Distributed Ledger Trust Bridging for Legacy Node Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy nodes, lacking the computational capabilities to participate in permissioned ledger channels, require static trust configurations that limit flexibility and adaptability in forming trust relationships with ledger-capable nodes, necessitating pre-provisioning and inflexible asset assignments.
Innovation Solution
A system that integrates distributed ledger-based trust relationships with traditional PKI-based trust mechanisms, enabling dynamic establishment of trust relationships between ledger-capable and legacy nodes using operational certificates and ad-hoc certificate authorities, allowing flexible and temporary trust management during missions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If legacy nodes use static trust configurations with pre-provisioned certificates, then security and authentication are maintained, but flexibility and adaptability in forming trust relationships are lost
Solution Approach 1:
The patent implements dynamic trust relationships by allowing ledger-capable nodes to act as ad-hoc certificate authorities that can issue operational certificates to legacy nodes on-demand. This transforms the static, pre-provisioned certificate model into a dynamic system where trust relationships can be established temporarily and revoked when no longer needed, enabling flexible asset assignments during missions while maintaining cryptographic security through the operational certificate mechanism.
2Reliability
If legacy nodes are pre-provisioned with certificates in advance, then authentication is established, but asset assignment flexibility and mission adaptability are reduced
Solution Approach 1:
The patent applies preliminary action by pre-configuring legacy nodes with a root certificate in advance, which enables them to verify operational certificates issued later by ad-hoc certificate authorities. This preliminary setup is minimal and does not require pre-provisioning of specific operational certificates, allowing certificates to be issued on-demand during missions while still providing immediate authentication capability.
3Device complexity
If static trust configurations are used for legacy nodes, then system simplicity is maintained, but operational flexibility and temporary trust establishment are limited
Solution Approach 1:
The patent introduces ledger-capable nodes as intermediaries that function as ad-hoc certificate authorities. These intermediaries bridge the gap between the simple static trust model and the need for dynamic trust relationships. The legacy nodes maintain simplicity by only needing to verify certificates against the root certificate, while the ledger-capable nodes handle the complexity of issuing and managing operational certificates on-demand, enabling temporary trust relationships without significantly complicating the legacy node implementation.
Data Source
AI summary
A system, apparatus and method for managing trust relationships with legacy nodes in a network of ledger-capable nodes. A first trust relationship is created among a plurality of ledger-capable nodes in the form of a permissioned mission channel. A second trust relationship is created among some of the ledger-capable nodes of the mission channel in a permissioned candidate channel. One of the ledger-capable nodes of the mission channel is selected as a trust manager for the candidate channel. The selected ledger-capable node establishes a third trust relationship with a legacy node based on a common, root certificate authority, and then another ledger-capable node establishes a fourth trust relationship with the legacy node based on the first ledger-capable node acting as a proxy certificate authority for the root certificate authority.


