Decentralized Device Identity: PUF-Driven Soulbound Token Verification for IoT Supply Chain Security
Abstract
The rapid proliferation of Internet of Things (IoT) devices across various industries, including healthcare, smart cities, and industrial automation, has introduced significant security, authenticity, and traceability challenges within increasingly complex supply chains. Although existing approaches have utilised blockchain-based digital identity solutions to address some of these concerns, persistent issues of counterfeit products and inadequate lifecycle transparency highlight the need for more robust, hardware-anchored identification mechanisms. Our work presents a novel architecture that integrates Physically Unclonable Functions (PUFs) and blockchain-based Soulbound Tokens (SBTs) to establish secure and verifiable digital identities directly tied to the physical hardware of IoT devices. By employing cryptographic tools such as fuzzy extractors, Merkle trees, and zero-knowledge proofs, the proposed architecture ensures accurate lifecycle tracking through key operational stages, including manufacturing, procurement, provisioning, maintenance, and eventual disposal or recycling. Performance evaluations conducted on the Ethereum Sepolia testnet demonstrate reasonable computational overhead in terms of gas usage and transaction confirmation times. The findings reveal that this approach aligns with NIST Special Publication 800-161 guidelines, as well as emerging regulatory standards, notably the European Union’s Digital Product Passport initiative, and has significant implications for enhancing transparency, sustainability, and security across global IoT supply chains.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.