Attestation Service for Computing Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional techniques for attesting to properties of computing resources, such as licensing and configuration, are cumbersome and inconvenient, especially in complex environments like Infrastructure as a Service (IaaS), where managing multiple devices and virtual resources is challenging.

Innovation Solution

A system generates and cryptographically signs documents that encode properties of computing resources, making them human-readable and machine-readable, allowing for secure attestation and verification of these properties across the network, enabling actions like updates and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional manual registration techniques are used for attesting to computing resource properties, then the attestation process can be performed, but the process becomes cumbersome and inconvenient

Engineering Contradiction:
Improveease of attestationVSAvoidtime for attestation process
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating and storing attestation documents for computing resources before they are needed. The attestation service proactively creates these documents and makes them available in advance, so when verification is needed, the process is immediate rather than requiring manual registration at the moment of need.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attestation service enables self-service by automatically generating, storing, and managing attestation documents without requiring manual intervention. The system serves itself by autonomously creating the necessary verification documents and making them accessible to authorized entities, eliminating the need for manual registration and documentation processes.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If traditional manual registration techniques are used for attesting to computing resource properties, then the attestation can be completed, but the process is cumbersome especially in multi-device environments

Engineering Contradiction:
Improveadaptability to multi-device environmentsVSAvoidcomplexity of managing multiple devices
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The attestation service provides a universal solution that works across all computing resources in the environment, whether physical or virtual devices. A single service instance can manage attestation for multiple diverse devices through a common interface and document format, making the system adaptable to multi-device environments without increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The attestation service acts as an intermediary between computing resources and entities that need to verify their properties. This mediator automatically handles the complex tasks of document generation, storage, and retrieval, shielding users from the complexity of managing multiple devices while providing versatile attestation capabilities across the entire environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If automated document generation and cryptographic signing is implemented, then secure and efficient attestation is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity of attestationVSAvoidcomplexity of attestation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The attestation service serves as a specialized intermediary that handles the complex cryptographic operations and document management tasks. By concentrating these security-critical functions in a dedicated service, the system achieves high reliability through automated cryptographic signing and verification, while the complexity is contained within the service rather than distributed across all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses cryptographic copying by generating digital signatures that are copies of the attested information in verified form. The attestation document contains a cryptographic copy of the computing resource properties that can be verified without exposing the original sensitive data, maintaining security while enabling efficient verification across the system.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10216921B1Techniques for attesting to information
Publication Date: 2019.02.26 AMAZON TECH INC
  • US10216921B1 patent drawing
  • US10216921B1 patent drawing
  • US10216921B1 patent drawing

AI summary

Systems and methods for attesting to information about a computing resource involve electronically signed documents. For a computing resource, a document containing information about the resource is generated and electronically signed. The document may be provided to one or more entities as an attestation to at least some of the information contained in the document. Attestation to information in the document may be a prerequisite for performance of one or more actions that may be taken in connection with the computing resource.