Remote Attestation Server for Cloud Host Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer networks face challenges in authenticating hypervisors and operating systems across multiple hosts in a data center, particularly in cloud environments, where existing solutions are limited to single hosts and rely on third-party attestation or hardware roots of trust, lacking integration with modern cloud environments.

Innovation Solution

A remote attestation system with an attestation operations subsystem, server pool, policy database, and state database, integrated into the cloud architecture, enabling centralized attestation managed by the cloud provider, independent of virtual machine actions, and accessible through an end-user service portal, allowing for Cloud-wide attestation policies and efficient resource optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware roots of trust are used for attestation, then authentication reliability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote attestation server as an intermediary between the cloud provider and the virtual machine. This server performs attestation operations remotely without requiring hardware roots of trust to be installed in each virtual machine. The intermediary handles the complex cryptographic operations and trust establishment centrally, eliminating the need for complex hardware security modules in each host while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If third-party attestation is used, then authentication reliability is improved, but loss of time and operational efficiency worsen

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidattestation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service attestation where the cloud provider can perform attestation operations autonomously without requiring third-party involvement. The remote attestation server enables the cloud provider to directly verify the integrity of virtual machines and host configurations, eliminating the time delays associated with third-party attestation processes while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If single-host attestation solutions are used, then ease of operation is improved, but adaptability to cloud environments worsens

Engineering Contradiction:
Improveease of operationVSAvoidcloud environment adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal remote attestation system that can operate across multiple cloud environments and host configurations. The remote attestation server is designed to work with different virtual machine types, cloud providers, and network configurations, making it adaptable to various cloud scenarios while maintaining ease of operation through a standardized interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If centralized attestation is implemented, then productivity and resource optimization are improved, but device complexity increases

Engineering Contradiction:
Improveresource optimization efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The remote attestation server acts as a centralized intermediary that handles all attestation operations for multiple virtual machines and hosts. This centralization enables efficient resource optimization by allowing the cloud provider to manage security policies uniformly across the entire infrastructure, improving productivity while the intermediary architecture distributes the complexity management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11831687B2Systems and methods for authenticating platform trust in a network function virtualization environment
Publication Date: 2023.11.28 CABLE TELEVISION LAB INC
  • US11831687B2 patent drawing
  • US11831687B2 patent drawing
  • US11831687B2 patent drawing

AI summary

A remote attestation system for a computer network includes an attestation operations subsystem configured to manage attestation procedures for the remote attestation system, and an attestation server pool including a plurality of attestation servers. The plurality of attestation servers is configured to perform attestation of at least one host in a data center. The system further includes an attestation state database configured to store a state of attestation of the at least one host, an attestation policy database configured to store at least one operator policy of the computer network, and an end-user service portal configured to provide access to the remote attestation system by users of the computer network.