US10812274B2 — Transferring ledger assets between blockchains via pegged sidechains
Document text
Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.
US010812274B2
( 12) United
Back et al .
States Patent ( 10 ) Patent No.: US 10,812,274 B2
(45) Date of Patent : Oct. 20 , 2020
( 54 ) TRANSFERRING LEDGER ASSETS ( 58 ) Field of Classification Search
BETWEEN BLOCKCHAINS VIA PEGGED USPC 705/64
SIDECHAINS See application file for complete search history.
( 71 ) Applicant: Blockstream Corporation , Montreal ( 56 ) References Cited
( CA )
U.S. PATENT DOCUMENTS
( 72 ) Inventors: Adam Back , Valletta (MT ) ; Gregory 2016/0098723 A1 * 4/2016 Feeney G06Q 20/4016
Maxwell, Mountain View , CA (US ) ; 705/75
Matt Corallo , New York City, NY 2018/0359096 A1 * 12/2018 Ford HO4L 9/3236
(US ) ; Luke Dashjr, Tampa bay, FL
(US ) ; Mark Friedenbach , San Jose ,
CA (US ); Andrew Poelstra , Austin , TX OTHER PUBLICATIONS
( US ) ; Jorge Timon , San Francisco , CA Andresen , G. , BIP16 : Pay to script hash , Bitcoin Improvement
(US ) ; Pieter Wuille , Mountain View , Proposal, 2012 , https://github.com/bitcoin/bips/blob/master/bip-0016 .
CA (US ) mediawiki.
( 73 ) Assignee: Blockstream Corporation , Montreal ( Continued )
( CA )
Primary Examiner Jacob C. Coppola
( * ) Notice: Subject to any disclaimer, the term of this Assistant Examiner John M Winter
patent is extended or adjusted under 35 ( 74 ) Attorney, Agent, or Firm Dergosits & Noah LLP ;
U.S.C. 154 ( b ) by 829 days . Todd A. Noah
( 21 ) Appl. No .: 15 /150,032 ( 57 ) ABSTRACT
(22 ) Filed : May 9, 2016 Systems and methods are described for transferring an asset
from a parent chain to a sidechain . A simplified payment
(65 ) Prior Publication Data verification ( SPV) proof associated with the parent chain
US 2016/0330034 A1 Nov. 10 , 2016 asset may be generated . The SPV proof may include a
threshold level of work . The SPV proof associated with the
Related U.S. Application Data parent chain asset may be validated, and a sidechain asset
( 60 ) Provisional application No. 62 / 158,432 , filed on May corresponding to the parent chain asset may be generated. If
7 , 2015 . no reorganization proof is detected, the sidechain asset is
released . To redeem the sidechain asset in the parent chain ,
( 51 ) Int . Cl. a SPV proof associated with the sidechain asset may be
G06Q 20/00 ( 2012.01 ) generated . The parent chain may validate the SPV proof
H04L 9/32 ( 2006.01 ) associated with the sidechain asset . The parent chain asset
( Continued ) associated with the sidechain asset may be held for a second
( 52 ) U.S. Ci .
predetermined contest period. The parent chain asset may
then be released if no reorganization proof associated with
CPC H04L 9/3255 (2013.01 ) ; G06Q 20/06 the sidechain asset is detected .
( 2013.01 ) ; G060 20/065 ( 2013.01 );
( Continued ) 13 Claims , 4 Drawing Sheets
100
110 120
:
Best IO SPV - Hockx contpåt 125
Wat out confirmation perind
Wat out contest period 130
135
Send to SPV -lexked output 140
145 Camtasi period begins 150
Contest period ands ( failed) 155
Wait ou cames per 160 170
( latra -chain transfers ) 165
US 10,812,274 B2
Page 2
( 51 ) Int. Ci. 112012 , OP_CHECKCOLORVERIFY: soft - fork for native color
G06Q 20/40 ( 2012.01 ) coin support, 2013 , Bitcoin Talk post , https://bitcointalk.org/index .
G06Q 20/06 ( 2012.01 ) php ? topic = 253385.0.
G06Q 40/00 ( 2012.01) Lamport, L. , Constructing digital signatures from a one -way func
( 52 ) U.S. CI . tion , Tech . Report SRI- CSL - 98, SRI International Computer Sci
CPC GO6Q 20/0655 (2013.01 ) ; G06Q 20/401 ence Laboratory , Oct. 1979 .
(2013.01 ) ; G06Q 40/12 (2013.12 ) Lietear, B. , The future of money, Random House , London , Jan.
2001 .
( 56 ) References Cited Maxwell, G. , Deterministic wallets, 2011 , Bitcoin Talk post , https://
bitcointalk.org/index.php?topic=19137.0 .
Maxwell, G. , User :gmaxwell/ alt ideas, https://en.bitcoin.it/wiki/
OTHER PUBLICATIONS User :Gmaxwell / alt_ideas. Retrieved on Oct. 9 , 2014. , 2014 .
Merkle, R.C. , A digital signature based on a conventional encryp
Andreson, G. , BIP34 : Block v2 , height in coinbase , Bitcoin Improve tion function, Lecture Notes in Computer Science , vol . 293 , 1988 ,
ment Proposal, 2012 , https://github.com/bitcoin/bips/blob/master/ p. 369.
bip -0034.mediawiki. Miller, A. , The high -value -hash highway, 2012 , Bitcoin Talk post,
Aspnes et al ., Exposing computationally -challenged Byzantine impos https://bitcointalk.org/index.php?topic=98986.0.
tors , Tech . Report YALEU /DCS / TR - 1332 , Yale University, 2005 , Miller et al . , Anonymous Byzantine consensus from moderately
http://www.cs.yale.edu/homes/aspnes/papers/tr1332.pdf. hard puzzles : A model for Bitcoin , Tech . Report CS - TR- 14-01 ,
Back, A. , Hashcash a denial of service counter-measure , 2002 , UCF, Apr. 2014 .
http://hashcash.org/papers/hashcash.pdf. Mouton , Y.M., Increasing anonymity in Bitcoin (possible
Back, A. , bitcoins with homomorphic value ( validatable but encrypted ), alternative to Zerocoin ? ) , 2013 , Bitcoin Talk post , https: // bitcointalk .
2013 , BitcoinTalk post , https://bitcointalk.org/Index.php?topic= org / index.php ? topic = 290971.
305791.0 . Maxwell et al . , Output distribution obfuscation, https : //download.
Back, A. , [Bitcoin -development] is there a way to do bitcoin wpsoftware.net/bitcoin/wizardry/brs-arbitrary-output-sizes.txt, 2014 .
staging?, 2013 , Mailing list post , http://sourceforge.net/p/bitcoin Nakamoto , S. , Bitcoin : A peer -to - peer electronic cash system , 2009 ,
mailman /message/315190677. https://www.bitcoin.org/bitcoin.pdf.
Bahack , L. , Theoretical Bitcoin attacks with less than half of the Nolan , T. , Re : Alt chains and atomic transfers, https://bitcointalk.
computational power ( draft ), arXiv preprint arXiv : 1312.7013 ( 2013 ) . org / index.php ? topic = 193281msg2224949 #msg2224949, 2013 .
Ben - Sasson et al . , SNARKs for C : Verifying program executions Poelstra, A. , ASICs and decentralization FAQ , 2014 , https://download .
succinctly and in zero knowledge , Cryptology ePrint Archive, wpsoftware.net/bitcoin/asic-faq.pdf.
Report 2013/507 , 2013 , http://eprint.iacr.org/2013/507. Poelstra , A. , Is there any _true_ anonymous cryptocurrencies ?,
Caldwell, M. , Sustainable nanopayment idea : Probabilistic pay Bitcoin.SE , 2014 , http://bitcoin.stackexchange.com/a/29473.
ments , 2012 , Bitcoin Talk post , https://bitcointalk.org/Index.php ? Poelstra, A. , A treatise on altcoins, 2014 , Unfinished, https: // download.
topic =62558.0. wpsoftware.net/bitcoin/alts.pdf.
Chaum , D. , Blind signatures for untraceable payments, Advances in Pugh, W. , Skip lists : A probabilistic alternative to balanced trees,
Cryptology Proceedings of Crypto 82 ( 1983 ) , No. 3 , 199-203 . Communications of the ACM 33 ( 1990 ) , No. 6 , 668 , ftp : //ftp.cs.
Friedenbach, M. , [ Bitcoin -development] compact SPV proofs via umd.edu/pub/skipLists/skiplists.pdf.
block header commitments, 2014 , Mailing list post, http : // sourceforge. Szabo, N. , The idea of smart contracts, 1997 , https ://nakamotoinstitute .
net / p /bitcoin /mailman /message /321113571. org /the -idea -of- smart - contracts/.
Friedenbach et al . , Freimarkets: extending bitcoin protocol with Todd , P., Fidelity -bonded banks : decentralized , auditable, private ,
user - specified bearer instruments, peer -to - peer exchange, off - chain off - chain payments, 2013 , Bitcoin Talk post , https://bitcointalk.org/
accounting, auctions, derivatives and transitive transactions, 2013 , index.php ? topic = 146307.0.
http://freico.in/docs/freimarkets-v0.0.1.pdf. Van Saberhagen, N. , Cryptonote v 2.0 , https://cryptonote.org/
Gesell , The natural economic order, Peter Owen Ltd. 1958. , Lon whitepaper.pdf, 2013 .
don , 1916 , https://archive.org/details/TheNaturalEconomicOrder. Wuille, P., BIP62 : Dealing with malleability, Bitcoin Improvement
Gerhardt et al . , Homomorphic payment addresses and the pay -to Proposal, 2014 , https://github.com/bitcoin/bips/blob/master/bip-0062.
contract protocol , CORR abs / 1212.3257 ( 2012 ) . mediawiki.
