Cryptographic Control Plane for Anonymous Software Trust Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in establishing and revoking trust with anonymous software artifacts or devices while preserving their anonymity, particularly in control planes where unique identities are typically required for trust establishment.

Innovation Solution

The use of cryptographically verifiable anonymized tokens allows control planes to establish and revoke trust with software artifacts or devices without requiring their unique identities, using methods like onion routing to maintain anonymity and employing anonymous token sets for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique identities are required for trust establishment in control planes, then trust management reliability is improved, but anonymity of software artifacts or devices is lost

Engineering Contradiction:
Improvetrust management reliabilityVSAvoidanonymity of software artifacts or devices
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces anonymous tokens as intermediary credentials that mediate between the control plane and software artifacts/devices. These tokens serve as trust carriers without revealing the actual identities of the software artifacts or devices, thus resolving the contradiction between reliable trust management and preserving anonymity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trust establishment mechanism is segmented into separate components: anonymous token issuance by the control plane, token validation by the software artifact/device, and identity preservation. This segmentation allows trust to be managed through tokens rather than direct identity linkage, maintaining both reliability and anonymity.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If anonymous tokens are used for trust establishment, then anonymity of software artifacts or devices is preserved, but trust revocation capability is weakened

Engineering Contradiction:
Improveanonymity of software artifacts or devicesVSAvoidtrust revocation capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The control plane maintains feedback mechanisms to monitor and manage anonymous token usage. When compromise or misuse is detected, the control plane can issue revocation notifications that propagate through the system, allowing trust revocation while preserving the anonymity of legitimate users through the same token infrastructure.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If traditional identity-based trust systems are used, then trust establishment is straightforward, but privacy and security are compromised

Engineering Contradiction:
Improvetrust establishment simplicityVSAvoidprivacy and security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Instead of using actual identities for trust establishment, the system creates and uses copies in the form of anonymous tokens. These tokens replicate the essential trust-functionality without containing sensitive identity information, thereby simplifying trust operations while eliminating privacy and security risks associated with direct identity exposure.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250247224A1System and methods for a control plane to cryptographically revoke the trust of anonymous software artifacts or devices
Publication Date: 2025.07.31 DELL PROD LP
  • US20250247224A1 patent drawing
  • US20250247224A1 patent drawing
  • US20250247224A1 patent drawing

AI summary

Systems and methods for a control plane to cryptographically trust and revoke the trust of anonymous software artifacts or devices are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor; and a memory coupled to the processor, where the memory includes program instructions stored thereon that, upon execution by the processor, cause a control plane of the IHS to: establish a trust relationship with a requesting entity based, at least in part, on a received anonymous token of a distributed anonymous token set package; receive a second request from the requesting entity; and subsequent to the second request, determine to revoke the trust relationship with the requesting entity.