Blockchain Certificate Validation via Segmented Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing blockchain-based certificate validation systems face limitations in scalability and data security when handling public and private access, as they typically operate within private networks, restricting real-world validation operations and trust relationships between institutions.

Innovation Solution

A public-permissioned blockchain network with a certificate service repository, access control logic via smart contracts, and a distributed storage/content distribution platform, allowing interaction with the blockchain through a public-permission blockchain node, enabling efficient certificate issuance, revocation, and management while ensuring confidentiality and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a private blockchain network is used to store certificate data, then data confidentiality and security are improved, but public access and validation capability are restricted

Engineering Contradiction:
Improvedata confidentialityVSAvoidpublic access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the blockchain network into two distinct parts: a private permissioned blockchain for storing and managing certificate data with access control, and a public permissionless blockchain for validation operations. This segmentation allows each part to serve its specific function optimally - the private chain maintains confidentiality while the public chain enables widespread validation access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer consisting of a validation service and bridge smart contracts that connect the private and public blockchain networks. This intermediary enables secure communication between the two networks, allowing the public network to validate certificates without accessing the private network's stored data, thus maintaining both confidentiality and public accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a public blockchain network is used for certificate validation, then public access and trust are improved, but data confidentiality and security are compromised

Engineering Contradiction:
Improvepublic validation accessVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system separates data storage and validation functions across two blockchain networks. The private permissioned blockchain securely stores certificate data with access control, while the public permissionless blockchain handles validation operations. This segmentation ensures that sensitive data remains confidential while validation is publicly accessible.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A validation service acts as an intermediary that bridges the private and public blockchains. It retrieves certificate data from the private network, validates it according to predefined rules, and records the validation result on the public network. This intermediary enables public validation without exposing private data to the public network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If third-party services are used to share certificates, then accessibility is improved, but system complexity and trust issues increase

Engineering Contradiction:
Improvecertificate sharingVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables certificate owners to self-manage their certificates by setting access permissions directly on the blockchain. Users can grant or revoke access to specific entities without requiring third-party service intermediaries. This self-service capability simplifies the system architecture by eliminating the need for complex external sharing services while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The blockchain-based access control system provides universal functionality for certificate sharing. The same smart contract-based permission mechanism handles all types of access requests (viewing, downloading, verifying) for all certificate types, eliminating the need for separate third-party services for different sharing scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3817320B1Blockchain-based system for issuing and validating certificates
Publication Date: 2023.01.04 UNIV INT DE LA RIOJA UNIR
  • EP3817320B1 patent drawingFigure 1~2

AI summary

The invention relates to a blockchain-based system for issuing and validating certificates, comprising: a public-permissioned blockchain network (1); a certifying institution network (4), wherein the certifying institution network (4) further comprises a public permission blockchain node (6) managed by a certifying institution (5), distributed peer-to-peer storage/content distribution platform (6'), one or more computing means configured with a certificate management service (7) adapted for issuing and revoking certificates by the certifying institution (5); one or more computing means configured with a plurality of offchain (8) services used by the certifying institution (5) to manage the access to the certificates by users not connected to the public permissioned blockchain network (1); and an external network (9) comprising a plurality of computing devices used by users (10) or other third-party service providers (11) not connected to the blockchain environment (1), configured to interact with the certificates stored at the storage/content distribution platform (6') through the offchain services (8).