SECURED DECENTRALIZED MULTI-STAKEHOLDER AUTOMATED PLATFORM FOR MANAGING OBJECT IDENTITIES USING BLOCKCHAIN TECHNOLOGY
Patent Information
- Application Number
- DE602020051198
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-16
- Filing Date
- 2020-12-16
- Publication Date
- 2025-05-14
- Estimated Expiration
- 2040-12-16
AI Technical Summary
Existing identity management and access solutions for IoT objects are centralized, which violates GDPR regulations and lacks scalability, security, and automation for managing object identities and access to digital services.
A decentralized communication process using a blockchain database for secure key and identity management, allowing objects to self-enroll and manage their identities, transfer ownership, and update attributes securely and autonomously.
This solution provides a scalable, secure, and automated identity management system that complies with GDPR regulations, enabling secure access to digital services for IoT objects while ensuring confidentiality, integrity, and authentication.
Description
TECHNICAL FIELD OF THE INVENTION
[0001] The present invention relates generally to the field of Identity and Access Management, and more particularly to automated access by objects, in a secure manner, to digital services, and the protection of the exchanges which follow. STATE OF PRIOR ART
[0002] Today, we are in a context of rapid growth of the Internet of Things (IoT) and securing these objects. A market estimate puts the number of objects connected to the IoT at 30 billion by 2020. This is why it is important to find IoT solutions that meet the need for scalability to meet demand, but also the security aspects to protect against cyberattacks. The security needs associated with object communications (confidentiality, integrity, authentication and non-repudiation) are covered by the use of cryptographic mechanisms based on sets of keys and digital identities. This key and identity manager thus represents the heart of the system's security.From the point of view of objects, it is thanks to this manager that the object is authorized to transmit on a network and to access an application service (identification and authentication of the object), that it is capable of transmitting encrypted, integral and authenticated messages and that it is capable of decrypting the data received (symmetric / asymmetric cryptography).
[0003] Automated, secure access by objects to digital services, and the protection of the exchanges that follow, require the implementation of enrollment processes for both the manufacturers of objects and the objects themselves, as well as their association with the digital services in question ("on-boarding service").
[0004] These processes must address issues such as the identification of objects with a list of associated attributes (including security identifiers such as cryptographic keys), and their registration in a repository of the Manufacturer of the objects; The transfer of ownership and / or exploitation rights of an object from a Manufacturer to a user of the object (for example, a service provider using the object); The transfer of ownership and / or exploitation rights from one user to another (case, for example, of the need for reversibility); The updating of attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.
[0005] Additionally, platforms that meet these processes must demonstrate high resilience to failures, high availability and strong security.
[0006] With the rise of connected objects (IoT), and particularly small and low-cost IoT objects, new constraints specific to them are emerging, such as reduced memory size, low computing power, low consumption and a possible offline mode or disconnection of the object.
[0007] In addition to all these technical constraints, there are growing legal constraints, such as the new regulations in force on data ownership (GDPR) and Privacy by Design (PvD).
[0008] There are several solutions available today to address these issues, including IAM (Identity and Access Management) solutions, more commonly known as IAM (Identity Access Management). Many cybersecurity companies offer such solutions: Active Directory, IBM Security Identity and Access Assurance, Oracle Identity Cloud Service, Okta, Centrify, RSA SecurID Access, Keeper Security, SailPoint, OneLogin, Ping, etc. However, the various players on this list offer centralized solutions, with internal data storage that may be personal and therefore sensitive and thus no longer comply with GDPR regulations.
[0009] For example, US 2019 / 222424 A1 describes a system for linking verifiable claims. Such a system includes: a client device; an authenticator of the client device for securely storing authentication data comprising one or more verifiable attestations received from one or more attestation providers, with attributes associated with each verifiable attestation; and attestation / attribute processing logic for generating a first verifiable attestation binding for a first verifiable attestation issued by the attestation provider; the authenticator to transmit a first signature assertion to a first relying party in order to authenticate to the first relying party, the first signature assertion comprising an attribute extension containing data associated with the first verifiable attestation binding.
[0010] These solutions generally offer a centralized technical process usually managed by the service provider, which does not allow for automation, and prior bipartite agreements between service providers and object manufacturers, necessary to enable the association of objects with the provider's services.
