IoT Device Commissioning via Permissioned Blockchain
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IoT device commissioning methods rely on trusted third-party certification authorities for public key management, which can lead to security risks such as key cloning and unsecure communications, as all trust is placed on this third party.
Innovation Solution
A method and system using a permissioned blockchain to commission IoT devices by providing meta-information and cryptographic keys, initializing the device for communication with the blockchain, generating and storing a hash key, and verifying it to enable secure communication with the IoT Hub, thereby reducing third-party involvement and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a trusted third party certification authority is used for public key management, then device commissioning and authentication can be simplified, but security risks increase due to key cloning and tampering possibilities
Solution Approach 1:
The patent extracts the third-party certification authority from the system and replaces it with a peer-to-peer blockchain-based authentication mechanism. Each device stores its own public key and certificate in a blockchain, eliminating the need for a central CA while maintaining secure authentication. This extraction resolves the contradiction by removing the single point of failure (CA) that enabled key cloning, while the distributed blockchain structure maintains ease of commissioning through automated verification.
Solution Approach 2:
The blockchain acts as an intermediary between devices and the authentication system. Instead of relying on a third-party CA, the blockchain provides a distributed ledger that verifies device certificates and public keys. This intermediary mechanism maintains security by cryptographically verifying identities while simplifying operations through automated blockchain-based authentication, thus resolving the contradiction between security and ease of commissioning.
2Device complexity
If all trust is placed on a third party certification authority, then centralized key management is achieved, but the system becomes vulnerable to infiltration and communication security breaches
Solution Approach 1:
The patent removes the centralized third-party CA from the system architecture and distributes trust across a blockchain network. Each device maintains its own key pair and certificate, storing them in the blockchain rather than relying on a central authority. This extraction eliminates the vulnerability to CA infiltration while maintaining manageable key structure, thus resolving the contradiction between centralized management simplicity and communication security.
Solution Approach 2:
The patent changes the fundamental parameter of trust from centralized (CA-based) to distributed (blockchain-based). Instead of trusting a single authority, the system uses cryptographic hashes and distributed verification to ensure communication security. This parameter change maintains key management feasibility while dramatically improving security against infiltration and breaches.
3Reliability
If a permissioned blockchain is used to store device meta-information and verify hash keys, then data integrity and security are enhanced, but system complexity increases
Solution Approach 1:
The patent implements self-service by having devices autonomously store their own meta-information and public keys in the blockchain, and automatically verify their hash keys. The commissioning process is automated, with devices independently completing authentication without manual intervention. This self-service approach enhances data integrity through immutable blockchain storage while managing complexity through standardized automated procedures.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring devices with their public keys and certificates before deployment. The blockchain is pre-established with the necessary verification mechanisms and rules. This preliminary setup simplifies the actual commissioning process, as devices only need to connect and verify their pre-configured credentials against the blockchain, thus reducing operational complexity while maintaining high data integrity.
Data Source
AI summary
A method and apparatus for commissioning a device to an Internet of Things (IoT) Hub using a permissioned blockchain. The method includes preparing a device to be commissioned by providing the device with meta-information and a set of cryptographic keys, initializing the device to facilitate communication with a permissioned blockchain by a trusted user, storing at least a portion of the meta-information in the permissioned blockchain, and receiving and storing by the device, a hash key from the permissioned blockchain, the hash key based on the storing. The method also includes connecting to the device via a service tool to obtain the hash key and verifying the hash key with the permissioned block chain. If the verifying is successful, communicating device information to a cloud service, the cloud service in communication with the IoT Hub to enable the commissioning.