Grigg , I. , Email correspondence, 1999 , http://cryptome.org/jya/
digicrash.htm . * cited by examiner
U.S. Patent Oct. 20 , 2020
9 Sheet 1 of 4 US 10,812,274 B2
oon
110 120
Sen to SPV - locked uutiset 125
130
Wait out contest PETICI
135
Send to SPV -locked output 140
145 Comment period begiris 150
fasilei 155
Wait out otet peris 160
FIG . 1
U.S. Patent Oct. 20 , 2020
9 Sheet 2 of 4 US 10,812,274 B2
200
Validate parent chain asset
210
Generate sidechain asset corresponding to parent chain asset
220
Send sidechain asset to an output of the sidechain
230
Generate a SPV proof associated with the sidechain asset
240
Validate the SPV proof
250
Hold the parent chain asset for a contest period
260
Release the parent chain asset
270
FIG . 2
U.S. Patent Oct. 20 , 2020
9 Sheet 3 of 4 US 10,812,274 B2
300
Generate a blockheader for block of parent chain asset including
a plurality of commitments
310
Store plurality of commitments in a Merkle tree
320
Extract plurality of commitments
330
Check block greater than one link back in plurality of past
headers
340
Verify work amount indicated by blockheader exceeds total
target work
350
FIG . 3
U.S. Patent Oct. 20 , 2020 Sheet 4 of 4 US 10,812,274 B2
400 Remote Devi!ces
Applications
Comunication Interface 412 430
Data
Entry
!
DEnatray 408 Interface Efxteornarl |
DisplayAdapter 410
FIG
.
4
Storage 406
420
Procesor 402
422
414 428
(
ROM
)
416 BIOS 418)RAM( System Operating AplicationPrograms ProgramData
pa
404 424 426
US 10,812,274 B2
1 2
TRANSFERRING LEDGER ASSETS parent chain asset . A sidechain asset may be generated
BETWEEN BLOCKCHAINS VIA PEGGED corresponding to the parent chain asset in response to a
SIDECHAINS receiving, by the sidechain validator server, a request to
transfer the parent chain asset to the sidechain . The
CROSS - REFERENCE TO RELATED 5 sidechain asset may be held for a predetermined contest
APPLICATIONS period , during which the transferring is invalidated if a
reorganization proof associated with the parent chain asset is
This application claims the benefit of U.S. Provisional detected in the parent chain . If no reorganization proof is
Application No. 62/ 158,432 , filed May 7 , 2015 , which is detected , then the sidechain asset may be released . A transfer
incorporated herein in its entirety. 10 of the sidechain asset back to the parent chain may be
performed in substantially the same manner as the symmet
COPYRIGHT NOTICE ric two -way pegging mechanism described above .
In addition to the foregoing, systems and methods for
A portion of the disclosure of this patent document creating and verifying a compressed version of a SPV proof
including any priority documents contains material that is 15 are described . A blockheader is generated for a block of a
subject to copyright protection . The copyright owner has no parent asset , where the blockheader includes a plurality of
objection to the facsimile reproduction by anyone of the commitments . Each commitment may be associated with
patent document or the patent disclosure , as it appears in the one of a plurality of past headers before the blockheader in
Patent and Trademark Office patent file or records , but a block history associated with the parent asset . The plurality
otherwise reserves all copyright rights whatsoever. 20 of commitments of the generated blockheader may be stored
in a Merkle tree . The generated blockheader may be verified
FIELD OF THE INVENTION by extracting the plurality of commitments, and checking a
block greater than one link back in the plurality of past
One or more implementations relate generally to digital headers. Based on the checked block , a work amount
cryptocurrencies, and more specifically to transferring led- 25 indicated by the blockheader may be verified to exceed a
ger assets between blockchains of different currencies using total work target proven by following direct predecessor
pegged sidechains. links of the blockheader, thereby verifying the authenticity
SUMMARY OF THE INVENTION
of the compressed SPV proof.
30 BRIEF DESCRIPTION OF THE DRAWINGS
Systems and methods are described for transferring an
asset from a parent chain to a sidechain . A processor may In the following drawings like reference numbers are used
send a parent chain asset to an output of the parent chain . A to refer to like elements. Although the following figures
simplified payment verification (SPV ) proof associated with depict various examples, the one or more implementations
the parent chain asset may be generated for the output. The 35 are not limited to the examples depicted in the figures.
SPV proof may include a threshold level of work , and the FIG . 1 shows a flow diagram for a symmetric two - way
generating may take place over a predetermined period of pegged transfer from a parent chain to a sidechain, under an
time . A sidechain validator server may validate that the SPV embodiment.
proof associated with the parent chain asset meets the FIG . 2 shows a flow diagram for an asymmetric two -way
threshold level of work indicated by the SPV proof. A 40 pegged transfer from a parent chain to a sidechain, under an
sidechain asset corresponding to the parent chain asset may embodiment.
be generated. The generated sidechain asset may be held for FIG . 3 shows a flow diagram of an exemplary method for
a predetermined contest period, during which the transfer is creating and verifying a compressed version of a simplified
invalidated if a reorganization proof associated with the payment verification ( SPV) proof in accordance with vari
parent chain asset is detected in the parent chain . If no 45 ous embodiments of the present invention .
reorganization proof is detected , the sidechain asset may be FIG . 4 is a block diagram of an exemplary system used in
released . a transfer between a parent chain and a pegged sidechain in
To redeem the sidechain asset in the parent chain , the accordance with various embodiments of the present inven
sidechain asset may be sent to an output of the sidechain . A tion .
SPV proof associated with the sidechain asset may be 50
generated. A parent chain validator server may validate the DETAILED DESCRIPTION
SPV proof associated with the sidechain asset . The parent
chain asset associated with the sidechain asset may be held Since the introduction of Bitcoin ( see S. Nakamoto ,
for a second predetermined contest period, during which a Bitcoin : A peer - to - peer electronic cash system , 2009 , https : //
release of the parent chain asset is denied if a reorganization 55 www.bitcoin.org/bitcoin.pdf, incorporated herein by refer
proof associated with the sidechain asset is detected in the ence ) in 2009 , there has been great interest in the potential
sidechain . The parent chain asset may then be released if no of decentralised cryptocurrencies. At the same time , imple
reorganization proof associated with the sidechain asset is mentation changes to the consensus - critical parts of Bitcoin
detected . are handled very conservatively. As a result, Bitcoin has had
The systems and methods described herein simultane- 60 great difficulty in adapting to new demands and accommo
ously allow for easy creation and use of sidechain assets dating new innovation.
while avoiding fragmenting markets and development. In The systems and methods for pegged sidechains described
addition to the foregoing, in various embodiments asym herein allow bitcoins and other ledger assets to be trans
metric two - way pegging may be used to transfer an asset ferred between multiple blockchains . This gives users access
from a parent chain to a sidechain . The sidechain may 65 to new and innovative cryptocurrency systems using the
include a sidechain validator server that monitors transac assets they already own , without requiring the consensus
tions taking place in the parent chain associated with a that Bitcoin does to implement innovative new abilities
US 10,812,274 B2
3 4
( e.g. , regarding security, transferability, etc. ). By being ware.net/bitcoin/asic-faq.pdf, hereby incorporated by refer
linked to Bitcoin's currency via two -way pegs , the separate ence ), it becomes infeasible for a computational minority to
currency systems can more easily interoperate with each change the chain . If the computational minority tries to
other and with Bitcoin , avoiding liquidity shortages and revise the DMMS - secured ledger, they will fall behind and
market fluctuations associated with new currencies. Since 5 be continually unable to catch up to the moving target of the
sidechains are separate currencysystems, technical and eco progressing consensus blockchain .
nomic innovation is not hindered . Despite bidirectional Because the miners do not form an identifiable set , they
transferability between Bitcoin and pegged sidechains , the cannot have discretion over the rules determining transac
blockchains of Bitcoin and the pegged sidechain are iso tion validity . Therefore, new valid transaction forms cannot
lated . This means that, in the case of a cryptographic break 10 be added except with the agreement of every network
( or malicious design ) in a pegged sidechain , the damage participant. Even with such an agreement, changes are
would be entirely confined to the sidechain itself. This difficult to deploy because they require all participants to
application describes out pegged sidechains, their imple implement and execute the new rules in exactly the same
mentation requirements, and the work needed to fully ben way, including edge cases and unexpected interactions with
efit from the future of interconnected blockchains. 15 other features. Over a large -scale system such as that of
A coin , or asset, is a digital property whose controller can Bitcoin , making changes to the rules determining transaction
be cryptographically ascertained . Bitcoin generally tracks validity may be difficult. Weaknesses in the implementation
asset transfers by aggregating them into blocks , which may of Bitcoin have been identified , including :
be a collection of transactions describing changes in asset Inability to customize trade - offs between scalability and
control. Each block may be linked to an associated block- 20 decentralization : for example , a larger block size would
header, which cryptographically commits to : the contents of allow the network to support a higher transaction rate,
the block , a timestamp, and the previous blockheader. A at the cost of placing more work on validators a
cryptographical “ commitment ” is a cryptographic object centralisation risk . Similarly , there are trade - offs
which is computed from some secret data such that the data between security and cost . Bitcoin stores every trans
cannot be changed after the fact, where the object does not 25 action in its history with the same level of irreversibil
reveal the secret data . An example of a commitment is a ity. This is expensive to maintain and may not be
hash : given data x , one can publish H ( x ) where H is a hash appropriate for low value or low - risk transactions (e.g.
function , and only later reveals x (e.g. , by using a hash where all parties already have shared legal infrastruc
table) ture in place to handle fraud ). These trade - offs should
Verifiers can confirm that the revealed value is the same 30 be made for each transaction , as transactions vary
as the original value by computing H ( x ) themselves. The widely in value and risk profile . However, Bitcoin by
blockheader commitments to previous headers form a block construction supports only a " one size fits all ” solution .
chain (or “ chain ) , which provides a well- defined ordering for Inability to customize blockchain features : for example,
transactions . A blockchain is a well- ordered (i.e. , each subset Bitcoin's script could be more powerful to enable
of the blockchain has a least element in the ordering ) 35 succinct and useful contracts, or could be made less
collection of blocks , on which all users must ( eventually ) powerful to assist in auditability.
come to consensus. This determines the history of asset Inability to trade assets other than bitcoins on block
control and provides a computationally unforgeable time chains : IOUS and other contracts, as well as smart
ordering for transactions. property ( see , e.g. , N. Szabo, The idea of smart con
Bitcoin's blockheaders can be regarded as an example of 40 tracts, 1997, http://szabo.best.vwh.net/idea.html,
a dynamic membership multi -party signature ( or DMMS ) , a hereby incorporated by reference ) could be traded on
new type of group signature. A DMMS is a digital signature blockchains, but may not be done under the current
formed by a set of signers which has no fixed size . Bitcoin's Bitcoin infrastructure .
