Composite Security Vectors for Heterogeneous TEE Trust Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies struggle to assess and maintain the trustworthiness of devices across a network, especially in heterogeneous systems where trustworthiness relationships multiple hops away are not effectively expressed.
Innovation Solution
The system generates a composite security information by combining security information from service nodes with different Trusted Execution Environments (TEEs), normalizing security claims, and creating a system-wide trustworthiness vector to establish and maintain trust across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If trustworthiness vectors are used to express verified trustworthiness from direct peers, then a mesh of trust can be established across network devices, but trustworthiness relationships multiple hops away cannot be effectively expressed
Solution Approach 1:
The patent implements nested trustworthiness vectors where vectors are embedded within routing protocol messages (OSPF, BGP, IS-IS) which are then embedded within network traffic flows. This nesting allows trust information to be carried through multiple routing hops while maintaining the original trust verification capability, effectively solving the multi-hop trust expression problem.
Solution Approach 2:
The patent uses routing protocol messages as intermediaries to carry trustworthiness vectors between network devices. These protocol messages act as mediators that transport trust information across multiple hops without requiring direct peer-to-peer verification, enabling indirect trust relationship expression while maintaining security.
2Reliability
If routing protocols are used to ensure IP packets take trustworthy paths, then network security is improved, but the problem of understanding trustworthiness across heterogeneous systems remains unsolved
Solution Approach 1:
The patent designs trustworthiness vectors with a universal structure that can be embedded in multiple different routing protocol messages (OSPF, BGP, IS-IS). This universal vector format allows the same trust verification mechanism to work across heterogeneous networking environments and different protocol stacks, solving the adaptability problem while maintaining reliable routing.
Solution Approach 2:
The patent modifies routing protocol messages by adding trustworthiness vector parameters without changing the fundamental protocol structures. This parameter addition approach allows trust verification to be layered onto existing heterogeneous protocols, enabling universal trust assessment across different system types while preserving original protocol functionality.
3Reliability
If active measurements are performed to validate device trustworthiness, then current trust status can be confirmed, but network overhead and measurement complexity increase
Solution Approach 1:
The patent performs trustworthiness measurements during device boot-up and configuration phases, storing the results in trustworthiness vectors before devices join the network. This preliminary measurement approach eliminates the need for continuous active measurements during network operation, reducing overhead while maintaining reliable trust validation through pre-collected evidence.
Solution Approach 2:
The patent uses cryptographic hashing to create compact copies of trust evidence (such as hardware identifiers, firmware hashes, and configuration certificates) and stores them in trustworthiness vectors. This copying mechanism allows comprehensive trust validation without transmitting or processing the full original measurement data, significantly reducing system complexity while maintaining measurement reliability.
Data Source
AI summary
Disclosed are systems, apparatuses, methods, and computer-readable media for providing security postures for a service provided by a heterogenous system. A method for verifying trust by a service node includes receiving a request for a security information of the service node from a client device, wherein the request includes information identifying a service to receive from the service node, identifying a related node to communicate with the service node based on the service, after identifying the related node, requesting a security information of the related node, generating a composite security information from the security information of the service node and the security information of the related node, and sending the composite security information to the client device. The composite security information provides security claims for a service implemented by a heterogenous devices that have different trusted execution environments.


