Trusted Computing Cluster Key Distribution via Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing and maintaining trusted channels with multiple trusted computing units becomes cumbersome and costly as the number of units increases, requiring separate key negotiations and complex user access.

Innovation Solution

A method and apparatus that allow a user to establish a trusted channel with a trusted computing cluster by negotiating a session key with one trusted computing unit and using a cluster manager to distribute an encrypted session key to other units within the cluster, simplifying the process and eliminating the need for sequential negotiations with each unit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate key negotiations are conducted with each trusted computing unit, then security is maintained, but user access becomes complicated and costly

Engineering Contradiction:
ImprovesecurityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cluster manager as an intermediary component that coordinates key distribution across the trusted computing cluster. The cluster manager receives the session key from the initiating trusted computing unit and automatically distributes it to other units, eliminating the need for users to manually negotiate keys with each unit while maintaining security through controlled key distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple separate key negotiation processes into a single unified process. By establishing one trusted channel between the user and any trusted computing unit in the cluster, the session key is then propagated to all other units through the cluster manager, combining what would otherwise require multiple separate negotiations into one operation

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate trusted channels are established with each trusted computing unit, then secure communication is achieved, but the process becomes cumbersome as the number of units increases

Engineering Contradiction:
Improvesecure communicationVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal trusted channel that works with any trusted computing unit in the cluster. The cluster manager enables this by maintaining a registry of all units and their public keys, allowing a single session key to be distributed to any combination of units, making the system universally applicable regardless of cluster size or composition

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple separate key negotiations are performed, then each trusted channel is secure, but time and resources are consumed

Engineering Contradiction:
Improvetrusted channel securityVSAvoidkey negotiation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the cluster manager pre-establish the infrastructure for key distribution, including maintaining the registry of trusted computing units and their public keys. When a user needs to communicate with the cluster, the key negotiation only needs to occur once with any unit, and the pre-configured cluster manager handles the distribution to all other units, significantly reducing the time required

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11728978B2Method and apparatus for establishing trusted channel between user and trusted computing cluster
Publication Date: 2023.08.15 ADVANCED NEW TECHNOLOGIES CO LTD
  • US11728978B2 patent drawing
  • US11728978B2 patent drawing
  • US11728978B2 patent drawing

AI summary

Some embodiments of the present specification provide a method and an apparatus for establishing a trusted channel between a user and a trusted computing cluster. According to the method, when a user wants to establish a trusted channel with a trusted computing cluster, the user only negotiates a session key with any first trusted computing unit in the cluster to establish the trusted channel. Then, the first trusted computing unit encrypts the session key using a cluster key common to the trusted computing cluster to which the first trusted computing unit belongs, and sends the encrypted session key to a cluster manager. The cluster manager transmits the encrypted session key in the trusted computing cluster, so that other trusted computing units in the cluster obtain the session key and join the trusted channel. Thus, the user establishes a trusted channel with the entire trusted computing cluster.