Hardware Trust ID Attestation for Cloud Server Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for forming trusted computing pools, such as Intel's Trusted Execution Technology, face challenges in ensuring the integrity and geolocation-based trust of cloud servers, as they rely on software-based hypervisor management and Geotags that can be spoofed and do not effectively tie virtual machines to unique physical hosts, leading to security and compliance issues.

Innovation Solution

A trust control management method that generates a unique encoded alphanumeric Trust ID value by combining user-defined and hardware-specific values using an encoding algorithm, storing it in the hardware, and performing attestation to verify the trust status of a computer system, providing robust and foolproof verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based hypervisor management and Geotags are used for trust verification, then the system is easier to operate and deploy, but the security and reliability are compromised due to spoofing vulnerabilities

Engineering Contradiction:
Improveease of deploymentVSAvoidtrust verification reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based trust verification mechanisms (hypervisor management and Geotags) with hardware-based verification using a Trusted Platform Module (TPM). The TPM provides hardware-rooted trust through cryptographic operations and secure storage of verification data, making the system resistant to spoofing while maintaining operational ease through automated attestation processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a TPM as an intermediary hardware component between the cloud workloads and the verification system. The TPM acts as a mediator that performs cryptographic verification of hardware integrity and provides geolocation-based trust verification, eliminating the need for vulnerable software-based mechanisms while preserving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If virtual machines are not tied to unique physical hosts, then workload migration is more flexible, but security and compliance are compromised

Engineering Contradiction:
Improveworkload migration flexibilityVSAvoidsecurity compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the TPM continuously verifies the physical host's hardware integrity and geolocation status. Before allowing workload migration, the system performs attestation to confirm the target host meets trust requirements, providing feedback that ensures security compliance while maintaining migration flexibility.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary verification of the target physical host's hardware integrity and geolocation status before allowing workload migration. The TPM validates the host's trustworthiness in advance, ensuring security and compliance requirements are met before the migration occurs, thus maintaining both flexibility and reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If hardware-based verification is implemented, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvetrust verification reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the TPM's multi-functionality to perform multiple verification tasks (hardware integrity verification, geolocation-based trust verification, cryptographic operations) through a single hardware component. This universal approach improves reliability while minimizing the increase in system complexity by consolidating verification functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The TPM performs self-service cryptographic verification of hardware integrity and geolocation status without requiring complex external verification systems. The hardware module autonomously validates its own state and provides attestation, simplifying the overall system architecture while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10305893B2System and method for hardware-based trust control management
Publication Date: 2019.05.28 TRAPEZOID
  • US10305893B2 patent drawing
  • US10305893B2 patent drawing
  • US10305893B2 patent drawing

AI summary

A trust control management method for security, operable on a computer system generates a unique Trust ID value by combining user-defined values with hardware-specific values associated with the user's computer system and storing the Trust ID value in a memory register physically associated with the hardware of the computer system. A Trust Control Suite (TCS) operable with a server OS/hypervisor maintains a database of user-defined values and list of hardware-specific value types for computer systems clustered in a trusted computing pool. An attestation procedure is performed by the trust control server combining the user-defined values with the hardware-specific values and comparing the resulting value to the user-stored Trust ID value stored in the memory register associated with a user's computer system. Depending on whether it is a match or mismatch, the TCS can determine if it is a trusted computer or not, and can take appropriate alerts and policy actions.