Blockchain Digital Certificate Verification via Account Type Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital certificate verification is unreliable when a certificate authority (CA) is hijacked, leading to low network security due to the potential for tampering and manipulation of verification results.
Innovation Solution
A digital certificate verification method and apparatus that utilizes a blockchain to store digital certificates as transaction resources, where the verification result is determined based on the account type associated with the transaction record, ensuring high reliability and security by preventing tampering and correlating different account types with distinct certificate operation states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificate verification is performed by a CA that generates the certificate, then the verification process is simple and direct, but the verification result becomes unreliable when the CA is hijacked
Solution Approach 1:
The patent introduces a blockchain system as an intermediary between the CA and the verification system. The blockchain stores transaction records including account types and certificate operations, serving as a neutral mediator that verifies certificate validity without relying solely on the CA. This resolves the contradiction by maintaining verification reliability even when the CA is compromised, while the blockchain's distributed architecture manages the added complexity.
Solution Approach 2:
The verification system is segmented into multiple independent components: the original CA verification process and a separate blockchain-based verification layer. The blockchain stores segmented information including transaction records, account types (issuance, recovery, revocation), and certificate operations. This segmentation allows the system to maintain reliability by distributing verification functions across multiple independent components rather than relying on a single CA.
2Reliability
If digital certificates are stored and verified using blockchain technology with transaction records, then verification reliability and security are improved, but the system complexity increases
Solution Approach 1:
The blockchain system performs multiple functions simultaneously: it stores certificate data, maintains transaction records, tracks account types (issuance, recovery, revocation), and provides verification capabilities. By making the blockchain a multi-functional universal system, the patent reduces overall system complexity compared to having separate specialized systems for each function, while maintaining high verification reliability through its immutable and distributed nature.
3Object-affected harmful factors
If the CA is hijacked, then the traditional verification method becomes vulnerable to tampering and manipulation, but implementing blockchain-based verification increases system complexity
Solution Approach 1:
The patent implements preliminary anti-action by pre-storing account types (issuance account type, recovery account type, revocation account type) and transaction records in the blockchain before any potential hijacking occurs. This preliminary setup creates an immutable verification trail that prevents tampering, as any manipulation would require altering the entire blockchain history. The system proactively defends against hijacking rather than reacting to it, managing complexity through preventive architecture design.
Data Source
AI summary
Embodiments of this application relate to a digital certificate verification method and apparatus, a computer device, and a storage medium. The digital certificate verification method is performed by a authentication center, and include receiving a verification request for verifying a target digital certificate; obtaining a target transaction record corresponding to the target digital certificate from a blockchain, the target digital certificate being stored in the blockchain as a transaction resource; obtaining a target account type corresponding to the target transaction record, different account types corresponding to different certificate operation states; and determining a verification result corresponding to the target digital certificate according to the target account type.


