Decentralized Root Store for PKI Trust Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current public-key infrastructure (PKI) solutions, such as PKI trust bridges and trusted root stores, rely on centralized entities for managing trust, leading to high costs, perpetual infrastructure expenses, and vulnerability to single points of failure, which is not efficient for decentralized networks.

Innovation Solution

A decentralized root store using blockchain technology to manage a list of trusted root certificates, where multiple entities participate in validating and adding certificates, eliminating the need for a single trusted party and reducing maintenance costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized root store is used to manage trusted root certificates, then trust management is simplified and centralized, but the system becomes vulnerable to single points of failure and requires perpetual infrastructure costs

Engineering Contradiction:
Improvetrust managementVSAvoidsingle point of failure
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized root store into multiple distributed nodes across a peer-to-peer network. Each node maintains a copy of the root store, eliminating the single point of failure. The root store is divided into blocks that are distributed and replicated across multiple participants, ensuring that no single node holds all the trust authority.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a consensus mechanism as an intermediary layer between the distributed nodes and the root store updates. This consensus mechanism coordinates the addition and removal of root certificates across the distributed network, maintaining trust management simplicity while enabling decentralization. The consensus algorithm acts as a mediator that resolves conflicts and ensures agreement among distributed participants.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a PKI trust bridge is used to extend trust between entities, then trust can be established between federated PKI infrastructures, but membership and auditing costs become relatively high

Engineering Contradiction:
Improvetrust extensionVSAvoidmembership and auditing costs
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent enables PKI entities to self-manage their trust relationships through the decentralized root store. Each entity can independently verify root certificates from other entities by checking them against the distributed root store, eliminating the need for expensive centralized auditing. The system allows entities to autonomously establish and verify trust relationships without requiring membership in expensive trust bridge consortia.

Inventive Principle:
Principle #25Self-service

3Productivity

If trusted root stores are built into operating systems or applications, then trust verification is streamlined, but the root store requires centralized management and periodic updates by trusted organizations

Engineering Contradiction:
Improvetrust verificationVSAvoidcentralized management structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent transitions the root store from a two-dimensional centralized database to a three-dimensional distributed network structure. The root store exists across multiple dimensions - spatially distributed across multiple nodes, temporally synchronized through consensus mechanisms, and hierarchically organized into blocks. This dimensional transformation enables streamlined verification while eliminating centralized management complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12184779B1Decentralized root store
Publication Date: 2024.12.31 ROCKWELL COLLINS INC
  • US12184779B1 patent drawing
  • US12184779B1 patent drawing
  • US12184779B1 patent drawing

AI summary

A network is described. The network is a peer-to-peer network of nodes. The nodes maintain a distributed ledger. The distributed ledger includes a list of transactions. The list of transactions includes various transactions for maintaining a decentralized root store between the nodes. The decentralized root store includes a list of certificate authorities which are trusted by the nodes in the network. The root certificates may be retrieved from the distributed ledger, validated, and then used to access the certificate authorities.