Blockchain Public Key Exchange for Secure PKI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public Key Infrastructure (PKI) techniques using public keys are vulnerable to single points of failure and 'man-in-the-middle' attacks due to reliance on key escrow systems, which can compromise key security.

Innovation Solution

Implementing a secure distributed ledger system, such as a private blockchain, to manage and share public keys, ensuring only authorized entities can access and modify key information, thereby preventing unauthorized access and ensuring the integrity of encrypted communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a key escrow system is used to distribute public keys, then key distribution is simplified, but the system creates a single point of failure and vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improvekey distributionVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the key escrow functionality into multiple independent nodes forming a distributed ledger system. Instead of relying on a single centralized key escrow, public keys are distributed across multiple nodes that collectively maintain the ledger, eliminating the single point of failure while preserving ease of key distribution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a blockchain intermediary layer that mediates between key generation and key distribution. The blockchain acts as a trusted mediator that verifies and records public key distribution without requiring a centralized key escrow, thereby maintaining security while enabling simplified key exchange

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a centralized key escrow system is used, then key management is centralized and simple, but the system allows opportunities for man-in-the-middle attacks

Engineering Contradiction:
Improvekey management systemVSAvoidman-in-the-middle attack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The centralized key management system is segmented into multiple distributed nodes that collectively perform key management functions. Each node maintains a copy of the ledger, distributing the trust model across the network rather than concentrating it in a single system, thereby reducing attack surfaces for man-in-the-middle attacks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the fundamental parameter of system architecture from centralized to distributed. This parameter change transforms the key management approach from relying on a single trusted entity to relying on cryptographic consensus across multiple entities, eliminating the vulnerability to man-in-the-middle attacks while maintaining manageable complexity

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If public keys are stored in a centralized system, then retrieval is fast and simple, but the system creates a single point of failure

Engineering Contradiction:
Improvekey retrieval timeVSAvoidsystem availability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The centralized key storage is segmented into multiple distributed nodes, each holding a copy of the public key ledger. This segmentation allows key retrieval to occur from any node in the network, eliminating the single point of failure while maintaining fast retrieval times through parallel access capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple identical copies of the key ledger across different nodes into a unified distributed storage system. This merging approach provides redundancy and fault tolerance, ensuring that key retrieval remains fast and reliable even when individual nodes are unavailable

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11849032B2Systems and methods for blockchain-based secure key exchange
Publication Date: 2023.12.19 VERIZON PATENT & LICENSING INC
  • US11849032B2 patent drawing
  • US11849032B2 patent drawing
  • US11849032B2 patent drawing

AI summary

A system described herein provide for the secure maintaining and providing of information, such as public keys used in Public Key Infrastructure (“PKI”) techniques or other techniques, using a secure distributed ledger (e.g., “blockchain”) system. A blockchain system may be utilized in lieu of a key escrow system in the exchange and/or providing of public keys in a Diffie-Hellman key exchange technique or other type of technique in which public keys are provided from one entity to another. A first entity may generate an asymmetric key pair that includes a public key and a private key, and may provide the public key to a blockchain system for retrieval by one or more other entities. For example, the entities may be engaged in a secure messaging session, in which messages are encrypted and may be decrypted using one or more keys, including the public key.