Attestation Token Sharing in Edge Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attestation techniques in edge computing and IoT networks face challenges in distributing and verifying attestation tokens across multiple service provider nodes, lacking the ability to generate tokens that represent attestation verification events, set time limits, and share attestation results with multiple orchestration entities, which affects security and trust establishment.

Innovation Solution

The introduction of attestation tokens managed through a single-sign-on (SSO) infrastructure, using OAuth2, SAML, or Kerberos to distribute attestation context/state, with tokens having expiration dates and being stored on public blockchains for verification, allowing flexible re-attestation and improved trust management across Edge/MEC, IoT, and cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional attestation techniques are used in edge computing and IoT networks, then attestation verification can be performed, but the system lacks the ability to efficiently distribute and share attestation tokens across multiple service provider nodes and orchestration entities

Engineering Contradiction:
Improvetrust establishmentVSAvoidtoken distribution capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The attestation system is segmented into multiple independent components: attestation tokens are divided into verifiable claims that can be independently validated, and the distribution system is segmented into multiple service provider nodes and orchestration entities that can independently verify and share tokens without requiring centralized coordination

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Blockchain technology serves as an intermediary layer that enables trustless verification of attestation tokens across multiple service providers and orchestration entities. The blockchain acts as a decentralized mediator that records and verifies token validity without requiring direct trust relationships between all participants

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If attestation tokens are distributed across multiple service provider nodes, then verification capability is improved, but the complexity of managing and coordinating tokens among multiple entities increases

Engineering Contradiction:
Improveattestation verificationVSAvoidtoken management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The attestation token is designed as a universal data structure that can be verified by any service provider node or orchestration entity using the same verification logic. The token contains all necessary claims and evidence in a standardized format that can be independently validated without requiring specialized coordination protocols between different entities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Each service provider node and orchestration entity is equipped with the capability to independently verify attestation tokens using the same verification logic. The system enables self-service verification where each entity can autonomously validate tokens without requiring manual coordination or complex inter-entity communication protocols

Inventive Principle:
Principle #25Self-service

3Measurement precision

If attestation tokens include detailed verification information, then trust verification accuracy is improved, but the size and processing overhead of tokens increases

Engineering Contradiction:
Improveverification accuracyVSAvoidtoken data size
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The attestation token extracts only the essential verification claims and evidence needed for trust verification, separating critical information from redundant data. The token contains structured claims about device identity, security state, and policy compliance that are sufficient for verification purposes without including unnecessary detailed information

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11425111B2Attestation token sharing in edge computing environments
Publication Date: 2022.08.23 INTEL CORP
  • US11425111B2 patent drawing
  • US11425111B2 patent drawing
  • US11425111B2 patent drawing

AI summary

Various approaches for implementing attestation using an attestation token are described. In an edge computing system deployment, an edge computing device includes an attestable feature (e.g., resource, service, entity, property, etc.) which is accessible from use of an attestation token, by the operations of: obtaining a first instance of a token that provides proof of attestation for an accessible feature of the edge computing device, with the token including data to indicate trust level designations for the feature as attested by an attestation provider; receiving, from a prospective user of the feature, a request to use the feature and a second instance of the token, with the second instance of the token originating from the attestation provider; and providing access to the feature based on a verification of the instances of the token, by using the verification to confirm attestation of the trust level designations for the feature.