Decentralized Root Store for PKI Trust Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current public-key infrastructure (PKI) solutions, such as PKI trust bridges and trusted root stores, rely on centralized entities for managing trust, leading to high costs, perpetual infrastructure expenses, and vulnerability to single points of failure, which is not efficient for decentralized networks.
Innovation Solution
A decentralized root store using blockchain technology to manage a list of trusted root certificates, where multiple entities participate in validating and adding certificates, eliminating the need for a single trusted party and reducing maintenance costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized root store is used to manage trusted root certificates, then trust management is simplified and centralized, but the system becomes vulnerable to single points of failure and requires perpetual infrastructure costs
Solution Approach 1:
The patent segments the centralized root store into multiple distributed nodes across a peer-to-peer network. Each node maintains a copy of the root store, eliminating the single point of failure. The root store is divided into blocks that are distributed and replicated across multiple participants, ensuring that no single node holds all the trust authority.
Solution Approach 2:
The patent introduces a consensus mechanism as an intermediary layer between the distributed nodes and the root store updates. This consensus mechanism coordinates the addition and removal of root certificates across the distributed network, maintaining trust management simplicity while enabling decentralization. The consensus algorithm acts as a mediator that resolves conflicts and ensures agreement among distributed participants.
2Adaptability or versatility
If a PKI trust bridge is used to extend trust between entities, then trust can be established between federated PKI infrastructures, but membership and auditing costs become relatively high
Solution Approach 1:
The patent enables PKI entities to self-manage their trust relationships through the decentralized root store. Each entity can independently verify root certificates from other entities by checking them against the distributed root store, eliminating the need for expensive centralized auditing. The system allows entities to autonomously establish and verify trust relationships without requiring membership in expensive trust bridge consortia.
3Productivity
If trusted root stores are built into operating systems or applications, then trust verification is streamlined, but the root store requires centralized management and periodic updates by trusted organizations
Solution Approach 1:
The patent transitions the root store from a two-dimensional centralized database to a three-dimensional distributed network structure. The root store exists across multiple dimensions - spatially distributed across multiple nodes, temporally synchronized through consensus mechanisms, and hierarchically organized into blocks. This dimensional transformation enables streamlined verification while eliminating centralized management complexity.
Data Source
AI summary
A network is described. The network is a peer-to-peer network of nodes. The nodes maintain a distributed ledger. The distributed ledger includes a list of transactions. The list of transactions includes various transactions for maintaining a decentralized root store between the nodes. The decentralized root store includes a list of certificate authorities which are trusted by the nodes in the network. The root certificates may be retrieved from the distributed ledger, validated, and then used to access the certificate authorities.


