New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Complementing DApps with Trusted Computing by Thomas Bertani (Devcon5)

DevconWed, Oct 7, 2020, 12:00 AM

Speaker

Thomas Bertani

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on IPFS and more. https://archive.devcon.org/archive/watch/5/complementing-dapps-with-trusted-computing-the-challenge-of-designing-rock-solid-oracles Decentralized Applications aim to change the way verticals across multiple industries work. An important element for this to happen is for smart contracts to access real-world data. Problem is, blockchain is a walled-garden and smart contracts cannot natively fetch data from the outside world. Blockchain oracles enable DApps to overcome this limitation. Designing such a tool is quite a challenge - elements such as security, decentralization and feasibility must be kept into consideration. Is blockchain a self-standing technology? Security-focused techniques such as Trusted Computing or ZKSnarks are being explored as a complementary technology enhancing the power of decentralized tools. How do those technologies complement each other? What’s the benefit for blockchain oracles to rely on both? And what’s the benefit for users? Speaker(s): Thomas Bertani Skill level: Beginner Track: Security Keywords: dapps, design, oracles, general Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon 5 was held in Osaka, Japan on Oct 8 - 11, 2019. Devcon is organized and presented by the Ethereum Foundation, with the support of our sponsors. To find out more, please visit https://ethereum.foundation/

