Abstract: Some embodiments of the present invention provide a method of cryptographically identifying and authenticating embedded devices through interaction with a distributed ledger. The device begins with a manufacturer root key and a globally unique identifier. It registers by signing a registration transaction that includes its identifier using its private root key with a digital signature algorithm and sending the resultant transaction to the distributed ledger. The ledger generates a registration root key and responds by sending this second root key back to the device. The device then uses the manufacturer root key and the registration root key to generate a child key that it uses to sign its response to the challenge proving that it possesses both the manufacturer key and the registration key. Thereafter, the device can non-interactively identify and authenticate itself to the distributed ledger by signing transactions with the derivative key.