SECURED DECENTRALIZED MULTI-STAKEHOLDER AUTOMATED PLATFORM FOR MANAGING OBJECT IDENTITIES USING BLOCKCHAIN TECHNOLOGY

DE602020052870T2Active Publication Date: 2025-06-18BULL SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602020052870
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-12-16
Filing Date
2020-12-16
Publication Date
2025-06-18
Estimated Expiration
2040-12-16

AI Technical Summary

Technical Problem

Existing Identity and Access Management (IAM) solutions for IoT devices are centralized, lacking automation and compliance with GDPR regulations, and require significant computing and storage resources, which are not feasible for all IoT objects.

Method used

A decentralized communication method using a blockchain database for secure key and identity management, where symmetric keys are generated and shared by manufacturers, and object identities are registered and updated on a blockchain, enabling secure access to digital services and transferring ownership rights.

Benefits of technology

This solution provides secure, automated, and scalable management of IoT device identities and keys, ensuring compliance with GDPR and supporting low-resource IoT devices by decentralizing data storage and processing.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD OF THE INVENTION

[0001] The present invention relates generally to the field of Identity and Access Management, and more particularly to automated access by objects, in a secure manner, to digital services, and the protection of the exchanges which follow. STATE OF PRIOR ART

[0002] Today, we are in a context of booming Internet of Things (IoT) and securing these objects. A market estimate puts the number of objects connected to the IoT at 30 billion by 2020. This is why it is important to find IoT solutions that meet the need for scalability to meet demand, but also the security aspects to protect against cyberattacks. The security needs associated with object communications (confidentiality, integrity, authentication and non-repudiation) are covered by the use of cryptographic mechanisms based on sets of keys and digital identities. This key and identity manager thus represents the heart of the system's security.From the point of view of objects, it is thanks to this manager that the object is authorized to transmit on a network and to access an application service (identification and authentication of the object), that it is capable of transmitting encrypted, integral and authenticated messages and that it is capable of decrypting the data received (symmetric / asymmetric cryptography).

[0003] Automated access by objects, in a secure manner, to digital services, and the protection of the exchanges that follow, require the implementation of enrollment processes both for the manufacturers of objects and for the objects themselves, as well as their association with the digital services in question ("service on-boarding").

[0004] These processes must address issues such as the identification of objects with a list of associated attributes (including security identifiers such as cryptographic keys), and their registration in a repository of the Manufacturer of the objects; The transfer of ownership and / or exploitation rights of an object from a Manufacturer to a user of the object (for example, a service provider using the object); The transfer of ownership and / or exploitation rights from one user to another (case, for example, of the need for reversibility); The updating of attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.

[0005] Additionally, platforms that meet these processes must demonstrate high resilience to failures, high availability and strong security.

[0006] With the rise of connected objects (IoT), and particularly small and low-cost IoT objects, new constraints specific to them are emerging, such as reduced memory size, low computing power, low consumption and a possible offline mode or disconnection of the object.

[0007] In addition to all these technical constraints, there are growing legal constraints, such as the new regulations in force on data ownership (GDPR) and Privacy by Design (PvD).

[0008] There are several solutions available today to address these issues, including IAM (Identity and Access Management) solutions, more commonly known as IAM (Identity Access Management). Many cybersecurity companies offer such solutions: Active Directory, IBM Security Identity and Access Assurance, Oracle Identity Cloud Service, Okta, Centrify, RSA SecurID Access, Keeper Security, SailPoint, OneLogin, Ping, etc. However, the various players on this list offer centralized solutions, with internal data storage that may be personal and therefore sensitive and thus no longer comply with GDPR regulations.

[0009] These solutions generally offer a centralized technical process usually managed by the service provider, which does not allow for automation, and prior bipartite agreements between service providers and object manufacturers, necessary to enable the association of objects with the provider's services.

[0010] The item is already registered and “paired with its Manufacturer / Owner”.

[0011] Additionally, Won Jongho et al., “Decentralized Public Key Infrastructure for Internet-of-Things,” MILCOM 2018, pages 907-913, describes a decentralized public key infrastructure for the Internet of Things, which uses distributed nodes in a blockchain network, instead of certificate authorities.

[0012] Finally, these solutions require sufficiently large computing and storage capacities at the object level to manage the security needs of identification and authentication using public cryptographic keys / electronic certificates. These demands in computing power, storage space and energy cost may not be managed by some IoT objects that have too little computing capacity and battery for this. STATEMENT OF THE INVENTION

[0013] The present invention therefore aims to propose a communication method for the secure management of keys and identities, making it possible to overcome at least some of the drawbacks of the prior art.

