Network Interface Device Attestation for Edge Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In edge computing environments, there is a need for efficient device attestation to ensure the trustworthiness of network interface devices, as distributed edge sites require reliable validation of hardware infrastructure with minimal human intervention and cost, while maintaining a centralized source of truth for trustworthiness.

Innovation Solution

The system employs a selected network interface device to perform device attestation, using out-of-band or in-band communications to negotiate and determine which device will act as the primary attester, and then communicate with an attestation server to validate the trustworthiness of other devices connected to the power rail, utilizing protocols like Remote Attestation (RATS) and generating attestation tokens for proof of trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device attestation is performed manually at distributed edge sites, then trustworthiness validation can be achieved, but human activity and associated costs increase

Engineering Contradiction:
Improvetrustworthiness validationVSAvoidhuman activity
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The network interface device performs self-attestation by automatically generating and providing evidence of its trustworthiness to the lead attester without requiring manual human intervention. The device uses its own root of trust and cryptographic credentials to prove its identity and integrity state, enabling automated validation at distributed edge sites

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A lead attester acts as an intermediary between the attestation server and subordinate network interface devices. The lead attester collects evidence from multiple devices, performs centralized validation, and communicates with the attestation server, thereby automating the trust validation process while reducing human activity at distributed sites

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized attestation validation is implemented, then a single source of truth for hardware validation is achieved, but device complexity increases

Engineering Contradiction:
Improvecentralized source of truthVSAvoidattestation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The attestation system is segmented into distinct roles: subordinate network interface devices that collect local evidence, a lead attester that performs centralized validation, and an attestation server that provides cryptographic verification. This segmentation distributes complexity across multiple components while maintaining a centralized source of truth through the lead attester

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple network interface devices are connected to a host system, then network functionality is improved, but determining trustworthiness of each device becomes more complex

Engineering Contradiction:
Improvenetwork functionalityVSAvoidtrust validation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The lead attester serves as an intermediary that centralizes the trust validation process for multiple network interface devices. Instead of each device independently validating trustworthiness, the lead attester collects evidence from all subordinate devices, performs unified validation, and communicates with the attestation server, thereby simplifying multi-device trust management

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230342449A1Hardware attestation in a multi-network interface device system
Publication Date: 2023.10.26 INTEL CORP
  • US20230342449A1 patent drawing
  • US20230342449A1 patent drawing
  • US20230342449A1 patent drawing

AI summary

Examples described herein relate to a network interface device that includes a network interface, one or more processors, and circuitry to: register the network interface device and based on selection as an attestation device by the management controller from among multiple candidate network interface devices, receive attestation information and perform attestation of one or more devices.