Blockchain Vulnerability Management via Smart Contracts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures for service providing platforms are inadequate in managing and addressing cybersecurity vulnerabilities, leading to potential data loss and unauthorized actions due to exploitable weaknesses in software, hardware, and networks.

Innovation Solution

Integration of a blockchain network that enables participating entities such as service providers, users, administrators, and security specialists to interact and manage cybersecurity vulnerabilities through smart contracts, maintaining a tamper-resistant vulnerability record and granting access authorities, thereby enhancing data security and trust among participants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity measures are used to manage vulnerabilities, then implementation is simpler, but security reliability is insufficient and data protection is weak

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain network as an intermediary layer between vulnerability reporters and service providers. This mediator enables trusted collaboration without requiring direct trust relationships, resolving the contradiction by providing cryptographic verification and immutable record-keeping that enhances security reliability while maintaining manageable complexity through standardized protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional centralized security management mechanisms with a decentralized blockchain-based system. By substituting centralized authority with distributed consensus and cryptographic verification, the system achieves higher security reliability through immutability and transparency, while the automated smart contract execution reduces operational complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If centralized vulnerability management is used, then coordination is easier, but trust among participants is insufficient and data security is compromised

Engineering Contradiction:
Improvedata securityVSAvoidcoordination ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the vulnerability management process into distinct functional modules implemented as smart contracts on the blockchain. Each participant type (reporter, verifier, provider) has dedicated interaction protocols, which enhances data security through role-based access control while maintaining coordination ease through clear, standardized interfaces for each segment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The blockchain network serves multiple functions simultaneously: it acts as a trustless coordination platform, an immutable audit trail, a decentralized verification system, and a reward distribution mechanism. This multi-functionality enhances data security by consolidating trust in a single system while improving coordination ease by providing a universal protocol for all participants

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3669522B1Managing cybersecurity vulnerabilities using blockchain networks
Publication Date: 2021.11.24 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3669522B1 patent drawingFigure 1
  • EP3669522B1 patent drawingFigure 2
  • EP3669522B1 patent drawingFigure 3

AI summary

Disclosed herein are methods, systems, and apparatus, including computer programs encoded on computer storage media, for cybersecurity vulnerability management. One of the methods includes receiving a vulnerability report indicating a cybersecurity vulnerability by a blockchain network. The blockchain network provides access to the vulnerability report to an administration server. A vulnerability verification report indicating a verification of the cybersecurity vulnerability from the administration server is received by the blockchain network. The blockchain network stores information of the cybersecurity vulnerability into a vulnerability record that is stored on the blockchain network. The blockchain network provides access to the vulnerability record to a service provider, and receives a notification indicating a resolution to the cybersecurity vulnerability from the service provider.