blockheaders are DMMSes because their proof -of -work has Risk of monoculture : Bitcoin is composed of many cryp
the property that anyone can contribute with no enrollment 45 tographic components , any one of whose failures could
process . Further, contribution is weighted by computational cause a total loss of value . If possible , it would be
power rather than one threshold signature contribution per desirable not to secure every bitcoin with the same set
party, which allows anonymous membership without risk of of algorithms.
a Sybil attack ( when one party joins many times and has Inability to implement new features not imagined when
disproportionate input into the signature ), because limita- 50 Bitcoin was first developed: For example, privacy and
tions in computational power. censorship -resistance could be improved by use of
Because the blocks are chained together, Bitcoin's cryptographic accumulators ( see Y. M. Mouton ,
DMMS is cumulative: any chain ( or chain fragment) of Increasing anonymity in Bitcoin ... (possible alterna
blockheaders is also a DMMS on its first block , with tive to Zerocoin ? ), 2013 , BitcoinTalk post , https : //
computational strength equal to the sum of the strengths of 55 bitcointalk.org/index.php?topic=290971., hereby
the DMMSes it is composed of. Because signers prove incorporated by reference ), ring signatures ( see N. van
computational work , rather than proving secret knowledge Saberhagen, Cryptonote v 2.0 , https://cryptonote.org/
as is typical for digital signatures, they may be referred to whitepaper.pdf, 2013 , hereby incorporated by refer
herein as miners . To achieve stable consensus on the block ence ), or Chaumian blinding ( see D. Chaum , Blind
chain history, economic incentives are provided where min- 60 signatures for untraceable payments, Advances in
ers are rewarded with fees and subsidies in the form of coins Cryptology, Proceedings of Crypto 82 ( 1983 ) , no . 3 ,
( e.g. bitcoins ) that are valuable only if the miners form a 199-203 , hereby incorporated by reference ).
shared valid history, incentivising the miners to behave Lack of safe upgrade path for Bitcoin, in the sense that all
honestly. Because the strength of Bitcoin's cumulative participants must act in concert for any change to be
DMMS is directly proportional to the total computational 65 effected : There is consensus amongst Bitcoin develop
power contributed by all miners ( see A. Poelstra, ASICs and ers that changes to Bitcoin must be done slowly,
decentralization FAQ, 2014 , https ://download.wpsoft cautiously , and only with clear assent from the com
US 10,812,274 B2
5 6
munity. The fact that functionality must be broadly ments herein use bitcoin as an examplery parent blockchain ,
acceptable to gain adoption limits participants' per because its strong network effects make it likely that users
sonal freedom and autonomy over their own coins . will prefer it over other, newer assets . However, any altcoin
Small groups are unable to implement features, such as can be adapted to be usable with pegged sidechains.
special -purpose script extensions ( see j12012,5 The pegged sidechains allow assets that are moved
OP_CHECKCOLORVERIFY: soft fork for native color between sidechains to be moved back by whomever the
coin support, 2013 , Bitcoin Talk post , https://bitcoin assets ' current holder is , and nobody else ( including previ
talk.org/index.php?topic=253385.0 , hereby incorpo ous holders ). A sidechain is a blockchain that validates data
rated by reference ), because they lack broad consensus . from other blockchains. A pegged sidechain is a sidechain
An early solution to these problems with Bitcoin has been 10 whose assets can be imported from and returned to other
the development of alternate blockchains, or altchains , chains. An exemplary mechanism for moving assets to and
which share the Bitcoin codebase except for modifications to from a pegged sidechain is a two -way peg , which allows
address the above concerns . However, implementing tech assets to be transferred to and from sidechains at a fixed or
nical changes through the creation of independent but essen otherwise deterministic exchange rate .
tially similar systems is problematic. One problem is infra- 15 Pegged sidechains also allow assets to be moved without
structure fragmentation : because each altchain uses its own counterparty risk ; that is , dishonest parties are precluded
technology stack , effort is frequently duplicated and lost from preventing the transfer to occur. Transfers using the
across different altchains . Because of this, and because pegged sidechains are atomic ; the transfer either happens
implementers of altchains may fail to clear the very high entirely, or not at all . Another benefit of using pegged
barrier of security -specific domain knowledge in Bitcoin, 20 sidechains is avoidance of failure modes that result in loss or
security problems may be duplicated across altchains while permit fraudulent creation of assets . Pegged sidechains may,
their fixes are not. Substantial resources must be spent to provide further security, be firewalled, meaning a bug in
finding or building the expertise to review novel distributed one sidechain enabling creation ( or theft) of assets in that
cryptosystems, but when they are not, security weaknesses sidechain does not result in creation or theft of assets on any
are often invisible until they are exploited. As a result, a 25 other sidechain .
volatile , un -navigable environment may develop , where the A reorganization, or reorg, occurs locally in clients when
most visible projects may be the least technically sound . As a previously accepted cryptocurrency blockchain is over
an analogy, imagine an Internet where every website used its taken by a competitor blockchain with more proof of work ,
own TCP implementation , advertising its customized check causing any blocks on the losing side of the fork to be
sum and packetsplicing algorithms to end users . This would 30 removed from consensus history. Blockchain reorganisa
not be a viable environment, and neither is the conventional tions within a pegged side chain may be handled cleanly,
environment of altchains . even during transfers. That is , any disruption may be local
A second problem is that such altchains , like Bitcoin , ized to the sidechain on which it occurs , and would not affect
typically have their own native cryptocurrency, or altcoin , the parent chain . In general, sidechains may be fully inde
with a floating price . To access the altchain, users must use 35 pendent, with users providing any necessary data from other
a market to obtain this currency , exposing them to the high chains. Validators of a sidechain may only be required to
risk and volatility associated with new currencies . Further, track another chain if the tracking is an explicit consensus
the requirement to independently solve the problems of rule of the sidechain itself. Finally , users of a sidechain may
initial distribution and valuation, while at the same time not be required to track sidechains that they are not actively
contending with adverse network effects and a crowded 40 using.
market, discourages technical innovation while at the same Assets are transferred to the pegged sidechains by pro
time encouraging market games. This is dangerous not only viding proofs of possession in the transferring transactions
to those directly participating in these systems , but also to themselves, avoiding the need for nodes to track the sending
the cryptocurrency industry as a whole . If the field is seen as chain . On a high level, when moving assets from one
too risky by the public , adoption may be hampered, or 45 blockchain to another, a transaction is created on the first
cryptocurrencies might be deserted entirely ( voluntarily or blockchain locking the assets . A transaction is also created
legislatively ) . on the second blockchain whose inputs include a crypto
It would be desirable to have interoperable altchains that graphic proof that the lock transaction on the first blockchain
may be easily created and used , but without unnecessarily was done correctly . These inputs are tagged with an asset
fragmenting markets and development. An early solution 50 type, e.g. the genesis hash of the asset's originating block
was to “ transfer” coins by destroying bitcoins in a publicly chain .
recognisable way, which would be detected by a new A simplified payment verification proof ( or SPV proof) is
blockchain to allow creation of new coins . This is a partial an example of a proof of possession used to transfer assets
solution to the problems listed above , but since it allows to a pegged sidechain . A SPV proof may be a DMMS
only unidirectional transfers between chains, without allow- 55 showing that an action occurred on a Bitcoin -like proof -of
ing for an asset to be returned to the parent chain, lacks work blockchain . “ Proof-of-work ” refers to how the rules of
flexibility. a chain, which may be part of a blockchain's definition,
The present invention describes such interoperable block define how work in that chain is measured . To verify a SPV
chains, which are referred to as " pegged sidechains . ” The proof for a particular chain, a verifier must know and
pegged sidechains described herein may simultaneously 60 understand the chain's rules about how work is generated.
achieve the seemingly contradictory goals of easy creation Nodes in the network may continually perform work to
and use while avoiding fragmenting markets and develop create blocks in a chain . In an embodiment, a SPV proof may
ment. The core observation is that “ Bitcoin ” the blockchain include (a ) a list of blockheaders demonstrating proof -of
is conceptually independent from “ bitcoin ” the asset : by work , and (b ) a cryptographic proof that an output was
supporting the movement of assets between blockchains, 65 created in one of the blocks in the list . Such SPV proofs may
new systems may be developed which users could adopt by allow verifiers to check that some amount of work has been
simply reusing the existing bitcoin currency. While embodi committed to the existence of an output. Such a proof may
US 10,812,274 B2
7 8
be invalidated by another proof demonstrating the existence tion . Furthermore, because sidechains transfer existing
of a chain with more work which does not include the block assets from the parent chain rather than creating new ones ,
which created the output , thereby exposing fraudulent trans sidechains cannot cause unauthorized creation of coins ,
fers. relying instead on the parent chain to maintain the security
Using SPV proofs to determine history, implicitly trusting 5 and scarcity of its assets . Of course , sidechains are able to
that the longest blockchain is also the longest correct block support their own assets , which the sidechains are respon
chain , may be done by SPV clients in Bitcoin . That is , if a sible for maintaining the scarcity thereof. However,
rule -violating ( " dishonest " ) participant produces an invalid sidechains can only affect the scarcity of themselves and
block or a fork in the past history of the chain , the honest their child chains , not of the parent chain .
participants will ignore it and continue to mine the entirely 10 Further still , using pegged sidechains , participants do not
valid chain with the most work . If the dishonest party has need to be as concerned that their holdings are locked in a
less than 50 % of the total work producing capacity (“ hash single experimental altchain , since sidechain coins can be
power ”) of the network as a whole, then the invalid block redeemed for an equal number of parent chain coins . This
fork will fall hopelessly behind, resulting in a shorter provides an exit strategy, reducing harm from unmaintained
blockchain than the valid chain . Accordingly, only a dis- 15 software and / or sidechains . On the other hand, because
honest collusion with greater than 50 % of the hashpower can sidechains are still blockchains independent of Bitcoin, they
persistently fool an SPV client ( unless the client is under a are free to experiment with new transaction designs, trust
long -term Sybil attack , preventing it from seeing the actual models, economic models , asset issuance semantics , or
longest chain ), since the honest hashpower will not contrib cryptographic features .
