IoT UID Provisioning for Brownfield Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT devices face challenges in managing their lifecycles, including provisioning, security, and trusted transfers across administrative boundaries, with susceptibility to hacking and lack of trusted device authentication.

Innovation Solution

A registry system for IoT devices using IoT Universal Identifiers (IoT UIDs) managed by a central authority, enabling device authentication, trust and risk assessment, and lifecycle management, with features like single-pane-of-glass displays for simplified access and fraud detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional domain controller servers are used to manage security groups, then device authentication can be performed, but system complexity and security vulnerability increase

Engineering Contradiction:
Improvedevice authentication securityVSAvoiddomain controller management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the device authentication function from traditional domain controller servers and relocates it to a distributed blockchain-based system. Each device has its own unique identifier stored on the blockchain, eliminating the need for centralized domain controllers while maintaining secure authentication capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The blockchain serves as an intermediary between devices for authentication purposes. Instead of devices directly communicating with domain controllers, all authentication transactions are mediated through the blockchain, which provides a decentralized, tamper-proof record of device identities and permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If approved lists are maintained by devices to trust other devices, then security can be enforced, but real-time trust assessment capability is reduced

Engineering Contradiction:
Improvedevice trust assessmentVSAvoidreal-time verification delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-provisioning unique device identifiers and registering device information on the blockchain before devices need to interact. This includes pre-establishing device profiles, permissions, and trust parameters on the blockchain, so that when devices need to authenticate, the information is already available for immediate verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The blockchain provides continuous feedback about device status, permissions, and trust levels to any querying device. When a device needs to verify another device's trustworthiness, the blockchain instantly returns the current state of the target device's identifier and associated metadata, enabling real-time trust assessment without manual list updates.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If centralized registries are used to track device histories, then comprehensive device management is achieved, but system vulnerability to attacks increases

Engineering Contradiction:
Improvedevice lifecycle managementVSAvoidsystem attack susceptibility
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the centralized device registry function and distributes it across the blockchain network. Device lifecycle information including histories, permissions, and trust indicators are stored as immutable records on the blockchain, eliminating single points of failure and reducing vulnerability to centralized attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses composite security architecture combining blockchain's distributed ledger technology with device-level unique identifiers and cryptographic verification. This composite approach integrates multiple security layers: decentralized storage, cryptographic hashing, and device-specific credentials, creating a more resilient system against attacks.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS12602697B2Systems and methods for provisioning embedded internet of things universal IDS (IoT UIDs) in brownfield devices
Publication Date: 2026.04.14 SOMOS INC
  • US12602697B2 patent drawing
  • US12602697B2 patent drawing
  • US12602697B2 patent drawing

AI summary

A method including: interpreting, via a device registration request circuit, a registration request that maps device property data to one or more Brownfield devices; generating, via an Internet of Things Universal Identification (IoT UID) generation circuit, based at least in part on the registration request, an IoT UID for each of the one or more Brownfield devices; and transmitting, via an IoT UID provisioning circuit, the IoT UID for each of the one or more Brownfield devices.