Attestation Token Sharing in Edge Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attestation techniques in edge computing and IoT networks face challenges in distributing and verifying attestation tokens across multiple service provider nodes, lacking the ability to generate tokens that represent attestation verification events, set time limits, and share attestation results with multiple orchestration entities, which affects security and trust establishment.
Innovation Solution
The introduction of attestation tokens managed through a single-sign-on (SSO) infrastructure, using OAuth2, SAML, or Kerberos to distribute attestation context/state, with tokens having expiration dates and being stored on public blockchains for verification, allowing flexible re-attestation and improved trust management across Edge/MEC, IoT, and cloud environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional attestation techniques are used in edge computing and IoT networks, then attestation verification can be performed, but the system lacks the ability to efficiently distribute and share attestation tokens across multiple service provider nodes and orchestration entities
Solution Approach 1:
The attestation system is segmented into multiple independent components: attestation tokens are divided into verifiable claims that can be independently validated, and the distribution system is segmented into multiple service provider nodes and orchestration entities that can independently verify and share tokens without requiring centralized coordination
Solution Approach 2:
Blockchain technology serves as an intermediary layer that enables trustless verification of attestation tokens across multiple service providers and orchestration entities. The blockchain acts as a decentralized mediator that records and verifies token validity without requiring direct trust relationships between all participants
2Reliability
If attestation tokens are distributed across multiple service provider nodes, then verification capability is improved, but the complexity of managing and coordinating tokens among multiple entities increases
Solution Approach 1:
The attestation token is designed as a universal data structure that can be verified by any service provider node or orchestration entity using the same verification logic. The token contains all necessary claims and evidence in a standardized format that can be independently validated without requiring specialized coordination protocols between different entities
Solution Approach 2:
Each service provider node and orchestration entity is equipped with the capability to independently verify attestation tokens using the same verification logic. The system enables self-service verification where each entity can autonomously validate tokens without requiring manual coordination or complex inter-entity communication protocols
3Measurement precision
If attestation tokens include detailed verification information, then trust verification accuracy is improved, but the size and processing overhead of tokens increases
Solution Approach 1:
The attestation token extracts only the essential verification claims and evidence needed for trust verification, separating critical information from redundant data. The token contains structured claims about device identity, security state, and policy compliance that are sufficient for verification purposes without including unnecessary detailed information
Data Source
AI summary
Various approaches for implementing attestation using an attestation token are described. In an edge computing system deployment, an edge computing device includes an attestable feature (e.g., resource, service, entity, property, etc.) which is accessible from use of an attestation token, by the operations of: obtaining a first instance of a token that provides proof of attestation for an accessible feature of the edge computing device, with the token including data to indicate trust level designations for the feature as attested by an attestation provider; receiving, from a prospective user of the feature, a request to use the feature and a second instance of the token, with the second instance of the token originating from the attestation provider; and providing access to the feature based on a verification of the instances of the token, by using the verification to confirm attestation of the trust level designations for the feature.


