Distributed Ledger Device Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale dynamic networks like 4G and 5G, identifying and verifying the trustworthiness of devices is challenging due to the lack of authentication mechanisms, fragmented lifecycle information across multiple databases, and the risk of malicious manipulation.

Innovation Solution

A distributed approach combining public key infrastructure (PKI) and permissioned distributed ledger technology (DLT) with trusted execution environments (TEE) to provide device identity management, history management, and software update management, ensuring decentralized storage and robust data consistency, and enabling authorized stakeholders to verify device authenticity and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If lifecycle information is collected from multiple databases, then device identification capability is improved, but information integrity and trustworthiness deteriorate due to fragmentation and potential malicious manipulation

Engineering Contradiction:
Improvedevice identification capabilityVSAvoidinformation integrity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent combines multiple fragmented device lifecycle databases into a unified blockchain-based distributed ledger. This merging approach consolidates device information from manufacturers, supply-chain parties, network companies, and cloud service providers into a single tamper-proof system, resolving the contradiction by maintaining comprehensive device identification capability while ensuring information integrity through cryptographic hashing and distributed consensus mechanisms that prevent malicious manipulation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The blockchain acts as an intermediary layer between multiple stakeholder databases. Instead of directly accessing and trusting multiple private databases, the system uses blockchain as a neutral mediator that collects, verifies, and stores device lifecycle information from all parties. This intermediary approach maintains the ability to gather comprehensive device information while ensuring integrity through the blockchain's immutable ledger and consensus protocols that prevent unauthorized manipulation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distributed ledger technology is implemented, then information integrity is improved through tamper-proof logging, but system complexity increases due to integration of PKI, DLT, and TEE

Engineering Contradiction:
Improveinformation integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a multi-functional system where the blockchain-based distributed ledger simultaneously performs multiple roles: it serves as a secure storage mechanism for device lifecycle information, as an authentication system through integration with PKI (Public Key Infrastructure), as a verification platform through TEE (Trusted Execution Environment) attestation, and as a transparent audit trail. This universal approach improves information integrity while managing complexity by consolidating multiple security functions into a single integrated architecture rather than separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments complexity into distinct functional layers: the blockchain ledger handles secure information storage and integrity verification, PKI manages digital certificates and authentication, TEE provides hardware-based security enclaves for sensitive operations, and the application layer handles device lifecycle management. This segmentation allows each component to be optimized independently while reducing overall system complexity through clear separation of concerns and standardized interfaces between layers.

Inventive Principle:
Principle #1Segmentation

3Reliability

If device authentication mechanisms are added, then trustworthiness verification is improved, but device compatibility deteriorates since most devices lack authentication means

Engineering Contradiction:
Improvetrustworthiness verificationVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary authentication by embedding security credentials (public-private key pairs) into devices during the manufacturing process, before the devices are deployed to the network. This preliminary action ensures that authentication capability is built-in from the start rather than requiring later additions. The blockchain ledger then stores and verifies these pre-configured credentials, enabling trustworthiness verification for all devices including those that would otherwise lack authentication means, while maintaining compatibility across heterogeneous device types.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3891954B1Method and system for device identification and monitoring
Publication Date: 2022.11.30 NEC CORP
  • EP3891954B1 patent drawingFigure 1
  • EP3891954B1 patent drawingFigure 2
  • EP3891954B1 patent drawingFigure 3

AI summary

A method for identification and monitoring of devices (4) of a network (1) is, wherein the devices (4) of the network (1) are provided and/or operated by different participating entities, includes setting up a distributed ledger network (7), wherein each of the participating entities maintains one or multiple nodes (6) in the distributed ledger network (7), and setting up a public key infrastructure that assigns each device (4), before being deployed to the network (1), a unique certified public key. An updated status of the devices (4) is kept in a ledger of the distributed ledger network (7). To this end, participating entities identify changes of a status of a device (4) and issue a transaction related to the status change of the device (4) to the ledger, wherein the device's (4) public key is recorded in the transaction.