Decentralized Identity Authentication for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional client-server security systems require uninterrupted internet access for identity and access management (IAM) services, which is not feasible for IoT devices and makes them vulnerable to attacks, and there is a need for a secure method to authenticate and store identity information locally without relying on continuous internet connectivity.

Innovation Solution

A decentralized approach using a security broker, blockchain system, and security gateway to manage and authenticate identity information locally, allowing IoT devices to operate securely without constant internet access by storing and transferring identity information through a distributed blockchain database, reducing network traffic and processing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional centralized server-based IAM services are used, then security management and validation can be performed, but uninterrupted internet access is required and security breaches at the server can compromise all user identity information

Engineering Contradiction:
Improvesecurity of identity informationVSAvoidvulnerability to attacks and security breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized identity information into distributed identity credentials stored locally on individual client devices. Each user's identity information is divided and stored across multiple devices through a decentralized identifier (DID) system, so that a breach at any single location does not compromise all identity information. This segmentation transforms the centralized security model into a distributed one, eliminating the single point of failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts identity information from the centralized server environment and places it directly on client devices. By taking out the identity credentials from the vulnerable centralized repository and embedding them in individual devices via secure enclaves or trusted execution environments, the system removes the vulnerability associated with centralized storage while maintaining the ability to validate identities.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If centralized server-based validation is used, then identity verification can occur, but client devices must have uninterrupted internet access

Engineering Contradiction:
Improveaccess to IAM servicesVSAvoidinternet connectivity requirement
Core Design Contradiction:
Ease of operationVSDuration of action of moving object

Solution Approach 1:

The patent implements self-service by enabling client devices to perform local validation of identity credentials without requiring continuous connection to a central server. Each device contains the necessary verification logic and cryptographic keys to validate identities locally, allowing operations to proceed autonomously even when offline. The system only needs intermittent connectivity to synchronize credential updates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-loading identity credentials and validation capabilities onto client devices before they are needed for operations. The decentralized identifiers and cryptographic proofs are established in advance and stored securely on devices, enabling immediate local validation without requiring real-time server communication during critical operations.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If all security apparatus is placed at the enterprise server, then centralized control is maintained, but the system becomes vulnerable to catastrophic security breaches

Engineering Contradiction:
Improvecentralized security architectureVSAvoidresistance to security breaches
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security apparatus from a single centralized location into distributed security capabilities across multiple client devices. Each device maintains its own security enclave with cryptographic keys and validation logic, creating a distributed security architecture where the failure or compromise of one device does not affect the overall system security. This segmentation fundamentally changes the attack surface and resilience characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by tailoring security capabilities to individual devices and users rather than applying a uniform centralized security model. Each device can have customized security policies, credentials, and validation rules appropriate to its specific context and requirements. This localized approach allows for more granular security control and reduces the impact of breaches to individual local instances rather than system-wide compromise.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11005812B2Autonomous decentralization of centralized stateful security services with systematic tamper resistance
Publication Date: 2021.05.11 XAGE SECURITY INC
  • US11005812B2 patent drawing
  • US11005812B2 patent drawing
  • US11005812B2 patent drawing

AI summary

In an embodiment, a computer implemented method comprises accessing, from a first data repository, identity information associated with one or more protected computing devices; creating mapped identity information by encrypting and mapping the identity information according to a different identity data format that is compatible with the one or more protected computing devices; updating stored blockchain data using the mapped identity information; storing the mapped identity information from the blockchain data in a second data repository; generating decrypted identity information from the mapped identity information stored in the second data repository; and performing one or more authentication services for a client device on behalf of the one or more protected computing devices by using the mapped identity information in the second data repository; wherein the method is performed by one or more computing devices.