This research investigates the potential use of a blockchain-based Public Key Infrastructure (PKI) within an organization and compares it to conventional PKI systems. The goal is to assess the advantages and disadvantages of both approaches in order to determine the feasibility of employing blockchain technology for a decentralized PKI. The study will also evaluate the impact of current legal frameworks, such as the Cyber Resilience Act (CRA) and NIS-2 Directive. The study will examine various implementations of blockchain PKIs based on factors such as security, performance, and platform. The results indicate that blockchain-based PKIs can overcome the limitations of conventional PKIs by decentralizing the trust anchor, providing greater security. Blockchain technology allows for the immutable and transparent management of certificates, making tampering significantly more challenging. Additionally, blockchain-based PKIs offer enhanced mechanisms for identifying and addressing certificate misconduct.
翻译:本研究探讨了在组织内部使用基于区块链的公钥基础设施(PKI)的潜在应用,并将其与传统PKI系统进行比较。研究旨在评估两种方法的优缺点,以确定采用区块链技术实现去中心化PKI的可行性。本研究还将评估当前法律框架(如《网络弹性法案》(CRA)和《网络与信息系统安全指令》(NIS-2))的影响。研究将基于安全性、性能和平台等因素,考察多种区块链PKI的实现方案。结果表明,基于区块链的PKI通过去中心化信任锚点,能够克服传统PKI的局限性,提供更高的安全性。区块链技术可实现证书的不可篡改和透明化管理,使伪造行为变得极为困难。此外,基于区块链的PKI还提供了增强的机制,用于识别和处理证书不当行为。