Intermediary Attestation Service for Distributed Confidential Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attestation mechanisms in networked computing environments, particularly in edge and edge-cloud settings, face scalability issues due to the need to verify numerous instances of distributed software services, which broadens the attack surface and requires intimate knowledge of the architecture, making them unmanageable and inefficient.

Innovation Solution

A Trust-as-a-Service (TaaS) framework using confidential computing technologies provides an independent trust authority to verify the integrity of computing assets and entities through attestation, issuing digital trust certifications based on remote attestation operations, policy validation, and reputation data, applicable to various Trusted Execution Environments (TEEs) and platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If relying party initiates attestation for each service instance in distributed software deployment, then trust verification completeness is improved, but system complexity and management overhead increase significantly

Engineering Contradiction:
Improvetrust verification completenessVSAvoidattestation management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary attestation service that acts as a mediator between service instances and relying parties. This service receives attestation requests, coordinates the verification process across multiple service instances, and consolidates results, thereby reducing the direct complexity burden on relying parties while maintaining comprehensive trust verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The attestation process is segmented into distinct components: service instance self-attestation, intermediary service coordination, and relying party verification. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while ensuring complete trust verification across all service instances.

Inventive Principle:
Principle #1Segmentation

2Reliability

If relying party attests all service instances of distributed software, then security trust is improved, but attack surface broadens and scalability deteriorates

Engineering Contradiction:
Improvesecurity trustVSAvoidattestation scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Service instances perform preliminary self-attestation before being discovered by relying parties. The intermediary attestation service also performs preliminary validation and registration of service instances. This preliminary action ensures that only pre-validated instances are added to the trust boundary, maintaining security trust while enabling scalable discovery and attestation of new instances without requiring relying party intervention for each individual instance.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If relying party requires intimate knowledge of distributed software architecture for attestation, then verification accuracy is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveverification accuracyVSAvoidattestation operation ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

Service instances perform self-attestation by automatically generating and providing attestation evidence about their own security state and configuration. The intermediary service handles the complexity of architecture knowledge by managing service instance registration, discovery, and coordination. This self-service approach maintains verification accuracy through detailed instance-level attestation while eliminating the need for relying parties to possess intimate knowledge of the distributed software architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12411928B2Attestation-as-a-service for confidential computing
Publication Date: 2025.09.09 INTEL CORP
  • US12411928B2 patent drawing
  • US12411928B2 patent drawing
  • US12411928B2 patent drawing

AI summary

Various systems and methods are described for implementing trust authority or trust attestation verification operations, including for Trust-as-a-Service or Attestation-as-a-Service implementations, in accordance with the techniques discussed herein. In various examples, operations and configurations are described to enable service-to-service attestation using a trust authority, to operate an attestation service, and to coordinate trust operations between relying and requesting parties.