Blockchain Public Key Exchange for Secure PKI
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public Key Infrastructure (PKI) techniques using public keys are vulnerable to single points of failure and 'man-in-the-middle' attacks due to reliance on key escrow systems, which can compromise key security.
Innovation Solution
Implementing a secure distributed ledger system, such as a private blockchain, to manage and share public keys, ensuring only authorized entities can access and modify key information, thereby preventing unauthorized access and ensuring the integrity of encrypted communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a key escrow system is used to distribute public keys, then key distribution is simplified, but the system creates a single point of failure and vulnerability to man-in-the-middle attacks
Solution Approach 1:
The patent segments the key escrow functionality into multiple independent nodes forming a distributed ledger system. Instead of relying on a single centralized key escrow, public keys are distributed across multiple nodes that collectively maintain the ledger, eliminating the single point of failure while preserving ease of key distribution
Solution Approach 2:
The patent introduces a blockchain intermediary layer that mediates between key generation and key distribution. The blockchain acts as a trusted mediator that verifies and records public key distribution without requiring a centralized key escrow, thereby maintaining security while enabling simplified key exchange
2Device complexity
If a centralized key escrow system is used, then key management is centralized and simple, but the system allows opportunities for man-in-the-middle attacks
Solution Approach 1:
The centralized key management system is segmented into multiple distributed nodes that collectively perform key management functions. Each node maintains a copy of the ledger, distributing the trust model across the network rather than concentrating it in a single system, thereby reducing attack surfaces for man-in-the-middle attacks
Solution Approach 2:
The patent changes the fundamental parameter of system architecture from centralized to distributed. This parameter change transforms the key management approach from relying on a single trusted entity to relying on cryptographic consensus across multiple entities, eliminating the vulnerability to man-in-the-middle attacks while maintaining manageable complexity
3Loss of time
If public keys are stored in a centralized system, then retrieval is fast and simple, but the system creates a single point of failure
Solution Approach 1:
The centralized key storage is segmented into multiple distributed nodes, each holding a copy of the public key ledger. This segmentation allows key retrieval to occur from any node in the network, eliminating the single point of failure while maintaining fast retrieval times through parallel access capabilities
Solution Approach 2:
The patent merges multiple identical copies of the key ledger across different nodes into a unified distributed storage system. This merging approach provides redundancy and fault tolerance, ensuring that key retrieval remains fast and reliable even when individual nodes are unavailable
Data Source
AI summary
A system described herein provide for the secure maintaining and providing of information, such as public keys used in Public Key Infrastructure (“PKI”) techniques or other techniques, using a secure distributed ledger (e.g., “blockchain”) system. A blockchain system may be utilized in lieu of a key escrow system in the exchange and/or providing of public keys in a Diffie-Hellman key exchange technique or other type of technique in which public keys are provided from one entity to another. A first entity may generate an asymmetric key pair that includes a public key and a private key, and may provide the public key to a blockchain system for retrieval by one or more other entities. For example, the entities may be engaged in a secure messaging session, in which messages are encrypted and may be decrypted using one or more keys, including the public key.


