Blockchain-Based Private Certificate Authority Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack mechanisms to quickly and easily determine whether a digital certificate is valid, particularly in cases where a 'dark' certificate is issued by an unauthorized entity outside the trusted certificate allocation process.

Innovation Solution

The proposed solution involves writing information about digital certificates to a secure database and simultaneously to a publicly-verifiable distributed ledger, such as a blockchain, allowing for additional verification of certificate validity by both the certificate authority and external parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are issued by unauthorized entities outside the trusted certificate allocation process, then the certificate can be generated and used, but the certificate cannot be verified as valid by the trusted certificate authority

Engineering Contradiction:
Improvecertificate validityVSAvoidverification mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a distributed ledger as an intermediary system that records all certificate issuance transactions. This mediator provides a transparent, immutable record that both trusted and unauthorized CAs must use, enabling verification of certificate validity without requiring complex direct verification mechanisms between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the distributed ledger continuously records certificate issuance transactions, allowing relying parties to verify certificate validity by checking the ledger. This feedback loop enables real-time detection of unauthorized certificate issuance and maintains trust in the certificate validation process.

Inventive Principle:
Principle #23Feedback

2Reliability

If a distributed ledger is used to record certificate transactions, then certificate validity can be verified, but the system complexity increases

Engineering Contradiction:
Improvecertificate management integrityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The distributed ledger serves multiple functions: it records certificate issuance transactions, provides verification capability, maintains an immutable audit trail, and enables detection of unauthorized operations. This multi-functionality reduces the need for separate complex verification systems while enhancing certificate management integrity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the certificate issuance recording function with the verification function into a single distributed ledger system. By combining these functions, the system avoids the complexity of separate verification infrastructure while maintaining high reliability through the unified, immutable record-keeping mechanism.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If additional verification checks are implemented, then dark certificate detection improves, but the verification process becomes more time-consuming

Engineering Contradiction:
Improvedark certificate detectionVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The distributed ledger records all certificate issuance transactions in advance, creating an immutable history that can be quickly queried. This preliminary recording of all transactions enables rapid verification by simply checking whether a certificate exists in the ledger, rather than performing complex real-time analysis, thus reducing verification time while maintaining detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the certificate issuance record in the distributed ledger that can be independently verified by relying parties. This copy provides a quick reference that eliminates the need for complex real-time verification procedures, enabling fast detection of dark certificates by simply querying the pre-recorded transaction history.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250047504A1High-assurance private certificate authorities
Publication Date: 2025.02.06 AMAZON TECH INC
  • US20250047504A1 patent drawing
  • US20250047504A1 patent drawing
  • US20250047504A1 patent drawing

AI summary

Approaches presented herein relate to the management of secure secrets, such as digital certificates. When an operation is performed by a certificate authority (CA) with respect to a digital certificate, information for the operation is written to a blockchain (or other distributed and verifiable ledger) in addition to a secure database accessible to the CA. The ability of an external party to access the blockchain and independently verify information about a digital certificate can help to increase a level or assurance in the integrity of the CA, which can be important when an entity wants to act as (or offer) their own private certificate authority. Information in the blockchain can also help to identify “dark” certificates, which may appear valid but were not issued by a CA using a valid and secure process, and thus can be identified by a lack of valid transactions included in the corresponding blockchain.