ute work to an invalid chain . This improves performance, as 20 An additional benefit to this infrastructure is that making
a verifier that cannot check all of the rules, can make an changes to a parent blockchain (e.g. , Bitcoin ) itself becomes
assumption that the chain with the most work is valid (at much less pressing. Rather than orchestrating a fork which
least beyond the most recent tip , which could be invalid all parties need to agree on and implement in tandem , a new
because the honest participants have not eclipsed any inva " changed Bitcoin ” could be created as a sidechain . If, in the
lidity there yet). 25 medium term , there were wide agreement that the new
In conventional Bitcoin implementations, only the set of system was an improvement, it may end up seeing signifi
unspent transaction outputs (UTXO's ) is needed to deter cantly more use than Bitcoin . As there are no changes to
mine the status of all coins . In an exemplary embodiment, by parent chain consensus rules, everyone can switch in their
requiring each blockheader to commit to the blockchain's own time without any of the risks associated with consensus
unspent output set, anyone in possession of an SPV proof 30 failure. Then, in the longer term , the success of the changes
can determine the state of the chain without needing to in the sidechain would provide the needed confidence to
" replay ” every block . (In conventional Bitcoin implemen change the parent chain, if and when it is deemed necessary
tations , full verifiers need to do this when they first start to do so .
tracking the blockchain .) By constructing a Merkle tree (R. To facilitate an understanding of the subject matter
C. Merkle, A digital signature based on a conventional 35 described below, many aspects are described in terms of
encryption function, Lecture Notes in Computer Science , sequences of actions . At least one of these aspects defined by
vol . 293 , 1988 , p . 369 , hereby incorporated by reference ), the claims is performed by an electronic hardware compo
every element of the UTXO set may be committed using nent. For example, it will be recognized that the various
only a single hash , minimizing the blockheader space used . actions can be performed by specialized circuits or circuitry,
As discussed below , by including some additional data in 40 by program instructions being executed by one or more
Bitcoin's block structure, smaller proofs than a full list of processors, or by a combination of both . The description
headers may be produced, which may improve scalability . herein of any sequence of actions is not intended to imply
Also , in some embodiments, the SPV proofs may not be that the specific order described for performing that
necessary for most transactions; holders of coins on each sequence must be followed . All methods described herein
sidechain may exchange them directly using atomic swaps 45 can be performed in any suitable order unless otherwise
( T. Nolan , Re : Alt chains and atomic transfers, https: // indicated herein or otherwise clearly contradicted by con
bitcointalk.org/ text .
index.php ? topic = 193281.msg2224949 # msg2224949, 2013 , FIG . 1 shows a flow diagram 100 for a symmetric
hereby incorporated by reference ), as described below . two -way pegged transfer from a parent chain 110 to a
The first blockchain may be referred to as the parent 50 sidechain 120 , under an embodiment. In flow 100 , a pro
chain , and the second blockchain may be referred to as the cessor may send a parent chain asset to an output of the
sidechain . In some embodiments, both chains are treated parent chain at step 125. A simplified payment verification
symmetrically, so this terminology should be considered ( SPV) proof associated with the parent chain asset may be
relative. Conceptually, an asset is transferred from the generated for the output. The SPV proof may include a
( original ) parent chain to a sidechain, then again possibly 55 threshold level of work , and the generating may take place
onward to another sidechain, and eventually back to the over a predetermined period of time , which may also be
parent chain , preserving the original asset. In an exemplary referred to as a confirmation period. The confirmation period
embodiment, the parent chain may be Bitcoin and the of a transfer between chains is a duration for which a coin
sidechain as one of many other blockchains. Of course , is locked on the parent chain before it can be transferred to
sidechain coins could be transferred between sidechains, not 60 the sidechain . This confirmation period may allow for suf
just to and from Bitcoin ; however, since any coin originally ficient work to be created such that a denial of service attack
moved from Bitcoin could be moved back , it would none in the next waiting period becomes more difficult . A exem
theless remain a bitcoin . plary typical confirmation period maybe on the order of a
Preservation of the asset within the parent chain advan 1-2 days . The confirmation period may be implemented , in
tageously solves the problem of fragmentation described in 65 an exemplary embodiment, as a per-sidechain security
the previous section, which is beneficial for cryptocurrency parameter, which trades cross - chain transfer speed for
developers who want to focus solely on technical innova greater security.
US 10,812,274 B2
9 10
The output created on the parent chain may be “ special,” In the event of a failure of validation of the second SPV
in that that the rules to spend an asset received by the output proof, after the reorganization proof 150 is received a second
in the future are set with additional conditions , in addition to SPV proof 170 associated with the sidechain asset may be
the rules governing transfer within the parent chain . That is , received and validated by the parent chain 110 during a third
release of assets received by the output are set to depend on 5 predetermined contest period at step 160. The parent chain
rules for verifying a proof from the destination chain, where asset may be released if no reorganization proof associated
the rules for the destination chain proof show that the with the sidechain asset is detected during the third prede
destination chain has released the asset and where the asset termined contest period, after which the parent chain asset is
has been released . After creating the special output on the free to be transferred within the parent chain at step 165 .
parent chain , the user waits out the confirmation period, then 10 Since pegged sidechains may carry assets from many
creates a transaction on the sidechain referencing this output. chains, and cannot make assumptions about the security of
The sidechain , using a sidechain validator server , is provid these chains , it is important, for certain embodiments , that
ing with an SPV proof that shows the parent chain asset was different assets are not interchangeable ( except by an
created and buried under sufficient work on the parent chain . explicit trade ) within the sidechain . Otherwise a malicious
A sidechain validator server may validate that the SPV proof 15 user may execute a theft by creating a worthless chain with
associated with the parent chain asset meets the threshold a worthless asset, move such an asset to a sidechain , and
level of work indicated by the SPV proof at step 130. A exchange it for something else . To combat this, sidechains
sidechain asset corresponding to the parent chain asset may mayeffectively treat assets from separate parent chains as
be generated . separate asset types.
Returning to FIG . 1 , the generated sidechain asset also 20 In a symmetric two - way pegged sidechain transfer, as
may be held for a predetermined contest period at step 130 , described in method 100 , the parent chain and sidechains do
during which the transfer is invalidated if a reorganization SPV validation of data on each other. Since the parent chain
proof associated with the parent chain asset is detected in the clients do not observe every sidechain , users import proofs
parent chain ( see below ) . The contest period is a duration in of work from the sidechain into the parent chain in order to
which a newly - transferred coin may not be spent on the 25 prove possession. In a symmetric two -way peg , the converse
sidechain . The predetermined contest period may advanta is also true .
geously prevent double -spending in the parent chain by To use Bitcoin as the parent chain , an extension to script
transferring previously -locked coins during a reorganiza which can recognize and validate such SPV proofs may be
tion . If at any point during this delay, a new proof ( known used . To facilitate such transactions, the SPV proofs would
as a “ reorganization proof ') is published containing a chain 30 preferably be compact enough to fit in a Bitcoin transaction .
with more aggregate work which does not include the block However, such a change may advantageously be imple
in which the lock output was created, the conversion is mented as a soft - forking change, without effect on transac
retroactively invalidated . If no reorganization proof is tions not involved in pegged sidechain transactions. That is ,
detected, the sidechain asset may be released. All users of using symmetric two -way pegged sidechains as described
the sidechain have an incentive to produce reorganization 35 above , no further restrictions would be made on what is
proofs if possible , as the consequence of a bad proof being valid within Bitcoin .
admitted is a dilution in the value of all sidechain coins . There are several additional advantages to using the
An exemplary typical contest period may also be on the pegged sidechains described herein . On the level of assets ,
order of a 1-2 days . To avoid these delays , users will likely a simple " one chain, one asset” maxim is no longer appli
use atomic swaps ( described below ) for most transfers, as 40 cable . Individual chains may be flexible enough to support
long as a liquid market is available . Once the sidechain asset many assets , even ones that did not exist when the chain was
is released , the side chain asset corresponding to the parent first created . Each of these assets may be labeled with the
chain asset may be transferred within the sidechain one or chain it was transferred from to ensure that their transfers
more times , as indicated at step 135. While locked on the can be unwound correctly.
parent chain , the coin can be freely transferred within the 45 Reorganizations of arbitrary depth are in principle pos
sidechain without further interaction with the parent chain . sible , which could allow an attacker to completely transfer
However, a sidechain asset retains its identity as a parent coins between sidechains before causing a reorganization
chain coin , and may, in some embodiments, only be trans longer than the contest period on the sending chain to undo
ferred back to the same chain from which the sidechain asset its half of the transfer. The result would be an imbalance
originated 50 between the number of coins on the recipient chain and the
To redeem the sidechain asset in the parent chain , the amount of locked output value backing them on the sending
sidechain asset may be sent to an output of the sidechain at chain . If the attacker is allowed to return the transferred
step 140. A SPV proof associated with the sidechain asset coins to the original chain , he would increase the number of
may be generated. A parent chain validator server may coins in his possession at the expense of other users of the
validate the SPV proof associated with the sidechain asset at 55 sidechain . This risk can be made arbitrarily small by, for
step 145. The validating the SPV proof associated with the example, increasing the contest period for transfers. The
sidechain asset may include , for example, validating, by the duration of the contest period could be made a function of
parent validator server, that the SPV proof associated with the relative hashpower of the parent chain and the sidechain :
the sidechain asset meets the threshold level of work indi the recipient chain might only unlock coins given an SPV
cated by the SPV proof associated with the sidechain asset . 60 proof of one day's worth of its own proof -of -work , which
The parent chain asset associated with the sidechain asset might correspond to several days of the sending chain's
also may be held for a second predetermined contest period proof-of -work . Security parameters like these are properties
at step 145 , during which a release of the parent chain asset of the particular sidechain and can be optimised for each
is denied at step 155 if a reorganization proof 150 associated sidechain's application .
with the sidechain asset is detected in the sidechain . The 65 Alternatively, in some embodiments an SPV proof may be
parent chain asset may be released if no reorganization proof created witnessing such a reorganization , and sidechains
150 associated with the sidechain asset is detected . may accept such proofs. The sidechains may be designed to
US 10,812,274 B2
11 12
react in one of many possible ways . For example, the rated by reference) and Back (A. Back, bitcoins with homo
sidechain may have no reaction, resulting in the sidechain morphic value ( validatable but encrypted ), 2013 , Bitcoin
being a “ fractional reserve” of the assets it is storing from Talk post , https://bitcointalk.org/
other chains. This may be acceptable for tiny amounts which index.php ? topic = 305791.0 ., hereby incorporated by
are believed to be less than the number of lost sidechain 5 reference ) which would allow for even greater privacy.
coins , or if an insurer promises to make good on missing Today, ring signatures can be used with Monero coins , but
assets .
