Distributed Ledger Device Authentication for IoT Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional device authentication methods in IoT systems face efficiency bottlenecks and high deployment costs due to reliance on third-party servers and secure channels, which are not suitable for large-scale applications.
Innovation Solution
A distributed ledger-based authentication method that eliminates the need for a third-party server and secure channel, enabling two-way authentication through public key cryptography and digital signatures on a distributed ledger, such as blockchain or IOTA, to authenticate devices and control service access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a trusted third-party server is used for device authentication, then authentication security is improved, but authentication efficiency deteriorates due to processing power limitations
Solution Approach 1:
The patent extracts the authentication verification function from the third-party server and distributes it to individual devices through the distributed ledger. Each device can independently verify authentication requests by checking the ledger, eliminating the single-point bottleneck while maintaining security through cryptographic verification of authentication credentials stored on the ledger.
Solution Approach 2:
The centralized authentication authority is segmented into distributed nodes across the network, with authentication credentials segmented and stored across multiple devices on the distributed ledger. This segmentation allows parallel verification of authentication requests by multiple devices simultaneously, improving overall authentication throughput while maintaining security through consensus mechanisms.
2Reliability
If a trusted third-party server is used for device authentication, then authentication security is improved, but system cost increases due to server deployment and maintenance
Solution Approach 1:
Devices authenticate themselves and each other directly using credentials from the distributed ledger, without requiring a dedicated third-party authentication server. Each participant in the network maintains its own authentication capabilities, eliminating the need for centralized server infrastructure and reducing deployment and maintenance costs while preserving security through cryptographic verification.
Solution Approach 2:
The distributed ledger serves multiple functions simultaneously: it stores authentication credentials, provides a decentralized verification mechanism, and enables direct device-to-device authentication. This multi-functionality eliminates the need for separate authentication servers, reducing system complexity and cost while maintaining security through the ledger's inherent cryptographic properties.
3Reliability
If secure channels with specific hardware support are used, then authentication security is improved, but deployment cost increases and scalability deteriorates
Solution Approach 1:
The patent replaces hardware-based secure channels (such as SIM cards or dedicated encryption modules) with software-based cryptographic verification using public key infrastructure and distributed ledger technology. This substitution eliminates the need for specialized hardware while maintaining security through mathematical cryptography, enabling broader device compatibility and large-scale deployment without additional hardware costs.
Solution Approach 2:
Instead of requiring each device to have unique hardware security modules, the authentication credentials are copied and distributed across multiple devices on the ledger. Each device can verify authentication using the same cryptographic algorithms and ledger data, eliminating hardware dependencies and enabling universal participation in the authentication system with standard devices.
Data Source
AI summary
A device authentication method, a service access control method, a device, and a non-transitory computer-readable recording medium are provided. In the device authentication method, an authentication request device issues an authentication request transaction in a distributed ledger, and an authentication response device reads the authentication request transaction in the distributed ledger and performs authentication. Thus, no third-party authentication center or coordinate device is required to participate in an authentication handshake process, thereby reducing deployment overhead of an authentication system and improving efficiency of authentication and access service control.


