Blockchain Identity Management for IoT Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current distributed Home Subscriber Server (HSS) solutions for LTE communications networks, which utilize blockchain, face challenges in scalability and management costs due to the need for centralized identity registration and exclusive operator limitations, making them unsuitable for IoT scenarios and inefficient in operation.

Innovation Solution

A method and system where a control plane node in a blockchain network generates and broadcasts identification, public, and private keys for user equipment, enabling decentralized registration and consensus calculation, allowing multiple operators to manage identities without redundant registrations, and separating control plane and data plane nodes for improved efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized identity registration by a single management device is implemented, then identity management security is improved, but scalability to IoT scenarios with massive user equipment is worsened

Engineering Contradiction:
Improveidentity management securityVSAvoidscalability to IoT scenarios
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the centralized management device into multiple control plane nodes distributed across the blockchain network. Each node can independently perform identity registration and verification, distributing the security function while enabling scalability. The segmentation transforms a single point of management into a decentralized network of management nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal identity registration system where multiple control plane nodes can serve multiple operators simultaneously. The blockchain network provides a universal ledger that all nodes and operators can access, allowing the same infrastructure to support diverse IoT scenarios and multiple service providers without requiring separate centralized management for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If exclusive operator-specific identifications are registered for each user equipment, then operator security control is improved, but management costs increase due to redundant registrations

Engineering Contradiction:
Improveoperator security controlVSAvoidmanagement costs
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal identification system where user equipment receives a single identification registered on the blockchain that can be recognized by multiple operators. The blockchain ledger serves as a universal database that all operators can query and verify, eliminating the need for each operator to maintain separate identification registries while preserving security through cryptographic verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple operator-specific identification systems into a single unified blockchain-based registration system. Instead of maintaining separate identification databases for each operator, the system combines all operator requirements into a single decentralized ledger that provides security for all participants simultaneously, reducing redundant management overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If control plane and data plane functions are combined in the same nodes, then system simplicity is improved, but node operation efficiency is worsened due to dual roles in consensus calculation and storage

Engineering Contradiction:
Improvesystem simplicityVSAvoidnode operation efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments blockchain nodes into specialized control plane nodes and data plane nodes. Control plane nodes focus on consensus calculation, identity registration, and verification operations, while data plane nodes specialize in data storage and retrieval. This functional segmentation allows each node type to optimize its operations for its specific purpose, improving overall network efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the data storage function from the consensus calculation function, separating them into different node types. By taking out the storage responsibility from the control plane nodes that perform consensus operations, the system allows control plane nodes to focus computational resources on security-critical consensus operations while data plane nodes handle storage operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11784788B2Identity management method, device, communications network, and storage medium
Publication Date: 2023.10.10 HUAWEI TECH CO LTD
  • US11784788B2 patent drawing
  • US11784788B2 patent drawing
  • US11784788B2 patent drawing

AI summary

This application provides an identity management method, a device, a communications network, and a storage medium. The method includes generating, by a first control plane node, a first identification, a first public key, and a first private key for user equipment. The method also includes signing the first identification and the first public key based on a second private key of the first control plane node, to obtain first transaction data. The method further includes broadcasting the first transaction data in a blockchain network, where the first transaction data is to be used for consensus calculation in the blockchain network.