Service lets you "certify" a document using the Bitcoin blockchain
proofofexistence.com
proofofexistence.com
One example would be to take a photo of a rental car showing damage at the time you rented it and be able to prove it was taken at that time. Then the rental company cannot later claim you caused the damage.
This is a pretty clever use of the blockchain as a publicly-visible and authenticated timestamp. This way, the site's owners do not have to establish themselves as a legal authority on timekeeping in order for this to be a trusted service.
Everyone has a copy of the Bitcoin block chain, so anyone can verify your transactions. You can write software that will crawl the block chain and generate automatic accounting histories for tax and verification purposes. You can engaged in “Trusted Timestamping” – take a cryptographic signature of any document, timestamp it, and put it into the block chain. Anyone can verify that the document existed at a given time. If you sign the document with your private key and another party signs it with theirs, it becomes an undeniable mutually-signed contract. This entirely eliminates notaries and websites like https://www.proofofexistence.com/ are showing the concept. The Namecoin project is building a distributed Domain Name System that allocates and resolve Domain Names without needing ICANN or Verisign, by using the block chain to establish proof-of-ownership.
Really worth a read.
[1] http://startupboy.com/2013/11/07/bitcoin-the-internet-of-mon...
It seems to me that the real problem is convincing a jury that a prior piece of work is related to a patented piece of work.
hu?
And I believe Jury would accept only those + a certified authority which would want to be testify in front of Jury.
I think you've missed my point. I'm saying that the problem isn't the TIME of the prior art, it is proving to a civilian jury that prior art relates to a patent.
Perhaps using a combination of different hash algorithms that we know are secure today to certify a file together would be a potential solution to the problem. It's not perfect, but at least this way all the algorithms used need to be compromised for the certification to break.
E.g.:
I claim that I authored the string "foo bar" with hash "1f2ec52b7743687..".
Now you find a collision and go to court arguing:
>> Your honor, but "3HSSHog*8FF9 z!!!!ady94765&$^#" also has the same hash!
I think the court will still assume that "foo bar" is the correct original, not the garbled collision data you produce. And you still can't deny that the original produces the correct hash.
The problem is that I can author "foo bar" and "moo bar" constructed to hash the same, and then assert retroactively which one I meant. While collisions are likely to have random binary garbage in them, it may not matter - I am on phone now, but IIRC I have two PDFs on my desktop that have the same MD5, one of which viewed is an airbus pamphlet, the other being a Boeing one. (created by Dan Kaminski, IIRC)
http://th.informatik.uni-mannheim.de/people/lucks/HashCollis...
http://www.win.tue.nl/hashclash/ChosenPrefixCollisions/ has a multicollision: 12 PDF files with different content and the same MD5 hash.
https://www.btproof.com/ https://news.ycombinator.com/item?id=5790382
Recent changes to Bitcoin made the method I'm using to timestamp the data on the blockchain somewhat problematic [1], but I'll be working on an update once I release another Bitcoin-related project I'm currently working on (hopefully in the coming days).
Once that hard limit is lifted, and things like this can scale and support demand, applications like this could be very interesting.
One thing though, it says the BTC involved in the transaction is unspendable, isn't that a bad thing? I imagine an idea like this that didn't render any amount of BTC unspendable would be ideal.
Fortunately, the doubling time is, from eyeballing the chart below, about 6 months, so that allows ~1-2 years for a fix.
https://blockchain.info/charts/n-transactions?timespan=30day...
There are surely periods of frenzy in the day where we cannot support 7 transactions per second as more economic activity takes place, even if the total transactions for the day is well under 600000. Its not like the transactions are neatly distributed on a flat line throughout the day.
There must also be some consideration that each time this is done, the BTC in the transaction is rendered unspendable and so it is taken out of the market. So I guess its not good if something like this could scale on top of BitCoin.
It doesn't really matter, it's not like they're at all close to that limit. The limit is there to create a market with transaction fees, so it's not just going to be "removed" any time soon.
The limit is actually there to limit the size of a block. It has nothing to do with transaction fees. Click the link I posted: https://en.bitcoin.it/wiki/Scalability#Current_bottlenecks
It used to be 250K and then this year was raised to 1M so it probably will get lifted again. That is the goal of the project, to allow it to scale to at least PayPal numbers (46 transfers per second).
Again, the limit is there to create a market with transaction fees. People jostle for space in the block and a market develops around how much people are willing to pay to get into the next block. It's based on the assumption that miners pick the transactions with the highest fees to include in their blocks, which does happen to a certain degree.
https://www.hackerleague.org/hackathons/hacktx/hacks/proveme with a demo copy @ http://162.242.216.46/
I got the proof server working again so you can play with it.