Another sidechain response to a reorganization may be notScript bitcoins ; sidechains may avoid this exclusivity.
extensions ( for example, to efficiently support
that the peg and all dependent transactions could be colored coins
reversed . A third sidechain response may be to reduce the 10 fork for native, seecolor j12012, OP_CHECKCOLORVERIFY: soft
coin support, 2013 , BitcoinTalk post ,
amount of all coins , while leaving the exchange rate intact. https://bitcointalk.org/index.php?topic=253385.0 , hereby
Reducing the exchange rate for sidechain coins would be incorporated by reference ) have been proposed for Bitcoin .
equivalent. Many variations on these reactions are also Since such extensions are usable only by a small subset of
possible : for example , temporarily decreasing the exchange
rate so those who “ make a run ” on the sidechain cover the 15 users , but all users would need to deal with the increased
loss of those who don't. complexity and risk of subtle interactions, these extensions
In Bitcoin, a soft - fork is an addition to the Bitcoin have not been accepted into Bitcoin , but could be imple
protocol made backwards compatible by being designed to mented in pegged sidechains . Other suggested script exten
strictly reduce the set of valid transactions or blocks . A sions could include support for new cryptographic primi
soft - fork can be implemented with merely a supermajority 20 tives . For example, Lamport signatures (L. Lamport ,
of the mining computational power participating, rather than Constructing digital signatures from a one -way function ,
all full nodes . However, participants' security with respect to Tech . Report SRI - CSL - 98 , SRI International Computer Sci
the soft - forked features is only SPV -level until they upgrade. ence Laboratory, October 1979 , hereby incorporated by
A two -way peg , implemented in the embodiment reference ), while large , may secure against quantum com
described above , may only have SPV security and may 25 puters.
therefore have greater short - term dependence on miner Since changes like those described above affect only the
honesty than Bitcoin . However, a two -way peg can be transfer of coins , rather than their creation , there is no need
boosted to security absolutely equal to Bitcoin's if all full for them to require a separate currency . With sidechains ,
nodes on both systems inspect each other's chain and users can safely and temporarily experiment with such
demand mutual validity as a soft- forking rule. 30 changes. This encourages adoption for the sidechain , and is
A negative consequence of this would be loss of isolation less risky for participants relative to using an entirely
of any soft - fork - required sidechain . Since isolation was one separate altcoin , as conventionally done.
of the goals of using pegged sidechains , this may be unde Other experimentation may be performed in sidechains
sirable unless a sidechain was almost universally used . with economic incentives . For example, Bitcoin's reward
Absent pegged sidechains , however, the next alternative 35 structure assigns new coins to miners. This effectively
would be to deploy individual changes as hard- or soft- forks inflates the currency but it winds down over time according
in Bitcoin directly. This is even more abrupt, and provides to a step - wise schedule . In a demurring cryptocurrency, by
no real mechanism for the new facility to prove its maturity contrast, all unspent outputs lose value over time , with the
and demand before risking Bitcoin's consensus on it . lost value being recollected by miners . This keeps the
There are many improvements to cryptocurrencies that 40 currency supply stable while still rewarding miners. It may
may be provided by using the pegged sidechains described be better aligned with user interests than inflation because
above . By using a sidechain which carries bitcoins rather loss to demurrage is enacted uniformly everywhere and
than a completely new currency, one can avoid the thorny instantaneously, unlike inflation ; it also mitigates the possi
problems of initial distribution and market vulnerability, as bility of long -unspent “ lost ” coins being reanimated at their
well as barriers to adoption for new users , who no longer 45 current valuation and shocking the economy, which is a
need to locate a trustworthy marketplace or invest in mining perceived risk in Bitcoin . Demurrage creates incentives to
hardware to obtain sidechain assets . increase monetary velocity and lower interest rates , which
Because sidechains are technically still fully - independent are considered to be socially beneficial. In pegged
chains, they are able to change features of Bitcoin such as sidechains , demurrage allows miners to be paid in existing
block structure or transaction chaining. For example, by 50 already valued currency. Other economic changes include
fixing undesired transaction malleability, protocols which required miner fees , transaction reversibility, outputs which
involve chains of unconfirmed transactions can be executed are simply deleted once they reach a certain age , or inflation /
safely . Transaction malleability is a problem in Bitcoin demurrage rates pegged to events outside of the sidechain .
which allows arbitrary users to tweak transaction data in a All of these changes are difficult to do safely in Bitcoin , but
way that breaks any later transactions which depend on 55 the ease of creation and reduced risk of sidechains provide
them , even though the actual content of the transaction is the necessary environment for them to be viable .
unchanged. It is possible for sidechains to produce their own tokens ,
Also , improved payer privacy (e.g. the ring signature or issued assets, which carry their own semantics . These can
scheme used by Monero ) can reduce the systemic risk of the be transferred to other sidechains and traded for other assets
transactions of particular parties being censored , protecting 60 and currencies, all without trusting a central party, even if a
the fungibility of the cryptocurrency . Improvements to this trusted party is needed for future redemption . Issued asset
have been suggested by Maxwell and Poelstra ( G. Maxwell chains may have many applications, including traditional
and A. Poelstra, Output distribution obfuscation , https : // financial instruments such as shares, bonds , vouchers, and
download.wpsoftware.net/bitcoin/wizardry/brs-arbitrary IOUs . This allows external protocols to delegate ownership
output -sizes.txt, 2014 and A. Poelstra, Is there any- 65 and transfer tracking to the sidechain on which the owner
_true_anonymous cryptocurrencies ?, Bitcoin.SE , 2014 , ship shares were issued . Issued asset chains may also
http://bitcoin.stackexchange.com/a/29473, hereby incorpo support more innovative instruments such as smart property.
US 10,812,274 B2
13 14
These technologies can also be used in complementary point if 33 % hashpower of the parent chain can block a
currencies . Examples of complementary currencies include proof, then 67 % is needed to successfully use a false one ,
community currencies , which are designed to preferentially and so on . However, modifications may be made with the
boost local businesses ; business barter associations, which transfer mechanism in accordance with various embodi
support social programs like education or elderly care ; and 5 ments of the present invention to increase attack resistance .
limited -purpose tokens which are used within organizations For example, assurance contracts may be required , such that
such as massive multiplayer games , loyalty programs, and the sidechain's transaction fees are withheld from miners
online communities. unless their hashpower is at least , say, 66 % of that of
A suitably extended scripting system and an asset - aware Bitcoin . These sorts of contracts are easy for a cryptocur
transaction format would allow the creation of useful trans- 10 rency to implement, if they are designed in from the start,
actions from well- audited components, such as the merger of and serve to increase the cost of blocking transfers. Time
a bid and an ask to form an exchange transaction , enabling shifted fees, where miners receive part of their fees in a
the creation of completely trustless peer-to - peer market block far in the future (or spread across many blocks ) so that
places for asset exchange and more complex contracts such they have incentive to keep the chain operational may also
as trustless options ( see M. Friedenbach and J. Timón , 15 be implemented. This may incentivise miners to simply
Freimarkets: extending bitcoin protocol with user - specified receive fees out -of- band, avoiding the need to wait for future
bearer instruments , peer- to -peer exchange, off- chain in - chain rewards . A variation on this scheme is for miners to
accounting, auctions, derivatives and transitive transac receive a token enabling them to mine a low - difficulty block
tions, 2013 , http://freico.in/docs/freimarkets-v0.0.1.pdf, far in the future; this has the same effect, but directly
hereby incorporated by reference ). These contracts could , 20 incentivizes the recipient of the sidechain asset to mine the
for example , help reduce the volatility of bitcoin itself. chain . Demurrage, as previously discussed , or subsidy,
An alternate scheme to the method of FIG . 1 is an where the sidechain issues its own separate native currency
asymmetric two -way peg : here users of the sidechain are full as a reward for mining , may also be implemented in some
validators of the parent chain , and transfers from parent embodiments. Moreover, SNARKs ( see E. Ben - Sasson, A.
chain to sidechain do not require SPV proofs, since all 25 Chiesa , D. Genkin, E. Tromer, and M. Virza, SNARKs for C:
validators are aware of the state of the parent chain . FIG . 2 Verifying program executions succinctly and in zero knowl
shows a method 200 for an asymmetric two - way pegged edge, Cryptology ePrint Archive, Report 2013/507 , 2013 ,
transfer from a parent chain to a sidechain , under an embodi hereby incorporated by reference ) are space - efficient,
ment. quickly verifiable zero -knowledge cryptographic proofs that
At step 210 , a sidechain validator server, may validate a 30 some computation was done. A futuristic idea for a low
parent chain asset in response to receiving, by the sidechain value or experimental sidechain is to invoke a trusted
validator server, a request to transfer the parent chain asset authority , whose only job is to execute a trusted setup for a
to the sidechain . The validating may include determining if SNARK scheme . Then blocks could be constructed which
a proof of work associated with the parent chain asset is prove their changes to the unspent -output set, but do so in
valid , as is described above with respect to Bitcoin . A 35 zero -knowledge in the actual transactions. They could even
sidechain asset corresponding to the parent chain asset is commit to the full verification of all previous blocks , allow
generated in response to determining that the proof of work ing new users to get up to speed by verifying only the single
is valid at step 220. The sidechain asset is then allowed to be latest block . These proofs could also replace the DMMSes
transferred normally within the sidechain system . Having used to move coins from another chain by proving that the
the sidechain validator server be a validator of the parent 40 sending chain is valid according to some rules previously
chain gives a boost in security compared to the symmetric defined .
