Distributed Ledger Authentication for Resource-Constrained IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices have limited storage and processing capacity, making them vulnerable to security compromises when connected to networks, which can lead to data insecurity and asset risk due to compromised authenticity of computing devices or platforms.

Innovation Solution

A method using a distributed ledger, such as blockchain, for secure authentication and authorization between user devices and IoT devices, involving onboarding identities based on public key identities, electronic signatures, and Proof of Authority (PoA) trust anchors to establish and verify relationships, ensuring secure data exchange and asset protection even in offline environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If IoT devices are connected to networks for data transfer, then data exchange capability is improved, but security vulnerability increases

Engineering Contradiction:
Improvedata exchange capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a distributed ledger as an intermediary layer between IoT devices and networks. The ledger stores verified identities and relationships, allowing devices to authenticate彼此 without direct network trust. This mediator enables secure offline operations while maintaining connectivity benefits when online.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If IoT devices store more authentication data locally, then authentication speed is improved, but storage capacity is exceeded

Engineering Contradiction:
Improveauthentication speedVSAvoidstorage capacity
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The patent moves authentication data from the constrained IoT device storage to the distributed ledger, which has effectively unlimited storage across the network. Devices only store minimal verification credentials, while comprehensive authentication data resides in the ledger's distributed storage dimension, enabling fast local verification without exceeding device storage limits.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If IoT devices perform complex verification operations, then authentication security is improved, but processing capacity is exceeded

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing capacity
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts complex verification computations from resource-constrained IoT devices and performs them in the distributed ledger environment where processing power is abundant. Devices only need to execute simple verification of cryptographic signatures and ledger entries, while the computationally intensive consensus validation and identity verification occur in the ledger network.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If distributed ledger verification is performed offline, then operational independence is improved, but verification reliability is reduced

Engineering Contradiction:
Improveoffline operational capabilityVSAvoidverification reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary actions by having IoT devices download and cache essential verification data, including trusted root certificates, organizational identities, and relationship proofs, before going offline. The distributed ledger syncs this critical authentication data in advance, enabling devices to perform verified authentication offline while maintaining security integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11463266B2System and method for secure authentication and authorization
Publication Date: 2022.10.04 VOUCH IO LLC
  • US11463266B2 patent drawing
  • US11463266B2 patent drawing
  • US11463266B2 patent drawing

AI summary

A system and method for secure authentication and authorization between a user device and an Internet of Things (IoT) device that is associated with an asset. The method includes onboarding, using one or more processors that are operatively associated with a distributed ledger, the user device at least based on a public key identity of the user device; onboarding a user with the user device; onboarding an identity of the IoT device and the asset such that association between the asset and the IoT device is endorsed on the distributed ledger; and facilitating the user device to retrieve a first set of data packets representative of any of a relevant electronic authoritative document(s), associated consensus proof(s), and block header(s) from the distributed ledger.