IoT Authentication via Distributed Ledger Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices have limited storage and processing capacity, making them vulnerable to security compromises when connected to networks, which can lead to data security risks and asset protection issues due to potential authenticity and integrity breaches.

Innovation Solution

A method using a centralized computing device with a distributed ledger to onboard user and IoT device identities, establishing relationships and verifying authenticity through public key identities, consensus proofs, and block headers, enabling secure authentication and authorization even in offline environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If IoT devices are connected to networks for data transfer, then data transfer capability is improved, but security and authenticity are compromised

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidsecurity and authenticity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces a distributed ledger (blockchain) as an intermediary between IoT devices and networks. The ledger stores verified identities and authorization records, allowing IoT devices to authenticate securely without direct network exposure. The mediator validates transactions and maintains trust anchors, enabling data transfer while preserving security through cryptographic verification of device identities and authorization proofs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If IoT devices have limited storage and processing capacity, then device portability is improved, but security vulnerability increases

Engineering Contradiction:
Improvestorage capacityVSAvoidsecurity vulnerability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the security architecture into multiple components: lightweight identity verification data stored locally in IoT devices, distributed ledger storage across the network, and cryptographic proof generation at the device level. This segmentation allows IoT devices to maintain minimal local storage while leveraging the distributed ledger for secure authentication, reducing security vulnerabilities without requiring extensive local processing capacity.

Inventive Principle:
Principle #1Segmentation

3Productivity

If centralized authentication systems are used, then authentication efficiency is improved, but system complexity and single point of failure risk increase

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic authentication system where the centralized computing device initially provisions identities and stores them in the distributed ledger, then enables decentralized offline authentication. The system dynamically adapts between centralized setup phase and distributed operation phase, maintaining authentication efficiency while reducing ongoing system complexity and eliminating single points of failure through the distributed nature of the ledger.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11329820B2System and method for secure authentication and authorization
Publication Date: 2022.05.10 VOUCH IO LLC
  • US11329820B2 patent drawing
  • US11329820B2 patent drawing
  • US11329820B2 patent drawing

AI summary

Embodiments herein relate to system and method for secure authentication and authorization between a user device and an Internet of Things (IoT) device that is associated with an asset. The method includes onboarding, using a centralized computing device having one or more processors that are operatively associated with a distributed ledger, the user device with a user at least based on a public key identity of the user device; onboarding the user of the user device with the user device; onboarding an identity of the IoT device and the asset such that association between the asset and the IoT device is endorsed on the distributed ledger; and facilitating, through the centralized computing device, the user device to retrieve a first set of data packets representative of any of a relevant electronic authoritative document(s), associated consensus proof(s), and block header(s) from the distributed ledger.