Blockchains for securing IoT devices

US12132609B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12132609-B2
Application numberUS-202217702463-A
CountryUS
Kind codeB2
Filing dateMar 23, 2022
Priority dateDec 30, 2016
Publication dateOct 29, 2024
Grant dateOct 29, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A trusted communications environment includes a primary participant with a group creator and a distributed ledger, and a secondary participant with communication credentials. An Internet of Things (IoT) network includes a trusted execution environment with a chain history for a blockchain, a root-of-trust for chaining, and a root-of-trust for archives. An IoT network includes an IoT device with a communication system, an onboarding tool, a device discoverer, a trust builder, a shared domain creator, and a shared resource directory. An IoT network includes an IoT device with a communication system, a policy decision engine, a policy repository, a policy enforcement engine, and a peer monitor. An IoT network includes an IoT device with a host environment and a trusted reliability engine to apply a failover action if the host environment fails. An IoT network includes an IoT server including secure booter/measurer, trust anchor, authenticator, key manager, and key generator.

First claim

Opening claim text (preview).

What is claimed is: 1. An apparatus comprising: at least one memory; instructions in the apparatus; and processor circuitry to execute the instructions to at least: detect a failure of a host environment of a first device based on a satisfaction of a time threshold by a time period since an attested watchdog message was stored on a blockchain, the attested watchdog message to be associated with the host environment; and after an identification on the blockchain of a failover device associated with the first device, cause activation of the failover device. 2. The apparatus of claim 1 , wherein the host environment is to output heartbeat data to a trusted execution environment associated with the host environment, and the processor circuitry is to determine that the trusted execution environment generated the attested watchdog message based on a signage of the heartbeat data with an attestation key. 3. The apparatus of claim 2 , wherein the trusted execution environment is an Intel Software Guard Extensions enclave, an ARM TrustZone, hardware security security, or a hardware security module. 4. The apparatus of claim 1 , wherein the processor circuitry is to determine that the failover device is within a geographically proximate distance of the first device. 5. The apparatus of claim 1 , wherein the processor circuitry is to store a blockchain transaction on the blockchain, the blockchain transaction to include data that is representative of a priority claim by the failover device for failover target rights associated with the failure of the host environment. 6. The apparatus of claim 1 , wherein the processor circuitry is to: after a determination that the host environment is recoverable by the first device, install a host replacement image in the host environment; and restart the host environment with the host replacement image to recover operation of the first device. 7. The apparatus of claim 1 , wherein the processor circuitry is to, after a determination that the first device is repairable, dispatching a repair drone to repair the first device. 8. The apparatus of claim 1 , wherein the processor circuitry is to, after a determination that the first device is replaceable: identify a robot drone, based on the blockchain, as being associated with replacement of the first device with the failover device; and cause dispatch of the robot drone to replace the first device with the failover device. 9. The apparatus of claim 1 , wherein the attested watchdog message is a first attested watchdog message, and the processor circuitry is to: store a second attested watchdog message from the host environment on the blockchain in a blockchain transaction; and detect that the host environment is in operation based on the second attested watchdog message. 10. The apparatus of claim 1 , wherein the processor circuitry is to detect the failure of the host environment based on the satisfaction of the time threshold by the time period since communication over a bus of the host environment is detected. 11. The apparatus of claim 1 , wherein the processor circuitry is first processor circuitry, and the first processor circuitry is to detect the failure of the host environment based on a determination that second processor circuitry of the first device is halted. 12. The apparatus of claim 1 , wherein the at least one memory is at least one first memory, and the processor circuitry is to detect the failure of the host environment based on a determination that at least one second memory of the first device failed. 13. The apparatus of claim 1 , further including interface circuitry to obtain the attested watchdog message from the first device, the host environment to generate the attested watchdog message to report on at least one of health or operation of the host environment. 14. The apparatus of claim 1 , wherein the blockchain includes one or more watchdog message blocks, one or more peer device blocks, or one or more identity blocks, and the processor circuitry is to cause the attested watchdog message to be committed to the blockchain in the one or more watchdog message blocks. 15. At least one storage disc or storage device comprising instructions that, when executed, cause at least one processor to at least: detect a failure of a host environment of a first device based on a satisfaction of a time threshold by a time period since a trusted watchdog message was committed on a blockchain, the trusted watchdog message to be associated with the host environment; and after an identification on the blockchain of a failover device associated with the first device, cause transmission of a message to activate the failover device. 16. The at least one storage disc or storage device of claim 15 , wherein the instructions are to cause the at least one processor to determine that the failover device is within a geographical threshold distance of the first device. 17. The at least one storage disc or storage device of claim 15 , wherein the instructions are to cause the at least one processor to commit a blockchain transaction on the blockchain, the blockchain transaction to include data that is representative of a primary claim by the failover device for failover target rights associated with the failure of the host environment. 18. The at least one storage disc or storage device of claim 15 , wherein the instructions are to cause the at least one processor to: after a determination that the host environment is recoverable by the first device, cause installation of a host replacement image in the host environment; and cause restart of the host environment with the host replacement image to recover operation of the first device. 19. The at least one storage disc or storage device of claim 15 , wherein the instructions are to cause the at least one processor to, after a determination that the first device is repairable, cause transmission of the message to a repair drone to repair the first device. 20. A method comprising: identifying a failure of a host environment of a first device based on a satisfaction of a time threshold by a timeout timer since an attested watchdog message was stored on a blockchain, the attested watchdog message to be associated with the host environment; and after an identification on the blockchain of a failover device associated with the first device, cause execution of a function of the host environment by the failover device. 21. The method of claim 20 , further including, after a determination that the first device is repairable, instructing a repair drone to repair the first device. 22. The method of claim 20 , further including, after a determination that the first device is replaceable: determining, based on the blockchain, that a drone is associated with replacement of the first device with the failover device; and dispatching the drone to replace the first device with the failover device. 23. The method of claim 20 , wherein the attested watchdog message is a first attested watchdog message, and the method further including: storing a second attested watchdog message from the host environment on the blockchain in a blockchain transaction; and detecting that the host environment is in operation based on the second attested watchdog message. 24. The method of claim 20 , further including detecting the failure of the host environment based on the satisfaction of the time threshold by the timeout timer since

Assignees

Inventors

Classifications

  • Discovery or management of network topologies · CPC title

  • for initial configuration or provisioning, e.g. plug-and-play · CPC title

  • H04W4/70Primary

    Services for machine-to-machine communication [M2M] or machine type communication [MTC] · CPC title

  • using hash chains, e.g. blockchains or hash trees · CPC title

  • Brokering proxy services · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12132609B2 cover?
A trusted communications environment includes a primary participant with a group creator and a distributed ledger, and a secondary participant with communication credentials. An Internet of Things (IoT) network includes a trusted execution environment with a chain history for a blockchain, a root-of-trust for chaining, and a root-of-trust for archives. An IoT network includes an IoT device with…
Who is the assignee on this patent?
Intel Corp
What technology area does this patent fall under?
Primary CPC classification H04L41/0806. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 29 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).