External Device Trust Using Verifiable Credentials and DTI
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing trust for external partner devices with varying security standards is challenging, as organizations often lack transparency and control over devices managed by different organizations, necessitating additional devices or manual installation of security tools.
Innovation Solution
A Device Trust Issuer (DTI) verifies existing external devices against security standards using Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), issuing and updating these credentials in a decentralized manner through a blockchain, allowing devices to prove trustworthiness and aligning with multiple organizations' security standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If external partners use their own existing devices, then device availability and ease of access improve, but security control and trust verification worsen
Solution Approach 1:
A Device Trust Issuer (DTI) is introduced as an intermediary between external partners and the organization. The DTI issues verifiable credentials that attest to device security compliance, allowing the organization to trust external devices without directly managing or controlling them. This mediator enables security verification while preserving partner device autonomy.
Solution Approach 2:
The patent changes the verification parameter from direct device management to credential-based verification. Instead of controlling device configurations directly, the system verifies security parameters through cryptographic credentials and trust scores, enabling indirect but reliable security control.
2Reliability
If organizations provide extra devices conforming to security rules, then security compliance improves, but device complexity and cost increase
Solution Approach 1:
External partners self-verify their device security compliance by obtaining verifiable credentials from a DTI without requiring the organization to provision or manage their devices. The partners maintain full control of their own devices while demonstrating compliance through cryptographic proof.
Solution Approach 2:
Instead of requiring physical device provisioning, the system uses digital copies of security attestations in the form of verifiable credentials. These credentials replicate the trust relationship without requiring physical device management infrastructure.
3Reliability
If direct device provisioning is used within own organization, then trust establishment improves, but adaptability to external partners worsens
Solution Approach 1:
The verifiable credential system serves multiple functions: it establishes trust for internal devices, verifies external partner devices, and enables cross-organization trust relationships. The same credential mechanism works universally across different organizational boundaries and device types.
Solution Approach 2:
Instead of the organization verifying each external device directly, the inversion approach has external devices verified by independent DTIs, and the organization trusts the DTI's verification. This reverses the traditional verification hierarchy to enable external trust.
4Reliability
If manual security tool installation is required on external devices, then security control improves, but ease of operation and deployment time worsen
Solution Approach 1:
Security verification is performed in advance through credential issuance by DTIs before partners need to access organizational resources. The trust relationship is established beforehand through automated credential verification, eliminating the need for manual security tool installation at deployment time.
Data Source
Figure 1~2
AI summary
Methods and systems for establishing trust for external partner devices with verifiable credentials are disclosed. Embodiments include verifying, by a device trust issuer, DTI, adherence to a first level of security of a device external to an organization according to one or more security standards; in response to the first level of security being met, issuing, by the DTI, one or more verifiable credentials, VCs, to the external device; writing, by the DTI, the VCs into an electronic ledger; requesting, by the external device, from a Service Owner, SO, within the organization, access to the resources within the organization by: authenticating the external device at the SO using an identity authentication protocol; and providing the VCs to the SO; verifying, by the SO, and based on the VCs provided by that the external device that the DTI is trusted by the SO; in response to the DTI being trusted by the SO, verifying, by the SO based on the VCs, that the first level of security of the external device matches a second level of security required by the SO; and in response to the first level of security matching the second level of security, granting access to the external device to the resources within the organization.