[0011] The item is already registered and “paired with its Manufacturer / Owner”. STATEMENT OF THE INVENTION
[0012] The present invention therefore aims to propose a communication method for the secure management of keys and identities, making it possible to overcome at least some of the drawbacks of the prior art.
[0013] Thisgoal is achieved by a communication method for the secure management of keys and identities of an Object manufactured by a Manufacturer having a public key pair Kp, private or secret key Ks of Manufacturer (Ks man , Kp man ) and a client having a Client key pair (Ks client , Kp client ), characterized in that the management is done at least partially on a decentralized database of blockchains, and that the method comprises the following steps: a) Generation by the Manufacturer of a manufacturing key pair (Ks fab ,Kp fab ) obtained via a key derivation function, the manufacturing key pair being recorded in the object, and composed of a manufacturing private key (Ks fab ) resulting from the derivation of the Manufacturer's private key (Ks man ) with a diversifier (DIV), and a manufacturing public key (Kp fab ) complementary to said private key (Ks fab ), the public key (Kp fab ) resulting from the derivation of the Manufacturer's public key (Kp man ) with the same diversifier (DIV). b) Publication and recording in the blockchain of the decentralized identifier (DID) comprising the public key Kp fab of the object and preferably of the diversifier (DIV) used to obtain the public key Kp fab of the object: DID-DIV association. And, when a Customer purchases the item from said Manufacturer, the process includes the following initialization steps: c) Provision by the Manufacturer of the object, of the identifier of the object DID including the manufacturing public key Kp fab to the client. d) Updating the blockchain by publishing the client's public key Kp client and creating the association in said database between the DID and the DIV and Kp client And, when the object is first turned on, the object enrolls itself according to the following steps: e) Generation of a usage key pair (Ks util , Kp util ), the generation preferably being carried out from a random number generated by the object itself. f) Self-enrollment using the manufacturing key pair by publication by the object of its public usage key (Kp util ) in an enrollment message, and signing of the enrollment message with the manufacturing private key (Ks fab ) g) Replacement in the block chain of the manufacturing public key associated with the DID of the object by the usage public key associated with the DID of the object.
[0014] According to A special feature is that the key pair generator relies on hierarchical key wallets to provide unique manufacturing key pairs that are diversified from the Manufacturer's key pair.
[0015] According to Another feature is that the object is transferred from one owner to another by repeating steps d to g.
[0016] According to another feature, the method further comprises a step prior to the generation of manufacturing key pairs by the Manufacturer, in which said Manufacturer records its Manufacturer identifier in the blockchain database and publishes its Manufacturer public key (Kp man ) by associating it with the Manufacturer identifier.
[0017] According to another particularity, the sharing or management of rights on the object is carried out by the owner of the object by means of verifiable titles (Verifiable Credentials), preferentially requested by the service providers (Service Providers) and validated by the owner.
[0018] According to another particularity, a Zero Knowledge Proof (ZKP) system is implemented within a smart contract to provide information without revealing its values.
[0019] The present invention also relates to a secure identity management system based on a blockchain capable of carrying out the steps of a process carrying out: The identification of objects with a list of associated attributes, including security identifiers such as cryptographic keys, and their registration in a Manufacturer's repository; The transfer of ownership and / or exploitation rights of an object from a Manufacturer to a user of the object, for example a service provider using the object, by registering new identities associated with the object; The transfer of ownership and / or exploitation rights from one user to another, by registering new identities associated with the object; The updating of attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.
[0020] ThereThe present invention also relates to a database, used by the secure identity management system based on a blockchain, implemented on a secure, decentralized, automated and multi-actor platform for managing object identities through the use of blockchain technology implemented on several nodes of the system with which the platform communicates, the nodes being responsible for maintaining the blockchain and allowing actors (and objects) to consult the state of this chain and to interact with this chain via a shared common repository (or register), each node having access to a cryptographic module, preferably physical,in charge of the secure storage of its private key and access to the shared registry characterized in that the database constitutes a repository for each manufacturer containing a list of associated attributes (including in particular security identifiers such as cryptographic keys) and either recording them in the Manufacturer's repository, or updating the attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.,
[0021] There The present invention also relates to a secure, decentralized, automated and multi-actor platform for managing object identities using a database, characterized in that it manages: Transfer of ownership and / or exploitation rights of an object; Recording of proof of possession of an object in the shared repository; Activation / reactivation of objects;
[0022] According to a particularity, the blockchain technology used does not have to be of a specific type and includes at least: a permission system, to strongly identify and authenticate an actor; an access control system, based on user identities; an anti-replay mechanism,
[0023] Each node maintaining the blockchain must be in a secure environment, and the public identity of each node must be made available to other nodes and actors within the shared registry; the execution of Smart Contracts and functions on the blockchain being carried out in this secure sphere, the purpose of registration being to create a link, accessible by everyone in the blockchain, to allow the actor and his digital identity to be matched by a key pair, public key and private key, or by a certificate possibly signed by a certified identity management organization.
