Blockchain RPKI Bidirectional Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current Resource Public Key Infrastructure (RPKI) lacks bidirectional authorization, making it vulnerable to malicious operations on resource certificates, which can lead to illegal BGP routes and traffic redirection, and existing security measures are inadequate to distinguish between legitimate and malicious actions.
Innovation Solution
Implementing a blockchain-based RPKI that requires bidirectional authorization for all operations on resource certificates, treating certificate issuance, revocation, modification, and overwriting as transactions on a decentralized blockchain network, ensuring that both the issuer and receiver consent to each operation, thereby preventing malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional RPKI operations are implemented without bidirectional authorization, then resource certificate operations can be performed quickly and easily, but the system becomes vulnerable to malicious operations and security threats
Solution Approach 1:
The patent introduces a blockchain-based bidirectional authorization mechanism as an intermediary between resource certificate issuers and receivers. This mediator verifies and records both issuance and acceptance of certificates, preventing malicious operations while maintaining operational efficiency through automated smart contract execution.
Solution Approach 2:
The system implements feedback loops where resource receivers must explicitly accept certificate operations, and the blockchain network continuously monitors and validates the authenticity of both issuance and acceptance actions. This feedback mechanism ensures that only legitimate operations are recorded, enhancing security without significantly increasing complexity.
2Reliability
If bidirectional authorization is implemented for all resource certificate operations, then malicious operations are prevented, but the operation process becomes more complex and time-consuming
Solution Approach 1:
The blockchain-based system enables self-service automation where smart contracts automatically execute and verify bidirectional authorization operations. Resource issuers and receivers interact through standardized interfaces that automatically record operations on the blockchain, reducing manual complexity while maintaining security requirements.
Solution Approach 2:
The system performs preliminary validation and recording of authorization intentions before actual certificate operations occur. Smart contracts pre-verify the legitimacy of issuance and acceptance actions, ensuring that only authenticated operations proceed to execution, thereby simplifying the actual operation process while maintaining high reliability.
3Productivity
If centralized RPKI authority operations are allowed, then resource certificate management is efficient and simple, but the system cannot distinguish between legitimate and malicious actions
Solution Approach 1:
The patent segments the centralized authority model into distributed blockchain nodes that collectively perform certificate management. Instead of a single point of control, multiple independent nodes validate and record operations, maintaining efficiency through parallel processing while enabling distinction between legitimate and malicious actions through distributed consensus mechanisms.
Solution Approach 2:
The system uses cryptographic signatures and blockchain transaction states as visual indicators (analogous to color changes) to distinguish between legitimate and malicious operations. Valid operations are marked with authenticated signatures and recorded in an immutable ledger, while unauthorized actions are rejected and flagged, providing clear differentiation without reducing operational efficiency.
Data Source
AI summary
The disclosure discloses a method for bidirectional authorization of a blockchain-based resource public key infrastructure, aiming at solving security threat problems that a legal BGP route is illegal and a legal IP address is blocked caused by malicious operations. A technical solution is as follows: constructing a blockchain-based resource public key infrastructure system RPKIB composed of a resource issuer, a resource transaction application client, a resource receiver and a blockchain network; changing any operation of issuing, revoking, overwriting and modifying of a resource certificate by the resource issuer into a bidirectional authorization mode, and implementing the operation of the resource certificate only when the issuer and the receiver both agree; and carrying out, by the issuer, operations of a resource certificate RC and route origin authorization ROA as transactions that are carried out through the blockchain network, and distinguishing whether the operations are malicious behaviors or normal operations.


