IoT Composite Object Identity with Blockchain-Based EPID Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT networks face challenges in enabling reliable, secure, and identifiable devices that can form networks as needed to accomplish tasks, particularly in heterogeneous environments with varying communication protocols and decentralized operations.
Innovation Solution
The implementation of blockchain technology for decentralized identification and authentication systems, using Enhanced Privacy Identification (EPID) to manage object identities and group formation, allowing IoT devices to dynamically form composite objects and fog devices without central authority intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If decentralized identification and authentication systems are implemented using blockchain and EPID, then device security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent introduces blockchain as a decentralized intermediary ledger and EPID (Enhanced Privacy Identifiers) as cryptographic intermediaries that enable secure device identification and authentication without requiring centralized authorities. These intermediaries handle the complex trust management, allowing IoT devices to verify each other's identities through cryptographic proofs stored on the blockchain, thereby improving security while managing complexity through standardized protocols.
Solution Approach 2:
The system enables IoT devices to autonomously manage their own identities and authentication credentials through self-sovereign identity mechanisms. Each device generates and controls its own cryptographic key pairs and can prove its identity without external intervention, reducing the need for complex centralized management infrastructure while enhancing security and device autonomy.
2Adaptability or versatility
If IoT devices dynamically form composite objects and networks without central authority, then adaptability and productivity are improved, but loss of information and measurement precision worsen
Solution Approach 1:
The patent implements preliminary registration of device identities and attributes on the blockchain before devices join dynamic networks. This pre-established identity infrastructure ensures that when devices form composite objects ad-hoc, their identities are already verified and recorded, preventing information loss. The blockchain serves as a persistent memory that retains identity information even as network compositions change dynamically.
Solution Approach 2:
The system incorporates feedback mechanisms where devices continuously verify and update their identities and relationships on the blockchain. When composite objects form or dissolve, the blockchain ledger provides feedback by recording these state changes, ensuring that identity management information is preserved and synchronized across the decentralized network, preventing information loss through continuous verification loops.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An Internet of Things (IoT) network composite object includes a device owner with name server and sub-object list, sub-objects, and a blockchain recording the sub-objects. An IoT network composite object includes a device owner with composite object type name server, and blockchain. An IoT network coalition group includes coalition group name server, coalition group member list, and blockchain. An IoT network apparatus includes device identity generator, message publisher, network applier, device describer, and packer sender. An IoT network apparatus includes a device registrar to register device to first network through a portal to second network, device joiner, token requester, and authentication request sender. An IoT network apparatus includes an identity verifier to verify the identity of an authentication request, and an authentication request response returner. An IoT network apparatus including a caller entity credential issuer, an object entity provisioner, credential presenter, and access control list policy applier.