Distributed Ledger Supply Chain Device Authenticity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of computing device onboarding in supply chains due to the need for trust between multiple entities makes it challenging to ensure the authenticity of computing devices as they pass through various sites, breaking trust when modifications are made by third parties.
Innovation Solution
A distributed ledger system, such as a blockchain, is used to maintain component verification records across the supply chain, allowing each entity to validate the authenticity of computing devices by generating and verifying component verification data, ensuring transparency and integrity of provisioning actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a distributed ledger system is implemented to maintain component verification records across the supply chain, then the authenticity and integrity of computing devices can be verified, but the system complexity and implementation difficulty increase
Solution Approach 1:
A distributed ledger system acts as an intermediary between multiple supply chain entities, providing a shared truth source that all parties can trust without needing to trust each other directly. The ledger mediates the verification process by storing and validating component verification records from manufacturers through distributors to end users, resolving the trust complexity through a decentralized consensus mechanism
Solution Approach 2:
The verification process is segmented into discrete component verification records that can be independently created, stored, and validated. Each provisioning action (manufacturing, distribution, deployment) creates a separate record in the ledger, allowing granular verification of individual components and actions rather than requiring verification of the entire supply chain at once
2Reliability
If component verification data is obtained and validated from a distributed ledger at each computing site, then trust is maintained throughout the supply chain, but the time and computational resources required for verification increase
Solution Approach 1:
Component verification records are created and stored in the distributed ledger at the source (manufacturing site) before the computing device moves through the supply chain. This preliminary action ensures that verification data is already available and validated when needed at downstream sites, eliminating the need for time-consuming re-verification and enabling rapid authenticity checks at each transfer point
3Loss of information
If the distributed ledger maintains detailed provisioning action records for each computing device, then transparency and auditability are improved, but the data storage requirements and processing overhead increase
Solution Approach 1:
The distributed ledger maintains cryptographic hashes and essential verification data rather than complete copies of all provisioning information at each node. This copying approach provides full transparency and auditability through the distributed network while minimizing storage requirements by storing only the essential verification evidence needed to prove authenticity, rather than redundant full copies of all device data
Data Source
AI summary
An apparatus comprises a processing device configured to obtain, at a given one of a plurality of computing sites in a supply chain associated with a given computing device, one or more component verification data records associated with the given computing device. The component verification data records are obtained from a distributed ledger maintained by the plurality of computing sites in the supply chain. The component verification data records characterize provisioning actions performed on the given computing device by computing sites in the supply chain. The processing device is also configured to generate component verification data characterizing a current configuration of hardware and software components of the given computing device. The processing device is further configured to determine an authenticity of the given computing device based on validating the generated component verification data for the given computing device utilizing the component verification data records obtained from the distributed ledger.


