Distributed Attestation Services for Secure TEE Launch

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted execution environments face challenges in secure and reliable launching, particularly due to the need for private attestation services that are vulnerable to unavailability and security threats, leading to high costs and reduced hardware utilization.

Innovation Solution

A system and method that utilize multiple alternate cloud providers to host attestation services, with secret sharing to ensure security and availability, allowing trusted execution environments to be launched securely and reliably without relying solely on private clouds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private attestation services are used to ensure security, then security is improved, but reliability deteriorates due to unavailability and single point of failure

Engineering Contradiction:
Improveavailability of attestation serviceVSAvoidsecurity threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the attestation service into multiple independent instances hosted on different cloud providers. Each provider runs separate attestation service instances that can independently validate TEE applications, eliminating the single point of failure in private attestation services while maintaining security through distributed validation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces alternate cloud providers as intermediary services between the TEE application and the validation process. These intermediary providers host attestation services that mediate the verification process, providing both security through independent validation and reliability through service availability when private attestation services are unavailable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple cloud providers are used to distribute attestation services, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveservice availabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates attestation service instances that can universally operate across multiple cloud provider environments. The same attestation service architecture and validation logic are deployed on different providers, allowing a single standardized service design to fulfill multiple functions across diverse infrastructure while managing complexity through uniformity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secret sharing across multiple providers is implemented, then security is improved, but difficulty of operation increases

Engineering Contradiction:
ImprovesecurityVSAvoidservice coordination
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the secret into multiple shares and distributes them across different alternate cloud providers. Each provider holds a portion of the secret necessary for attestation, and the system coordinates these segmented secrets through standardized protocols, improving security through distribution while managing operational complexity through systematic secret sharing mechanisms.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11943337B2Secure reliable application environments
Publication Date: 2024.03.26 RED HAT LLC
  • US11943337B2 patent drawing
  • US11943337B2 patent drawing
  • US11943337B2 patent drawing

AI summary

A system includes an application instance or application environment instance and a first cloud service of a trusted cloud provider. The first cloud service is configured to receive an encrypted disk image and to launch the application instance or application environment instance. The system also includes a second cloud service of a first alternate cloud provider, which is configured to launch a first attestation service instance from an attestation disk image that includes a secret and to provide the secret to the application instance or application environment instance.