Trusted Computing Service Directory for User-Defined Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mechanisms for trusted computing primarily benefit computing infrastructure owners and application owners, rather than end users, as users cannot demand or find services with specific trusted computing and software settings, particularly in cloud environments like DNS resolvers.

Innovation Solution

A method for users to query remote service databases for trusted computing services (TCS) that match their requirements, including software and trust indicia, and establish connections with service providers offering compatible TCS, enabling users to find and utilize services with specific software and trusted computing settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional trusted computing mechanisms are used, then computing infrastructure owners and application owners benefit from security improvements, but end users cannot demand or find services with specific trusted computing and software settings

Engineering Contradiction:
Improvetrusted computing securityVSAvoiduser ability to find and demand TCS
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a service database as an intermediary component that mediates between users and service providers. The database stores information about available trusted computing services and enables users to query for services matching their requirements. This intermediary structure allows users to discover and demand specific TCS without directly managing the complex trusted computing infrastructure, thus resolving the contradiction between security reliability and user ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables users to perform self-service by allowing them to directly query the service database for trusted computing services that match their requirements and establish connections with compatible service providers. Users can independently search for, select, and connect to services with specific trusted computing settings without requiring infrastructure owner intervention, thereby improving ease of operation while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If cloud computing infrastructure is provided as-is, then service delivery is simple and flexible, but no guarantees of security, privacy, or user information protection are provided

Engineering Contradiction:
Improvecloud service delivery flexibilityVSAvoidsecurity and privacy guarantees
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the cloud computing ecosystem into distinct components: service providers offering various services, a centralized service database storing trusted computing information, and users making requests. This segmentation allows the system to maintain the flexibility of cloud service delivery while adding security guarantees through the trusted computing layer. The service database acts as a separate segment that provides security verification without constraining the flexibility of service provision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by having service providers pre-configure and register their trusted computing parameters in the service database before users need them. Users can then query for pre-verified services that meet their security and privacy requirements. This preliminary setup allows cloud services to maintain delivery flexibility while ensuring security guarantees are already in place before service consumption.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If DNS resolvers sell user query history to third parties, then revenue generation is possible, but user privacy is compromised

Engineering Contradiction:
ImproveDNS resolver operational capabilityVSAvoiduser privacy violation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies the disposable principle by enabling users to establish temporary, dedicated connections to trusted DNS resolvers that are configured to not sell or expose user query history. Users can select and connect to resolvers with specific privacy guarantees, effectively creating a disposable trust relationship that protects user privacy without requiring long-term commitments to privacy-invasive services. This resolves the contradiction by allowing DNS resolvers to remain operationally capable while eliminating the harmful privacy violation through user-selectable trusted computing settings.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20240054221A1Trusted Computing Service Directory
Publication Date: 2024.02.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240054221A1 patent drawing
  • US20240054221A1 patent drawing
  • US20240054221A1 patent drawing

AI summary

Embodiments include methods performed by a computing device to obtain trusted computing services (TCS) from service providers (SPs). Such methods include querying one or more remote service databases for one or more TCS required by a user of the computing device or by an application executing on the computing device. The query for each required TCS includes identification of software required to provide the required TCS, and one or more indicia of trust for any computing platform that provides the required TCS. Such methods include receiving, from the remote service databases, information related to one or more available TCS and corresponding SPs of the available TCS and, based on the received information, selecting one of the available TCS and establishing a connection with the SP corresponding to the selected TCS. Embodiments include complementary methods performed by SPs and remote service databases, as well as apparatus configured to perform such methods.