Open Source Immutable Database – Dennis Zimmer, Codenotary
Codenotary CTO Dennis Zimmer explains why there is a need for an open source immutable database that as an alternative to blockchain platforms will better secure software supply chains.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Dennis Zimmer. Who's CTO for code? Notary we're talking about immutable databases and use cases for that and especially how they might apply in the land of application development and a lot of the issues that we're seeing in that context as well Dennis.
Welcome to the show. Thank you very much Micah pleasure to be here. Every time anybody hears the word immutable database they immediately think about blockchain but you guys are not blockchain based at all.
So maybe walk us through a little bit exactly what you guys do. And how did you guys come up with a database that's immutable because it's been a problem for a long time. Yeah, absolutely.
And I'm typically I start with a joke that it immutable database would be empty forever. But in our case so that every data point that is being written to the database will be immutably written to it. So you cannot change or template afterwards without everybody else complaining about change in Tampa data and that makes database verifiable.
So what we deliver is an open source immutable database that is so called client verifiable. So you don't need to trust the database itself. You can always have a local state or any application can hold a state of the immutable database and this state is changing with every new entry that you at to the data base.
And that means that every client automatically can follow the cryptographic verification. And why that sounds a bit complex. The benefits are performance.
So when you think of a distributed Ledger Tech or a blockchain most people call, it means that the typically the consensus is being calculated by all the notes in the backend. And that means the transactions are automatically slowed down because all the consensus needs to be built and needs to be at least 51% of course all the notes in the backend in our case. The clients do the verification with every communication step.
And the database itself is extremely fast because of that so you can actually enter 1 million to 10 million data points, depending on your setup every second. So we write operations a second. And everything that you write is also versioned.
So that gives you the possibility also to travel back in time. So you can check what was actually the value one month ago two months ago officer. No record and immedi B is also key Value Store as well as a secret database.
So you have also more functionality in the database than you would have a blockchain right or a DLT right by having really and secretly on top of your data structure. And also these data points are completely client verifiable. The interesting part is they are still use cases for blockchains.
So public blockchains itself can still provide value because they are distributed and cannot be controlled by anyone, hopefully and There are requests from the market. Where you can combine immutable database with a blockchain and that is also something that we achieve. And how did you achieve that?
I mean, are you integrating your database with the different public blockchain? Is that the idea and if so, which ones? So that two ways how you can achieve it in general we support currently ethereum and we use technology that is called CK Roll-Ups.
So CEO of knowledge Roll-Ups. They means that you collect as many transactions as possible in a certain time frame and then you basically send all the transaction at one point. So if you're in blockchain, let's say allows you to have a hundred transactions a second.
You just feed a thousand transactions into one transaction. So this way you can actually get a thousand times more transaction speed and the big issue is of course what happens during this time frame where you collect all the different data points in the transactions. So you need to make sure that these transactions cannot be tempered with and immedi B is a perfect solution to use as this kind of a yeah, hola.
Platform so you sent these thousand transactions to MDB. They are completely immutable during this time frame and then you ascend it to a ethereum blockchain with then distributed worldwide distributed because I don't know 10,000 of notes or even more and that way you save costs but you also can gain a lot of performance benefits. That is I would say the most popular way probably to combine these two technologies, but in CEO, you could also do it the way around so you could for example use immedi b or the time and then your anchor the image B state so the client verification to Eco blockchain.
So either you use immedi to speed up ethereum and to speed up the applications, but your main point of contact would be a Serial blockchain or the main point of data or you can have Immediatbs your main point of data and just for additional security. You also write a kind of a snapshot or point in time timestamp to the ethereum blockchain. We hear a lot about blockchain as it relates to maybe better security for software Supply chains these days but blockchains a little complicated.
So is it practical to use blockchain for that or is that perhaps and use case where we should be thinking about another approach? I don't know how it will be how the situation will be in 5 10 years, but currently a blockchain is definitely hard to slow any distributed. Blockchain is far too slow to keep up with this amount of data that you would need to protect the supplies office supply chain.
There is the reason why we started initially with immedi B. So we developed immediately be because we need a very fast immutable data structure to keep up with all the artifacts that are being created during a software built and and Enterprise corporate company is producing sometimes thousands millions of artifacts every single day. So you need to keep up with this volume and you also need to be able to store data.
That is an important point I missed in the blockchain path blockchains are not meant to store data. They're meant to store. Transactions and Ashes immedi B was built from the ground up to store our data as well.