[0014] Thisgoal is achieved by a communication method for the secure management of keys and identities of an Object manufactured by a Manufacturer having a public key pair Kp, private or secret key Ks of Manufacturer (Ks man ,Kp man ) and a client having a Client key pair (Ks client ,Kp client ), characterized in that the management is done at least partially on a decentralized blockchain database, and that the method comprises the following steps: a) Generation by the Manufacturer of two diversified symmetric keys from its key pair and diversifiers, for example in the form of 128-bit AES keys, the two symmetric keys being composed of a confidentiality key K0c and an Identity key K0i, then sharing of said keys with the object. b) Publication and recording in the blockchain database of the decentralized identifier (DID) of the object and preferably of the encryption of the diversifiers used to obtain the two symmetric keys by a public key Kp man: and association of the object identifier pair with the encryption of the public key Kp man and the encrypted diversifiers to form the information DID - Enc(KP man ,DIV_C∥DIV_ID) And, when a Customer purchases the item from said Manufacturer, the process includes the following initialization steps: c) Supply by the Manufacturer of the object, the object identifier DID, and the symmetric keys confidentiality key K0c and Identity key KOi, the symmetric keys being encrypted by the client's public key Kp client, to the client, preferably by a mechanism, outside the blockchain, called "off-chain"; d) Updating the database blockchain by publication and association in the said chain of blocks of the object identifier pair (DID) with the client's public key Kp client and the encryption of the client's public key Kp client and encrypted diversifiers to form the information DID-Kp client and Enc( Customer Kp ,DIV_C∥DIV_ID) so that the client can recalculate the values ​​of the object's keys. And, when the object is turned on for the first time, the object self-enrolls according to the following steps: e) Generation of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys K0c, KOi.; f) Self-enrollment of the object is carried out by a cryptographic challenge implementing the identity key g) Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism outside the blockchain, called "off-chain" h) Publication and registration of said new diversifiers encrypted with the client's public key in the blockchain.

[0015] According to a particular feature, the method further comprises a step prior to the generation of manufacturing key pairs by the Manufacturer, in which said Manufacturer records its Manufacturer identifier in the blockchain and publishes its Manufacturer public key (Kp man) by associating it with its Manufacturer ID.

[0016] According to another peculiarity, the key pair generator relies on hierarchical key wallets to provide the unique manufacturing key pairs which are diversified from the Manufacturer key pair.

[0017] According to another particularity, the two symmetric keys generated by the Manufacturer come from the IES scheme (Integration Encryption Scheme, or the ECIES scheme (Elliptic Curve Integrated Encryption Scheme), preferably from the ECIES scheme, and where the Manufacturer generates a temporary key pair of which it uses the public part for the derivation of said two symmetric keys generated.

[0018] According to another particularity, the object is transferred from one owner to another by repeating steps d to e.

[0019] According to another particularity, the sharing or management of rights on the object is carried out by the owner of the object by means of verifiable titles (Verifiable Credentials), preferentially requested by the service providers (Service Providers) and validated by the owner.

[0020] According to another feature, a Zero Knowledge Proof (ZKP) system is implemented within a smart contract to provide information without revealing its values.

[0021] There The present invention also relates to a secure identity management system based on a blockchain capable of carrying out the steps of a process carrying out: The identification of objects with a list of associated attributes, including security identifiers such as cryptographic keys, and their registration in a Manufacturer's repository; The transfer of ownership and / or exploitation rights of an object from a Manufacturer to a user of the object, for example a service provider using the object, by registering new identities associated with the object; The transfer of ownership and / or exploitation rights from one user to another, by registering new identities associated with the object; The updating of attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.

[0022] ThereThe present invention also relates to a database, used by the secure identity management system based on a blockchain, implemented on a secure, decentralized, automated and multi-actor platform for managing object identities through the use of blockchain technology implemented on several nodes of the system with which the platform communicates, the nodes being responsible for maintaining the blockchain and allowing actors (and objects) to consult the state of this chain and to interact with this chain via a shared common repository (or register), each node having access to a cryptographic module, preferably physical, in charge of the secure storage of its private key and access to the shared register characterized in that the database constitutes a repository for each manufacturer containing a list of associated attributes,including in particular security identifiers such as cryptographic keys, and either registering them in the Manufacturer's repository, or updating the attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.,

[0023] The present invention also relates to a secure, decentralized, automated and multi-actor platform for managing object identities using a database, characterized in that it manages: Transfer of ownership and / or exploitation rights of an object; Recording of proof of possession of an object in the shared repository; Activation / reactivation of objects;

[0024] According to a particularity, the blockchain technology used does not have to be of a specific type and includes at least: a permission system, to strongly identify and authenticate an actor; an access control system, based on user identities; an anti-replay mechanism, each node maintaining the blockchain must be in a secure environment, and the public identity of each node must be made available to other nodes and actors within the shared registry; the execution of Smart Contracts and functions on the blockchain being carried out in this secure sphere, the purpose of registration being to create a link, accessible by everyone in the blockchain, to enable the actor and his digital identity to be matched by a key pair (public key and private key) or by a certificate possibly signed by a certified identity management body.

[0025] The present invention also relates to a secure identity management system based on a blockchain and capable of carrying out the steps of a communication method for the secure management of keys and identities, the system comprising at least: a Manufacturer, using a key diversification system from diversifiers generated by a diversifier generator, a blockchain connection system, a system for assigning, to each object leaving manufacturing, an identifier, and a hardware and software arrangement for sending to the blockchain server a message for publishing and registering the association DID - Enc(Kp man , DIV_C∥DIV_ID).

