IoT Device Commissioning via Permissioned Blockchain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT device commissioning methods rely on trusted third-party certification authorities for public key management, which can lead to security risks such as key cloning and unsecure communications, as all trust is placed on this third party.

Innovation Solution

A method and system using a permissioned blockchain to commission IoT devices by providing meta-information and cryptographic keys, initializing the device for communication with the blockchain, generating and storing a hash key, and verifying it to enable secure communication with the IoT Hub, thereby reducing third-party involvement and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a trusted third party certification authority is used for public key management, then device commissioning and authentication can be simplified, but security risks increase due to key cloning and tampering possibilities

Engineering Contradiction:
Improvedevice commissioningVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the third-party certification authority from the system and replaces it with a peer-to-peer blockchain-based authentication mechanism. Each device stores its own public key and certificate in a blockchain, eliminating the need for a central CA while maintaining secure authentication. This extraction resolves the contradiction by removing the single point of failure (CA) that enabled key cloning, while the distributed blockchain structure maintains ease of commissioning through automated verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The blockchain acts as an intermediary between devices and the authentication system. Instead of relying on a third-party CA, the blockchain provides a distributed ledger that verifies device certificates and public keys. This intermediary mechanism maintains security by cryptographically verifying identities while simplifying operations through automated blockchain-based authentication, thus resolving the contradiction between security and ease of commissioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If all trust is placed on a third party certification authority, then centralized key management is achieved, but the system becomes vulnerable to infiltration and communication security breaches

Engineering Contradiction:
Improvekey managementVSAvoidcommunication security
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent removes the centralized third-party CA from the system architecture and distributes trust across a blockchain network. Each device maintains its own key pair and certificate, storing them in the blockchain rather than relying on a central authority. This extraction eliminates the vulnerability to CA infiltration while maintaining manageable key structure, thus resolving the contradiction between centralized management simplicity and communication security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the fundamental parameter of trust from centralized (CA-based) to distributed (blockchain-based). Instead of trusting a single authority, the system uses cryptographic hashes and distributed verification to ensure communication security. This parameter change maintains key management feasibility while dramatically improving security against infiltration and breaches.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a permissioned blockchain is used to store device meta-information and verify hash keys, then data integrity and security are enhanced, but system complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidblockchain integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having devices autonomously store their own meta-information and public keys in the blockchain, and automatically verify their hash keys. The commissioning process is automated, with devices independently completing authentication without manual intervention. This self-service approach enhances data integrity through immutable blockchain storage while managing complexity through standardized automated procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-configuring devices with their public keys and certificates before deployment. The blockchain is pre-established with the necessary verification mechanisms and rules. This preliminary setup simplifies the actual commissioning process, as devices only need to connect and verify their pre-configured credentials against the blockchain, thus reducing operational complexity while maintaining high data integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11271746B2Component commissioning to IoT hub using permissioned blockchain
Publication Date: 2022.03.08 OTIS ELEVATOR CO
  • US11271746B2 patent drawing
  • US11271746B2 patent drawing
  • US11271746B2 patent drawing

AI summary

A method and apparatus for commissioning a device to an Internet of Things (IoT) Hub using a permissioned blockchain. The method includes preparing a device to be commissioned by providing the device with meta-information and a set of cryptographic keys, initializing the device to facilitate communication with a permissioned blockchain by a trusted user, storing at least a portion of the meta-information in the permissioned blockchain, and receiving and storing by the device, a hash key from the permissioned blockchain, the hash key based on the storing. The method also includes connecting to the device via a service tool to obtain the hash key and verifying the hash key with the permissioned block chain. If the verifying is successful, communicating device information to a cloud service, the cloud service in communication with the IoT Hub to enable the commissioning.