IP Library › Granted Patent US 12,386,727
Granted Patent B2
US 12,386,727 · App. 18/144,714 · Granted Aug 12, 2025

Method and apparatus for bug bounty system for blockchain

Inventors: Kaiho Fukuchi (Santa Clara, CA); Takayuki Suzuki (Cupertino, CA); Takatoshi Ohara (Cupertino, CA); Shin Tezuka (Campbell, CA); Nobutaka Kawaguchi (Santa Clara, CA); Ken Naganuma (Campbell, CA)
Assignee: HITACHI, Ltd.
G06F11/3636G06F11/362
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,727
App. No.
18/144,714
Granted
Aug 12, 2025
Kind
B2
Abstract

Example implementations provide a blockchain-based bug bounty platform/system for discovering system vulnerability. To prevent attack method from becoming public, the attack and test are performed in the attacker's (end-user's) private blockchain (BC) environment, and the confidential computing technology provides proof of testing. The amount of the reward awarded may vary based on the rarity of the vulnerability discovered. The feature values of current transactions are extracted and compared against features values of prior transactions to determine vulnerabilities and associated rewards.

Claims (59)

1. A bug bounty generation system, the system comprising:

a plurality of nodes;

a private blockchain system being set in a first node of the plurality of nodes, wherein the first node is a private blockchain node, and the private blockchain system comprises:

a first processor configured to:

receive a transaction for execution in runtime for bug detection, and

monitor the transaction in the runtime and extract features of the transaction to output first feature values; and

an external system in communication with the private blockchain system, the external system comprises:

a second processor configured to:

extract features of past transactions stored in nodes other than the first node of the plurality of nodes and outputs second feature values; and

generate a bounty information corresponding to a bug alert in the transaction, wherein the bounty information is generated based on (i) a degree of similarity between the first feature values and the second feature values by comparing the first feature values with the second feature values; and (ii) rarity, basicity, and scale of damage of a bug detected in the transaction,

wherein the second processor instructs payment of bounty based on the bounty information, and

wherein the nodes other than the first node of the plurality of nodes are physical blockchain nodes,

wherein the first processor generate a test report to the external system.

2. The system of claim 1 , wherein the external system exists on a server.

3. The system of claim 1 , wherein the nodes other than the first node of the plurality of nodes together form a blockchain network.

4. The system of claim 1 , wherein the private blockchain system is downloaded and executed on a confidential computing environment of a user device.

5. The system of claim 1 , wherein the transaction is an arbitrary transaction for testing a smart contract.

6. The system of claim 1 , wherein

the test report comprises the first feature values and proof of verification.

7. The system of claim 6 ,

wherein the private blockchain system further stores potential vulnerability information;

wherein the runtime determines whether a state of the runtime changed by the transaction by the first processor matches any state identified in the potential vulnerability information;

wherein, for the state of the runtime matching any state identified in the potential vulnerability information, including the state of the runtime in the test report; and

wherein the second processor instructs payment of an additional bounty based on the state of runtime included in the test report.

8. The system of claim 1 , wherein the bounty information is generated by comparing the first feature values with the second feature values through the second processor being further configured to:

compare the first feature values with the second feature values to determine a number of similar attacks associated with the past transactions; and

generate and adjust the bounty information based on the number of similar attacks associated with the past transactions.

9. The system of claim 1 , wherein the external system further comprises:

a database for storing known bugs of the bug bounty generation system and feature values associated with the known bugs;

the second processor is further configured to compare the first feature values against the feature values associated with the known bugs; and

for the first feature values matching third feature values associated with a known bug of the known bugs, the second processor is further configured to generate a second bounty information and instructing payment of bounty based on the second bounty information to discoverer of the known bug associated with the third feature values.

10. A method for generating blockchain bug bounty, the method comprising:

performing, by a first processor, bug detection by issuing a transaction for execution in runtime of a private blockchain system, wherein the private blockchain system is set in a first node of a plurality of nodes, and the first node is a private blockchain node;

monitoring the transaction in the runtime and outputting first feature values associated with the transaction, wherein the first feature values are generated by performing feature extraction on the transaction;

communicating with an external system, wherein the external system performs:

receiving, by a second processor, the first feature values;

extracting, by the second processor, features of past transactions stored in nodes other than the first node of the plurality of nodes and outputting second feature values associated with the past transactions;

generating, by the second processor, bounty information corresponding to a bug alert in the transaction, wherein the bounty information is generated based on (i) a degree of similarity between the first feature values and the second feature values by comparing the first feature values with the second feature values, and (ii) rarity, basicity, and scale of damage of a bug detected in the transaction; and

instructing, by the second processor, payment of bounty based on the bounty information,

wherein the nodes other than the first node of the plurality of nodes are physical blockchain nodes,

wherein the first processor generate a test report to the external system.

