Universal Reference Hierarchical Description for Hardware Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to network security lack a comprehensive and consistent method to describe hardware and software configurations, making it difficult to perform thorough attestation and digital forensics tasks, especially in identifying vulnerabilities and security threats.

Innovation Solution

The implementation of universal references that provide a hierarchical description of computing entities, allowing for the exhaustive listing of components and sub-components, enabling policy enforcement, attestation, and forensics tasks by representing software and hardware components using a Merkle tree-like structure and storing relationships in a trusted repository.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional approaches are used to describe hardware and software configurations, then the system is simpler to implement, but the ability to perform thorough attestation and digital forensics tasks is insufficient

Engineering Contradiction:
Improveattestation and forensics capabilityVSAvoidconfiguration description system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The configuration description is segmented into hierarchical levels (system level, component level, sub-component level) where each level describes specific aspects of the computing entity. This segmentation allows thorough attestation and forensics capabilities while maintaining manageable complexity through structured organization of configuration data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A universal reference system is implemented that can describe any hardware or software configuration using a common framework of levels and components. This universal approach enables consistent attestation and forensics across diverse systems without requiring system-specific complex descriptions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If detailed hierarchical descriptions of computing entities are created, then complete inventory and vulnerability identification is achieved, but the data structure becomes more complex

Engineering Contradiction:
Improveconfiguration information completenessVSAvoidhierarchical data structure
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The configuration information is segmented into discrete levels (system, component, sub-component) with each level containing specific information about that tier. This segmentation ensures complete information capture while organizing data in a structured manner that reduces overall complexity through clear hierarchical boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hierarchical dimension is added to the configuration description, organizing information across multiple levels rather than a flat structure. This dimensional organization allows complete inventory information to be captured while managing complexity through the hierarchical framework that naturally groups related data.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If universal references are implemented for all components, then consistent identification and comparison of security threats is improved, but the implementation complexity increases

Engineering Contradiction:
Improvethreat identification consistencyVSAvoidreference system implementation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A universal reference system is implemented where each component at each hierarchical level is identified by a reference that can be used consistently across different computing entities. This universality enables consistent identification and comparison of security threats while the modular reference structure keeps implementation complexity manageable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The universal reference system uses standardized reference patterns and structures that can be copied and applied across different components and levels. This copying approach maintains consistency in threat identification while reducing implementation complexity through reuse of established reference formats.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11997141B2Attestation and computer forensics based on universal references for hardware and/or software configurations
Publication Date: 2024.05.28 CISCO TECHNOLOGY INC
  • US11997141B2 patent drawing
  • US11997141B2 patent drawing
  • US11997141B2 patent drawing

AI summary

A method, computer system, and computer program product are provided for performing policy enforcement, attestation, and network forensics. A universal reference for a computing entity is obtained, wherein the universal reference identifies one or more components of the computing entity by additional universal references assigned to the one or more components. A hierarchical description of the computing entity is determined by enumerating each additional universal reference of the one or more components and additional sub-components, wherein the hierarchical description exhaustively identifies the components and sub-components of the computing entity. The hierarchical description is analyzed by accessing a database to identify mappings of the one or more additional universal references to the one or more components and sub-components. The one or more components and sub-components identified by the analyzing are assessed to perform one or more of: an inventory task, a policy enforcement task, an attestation task, and a forensics task.