BIX Certificates Ledger for Anonymous Peer-to-Peer PKI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current X.509 certificates and public key infrastructure (PKI) are inadequate for peer-to-peer transactions that require security, privacy, and anonymity, as they rely on third-party certification authorities and compromise user anonymity and privacy.

Innovation Solution

A community-based public certificates ledger system, called BIX Certificates Ledger (BCL), which uses cryptographically encapsulated BIX certificates that are issued and validated directly by users without third-party assistance, enabling secure, private, and anonymous transactions through a blockchain-like structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party certification authorities are used to issue and validate certificates, then certificate validation and security services are provided, but user privacy and anonymity are compromised

Engineering Contradiction:
Improvecertificate validationVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the certificate issuance and validation functions from third-party certification authorities and places them directly in the hands of users through cryptographic key pairs. Each user generates their own certificate containing their public key and identity information, eliminating the need for external validation authorities while maintaining security through cryptographic proof of ownership.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Users independently issue their own certificates by generating cryptographic key pairs and creating self-signed certificates that contain their public key and identity information. The certificates are validated by other users through cryptographic verification without requiring third-party intervention, enabling users to serve themselves in the certificate management process.

Inventive Principle:
Principle #25Self-service

2Reliability

If third-party certification authorities are involved in certificate management, then security services are provided, but user anonymity is compromised

Engineering Contradiction:
Improvesecurity servicesVSAvoiduser anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent removes third-party certification authorities from the certificate management process entirely. Users generate their own certificates and validate each other's certificates through direct cryptographic verification. This extraction of the third-party element preserves user anonymity while maintaining security through the mathematical properties of public key cryptography and the distributed verification process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Users independently manage their own certificates and validate other users' certificates without revealing their identities to third parties. The system enables users to verify each other's credentials through cryptographic proof while maintaining anonymity, as the validation process only requires public key verification rather than identity disclosure to intermediaries.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If a centralized PKI system is used, then certificate distribution and validation are standardized, but the system complexity and third-party dependency increase

Engineering Contradiction:
Improvecertificate distributionVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized PKI system into individual user-controlled certificate units. Instead of a monolithic certification authority, each user holds their own certificate and privately managed key pair. This segmentation distributes the trust model across many independent users rather than concentrating it in a single authority, reducing infrastructure complexity while maintaining adaptability through peer-to-peer verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Users independently generate, manage, and validate certificates without requiring centralized infrastructure. Each user serves as their own certification authority, eliminating the need for complex centralized PKI infrastructure while maintaining standardized certificate formats and validation procedures through cryptographic conventions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20190158298A1Public key infrastructure based on the public certificates ledger
Publication Date: 2019.05.23 MUFTIC SEAD
  • US20190158298A1 patent drawing
  • US20190158298A1 patent drawing
  • US20190158298A1 patent drawing

AI summary

Systems and methods for managing public key certificates and supporting the users thereof. The certificates are cryptographically encapsulated objects that bind the identities of their owners to public keys and provide digital signature mechanisms for other users to verify the binding and correctness of other attributes of the certificate. Certificates include double links that reflect their validation and position in a public certificates ledger, thereby preventing insertion or removal of certificates in the ledger. Certificate protocols of the system include requesting issuance of certificates, issuing and returning certificates to their requesting users, storing certificates in the certificates ledger, requesting and distributing certificates to transaction partners, verification of certificates by transaction partners, and revoking certificates by their owners. These protocols are performed as direct peer-to-peer transactions between the members of the system.