Peer-to-Peer Attestation for Heterogeneous Cluster Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogenous computing clusters, existing attestation methods rely on a single device for verification, leading to significant processing overhead and a single point of failure, with trust established only between the attestation service and a single device.

Innovation Solution

Implementing distributed attestation through peer-to-peer verification using a decentralized protocol, such as blockchain, where each processing node can attest to other nodes, distributing attestation results and cryptographic keys to establish trust among all nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single device is used for attestation verification, then the attestation service can be simplified, but processing overhead increases and a single point of failure is created

Engineering Contradiction:
Improveattestation service structureVSAvoidprocessing overhead
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments the centralized attestation service into multiple distributed attestation nodes. Each node independently performs attestation verification, dividing the processing workload across the network rather than concentrating it at a single device. This segmentation reduces processing overhead at any individual node while eliminating the single point of failure.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a single device performs attestation, then trust establishment is simplified, but reliability decreases due to single point of failure

Engineering Contradiction:
Improvetrust establishment mechanismVSAvoidcluster availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the trust establishment function across multiple attestation nodes, each maintaining independent trust relationships with cluster members. This segmentation ensures that failure of one node does not compromise overall system reliability, as other nodes continue to provide attestation services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a distributed ledger as an intermediary that records attestation results from multiple nodes. This intermediary mechanism enables trust propagation across the cluster without requiring all nodes to directly verify each other, maintaining reliability while simplifying the trust establishment process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If distributed attestation is implemented, then processing overhead is reduced and reliability improves, but device complexity increases

Engineering Contradiction:
Improveprocessing overheadVSAvoidattestation system structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent employs a distributed ledger as an intermediary that automatically stores and propagates attestation results across the network. This intermediary eliminates the need for complex direct peer-to-peer communication protocols, reducing the operational complexity of distributed attestation while maintaining its productivity and reliability benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent designs the distributed ledger to serve multiple functions: storing attestation results, propagating trust information, and providing a single source of truth for all nodes. This multi-functionality reduces the need for separate specialized components, thereby managing system complexity while achieving distributed attestation benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12413420B2Distributed attestation in heterogenous computing clusters
Publication Date: 2025.09.09 ALTERA CORP
  • US12413420B2 patent drawing
  • US12413420B2 patent drawing
  • US12413420B2 patent drawing

AI summary

A method comprises receiving, from a first processing node of a distributed processing cluster, an indication of an attestation result and supporting data for a second processing node of the distributed processing cluster, transmitting the indication of attestation result and supporting data for the second processing node of the distributed processing cluster to at least one additional processing node of the processing cluster, and in response to a determination that the indication of an attestation result for the second processing node of the distributed processing cluster indicated that the second processing node of the distributed processing device is secure, establishing a secure communication connection with the second processing node of the distributed processing cluster using the supporting data.