[0026] The present invention also relates to a secure identity management system based on a blockchain and capable of carrying out the steps of a communication method for the secure management of keys and identities, the system comprising at least one object provided with calculation means and means for storing a program and data sufficient to carry out the following operations: when the object is switched on for the first time, the object is enrolled according to the following steps: Generation of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys keys K0c, KOi Self-enrollment by a cryptographic challenge implementing the identity key KOi Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism, outside the blockchain database, Publication and recording of said new diversifiers encrypted with the client's public key in the blockchain database

[0027] According to Another feature is that a confidentiality key sharing system is set up "off-chain", so that service operators have access to the object, and therefore to the related information.

[0028] The present invention also relates to an identity management system of an identity service provider (ID service provider) implementing a blockchain and using the objects recorded on a network to fulfill application services (AS) in which the information provided by the objects is used, each node of the network of the identity service provider has access to a cryptographic module in charge of the secure storage of its private key, the nodes having clients called Actors each having their own ID act identity recorded in the blockchain, each object manufacturer is recorded in the blockchain of the identity service provider and their public key is known to all,for each object sold or transferred each manufacturer provides the object identifier and the encryption of the diversifiers used by the manufacturer for the calculation of the symmetric keys of each object by publication in the blockchain, only the symmetric keys remain stored outside the chain, in this case in the object; Each object being provided with means of calculation and means of memorizing a program and data sufficient to carry out the following operations: when the object is switched on for the first time, the object registers with the identity service provider by carrying out the following steps: , Generation in the object of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys keys K0c, K0i, Self-enrollment by a cryptographic challenge implementing the identity key. Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism, outside the blockchain, Publication and registration of said new diversifiers encrypted with the client's public key in the blockchain.

[0029] There The present invention also relates to an object provided with calculation means and means for storing a program and data sufficient to carry out the following operations: when the object is switched on for the first time, the object registers with the identity service provider by carrying out the following steps: Generation in the object of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys keys K0c, K0i, Self-enrollment by a cryptographic challenge implementing the identity key. Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism, outside the blockchain, Publication and registration of said new diversifiers encrypted with the client's public key in the blockchain. BRIEF DESCRIPTION OF THE FIGURES

[0030] Other characteristics, details and advantages of the invention will emerge from reading the description which follows with reference to the appended figures, which illustrate: [ Fig. 1 ], represents an embodiment of the method in a schematic manner. Fig. 2 ], represents steps a) and b) of the method according to certain embodiments, [ Fig. 3], represents steps c) and d) of the method according to certain embodiments, [ Fig. 4 ], represents steps e), f), g) and h) of the method according to certain embodiments, DETAILED DESCRIPTION OF THE INVENTION

[0031] Many combinations can be envisaged without departing from the scope of the invention; the person skilled in the art will choose one or the other depending on the economic, ergonomic, dimensional or other constraints that he must respect.

[0032] In general, the present invention comprises a communication method for the secure management of keys and identities of an Object manufactured by a Manufacturer having a public key pair Kp, private or secret key Ks of the Manufacturer (Ks man ,Kp man ) and a client having a Client key pair (Ks client ,Kp client ), characterized in that the management is done at least partially on a decentralized blockchain database, and that the method comprises the following steps: a) Generation by the Manufacturer of two diversified symmetric keys from its key pair and diversifiers, for example in the form of 128-bit AES keys, the two symmetric keys being composed of a confidentiality key K0c and an Identity key K0i, then sharing of said keys with the object. b) Publication and recording in the blockchain database of the decentralized identifier (DID) of the object and preferably of the encryption of the diversifiers used to obtain the two symmetric keys by a public key Kp man: and association of the object identifier pair with the encryption of the public key Kp man and the encrypted diversifiers to form the information DID - Enc(Kp man , DIV-C∥DIV_ID) And, when a Customer purchases the item from said Manufacturer, the process includes the following initialization steps: c) Supply by the Manufacturer of the object, the object identifier DID, and the symmetric keys confidentiality key K0c and Identity key KOi, the symmetric keys being encrypted by the client's public key kp client, to the client, by a mechanism, outside the blockchain, called "off-chain", d) Updating the database blockchain by publication and association in said blockchain of the object identifier pair (DID) with the client's public key Kp client and the encryption of the client's public key Kp client and the encrypted diversifiers to form the information DID-Kp client and Enc( Kp customer, DIV_C∥DIV_ID) . so that the client can recalculate the values ​​of the object's keys.

[0033] In some embodiments, in the method, when the object is first powered on the object self-enrolls according to the following steps: e) Generation of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys K0c, KOi.; f) Self-enrollment of the object is carried out by a cryptographic challenge implementing the identity key g) Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism outside the blockchain, called "off-chain" h) Publication and registration of said new diversifiers encrypted with the client's public key in the blockchain.

[0034] Advantageously, the first key, confidentiality key K0c, is necessary for data encryption, and the second key, Identity key K0i, is necessary for authentication on the blockchain.

