Self-Organizing Trusted Network via Decentralized Service Pooling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current trusted networks face scalability issues due to their centralized approach, which becomes impractical with user and device mobility, and the complexity of network expansion and contraction, leading to inefficiencies in service provisioning.
Innovation Solution
The implementation of a self-organizing trusted network using a Trusted Network Arbiter (TNA) with Trusted Execution Environment (TEE) technology, such as Intel SGX, allows for dynamic formation and management of trusted networks, enabling devices to discover and pool services securely, even across mobile devices, through a decentralized registry system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized approach is used to host services on a central server or web gateway, then service provisioning is simplified, but scalability issues arise as the network size expands and contracts
Solution Approach 1:
The patent segments the centralized service hosting model into distributed service hosting across multiple network devices. Each device can independently host services, eliminating the single point of control and enabling the network to scale dynamically as devices are added or removed. This is achieved through the trusted network arbiter that coordinates service discovery and registration in a decentralized manner.
Solution Approach 2:
The patent implements dynamic service provisioning where the network architecture adapts automatically to changing network conditions, device mobility, and service demands. The trusted network arbiter enables real-time service registration, discovery, and unregistration without manual intervention, allowing the network to dynamically expand and contract based on actual needs.
2Reliability
If strict control is implemented over device connection and configuration assessment, then network security is improved, but practical usability deteriorates due to user mobility and device mobility
Solution Approach 1:
The patent implements self-service mechanisms where mobile devices automatically perform configuration assessment and security verification when joining the network. The trusted network arbiter enables devices to self-register, self-verify their security posture, and self-integrate into the trusted network without manual administrative intervention, thus maintaining security while enabling mobility.
Solution Approach 2:
The patent performs preliminary security assessment and configuration verification before devices are fully integrated into the network. The trusted network arbiter conducts pre-connection security checks and establishes trust relationships in advance, allowing devices to quickly join and leave the network without repeated manual security assessments.
3Reliability
If firewalls and gateway devices are hardened to prevent attacks from untrusted devices, then network security is improved, but network complexity and difficulty of managing dynamic connections increase
Solution Approach 1:
The patent introduces a trusted network arbiter as an intermediary that manages security policies, service registration, and device authentication. This intermediary simplifies the security management burden by centralizing policy enforcement and automatic trust verification, reducing the complexity of managing firewalls and gateway devices while maintaining strong security posture.
4Ease of operation
If services are hosted centrally, then service management is simplified, but service discovery and access efficiency deteriorate in large-scale mobile networks
Solution Approach 1:
The patent segments service hosting from centralized to distributed across multiple network devices. The trusted network arbiter coordinates a decentralized service discovery mechanism where services are registered and discovered locally, reducing the distance and hops required for service access in large-scale mobile networks while maintaining simplified management through automated arbitration.
Data Source
AI summary
Disclosed examples include during basic discovery, provide information from a local device to a first remote trusted device, the information to indicate the local device supports trusted discovery and to establish the local device as a second remote trusted device; during the trusted discovery, access, by the local device, a trusted discovery message received from the first remote trusted device; in response to verifying security credentials identified in the trusted discovery message for the first remote trusted device: add the first remote trusted device to a trusted network including the local device; and index, by the local device, a first service hosted by the first remote trusted device in a registry, the registry to identify second services available to the local device and corresponding locations of the second services.