[0024] There The present invention also relates to a secure identity management system based on a blockchain and capable of carrying out the steps of a communication method for the secure management of keys and identities, the system comprising at least: A Manufacturer, using a key diversification system from diversifiers generated by a diversifier generator, a system for connecting to a blockchain, a system for assigning an identifier to each object produced from manufacturing and a hardware and software arrangement for sending to the blockchain server a message for publishing and registering the client's public key Kp client and the association in said database between the DID and the DIV.
[0025] ThereThe present invention also relates to a secure identity management system based on a blockchain and capable of carrying out the steps of a communication method for the secure management of keys and identities, the system comprising at least: An object provided with means of calculation and means of memorizing a program and sufficient data to carry out the following operations: when the object is switched on for the first time, the object is enrolled according to the following steps: Generation of a usage key pair (Ks util , Kp util ), the generation being preferably carried out from a random number, Self-enrollment thanks to the manufacturing key pair by publication by the object of its public usage key (Kp util ) in an enrollment message, and signing of the enrollment message with the manufacturing private key (Ks fab ) Replacement in the block chain of the manufacturing public key by the usage public key
[0026] The present invention also relates to an identity management system of an identity service provider (ID service provider) implementing a blockchain and using the objects recorded on a network to fulfill application services (AS) in which the information provided by the objects is used, each node of the network of the identity service provider has access to a cryptographic module in charge of the secure storage of the private key of said node, the nodes having clients called Actors each having their own identity ID act recorded in the blockchain, each object manufacturer is recorded in the blockchain of the identity service provider and the manufacturers' public manufacturing keys are known to all, for each object sold or transferred, each manufacturer provides the identifier of the object and a diversifier used by the manufacturer (DID,DIV) for the calculation of the manufacturing key pairs of each object by the manufacturer, and only the object identifier and the manufacturing public key are published in the blockchain, only the manufacturing private key remains stored outside the chain, in this case in the object; Each object being provided with means of calculation and means of memorizing a program and sufficient data to execute the following operations: when the object is switched on for the first time, the object enrolls with the identity service provider by carrying out the following steps: Generation in the object of a usage key pair (Ks util , Kp util ), the generation preferably being carried out from a random number generated by the object itself. Self-enrollment thanks to the usage key pair by publication by the object of its public usage key (Kp util ), and signing of the transaction with the private manufacturing key (Ks fab ) Replacement of the public manufacturing key by the public usage key by updating the blockchain.
[0027] ThereThe present invention also relates to an object provided with calculation means and means for storing a program and data sufficient to carry out the following operations: when the object is switched on for the first time, the object is enrolled according to the following steps: Generation of a usage key pair (Ks util , Kp util ), the generation preferably being carried out from a random number generated by the object itself. Self-enrollment using the manufacturing key pair by publication by the object of its public usage key (Kp util ) in an enrollment message, and signing of the enrollment message with the manufacturing private key (Ks fab ) Replacement of the manufacturing public key by the usage public key by updating the blockchain. BRIEF DESCRIPTION OF THE FIGURES
[0028] Other characteristics, details and advantages of the invention will emerge from reading the description which follows with reference to the appended figures, which illustrate: [ Fig. 1 ], represents an embodiment of the method in a schematic manner. [ Fig. 2 ], represents steps a) and b) of the method according to certain embodiments, [ Fig. 3 ], represents steps c) and d) of the method according to certain embodiments, [ Fig. 4 ], represents steps e), f), and g) of the method according to certain embodiments, DETAILED DESCRIPTION OF THE INVENTION
[0029] Many combinations can be envisaged without departing from the scope of the invention; the person skilled in the art will choose one or the other depending on the economic, ergonomic, dimensional or other constraints that he must respect.
