IoT Device Isolation via Distributed Ledger Role Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are vulnerable to compromise and counterfeiting during the supply chain, posing risks of attacks and security breaches when connected to networks, due to lack of effective trust establishment and authentication mechanisms.

Innovation Solution

A system utilizing a distributed ledger to manage and verify role certificates for IoT devices, ensuring secure communication channels by periodically validating role certificate proofs recorded on the ledger, and dynamically isolating compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized system is used for establishing trust and secure communication channels, then device management is simplified, but the system becomes a single point of failure and vulnerable to attacks

Engineering Contradiction:
Improvedevice managementVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized trust establishment into distributed peer-to-peer verification using blockchain technology. Each device independently verifies others through smart contracts and cryptographic proofs, eliminating the single point of failure while maintaining simplified operation through automated consensus mechanisms

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces blockchain as an intermediary layer that mediates trust establishment between devices. Smart contracts act as automated intermediaries that verify device identities and communication channels without requiring direct centralized control, thus improving reliability while maintaining ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If devices are connected to the network without rigorous authentication, then network access is faster and easier, but compromised or counterfeit devices can cause attacks

Engineering Contradiction:
Improvenetwork access speedVSAvoidsecurity risks from compromised devices
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication through blockchain-based identity verification and smart contract validation before devices are allowed to access the network. This pre-verification process ensures that only authenticated devices can connect, eliminating security risks while maintaining fast access through automated credential checking

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous feedback mechanisms where devices periodically verify each other's credentials through the blockchain network. This ongoing validation provides real-time feedback on device authenticity, allowing the network to quickly isolate compromised devices while maintaining fast access for authenticated devices

Inventive Principle:
Principle #23Feedback

3Device complexity

If traditional certificate validation is used, then authentication is simpler, but it cannot dynamically revoke certificates or detect compromised devices in real-time

Engineering Contradiction:
Improveauthentication mechanismVSAvoidreal-time security response
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transforms static certificate validation into a dynamic process using blockchain-based credentials that can be revoked or updated in real-time. Smart contracts automatically detect credential invalidation and adjust device permissions dynamically, providing real-time security response while maintaining simple authentication through automated verification

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces traditional mechanical certificate validation systems with blockchain-based cryptographic verification. This substitution enables real-time credential revocation and compromise detection through distributed consensus mechanisms while maintaining authentication simplicity through automated smart contract execution

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11729004B2Certificate-based remote dynamic isolation of IOT devices using distributed ledger technologies
Publication Date: 2023.08.15 UNISYS CORP
  • US11729004B2 patent drawing
  • US11729004B2 patent drawing
  • US11729004B2 patent drawing

AI summary

Methods and systems for remote dynamic isolation of IoT devices are provided. One system includes a first IoT device and a second IoT device configured with an active communication channel with the first IoT device and a role certificate. An operator device is configured to interact with a distributed ledger to issue and revoke role certificates for a plurality of devices including the first IoT device and the second IoT device. The first IoT device periodically validates a role certificate proof received from the second IoT device with an entry of the role certificate proof recorded on the distributed ledger.