Multi-Cloud Blockchain Admission Control with Hardware Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Blockchain technology is computationally expensive and less practical for distrusted orchestration and configuration management due to high computation requirements and slower transaction performance, especially for IoT devices and enterprise management servers.
Innovation Solution
Implementing a system that applies zero trust principles for device admission into a blockchain group, requiring supermajority validation of hardware attestation data, and using a bounded blockchain with a maximum block count to reduce computational complexity and improve transaction throughput.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If blockchain is used for distributed orchestration and configuration management, then security and immutability are improved, but computational requirements increase and transaction performance decreases
Solution Approach 1:
The patent segments the blockchain validation process by introducing a committee-based verification system where a subset of trusted devices validate hardware attestation data. This segmentation reduces the computational burden on all devices while maintaining security through cryptographic verification of hardware roots of trust, thereby improving transaction performance without sacrificing security.
Solution Approach 2:
The patent implements preliminary hardware attestation and validation before devices join the blockchain network. By pre-verifying hardware roots of trust and binding device identities to hardware configurations before admission, the system eliminates the need for continuous heavy cryptographic validation of device identities, reducing ongoing computational requirements while maintaining security.
2Reliability
If blockchain validation is performed for each transaction, then security is improved, but computational overhead increases
Solution Approach 1:
The patent performs hardware attestation and identity binding as a preliminary action before device admission to the blockchain. This one-time validation establishes trusted device identities that can be verified through cryptographic signatures without requiring heavy computational resources for each subsequent transaction, thereby reducing ongoing computational overhead while maintaining security.
Solution Approach 2:
The patent uses cryptographic copying of hardware roots of trust to device identities through signed attestations. Instead of continuously validating hardware configurations, the system creates cryptographic copies (signatures) of hardware trust attributes that can be efficiently verified, reducing computational overhead while preserving security guarantees.
3Stability of the object's composition
If unbounded blockchain is used, then data integrity is maintained, but storage requirements increase and computational complexity increases
Solution Approach 1:
The patent segments the blockchain into a bounded structure with a defined maximum block count, dividing the distributed ledger into manageable segments. This segmentation maintains data integrity within each block through cryptographic linking while limiting overall storage requirements and reducing the computational complexity of validating and maintaining the entire chain, as devices only need to track a finite number of blocks.
Data Source
AI summary
Blockchain security for distributed multi-cloud orchestration and configuration management is described herein. A method as described herein can include receiving, by a system comprising a processor from a first computing device, an admission request for entry of the first computing device into a blockchain system, the admission request comprising hardware verification data relating to a hardware configuration of the first computing device, wherein the admission request is signed by a private key associated with the first computing device; facilitating, by the system, validation of the hardware verification data by respective second computing devices in the blockchain system, the validation being based on a public key stored in a public key certificate associated with the first computing device; and granting, by the system, admission of the first computing device into the blockchain system in response to a supermajority of the second computing devices successfully validating the hardware verification data.


