Distributed Ledger Security Attestation for Container Images

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing centralized certificate authority systems for remote device security are vulnerable to fake certificates and compromised systems, relying on a single third-party authority, which creates significant security risks, especially in dynamic network environments where user equipment must connect to various and unknown network access points.

Innovation Solution

Implementing a distributed security attestation system using a distributed ledger (such as a blockchain) where devices capture and analyze their own container stack images, hash them, and share the hashes for validation before connecting, thereby establishing trust without relying on a single central authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized certificate authorities are used to verify device identity, then device identity verification is simplified, but security vulnerabilities increase due to single points of failure and potential compromise

Engineering Contradiction:
Improvedevice identity verificationVSAvoidsecurity trust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized certificate authority function into distributed validator nodes across the network. Instead of relying on a single CA, multiple independent validators collectively perform identity verification and security attestation, eliminating the single point of failure while maintaining verification capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a distributed ledger as an intermediary layer between devices seeking to establish trust. The ledger records and verifies security attestations from multiple sources, mediating the trust relationship without requiring direct reliance on a single centralized authority

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distributed security attestation is implemented, then centralized security risks are mitigated, but system complexity increases due to multiple validation entities

Engineering Contradiction:
Improvesecurity trustVSAvoidvalidation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security attestation protocol that can be applied across diverse devices and network configurations. The distributed ledger and validation mechanism serve multiple functions including identity verification, compromise detection, and trust establishment, reducing the need for device-specific complex validation systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the fundamental parameters of security verification from centralized certificate-based authentication to distributed behavioral and structural analysis. By monitoring system behavior, file integrity, and process characteristics, the system achieves reliable security attestation through different measurement parameters rather than complex hierarchical validation

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If devices connect to dynamic network access points, then network coverage and accessibility improve, but security risks increase due to unknown or potentially compromised access points

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary security attestation and compromise detection before devices establish connections to network access points. Validators analyze the target device's security state in advance, recording attestation data on the distributed ledger so that connecting devices can verify security status before establishing trust, enabling safe connections to dynamic unknown access points

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11954075B2Systems and methods for remote device security attestation and manipulation detection
Publication Date: 2024.04.09 T MOBILE US INC
  • US11954075B2 patent drawing
  • US11954075B2 patent drawing
  • US11954075B2 patent drawing

AI summary

A system including: a transceiver; a boot processor configured to: capture an image of a container of the system, determine whether the system container image has been modified, and post, to a node of a distributed ledger network, a first attestation based on a determination of whether an anomaly exists in the system container image; a system processor; and a memory storing instructions that instruct the system processor to: receive a request to connect to an external device, request a second attestation from a node of the distributed ledger network as to whether an anomaly exists in the external device container image, determine whether an anomaly exists in the external device container image, and either: establish, in response to determining that an anomaly does not exist, a connection with the external device, or deny the request to connect to the external device in response to determining that an anomaly exists.