IoT Device Provisioning via Blockchain Public Key Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices often lack secure management, leading to security risks due to unknown or unmanaged devices, which can be exploited for unauthorized access and data breaches, especially when connected to global networks like the WAN.
Innovation Solution
A device provisioning system utilizing a blockchain to securely manage devices by using unique public and private keys, ensuring that only authorized devices receive provisioning data, thereby preventing unauthorized access and simplifying communication encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IoT devices are directly connected to WAN for global network access, then network connectivity and data transmission capability are improved, but security risk increases due to unauthorized access and device exploitation
Solution Approach 1:
The patent introduces an edge server as an intermediary between IoT devices and the WAN. The edge server performs certificate issuance and management functions, acting as a trusted mediator that enables secure communication. This resolves the contradiction by allowing IoT devices to access the WAN through a secure gateway rather than direct connection, maintaining connectivity while reducing security risks through centralized certificate management and validation.
Solution Approach 2:
The patent implements preliminary certificate issuance and device validation before allowing WAN access. The edge server issues digital certificates to IoT devices in advance, and validates these certificates before permitting network communication. This preliminary security setup ensures that only authorized devices can connect to the WAN, preventing unauthorized access while maintaining network connectivity for legitimate devices.
2Reliability
If SSL security communication and electronic certificates are implemented on each IoT device, then communication security is improved, but processing cost and operation cost increase
Solution Approach 1:
The patent extracts the complex certificate management functions from individual IoT devices and centralizes them in the edge server. The edge server handles certificate issuance, storage, and validation, while IoT devices only need to store their own certificates and present them for validation. This extraction reduces the processing burden on resource-constrained IoT devices while maintaining strong SSL/TLS security communication.
Solution Approach 2:
The edge server is designed as a universal platform that performs multiple functions: it acts as a certificate authority, a validation server, and a security gateway for multiple IoT devices. By consolidating these security functions in a single multi-functional server rather than implementing them on each individual device, the system achieves communication security while reducing overall processing costs and operational complexity.
3Object-affected harmful factors
If edge servers are deployed between IoT devices and management servers, then security risk is reduced through LAN isolation, but system complexity and infrastructure cost increase
Solution Approach 1:
The patent merges multiple functions into the edge server: network gateway, certificate authority, certificate validation server, and security enforcement point. By combining these functions in a single infrastructure component rather than distributing them across multiple separate systems, the patent reduces system complexity while maintaining the security benefits of LAN isolation and centralized certificate management.
Data Source
AI summary
To provide a provisioning system capable of providing a valid device with valid provisioning data and preventing intrusion of an unauthorized device.A device provisioning system that provides a device 4 with provisioning data for provisioning the device 4 includes: public key providing means configured to acquire a first public key unique to the device 4 from a blockchain 2 storing the first public key in association with a first trail in response to a query using the first trail; and provisioning data providing means configured to acquire the first public key through the public key providing means in response to a query using the first trail from the device 4 and transmit the provisioning data encrypted with the first public key to the device 4.


