Trusted Computing Cluster Key Distribution via Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing and maintaining trusted channels with multiple trusted computing units becomes cumbersome and costly as the number of units increases, requiring separate key negotiations and complex user access.
Innovation Solution
A method and apparatus that allow a user to establish a trusted channel with a trusted computing cluster by negotiating a session key with one trusted computing unit and using a cluster manager to distribute an encrypted session key to other units within the cluster, simplifying the process and eliminating the need for sequential negotiations with each unit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate key negotiations are conducted with each trusted computing unit, then security is maintained, but user access becomes complicated and costly
Solution Approach 1:
The patent introduces a cluster manager as an intermediary component that coordinates key distribution across the trusted computing cluster. The cluster manager receives the session key from the initiating trusted computing unit and automatically distributes it to other units, eliminating the need for users to manually negotiate keys with each unit while maintaining security through controlled key distribution
Solution Approach 2:
The patent merges multiple separate key negotiation processes into a single unified process. By establishing one trusted channel between the user and any trusted computing unit in the cluster, the session key is then propagated to all other units through the cluster manager, combining what would otherwise require multiple separate negotiations into one operation
2Reliability
If separate trusted channels are established with each trusted computing unit, then secure communication is achieved, but the process becomes cumbersome as the number of units increases
Solution Approach 1:
The patent creates a universal trusted channel that works with any trusted computing unit in the cluster. The cluster manager enables this by maintaining a registry of all units and their public keys, allowing a single session key to be distributed to any combination of units, making the system universally applicable regardless of cluster size or composition
3Reliability
If multiple separate key negotiations are performed, then each trusted channel is secure, but time and resources are consumed
Solution Approach 1:
The patent implements preliminary action by having the cluster manager pre-establish the infrastructure for key distribution, including maintaining the registry of trusted computing units and their public keys. When a user needs to communicate with the cluster, the key negotiation only needs to occur once with any unit, and the pre-configured cluster manager handles the distribution to all other units, significantly reducing the time required
Data Source
AI summary
Some embodiments of the present specification provide a method and an apparatus for establishing a trusted channel between a user and a trusted computing cluster. According to the method, when a user wants to establish a trusted channel with a trusted computing cluster, the user only negotiates a session key with any first trusted computing unit in the cluster to establish the trusted channel. Then, the first trusted computing unit encrypts the session key using a cluster key common to the trusted computing cluster to which the first trusted computing unit belongs, and sends the encrypted session key to a cluster manager. The cluster manager transmits the encrypted session key in the trusted computing cluster, so that other trusted computing units in the cluster obtain the session key and join the trusted channel. Thus, the user establishes a trusted channel with the entire trusted computing cluster.


