Blockchain Certificate Issuance via Secure Element Key Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public certificate issuance systems are vulnerable to hacking due to the storage of private keys on user devices, which can be compromised, and require costly maintenance, especially since they often rely on ActiveX controls that lower security and increase the risk of data breaches.
Innovation Solution
A system that generates and stores private keys within a secure random number generator device, inaccessible physically and to software installation, while managing public keys on blockchain nodes using a peer-to-peer network, eliminating the need for a certificate authority and minimizing maintenance costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private keys are stored on user devices in conventional PKI systems, then certificate issuance and authentication can be performed, but security is compromised due to physical access and software installation vulnerabilities
Solution Approach 1:
The system separates private key storage from public key management. Private keys are generated and stored in a secure element (separate module) that is physically isolated and cannot be accessed by external software or hardware, while public keys are managed on the user device and in the distributed ledger. This segmentation ensures that even if the user device is compromised, the private key remains protected.
Solution Approach 2:
A secure element acts as an intermediary between the user device and the certificate authority system. It generates private keys internally and only allows controlled communication of public keys and signed data to external systems, preventing direct access to sensitive cryptographic materials while enabling certificate issuance and authentication functions.
2Reliability
If ActiveX controls are installed for certificate authentication, then authentication security is enhanced, but the system becomes vulnerable to hacking and requires costly maintenance
Solution Approach 1:
The system extracts the authentication functionality from vulnerable ActiveX controls and implements it using standard web technologies combined with secure element-based cryptography. The secure element handles sensitive operations internally, while the web interface uses only public keys and signed data, eliminating the security vulnerabilities associated with ActiveX while maintaining authentication security.
Solution Approach 2:
The secure element performs self-service by generating its own private keys internally and managing its own cryptographic operations without requiring external software installation or configuration. This autonomous operation eliminates the need for ActiveX controls and reduces the attack surface for hacking while maintaining strong authentication capabilities.
3Ease of operation
If a centralized CA server manages public keys, then certificate issuance is controlled, but maintenance costs increase and security against hacking is reduced
Solution Approach 1:
The system segments the public key management function across multiple independent nodes in a distributed ledger, eliminating the single point of failure and attack target that a centralized CA server represents. Each node maintains a copy of the ledger and can independently verify public keys, providing both decentralized security and continued certificate management capability.
Solution Approach 2:
The distributed ledger acts as an intermediary that replaces the centralized CA server. It provides a decentralized, immutable record of public keys and certificate information that can be verified by any participant in the network, eliminating the need for a trusted centralized authority while maintaining certificate management functionality.
Data Source
AI summary
The present invention relates to an accredited certificate issuance system based on a block chain and a method using the same, and an accredited certificate authentication system based on a block chain and a method using the same, which disenable a leak of a personal key by autonomously generating, storing and managing the personal key by a random number generator mounted in a terminal in which it is impossible to install a function or an additional program for physically accessing; enable a public key for accredited certification to be stored in a block chain of electronic wallets mounted in block chain retention servers via a P2P network-based distribution database, not in a server of an accredited certificate authority (CA), and thus incur almost no costs for maintenance and for operating the established accredited certificate issuance system; and can perform an accredited certification process without ActiveX.