[0030] OfIn general, the present invention comprises a communication method for the secure management of keys and identities of an Object manufactured by a Manufacturer having a public key pair Kp, private or secret key Ks of the Manufacturer (Ks man , Kp man ) and a client having a Client key pair (Ks client , Kp client ), characterized in that the management is done at least partially on a decentralized database of blockchains, and that the method comprises the following steps: a) Generation by the Manufacturer of a manufacturing key pair (Ks fab ,Kp fab ) obtained via a key derivation function, the manufacturing key pair being recorded in the object, and composed of a manufacturing private key (Ks fab ) resulting from the derivation of the Manufacturer's private key (Ks man ) with a diversifier (DIV), and a manufacturing public key (Kp fab ) complementary to said private key (Ks fab ), the public key (Kp fab ) resulting from the derivation of the Manufacturer's public key (Kp man ) with the same diversifier (DIV). b) Publication and recording in the blockchain of the decentralized identifier (DID) of the object and preferably of the diversifier (DIV) used to obtain the public key Kp fab of the object: DID-DIV association. And, when a Customer purchases the item from said Manufacturer, the process includes the following initialization steps: c) Provision by the Manufacturer of the object, of the object identifier DID, And of the manufacturing public key Kp fab to the client, d) Updating the blockchain by publishing the client's public key Kp client and creating the association in said database between the DID and the DIV and Kp client And, when the object is first turned on, the object enrolls itself according to the following steps: e) Generation of a usage key pair (Ks util , Kp util ), the generation preferably being carried out from a random number generated by the object itself. f) Self-enrollment using the manufacturing key pair by publication by the object of its public usage key (Kp util ) in an enrollment message, and signing of the enrollment message with the manufacturing private key (Ks fab ) g) Replacement in the block chain of the manufacturing public key associated with the DID of the object by the usage public key associated with the DID of the object.
[0031] Enrollment is made possible because the object knows its manufacturer's access point (IP address and / or gateway, etc.) and is in possession of the Kfab key pair (in particular the private key).
[0032] In some embodiments, each publication in the blockchain is equivalent to at least one transaction therein.
[0033] The DIV diversifier may not be published in the Blockchain, but for security reasons it is. This allows the Manufacturer to avoid storing the manufacturing key pair, and thus be obliged to recalculate it if necessary.
[0034] There is a relationship that allows the association between the DID and the DIV. Thus, any actor is able to find the DIV if they know the DID. The DIV is necessary because it allows the manufacturer to recalculate the key: DIV for diversifier. A diversified key is obtained from a key and a diversifier: the key is known to the manufacturer and the diversifier is stored in the blockchain.
[0035] Advantageously, the object is capable of self-enrollment and signs the enrollment message with the manufacturing key (Ks fab ) that only it possesses.
[0036] Advantageously, the replacement in the blockchain is achieved by updating the blockchain via a transaction. The blockchain is like a state register: updating the state of a value, therefore replacing it via a transaction. The old state is kept (blockchain paradigm) but is no longer up to date.
[0037] A decentralized database, or "blockchain," is a decentralized database comprising a network of blockchains, with nodes comprising all or part of the blockchain ledger. Advantageously, to keep track of all transactions, the blockchain network uses the multi-chain ledger that is replicated across all peer nodes in the blockchain network. The blockchain is a list of blocks, each containing multiple transactions. Each block has a pointer to the previous block, and the order and content of the blocks are protected by hash signatures. Bitcoin mining nodes construct new blocks from incoming transactions. This construction is made difficult to achieve and requires considerable mining computations, the proof of work.The effort involved makes it equally difficult to change blocks already included in the blockchain, especially since changing a block in the middle of the chain would require recreating all subsequent blocks. Thus, the blockchain ledger is well protected from changes and can be considered a permanent record of transactions. To incentivize mining effort, miners are rewarded with newly created bitcoins when a block is created. They also receive all transaction fees from transactions included in the new block.