Transcript

hello everyone thank you for having me here today my name is Thomas I'm the CEO and founder of provable provable is a blockchain Oracle service that has been operating in the tearoom space since 2015 so duties during this presentation I will show you what is the trust model that we are using with our Oracle service and we try to understand what are the trust implications and what's the challenge behind the you know designing of social services and in the last part I will like introduce a new project based on the same trans model which is called the P tokens and this is basically a two-way peg for tokens which are native to one blockchain so that we can use them like on a theorem or on other blockchain so let's start with like a brief introduction to understand the like some terms that we will be using during the presentation so the three entities we are interested in are basically the data source which is like a Web API or a source for external data that doesn't live on the blockchain then we have the application which typically will be a smart contract and we have the Oracle which is this like new intermediary in a word that is trying to get rid of intermediaries right so why do we need like an Oracle to reach out to external data well this is because of the way the blushin works so it's not possible to reach out to like the internet from within the blockchain so the or core somehow enables that we see later how this is possible but the Oracle is basically an actor that operates on the blockchain but he's also capable somehow to reach out outside to the data source so as you see already here the data source is always to be trusted because the data in general is something inherently trusted like if we have a smart contract that needs to release a payment when you know given flight is late or if the temperature is reaching a some degrees or like if number of views of a YouTube video go above a certain limit then we always have like a third party that is like claiming what the correct answer to those questions is so one example for the number of like views for a YouTube video is that YouTube is the one telling us how many views the video has and we have no way to independently verify that so we always need to trust YouTube in the same way if we if I was asking you like what's the temperature here today I'm sure I will get different answers but most of you will probably look for the first results on Google and the reality is that we don't know like the precision that we are looking for as for the this data we don't know the exact location so you know the data source is always making some assumptions so we need to trust the the data source for the data's providing is like the data we are pushing to the blockchain is always like a claim coming from the data source yes sorry so as I said we have been around for a while so this enabled us to collect some interesting data the data you can see here it's quite small but they will help you to to understand it so over the last like four years we have processed over 1 million transactions on the T domain net asking for external data and if you look on github there are approximately 1,000 Gita open source smart contracts that are basically using the Oracle service so we have like process this data to understand what those contracts do but they're like field and basically what we found out is that of course there is a lot around you know D Phi so a certain tokens or you know I cos that needs to check a price feed because maybe they wants to fix like the contribution in USD instead but they receive eaters or things like that but there is also a lot around gambling as you can see here because the randomness is yet another like piece of data which is not easy to compute straight on the blockchain without having like the - to possibly collude so the D role of the Oracle goes way beyond the fetching of the data from a Web API it could be really the offloading to of a competition to an Austrian context but it could be much more as we see later so the model the provable as adopted is the one of using the basically trusted computing techniques to prove that the data we are fetching from a Web API is indeed authentic and it has not been tampered with during the delivery process so you don't want the Oracle to potentially like compromise the data so you're already trusting data source you shouldn't trust the Oracle as the Oracle could potentially you know change the data it has received from the data source and just push something different to the blushing so it may trigger like a Bronk payment on the blockchain or it may lead to Bronk results so what you want is the Oracle not to be trusted and that's why you need the like some kind of proofs that the data delivered is correct is is authentic so provable has been doing that with trusted computing techniques for those of you who are not familiar around trusted computing the idea is to basically use some like dedicated chips that provide sandboxing in hardware for the execution of a given piece of code so basically we publish the code that gets executed on those special machines and with those machines help to to generate an authenticity proof so it's basically something that along with the result helps to understand that the computation has happened within those safe boundaries we send them to the blockchain and then basically this provides like a shield against the manipulations during the data delivery so this enables you to verify that the Oracle has sent the answer but it is not the like owner of the data and the owner of the data is really the website so there has been no alteration during the process this is why they are called like authenticity bras there are many like challenges around Oracle's it's not just around it you know proving the authenticity of data which has been our main like focus for the last years there are many more challenges so as you can see here one is around you know relying on reliable data sources we don't want to you know push data to the blocks in a way which is secure and then have low quality data sources that cannot really be trusted so this is something where well players like Thomson Reuters but also streamer and few others are working a lot so that they can basically provide some guarantees on the selected data sources and they can provide quality data to to the blossom and the way to basically not rely on a single trust line on the data source front is to basically use more than one data source so in the case of the price of each other for instance is quite simple because you can just you know do an average on all the exchanges that have the majority of the trading volumes so you have something accurate which doesn't have like points of failure theory but it depends it can get much harder depending on the data you want as I said for with the example of the number of views for a YouTube video you have no possibility to go you know to avoid the trust on with Google because it's just something which inherently belongs to to YouTube right so YouTube is somehow the only data source you you you will need to do reach out to then as for the like authenticity of the data we have been using few technologies such as like the trusted execution environment of Qualcomm the legend on us the some of you some of you may be familiar with and Intel SGX so this is something that's