two -way peg , since now even a 51 % attacker cannot falsely Another way to improve hashpower attack resistance is to
move coins from the parent chain to the sidechain . use co - signed SPV proofs. Signers may be required to sign
Returning the sidechain asset to the parent chain is off on valid SPV proofs, watching for false proofs. This
accomplished using SPV proofs, as described above , in an 45 results in a direct tradeoff between centralization and secu
exemplary embodiment. At step 230 , the sidechain asset is rity against a high -hashpower attack . There is a wide spec
sent to an output of the sidechain in response to a request to trum of trade - offs available in this area : signers may be
transfer the sidechain asset back to the parent chain . A SPV required only for high -value transfers; they may be required
proof associated with the sidechain asset is generated at step only when sidechain hashpower is too small a percentage of
240. A transaction is created on the parent chain referencing 50 Bitcoin’s ; etc.
the output of the sidechain, and the parent chain , via a parent One of the challenges in deploying pegged sidechains is
chain validator server , is provided with the generated SPV that Bitcoin script is currently not expressive enough to
proof. The parent chain may then validate the SPV proof encode the verification rules for an SPV proof. The required
associated with the sidechain at step 250. The parent chain expressiveness could be added in a safe, compatible , and
asset may then be held for a predetermined contest period, 55 highly compartmentalized way (e.g. , by converting a no - op
during which a release of the parent chain asset is denied if instruction into an OP_SIDECHAINPROOFVERIFY in a
a reorganization proof associated with the sidechain asset is soft -fork ). However, the difficulty of building consensus for
detected in the sidechain at step 260. The contest period may and deploying even simple new features is non - trivial.
function as described above . At step 270, the parent chain Fortunately, by adopting some additional security
asset is released if no reorganization proof associated with 60 assumptions at the expense of the low trust design objective,
the sidechain asset is detected . it is possible to do an initial deployment in a completely
The discussion above centers on two -way pegged trans permissionless way. Instead of utilizing SPVs , pegged
fers using SPV proofs, which are forgeable by a 51 % sidechains can be implemented externally by having a
majority of hashpower (as described above ) and blockable trusted federation of mutually distrusting functionaries
by however much hashpower is needed to build a suffi- 65 evaluate the script and accept the script by signing for an
ciently -long proof during the transfer's contest period in the ordinary multisignature script. That is , the functionaries act
exemplary embodiment. There is a tradeoff on this latter as a protocol adaptor by evaluating the same rules we would
US 10,812,274 B2
15 16
have wanted Bitcoin to evaluate , but cannot for lack of script immediately be able to pay into, or receive payments from ,
enhancements. Using this we can achieve a “ federated peg." a user using a federated sidechain .
This approach is very similar to the approach of creating The federated peg approach necessarily compromises on
a multi -signature off -chain transaction system , but the trust, but requires no changes to Bitcoin only the partici
required server- to - server consensus process is provided by 5 pants need to agree to use it and only the participants take
the costs or risks of using it . Further, if someone wanted to
simply observing the blockchains in question. The result is prevent
a deterministic , highly - auditable process which simplifies other people from using a sidechain they could not
the selection and supervision of functionaries . Because of do so : if the federated peg is used privately in a closed
community , its use can be made undetectable and uncen
these similarities, many of the techniques used to improve
security and confidence in off-chain payment systems can be 10 mentation
sorable. Thisandapproach allows
may allow rapid deployment
the community to gainand experi
confidence
employed for federated pegs . For example: functionaries can in pegged sidechains
be geographically diverse , bonded via escrowed coins or Bitcoin protocol. before adopting any changes to the
expensive - to - create coercion - resistant pseudonymous iden Once a sidechain is operational, it is possible for users to
tities, implemented on remote - attesting tamper-resistant 15 exchange coins atomically between chains, without using
hardware, and so on . For small - scale uses , owners of coins the peg . This is important, because as we have seen , direct
in the system can themselves act as the functionaries, thus use of the peg requires fairly large transactions (with cor
avoiding third party trust . respondingly large fees) and long wait periods. To contrast,
Once sidechains with a federated peg are in use , the atomic swaps can be done using only two transactions on
addition of SPV verification to Bitcoin script can be seen as 20 each network, each of size similar to ordinary pay -to -address
merely a security upgrade to reduce the trust required in the transactions.
system . Existing sidechains could simply migrate their coins Suppose we have two parties, A and B , who hold coins on
to the new verification system . This approach also opens different blockchains. Suppose also that they each have
additional security options : the DMMS provided by mining addresses pkA and pkB on the other's chain , and that A has
is not very secure for small systems , while the trust of the 25 a secret number a . Then A can exchange coins for B’s as
federation is riskier for large systems . A sidechain could follows:
adaptively use both of these approaches in parallel, or even 1. On one chain , A creates a transaction moving coins to
switch based on apparent hashrate . an output 01 which can only be redeemed with (a ) a
Consider the example of a sidechain using a 3 of 5 revealing of a and B’s signature , or ( b ) both A and B’s
federation of functionaries to implement a two - way peg with 30 signatures. A does not yet broadcast this . A creates a
Bitcoin . The federation may have secp256k1 public points second transaction returning the coins from 01 to A ,
(public keys) P1 , P2 , P3 , P4 , and P5 and a redeemscript with a locktime of 48 hours (the locktime prevents the
template 3 X X X X X 5 OP_CHECKMULTISIG known to all transaction from being included in the blockchain until
participants in the sidechain . To send coins to a ScriptPub a predetermined timeout has expired ). A passes this
Key SPK , a user who wants the coins to become available 35 transaction to B to be signed. Once B signs the locked
on a sidechain using the federated peg computes a cross refund transaction , A may safely broadcast the trans
chain P2SH address by the following key derivation scheme: action moving coins to 01 , and does so .
2. Similarly, B creates a transaction moving coins to an
output 02 on the other chain , which can only be
Algorithm 1 GenerateCrossChainAddress 40 redeemed by (a ) a revealing of a and A's signature, or
Input: A target ScriptPubKey SPK which will receive the coins in the (b ) both A and B's signatures. B does not yet broadcast
other chain this . B creates a second transaction returning the coins
Input A list { P ; } i- 1 " of the functionaries * public points
Input : A redeemScript template describing the functionary requirements
from O2 to B , with a locktime of 24 hours . B passes this
Output: A P2SH address transaction to A to be signed. Once A signs the locked
Output: Nonce used for this instance 45 refund transaction , B may safely broadcast the trans
1 : nonce random_128bit ( ) action moving his coins to O2 , and does so .
2 : for ia- [1 ,n] do
3 : Tweak;
3. Since A knows a , A is able to spend the coins in O2 , and
HMAC - SHA256 (key = Pi , data nonce | SPK )
=
does so , taking possession of B’s coins . As soon as A
4 : if Tweak; > = secp256k1__order then
5: Go back to start. does so , a is revealed and B becomes able to spend the
6: end if 50 coins in 01 , and does so , taking possession of A’s
7: PCC ; = Pi + G x Tweak; coins .
8 : end for In order to transfer coins from a sidechain back to Bitcoin ,
9 : address – P2SH_Multisig (template ,keys = PCC ) ) embedded proofs (e.g. , the SPVs described above ) showing
that sidechain coins were locked in the Bitcoin blockchain
Algorithm 1 illustrates an exemplary derivation scheme. 55 are utilized . These proofs may contain ( a) a record that an
After generating the address, coins can be paid to the output was created in the sidechain , and (b ) a DMMS
address. A user may connect over a network to a node proving sufficient work on top of this output. Because
participating in the parent chain , and can request the SPV Bitcoin's blockchain is shared and validated by all of its
proof. The user may then later receive the resulting coins on participants , it is preferable that these proofs not impose
the sidechain by providing the functionaries with the nonce, 60 undue burden on the network . Outputs can be easily
ScriptPubKey, and an SPV proof to help them locate the recorded compactly, but DMMS , including a significant
payment in the blockchain . In order to aid third -party block history, are not as easily compressed .
verification of the sidechain , the nonce , the ScriptPubKey, The confidence in an SPV proof can be justified by
and the SPV proof could be included in the sidechain itself. modelling an attacker and the honest network as random
Because the transfer is made by paying to a standard P2SH 65 processes . These random processes have a useful statistical
address and can pay to any ScriptPub Key, all Bitcoin property : while each hash must be less than its target value
services which can pay to a multisignature address may to be valid , half the time it will be less than half the target;
US 10,812,274 B2
17 18
a third of the time it will be less than a third the target; a The compact SPV proof generated by method 300 can
quarter of the time less than a quarter the target; and so on . have a significant size reduction compared to uncompressed
While the hash value itself does not change the amount of SPV proofs. For example , suppose we are trying to produce
work a block is counted as , the presence of lower-than an SPV proof of an entire blockchain of height N. Assume
necessary hashes is in fact statistical evidence of more work 5 for simplicity that difficulty is constant for the chain ; i.e. ,
done in the chain . We can exploit this fact to prove equal every block target is the same . Consider the probability of
amounts of work with only a few block headers . It should finding a large enough proof to skip all the way back to the
therefore be possible to greatly compress a list of headers genesis within x blocks ; that is , between block N - x and
while still proving the same amount of work . We refer to block N. This is one minus the probability we don't , or
such a compressed list as a compact SPV proof or com- 10
pressed DMMS.
However, while the expected work required to produce a X
N-i (1 )
fraudulent compact SPV proof is the same as that for a
non -compact one , a forger's probability of success no longer
1 -
0i = 1 N - i +1
= 1
N -X ?
N
=
?
N
decays exponentially with the amount of work proven : a 15
weak opportunistic attacker has a much higher probability of The expected number of blocks needed to scan back before
succeeding " by chance " ; i.e. , by finding low hashes early . To
illustrate this , suppose such an attacker has 10% of the skipping the remainder of the chain is thus:
network's hashrate , and is trying to create an SPV proof of
1000 blocks before the network has produced this many. 20 N
N +1 (2)
Following the formula in Nakamoto 2009 ( see above for full X
N 2
citation ), the likelihood of success is approximately 10-196 .