[0038] There Blockchain technology is used as a shared and distributed repository of identities including a list of associated public attributes. These identities may, for illustration purposes, use the DID format defined in the "Decentralized Identifiers (DIDs)" specification.
[0039] The system is preferably not based on a public blockchain, and not on a blockchain with a proof of work, which requires computing power and energy in an IoT use case (objects with low consumption and low computing power constraints). On the contrary, the solution is preferably based on a consortium blockchain / enterprise blockchain / permission blockchain / POK blockchain (Proof of Knowledge).
[0040] The invention relates to a secure, decentralized, automated and multi-actor system or platform for managing object identities through the use of blockchain technology. In other words, a blockchain system in order to benefit from its advantages: scalability, replication, resilience to failures / attacks while adding an additional layer for IAM and IAM linked to the identity of the entities.
[0041] These embodiments therefore do not require additional actors, additional servers, only the direct actors (Manufacturer, Client, Object), a decentralized blockchain database, and potentially a service provider. Advantageously, the nodes of the blockchain are only used to store data and update them via transactions carried out on said blockchain.
[0042] Some solutions require the presence of a DM (Device Manager), while in this system, the registration is already done and the enrollment on the network is initiated by the object. The autonomous object thanks to the DID.
[0043] In In some embodiments, the provision of data, in particular the identifier of the DID object, and the public manufacturing key Kp fab, to the client, is carried out by an “off-chain” transmission.
[0044] An "off-chain" data supply or sending is understood to mean a supply or sending of data by a mechanism external to the blockchain, in order to improve the security and confidentiality of particularly sensitive data. This means, for example, secure sending by email, making it available on a secure storage server, sending a USB key with the secure data, or other possible means that can be envisaged by a person skilled in the art that respond to the given problem.
[0045] In some embodiments, the key pair generator relies on hierarchical key wallets to provide the unique manufacturing key pairs that are diversified from the Manufacturer's key pair.
[0046] In some embodiments, the object is transferred from one owner to another by repeating steps d through g.
[0047] In some embodiments, the method further comprises a step prior to the generation of manufacturing key pairs by the Manufacturer, in which said Manufacturer registers its Manufacturer identifier in the blockchain database and publishes its Manufacturer public key (Kp man ) by associating it with the Manufacturer identifier.
[0048] In some embodiments, the sharing or management of rights to the object is carried out by the owner of the object by means of verifiable credentials, preferably requested by service providers and validated by the owner.
[0049] Verifiable Credentials and DID Documents (Decentralized Identifiers) will be used respectively as a means of access control and as a format for storing information related to the object on the blockchain. The former allows read access to the object's information based on the peer's identity.
[0050] In some embodiments, in the method, a Zero Knowledge Proof (ZKP) system is implemented within a Smart Contract to provide information without revealing its values.
[0051] THEZPK is a method that allows one entity to prove to another that a proposition is true without revealing its value. This allows, for data preservation purposes, to answer a question without revealing the value. For example, a service can ask an object if its temperature is below or above 0°C without the object having to reveal its temperature value. This allows optimization based on the use of the service, not on the steps.
[0052] A Smart Contract is a unique and replicated digital protocol / program that allows operations to be carried out on the blockchain, and that this is done in compliance with well-defined rules.
[0053] Thus, all registrations / publications in the blockchain go through smart contracts. Access rules are also governed by smart contracts.
[0054] Various embodiments described also relate to a secure identity management system based on a blockchain.
[0055] Thus, in certain embodiments, a secure identity management system based on a blockchain is capable of carrying out the steps of a process carrying out: The identification of objects with a list of associated attributes, including security identifiers such as cryptographic keys, and their registration in a Manufacturer's repository; The transfer of ownership and / or exploitation rights of an object from a Manufacturer to a user of the object, for example a service provider using the object, by registering new identities associated with the object; The transfer of ownership and / or exploitation rights from one user to another, by registering new identities associated with the object; The updating of attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.
[0056] Thus, a system or a secure, decentralized, automated and multi-actor platform for managing object identities can be set up through the use of blockchain technology, allowing automated access by objects, in a secure manner, to digital services, and ensuring protection of the exchanges that follow.
[0057] Various embodiments described also relate to a database, used by the blockchain-based secure identity management system.
