Digital Certificate Issuing Center for Blockchain Node Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In conventional blockchain networks, the process of issuing digital certificates to nodes lacks assurance, resulting in low probative value and authority for the issued keys, as it cannot definitively verify that the digital certificate corresponds to the actual key, compromising the security and credibility of data exchange.

Innovation Solution

A digital certificate issuing center equipped with a public-private key generation module and an authentication module generates and verifies public-private key pairs for nodes, ensuring that the digital certificate includes a signature formed using the private key, allowing nodes to verify the signature using the public key, thereby enhancing the credibility of the issued keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a digital certificate is issued to a node using a conventional isolated process, then the certificate issuance is simple and fast, but the probative value and authority of the certificate is low because it cannot definitively verify correspondence to the actual key

Engineering Contradiction:
Improveprobative value of digital certificateVSAvoidcertificate issuance process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a digital certificate issuing center as an intermediary between key generation and certificate issuance. This center includes a public-private key generation module that generates keys and an authentication module that verifies the correspondence between certificates and keys. The intermediary ensures authoritative binding while maintaining process efficiency through automated verification mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges the key generation function and certificate issuance function into a single integrated process within the digital certificate issuing center. The public-private key generation module and authentication module work together to ensure that the digital certificate definitively corresponds to the actual key, thereby improving probative value without requiring separate complex verification processes.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If key authentication is strengthened to ensure digital certificates correspond to actual keys, then security and authority are improved, but the complexity of the issuance process increases

Engineering Contradiction:
Improvesecurity of data exchangeVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The digital certificate issuing center serves as a trusted intermediary that performs authentication between nodes and the blockchain network. It includes an authentication module that verifies node identities and ensures digital certificates correspond to actual keys, thereby strengthening security while centralizing the complexity of authentication operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication module implements feedback mechanisms to verify the correspondence between digital certificates and actual keys. The system provides authentication results back to the certificate issuance process, ensuring security through verified correspondence while automating the feedback loop to manage complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11924358B2Method for issuing digital certificate, digital certificate issuing center, and medium
Publication Date: 2024.03.05 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US11924358B2 patent drawing
  • US11924358B2 patent drawing
  • US11924358B2 patent drawing

AI summary

This application provides a method for issuing a digital certificate performed by a digital certificate issuing center that includes a public-private key generation module and an authentication module. The method includes: receiving a public-private key request from a node in a blockchain network; generating a public key and a private key of the node by using the public-private key generation module, and transmitting the public and private keys to the node; receiving the public key of the node and registration information of the node, and authenticating the registration information by using the authentication module; and generating, in accordance with a determination that the authentication succeeds, a digital certificate of the node by using the authentication module, and transmitting the digital certificate to the node. The embodiments of this application can improve the probative value of an issued digital certificate, thereby improving the security of data exchange in a blockchain network.