By contrast, an attacker in the same time can produce a
single block proving 1000 blocks ' worth of work with Therefore if we want to skip the entire remaining chain in
probability of roughly 10 % , significantly higher. 25
FIG . 3 shows a flow diagram of an exemplary method 300 one jump, we expect to search only halfway; by the same
for creating and verifying a compressed version of a sim argument we expect to skip this half after only a quarter, this
plified payment verification ( SPV) proof in accordance with quarter after only an eighth , and so on . The result is that the
various embodiments of the present invention . expected total proof length is logarithmic in the original
To implement a compressed SPV proof, Bitcoin is modi- 30 length of the chain . For a million- block chain , the expected
fied in an exemplary embodiment so that rather than each proof size for the entire chain is only log2 1000000–20
asset blockheader committing only to the header before it , headers. This brings the DMMS size down into the tens - of
the asset blockheader commits every one of its ancestors kilobytes range , a significant size reduction .
in the blockchain . This may be seen at step 310 of method However, as observed above , if an attacker is able to
300 , where a blockheader is generated for a block of a parent 35 produce compact proofs in which only the revealed headers
chain asset , where the blockheader includes a plurality of are actually mined, he is able to do so with non -negligible
commitments. Each commitment may be associated with probability in the total work being proven . One such strategy
one of a plurality of past headers before the blockheader in is for the attacker to produce invalid blocks in which every
a block history (i.e. a blockchain ) associated with the parent backlink points to the most recent block . Then when extract
asset. The plurality of commitments of the generated block- 40 ing a compact proof, the attacker simply follows the highest
header may be stored in a Merkle tree at step 320 for space weighted link every time .
efficiency . By including only a root hash in each block , we This problem may be addressed in several ways. By
obtain a commitment to every element in the tree , since hash limiting the maximum skip size , we return to Bitcoin's
commitments are transitive . For example, given a hash property that the likelihood of a probabilistic attack decays
function H ( ) that takes input data and returns a commitment, 45 exponentially with the amount of work being proven . The
a tree can be generated based on the commitments . The tree expected proof size is smaller than a full list of headers by
may be generated using the form : H ( H (data1) || H ( data2) a constant (proportional to the maximum skip size ) factor.
-commitment, which outputs a commitment to both datal Alternatively , a maximum skip size may be used that
and data2. The top level commitment may be designated as increases with the amount of work being proven . Such a
the root hash (as it is the base of the tree ), allowing a small 50 dynamic maximum skip size may make it possible to get
piece of data ( e.g. , 32 bytes, 64 bytes, etc ) to commit to an sublinear proof sizes , at the cost of subexponential decay in
arbitrarily large number of items each of arbitrary size . the probability of attack success . This may give greater
When extracting SPV proofs, provers are allowed to use space savings while still forcing a probabilistic attacker's
the plurality of commitments in an asset’s blockheader to likelihood of success low enough to be considered negli
jump back to a block more than one link back in the chain , 55 gible . In another embodiment, interactive approaches or a
provided the work actually proven by the header exceeds the cut - and - choose mechanism may allow compact proofs with
total target work proven by only following direct predeces only a small security reduction . For example , provers might
sor links. The result is a short DMMS which proves just as be required to reveal random committed blockheaders ( and
much work as the original blockchain . This is reflected in their connection to the chain ), using some part of the proof
method 300 , where, to verify the validity of the blockheader, 60 as a random seed (e.g. , by Fiat - Shamir transform ). The root
the plurality of commitments may be extracted ( e.g. from the commitment would be used as a seed to initialize a crypto
Merkle tree) at step 330. A block greater than one link back graphic deterministic random number generator, such as , for
in the plurality of past headers may be checked at step 340 . example , NIST HMAC_DRBG ( See U.S. Dept of Com
Based on the checked block , a verifying server may verify merce , NIST SP 800-90A , January 2012 , hereby incorpo
that a work amount indicated by the blockheader exceeds a 65 rated by reference ). Random values may be drawn from the
total target work proven by following direct predecessor generator and may be used to select parts of the SPV proof
links of the blockheader at step 350 . which must be revealed . Any change to the data in the proof
US 10,812,274 B2
19 20
( e.g. to insert a valid entries where they would otherwise be tines that help to transfer information between elements
caught by the sampling) would change the seed, and then within the computer system , such as during start -up , is
largely change which parts are sampled, causing a forged stored in ROM 416 .
proof to be invalidated . This reduces the probability of The storage 406 may include a flash memory data storage
attack while only increasing proof size by a constant factor. 5 device for reading from and writing to flash memory, a hard
If many transfers per sidechain are expected, a special disk drive for reading from and writing to a hard disk , a
output may be maintained in the parent chain to monitor the magnetic disk drive for reading from or writing to a remov
able magnetic disk , and / or an optical disk drive for reading
sidechain's tip . That is , instead of showing all the work for
a chain associated with an asset, a SPV proof may show only ROM or, DVD
from writing to a removable optical disk such as a CD
the work generated since a known point. The parent chain 10 associated or other optical media . The drives and their
may separately store a counter that remembers the known storage of computer -readable
computer readable media provide nonvolatile
instructions, data structures,
point and how much work was at that point since the start of program modules and other data for the hardware device
the chain . Transfers would reference the known point and 400 .
move it forward , which may result in smaller proofs. This 15 It is noted that the methods described herein can be
parent chain output is moved by separate SPV proofs (which embodied in executable instructions stored in a non -transi
may be compacted in one of the above ways ) , with the result tory computer readable medium for use by or in connection
that the parent chain is aware of a recent sidechain's tip at with an instruction execution machine , apparatus, or device ,
all times . The transfer proofs would , in the embodiment, be such as a computer -based or processor - containing machine,
required to always end at this tip , which can be verified with 20 apparatus, or device. It will be appreciated by those skilled
only a single output lookup . This may ensure verifiers that in the art that for some embodiments , other types of com
there are no “ missing links” in the transfer proofs, so they puter readable media may be used which can store data that
may be logarithmic in size without increased risk of forgery. is accessible by a computer, such as magnetic cassettes, flash
This makes the total cost to the parent chain proportional to memory cards, digital video disks , Bernoulli cartridges,
the number of sidechains and their length ; without this 25 RAM , ROM , and the like may also be used in the exemplary
output, the total cost is also proportional to the number of operating environment. As used here, a " computer - readable
inter - chain transfers . While several solutions have been medium " can include one or more of any suitable media for
discussed , the invention is not limited to these solutions , as storing the executable instructions of a computer program in
any suitable solution optimizing the tradeoffs described one or more of an electronic, magnetic , optical , and elec
above and formalizing the security guarantees may be used . 30 tromagnetic format, such that the instruction execution
FIG . 4 is a block diagram of an exemplary system for machine , system , apparatus, or device can read ( or fetch ) the
providing a pegged sidechain in accordance with various instructions from the computer readable medium and
embodiments of the present invention . With reference to execute the instructions for carrying out the described meth
FIG . 4 , an exemplary system for implementing the subject ods . A non - exhaustive list of conventional exemplary com
matter disclosed herein , including the methods described 35 puter readable medium includes: a portable computer dis
above , includes a hardware device 400 , including a process kette; a RAM ; a ROM ; an erasable programmable read only
ing unit 402 , memory 404 , storage 406 , data entry module memory ( EPROM or flash memory ); optical storage
408 , display adapter 410 , communication interface 412 , and devices, including a portable compact disc (CD ) , a portable
a bus 414 that couples elements 404-412 to the processing digital video disc (DVD ), a high definition DVD (HD
unit 402 . 40 DVDTM ) , a BLU -RAY disc ; and the like .
The bus 414 may comprise any type of bus architecture . A number of program modules may be stored on the
Examples include a memory bus , a peripheral bus , a local storage 406 , ROM 416 or RAM 418 , including an operating
bus , etc. The processing unit 402 is an instruction execution system 422 , one or more applications programs 424 , pro
machine, apparatus, or device and may comprise a micro gram data 426 , and other program modules 428. A user may
processor, a digital signal processor, a graphics processing 45 enter commands and information into the hardware device
unit , an application specific integrated circuit (ASIC ), a field 400 through data entry module 408. Data entry module 408
programmable gate array (FPGA ), etc. The processing unit may include mechanisms such as a keyboard , a touch screen ,
402 may be configured to execute program instructions a pointing device, etc. Other external input devices ( not
stored in memory 404 and / or storage 406 and / or received via shown ) are connected to the hardware device 400 via
data entry module 408 . 50 external data entry interface 430. By way of example and not
The memory 404 may include read only memory ( ROM) limitation, external input devices may include a microphone,
416 and random access memory (RAM ) 418. Memory 404 joystick , game pad, satellite dish , scanner, or the like . In
may be configured to store program instructions and data some embodiments, external input devices may include
during operation of device 400. In various embodiments, video or audio input devices such as a video camera , a still
memory 404 may include any of a variety of memory 55 camera, etc. Data entry module 408 may be configured to
technologies such as static random access memory ( SRAM ) receive input from one or more users of device 400 and to
or dynamic RAM ( DRAM ), including variants such as dual deliver such input to processing unit 402 and / or memory 404
data rate synchronous DRAM (DDR SDRAM ), error cor via bus 414 .
recting code synchronous DRAM ( ECC SDRAM ), or RAM The hardware device 400 may operate in a networked
BUS DRAM (RDRAM ), for example . Memory 404 may 60 environment using logical connections to one or more
also include nonvolatile memory technologies such as non remote nodes (not shown) via communication interface 412 .
volatile flash RAM (NVRAM ) or ROM . In some embodi The remote node may be another computer, a server, a
ments, it is contemplated that memory 404 may include a router, a peer device or other common network node, and
combination of technologies such as the foregoing, as well typically includes many or all of the elements described
as other technologies not specifically mentioned . When the 65 above relative to the hardware device 400. The communi
subject matter is implemented in a computer system , a basic cation interface 412 may interface with a wireless network
input /output system ( BIOS ) 420 , containing the basic rou and / or a wired network . Examples of wireless networks
US 10,812,274 B2
21 22
include , for example , a BLUETOOTH network , a wireless For purposes of the present description , the terms “ com
personal area network , a wireless 802.11 local area network ponent,” “ module , ” and “ process , ” may be used inter
(LAN ), and / or wireless telephony network ( e.g. , a cellular, changeably to refer to a processing unit that performs a
PCS , or GSM network ). Examples of wired networks particular function and that may be implemented through
include , for example, a LAN , a fiber optic network , a wired 5 computer program code ( software ), digital or analog cir
personal area network , a telephony network , and / or a wide cuitry, computer firmware, or any combination thereof.
