Collaborative Blockchain Key Exchange Against PKI Single-Point Failure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public Key Infrastructure (PKI) techniques face vulnerabilities such as single points of failure and potential 'man-in-the-middle' attacks due to the distribution and storage of public keys, which can be compromised.

Innovation Solution

A secure distributed ledger system, specifically a private blockchain, is used to store and manage public keys, ensuring only authorized entities have access, and records are immutable, preventing unauthorized modification or access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public keys are distributed or stored by key escrow systems, then public key management is simplified, but security is compromised due to single point of failure and potential man-in-the-middle attacks

Engineering Contradiction:
Improvepublic key managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized key escrow system into a distributed blockchain network where multiple nodes collectively manage public keys. Instead of relying on a single central authority, the system divides key management responsibilities across numerous decentralized participants, eliminating the single point of failure while maintaining ease of operation through automated consensus mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a blockchain intermediary layer that mediates between users and public key storage. This blockchain acts as a trustless mediator that verifies and records public key distributions immutably, preventing man-in-the-middle attacks while simplifying the key management process for end users who don't need to directly trust any single entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If public keys are stored in a centralized system, then access control is simplified, but the system becomes vulnerable to unauthorized access and modification

Engineering Contradiction:
Improveaccess control systemVSAvoidunauthorized access
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized access control into distributed authorization across multiple blockchain nodes. Each node independently verifies access requests against the immutable ledger, so no single point of unauthorized access can compromise the entire system. The complexity is distributed rather than eliminated, but this distributed complexity provides inherent security against unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-recording public keys and access authorizations in the blockchain before any actual key exchange or access occurs. This creates an immutable audit trail and pre-established trust framework that prevents unauthorized access attempts, as all access must conform to previously recorded and consensus-validated rules.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12395477B2Systems and methods for collaborative blockchain establishment for blockchain-based secure key exchange
Publication Date: 2025.08.19 VERIZON PATENT & LICENSING INC
  • US12395477B2 patent drawing
  • US12395477B2 patent drawing
  • US12395477B2 patent drawing

AI summary

A system described herein provides for the secure maintaining and providing of information, such as public keys used in Public Key Infrastructure (“PKI”) techniques or other techniques, using a distributed ledger (e.g., “blockchain”) system. A first device may output a first request to a second device to establish a communication session between the first device and the second device, where the request includes a first value. The first device may receive a second request from the second device, including a second value, to establish the communication session between the first device and the second device. The first device may determine, based on a comparison of the first and second values, that the first device should initiate an establishment procedure of a blockchain associated with the communication session between the first device and the second device, and may accordingly output a blockchain establishment message to a set of devices.