Trusted Co-Processor for Cloud Host Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, customers lack direct control and security assurance over resources provided by service providers, leading to potential compromises in data and software integrity due to shared resources and lack of trust in the hosting environment.

Innovation Solution

Implementing a trusted co-processor as a peripheral card within the host machine, logically owned by the customer, which provides a secure enclave for verification and observation, allowing customers to validate the state and operation of the host computing device and lock out the provider if unexpected changes occur.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud computing resources are shared and managed by providers, then resource scalability and accessibility are improved, but customer control and security assurance deteriorate

Engineering Contradiction:
Improveresource scalabilityVSAvoidcustomer control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments control authority by separating provider-managed physical resources from customer-controlled virtual resources. The virtual machine manager and virtualized resources create distinct layers where the provider maintains control of host hardware while customers gain control over their virtual instances, resolving the contradiction between shared resource management and customer control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted co-processor as an intermediary component that mediates between the provider's physical infrastructure and the customer's virtual resources. This trusted platform module verifies the integrity of the virtualization environment and provides cryptographic proof, enabling customers to trust provider-managed resources without direct control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If resources are located under provider control, then service management and scalability are improved, but data and software integrity assurance deteriorate

Engineering Contradiction:
Improveservice managementVSAvoiddata integrity compromise
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback mechanisms where the trusted co-processor continuously monitors the state of virtualized resources and provides integrity verification to customers. This feedback loop allows customers to receive proof that their data and software remain intact, even though resources are managed by the provider, thus resolving the contradiction between service management control and integrity assurance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The trusted co-processor performs preliminary verification of the virtualization environment before customers deploy their workloads. By pre-establishing trust through cryptographic measurement and verification of the virtual machine manager and host system state, the system ensures data integrity is protected before potential compromises can occur during provider-managed operations.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If virtual machines are deployed on provider-hosted hardware, then resource accessibility and scalability are improved, but trust in the hosting environment deteriorates

Engineering Contradiction:
Improveresource accessibilityVSAvoidenvironmental trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The trusted co-processor acts as an intermediary that bridges the trust gap between customers and provider-hosted hardware. It provides cryptographic verification of the hosting environment's integrity, allowing customers to access and utilize provider resources while maintaining trust through verifiable proof of environment authenticity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical control and inspection mechanisms with cryptographic verification. Instead of customers needing direct physical access to verify hardware integrity, the system uses cryptographic measurements, digital signatures, and trusted platform modules to provide remote, programmable verification of the hosting environment, thus maintaining trust while enabling remote accessibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11050844B2User controlled hardware validation
Publication Date: 2021.06.29 AMAZON TECH INC
  • US11050844B2 patent drawing
  • US11050844B2 patent drawing
  • US11050844B2 patent drawing

AI summary

A trusted co-processor can provide a hardware-based observation point into the operation of a host machine owned by a resource provider or other such entity. The co-processor can be installed via a peripheral card on a fast bus, such as a PCI bus, on the host machine. The provider can provide the customer with expected information that the customer can verify through a request to an application programming interface (API) of the card, and after the customer verifies the information the customer can take logical ownership of the card and lock out the provider. The card can then function as a trusted but limited environment that is programmable by the customer. The customer can subsequently submit verification requests to the API to ensure that the host has not been unexpectedly modified or is otherwise operating as expected.