Blockchain PKI Device Interoperability with CA Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing centralized public key infrastructure (PKI) systems are vulnerable to attacks on the root Certification Authority (CA), requiring revocation of all user certificates, whereas blockchain-based PKI systems lack interoperability with traditional CA-based PKI systems for mutual certification.
Innovation Solution
An electronic device in a blockchain-based PKI domain is designed to enable cryptographic communication with CA-based PKI domains by receiving certificates, verifying transactions on a distributed ledger, and performing mutual certification with devices in CA-based PKI domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized PKI system with root CA is used, then certificate issuance and management is simplified, but the system becomes vulnerable to attacks and requires revocation of all certificates when the root CA is compromised
Solution Approach 1:
The patent segments the centralized PKI system into a hierarchical structure with root CA, intermediate CAs, and end entities. This segmentation isolates the vulnerability scope so that compromise of one intermediate CA does not require revocation of all certificates, only those issued by the compromised intermediate CA.
Solution Approach 2:
The patent introduces intermediate CAs as mediators between the root CA and end entities. These intermediate CAs can be compromised and revoked independently without affecting the root CA or other intermediate CAs, thus protecting the overall system while maintaining centralized management benefits.
2Reliability
If a blockchain-based PKI system is used, then system reliability and decentralization are improved, but interoperability with traditional CA-based PKI systems is lost
Solution Approach 1:
The patent makes the blockchain system universal by enabling it to verify both blockchain-issued certificates and traditional PKI certificates. The blockchain network can validate certificates from traditional CAs by incorporating their public keys, allowing interoperability while maintaining blockchain's security benefits.
Solution Approach 2:
The patent uses the blockchain network as an intermediary trust layer that can verify certificates from different sources (both blockchain-based and traditional PKI). This intermediary approach allows different PKI systems to interoperate through the common blockchain verification mechanism.
3Adaptability or versatility
If mutual certification between blockchain-based and CA-based PKI domains is enabled, then interoperability is improved, but system complexity increases
Solution Approach 1:
The patent simplifies mutual certification by having traditional CAs publish their public keys and verification rules on the blockchain. This creates a simplified copy/representation of traditional PKI trust anchors that the blockchain network can verify using standard cryptographic operations, avoiding complex integration of entire PKI infrastructures.
Data Source
AI summary
An electronic device of a first domain, which is a blockchain-based public key infrastructure (PKI) domain, includes: an interface configured to receive, from a first entity belonging to a second domain which is a certification authority (CA)-based PKI domain, a first certificate of the first entity and a second certificate of a second entity, wherein the second entity is an upper node of the first entity and is a node of a blockchain; a memory configured to store the first certificate and the second certificate; and a processor configured to look up a transaction corresponding to the second entity at a distributed ledger of the first domain based on an identifier of the second entity, verify the second certificate based on the transaction, and verify the first certificate based on the second certificate.


