Dynamic Computing Environment Measurement Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attestation mechanisms struggle to reliably verify the integrity of computing environments due to changes in software versions or orders of operations, which can render reference measurements obsolete.
Innovation Solution
A method and system for dynamically deriving and verifying a measurement of a computing environment, involving the receipt of a dataset from an untrusted source and attestation evidence from a trusted source, followed by derivation of a measurement value and comparison with the initial measurement value to determine trustworthiness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If reference measurements are kept fixed in the verifier to ensure security and integrity verification, then verification reliability is improved, but the system cannot adapt when software versions or computing environment changes occur
Solution Approach 1:
The patent applies dynamics by making the reference measurement adaptable rather than fixed. The system dynamically generates reference measurements based on the actual computing environment configuration (software versions, hardware details, etc.) at the time of verification. This allows the verifier to maintain reliability by using accurate reference points while adapting to environmental changes through dynamic regeneration of these references.
Solution Approach 2:
The system changes the parameter of reference measurement from static to dynamic. When the computing environment changes (software updates, configuration modifications), the reference measurement is regenerated to reflect the new state. This parameter change enables the system to maintain verification reliability while adapting to evolving environments.
2Reliability
If the verifier uses static reference measurements to verify attestation evidence, then security and integrity are maintained, but verification fails when software versions change
Solution Approach 1:
The reference measurement transitions from static to dynamic, being regenerated based on current environment state. This ensures that the reference measurement remains precise and accurate even when software versions or configurations change, while still maintaining the integrity verification function through cryptographic comparison.
Solution Approach 2:
The system performs preliminary generation of reference measurements based on expected environment configurations. By pre-computing what the measurement should be given specific software versions and configurations, the system can quickly verify attestation evidence without requiring real-time complex analysis, thus maintaining both accuracy and efficiency.
3Adaptability or versatility
If dynamic derivation of measurement values is implemented to handle environment changes, then adaptability is improved, but system complexity increases
Solution Approach 1:
The system applies self-service by having the verifier automatically generate reference measurements based on environment descriptors without requiring manual intervention or complex external validation processes. The attester and verifier independently derive the same measurement values from shared environment information, eliminating the need for manual reference measurement updates and reducing operational complexity.
Solution Approach 2:
The measurement derivation mechanism serves multiple functions: it generates reference measurements for verification, validates environment configurations, and provides adaptability to changes. This multi-functional approach consolidates what could be separate complex systems into a unified measurement derivation process, reducing overall system complexity while maintaining adaptability.
Data Source
AI summary
A method and a system for dynamically deriving and verifying a measure of a computing environment is presented. The proposed method and system are used to reliably verify measurements of the computing environment. The method includes receiving a dataset recorded by an untrusted source describing elements used to create a computing system operating in a computing environment, receiving attestation evidence generated by a trusted source including an initial measurement value describing the elements of the computing system, deriving a measurement value based on the received dataset, and performing a verification process on a measurement of the computing environment. The verification process is performed by comparing the derived measurement value with the measurement value of the attestation evidence. In response to the comparison of the derived measurement value with the measure value of the attestation evidence being equal, trustworthiness of the computing environment is determined.


