Decentralized Public Key Infrastructure Using Blockchain Transaction Chains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized Public Key Infrastructure (PKI) systems are vulnerable to large-scale negative consequences due to the compromise of trusted entities, highlighting the need for a decentralized approach to manage and store public cryptographic keys securely.
Innovation Solution
A decentralized public key infrastructure (DPKI) is implemented using a distributed computer framework with a public pool and a public distributed ledger (blockchain) for storing and managing public cryptographic keys, ensuring that transactions are interlinked and tamper-proof, with participant computing devices and a verifier computing device responsible for generating and verifying transaction chains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized Public Key Infrastructure (PKI) is used, then key management is simplified and centralized control is achieved, but the system becomes vulnerable to large-scale negative consequences when trusted entities are compromised
Solution Approach 1:
The patent segments the centralized PKI into multiple decentralized nodes distributed across a blockchain network. Each node independently validates and stores public key information, eliminating the single point of failure in centralized systems. The segmentation is implemented through distributed ledger technology where no single entity controls the entire key management infrastructure.
Solution Approach 2:
The patent introduces blockchain technology as an intermediary layer between key users and the underlying infrastructure. This mediator provides trustless verification of public keys through cryptographic proof and consensus mechanisms, replacing the need for traditional trusted intermediaries like Certificate Authorities while maintaining system reliability.
2Productivity
If public keys are stored in a centralized database, then access and management is efficient, but unauthorized access can lead to catastrophic consequences
Solution Approach 1:
The patent creates multiple identical copies of public key information distributed across numerous nodes in the blockchain network. Each node holds a copy of the verified public key data, eliminating the single storage point vulnerability. This copying mechanism ensures that even if some nodes are compromised, the system remains secure and operational.
Solution Approach 2:
The patent creates a cryptographically secure environment where public keys are protected by mathematical proofs and consensus protocols. The blockchain structure provides an 'inert' trust environment where keys are verified through cryptographic signatures and stored in an immutable ledger, making unauthorized access and modification computationally infeasible.
3Measurement precision
If digital certificates are used for authentication, then public key authenticity is ensured, but compromise of Certificate Authorities affects the entire PKI user community
Solution Approach 1:
The patent enables entities to self-verify their public keys through cryptographic proofs and consensus mechanisms without relying on external Certificate Authorities. Each participant in the blockchain network can independently validate public key authenticity through the distributed verification process, eliminating the need for centralized trust intermediaries.
Solution Approach 2:
The patent implements continuous feedback loops where blockchain nodes constantly verify and update the status of public keys through consensus protocols. The system provides real-time validation and automatic revocation mechanisms where compromised keys can be quickly identified and invalidated by the network, ensuring ongoing authentication accuracy without centralized control.
Data Source
AI summary
The invention relates, in general, to the field of computer engineering and, in particular, to arranging and storing information in the form of interlinked transactions in a distributed computer framework. The technology for linking transactions is provided. Transactions include information on public keys, as well as credentials of owners of these public keys. Public keys which belong to one owner are linked into a logical chain at the level of transactions. Each transaction contains information on one public key. Transactions are signed by a digital signature. Transactions are preliminarily placed into a specialized pool, then they are retrieved from the pool, verified, and, upon successful verification, data form the transactions is placed into a public ledger (blockchain). The verification comprises verifying the digital signature and confirming linkability or, in other words, confirming that a transaction belongs to a particular chain. Anyone having access to the ledger can perform all the necessary verifications. The invention provides decentralized storage and management of public keys, thereby enabling to minimize risks inherent to the commonly known centralized approach.


