes, JR. Method and system for certifying webforms
US9064238B2 (en) * 2011-03-04 2015-06-23 Factify Method and apparatus for certification of facts
HK1259297A1 (zh) * 2015-11-13 2019-11-29 Badge Inc. 公/私钥生物特徵认证系统
US10693872B1 (en) * 2019-05-17 2020-06-23 Q5ID, Inc. Identity verification system

Also Published As

Publication number Publication date
JP2025504434A (ja) 2025-02-12
EP4463776A4 (de) 2026-02-18
AU2023206308A1 (en) 2024-07-25
CA3248071A1 (en) 2023-07-20
WO2023137289A2 (en) 2023-07-20
WO2023137289A3 (en) 2023-09-28

Similar Documents

Publication Publication Date Title
US12020178B2 (en) Method and apparatus for information representation, exchange, validation, and utilization through digital consolidation
US20250013694A1 (en) Blockchain system
Verma et al. Blockchain for government organizations: Past, present and future
US20240046391A1 (en) Methods and system for managing intellectual property using a blockchain
US11443380B2 (en) System and method of providing and recording personalized context-specific advice in the form of an artificial intelligence view of a hierarchical portfolio
JP7064651B2 (ja) ブロックチェーンベースの文書配信、連携、および配布によって可能にされる分散型マーケットプレイスおよびエコシステム
Swan Blockchain: Blueprint for a new economy
Duy et al. A survey on opportunities and challenges of Blockchain technology adoption for revolutionary innovation
Franks Implications of blockchain distributed ledger technology for records management and information governance programs
Ghosh The blockchain: opportunities for research in information systems and information technology
WO2024025863A1 (en) Systems and methods for providing process automation and artificial intelligence, market aggregation, and embedded marketplaces for a transactions platform
JP2025538951A (ja) 企業資源の保護、アクセス、インターフェースのための方法
Tilooby The impact of blockchain technology on financial transactions
Hang et al. SLA-based sharing economy service with smart contract for resource integrity in the internet of things
Khatun et al. B-SAHIC: A blockchain based secured and automated health insurance claim processing system
Szabó et al. Affordances in blockchain-based financial recommendations concerned with life events and personalities
US20250335458A1 (en) Contextual orchestration and scoped memory protocol with decentralized memory wallet for adaptive artificial intelligence systems
Boiardi et al. To what extent can blockchain help development co-operation actors meet the 2030 Agenda?
Shaikh et al. Blockchain, metaverse, and digital payments: A global digital consumer perspective
US20220051192A1 (en) Document, drive and process management for contract of things and document of things
Kumble Practical Artificial Intelligence and Blockchain: A guide to converging blockchain and AI to build smart applications for new economies
EP4463776A2 (de) Digitale konsolidierung
WO2025175278A1 (en) Blockchain-based software-as-a-service platform for automatically coordinating reverse transactions
Conley Blockchain as a decentralized mechanism for financial inclusion and economic mobility
Karkeraa Unlocking Blockchain on Azure

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20240718

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)
REG Reference to a national code

Ref country code: DE

Ref legal event code: R079

Free format text: PREVIOUS MAIN CLASS: G06F0016000000

Ipc: H04L0009320000

RIC1 Information provided on ipc code assigned before grant

Ipc: H04L 9/32 20060101AFI20251015BHEP

Ipc: H04L 9/00 20220101ALI20251015BHEP

A4 Supplementary search report drawn up and despatched

Effective date: 20260115

RIC1 Information provided on ipc code assigned before grant

Ipc: H04L 9/32 20060101AFI20260109BHEP

Ipc: H04L 9/00 20220101ALI20260109BHEP