Machine Network Identity via Distributed Ledger
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing machine data communication networks face challenges in maintaining reliable digital identities when replacing hardware components, as the private key stored in hardware security modules is lost during replacement, disrupting communication with communication partners.
Innovation Solution
Implementing a separate identification device that stores the public key via an intelligent contract using distributed ledger technology, allowing for secure key management and communication partner verification, even after hardware component replacement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the private key is stored in the hardware security module of the hardware component, then the digital identity can be verified securely, but the digital identity is lost when the hardware component is replaced
Solution Approach 1:
The system segments the digital identity management into two parts: the private key remains securely stored in the hardware security module of the hardware component, while the public key is separated and stored in the distributed ledger technology. This segmentation allows the hardware component to be replaced without losing the digital identity, as the public key persists in the decentralized ledger.
Solution Approach 2:
The distributed ledger technology acts as an intermediary between the hardware component and the communication partner. Instead of storing the public key locally in the hardware component, the system uses the decentralized ledger as a mediator to store and manage public keys, enabling seamless hardware replacement while maintaining identity verification.
2Ease of operation
If the public key is stored locally in the hardware component, then communication partner verification is simplified, but the digital identity cannot be retained after hardware replacement
Solution Approach 1:
The system creates a copy of the public key and stores it in the distributed ledger technology. The hardware component uses its local public key for verification, while the redundant copy in the decentralized ledger ensures the digital identity persists even when the hardware component is replaced or lost.
3Device complexity
If a centralized system manages digital identities, then key management is straightforward, but the system becomes vulnerable to single points of failure and security risks
Solution Approach 1:
The centralized key management system is segmented into a distributed architecture using blockchain technology. Public keys are distributed across multiple nodes in the ledger, eliminating the single point of failure while maintaining straightforward verification processes through cryptographic algorithms.
Data Source
AI summary
A method for the initial setup of a machine data communication network including a network unit provided with a first hardware component having a digital identity. For the digital identity, a signature of the network unit is generated based on a first private key for a communication partner in the machine data communication network. The first private key is stored in a first hardware security module of the first hardware component, and a first public key corresponding to the first private key and the signature is disclosed to the communication partner in order to verify the identity of the network unit. A separate identification device is arranged in the network unit, and the first public key is transferred from the first hardware security module to the identification device. The first public key of the identification device is saved in the identification device by an intelligent contract and is transmitted by distributed ledger technology to the communication partner.

