Distributed Cryptographic Domain Trust Update via Quorum Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed systems, ensuring the secure update and integrity of cryptographic material across multiple nodes is challenging due to increased complexity, intermittent connections, and the time required for propagation of updates, which can lead to security breaches and data integrity issues.

Innovation Solution

A distributed system architecture that utilizes domain tokens and domain trusts, where each node verifies digital signatures and adheres to quorum rules for updating cryptographic domains, ensuring secure cryptographic operations and maintaining data integrity through sequential verification of domain trust versions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic material is shared across a fleet of devices to enhance data security, then security is improved, but the complexity of maintaining the cryptographic material secure increases

Engineering Contradiction:
Improvedata securityVSAvoidcomplexity of maintaining cryptographic material
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the cryptographic domain into distinct versions (current domain trust and candidate domain trust) that can be maintained separately. This allows the system to manage cryptographic material updates by working with discrete, manageable segments rather than a monolithic cryptographic infrastructure, reducing the complexity of maintaining security across the fleet.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a quorum-based intermediary mechanism that mediates between nodes with different cryptographic versions. This quorum system acts as a mediator to coordinate updates and verify integrity without requiring all nodes to simultaneously manage the full complexity of cryptographic material, thereby maintaining security while reducing individual node complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If updates are propagated quickly across all nodes to maintain consistency, then system consistency is improved, but the risk of security breaches increases due to intermittent connections and propagation delays

Engineering Contradiction:
Improvesystem consistencyVSAvoidsecurity integrity
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The system performs preliminary verification of candidate domain trusts against current domain trust before applying updates. This preliminary action of verifying digital signatures and quorum rules ensures that only authenticated and validated updates are propagated, maintaining security integrity even when propagation timing varies across intermittent connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where nodes report their cryptographic domain version status, and the system uses this feedback to determine when updates can be safely propagated. This feedback loop allows the system to maintain consistency by coordinating propagation timing with actual node readiness, reducing security risks associated with premature or unverified updates.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple domain trust versions are maintained to ensure update integrity, then security verification is improved, but the complexity of verifying and managing these versions increases

Engineering Contradiction:
Improveupdate integrityVSAvoidcomplexity of verifying domain trust versions
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the verification process into distinct phases: verifying the current domain trust, verifying the candidate domain trust against the current one, and only then transitioning. This segmentation of verification into manageable steps reduces the complexity of managing multiple versions by handling them sequentially rather than simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses parameter changes in the form of version numbers and quorum thresholds to simplify the management of multiple domain trust versions. By representing trust states through discrete parameters (version identifiers, quorum counts) rather than complex structural comparisons, the system reduces the complexity of verifying and transitioning between versions while maintaining integrity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10721075B2Web of trust management in a distributed system
Publication Date: 2020.07.21 AMAZON TECH INC
  • US10721075B2 patent drawing
  • US10721075B2 patent drawing
  • US10721075B2 patent drawing

AI summary

A new version of a structured collection of information, different from a previous version, of a cryptographic domain is created. The new version is created to be verifiable as a valid successor to the previous version and to specify a new set of quorum rules, with the new set of quorum rules defining one or more conditions to be fulfilled by a plurality of operators as conditions precedent to update the structured collection. The new version is provided to the plurality of operators. Digital signatures corresponding to the new version are obtained, and, as a result of the digital signatures received fulfilling the one or more conditions defined by a previous set of quorum rules specified by the previous version, the new version is caused to replace the previous version.