Decentralized Identity Binding for Secure IoT Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized network architectures for managing and authenticating devices are vulnerable to hacker attacks, particularly through account and password theft, which is exacerbated by the increasing number of IoT devices with inadequate protection.

Innovation Solution

A decentralized network system that applies for and binds decentralized identities with digital identities, updates authentication information using a randomizing rule, and saves this information for secure retrieval and use, thereby enhancing security and usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized frameworks or systems are used to store and manage device passwords and authentication information, then ease of operation and management is improved, but security against hacker attacks deteriorates

Engineering Contradiction:
Improveease of device managementVSAvoidvulnerability to hacker attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized authentication system into distributed components. Each device maintains its own authentication information locally rather than relying on a central server. The authentication process is divided into device-side verification and optional cloud synchronization, eliminating the single point of failure that hackers target in centralized systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where a decentralized identity (DID) acts as a mediator between devices and users. The DID controller manages authentication credentials and verifies device identities without exposing sensitive password information, creating a secure intermediate layer that protects against direct attacks on authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If decentralized network architecture is implemented to enhance security, then security against hacker attacks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against hacker attacksVSAvoidcomplexity of network architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal decentralized identity framework that can be applied across multiple devices and platforms. The DID controller and verification mechanisms serve multiple functions including authentication, authorization, and credential management, reducing the need for separate complex systems for each function while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables devices to perform self-service authentication without requiring complex centralized management. Each device can independently verify authentication credentials and manage its own security posture, eliminating the need for complex administrative overhead while maintaining strong security through cryptographic verification.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If authentication information is stored locally on each device, then security is improved by eliminating centralized vulnerability points, but ease of management and updates deteriorates

Engineering Contradiction:
Improvecentralized vulnerability pointsVSAvoidease of authentication management
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the decentralized identity controller monitors and manages authentication credentials across devices. When authentication information needs updating or revocation, the system provides feedback to relevant devices through secure communication channels, enabling centralized control benefits without creating centralized vulnerability points.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary authentication and credential verification actions before devices connect to networks or access resources. Authentication credentials are pre-configured and verified through the DID controller, eliminating the need for complex post-connection management and simplifying ongoing authentication operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11533306B2Processes and method for safe of use, monitoring and management of device accounts in terminal manner
Publication Date: 2022.12.20 GLOBAL WISDOM SOFTWARE TECH CO LTD
  • US11533306B2 patent drawing
  • US11533306B2 patent drawing
  • US11533306B2 patent drawing

AI summary

A method and structure uses a decentralized network to connect and manage multiple devices. The method includes the steps of: applying for a decentralized identity in the decentralized network, and binding the decentralized identity with a digital identity; storing a correspondingly generated binding information in the decentralized network; authorizing one of the devices, to which the digital identity is allowed to connect, and an allowable account; storing a correspondingly generated authorization information in the decentralized network; when necessary, updating and storing an authentication information of the bound digital identity in the decentralized network; retrieving the authentication information from the decentralized network through a terminal device to process certification for connecting the one of the devices.