Digital Certificate Storage on Blockchain with Simplified CA Hierarchy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current blockchain ecosystems lack effective methods for securely linking public keys to real-world identities, leading to privacy and security risks, and existing certificate authority systems are fragmented and inefficient.

Innovation Solution

A method and system for storing digital certificates on a blockchain, utilizing a simplified CA hierarchy and embedding certificate metadata in OP_RETURN outputs, enabling secure verification, renewal, and revocation of digital certificates, while leveraging the blockchain's inherent security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are stored off-chain using traditional CA systems, then certificate issuance and management can be performed, but security risks increase and system complexity grows due to dependence on off-chain security protocols and fragmented CA hierarchies

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the certificate storage and verification processes from off-chain traditional CA systems onto the blockchain. By embedding certificate data directly in blockchain transactions and using blockchain's inherent cryptographic verification, the system eliminates the need for separate off-chain storage infrastructure and multiple fragmented CAs, thereby improving security while reducing system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a simplified CA hierarchy where CAs act as intermediaries that issue certificates by signing transactions on the blockchain. This intermediary layer maintains compatibility with traditional PKI while leveraging blockchain's security, allowing gradual migration without complete system overhaul

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If traditional CA systems are used for certificate management, then identity verification can be performed, but the process becomes inefficient and costly due to fragmented CA hierarchies and lack of standardized protocols

Engineering Contradiction:
ImproveefficiencyVSAvoidprocessing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent creates a universal certificate management system on the blockchain that can handle multiple CA hierarchies and certificate types through standardized transaction formats. This universal approach allows different CAs to operate on the same blockchain infrastructure with consistent verification protocols, improving efficiency by eliminating redundant processes and reducing processing time through automated cryptographic verification

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary verification mechanisms where certificate validity is checked through blockchain transaction verification before any actual use. The blockchain network pre- validates certificate signatures and maintains revocation status, so that verification happens in advance rather than requiring complex real-time checks during transaction processing

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12413428B2Computer implemented method and system for storing certified data on a blockchain
Publication Date: 2025.09.09 NCHAIN LICENSING AG
  • US12413428B2 patent drawing
  • US12413428B2 patent drawing
  • US12413428B2 patent drawing

AI summary

A method of storing certified data on a blockchain is disclosed. The method comprises generating a first blockchain transaction (Tx1) having a first output (Output 3) containing a first public key of a first private/public key pair, comprising a first private key and a first public key, of a cryptography system, first data related to the first public key, and a first digital signature applied, by means of a second private key of a second private/public key pair, comprising a second private key and a second public key, of a cryptography system, to the first data and to the first public key. The first blockchain transaction is broadcast to the blockchain.