Hardware Trust ID Attestation for Cloud Server Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for forming trusted computing pools, such as Intel's Trusted Execution Technology, face challenges in ensuring the integrity and geolocation-based trust of cloud servers, as they rely on software-based hypervisor management and Geotags that can be spoofed and do not effectively tie virtual machines to unique physical hosts, leading to security and compliance issues.
Innovation Solution
A trust control management method that generates a unique encoded alphanumeric Trust ID value by combining user-defined and hardware-specific values using an encoding algorithm, storing it in the hardware, and performing attestation to verify the trust status of a computer system, providing robust and foolproof verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-based hypervisor management and Geotags are used for trust verification, then the system is easier to operate and deploy, but the security and reliability are compromised due to spoofing vulnerabilities
Solution Approach 1:
The patent replaces software-based trust verification mechanisms (hypervisor management and Geotags) with hardware-based verification using a Trusted Platform Module (TPM). The TPM provides hardware-rooted trust through cryptographic operations and secure storage of verification data, making the system resistant to spoofing while maintaining operational ease through automated attestation processes.
Solution Approach 2:
The patent introduces a TPM as an intermediary hardware component between the cloud workloads and the verification system. The TPM acts as a mediator that performs cryptographic verification of hardware integrity and provides geolocation-based trust verification, eliminating the need for vulnerable software-based mechanisms while preserving ease of operation.
2Adaptability or versatility
If virtual machines are not tied to unique physical hosts, then workload migration is more flexible, but security and compliance are compromised
Solution Approach 1:
The patent implements a feedback mechanism where the TPM continuously verifies the physical host's hardware integrity and geolocation status. Before allowing workload migration, the system performs attestation to confirm the target host meets trust requirements, providing feedback that ensures security compliance while maintaining migration flexibility.
Solution Approach 2:
The patent performs preliminary verification of the target physical host's hardware integrity and geolocation status before allowing workload migration. The TPM validates the host's trustworthiness in advance, ensuring security and compliance requirements are met before the migration occurs, thus maintaining both flexibility and reliability.
3Reliability
If hardware-based verification is implemented, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent leverages the TPM's multi-functionality to perform multiple verification tasks (hardware integrity verification, geolocation-based trust verification, cryptographic operations) through a single hardware component. This universal approach improves reliability while minimizing the increase in system complexity by consolidating verification functions.
Solution Approach 2:
The TPM performs self-service cryptographic verification of hardware integrity and geolocation status without requiring complex external verification systems. The hardware module autonomously validates its own state and provides attestation, simplifying the overall system architecture while maintaining high reliability.
Data Source
AI summary
A trust control management method for security, operable on a computer system generates a unique Trust ID value by combining user-defined values with hardware-specific values associated with the user's computer system and storing the Trust ID value in a memory register physically associated with the hardware of the computer system. A Trust Control Suite (TCS) operable with a server OS/hypervisor maintains a database of user-defined values and list of hardware-specific value types for computer systems clustered in a trusted computing pool. An attestation procedure is performed by the trust control server combining the user-defined values with the hardware-specific values and comparing the resulting value to the user-stored Trust ID value stored in the memory register associated with a user's computer system. Depending on whether it is a match or mismatch, the TCS can determine if it is a trusted computer or not, and can take appropriate alerts and policy actions.


