Attestation Manifest Derivation for Coordinated Software Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current MEC deployments face challenges in coordinating software updates across disparate systems, leading to invalidation of device characteristics and authentication tokens, resulting in stale attestation statuses and inefficient orchestration.
Innovation Solution
The use of a software update package that derives a Reference Integrity Measurement (RIM) to create a RIM manifest, which is broadcast for re-verifying authentication tokens and cryptographic identities, and regenerates attestation tokens to reflect device state changes, improving coordination and reducing stale attestation statuses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software updates are deployed across MEC systems, then device functionality and security are improved, but device characteristics and authentication tokens become invalid, requiring complex re-attestation processes
Solution Approach 1:
The patent generates an attestation manifest before the software update is applied. This manifest contains pre-calculated integrity measurements and attestation information that will be valid after the update. By performing the attestation preparation in advance, the system avoids the complexity of coordinating re-attestation after the update, as the manifest is already ready to be presented and verified post-update without requiring complex coordination between multiple systems.
2Reliability
If traditional attestation methods are used after software updates, then device security can be verified, but stale attestation statuses occur due to coordination delays between disparate systems
Solution Approach 1:
The attestation manifest is generated in advance, before the software update is applied to the device. This pre-generation ensures that the attestation information is current and accurate at the time of creation. When the update is applied and the manifest is later verified, there is no coordination delay or staleness issue because the manifest was created with the exact device state that will exist after the update, eliminating the time loss associated with post-update re-attestation coordination.
3Adaptability or versatility
If multiple systems coordinate software updates, then comprehensive device management is achieved, but authentication tokens and cryptographic identities become invalid, requiring complex re-synchronization
Solution Approach 1:
The patent extracts the attestation information into a separate, self-contained attestation manifest that is generated before the software update. This manifest contains all necessary integrity measurements and attestation data that would otherwise need to be re-synchronized across multiple systems after the update. By taking out the attestation information as a独立 artifact, the system avoids the complexity of re-synchronizing authentication tokens and cryptographic identities across multiple coordinated systems, as the manifest can be independently verified without requiring complex inter-system coordination.
Data Source
AI summary
Various systems and methods for enabling derivation and distribution of an attestation manifest for a software update image are described. In an example, these systems and methods include orchestration functions and communications, providing functionality and components for a software update process which also provides verification and attestation among multiple devices and operators.