also chain linked with the town crier project has been working on there are a few options on that front but using trusted computing is quite general purpose so it can help to basically provide those guarantees for the execution of something on the option context while interacting with young-shin context also there is a lot of work go on the protocol that those Oracle's should use while speaking with the blockchain so chain link but also make a dao compound rhombus and others also with net they are working on on that front we have been doing so for few years as well and I think those systems will end up to interoperate one with the other and depending on like the needs of the smart contract there will be the adoption or of one system over the other so for example as you will see in a second the provable one is optimized for being a cost-effective on chain so the gas cost is very low and it doesn't give strong guarantees on the fact that the unanswered will be provided but it provides guarantees on the fact that when an answer is sent to the blocking it's really authentic so you know that basically if you get an answer the answer is secure while other systems focus also on like giving some more guarantees around the redundancy so that basically you can potentially have also a guarantee that the result will be sent so that's why for instance we are looking to integrate with other systems here so if someone is interested to pay a premium because maybe they want more redundancy then they can go via other Oracle systems and still benefit from our authenticity process so over the years what we have like heard from the community as for the community feedback is basically that this is what they were looking for like a reduced cost because many times you have like a transaction on a theorem that needs to reach out to external data and you don't really want this external data fetching to like increase significantly the cost of your transaction you're already paying like the gas price for confirming transaction you don't want the Oracle to impact significantly on that cost so this is why having a fully decentralized approach is typically more expensive and for some applications it may be like it may not be a good fit so it depends on the application if you have an application where for instance you want to like get external data for every transaction doing it in a fully decentralized way maybe we're more expensive so it depends like for gambling for instance I don't think that decentralization provides really a strong benefit on the random number generation part why for other things like price feeds you may want like to get data every few minutes instead that then every transaction so you may want to obtain in a more like decentralized approach and pay a premium for that also the other things you see here like data security so the authenticity proofs approach and more they are all like critical components that are needed because you don't want to compromise the security of your smart contract again and also reputation systems of course are something that is often mentioned and that somehow is part of those Oracle systems that are being implemented and where the ease of use as well because he really wants to you know you don't want the Oracle components to complicate too much the way your application is structure so so basically the technologies as I said that we work with are basically blockchain in general because we don't integrate just with a theorem we have integrations with a few blocks but the theorem is the one with most of the traction and trusted execution environments so trusted computing techniques of different kinds so at the moment we have approximately 200 projects that are reaching out to provable every month from their smart contracts to to get real-world data and as I said most of them are around like the generation of random numbers price feeds or like a variety of web API calls that connect some advanced like off chain computations typically with the on chain smart contracts that may just you know release a payment so Oracle is currently integrated with it'll may not but also with many test nets basically all the main etherium testaments and also with like other Oracle's Network and with some side chains so we have focused a lot in the last few years on the random number generation use case because it's actually a strong need and it has been one of the first applications getting some traction in the etherium space and before also in the Bitcoin space if you think of Satoshi dice which was like the first application on Bitcoin death caused like a spike in the transaction volumes in 2012 so the technology we have used to like provide the provable random number generator which is a part of the Oracle are the ones you see mention here so it's quite interesting the use of the ledger te because most of us know the legend an OS has the you know Hardware wallet to secure you know if or other tokens but the reality is that the security guarantee is provided by the legend an OS could be used for custom applications and you can really implement anything within the safe boundaries of the legend an OS Y proving to third parties that you know the application was really running on a legend an OS with North durations so this is what we are using for the random number generator for instance these are the networks I was mentioning where we are integrated as you see we also have like other ATM based networks such as our SK but also other networks which are not a tea room based EDM based such as us art record fabric and others so um everyone is discussing this year about defy which is really a new term for something that you know we have always discussed which is the potential of decentralized financial applications in this space so I found that tweet a few months ago quite interesting as it's basically showing as we have seen in other presentations as well that like the composability of those defy tools is somehow leading to many interesting use cases and everyone is building on top of other components that are built by other teams so thinking about that I think we could really split the needs of defy into categories so the first one is the engine which is like the platform where you want to run the defy tool and at the moment it's mostly tedium right so we have something that I like on eros but it's still quite limited why because on on you don't really have other you know the rest of the ecosystem is sort of missing so a tedium got a lot of traction for different reasons for the technology but I would say that one of the main points in favor of a team today is the huge like developers base and the user base and the fact that we already have some initial traction differently than other blushes so this is probably one of the main reasons why defy is being built there and why there are so many new tools that are being built there so interoperability of blockchain and composability of those defy tools are helping to like grow significantly the relevance of define in general so the first thing you need is like the engine as I said which today is a theorem and that that's fine as there doesn't seem to be like requests from the users to to move it as well so that's that's where we are building and then you need assets right this is what's also listed in the TWiT but we've been saying like tokens of