It’s not a blockchain. It’s closer to a series of forwarded emails with certificate signing. Who gets to add the next record? How about the party that is doing that step of processing in the supply chain. And I have a great idea for protecting the keys. It’s called asymmetric key pairs. You can verify a signature using a public key without having the private key required to be able to generate that signature.
Blockchain is the shitty reinvention of PGP, my dude. I don’t agree to this silly retronym for nearly 50 year old cryptographic methods. Yes, if you remove all the supposed advancements and advantages of blockchain, you’re left with the cryptographic foundation which was the only thing that had merit. Congratulations.