Distributed PKI Root CA Management via Blockchain and DNSSEC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Public Key Infrastructure (PKI) ecosystems face scalability limitations and security risks due to the requirement of a central authority, lengthy CA certificates, and the difficulty in implementing PKI without pre-established Root CAs, especially in distributed ecosystems.
Innovation Solution
A PKI ecosystem utilizing a digital ledger, such as a blockchain, and Domain Name System Security Extensions (DNSSEC) to create and manage public/private keypairs, register Certificate Authorities, and verify certificates without the need for a priori setup of Root CAs, enabling dynamic discovery and management of trusted CAs through consensus-based mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central Root CA is required in conventional PKI ecosystems, then trust verification can be established, but scalability is limited and supply chain problems occur
Solution Approach 1:
The patent extracts the central Root CA from the PKI ecosystem and replaces it with a distributed network of CAs registered on a blockchain. Each CA operates independently without requiring a central authority, thereby maintaining trust verification through cryptographic proofs while enabling ecosystem scalability.
Solution Approach 2:
The patent segments the monolithic central Root CA into multiple independent CAs distributed across a blockchain network. Each CA manages its own certificate issuance independently, allowing the system to scale horizontally by adding more CAs without modifying the core trust architecture.
2Adaptability or versatility
If multiple independent Root CAs participate in the ecosystem, then trust diversity is achieved, but all endpoints must maintain a list of all participating Root CAs which limits the ecosystem
Solution Approach 1:
The patent enables endpoints to automatically discover and verify CAs through blockchain queries without manual configuration. The blockchain serves as a self-updating registry where endpoints can autonomously retrieve the current list of trusted CAs, eliminating the need for manual list maintenance and reducing configuration complexity.
Solution Approach 2:
The blockchain acts as an intermediary between CAs and endpoints, providing a decentralized registry that automatically manages the list of trusted CAs. This intermediary eliminates the need for endpoints to maintain local lists, as the blockchain provides authoritative, up-to-date information on-demand.
3Duration of action of stationary object
If conventional CA-level certificates are created with significant lengths of time (e.g., up to 50 years), then certificate stability is achieved, but security risks increase if certificates become compromised
Solution Approach 1:
The patent implements dynamic certificate validity periods managed through blockchain-based CA registration. CAs can register and renew their certificates with flexible timeframes, allowing the system to adapt certificate lifecycles based on security requirements rather than using fixed long-term validity periods.
Solution Approach 2:
The patent changes the parameter of certificate validity period from fixed long-term (50 years) to flexible short-term intervals. By implementing automated renewal mechanisms through blockchain smart contracts, the system maintains security by limiting the exposure window of compromised certificates while preserving stability through automated renewal processes.
4Reliability
If conventional PKI mechanisms depend on DNSSEC for specific use cases, then domain authentication is achieved, but bootstrapping is not allowed and building a trusted set of Root CAs using consensus is not enabled
Solution Approach 1:
The patent implements preliminary action by pre-registering CAs on the blockchain before they issue certificates. This preliminary registration creates a trusted foundation that enables bootstrapping of new CAs and domains without requiring pre-existing Root CAs, as the blockchain itself serves as the initial trust anchor.
Solution Approach 2:
The patent implements feedback mechanisms through blockchain-based consensus where CAs and domains can be registered and verified through cryptographic proofs. The system provides feedback by allowing any participant to verify the authenticity of CAs and domains through blockchain queries, enabling decentralized trust establishment without central authority feedback loops.
Data Source
AI summary
A public key infrastructure (PKI) ecosystem includes a first organization computer system having a first processor, a first memory, and a first organization process including instructions that are (i) encoded in the first memory, and (ii) executable by the first processor. The ecosystem further includes a second organization computer system having a second processor and a second memory, a digital ledger, and domain name system security extensions (DNSSEC). When executed, the first instructions cause the first processor to create at least one public/private PKI keypair for a first domain name, in the DNSSEC, register the first domain name and create a certificate authority (CA), register the CA in the blockchain, using the CA, create a certificate for a first entity, register the certificate in the blockchain and/or the DNSSEC, and assert, to the second organization computer system, trust in the first entity based on the registered certificate.

