Email Public-Key Distribution Through Domain Key Authorities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of well-defined mechanisms for the distribution and lookup of users' public keys in existing Public Key Infrastructure (PKI) systems, which hinders secure communication and authentication across various applications, including encrypted email, instant messaging, and crypto wallets.

Innovation Solution

A decentralized public key framework utilizing Domain Key Authorities (DKAs) that store and serve public keys through DNS records, allowing for deterministic key lookup and distribution, eliminating the need for centralized Certificate Authorities and webs of trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized repository for hosting certificates is established, then key distribution becomes centralized and manageable, but it creates a single point of failure and reduces system decentralization

Engineering Contradiction:
Improvecertificate validation reliabilityVSAvoidcentralized infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized certificate repository into distributed domain-key authorities (DKAs), where each domain operates its own DKA that stores and serves public keys for email IDs within that domain. This segmentation eliminates the single point of failure while maintaining organized key distribution through domain-based autonomy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces DKAs as intermediary entities between email IDs and the broader system. Each DKA acts as a domain-specific mediator that authenticates and distributes public keys, replacing the need for a centralized repository while ensuring reliable key validation through domain-based trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Certificate Authorities issue and manage certificates, then key binding is certified, but it requires trust in third-party validation authorities

Engineering Contradiction:
Improvekey binding certificationVSAvoidthird-party authentication requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service through DKAs that autonomously authenticate email IDs and issue public key bindings without requiring external validation authorities. Each DKA independently verifies email ID ownership and certifies public key bindings, eliminating dependency on third-party CAs while maintaining certification reliability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If public keys are distributed through corporate email directories, then key lookup is simplified for corporate users, but it lacks universality across different domains and applications

Engineering Contradiction:
Improvekey lookup simplicityVSAvoidcross-domain applicability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal key distribution system where DKAs serve multiple functions: they store public keys, authenticate email IDs, enable encrypted communication, support digital signatures, and facilitate key exchange. This multi-functional DKA framework works across different domains and applications, extending beyond corporate email directories to provide universal adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If OpenPGP users upload certificates to open-source directories, then key distribution is decentralized, but key lookup becomes unreliable and uncertain

Engineering Contradiction:
Improvedecentralized distributionVSAvoidkey lookup reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where DKAs actively verify email ID ownership before issuing public keys and provide confirmation of key binding validity. This feedback loop ensures that decentralized key distribution maintains reliability, as each DKA confirms the authenticity of published keys through domain-based authentication rather than passive directory hosting.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12401508B2Public-key distribution framework
Publication Date: 2025.08.26 SWAMINATHAN KISHORE
  • US12401508B2 patent drawing
  • US12401508B2 patent drawing
  • US12401508B2 patent drawing

AI summary

Described herein is a public and distributed framework for the distribution and lookup of public keys of email IDs. In this framework, an Internet domain, via a DNS record, specifies its Domain Key Authority (DKA) which collects, stores, and serves the public keys of email IDs belonging to that domain. Through techniques described herein, the DKA verifies and guarantees the binding between an email ID and its public key without certificates or webs of trust. The DKAs provide, collectively, a logical framework for the distribution and lookup of public keys for the email namespace. Since users use email IDs routinely for signing into a range of applications, a public key framework for email IDs provides an authentication infrastructure without third-party authenticators. The framework has extensive uses in applications from email encryption to crypto wallets.