Multi-verifier node attestation for network security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional device attestation systems rely on a single verifier approach, making them vulnerable to failures and malicious activities, as the entire attestation process can be compromised if the single verifier fails or is hacked.

Innovation Solution

A multi-verifier approach is implemented, where multiple nodes in a network are identified as verifier nodes, each collecting and verifying data independently to perform attestation, using mechanisms like certificate-based or zero-knowledge protocols, and applying a majority function to consolidate results and detect malicious nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single verifier is used for device attestation, then the attestation process is simple and fast, but the system becomes vulnerable to failures and malicious activities

Engineering Contradiction:
Improveattestation reliabilityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the single verifier into multiple verifier nodes distributed across the network. Each verifier node independently performs attestation on target devices, segmenting the verification function across multiple entities. This segmentation improves reliability by eliminating single points of failure while maintaining the core attestation functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple verification results from different verifier nodes using a consensus mechanism. The attestation is considered successful when a threshold number of verifiers confirm the device's integrity, merging individual verification outcomes into a collective decision that enhances system reliability.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple verifier nodes are introduced, then the system reliability improves, but the attestation process complexity increases

Engineering Contradiction:
Improvenetwork attestation reliabilityVSAvoidmulti-verifier system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes each verifier node universal by enabling them to perform multiple functions: verifying device integrity, validating cryptographic signatures, and participating in consensus decision-making. This multi-functionality reduces the need for specialized components, managing complexity while maintaining reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Verifier nodes autonomously perform attestation without requiring centralized coordination for each verification event. Each node independently collects device metrics, validates certificates, and contributes to the consensus process, allowing the system to self-organize and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If a single verifier performs all attestation, then the verification process is fast, but the entire system is compromised if the verifier is hacked

Engineering Contradiction:
Improveattestation securityVSAvoidattestation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a threshold-based consensus mechanism where only a partial number of verifier nodes (exceeding a predefined threshold) need to successfully verify a device for the attestation to pass. This partial action approach maintains security by requiring multiple independent verifications while avoiding the need for all nodes to complete verification, thus limiting time loss.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts the threshold parameter for consensus based on security requirements and network conditions. By changing this parameter, the system can balance between security (higher threshold) and speed (lower threshold), optimizing the trade-off between attestation security and time consumption for different operational contexts.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11245709B2Multi-verifier approach for attestation of nodes in a network
Publication Date: 2022.02.08 TATA CONSULTANCY SERVICES LTD
  • US11245709B2 patent drawing
  • US11245709B2 patent drawing
  • US11245709B2 patent drawing

AI summary

This disclosure relates generally to contract management, and more particularly to contract management in a data marketplace. In an embodiment, a system for contract management performs refactoring of a contract, during which the system extracts terms and conditions from the contract and generates a simplified view of the contract. The system further performs a requirement validation based on the contract, during which the system determines features of data entity matches requirements specified by a first party or not, based on domain specific ontologies. If the data entity features are not matching with the requirements, then the system fetches one or more relevant attributes from a list of ontologies, verifies whether the features of entity along with the selected feature(s) satisfy the requirements or not. The system accordingly generates an agreeable requirement document as output of the requirement validation.