Try proving data and typing in "testing" (lowercase). It will tell you when we put it in the blockchain. This file should also work: http://s3.amazonaws.com/rapgenius/filepicker%2FvCleswcKTpuRX...
It's a little patchy, but it does work! Payments are fake, and don't do anything! So don't pay! I don't know how much our Bitcoin wallet has left in it. I'll try to remember what we've uploaded so you can try it out.
Bitcoin/crypto code here: https://github.com/wyager/hacktx-proveme
162.242.216.46
Try proving data and typing in "testing" (lowercase). It will tell you when we put it in the blockchain. This file should also work: http://s3.amazonaws.com/rapgenius/filepicker%2FvCleswcKTpuRX...
Here is our bitcoin/crypto stuff. https://github.com/wyager/hacktx-proveme
It's not up to my usual quality because we did it in 24 hours with a sleep break! Please don't judge me on this :p
1) AFAIK, bitcoin has "comments" within transactions. Why not embed the checksum as a comment in a transaction between wallets you control?
2) In the approach described here, no coins are being sent with the transaction (right?). Are blockchain participants really accepting NOP transactions involving 0 BTC transfers. Maybe I missed something.
3) As others pointed out, requiring the whole file to be uploaded is a non-starter for anybody savvy enough to be using this service. Users should be able to directly specify the checksum.
2) Money is sent and is rendered unspendable[2] afterwards, so I assume the idea is to send the smallest amount possible (although it seems the service takes a fee).
[1] https://en.bitcoin.it/wiki/Block#Block_structure [2] http://www.proofofexistence.com/about
2) Coins are being sent. The Developer page says you must send at least 0.00000001 BTC. Edit: actually 500000 Satoshi.
3) Agree. So does the service. See the Developer Page[2]
"Your document will not be uploaded. The cryptographic digest is calculated client-side."
2) 500000 satoshis, as it says on http://www.proofofexistence.com/developers
3) If you are tech savvy, the api lets you send a checksum through a curl to their endpoint. http://www.proofofexistence.com/developers
The problem has been around for a long time, especially when dealing with semi-intangibles like Priority for scientific discoveries, or proof of first invention for patents[1]
One solution is to present proof to a trusted but private notary, who can copy or stamp or otherwise indicate that he has seen your documents and so they must have existed at least since the date indicated.
But counterfeiting, forgery, untrustworthy notaries, etc, all make this a less than ideal solution. So we add computers & crypto.
The document in question is condensed down to a single cryptographic hash, which (should[2]) to all intents and purposes be unique for a given document, despite being only a few tens of characters long, regardless of the size of the original input.
This hash then serves as proof[3] that you have the source document, without anyone being able to turn it back into the original document. This is a very one-way process.
Then, you need to find someone to vouch for your hash and indicate when they first saw it. You can do this with lawyers/notaries again as before[4], which partly solves the forgery problem, but not the trust one.
The solution proposed here is to store that hash in the bitcoin block-chain, which is a distributed log of all transactions on the bitcoin network, which has 3 nice properties:
1. It's append-only. Once your hash is encoded in there, it's staying there as long as bitcoin exists[5].
2. It's peer-to-peer/distributed. There's no single controlling organisation you need to trust for answers.
3. It's updated regularly enough that timestamps can be relatively fine-grained.
So you stuff it in there using this tool or whatever, and then X years hence when you need to prove you'd actually created that file in 2013, you should be able to prove that to most people's satisfaction.
This is a loose take on the matter and glosses over whole swathes of other complexities involved, but is probably close enough for [non]government work :)
[1] That is, who discovered/did something first. You may want to be able to claim you did in future, but without making it public at the time, because you might tip your rivals off to the idea before you've fully developed it. See: https://en.wikipedia.org/wiki/Scientific_priority
[2] Breaking (or "colliding") hashes is a whole subfield of cryptography research, and some pretty impressive things have been done there. It's why you probably shouldn't use MD5 for anything nowadays, for example. But again, we'll handwave "Done Properly = unique identifier".
[3] Well, in the same way that a password proves that you're the/a person who knows that password - if you did it right and never told anyone, it should be exclusively you. But if it leaks somehow, others could represent the hash as belonging to something they own. But if they only have the hash and not the original source document, there are relatively easy tests that could distinguish them. That's not very important here though.
[4] https://en.wikipedia.org/wiki/Trusted_timestamping
[5] well, mostly. But it's really hard, and the same capabilities let you defraud the rest of the bitcoin network with double-spending and whatnot, so unless your timestamp priority is super-important, you're probably ok.
(Just wondering. Not throwing criticism. I actually LOVE this idea!)
I wrote a haiku
to run through a hash function
and send to strangers.
