IoT Edge Network Device Registration via Blockchain
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT networks face challenges in securing devices with varying capabilities at the edge, particularly when new nodes are added, as existing methods do not effectively address authentication and registration, leading to potential security threats.
Innovation Solution
A method utilizing a Certifying Authority (CA) node on the network to register new Off-The-Shelf devices by verifying their authenticity through a public blockchain, establishing a shared secret using Diffie-Hellman key exchange, and generating symmetric keys for secure communication, with digital certificates stored on a permissioned blockchain for validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificates are issued among devices to secure communication, then communication security is improved, but device authentication and registration are not addressed
Solution Approach 1:
The patent applies preliminary action by pre-provisioning each IoT device with a unique device identifier and cryptographic key pair during manufacturing. These credentials are stored in secure element hardware before the device is deployed to the network, enabling automatic authentication and registration without manual intervention when the device first connects.
Solution Approach 2:
The patent implements self-service through an automated registration process where the IoT device independently authenticates itself to the network using its pre-provisioned credentials. The device autonomously generates registration requests, verifies responses, and completes the registration workflow without requiring manual configuration or intervention, thereby improving ease of operation while maintaining security.
2Adaptability or versatility
If separate wireless networks are established for less secure and more secure devices, then device security classification is improved, but prevention of security attacks is not addressed
Solution Approach 1:
The patent applies local quality by implementing differentiated security policies and authentication mechanisms tailored to specific device types and their security capabilities. Instead of creating separate physical networks, the system assigns different security levels, access permissions, and cryptographic requirements to individual devices or device groups based on their specific needs and capabilities, thereby maintaining network unity while providing customized security protection.
Solution Approach 2:
The patent implements preliminary anti-action by establishing a comprehensive authentication and authorization framework before devices can access the network. The system preemptively verifies device credentials, validates device identities, and enforces access control policies to prevent security attacks before they can occur, rather than relying on network segmentation alone.
3Manufacturing precision
If manual intervention is required to store association identification code, then device provisioning accuracy is improved, but provisioning efficiency deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-provisioning each IoT device with a unique device identifier and cryptographic key pair during the manufacturing process. These credentials are embedded in the device's secure element hardware before deployment, ensuring high provisioning accuracy through controlled manufacturing processes while eliminating the need for manual intervention during deployment, thereby achieving both precision and efficiency.
Solution Approach 2:
The patent implements self-service through automated device registration where the IoT device independently presents its pre-provisioned credentials to the network operator. The system automatically verifies the device identifier against the blockchain registry, validates cryptographic signatures, and completes the registration process without manual intervention, thereby maintaining high provisioning accuracy while dramatically improving provisioning efficiency and scalability.
4Device complexity
If the IoT service assumes other participating devices are not compromised, then system complexity is reduced, but overall network security deteriorates
Solution Approach 1:
The patent implements preliminary anti-action by establishing a blockchain-based trusted registry that stores and verifies device identifiers and cryptographic credentials before devices join the network. The system preemptively validates device identities through cryptographic proof mechanisms and continuously monitors device behavior, enabling the IoT service to maintain simplified operations while achieving robust security through automated verification and anomaly detection.
Solution Approach 2:
The patent introduces a blockchain-based intermediary registry that mediates between IoT devices and the service platform. This decentralized ledger stores device credentials and provides cryptographic verification mechanisms, allowing the IoT service to assume devices are authenticated without directly managing complex security protocols. The blockchain intermediary handles credential verification, device registration, and security policy enforcement, thereby reducing system complexity while maintaining high security standards.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Ensures overall security of IoT edge networks by authenticating and registering new devices, preventing unauthorized access, and securing communication between nodes, thereby enhancing the resilience against various security attacks.
Implementation Method 1
establishing a shared secret between the first node and the second node using the Diffie-Hellman common secret multiplier
Data Source
AI summary
A mechanism for registering a device with an Internet of Things (IoT) edge network is disclosed. The manufacturer of the device stores credentials of the device in a secure storage of the device. The manufacturer also stores the credentials on a public blockchain with sensitive parameters hashed or encrypted. A certifying node accesses the credentials from the public blockchain to establish a secure connection with the device and to verify its credentials. The device sends the credentials to the certifying node, only if the certifying node is able to decrypt a device access parameter from the public blockchain. Upon verifying the credentials of the device, the certifying node issues a digital certificate to the new device and it is stored on a permissioned blockchain within the IoT network. Other nodes in the IoT network may use the digital certificate on the permissioned blockchain for secure communication with the device.


