Decentralized Identity Binding for Secure IoT Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized network architectures for managing and authenticating devices are vulnerable to hacker attacks, particularly through account and password theft, which is exacerbated by the increasing number of IoT devices with inadequate protection.
Innovation Solution
A decentralized network system that applies for and binds decentralized identities with digital identities, updates authentication information using a randomizing rule, and saves this information for secure retrieval and use, thereby enhancing security and usability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized frameworks or systems are used to store and manage device passwords and authentication information, then ease of operation and management is improved, but security against hacker attacks deteriorates
Solution Approach 1:
The patent segments the centralized authentication system into distributed components. Each device maintains its own authentication information locally rather than relying on a central server. The authentication process is divided into device-side verification and optional cloud synchronization, eliminating the single point of failure that hackers target in centralized systems.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where a decentralized identity (DID) acts as a mediator between devices and users. The DID controller manages authentication credentials and verifies device identities without exposing sensitive password information, creating a secure intermediate layer that protects against direct attacks on authentication data.
2Object-affected harmful factors
If decentralized network architecture is implemented to enhance security, then security against hacker attacks is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal decentralized identity framework that can be applied across multiple devices and platforms. The DID controller and verification mechanisms serve multiple functions including authentication, authorization, and credential management, reducing the need for separate complex systems for each function while maintaining security.
Solution Approach 2:
The system enables devices to perform self-service authentication without requiring complex centralized management. Each device can independently verify authentication credentials and manage its own security posture, eliminating the need for complex administrative overhead while maintaining strong security through cryptographic verification.
3Object-affected harmful factors
If authentication information is stored locally on each device, then security is improved by eliminating centralized vulnerability points, but ease of management and updates deteriorates
Solution Approach 1:
The patent implements a feedback mechanism where the decentralized identity controller monitors and manages authentication credentials across devices. When authentication information needs updating or revocation, the system provides feedback to relevant devices through secure communication channels, enabling centralized control benefits without creating centralized vulnerability points.
Solution Approach 2:
The system performs preliminary authentication and credential verification actions before devices connect to networks or access resources. Authentication credentials are pre-configured and verified through the DID controller, eliminating the need for complex post-connection management and simplifying ongoing authentication operations.
Data Source
AI summary
A method and structure uses a decentralized network to connect and manage multiple devices. The method includes the steps of: applying for a decentralized identity in the decentralized network, and binding the decentralized identity with a digital identity; storing a correspondingly generated binding information in the decentralized network; authorizing one of the devices, to which the digital identity is allowed to connect, and an allowable account; storing a correspondingly generated authorization information in the decentralized network; when necessary, updating and storing an authentication information of the bound digital identity in the decentralized network; retrieving the authentication information from the decentralized network through a terminal device to process certification for connecting the one of the devices.


