Network Service Attribute Manifest for Security Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of network services face security concerns due to outdated information about data storage and usage policies, as changes in software code can alter how data is handled, leading to inconsistencies between published characteristics and actual service operations.

Innovation Solution

A security platform generates and signs an attribute manifest that specifies the characteristics of the network service, including data storage and security vulnerabilities, which is verified by users using a public key, ensuring they can securely interact with the service based on verified attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the network service provider publishes information specifying characteristics of the network service, then users can access and review the information relating to the network service, but the information may become outdated when the software code is altered and characteristics are changed

Engineering Contradiction:
Improveoutdated informationVSAvoidsoftware code changes
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by generating and signing an attribute manifest that captures the characteristics of the network service code at a specific point in time, before any potential modifications occur. This manifest serves as a pre-established reference that users can verify against the actual service implementation, ensuring information remains current without requiring continuous manual updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by enabling users to verify the attribute manifest against the actual network service characteristics. This verification process creates a feedback loop where users can confirm whether the published information accurately reflects the current service state, allowing providers to identify and correct any discrepancies between published attributes and actual service behavior.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the network service provider updates the software code to improve functionality, then the service capabilities are enhanced, but the published information specifying characteristics may no longer accurately reflect the current service operations

Engineering Contradiction:
Improveservice functionalityVSAvoidinformation accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies dynamics by making the attribute manifest generation process adaptable to code changes. Rather than maintaining static published information, the system dynamically generates updated manifests that reflect the current state of the service code, allowing the information to evolve with the service while maintaining accuracy through cryptographic verification.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If users rely on published information to securely interact with the network service, then user confidence is maintained, but security concerns arise when the published characteristics do not match the actual service operations

Engineering Contradiction:
Improveuser confidenceVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies partial action by implementing selective verification of service attributes rather than requiring complete re-verification of all service characteristics. Users can verify specific critical attributes (such as data handling practices or security configurations) without needing to validate the entire service codebase, maintaining user confidence while efficiently detecting security-relevant discrepancies.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11095684B2Providing attributes of a network service
Publication Date: 2021.08.17 FORTANIX INC
  • US11095684B2 patent drawing
  • US11095684B2 patent drawing
  • US11095684B2 patent drawing

AI summary

A network service may be identified. One or more attributes of the network service may be determined. An attribute manifest for the network service may be generated based on the determined one or more attributes of the network service. Furthermore, the attribute manifest may be transmitted based on the determined one or more attributes to the network service.