11. The method of claim 10 , wherein the external system exists on a server.

12. The method of claim 10 , wherein the nodes other than the first node of the plurality of nodes together form a blockchain network.

13. The method of claim 10 , wherein the private blockchain system is downloaded and executed on a confidential computing environment of a user device.

14. The method of claim 10 , wherein the transaction is an arbitrary transaction for testing a smart contract.

15. The method of claim 10 , wherein

the test report comprises the first feature values and proof of verification; and.

16. The method of claim 15 , further comprising:

storing, by the private blockchain system, potential vulnerability information;

determining, by the first processor, whether a state of the runtime of the transaction matches any state identified in the potential vulnerability information;

for the state of the runtime matching any state identified in the potential vulnerability information, including the state of the runtime in the test report; and

instructing, by the second processor, payment of an additional bounty based on the state of the runtime included in the test report.

17. The method of claim 10 , wherein the bounty information is generated by comparing the first feature values with the second feature values through a process comprising:

comparing, by the second processor, the first feature values with the second feature values to determine a number of similar attacks associated with the past transactions; and

generating and adjusting, by the second processor, the bounty information based on the number of similar attacks associated with the past transactions.

18. The method of claim 10 , further comprising:

storing known bugs and feature values associated with the known bugs in a database;

comparing, by the second processor, the first feature values against the feature values associated with the known bugs; and

for the first feature values matching third feature values associated with a known bug of the known bugs, generating, by the second processor, a second bounty information and instructing payment of bounty based on the second bounty information to discoverer of the known bug associated with the third feature values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2023
From: FUKUCHI, KAIHO; SUZUKI, TAKAYUKI; OHARA, TAKATOSHI; TEZUKA, SHIN; KAWAGUCHI, NOBUTAKA; NAGANUMA, KEN
To: HITACHI, LTD.
Reel/Frame 063578/0938 →
Continuity (1)
Related Publication 20240378284A1 · Nov 14, 2024
References Cited (18)
US 5911041A · Schaffer · 1999 [cited by examiner]
US 7587709B2 · Chilimbi · 2009 [cited by examiner]
US 7971190B2 · Davies · 2011 [cited by examiner]
US 9015847B1 · Kaplan · 2015 [cited by examiner]
US 9223978B2 · Kraemer · 2015 [cited by examiner]
US 9413780B1 · Kaplan · 2016 [cited by examiner]
US 10771239B2 · Nandakumar · 2020 [cited by examiner]
US 11489854B2 · Dumont et al. · 2022 [cited by applicant]
US 11645188B1 · Azad · 2023 [cited by examiner]
US 11748232B2 · Muras · 2023 [cited by examiner]
US 20200027089A1 · Kuchar · 2020 [cited by examiner]
US 20220318399A1 · Rodler · 2022 [cited by examiner]
US 20230019180A1 · de Nijs · 2023 [cited by examiner]
Hasnaoui et al, “Beyond the Bug Bounty Programs Trilemma: Bounty 3.0's Blockchain-ZKP Approach”, IEEE, pp. 663-668 (Year: 2023). [cited by examiner]
Badash et al, “Blockchain-based Bug Bounty Framework”, ACM, pp. 239-248 (Year: 2021). [cited by examiner]
Breidenbach et al, “The Hydra Framework for Principled, Automated Bug Bounties”, IEEE, pp. 1-9 (Year: 2019). [cited by examiner]
Yi et al, “An Empirical Study of Blockchain System Vulnerabilities: Modules, Types, and Patterns”, ACM, pp. 1-13 (Year: 2022). [cited by examiner]
Ding et al, “Ethical Hacking for Boosting IoT Vulnerability Management: A First Look into Bug Bounty Programs and Responsible Disclosure”, ACM, pp. 1-7 (Year: 2019). [cited by examiner]