[0035] Thesekeys can be derived from the IES (Integrated Encryption Scheme) scheme, where it is preferable to use the ECIES (Elliptic Curve Integrated Encryption Scheme) scheme, which is more suitable for IoT than the DLIES (Discrete Logarithm Integrated Encryption Scheme) scheme. In this case, the Manufacturer is obliged to generate a temporary key pair and use the public part for derivation. These two symmetric keys are calculated by a key derivation function which takes as an argument the temporary public key gt generated by the Manufacturer and derived from the key pair of the Manufacturer (gf< ,f) by a diversifier.

[0036] In other words, in this embodiment, a temporary public key is randomly generated by the manufacturer. It is derived from two objects: the manufacturer's key pair and a diversifier. The result of the derivation with a first diversifier is a new object: a symmetric confidentiality key K. The result of the derivation with a second diversifier is a new object: a symmetric identity key K.

[0037] In some embodiments, each publication in the blockchain is equivalent to at least one transaction therein.

[0038] The DIV diversifier may not be published in the Blockchain, but for security reasons it is. This allows the Manufacturer to avoid storing the manufacturing key pair, and thus be forced to recalculate it if necessary.

[0039] There is a relationship that allows the association between the DID and the DIV. Thus, any actor is able to find the DIV if they know the DID. The DIV is necessary because it allows the manufacturer to recalculate the key: DIV for diversifier. A diversified key is obtained from a key and a diversifier: the key is known to the manufacturer and the diversifier is stored in the blockchain.

[0040] In in some embodiments, the encryption of the diversifiers is carried out with the manufacturer's public key (only the manufacturer carrying the private key can thus decrypt)

[0041] There Proof of ownership of the object is done intrinsically because the owner / manufacturer is the only one to possess the private key associated with the referenced public key.

[0042] Advantageously, the object is capable of self-enrollment and signs the enrollment message with the manufacturing key (Ks fab) that only it possesses.

[0043] In some embodiments, the provision of data, in particular the identifier of the DID object, and the encrypted symmetric keys confidentiality key K0c and Identity key KOi, is carried out by off-chain transmission.

[0044] An "off-chain" data supply or sending is understood to mean a supply or sending of data by a mechanism external to the blockchain, in order to improve the security and confidentiality of particularly sensitive data. This means, for example, secure sending by email, making it available on a secure storage server, sending a USB key with the secure data, or other possible means that can be envisaged by a person skilled in the art that address the given problem.

[0045] Alternatively, it would be possible, but less secure, to send the new diversifiers during step e) directly to the Smart Contract which encrypts them with the client's public key.

[0046] The mechanism must absolutely secure these diversifiers: encryption of the data by the sender with the public key of the recipient, for example.

[0047] Advantageously, the encryption of symmetric keys is carried out by the Manufacturer.

[0048] Advantageously, the replacement (update), that is, the publication and recording in the blockchain, is carried out by updating the blockchain via a transaction. The Blockchain is like a state register: updating the state of a value, therefore replacing it via a transaction. The old state is kept (blockchain paradigm) but is no longer up to date.

[0049] In some embodiments, the object accesses the shared registry via its Manufacturer's node, with its KOi Identity key which gives it the necessary rights to carry out the enrollment process. This symmetric key is known only to the Manufacturer, the object and the Client, the object is authenticated by the Blockchain: the verification is done by the Smart Contract, via a challenge that can only be carried out by the sole holders of the KOi identity key (e.g., using an HMAC type mechanism).

[0050] A cryptographic challenge is an authentication mechanism that implements a secret, in this case a key. The HMAC function cited allows the sender of data to be authenticated and ensures its integrity.

[0051] WeDecentralized database "blockchain" means a decentralized database comprising a network of blockchains, with nodes comprising all or part of the blockchain ledger. Advantageously, to keep track of all transactions, the blockchain network uses the multi-chain ledger that is replicated across all peer nodes in the blockchain network. The blockchain is a list of blocks, each containing multiple transactions. Each block has a pointer to the previous block, and the order and contents of the blocks are protected by hash signatures. Bitcoin mining nodes construct new blocks from incoming transactions. This construction is made difficult to achieve and requires considerable mining computation, the proof of work.The effort involved makes it equally difficult to change blocks already included in the blockchain, especially since changing a block in the middle of the chain would require recreating all subsequent blocks. Thus, the blockchain ledger is well protected from changes and can be considered a permanent record of transactions. To incentivize mining effort, miners are rewarded with newly created bitcoins when a block is created. They also receive all transaction fees from transactions included in the new block.

[0052] Blockchain technology is used as a shared and distributed repository of identities including a list of associated public attributes. These identities may, for example, use the DID format defined in the "Decentralized Identifiers (DIDs)" specification.

[0053] The system is not preferably based on a public blockchain, and not on a blockchain with a proof of work, which requires computing power and energy in an IoT use case (objects with low consumption and low computing power constraints). On the contrary, the solution is preferably based on a consortium blockchain / enterprise blockchain / permission blockchain / POK blockchain (Proof of Knowledge).