all kinds that you know are interest bearing or that I have other properties think of like Rob the bitcoin is one of example of that where you have a federation securing basically any RC 20 token on a theorem which is collateralized by Bitcoin and yeah the point is do we really believe that like all those defy tools we'll never have any need outside of a theorem well I guess the answer is already there with W BTC right we see there is a first need for like going beyond the limits of the platform where the defy those are operating which is a theorem so we have if you look on current market cap the like tools being the the assets being traded that I have most of the volumes and also the liquidity are not just a Tyrian based so some of them are 18 on base but you have many others that are not adhere on base not to talk about the you know non-blocking assets so there is a strong need to go beyond that so that's why we started to work on this new project called the P tokens this is based on the provable infrastructure and provable technology P stands for a few things instance for provable but it's also stands for portable tokens and also for pegged tokens because what they are is really just a two-way back with tokens from that live natively on a different block containing helium but the P tokens are their representation on it of a material so it's basically the same thing you may have already tested out with W BTC but it goes beyond that because it could either be like in support of a federation so it could be something used on top of W BTC or it's something you can use to potentially like replicate WBT see without the Federation or start other tokens without bootstrapping a new Federation again and again so I believe this is like quite significant for the impact it could have on defi so I want to explain you how it works the the test assumption is the same one we had built the provable Oracle service on so its uses trusted computing to secure the packing and it can be integrated with like any blockchain really for the way it works so it's very general purpose so let me show you what's the what's the flaw so this is like a general representation of DT on blockchain on the right and on the left you have a blush in which is known at Eden based so it's like the the first one we release is years as it didn't exist on a theorem so it will be like a PE Oz token on a theorem but it is disciplinary 20 blushing so it could be a Bitcoin it could be you know rape or or whatever whatever there is our need for in the defi ecosystem on on a theorem so you have the trusted execution environment in the middle which is the secure sign books executed on Intel SGX in this case and basically what the what the what happens is that the the securing clave at the moment is running within like those boxes that we had as part of our infrastructure but it could be run anywhere so you can run it on your own like Intel SGX machine it could be run in the cloud with some Intel SGX enable the machines or you can just use one of those machines as well if like you want to potentially secure this two-way back and contribute to the redundancy of it so it doesn't it need to be limited to Intel SGX the concept goes beyond SGX itself but the first implementation will be honest reacts as if the like easier the easiest to get started with and the code is quite complex at the moment the code is open source so basically anyone will be able to to verify the code and know that the true way peg is actually secure and it's running as intended so it gives full transparency which is not reputation based so that's why you know you don't necessarily need a Federation you can potentially use it with other Federation or in support of Federation to minimize the trust in the players involved so we in the peos use case that's what happens with the issuance of new POS tokens so you basically send like a new transaction to a specific address which is probably under the control of the clave of the trusted execution environment and then you send to the trusted execution environment approve of that like a proof of the deposit so the in clave will be able to verify that this deposit opened correctly and will authorize on a theorem a transaction where that basically issues the new POS tokens so the opposite happens when you want to like Banda token and redeem DPOs token so the POS token can like freely be exchanged on a theorem as NESC 20 token and at any time in an automated way with no manual intervention it can just be redeemed for the underlying asset which in this case is ears so what you will do is basically barring the use DPS token and when you burn it you specify the ears address that where you want to redeem the de oz torque and so on and what happens is that basically after the trusted execution environment has verified that everything is correct it really is the ears focus accordingly so there is no possibility to steal funds is fully transparent and secure thanks to the trusted computing component and yeah so we have a demo working we plan to release the production version of the PS token by end of month but now we are looking for community feedback and we are discussing with defy tools to see if they are interested and what tokens they would like to have on a theorem so if you are interested to potentially have like on etherium a token which is not there at the moment please reach out and we will be happy to support you so this is the dub that you will be connecting to it's ready actually everything is already working we are finalizing the enclaved component at the moment but the blockchain component is already finalized so what you have ended up is well just a transparent Luke house - like the minting events and binding events so you can check that you know DP of tokens and the underlying euros tokens do match and then you would see the state of the enclaves so this is the trusted computing you will see the last year's and the last item block that is that are known to the in clave and there are some statistics here on like the operations that has been done by the in Cleveland that are reported by it you can also like issue and redeem via deed up the tokens independently at any time with no intervention so that's much faster than any alternative solution like WB TC or in general since there is no human intervention for the main thing or anything like that it can be really done very quickly so in the case of like Bitcoin for example you would just need to wait for the confirmation time so this is a recap so basically we have worked a lot recently on securing like the the Oracle service which is already like stable and use the a lot on DT no maintenance we have also released like new certifications for regulated casinos around the provable RNG but our recent area focus has become the P tokens which we believe will use the same technology while providing like a service which is strongly needed today in DD Phi ecosystem so if you are interested well sorry this was like P tokens dot IO is a website where you can go ahead there is like a whitepaper there is the draft of a white paper that we have released today and there is a telegram channel where you can join the discussion if you are interested on the topic so it's betoken so ty oh thank you for your attention Thanks [Applause] you

Automatic transcript — names and jargon may be misspelled.