[0058] Thus, certain embodiments relate to a database, used by the secure identity management system based on a blockchain, implemented on a secure, decentralized, automated and multi-actor platform for managing object identities through the use of blockchain technology implemented on several nodes of the system with which the platform communicates, the nodes being responsible for maintaining the blockchain and allowing actors (and objects) to consult the state of this chain and to interact with this chain via a shared common repository (or register), each node having access to a cryptographic module, preferably physical, in charge of the secure storage of its private key and access to the shared register characterized in that the database constitutes a repository for each manufacturer containing a list of associated attributes,including in particular security identifiers such as cryptographic keys, and either registering them in the Manufacturer's repository, or updating the attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.,
[0059] Miscellaneous The embodiments described also relate to a secure, decentralized, automated and multi-actor platform for managing object identities using a decentralized database.
[0060] In some embodiments, a secure, decentralized, automated, multi-actor object identity management platform using a decentralized database manages: Transfer of ownership and / or exploitation rights of an object; Recording of proof of possession of an object in the shared repository; Activation / reactivation of objects;
[0061] In In some embodiments, the blockchain technology used does not have to be of a specific type. In some embodiments, the blockchain technology used comprises at least: a permission system, to strongly identify and authenticate an actor; an access control system, based on user identities; an anti-replay mechanism, Each node maintaining the blockchain must be in a secure environment, and the public identity of each node must be made available to other nodes and actors within the shared registry; the execution of Smart Contracts and functions on the blockchain being carried out in this secure sphere, the purpose of registration being to create a link, accessible by everyone in the blockchain, to allow the actor and his digital identity to be matched by a key pair, public key and private key, or by a certificate possibly signed by a certified identity management organization.
[0062] A replay attack (or playback attack) is a form of network attack in which a transmission is maliciously repeated by an attacker who has intercepted the transmission. It is a type of spoofing.
[0063] In certain embodiments, the system comprises at least: A Manufacturer, using a key diversification system from diversifiers generated by a diversifier generator, a system for connecting to a blockchain, a system for assigning an identifier to each object produced from manufacturing and a hardware and software arrangement for sending to the blockchain server a message for publishing and registering the public key of the client Kp client and the association in said database between the DID and the DIV.
[0064] Registration, also called personalization, is done only once by the manufacturer. The object updates itself in the stages following manufacturing, in particular when it is purchased / given away.
[0065] In some embodiments, the system comprises at least: An object provided with means of calculation and means of memorizing a program and sufficient data to carry out the following operations: when the object is switched on for the first time, the object is enrolled according to the following steps: Generation of a usage key pair (Ks util , Kp util ), the generation being preferably carried out from a random number, Self-enrollment thanks to the manufacturing key pair by publication by the object of its public usage key (Kp util ) in an enrollment message, and signing of the enrollment message with the manufacturing private key (Ks fab ) Replacement in the block chain of the manufacturing public key by the usage public key.
[0066] Enrollment is made possible because the object knows its manufacturer's access point (IP address and / or gateway, etc.) and is in possession of the Kfab key pair (in particular the private key).
[0067] In some embodiments, an identity management system of an identity service provider (ID service provider) implements a blockchain and uses the objects registered on a network to fulfill application services (AS) in which the information provided by the objects is used, each node of the network of the identity service provider has access to a cryptographic module in charge of the secure storage of the private key of said node, the nodes having clients called Actors each having their own identity ID act registered in the blockchain, each object manufacturer is registered in the blockchain of the identity service provider and the manufacturers' manufacturing public keys are known to all, for each object sold or transferred, each manufacturer provides the identifier of the object and a diversifier used by the manufacturer (DID,DIV) for the calculation of the manufacturing key pairs of each object by the manufacturer, and only the object identifier and the manufacturing public key are published in the blockchain, only the manufacturing private key remains stored outside the chain, in this case in the object; Each object being provided with means of calculation and means of memorizing a program and sufficient data to execute the following operations: when the object is switched on for the first time, the object enrolls with the identity service provider by carrying out the following steps: Generation in the object of a usage key pair (Ks util , Kp util ), the generation preferably being carried out from a random number generated by the object itself. Self-enrollment thanks to the usage key pair by publication by the object of its public usage key (Kp util ), and signing of the transaction with the private manufacturing key (Ks fab ) Replacement of the public manufacturing key by the public usage key by updating the blockchain.
