Machine Network Identity via Distributed Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing machine data communication networks face challenges in maintaining reliable digital identities when replacing hardware components, as the private key stored in hardware security modules is lost during replacement, disrupting communication with communication partners.

Innovation Solution

Implementing a separate identification device that stores the public key via an intelligent contract using distributed ledger technology, allowing for secure key management and communication partner verification, even after hardware component replacement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the private key is stored in the hardware security module of the hardware component, then the digital identity can be verified securely, but the digital identity is lost when the hardware component is replaced

Engineering Contradiction:
Improvesecurity of digital identity verificationVSAvoidreplaceability of hardware component
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the digital identity management into two parts: the private key remains securely stored in the hardware security module of the hardware component, while the public key is separated and stored in the distributed ledger technology. This segmentation allows the hardware component to be replaced without losing the digital identity, as the public key persists in the decentralized ledger.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The distributed ledger technology acts as an intermediary between the hardware component and the communication partner. Instead of storing the public key locally in the hardware component, the system uses the decentralized ledger as a mediator to store and manage public keys, enabling seamless hardware replacement while maintaining identity verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the public key is stored locally in the hardware component, then communication partner verification is simplified, but the digital identity cannot be retained after hardware replacement

Engineering Contradiction:
Improvesimplicity of communication partner verificationVSAvoidloss of digital identity
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system creates a copy of the public key and stores it in the distributed ledger technology. The hardware component uses its local public key for verification, while the redundant copy in the decentralized ledger ensures the digital identity persists even when the hardware component is replaced or lost.

Inventive Principle:
Principle #26Copying

3Device complexity

If a centralized system manages digital identities, then key management is straightforward, but the system becomes vulnerable to single points of failure and security risks

Engineering Contradiction:
Improvesimplicity of key management systemVSAvoidsystem security and availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The centralized key management system is segmented into a distributed architecture using blockchain technology. Public keys are distributed across multiple nodes in the ledger, eliminating the single point of failure while maintaining straightforward verification processes through cryptographic algorithms.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12047495B2Method for the initial setup and of a machine data communication network, method for replacing a hardware component
Publication Date: 2024.07.23 MERCEDES BENZ GROUP AG
  • US12047495B2 patent drawing
  • US12047495B2 patent drawing

AI summary

A method for the initial setup of a machine data communication network including a network unit provided with a first hardware component having a digital identity. For the digital identity, a signature of the network unit is generated based on a first private key for a communication partner in the machine data communication network. The first private key is stored in a first hardware security module of the first hardware component, and a first public key corresponding to the first private key and the signature is disclosed to the communication partner in order to verify the identity of the network unit. A separate identification device is arranged in the network unit, and the first public key is transferred from the first hardware security module to the identification device. The first public key of the identification device is saved in the identification device by an intelligent contract and is transmitted by distributed ledger technology to the communication partner.