RIM Transparency Service for Supply Chain Attestation Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of maintaining trust and integrity in cloud computing environments, particularly in edge computing devices, is hindered by the large number of suppliers and diverse geopolitical conditions, leading to potential misbehavior and compromised suppliers that can forge reference integrity manifests (RIMs) to assert false trustworthiness claims.
Innovation Solution
Implementing a supplier-specific reference integrity manifest (RIM) authorization system with a RIM transparency service (RTS) that maintains an archive of issued RIMs using distributed ledger technology (DLT) to detect competing RIMs and perform fraud detection, and introducing a proto-RIM to delegate reference value provider authority, ensuring only authorized measurements are included in the RIM.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a cloud computing environment includes multiple suppliers of edge computing devices, then the system can provide diverse functionality and scalability, but trust and attestation integrity are compromised due to the large number of suppliers and diverse geopolitical conditions
Solution Approach 1:
The patent introduces a transparency service as an intermediary between suppliers and verifiers. This service receives, stores, and manages reference integrity manifests (RIMs) and proto-RIMs in a distributed ledger, acting as a neutral mediator that enables trust verification without requiring direct trust relationships between multiple suppliers and verifiers. The intermediary resolves the contradiction by providing a centralized trust anchor point in a distributed system.
2Adaptability or versatility
If certificate authorities issue certificates to all suppliers without reliable reputation information, then supplier coverage is maximized, but security is weakened due to potential compromise by bad actors
Solution Approach 1:
The patent implements preliminary action by requiring suppliers to register their measurement authorities and reference values in the transparency service before issuing any RIMs. The system pre-validates supplier identities and establishes their authorization scope in advance, creating a trusted baseline before any attestation operations occur. This preliminary registration and validation process prevents bad actors from easily compromising the system while maintaining broad supplier coverage.
3Extent of automation
If suppliers can issue RIMs independently, then system autonomy and decentralization are improved, but fraud detection capability deteriorates due to inability to detect competing RIMs
Solution Approach 1:
The transparency service implements feedback mechanisms by monitoring and recording all RIM issuances in a distributed ledger. When a supplier issues a RIM, the service automatically checks for conflicts with existing RIMs and provides feedback about potential fraud. The system continuously monitors the supply chain ecosystem, comparing new RIMs against historical data and governance policies, enabling automated fraud detection while maintaining supplier autonomy.
4Reliability
If the system maintains detailed archives of all issued RIMs for fraud detection, then security and transparency are improved, but system complexity and storage requirements increase
Solution Approach 1:
The patent uses copying by storing RIMs and proto-RIMs as data structures in a distributed ledger, where each node maintains a copy of the entire ledger. This approach provides full transparency and security through redundancy while distributing the storage burden across multiple nodes rather than centralizing complexity. The copying mechanism enables any verifier to independently audit the entire supply chain history without requiring a centralized storage system.
Data Source
AI summary
The technology described herein includes receiving a first reference integrity manifest (RIM) and a first proto-RIM from a first endorser, the first endorser asserting authority, by the first RIM and the first proto-RIM, to supply first attestation reference values for a computing device; storing the first proto-RIM in a RIM transparency database; notarizing the first proto-RIM; and providing the first RIM and the notarized first proto-RIM to a verifier of the computing device.