Every time this document is run through a particular function, it returns:> d15396b27a2b176e6315c9fbbec09e2c2e042e595755902e5ff5eccec1ca634b
If I changed a single character of the document, the function would return an entirely different string.
This means it's very, very difficult to come up with another document that returns the same string when run through this same function.
If I sent my string to a bunch of strangers, they wouldn't know what my haiku is. To find it out, they would have to run through every possible document ever written (and that ever could be written) to hope to return the string.
But if someone decided to say they wrote my haiku, I could prove I wrote it first by showing that the document returns the unique string that I sent off to strangers.
What this service provides is a way of making it easy for strangers to store and date these strings for me, because they're doing it anyway when they're using Bitcoins.
This isn't entirely true for some hashes (like MD5). However coming up with another Haiku, in English, that makes sense and has the same hash, is probably close to impossible.
So this probably wouldn't work that well as a service to see who first generated a random string, but works very well if we know something about the structure of the string in question (like that it is in a known human language and makes sense)
It could be used as a form of "poor mans copyright", where people would send a book manuscript, or whatever, to themselves through registered post and keep the envelope intact so they could use it, if need be, in a court. There could be other uses, you could verify that picture was taken when you said it was etc.
What this does is it stores a document's signature into the actual "history" of bitcoins which is public. ANYONE and EVERYONE can access this history of all transactions and by them storing the actual signature of the document into this public "log" you are now able to say that this document DID exist before the specific bitcoin transaction. This removes the hassle of all current methods of proving for existence and now no longer rely on a single third party (which could manipulate it themselves).
They work basically the same way, except that you have to set up your own network. When you want to timestamp something, you (just like this service) hash it together with the previous entry in the system, sign it, and publish that. The proof of the timestamp lies in how you had to look at the previous entry to make it, and the next, at yours. Compromising it would require a large number of participants to cooperate to re-write the history (and the participants' own records).
What this service does is avoid the need to integrate with an existing service or pay any of the record-keeping costs yourself, and it does so by piggy-backing off of bitcoin's distributed timestamp system, thereby making your timestamps at least as valid as bitcoin's, and increasing (significantly) the number of conspirators required to falsify it.
tl;dr: This is just like existing crypto timestamp systems except for the more extreme decentralization and using the bitcoin network's resources.
Your provider stores when you had which IP address. This is used for instance in file sharing processes. At least in Germany it has turned out that this information is unreliable. So you want to log your IP addresses and you want to have a proof of the logs integrity. You could use this service for the purpose.
However, I don't like that I need to upload something. I'd prefer generating and sending the hash and get it signed.
1) Will this have legal weight? I know that the whole "prove paternity of an invention by sending a certified letter containing the design through the mail, and not opening it until you need it" thing doesn't very much work, if it goes to court you tend to be told "OK, what you say is true in the physical universe, but you did not go through our blessed channels, so nyah nyah nyah".
2) Anything that makes bitcoins more legitimate / part of the world's infrastructure decreases the chance of bitcoin going away as a system. I think the idea for the bitcoin community is to make the system as a whole "too big to fail" before governments decide that they want to get rid of it.
I doubt it. If I have to fax something for it to be a legal document, such an antiquated system will ignore any advances made around it.
http://opinionator.blogs.nytimes.com/2010/01/11/the-true-ans...
Any time you introduce evidence, you have to establish its credibility. The first time a signing system like this is used it's likely to take the court some time to understand, but there's no legal doctrine forbidding it.
Source: I am a (not practicing anymore) lawyer.
That's great, but I have to trust you there. For a document that really matters, I don't think I would.
How about a box that allows me to specify my own SHA256 instead?
http://www.proofofexistence.com/developersIn the About, they say that they make 2 undependable dust transactions.
Would there be any incentive for miners to confirm these transactions and store them in the blockchain? If there's no incentive to confirm the transactions, then the miners might find a way to filter these out of the blockchain.
See also dust transactions:
http://bitcoin.stackexchange.com/questions/10986/what-is-mea...
Just trying to think of practical uses of this cool project, and it's the first thing that came to mind.
I think you have that one backwards. You can demonstrate a contract did exist at a certain date. There is no proof of non-existence before that date.
Then again, digital signatures come with a timestamp, Alice could lie about that timestamp, but it would be obvious to Bob that she did.
Fun to think about.
I've also got an idea related to this which involves a global array of satellites in order to add a geo component to this kind of verification..
It would also help certify that a particular person created a document, once again because it was signed by their personal key and included in the blockchain.
It basically functions as a certain timestamp.
my script that does exactly that (not updated, maybe won't work now)
Twitter can remove a single post or turn off their servers and your prove is gone. That's not so easy for a BitCoin transaction. Once it's added to the blockchain it's there for as long as anyone is running a bitcoin node.