Distributed PKI Root CA Management via Blockchain and DNSSEC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Public Key Infrastructure (PKI) ecosystems face scalability limitations and security risks due to the requirement of a central authority, lengthy CA certificates, and the difficulty in implementing PKI without pre-established Root CAs, especially in distributed ecosystems.

Innovation Solution

A PKI ecosystem utilizing a digital ledger, such as a blockchain, and Domain Name System Security Extensions (DNSSEC) to create and manage public/private keypairs, register Certificate Authorities, and verify certificates without the need for a priori setup of Root CAs, enabling dynamic discovery and management of trusted CAs through consensus-based mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central Root CA is required in conventional PKI ecosystems, then trust verification can be established, but scalability is limited and supply chain problems occur

Engineering Contradiction:
Improvetrust verificationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the central Root CA from the PKI ecosystem and replaces it with a distributed network of CAs registered on a blockchain. Each CA operates independently without requiring a central authority, thereby maintaining trust verification through cryptographic proofs while enabling ecosystem scalability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the monolithic central Root CA into multiple independent CAs distributed across a blockchain network. Each CA manages its own certificate issuance independently, allowing the system to scale horizontally by adding more CAs without modifying the core trust architecture.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple independent Root CAs participate in the ecosystem, then trust diversity is achieved, but all endpoints must maintain a list of all participating Root CAs which limits the ecosystem

Engineering Contradiction:
Improvetrust diversityVSAvoidendpoint configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent enables endpoints to automatically discover and verify CAs through blockchain queries without manual configuration. The blockchain serves as a self-updating registry where endpoints can autonomously retrieve the current list of trusted CAs, eliminating the need for manual list maintenance and reducing configuration complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The blockchain acts as an intermediary between CAs and endpoints, providing a decentralized registry that automatically manages the list of trusted CAs. This intermediary eliminates the need for endpoints to maintain local lists, as the blockchain provides authoritative, up-to-date information on-demand.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Duration of action of stationary object

If conventional CA-level certificates are created with significant lengths of time (e.g., up to 50 years), then certificate stability is achieved, but security risks increase if certificates become compromised

Engineering Contradiction:
Improvecertificate validity periodVSAvoidsecurity risk
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The patent implements dynamic certificate validity periods managed through blockchain-based CA registration. CAs can register and renew their certificates with flexible timeframes, allowing the system to adapt certificate lifecycles based on security requirements rather than using fixed long-term validity periods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of certificate validity period from fixed long-term (50 years) to flexible short-term intervals. By implementing automated renewal mechanisms through blockchain smart contracts, the system maintains security by limiting the exposure window of compromised certificates while preserving stability through automated renewal processes.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If conventional PKI mechanisms depend on DNSSEC for specific use cases, then domain authentication is achieved, but bootstrapping is not allowed and building a trusted set of Root CAs using consensus is not enabled

Engineering Contradiction:
Improvedomain authenticationVSAvoidbootstrapping capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by pre-registering CAs on the blockchain before they issue certificates. This preliminary registration creates a trusted foundation that enables bootstrapping of new CAs and domains without requiring pre-existing Root CAs, as the blockchain itself serves as the initial trust anchor.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms through blockchain-based consensus where CAs and domains can be registered and verified through cryptographic proofs. The system provides feedback by allowing any participant to verify the authenticity of CAs and domains through blockchain queries, enabling decentralized trust establishment without central authority feedback loops.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11706038B1System and method for distributed PKI root
Publication Date: 2023.07.18 CABLE TELEVISION LAB INC
  • US11706038B1 patent drawing
  • US11706038B1 patent drawing

AI summary

A public key infrastructure (PKI) ecosystem includes a first organization computer system having a first processor, a first memory, and a first organization process including instructions that are (i) encoded in the first memory, and (ii) executable by the first processor. The ecosystem further includes a second organization computer system having a second processor and a second memory, a digital ledger, and domain name system security extensions (DNSSEC). When executed, the first instructions cause the first processor to create at least one public/private PKI keypair for a first domain name, in the DNSSEC, register the first domain name and create a certificate authority (CA), register the CA in the blockchain, using the CA, create a certificate for a first entity, register the certificate in the blockchain and/or the DNSSEC, and assert, to the second organization computer system, trust in the first entity based on the registered certificate.