Blockchain RPKI Validation via Smart Contract Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Resource Public Key Infrastructure (RPKI) faces security risks due to malicious operations on resource certificates, leading to difficulties in distinguishing between legitimate and malicious transactions, and current mechanisms struggle to address conflicts and illegal transactions effectively.

Innovation Solution

A blockchain-based RPKI system is introduced, where resource certificate and route origin authorization (ROA) transactions are submitted to a blockchain network, and a validation node runs a smart contract to verify transactions, eliminating reliance on central nodes and ensuring bidirectional authorization between resource issuers and receivers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional RPKI mechanisms are used for certificate transaction validation, then the system structure is relatively simple, but the security is insufficient due to inability to distinguish malicious operations from legitimate transactions

Engineering Contradiction:
ImprovesecurityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces blockchain as an intermediary layer between resource issuers and receivers. The blockchain network validates transactions through distributed consensus mechanisms, acting as a neutral mediator that prevents malicious operations without requiring complex changes to the core RPKI architecture. Smart contracts serve as automated intermediaries that enforce transaction rules objectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the RPKI validation process into distinct blockchain transactions. Each certificate issuance, revocation, or modification is broken down into discrete, traceable blockchain events. This segmentation allows independent validation of each operation while maintaining overall system security through the cumulative effect of validated transactions.

Inventive Principle:
Principle #1Segmentation

2Reliability

If blockchain-based transaction validation is implemented, then security is enhanced through validation and prevention of illegal transactions, but the device complexity increases due to blockchain network integration

Engineering Contradiction:
Improvetransaction validation securityVSAvoidblockchain network structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the blockchain network multi-functional by using it not only for transaction validation but also for maintaining distributed ledgers, enabling bidirectional authorization, providing timestamping services, and creating immutable audit trails. This consolidates multiple security functions into a single infrastructure, reducing the need for separate validation systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The blockchain network performs self-validation through its inherent consensus mechanisms and smart contract execution. Transactions are automatically validated by the distributed network without requiring external arbitration or complex manual verification processes. The system validates itself through cryptographic proof and distributed agreement.

Inventive Principle:
Principle #25Self-service

3Reliability

If central nodes are relied upon for transaction validation, then the operation is simpler, but the security is compromised due to single point of failure and potential malicious operations

Engineering Contradiction:
Improvefault toleranceVSAvoidvalidation process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the centralized validation authority into multiple distributed validation nodes across the blockchain network. Each node independently validates transactions and maintains a copy of the ledger, eliminating single points of failure. The segmentation of authority into distributed participants provides inherent fault tolerance while maintaining operational simplicity through automated consensus.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The blockchain network acts as an intermediary layer that simplifies the validation process despite its distributed nature. Smart contracts automatically enforce validation rules, and the consensus mechanism handles coordination between nodes, making the complex distributed validation appear simple to external users who only need to interact with standardized APIs.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If resource certificate transactions are monitored for malicious operations, then security is improved, but the processing time increases due to additional validation steps

Engineering Contradiction:
Improvemalicious operation detectionVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary validation through smart contracts that automatically check transaction legitimacy before execution. Validation rules are pre-programmed into the blockchain, so malicious operations are detected and rejected before they can cause harm. This preliminary automated checking reduces the need for time-consuming post-validation analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The blockchain network performs self-validation of transactions through its consensus mechanisms and smart contract execution. Each node independently verifies transaction signatures and validity, eliminating the need for sequential manual review. This parallel self-validation by multiple nodes actually reduces total processing time compared to centralized sequential validation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11521205B2Method for certificate transaction validation of blockchain-based resource public key infrastructure
Publication Date: 2022.12.06 GUANGZHOU UNIVERSITY
  • US11521205B2 patent drawing
  • US11521205B2 patent drawing
  • US11521205B2 patent drawing

AI summary

A method for certificate transaction validation of a blockchain-based resource public key infrastructure aims to avoid security threats caused by conflicts or illegal transactions during transactions and improve security. A technical solution is as follows: constructing a resource public key infrastructure RPKIB system composed of a resource issuer, a resource transaction application client, a resource receiver, a blockchain network and a validation node; designing operations of a resource certificate and route origin authorization ROA as transactions, submitting operations of various resource transactions initiated by a resource issuer as transactions to the blockchain network, running, by the validation node, a smart contract to verify the transactions, and distinguishing whether the operations are malicious behaviors or normal operations of an authority.