[0054] The invention relates to a secure, decentralized, automated and multi-actor system or platform for managing object identities through the use of blockchain technology. In other words, a blockchain system in order to benefit from its advantages: scalability, replication, resilience to failures / attacks while adding an additional layer for IAM and IAM linked to the identity of the entities.

[0055] These embodiments therefore do not require additional actors, additional servers, only direct actors (Manufacturer, Client, Object), a decentralized blockchain database, and potentially a service provider. Advantageously, the nodes of the blockchain are only used to store data and update them via transactions carried out on said blockchain.

[0056] Some solutions require the presence of a DM (Device Manager), while in this system, registration is already done and enrollment on the network is initiated by the object. The autonomous object thanks to the DID.

[0057] In some embodiments, the method further comprises a step prior to the generation of manufacturing key pairs by the Manufacturer, in which said Manufacturer registers its Manufacturer identifier in the blockchain and publishes its Manufacturer public key (Kp man ) by associating it with its Manufacturer ID.

[0058] In some embodiments, the key pair generator relies on hierarchical key wallets to provide the unique manufacturing key pairs that are diversified from the Manufacturer's key pair.

[0059] In certain embodiments, the two symmetric keys generated by the Manufacturer come from the IES scheme (Integration Encryption Scheme, or the ECIES scheme (Elliptic Curve Integrated Encryption Scheme), preferably from the ECIES scheme, and where the Manufacturer generates a temporary key pair of which it uses the public part for the derivation of said two symmetric keys generated.

[0060] In some embodiments, the object is transferred from one owner to another by repeating steps d through e.

[0061] In some embodiments, the sharing or management of rights to the object is carried out by the owner of the object by means of verifiable credentials, preferably requested by service providers and validated by the owner.

[0062] Verifiable Credentials and DID Documents (Decentralized IDentifiers) will be used as a means of access control and a storage format for object-related information on the blockchain, respectively. The former allows read access to object information based on the peer's identity.

[0063] In some embodiments, in the method, a Zero Knowledge Proof (ZKP) system is implemented within a Smart Contract to provide information without revealing its values.

[0064] THEZPK is a method that allows one entity to prove to another that a proposition is true without revealing its value. This allows, for data preservation purposes, to answer a question without revealing the value. For example, a service can ask an object if its temperature is below or above 0°C without the object having to reveal its temperature value. This allows optimization based on the use of the service, not on the steps.

[0065] A Smart Contract is a unique and replicated digital protocol / program that allows operations to be carried out on the blockchain, and that this is done in compliance with well-defined rules.

[0066] Thus, all registrations / publications in the blockchain go through smart contracts. Access rules are also governed by smart contracts.

[0067] Various embodiments described also relate to a secure identity management system based on a blockchain.

[0068] Thus, in certain embodiments, a secure identity management system based on a blockchain is capable of carrying out the steps of a process carrying out: The identification of objects with a list of associated attributes, including security identifiers such as cryptographic keys, and their registration in a Manufacturer's repository; The transfer of ownership and / or exploitation rights of an object from a Manufacturer to a user of the object, for example a service provider using the object, by registering new identities associated with the object; The transfer of ownership and / or exploitation rights from one user to another, by registering new identities associated with the object; The updating of attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.

[0069] Thus, a system or a secure, decentralized, automated and multi-actor platform for managing object identities can be set up through the use of blockchain technology, allowing automated access by objects, in a secure manner, to digital services, and ensuring protection of the exchanges that follow.

[0070] Various embodiments described also relate to a database, used by the blockchain-based secure identity management system.

[0071] Thus, some embodiments relate to a database, used by the secure identity management system based on a blockchain, implemented on a secure, decentralized, automated and multi-actor object identity management platform through the use of blockchain technology implemented on several nodes of the system with which the platform communicates, the nodes being responsible for maintaining the blockchain and allowing actors (and objects) to consult the state of this chain and to interact with this chain via a shared common repository (or register), each node having access to a cryptographic module, preferably physical, in charge of the secure storage of its private key and access to the shared register characterized in that the database constitutes a repository for each manufacturer containing a list of associated attributes,including in particular security identifiers such as cryptographic keys, and either registering them in the Manufacturer's repository, or updating the attributes linked to the identity of the object by the owner of an object and / or the entity in charge of its exploitation rights.,

[0072] Miscellaneous The embodiments described also relate to a secure, decentralized, automated and multi-actor platform for managing object identities using a decentralized database.

[0073] In some embodiments, a secure, decentralized, automated, multi-actor object identity management platform using a decentralized database manages: Transfer of ownership and / or exploitation rights of an object; Recording of proof of possession of an object in the shared repository; Activation / reactivation of objects;

[0074] In some embodiments, the blockchain technology used does not have to be of a specific type. In some embodiments, the blockchain technology used comprises at least: a permission system, to strongly identify and authenticate an actor; an access control system, based on user identities; an anti-replay mechanism, Each node maintaining the blockchain must be in a secure environment, and the public identity of each node must be made available to other nodes and actors within the shared registry; the execution of Smart Contracts and functions on the blockchain being carried out in this secure sphere, the purpose of registration being to create a link, accessible by everyone in the blockchain, to enable the actor and his digital identity to be matched by a key pair, public key and private key, or by a certificate possibly signed by a certified identity management organization.

