Blockchain Certificate Verification for Instant Revocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public key infrastructure (PKI) systems face delays and inefficiencies in revoking compromised digital certificates, as entities must rely on periodically updated certificate revocation lists, which can lead to security risks due to delayed updates.
Innovation Solution
Utilizing a blockchain network to record and manage digital certificates, enabling instantaneous revocation and verification by ensuring that the certificate authority's transactions remain unspent, allowing for quick validation and replacement of public keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certification authorities maintain and periodically update certificate revocation lists, then digital certificates can be revoked when public keys are compromised, but there are delays in publishing updates and entities may not have the latest revocation information
Solution Approach 1:
The patent replaces the traditional mechanical system of periodically published revocation lists with a blockchain-based distributed ledger system. The blockchain continuously records certificate issuance and revocation transactions, providing real-time, immutable verification of certificate status without periodic updates or centralized publication delays.
Solution Approach 2:
The patent introduces a blockchain network as an intermediary between certification authorities and entities verifying certificates. This decentralized intermediary continuously maintains and propagates the latest certificate status information, eliminating the need for entities to periodically check for updates from centralized authorities.
2Ease of operation
If entities rely on digital certificates for public key validation, then secure communications can be established, but the system requires separate revocation list management and periodic updates
Solution Approach 1:
The patent merges the certificate verification process with the blockchain ledger verification. Instead of separately managing revocation lists and checking them periodically, the system combines certificate status verification with blockchain transaction validation, where the blockchain's inherent immutability and distributed consensus automatically indicate whether a certificate is valid or revoked.
Solution Approach 2:
The patent enables entities to self-verify certificate status by querying the blockchain directly, without requiring centralized revocation list distribution or manual updates. The blockchain network automatically provides the latest certificate status information to any entity that queries it, eliminating the need for coordinated updates across the system.
Data Source
AI summary
A public key may be recorded on the blockchain by a certificate authority in such a manner that any third party may quickly and easily verify that the public key is certified by the certificate authority and that the certification has not been revoked. The certificate authority may be able to revoke the certification nearly instantaneously, and/or may be able to simultaneously certify a new key for the same entity while revoking the old key. The verification may be incorporated into a new transaction so that there is no gap between reliance on the certificate and the verification of its validity. In some cases, each transaction in which the certificate is used may also serve as linked certificate transaction that renews the certificate to enable a subsequent use.


