Trust Authority Service for Cloud Native Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud tenants and service providers face challenges in verifying the trustworthiness of cloud-native applications and services running in trusted execution environments, as current methods are costly and inefficient, especially when dealing with rapidly changing software supply chains and the inability to access source code.

Innovation Solution

A software-based architecture and trust authority service, independent of cloud service providers, is introduced to provide remote verification of compute assets using attestation, reputation, and policy validation, ensuring the integrity of binary and source code through a Trust-as-a-Service (TaaS) deployment, which can be applied to any TEE-enabled platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud tenants verify trustworthiness of cloud-native applications using current methods, then verification accuracy is improved, but verification cost and overhead increase significantly

Engineering Contradiction:
Improveverification accuracyVSAvoidverification cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces a trust authority service as an intermediary between cloud tenants and cloud service providers. This mediator issues attestation tokens that verify the trustworthiness of computing tasks, eliminating the need for cloud tenants to perform expensive and complex verification processes themselves. The trust authority consolidates verification capabilities centrally, reducing redundant verification costs while maintaining high verification accuracy through professional attestation services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud tenants perform comprehensive verification of computing tasks, then trustworthiness assurance is improved, but processing time and efficiency deteriorate

Engineering Contradiction:
Improvetrustworthiness assuranceVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The trust authority service performs verification actions in advance by issuing attestation tokens before computing tasks are executed. Cloud service providers obtain these tokens beforehand through the trust authority's verification process, allowing cloud tenants to quickly validate task trustworthiness by simply checking the token rather than performing comprehensive verification at task execution time. This preliminary verification approach ensures high trustworthiness assurance while maintaining processing efficiency.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If a centralized trust verification system is implemented, then verification consistency is improved, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improveverification consistencyVSAvoidsystem complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The trust authority service is designed as a universal platform that can verify multiple types of computing tasks across different cloud service providers using a standardized attestation token format. The system handles diverse verification scenarios (source code verification, binary verification, container image verification) through a unified architecture, reducing deployment complexity while ensuring consistent verification standards across the entire cloud-native ecosystem.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If source code access is required for verification, then verification thoroughness is improved, but ease of operation deteriorates due to inability to access source code in many cases

Engineering Contradiction:
Improveverification thoroughnessVSAvoidoperational simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The trust authority service creates cryptographic copies (attestation tokens) that represent the verification results of computing tasks. Instead of requiring cloud tenants to directly access and verify source code, the trust authority generates these token copies that encapsulate the verification outcomes. Cloud tenants can then operate with these simplified token representations, maintaining verification thoroughness through the trust authority's comprehensive checks while greatly improving ease of operation through simple token validation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240241960A1Trusted provenance authority for cloud native computing platforms
Publication Date: 2024.07.18 INTEL CORP
  • US20240241960A1 patent drawing
  • US20240241960A1 patent drawing
  • US20240241960A1 patent drawing

AI summary

Various systems and methods are described for implementing remote attestation and data provenance verification. An example method for attestation and provenance verification, performed by a computing node, includes: receiving evidence from a client relating to a computing task; analyzing the evidence to determine a provenance verification result for trustworthiness of the computing task; evaluating compliance of the computing task with a policy; and returning an attestation token that includes the provenance verification result for the computing task, in response to determining the computing task is compliant with the policy.