IP Library › Granted Patent US 11,917,088
Granted Patent B2
US 11,917,088 · App. 17/026,467 · Granted Feb 27, 2024

Integrating device identity into a permissioning framework of a blockchain

Inventors: Nitin Gaur (Round Rock, TX); Jeronimo Irazabal (Roque Perez, AR); Abhishek Malvankar (White Plains, NY)
Assignee: International Business Machines Corporation
H04L9/3278H04L9/0894H04L9/3218H04L41/12H04L67/56H04L9/50H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,917,088
App. No.
17/026,467
Granted
Feb 27, 2024
Kind
B2
Abstract

A computer-implemented method for configuring a blockchain network, a computer program product for integrating device identity into a permissioning framework of a blockchain network, and a blockchain network. One embodiment may comprise registering a device at a delineate node of a blockchain network, creating, by a processor of the delineate node based on the registering, a profile for the device; an performing, by the processor of the delineate node, a pass-through service for the device. The registering may include receiving, by a network interface, an immutable device identity from the device.

Claims (39)

1. A computer-implemented method for configuring a blockchain network, comprising:

initializing, by a delineate node of the blockchain network, pass-through services;

receiving, at the delineate node, a registration request from a device;

validating the device, by the delineate node in response to the registration request, using a physical uncloneable function (PUF) response received from the device, wherein the PUF automatically provides a cryptographic proof for immutable registration key previously measured or calculated by a manufacturer of the IoT device and previously communicated to the delineate node by a secure channel, and wherein the validating comprises:

sending, by the delineate node, a challenge to the device; and

receiving, by the delineate node, the PUF response from the device;

registering, by a processor of the delineate node in response to the validating, the device in a virtual profile; and

performing, by the processor of the delineate node, a pass-through service for the registered device.

2. The method of claim 1 , further comprising, by the delineate node, updating a transaction correlation table on behalf of the registered device, wherein the transaction correlation table contains a record of blockchain functions associated with the registered device.

3. The method of claim 2 , wherein the blockchain functions comprise maintaining an endorsement policy and a delegate authority proof for the blockchain network.

4. The method of claim 2 , further comprising:

receiving, at the delineate node, a membership services directive from a node in the blockchain network directed to the registered device; and

by the delineate node, in response to the membership services directive, updating the transaction correlation table for the registered device.

5. The method of claim 2 , further comprising:

receiving, at the delineate node, a membership services directive from the registered device directed to the blockchain network; and

by the delineate node, in response to the membership services directive, updating the transaction correlation table for the registered device.

6. The method of claim 1 , wherein the pass-through service comprises creating a channel for communication between peers on the blockchain network.

7. The method of claim 1 , wherein the pass-through service comprises facilitating a transaction on behalf of the registered device.

8. The method of claim 1 , wherein the pass-through service comprises communication between the delineate node on behalf of the registered device and other nodes in the blockchain network.

9. The method of claim 8 , wherein the pass-through service further comprises proxying, by the delineate node, all communication between the registered device and the other nodes in the blockchain network.

10. The method of claim 1 , wherein the registration further comprises registering the device with a membership service of the blockchain network.

11. The method of claim 10 , wherein the registration enables the device to be registered as a peer node on a private blockchain network.

12. The method of claim 1 , wherein the virtual profile includes an encryption key pair for the registered device, and wherein the encryption key pair is generated by the delineate node and stored in a secure vault associated with the delineate node.

13. The method of claim 12 , wherein the secure vault comprises a hardware security architecture.

14. The method of claim 1 , wherein the PUF comprises a physically-defined digital fingerprint associated with the device.

15. The method of claim 14 , and wherein the immutable registration key is used as an identity mechanism in the blockchain network.

16. The method of claim 1 , wherein the registered device is an Internet-of-Things (IoT) device and wherein the delineate node maintains a distributed ledger on behalf of the registered IoT device.

17. The method of claim 1 , wherein the delineate node comprises a specialized hardware co-processor for performing the pass-through service.

18. The method of claim 1 , further comprising generating, by the delineate node, a blockchain signing key for the device.

19. The method of claim 1 , further comprising storing the generated blockchain signing key in a secure vault associated with the delineate node.

20. A computer program product for integrating device identity into a permissioning framework of a blockchain network, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to:

provide, by a node, pass-through security services, wherein the pass-through security services include a trusted registration of peers in the blockchain network;

receive, at the node, a registration request from a device;

validate the device, by the node in response to the registration request, using a physical uncloneable function (PUF) response received from the device, wherein the PUF automatically provides a cryptographic proof for immutable registration key previously measured or calculated by a manufacturer of the IoT device and previously communicated to the delineate node by a secure channel, and wherein the validating comprises:

sending, by the node, a challenge to the device; and

receiving, by the node, the PUF response from the device;

register, by the node in response to the validation, the device as a registered node on the blockchain network, wherein the registering includes creating, by the node based on the registering, a virtual profile for the registered device in a secure enclave;

maintain, by the node, a transaction correlation table for the registered device, wherein the transaction correlation table contains a record of blockchain essentials associated with the registered device, wherein the blockchain essentials include channels, endorsement policies, and delegate authority proofs; and

carry out, by the node, transaction commitment and client communication on behalf of the registered device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2020
From: GAUR, NITIN; IRAZABAL, JERONIMO; MALVANKAR, ABHISHEK
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 053827/0713 →
Continuity (1)
Related Publication 20220094560A1 · Mar 24, 2022