Trust Establishment via Side Channel Pattern Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments where multiple machine instances execute sensitive operations, establishing trust between insulated instances is challenging due to the risk of compromising confidential operations or data through observable side channel patterns, such as power usage and cache activity.

Innovation Solution

A trust establishment application monitors side channel patterns to determine the trustworthiness of machine instances by generating and detecting specific communication patterns, configuring instances to operate in either trusted or untrusted modes based on the presence of a quorum of trusted machines, and restricting access and functionality accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine instances are insulated from communicating amongst themselves, then security and confidentiality of operations are improved, but trust establishment between instances becomes difficult

Engineering Contradiction:
ImprovesecurityVSAvoidtrust establishment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trust establishment application as an intermediary that mediates between insulated machine instances. This application uses side channel monitoring to establish trust relationships without requiring direct communication between instances, thus maintaining security while enabling trust verification through a trusted third-party mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical communication channels (direct instance-to-instance communication) with an alternative mechanism based on side channel monitoring. Instead of instances communicating directly, the trust establishment application monitors physical side channels (power consumption, electromagnetic emissions, cache timing) to infer trust relationships, substituting physical observation for direct communication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If side channel patterns are monitored to detect trustworthiness, then trust verification capability is improved, but risk of compromising confidential operations through observable patterns increases

Engineering Contradiction:
Improvetrust verificationVSAvoidside channel leakage
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful side channel leakage into a beneficial trust verification mechanism. Instead of treating side channel observations (power consumption, cache activity, electromagnetic emissions) as security threats that leak confidential information, the system uses these same observable patterns as indicators of trusted behavior. Trusted instances exhibit predictable, consistent side channel patterns that can be verified without exposing actual confidential operations.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The trust establishment application acts as an intermediary that safely observes side channel patterns without exposing confidential operations. It monitors physical characteristics (power consumption, electromagnetic emissions, cache timing) and translates them into trust decisions, preventing direct exposure of sensitive data while still enabling verification through a controlled intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If machine instances are configured to execute sensitive operations, then operational capability is improved, but vulnerability to side channel attacks increases

Engineering Contradiction:
Improveoperational capabilityVSAvoidside channel vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The trust establishment application serves as a protective intermediary between machine instances executing sensitive operations and potential side channel attackers. It monitors side channel patterns and enforces trust policies, allowing instances to execute sensitive operations securely by filtering and controlling access based on verified trust relationships established through side channel observation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9934391B2Establishing trust using side channels
Publication Date: 2018.04.03 AMAZON TECH INC
  • US9934391B2 patent drawing
  • US9934391B2 patent drawing
  • US9934391B2 patent drawing

AI summary

Disclosed are various embodiments for a trust establishment application. Machine instances executed in the same computing environment generate side channel patterns embodying data identifying themselves as trusted machine instances. The side channel patterns are detected to determine which machine instances are trusted. An operational mode of a machine instance is configured as a function of whether a quorum of trusted machine instances are executed in the computing environment.