Master TEE Intermediary for Network Endpoint Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In home and enterprise networks, service providers face significant complexity and overhead in attesting individual devices with various trusted execution environments (TEEs), requiring multiple backend services for each device to ensure secure service delivery.

Innovation Solution

Implementing a master TEE within the network that acts as an intermediary between service providers and endpoint devices, allowing service providers to attest and provision kernels only to the master TEE, which then securely redirects requests to endpoint devices, eliminating the need for individual device attestation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service providers perform individual attestation against each endpoint device with TEE, then security and trust are ensured, but device complexity and overhead increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a master TEE as an intermediary between service providers and endpoint devices. The master TEE performs centralized attestation and kernel provisioning for multiple endpoint devices, eliminating the need for service providers to individually attest each device. This reduces complexity while maintaining security through the trusted intermediary that verifies device integrity before allowing service access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service providers install and provision kernels to each individual endpoint device, then secure service delivery is achieved, but the overhead and time required increases

Engineering Contradiction:
Improvesecure service deliveryVSAvoidoverhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the kernel provisioning function into a centralized master TEE that serves multiple endpoint devices. Instead of provisioning kernels to each individual device, the master TEE provisions kernels to itself and manages their distribution, significantly reducing the time and overhead required for secure service delivery while maintaining the integrity of the execution environment.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple backend services are deployed for each device, then comprehensive service coverage is achieved, but system complexity increases

Engineering Contradiction:
Improveservice coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The master TEE is designed as a universal platform that can provision and manage kernels for multiple different service providers and endpoint devices through a single interface. This multi-functional approach allows comprehensive service coverage without requiring separate backend services for each device, thereby reducing overall system complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12069055B2Mechanism for managing services to network endpoint devices
Publication Date: 2024.08.20 INTEL CORP
  • US12069055B2 patent drawing
  • US12069055B2 patent drawing
  • US12069055B2 patent drawing

AI summary

An apparatus comprising a processor comprising a trusted execution environment (TEE) to be attested by a plurality of service provider servers on behalf of a plurality of endpoint devices in a network environment and provision kernels for the plurality of service provider servers requesting to access one or more of the plurality of endpoint devices.