Multi-dimensional attestation graph for microservice integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current attestation models are inadequate for verifying the trustworthiness of cloud applications due to their static nature and inability to accommodate the complex, decentralized, and dynamic composition of microservices and their software supply chains, requiring customers to know all components and layers for attestation and independent detection of revocations and patches.
Innovation Solution
The introduction of multi-dimensional attestation graphs that map software and hardware components across spatial and temporal dimensions, enabling richer attestation semantics and allowing verification of individual components and their dependencies, with temporally chained attestations for efficient revocation and compliance with software supply chain regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static hardware attestation is used for TEEs, then integrity of a single code version is provided, but it cannot reflect individual components of microservices and their execution environment
Solution Approach 1:
The patent segments the monolithic attestation into component-level attestations. Each microservice, dependency, and software layer receives its own attestation measurement, allowing verification of individual components rather than treating the entire application as a single unit. This enables selective verification of specific components while maintaining overall system integrity.
Solution Approach 2:
The patent introduces a temporal dimension to attestation by creating attestation graphs that track measurements across multiple time points. This allows verification of not only the current state but also the evolution and provenance of software components through time, adding a temporal axis to the traditional spatial attestation model.
2Reliability
If software-based attestation is implemented for each individual component, then authentication of components is enabled, but it requires ad-hoc implementation for each layer
Solution Approach 1:
The patent creates a universal attestation framework that works across all software layers and components. The attestation graph structure and measurement collection mechanism provide a standardized, multi-functional approach that can authenticate microservices, dependencies, container runtimes, and other components using the same methodology, eliminating the need for ad-hoc implementations.
Solution Approach 2:
The patent introduces an intermediary attestation management system that collects, stores, and correlates attestation measurements from various components. This intermediary layer simplifies the complexity by providing a centralized mechanism to manage multiple attestations, automatically correlating measurements across the software stack without requiring direct implementation complexity at each component level.
3Ease of operation
If flat attestation is used for the entire software stack, then single attestation is provided, but customers must know all components and layers in advance
Solution Approach 1:
The patent segments the flat attestation model into a hierarchical structure where the overall application attestation is divided into component-level attestations. Customers can verify the top-level application integrity while also drilling down to examine specific component measurements and their relationships, maintaining both simplicity and detailed visibility.
Solution Approach 2:
The patent implements a nested attestation structure where component-level attestations are embedded within layer-level attestations, which are in turn embedded within the overall application attestation. This nested structure allows customers to verify at any level of granularity, from the complete software stack down to individual components, without needing to know all components in advance.
4Reliability
If previous attestation solutions are used, then integrity is provided for known components, but customers must independently detect revocations and patches
Solution Approach 1:
The patent implements a feedback mechanism through the attestation graph that automatically tracks and reports changes in component measurements over time. The system continuously monitors attestation measurements and can detect revocations, patches, or unauthorized modifications by comparing current measurements against historical baselines, providing automatic feedback without requiring customer intervention.
Solution Approach 2:
The patent establishes baseline attestation measurements in advance for all software components before deployment. These preliminary measurements serve as reference points that enable automatic detection of any subsequent changes, revocations, or patches by comparing against the pre-established baselines, allowing proactive security monitoring.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and apparatus for multi-dimensional attestations for a software application. A multi-dimensional attestation is generated for at least one component of the software application. The multi-dimensional attestation includes a signed attestation for the at least one component and an attestation reference to at least one other related component. A verifier obtains multi-dimensional attestations for the components of the software application and obtains the signed attestation for the related components of the software application based on the attestation reference and verifies integrity of at least part of the software application based on the obtained signed attestations. The multi-dimensional attestation for a given component of a software application can link attestations across spatial and temporal dimensions including other microservice(s) that communicates directly with the subject microservice, imported code dependencies on which the subject microservice is dependent, and/or the underlying software layer of the subject microservice.