[0075] A replay attack (or playback attack) is a form of network attack in which a transmission is maliciously replayed by an attacker who has intercepted the transmission. It is a type of spoofing.

[0076] In some embodiments, the system comprises at least: a Manufacturer, using a key diversification system from diversifiers generated by a diversifier generator, a blockchain connection system, a system for assigning, to each object released from manufacturing, an identifier, and a hardware and software arrangement for sending to the blockchain server a message for publishing and registering the association DID - Enc(Kp man ,DIV_C∥DIV_ID), the system able to request a service provider to update the blockchain in the database by publication and association in said blockchain of the object identifier pair (DID) with the client's public key Kp client and encryption of the client public key Customer Kp and encrypted diversifiers to form the information DID-Kpclient and Enc( Kp customer, DIV_C∥DIV_ID) the DID-DIV association and customer Kp. .

[0077] Registration, also called personalization, is done only once by the manufacturer. The item updates itself in the stages following manufacturing, in particular when it is purchased / given away.

[0078] The DIV diversifier may not be published in the Blockchain, but for security reasons it is. This allows the Manufacturer to avoid storing the manufacturing key pair, and thus be forced to recalculate it if necessary.

[0079] In some embodiments, the object, once purchased, is able to request a service provider to update the blockchain in the database by publishing and associating in said blockchain the object identifier pair (DID) with the client's public key Kp client and the encryption of the client's public key Kp client and encrypted diversifiers to form the information DID-Kp client and Enc( Kp customer, DIV_C∥DIV_ID) the DID-DIV association and customer Kp.

[0080] In some embodiments, the system comprises at least: An object provided with calculation means and means for storing a program and data sufficient to carry out the following operations: when the object is switched on for the first time, the object enrolls according to the following steps: Generation of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys keys K0c, KOi Self-enrollment by a cryptographic challenge implementing the identity key KOi Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism, outside the blockchain database, Publication and recording of said new diversifiers encrypted with the client's public key in the blockchain database.

[0081] In some embodiments, a confidentiality key sharing system is implemented “off-chain”, so that service operators have access to the object, and therefore to the related information. In some embodiments, an identity management system of an identity service provider (ID service provider) implements a blockchain and uses the objects registered on a network to fulfill application services (AS) in which the information provided by the objects is used, each node of the network of the identity service provider has access to a cryptographic module in charge of the secure storage of the private key of said node, the nodes having clients called Actors each having their own identity ID act registered in the blockchain, each object manufacturer is registered in the blockchain of the identity service provider and the manufacturers' public manufacturing keys are known to all, for each object sold or transferred, each manufacturer provides the identifier of the object and a diversifier used by the manufacturer (DID,DIV) for the calculation of the manufacturing key pairs of each object by the manufacturer, and only the object identifier and the manufacturing public key are published in the blockchain, only the manufacturing private key remains stored outside the chain, in this case in the object; Each object being provided with means of calculation and means of memorizing a program and sufficient data to execute the following operations: when the object is switched on for the first time, the object enrolls with the identity service provider by carrying out the following steps: Generation in the object of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys keys K0c, K0i, Self-enrollment by a cryptographic challenge implementing the identity key. Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism,outside the blockchain, Publication and registration of said new diversifiers encrypted with the client's public key in the blockchain.

[0082] In some embodiments, an object provided with computing means and means for storing a program and data sufficient to perform the following operations: when the object is first powered on, the object enrolls with the identity service provider by performing the following steps: Generation in the object of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its old keys keys K0c, K0i, Self-enrollment by a cryptographic challenge implementing the identity key. Sending by the object to the client of the two new diversifiers encrypted with the client's public key, the sending being carried out by a mechanism, outside the blockchain, Publication and registration of said new diversifiers encrypted with the client's public key in the blockchain.

[0083] The system thus includes a secure identity manager based on a blockchain in which the identities or the process for finding these identities are published. The nodes of the shared registry thus maintain a blockchain and, by extrapolation, the identity manager.

[0084] Thus, a system or a secure, decentralized, automated and multi-actor platform for managing object identities can be set up through the use of blockchain technology, allowing automated access by objects, in a secure manner, to digital services, and ensuring protection of the exchanges that follow.

[0085] This system can be implemented for IoT Objects with low computing capacity, low storage capacity and / or low energy consumption constraints.

[0086] In some embodiments, and in summary, manufacturers are registered in the Blockchain, and their respective public keys are known to all. They manufacture and personalize Objects with unique identifiers and symmetric keys. For each object, they publish in the Blockchain the identifier of the object, and the ciphertext of the diversifiers used for generation. IoT objects may only be able to use symmetric cryptography mechanisms. To identify themselves, they must use cryptographic challenges that involve secret keys. The Client operates the Object and must therefore have knowledge of the secret keys, in order to be able to communicate with the Object and manage access rights. Figure 1 illustrates this by way of example and in a non-limiting manner by summarizing the different key stages of certain embodiments.