area network ( WAN ). Such networking environments are It should be noted that the various functions disclosed
commonplace in intranets, the Internet, offices, enterprise herein may be described using any number of combinations
wide computer networks and the like . In some embodiments, of hardware , firmware, and / or as data and / or instructions
communication interface 412 may include logic configured 10 embodied in various machine - readable or computer-read
to support direct memory access (DMA ) transfers between able media , in terms of their behavioral, register transfer,
memory 404 and other devices. logic component, and / or other characteristics. Computer
In a networked environment, program modules depicted readable media in which such formatted data and / or instruc
relative to the hardware device 400 , or portions thereof, may tions may be embodied include , but are not limited to ,
be stored in a remote storage device , such as , for example, 15 physical (non - transitory ), non - volatile storage media in vari
on a server . It will be appreciated that other hardware and / or ous forms, such as optical , magnetic or semiconductor
software to establish a communications link between the storage media .
hardware device 400 and other devices may be used . Unless the context clearly requires otherwise, throughout
It should be understood that the arrangement of hardware the description and the claims , the words " comprise , " " com
device 400 illustrated in FIG . 4 is but one possible imple- 20 prising , " and the like are to be construed in an inclusive
mentation and that other arrangements are possible . It sense as opposed to an exclusive or exhaustive sense ; that is
should also be understood that the various system compo to say , in a sense of “ including, but not limited to .” Words
nents (and means) defined by the claims , described above, using the singular or plural number also include the plural or
and illustrated in the various block diagrams represent singular number respectively. Additionally, the words
logical components that are configured to perform the func- 25 “ herein , ” “ hereunder, ” “ above, ” “ below , " and words of
tionality described herein . For example, one or more of these similar import refer to this application as a whole and not to
system components (and means ) can be realized, in whole or any particular portions of this application . When the word
in part, by at least some of the components illustrated in the “ or ” is used in reference to a list of two or more items, that
arrangement of hardware device 400. In addition , while at word covers all of the following interpretations of the word :
least one of these components are implemented at least 30 any of the items in the list , all of the items in the list and any
partially as an electronic hardware component, and therefore combination of the items in the list .
constitutes a machine , the other components may be imple While one or more implementations have been described
mented in software, hardware, or a combination of software by way of example and in terms of the specific embodi
and hardware. More particularly, at least one component ments, it is to be understood that one or more implementa
defined by the claims is implemented at least partially as an 35 tions are not limited to the disclosed embodiments . To the
electronic hardware component, such as an instruction contrary , it is intended to cover various modifications and
execution machine (e.g. , a processor -based or processor similar arrangements as would be apparent to those skilled
containing machine) and / or as specialized circuits or cir in the art. Therefore , the scope of the appended claims
cuitry ( e.g. , discrete logic gates interconnected to perform a should be accorded the broadest interpretation so as to
specialized function ), such as those illustrated in FIG . 4. 40 encompass all such modifications and similar arrangements.
Other components may be implemented in software , hard What is claimed is :
ware , or a combination of software and hardware . Moreover, 1. A method for transferring an asset from a parent chain
some or all of these other components may be combined , to a sidechain , the method comprising:
some may be omitted altogether, and additional components sending, by a processor, a parent chain asset to an output
can be added while still achieving the functionality 45 of the parent chain ;
described herein . Thus, the subject matter described herein generating, by the processor for the output, a simplified
can be embodied in many different variations, and all such payment verification ( SPV) proof associated with the
variations are contemplated to be within the scope of what parent chain asset , the SPV proof meeting a predeter
is claimed . mined threshold level of computational work , the gen
In the description that follows, the subject matter will be 50 erating taking place over a predetermined period of
described with reference to acts and symbolic representa time ;
tions of operations that are performed by one or more validating, by a sidechain validator server, that the SPV
devices, unless indicated otherwise. As such , it will be proof associated with the parent chain asset meets the
understood that such acts and operations, which are at times threshold level of computational work indicated by the
referred to as being computer -executed , include the manipu- 55 SPV proof;
lation by the processing unit of data in a structured form . generating a sidechain asset corresponding to the parent
This manipulation transforms the data or maintains it at chain asset;
locations in the memory system of the computer, which holding the sidechain asset for a predetermined contest
reconfigures or otherwise alters the operation of the device period ;
in a manner well understood by those skilled in the art. The 60 monitoring the parent chain asset during the predeter
data structures where data is maintained are physical loca mined contest period for any reorganization proofs
tions of the memory that have particular properties defined associated with the parent chain asset ;
by the format of the data . However, while the subject matter releasing the sidechain asset in response to a determina
is being described in the foregoing context, it is not meant tion that no reorganization proof associated with the
to be limiting as those of skill in the art will appreciate that 65 parent chain asset has been created during the prede
various of the acts and operation described hereinafter may termined contest period , the reorganization proof asso
also be implemented in hardware. ciated with the parent chain asset being a published
US 10,812,274 B2
23 24
proof that includes more aggregate work than the SPV validating, by the parent chain , the SPV proof associated
proof associated with the parent chain and does not with the sidechain ;
include a block recording the sending of the parent holding the parent chain asset for a predetermined contest
chain asset to the output of the parent chain ; period ;
sending, by a second processor, the sidechain asset to an 5 monitoring the sidechain asset during the predetermined
output of the sidechain ; contest period for any reorganization proofs associated
generating, by the second processor, a SPV proof asso with the sidechain chain asset , the reorganization proof
ciated with the sidechain asset ; associated with the sidechain asset being a published
validating, by a parent chain validator server, the SPV proof that includes more aggregate work than the SPV
proof associated with the sidechain asset ; 10
proof associated with the sidechain and does not
holding the parent chain asset for a second predetermined include a block recording the sending of the sidechain
contest period; asset to an output of the sidechain ; and
monitoring the sidechain asset during the second prede releasing the parent chain asset in response to a determi
termined contest period for any reorganization proofs
associated with the sidechain chain asset ; and 15 nation that no reorganization proof associated with the
releasing the parent chain asset in response to a determi sidechain asset has been created during the predeter
nation that no reorganization proof associated with the mined contest period .
sidechain asset has been created during the second 10. The method of claim 9 , the generating the sidechain
predetermined contest period . asset further comprising sending the parent chain asset to a
2. The method of claim 1 , the validating the SPV proof 20 federated peg , the federated peg comprising a plurality of
associated with the sidechain asset comprising validating, by functionaries, wherein at least one functionary generates a
the parent validator server, that the SPV proof associated SPV proof associated with the parent chain asset , the SPV
with the sidechain asset meets the threshold level of work proof comprising a threshold level of work , the generating
indicated by the SPV proof associated with the sidechain taking place over a predetermined period of time , the
asset, the method further comprising: 25 method further comprising activating, by a server of the
when release of the parent chain asset is denied , receiving federated peg , the generated sidechain asset in response to
a second SPV proof associated with the sidechain asset; receiving a nonce , a ScriptPubKey, and the generated SPV
validating the second SPV proof associated with the proof, the activating the sidechain asset allowing the
sidechain asset; sidechain asset to be transferred within the sidechain .
holding the parent chain asset for a third predetermined 30 11. The method of claim 10 , wherein the federated peg is
contest period, during which a release of the parent not monitored by blockchains of the parent chain .
chain asset is denied if a reorganization proof associ 12. The method of claim 1 , further comprising:
ated with the sidechain asset is detected in the sending a second parent chain asset to a second output of
sidechain ; and the parent chain ;
releasing the parent chain asset if no reorganization proof 35 generating a SPV proof associated with the second parent
associated with the sidechain asset is detected . chain asset;
3. The method of claim 1 , wherein the predetermined validating, by the sidechain validator server , that the SPV
contest period has a duration that is a function of a relative proof associated with the second parent chain asset
hashpower of the parent chain and the sidechain . meets a threshold of work indicated by the SPV proof
4. The method of claim 1 , wherein the sidechain asset 40 associated with the second parent chain ;
differs from the parent asset in one of block structure and generating a second sidechain asset corresponding to the
transaction chaining . second parent chain asset ;
5. The method of claim 1 , wherein the sidechain asset holding the second sidechain asset for the predetermined
utilizes a ring signature scheme . contest period ; and
6. The method of claim 1 , the sidechain asset further 45 invalidating the transfer of the second sidechain asset in
comprising script extensions not present in the parent chain response to a determination that a reorganization proof
asset. associated with the second parent chain asset has been
7. The method of claim 1 , wherein the sidechain supports created during the predetermined contest period.
demurrage for sidechain assets . 13. The method of claim 9 , further comprising:
8. The method of claim 1 , wherein the sidechain supports 50 validating a second parent chain asset ;
smart property. generating a second sidechain asset corresponding to the
9. A method for transferring an asset from a parent chain second parent chain asset in response to validating the
to a sidechain , the method comprising: second parent chain asset ;
validating, by a sidechain validator server, a parent chain sending the second sidechain asset to a second output of
asset in response to receiving , by the sidechain valida- 55 the sidechain in response to a request to transfer the
tor server, a request to transfer the parent chain asset to second sidechain asset back to the parent chain ;
the sidechain , the validating comprising determining if generating a SPV proof associated with the second
a proof of work associated with the parent chain asset sidechain asset;
is valid; validating the SPV proof associated with the second
generating a sidechain asset corresponding to the parent 60 sidechain asset;
chain asset in response to determining that the proof of holding the second parent chain asset for the predeter
work is valid ; mined contest period ;
sending the sidechain asset to an output of the sidechain monitoring the second sidechain asset during the prede
in response to a request to transfer the sidechain asset termined contest period for any reorganization proofs
back to the parent chain ; 65 associated with the second sidechain asset ; and
generating a simplified payment verification (SPV ) proof denying release of the second parent chain asset in
associated with the sidechain asset; response to a determination that a reorganization proof
US 10,812,274 B2
25 26
associated with the second sidechain asset has been
created during the predetermined contest period .