Composite Security Vectors for Heterogeneous TEE Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies struggle to assess and maintain the trustworthiness of devices across a network, especially in heterogeneous systems where trustworthiness relationships multiple hops away are not effectively expressed.

Innovation Solution

The system generates a composite security information by combining security information from service nodes with different Trusted Execution Environments (TEEs), normalizing security claims, and creating a system-wide trustworthiness vector to establish and maintain trust across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If trustworthiness vectors are used to express verified trustworthiness from direct peers, then a mesh of trust can be established across network devices, but trustworthiness relationships multiple hops away cannot be effectively expressed

Engineering Contradiction:
Improvetrustworthiness verificationVSAvoidmulti-hop trust relationship expression
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements nested trustworthiness vectors where vectors are embedded within routing protocol messages (OSPF, BGP, IS-IS) which are then embedded within network traffic flows. This nesting allows trust information to be carried through multiple routing hops while maintaining the original trust verification capability, effectively solving the multi-hop trust expression problem.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent uses routing protocol messages as intermediaries to carry trustworthiness vectors between network devices. These protocol messages act as mediators that transport trust information across multiple hops without requiring direct peer-to-peer verification, enabling indirect trust relationship expression while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If routing protocols are used to ensure IP packets take trustworthy paths, then network security is improved, but the problem of understanding trustworthiness across heterogeneous systems remains unsolved

Engineering Contradiction:
Improvetrustworthy path routingVSAvoidheterogeneous system trust assessment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent designs trustworthiness vectors with a universal structure that can be embedded in multiple different routing protocol messages (OSPF, BGP, IS-IS). This universal vector format allows the same trust verification mechanism to work across heterogeneous networking environments and different protocol stacks, solving the adaptability problem while maintaining reliable routing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent modifies routing protocol messages by adding trustworthiness vector parameters without changing the fundamental protocol structures. This parameter addition approach allows trust verification to be layered onto existing heterogeneous protocols, enabling universal trust assessment across different system types while preserving original protocol functionality.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If active measurements are performed to validate device trustworthiness, then current trust status can be confirmed, but network overhead and measurement complexity increase

Engineering Contradiction:
Improveactive trust validationVSAvoidmeasurement system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs trustworthiness measurements during device boot-up and configuration phases, storing the results in trustworthiness vectors before devices join the network. This preliminary measurement approach eliminates the need for continuous active measurements during network operation, reducing overhead while maintaining reliable trust validation through pre-collected evidence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic hashing to create compact copies of trust evidence (such as hardware identifiers, firmware hashes, and configuration certificates) and stores them in trustworthiness vectors. This copying mechanism allows comprehensive trust validation without transmitting or processing the full original measurement data, significantly reducing system complexity while maintaining measurement reliability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12294614B2Verifying trust postures of heterogeneous confidential computing clusters
Publication Date: 2025.05.06 CISCO TECHNOLOGY INC
  • US12294614B2 patent drawing
  • US12294614B2 patent drawing
  • US12294614B2 patent drawing

AI summary

Disclosed are systems, apparatuses, methods, and computer-readable media for providing security postures for a service provided by a heterogenous system. A method for verifying trust by a service node includes receiving a request for a security information of the service node from a client device, wherein the request includes information identifying a service to receive from the service node, identifying a related node to communicate with the service node based on the service, after identifying the related node, requesting a security information of the related node, generating a composite security information from the security information of the service node and the security information of the related node, and sending the composite security information to the client device. The composite security information provides security claims for a service implemented by a heterogenous devices that have different trusted execution environments.