A Semi-decentralized PKI Based on Blockchain with Identity Retention
摘要
Public Key Infrastructure (PKI) plays an essential role in securing communication and data exchange over the Internet. PKIs typically utilize two trust models: the CA-based model, which relies on a central authority for certificate issuance but creates a single point of failure, and the Web of Trust model, which distributes trust among users but lacks scalability. In this paper, we introduce the Multi-CA trust model, which employs signatures from multiple Certificate Authorities (CAs) to enhance resilience and mitigate single-point-of-failure risks. Moreover, current PKIs often lack safeguards to prevent attackers from impersonating identities registered to legitimate owners. To address this issue, we introduce an identity retention mechanism to protect user identities. Finally, blockchain technology is applied to monitor and log the entities’ activities to ensure the system’s trust and transparency.