[0068] Alternatively, it would be possible, but less secure, to send the new diversifiers directly to the Smart Contract which encrypts them with the client's public key.
[0069] In some embodiments, an object is provided with computing means and means for storing a program and data sufficient to perform the following operations: when the object is first powered on, the object enrolls according to the following steps: Generation of a usage key pair (Ks util , Kp util ), the generation preferably being carried out from a random number generated by the object itself. Self-enrollment using the manufacturing key pair by publication by the object of its public usage key (Kp util ) in an enrollment message, and signing of the enrollment message with the manufacturing private key (Ks fab ) Replacement of the manufacturing public key by the usage public key by updating the blockchain
[0070] It is understood that throughout this description an automated Identity and Access management system is described through the use of blockchain technology.
[0071] In some embodiments, and in summary, the manufacturers are registered in the Blockchain, and their respective public keys are known to all. They manufacture and personalize Objects with identifiers and manufacturing keys. For each object, they publish in the Blockchain the identifier, and the diversifier used to calculate the manufacturing key. The objects are capable of self-enrollment and changing keys by generating their own keys. The key change is allowed / validated thanks to the private manufacturing key that only the object possesses and uses. The service providers can verify via the Blockchain that the Object has indeed changed its key. This verification of the signature of the change could only be done by the object alone knowing the manufacturing key. figure 1 illustrates this by way of example and in a non-limiting manner.
[0072] More specifically, the figure 2illustrates an exemplary non-limiting embodiment of the present invention, in which steps a) and b are represented. Step a) concerns the generation of the manufacturing key pair (Ks fab ,Kp fab ) obtained via a key derivation function using a diversifier (DIV) from the Manufacturer's key pair (Ks man , Kp man ) (Step I-1), and the personalization of the object (the object is made aware of its manufacturer's access point (IP address and / or gateway, etc.) and in possession of the Kfab key pair (Step I-2)). Step b) concerns the publication and recording in the blockchain of the DID and the DIV (Step II). Thus, the script with a double signature makes it possible to differentiate the owner of the object from the one who created the object. This also makes it possible to check that the one who writes this transaction is indeed the one who created the object.
[0073] There figure 3illustrates an exemplary non-limiting embodiment of the present invention, in which steps c) and d) are represented, corresponding to the steps carried out when a Customer purchases the object from said Manufacturer (Step III-1). Proof of ownership of the object is done intrinsically because the owner is the only one to possess the private key associated with the referenced public key. During the exchange between the Customer and the Manufacturer, the customer proves that he is indeed the owner of the public key by inserting his signature (Step III-2). The provision of data by the Manufacturer to the customer by an “off-chain” mechanism is not shown. The Manufacturer updates the common repository by publishing the public key associated with the Customer Kp customer and creating the association in said database between the DID and the DIV and Kp customer (Step III-3).
[0074] Finally, the figure 4illustrates an exemplary non-limiting embodiment of the present invention, in which steps e), f), and g) are represented, corresponding to the steps carried out when the object is switched on for the first time, and self-enrolls. Indeed, once switched on, the object generates a usage key pair (Step IV-1). The object then self-enrolls by publishing its public usage key (Kp util ) in an enrollment message (Step IV-2), the enrollment message being signed with the private manufacturing key (Ks fab ) that only the Object possesses. Finally, the publication (Step IV-3) for updating the blockchain of the public usage key associated with the DID of the object (and therefore replacing the public manufacturing key associated with the DID of the object with said public usage key).
[0075] The system thus includes a secure identity manager based on a blockchain in which the identities or the process for finding these identities are published. The nodes of the shared registry thus maintain a blockchain and, by extrapolation, the identity manager.
[0076] We It will be readily understood from reading this application that the features of the present invention, as generally described and illustrated in the figures, can be arranged and designed in a wide variety of different configurations. Thus, the description of the present invention and the related figures are not intended to limit the scope of the invention but simply represent selected embodiments.
[0077] Those skilled in the art will understand that the technical features of a given embodiment may in fact be combined with features of another embodiment unless the opposite is explicitly stated or it is obvious that these features are incompatible. Furthermore, the technical features described in a given embodiment may be isolated from the other features of this embodiment unless the opposite is explicitly stated.