[0087] More specifically, the Figure 2illustrates an exemplary non-limiting embodiment of the present invention, in which steps a) and b are represented. Step a) concerns the generation of the two symmetric keys by the Manufacturer, which the latter will share with the object, the two symmetric keys being diversified from the Manufacturer's key pair and diversifiers, for example in the form of 128-bit AES keys, the two symmetric keys being composed of a confidentiality key K0c and an Identity key KOi (Step I-1), and the initialization of the object with these symmetric keys (Step I-2). Step b) concerns the publication and recording in the blockchain of the DID and the encryption of the diversifiers used to obtain the two symmetric keys to form the information DID - Enc(Kp man ,DIV_C∥DIV_ID) (Step II). Thus the script with a double signature makes it possible to differentiate the owner of the object from the one who created the object.This also allows you to check that the person writing this transaction is indeed the one who created the object.

[0088] For simplification, the temporary key pair gt<, which is one of the possible mechanisms for generating these secret keys, does not appear intentionally in the diagrams and explanations. The same is true for symmetric keys, which are "master keys." All signature and encryption mechanisms involving them require that they be diversified by their associated diversifiers.

[0089] There Figure 3illustrates an exemplary non-limiting embodiment of the present invention, in which steps c) and d) corresponding to the steps performed when a Customer purchases the object from said Manufacturer are represented (Step III-1). The provision of data by the Manufacturer to the customer by an “off-chain” mechanism is not represented. The proof of ownership of the object is done intrinsically because the owner is the only one to possess the private key associated with the referenced public key. During the exchange between the Customer and the Manufacturer, the customer proves that he is indeed the owner of the public key by inserting his signature (Step III-2). The Manufacturer updates the common repository by publishing the public key associated with the Customer Kp customer and the encryption of the customer public key Kp customer and the encrypted diversifiers to form the information DID-Kp client and Enc( Customer Kp,DIV_C∥DIV_ID) so that the client can recalculate the values ​​of the object keys (Step III-3).

[0090] Finally, the Figure 4 illustrates an exemplary non-limiting embodiment of the present invention, in which steps e), f), g) and h) are represented, corresponding to the steps carried out when the object is switched on for the first time, and self-enrolls. Indeed, once switched on, the object generates new symmetric keys (Step IV-1). The object then self-enrolls by a cryptographic challenge implementing the identity key KOi (Step IV-2). The sending by the object to the client of the two new diversifiers encrypted with the client's public key, carried out by a mechanism outside the blockchain, called "off-chain", is not shown in the figure. Finally, the publication (Step IV-3) for updating the blockchain of said new diversifiers encrypted with the client's public key.

[0091] Self-enrollment of the object is done through a gateway provided by the manufacturer; this is the only information known about the object when it is started.

[0092] We It will be readily understood from reading this application that the features of the present invention, as generally described and illustrated in the figures, can be arranged and designed in a wide variety of different configurations. Thus, the description of the present invention and the related figures are not intended to limit the scope of the invention but simply represent selected embodiments.

[0093] Those skilled in the art will understand that the technical features of a given embodiment may in fact be combined with features of another embodiment unless the opposite is explicitly stated or it is obvious that these features are incompatible. Furthermore, the technical features described in a given embodiment may be isolated from the other features of this embodiment unless the opposite is explicitly stated.

[0094] It should be obvious to those skilled in the art that the present invention allows embodiments in many other specific forms without departing from the field defined by the scope of the appended claims, they should be considered by way of illustration and the invention should not be limited to the details given above.

Claims

1. A communication method for the secure management of keys and identities of an Object manufactured by a Manufacturer having a Manufacturer key pair of public key Kp, and private or secret key Ks (Ksman, Kpman), and a client having a Client key pair (Ksclient, Kpclient), characterized in that the management is carried out at least partially on a decentralized blockchain database, and in that the method comprises the following steps: a. generation, by the Manufacturer, of two diversified symmetric keys from their key pair and from diversifiers, for example in the form of 128 bit AES keys, the two symmetric keys being composed of a confidentiality key K0c and an identity key K0i, then sharing of said keys with the object. b. publication and recording, in the blockchain database, of a decentralized identifier (DID) of the object and of the diversifier encryption used to obtain the two symmetric keys by a public key Kpman: and association of the pair identifying the object with the encryption of the public key Kpman and encrypted diversifiers in order to form the information DID - Enc(Kpman,DIV_C∥DIV_ID) And, when a Client purchases the object from said Manufacturer, the method comprises the following initialization steps: c. Providing, by the Manufacturer of the object, of the identifier of the object DID, and of the symmetric keys confidentiality key K0c and identity key K0i, the symmetric keys being encrypted by the public client key Kpclient, to the client, by a mechanism outside of the blockchain, referred to as "off-chain"; d. Updating the blockchain of the database by publication, and association in said blockchain, of the pair identifying the object (DID) with the public client key Kpclient and the encryption of the public client key Kpclient and the encrypted diversifiers in order to form the information DID-Kpclient and Enc(Kpclient,DIV_C∥DIV_ID) so that the client is able to recalculate the values of the object keys. And, when the object is switched on for the first time, the object auto-enrolls according to the following steps: e. Generation of its new symmetric keys, confidentiality key K1c and Identity key K1i, by diversification of its former keys K0c, K0i; f. Auto-enrollment of the object is carried out by a cryptographic challenge implementing the former identity key g. Sending, by the object to the client of the two new encrypted diversifiers with the public client key, the sending being carried out by a mechanism outside of the blockchain, referred to as "off-chain" h. Publication and recording of said new encrypted diversifiers with the public client key in the blockchain.