So you can store evidence like vulnerabilities can have reports like built locks. Well, I need that kind of attestation as well. So there are ways where you can use I would say technologies that use the same cook to graphic technology as a blockchain but not the current setup of A blockchain and immedi B is one of them but they are also other platforms out there like a trillion or equal that just focus on the lecture technology, but not so much on being really a database.
So your database as I understand that is open sourcing you just had some updates to it. So what's new and what's coming down the pike? Yes, so from the when we actually start the developing immed we wanted to have immedi be open source, because there are so many use cases that we don't want to disclose or to just have a close to us application and we wanted to have it ready for everyone but also everybody should be able to look into the details how the verification happens so it's also about transparency when it comes to verification and we saw more and more companies that are in the government or military or there's a fedcom compliance.
So that is a kind of a framework or application set up or infrastructure set up needs to look like for government agency to be able to use it. And one of these requirements is having a so-called Phipps compliant. I got to graphic.
Yeah hashing Technologies. So everything all methods that you use or libraries that you use need to be Phipps compliant to be part of the spectrum initiative. And that is something we added.
4 that just has been released is fixed compliant that is a major step forward when it comes to government use military use but it also allows different cryptographic and hashing Technologies to be used in the future. So when a company uses for example a closed source code to graphic algorithm they can use it maybe as well. Then for the broader public probably the most exciting features our synchronous replication.
So now you can use the midi image database, but you can also completely set it up higher variable and you can also distribute. Yeah globally if you like and that is something that we are request that we kind of course from financial institutions insurance. So whenever it came to an Enterprise setup And one of the most important parts or features and improvements for every release is performance.
So we improve the performance of the database itself. You moved also the performance of the replication to make sure we can have a synchronous replication and all of our sdks have been updated and have been the performance has been improved. The usability has been moved.
js python all these on Java all these sdks have been updated as well. Do I need to be a rocket scientist to deploy this do I need a dedicated DBA or can some mere mortals actually the playlist? So the simplest cloud is just to get it up and running everybody can do it's just one command.
If you're a family of DACA. You can just do a Docker run command. And then you're immedi B is up and running but you can also use it Standalone.
It's just that is a beauty of going as the development language. You just provide one binary and you can run it on Linux Windows Macos, even on a s390 and it's just a binary that you start and then you need to be is I've been running. Of course, there are more complex configurations when you want to have it on a hardened system or you want to have it replicated and I but also this part is very so we always do our best to make it extremities to use and the simple deployment should also be ready in one minute and that is currently the case having is the community because you know, let's have open source.
Everybody's looking for help. Anybody else but if there's nobody out there it's a problem. So, you know, just how big is the number of folks that I can lean on?
So we are getting closer and closer to reach 8,000 stars on GitHub. So the interest from the community is definitely also shown in the recognition. We get by the the Stars.
We have a couple of hundred active people in the community that I also support our core teams. Of course, we have also our core developers that work for code notary for us dedicated for immedi B, but the community is over a hundred companies. I would say so companies times the developers and also and they actively helping each other on GitHub issues.
But also on our Discord Channel and also on the support s*** in general And lastly do you think we'll see more security use cases involving the database since we are trying to figure out how to do zero trust everywhere, but underneath there, there should be some sort of immutable database right? I would. Thank you.
Absolutely, and we see that also other database Windows start to integrate blockchain functionality into an existing data base as well. Like all the blockchain tables for example or Amazon didb, but we are the only open source database out there that this kind of immutable set up with key various and SQL on top of it and I fully agree either as the top here or the first year. So that is typically true for all sensible data.
There's our sensitive data that should never be tempered with so we see for example, the Indian ministry of housing all the smart cities are using immedi b or their framework for the smart cities is using immedi B to track and securely store all the API requests that go in and get processed. So there are a lot of data types that need to be Didn't immutable database so I'm not saying that they need to be database is going to solve everything but there are certain data types where you want to make sure nobody's ever going to be able to tamper with it. You have a version in place that is also temporally and that is timestamp.
So you can follow the sequence when we are changes made and the demand is getting bigger and bigger. We even see cases where people fight renson we have of immedi B. So because you can very quickly go back to a form of version of your data record.
They don't use I mean to be as a primary database, but they're using ADB to protect the primary database. All right, folks and readability may not be as inscrutable as you think hey, Dennis. Thanks for being on the show.
Michael thank you very much pleasure to all right back to you guys in the studio.