Multi-verifier node attestation for network security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional device attestation systems rely on a single verifier approach, making them vulnerable to failures and malicious activities, as the entire attestation process can be compromised if the single verifier fails or is hacked.
Innovation Solution
A multi-verifier approach is implemented, where multiple nodes in a network are identified as verifier nodes, each collecting and verifying data independently to perform attestation, using mechanisms like certificate-based or zero-knowledge protocols, and applying a majority function to consolidate results and detect malicious nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single verifier is used for device attestation, then the attestation process is simple and fast, but the system becomes vulnerable to failures and malicious activities
Solution Approach 1:
The patent divides the single verifier into multiple verifier nodes distributed across the network. Each verifier node independently performs attestation on target devices, segmenting the verification function across multiple entities. This segmentation improves reliability by eliminating single points of failure while maintaining the core attestation functionality.
Solution Approach 2:
The patent combines multiple verification results from different verifier nodes using a consensus mechanism. The attestation is considered successful when a threshold number of verifiers confirm the device's integrity, merging individual verification outcomes into a collective decision that enhances system reliability.
2Reliability
If multiple verifier nodes are introduced, then the system reliability improves, but the attestation process complexity increases
Solution Approach 1:
The patent makes each verifier node universal by enabling them to perform multiple functions: verifying device integrity, validating cryptographic signatures, and participating in consensus decision-making. This multi-functionality reduces the need for specialized components, managing complexity while maintaining reliability.
Solution Approach 2:
Verifier nodes autonomously perform attestation without requiring centralized coordination for each verification event. Each node independently collects device metrics, validates certificates, and contributes to the consensus process, allowing the system to self-organize and reducing operational complexity.
3Reliability
If a single verifier performs all attestation, then the verification process is fast, but the entire system is compromised if the verifier is hacked
Solution Approach 1:
The patent implements a threshold-based consensus mechanism where only a partial number of verifier nodes (exceeding a predefined threshold) need to successfully verify a device for the attestation to pass. This partial action approach maintains security by requiring multiple independent verifications while avoiding the need for all nodes to complete verification, thus limiting time loss.
Solution Approach 2:
The system dynamically adjusts the threshold parameter for consensus based on security requirements and network conditions. By changing this parameter, the system can balance between security (higher threshold) and speed (lower threshold), optimizing the trade-off between attestation security and time consumption for different operational contexts.
Data Source
AI summary
This disclosure relates generally to contract management, and more particularly to contract management in a data marketplace. In an embodiment, a system for contract management performs refactoring of a contract, during which the system extracts terms and conditions from the contract and generates a simplified view of the contract. The system further performs a requirement validation based on the contract, during which the system determines features of data entity matches requirements specified by a first party or not, based on domain specific ontologies. If the data entity features are not matching with the requirements, then the system fetches one or more relevant attributes from a list of ontologies, verifies whether the features of entity along with the selected feature(s) satisfy the requirements or not. The system accordingly generates an agreeable requirement document as output of the requirement validation.