[0078] It should be obvious to those skilled in the art that the present invention allows embodiments in many other specific forms without departing from the field defined by the scope of the appended claims, they should be considered by way of illustration and the invention is defined only by the claims.
Claims
1. A communication method for the secure management of keys and identities of an Object manufactured by a Manufacturer having a Manufacturer key pair of public key Kp, and private or secret key Ks (Ksman, Kpman), and a client having a Client key pair (Ksclient, Kpclient), characterized in that the management is carried out at least partially on a decentralized blockchain database, and in that the method comprises the following steps: a) Generation, by the Manufacturer, of a manufacturing key pair (Ksfab,Kpfab) obtained via a key derivation function, the manufacturing key pair being recorded in the object, and composed of a private manufacturing key (Ksfab) resulting from the derivation of the private Manufacturer key (Ksman) with a diversifier, DIV, and of a public manufacturing key Kpfab, complementary to said private key (Ksfab), the public key (Kpfab) resulting from the derivation of the public Manufacturer key (Kpman) with the same diversifier DIV; b) Publication and recording, in the blockchain, of a decentralized Identifier, DID, comprising the public manufacturing key Kpfab of the object and preferentially of the diversifier DIV used to obtain the public key Kpfab of the object: DID-DIV association; and when a Client purchases the object from said Manufacturer, the method comprises the following initialization steps: c) Providing, by the Manufacturer of the object, of the identifier of the object DID, comprising the public manufacturing key Kpfab to the client, preferentially by a mechanism outside of the blockchain, referred to as "off-chain" d) Updating the blockchain by publication of the public client key Kpclient and creation of the association, in said database, between the DID and the DIV and Kpclient; and when the object is switched on for the first time, the object enrolls itself according to the following steps: e) Generation of an utilization key pair (Ksutil, Kputil), the generation preferably being carried out from an unknown generated by the object itself; f) Auto-enrollment using the manufacturing Key pair by publication, by the object, of its public utilization key (Kputil) in an enrollment message, and signing of the enrollment message with the private manufacturing key (Ksfab); g) Replacement, in the blockchain, of the public manufacturing key associated with the DID of the object with the public utilization key associated with the DID of the object.
2. The communication method according to claim 1, wherein the key pair generator is based on Hierarchical Key Wallets to provide the unique manufacturing key pairs which are diversified based on the Manufacturer key pair.
3. The communication method according to claim 1, wherein the object is transferred from one owner to another by reiterating steps d to g.
4. The communication method according to any one of the preceding claims, which further comprises a step prior to the generation of the manufacturing key pairs by the Manufacturer, wherein said Manufacturer records their Manufacturer identifier in the blockchain database and publishes their public Manufacturer key (Kpman) by associating it with the Manufacturer identifier.
5. The communication method according to any one of the preceding claims, wherein sharing or managing the rights to the object is performed by the owner of the object by means of Verifiable Credentials, preferentially requested by the Service Providers and validated by the owner.
6. The communication method according to any one of the preceding claims, wherein a Zero Knowledge Proof (ZKP) system is established within a Smart Contract, in order to give information without revealing the values thereof.
7. A system for managing secure identities based on a blockchain and configured to carry out the steps of the method according to any one of claims 1 to 6, the system comprising at least: - a Manufacturer, using a key diversification system based on diversifiers generated by a diversifier generator, - a connection system for connecting to a blockchain, - an attribution system for attributing an identifier to each object leaving manufacturing, and - a hardware and software arrangement for sending, to the blockchain server, a message of publication and of recording of the public client key Kpclient and of the association in said database between the DID and the DIV.
8. A system for managing secure identities based on a blockchain and configured to carry out the steps of the method according to any one of claims 1 to 6, the system comprising at least: - An object provided with computation means and storing means for storing a program and sufficient data to carry out the following operations: when the object is switched on for the first time, the object enrolls itself according to the following steps: - Generation of an utilization key pair (Ksutil, Kputil), the generation preferably being carried out from an unknown, - Auto-enrollment using the manufacturing Key pair by publication, by the object, of its public utilization key (Kputil) in an enrollment message, and signing of the enrollment message with the private manufacturing key (Ksfab) - Replacement, in the blockchain, of the public manufacturing key with the public utilization key.