2. The communication method according to claim 1, which further comprises a step prior to the generation of the manufacturing key pairs by the Manufacturer, wherein said Manufacturer records their Manufacturer identifier in the blockchain and publishes their public Manufacturer key (Kpman) by associating it with its Manufacturer identifier.

3. The communication method according to either one of the preceding claims, wherein the key pair generator is based on Hierarchical Key Wallets to provide Manufacturer and Client key pairs.

4. The communication method according to any one of the preceding claims, wherein the two symmetric keys generated by the Manufacturer result from the IES scheme (Integration Encryption Scheme) or from the ECIES scheme (Elliptic Curve Integrated Encryption Scheme), preferentially from the ECIES scheme, and where the Manufacturer generates a temporary key pair, the public part of which they use for deriving said two generated symmetric keys.

5. The communication method according to any one of the preceding claims, wherein the object is transferred from one owner to another by reiterating steps d to e.

6. The communication method according to any one of the preceding claims, wherein sharing or managing the rights to the object is performed by the owner of the object by means of Verifiable Credentials, preferentially requested by the Service Providers and validated by the owner.

7. The communication method according to any one of the preceding claims, wherein a Zero Knowledge Proof (ZKP) system is established within a Smart Contract, in order to give information without revealing the values thereof.

8. A system for managing secure identities based on a blockchain, able to carry out the steps of the method according to any one of claims 1 to 7, the system comprising at least: a Manufacturer, using a key diversification system based on diversifiers generated by a diversifier generator, a system for connecting to a blockchain, a system for attributing an identifier to each object leaving manufacturing, and a hardware and software arrangement in order to send, to the blockchain server, a message of publication and of recording of the association DID - Enc(Kpman,DIV_C∥DIV_ID).

9. A system for managing secure identities based on a blockchain and able to carry out the steps of the method according to any one of claims 1 to 7, the system comprising at least An object provided with computation means and means for storing in memory a program and sufficient data to carry out the following operations: when the object is switched on for the first time, the object auto-enrolls according to the following steps: Generation of its new symmetric confidentiality key K1c and Identity key K1i by diversification of its former keys K0c, KOi - Auto-enrollment by a cryptographic challenge implementing the identity key KOi - Sending, by the object to the client, of the two new encrypted diversifiers with the public client key, the sending being carried out by a mechanism outside of the blockchain database, - Publication and recording of said new encrypted diversifiers with the public client key in the blockchain database,10. The identity management system according to claim 8 or 9, wherein a system for sharing confidentiality keys is established "off chain", in order for service operators to have access to the object and therefore to the related information.

11. An identity management system of an identity (ID) service provider, implementing a blockchain and using the objects recorded on a network to fulfill application services (AS) in which the information provided by the objects are used, each node of the network of the identity service provider has access to a cryptographic module responsible for the secure storage of the private key thereof, the nodes having clients referred to as Stakeholders, each having their own identity IDact recorded in the blockchain, each object manufacturer is recorded in the blockchain of the identity service provider and their public manufacturing keys are known to everybody; for each object sold or transferred each manufacturer provides the identifier of the object and the encryption of the diversifiers used by the manufacturer for the calculation of the symmetric key pairs of each object by publishing in the blockchain, only the symmetric keys remain stored outside of the chain, in this instance in the object; Each object being provided with computation means and means for storing in memory a program and sufficient data to execute the following operations: when the object is switched on for the first time, the object auto-enrolls with the identity service provider by carrying out the following steps: - Generation, in the object, of its new symmetric keys confidentiality key K1c and Identity key K1i by diversification of its former keys K0c, K0i; - Auto-enrollment by a cryptographic challenge implementing the former identity key. - Sending, by the object to the client, of the two new encrypted diversifiers with the public client key, the sending being carried out by a mechanism, outside of the blockchain, - Publication and recording of said new encrypted diversifiers with the public client key in the blockchain.

12. An object, being provided with computation means and means for storing in memory a program and sufficient data to execute the following operations: when the object is switched on for the first time, the object auto-enrolls with the identity service provider by carrying out the following steps: - Generation, in the object, of its new symmetric keys, confidentiality key K1c and Identity key K1i by diversification of its former keys K0c, KOi - Auto-enrollment by a cryptographic challenge implementing the former identity key. - Sending, by the object to the client, of the two new encrypted diversifiers with the public client key, the sending being carried out by a mechanism, outside of the blockchain, - Publication and recording of said new encrypted diversifiers with the public client key in the blockchain.