Heterogeneous TEE Trust Posture Verification Across Indirect Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to establish trustworthiness across heterogeneous systems in computer networks, particularly in scenarios where trustworthiness relationships extend beyond direct connections, and there is no method to verify the trustworthiness of indirectly connected Trusted Execution Environments (TEE) in a heterogeneous system.

Innovation Solution

A system and method for generating a composite trustworthiness vector by combining security information from related service nodes with different TEEs, using a hub-and-spoke topology to normalize and standardize trustworthiness claims, allowing devices to assess the trustworthiness of indirectly connected TEEs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If trustworthiness verification is limited to direct connections only, then verification simplicity is maintained, but system-wide trustworthiness assessment capability is lost

Engineering Contradiction:
Improveverification simplicityVSAvoidsystem-wide trustworthiness assessment capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent extends trustworthiness verification from direct connections (single hop) to indirect connections (multiple hops) by adding a dimensional aspect to the verification process. The trustworthiness vector is propagated through routing protocols across multiple network hops, enabling assessment of devices that are not directly connected, thus resolving the contradiction between verification simplicity and system-wide assessment capability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If trustworthiness vectors are propagated across multiple hops using routing protocols, then system-wide trustworthiness assessment is achieved, but verification complexity increases

Engineering Contradiction:
Improvesystem-wide trustworthiness assessmentVSAvoidverification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces routing protocols as intermediaries that automatically handle the propagation and verification of trustworthiness vectors across multiple network hops. Instead of requiring direct peer-to-peer verification between all devices, the routing protocol infrastructure mediates the trustworthiness assessment, reducing verification complexity while maintaining system-wide coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trustworthiness vector mechanism is designed to work universally with existing routing protocols and network infrastructure, allowing the same verification framework to operate across diverse network topologies and device types. This multi-functionality enables system-wide assessment without requiring device-specific customization, thereby controlling verification complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If heterogeneous TEE implementations are supported, then system compatibility is improved, but trustworthiness verification difficulty increases

Engineering Contradiction:
Improvesystem compatibilityVSAvoidtrustworthiness verification difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates a unified trustworthiness vector format that standardizes security claims across heterogeneous Trusted Execution Environment (TEE) implementations. By normalizing different TEE-specific security measurements into a common vector structure, the system achieves homogeneous verification processes despite hardware diversity, thereby reducing verification difficulty while maintaining broad compatibility

Inventive Principle:
Principle #33Homogeneity

Data Source

PatentUS20250220051A1Verifying trust postures of heterogeneous confidential computing clusters
Publication Date: 2025.07.03 CISCO TECHNOLOGY INC
  • US20250220051A1 patent drawing
  • US20250220051A1 patent drawing
  • US20250220051A1 patent drawing

AI summary

Disclosed are systems, apparatuses, methods, and computer-readable media for providing security postures for a service provided by a heterogenous system. A method for verifying trust by a service node includes receiving a request for a security information of the service node from a client device, wherein the request includes information identifying a service to receive from the service node, identifying a related node to communicate with the service node based on the service, after identifying the related node, requesting a security information of the related node, generating a composite security information from the security information of the service node and the security information of the related node, and sending the composite security information to the client device. The composite security information provides security claims for a service implemented by a heterogenous devices that have different trusted execution environments.