Blockchain Onboarding via Trusted Device Referral

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems, such as PKI, are vulnerable to single failure points, allowing unauthorized access if the certificate authority is compromised, necessitating a solution for establishing trust between devices without reliance on a single entity.

Innovation Solution

Implementing a blockchain-secured network that uses a trusted device to onboard new devices through a UEM system, where both devices exchange information and authentication tokens, and the UEM server verifies and adds the new device to the blockchain consensus, establishing two-way trust and secure communication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI infrastructure is used to secure communication, then security is provided through two-key encryption system, but the system has a single failure point (certificate authority) that can compromise the entire network

Engineering Contradiction:
Improvenetwork securityVSAvoidcentralized trust structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized certificate authority into multiple distributed blockchain nodes. Instead of relying on a single trusted entity, the trust function is divided among multiple nodes that collectively maintain the blockchain ledger, eliminating the single point of failure while preserving security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a blockchain ledger as an intermediary mechanism between devices. Rather than direct trust between devices or reliance on a central authority, the blockchain serves as a decentralized mediator that verifies and records device identities and communications, enabling trust without centralization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a centralized certificate authority is used to issue keys, then key management is simplified, but the entire network can be compromised if the certificate authority is breached

Engineering Contradiction:
Improvekey managementVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The key management function is segmented from the centralized certificate authority and distributed across multiple blockchain nodes. Each node maintains a copy of the blockchain ledger containing device identities and cryptographic information, providing both ease of management through standardization and reliability through distribution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing each blockchain node to independently verify device identities using the distributed ledger. Each node has the capability to perform authentication and key verification locally without needing to query a central authority, enhancing both security and operational efficiency

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional PKI systems are used, then device authentication is established through central authority, but unauthorized access can occur if the authority is compromised

Engineering Contradiction:
Improvedevice authenticationVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The blockchain ledger acts as a decentralized intermediary that performs device authentication without relying on a vulnerable central authority. The ledger contains verified device identities and cryptographic signatures, allowing any node to independently authenticate devices while preventing unauthorized access through cryptographic verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-verifying device identities and recording them in the blockchain ledger before actual communication occurs. Devices are authenticated in advance through the distributed ledger, ensuring that only authorized devices can access the network while preventing unauthorized access attempts

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11824989B2Secure onboarding of computing devices using blockchain
Publication Date: 2023.11.21 OMNISSA LLC
  • US11824989B2 patent drawing
  • US11824989B2 patent drawing
  • US11824989B2 patent drawing

AI summary

Systems and methods are described for onboarding a new device to a blockchain secured network. A trusted device that is already enrolled on the blockchain can receive information from a new device. The new device can send an onboarding request to a server through a non-blockchain secured Application Programming Interface (“API”). The trusted device can send an onboarding request for the new device through a blockchain secured API. The server can receive the requests and match them. The server can authenticate the two devices and send a request to a blockchain consensus to add the new device to the blockchain with the trusted device as a referral. The blockchain consensus can add the new device to the blockchain and notify the server. The server can notify the new device, and the new device can begin communicating through the blockchain secured API or directly with other devices on the blockchain.