IP Library › Granted Patent US 12,294,614
Granted Patent B2
US 12,294,614 · App. 17/583,284 · Granted May 6, 2025

Verifying trust postures of heterogeneous confidential computing clusters

Inventors: Eric Voit (Bethesda, MD); Pradeep Kumar Kathail (Los Altos, CA); Avinash Kalyanaraman (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,294,614
App. No.
17/583,284
Granted
May 6, 2025
Kind
B2
Abstract

Disclosed are systems, apparatuses, methods, and computer-readable media for providing security postures for a service provided by a heterogenous system. A method for verifying trust by a service node includes receiving a request for a security information of the service node from a client device, wherein the request includes information identifying a service to receive from the service node, identifying a related node to communicate with the service node based on the service, after identifying the related node, requesting a security information of the related node, generating a composite security information from the security information of the service node and the security information of the related node, and sending the composite security information to the client device. The composite security information provides security claims for a service implemented by a heterogenous devices that have different trusted execution environments.

Claims (44)

1. A method for verifying trust by a service node, the method comprising:

receiving a request for a security information of the service node from a client device, wherein the request includes information identifying a service to receive from the service node;

identifying a related service node to communicate with the service node based on the service, wherein the related service node is associated with the service;

after identifying the related service node, requesting a security information of the related service node;

generating a composite security information from the security information of the service node and the security information of the related service node, including:

identifying affirming claims and detracting claims in the security information of the service node and the security information of the related service node, the affirming claims being in support of providing security, and the detracting claims being opposed to provide security;

including in the composite security information matching affirming claims which appear in both the security information of the service node and the security information of the related service node;

excluding from the composite security information affirming claims which appear in one but not both of the security information of the service node and the security information of the related service node;

including in the composite security information any detracting claims that appear in either of the security information of the service node and the security information of the related service node; and

sending the composite security information to the client device.

2. The method of claim 1 , wherein the security information includes a plurality of claims related to a type of verification, wherein the type of verification includes at least one a hardware verification, a unique identify verification, a data integrity verification, a boot verification, and an executable verification.

3. The method of claim 2 , first comprising: in response to receiving the security information from the related service node, identifying implicit claims in the security information of the related service node, and appending the implicit claims to the security information from the related service node.

4. The method of claim 1 , further comprising:

executing a spanning tree algorithm to identify candidate nodes associated with the service from addressable nodes, wherein the related service node is selected from the candidate nodes.

5. The method of claim 1 , wherein the service node comprises a first trusted module and the related service node comprises a second trusted module, and wherein the first trusted module is different from the second trusted module.

6. The method of claim 1 , further comprising:

transmitting a request to a management node to identify candidate related service nodes; and

receiving a list of the candidate related service nodes from a management node that determines which candidate nodes are qualified to deliver the service.

7. A service node for providing trust postures of a heterogenous system, comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions and cause the processor to:

receive a request for a security information of the service node from a client device, wherein the request includes information identifying a service to receive from the service node;

identify a related service node to communicate with the service node based on the service, wherein the related service node is associated with the service;

after identifying the related service node, request a security information of the related service node;

generate a composite security information from the security information of the service node and the security information of the related service node, including:

identify affirming claims and detracting claims in the security information of the service node and the security information of the related service node, the affirming claims being in support of providing security, and the detracting claims being opposed to provide security;

include in the composite security information matching affirming claims which appear in both the security information of the service node and the security information of the related service node;

exclude from the composite security information affirming claims which appear in one but not both of the security information of the service node and the security information of the related service node;

include in the composite security information any detracting claims that appear in either of the security information of the service node and the security information of the related service node; and

send the composite security information to the client device.

8. The service node of claim 7 , wherein the security information includes a plurality of claims related to a type of verification, wherein the type of verification includes at least one a hardware verification, a unique identify verification, a data integrity verification, a boot verification, and an executable verification.

9. The service node of claim 7 , wherein the processor is configured to execute the instructions and cause the processor to:

executing a spanning tree algorithm to identify candidate nodes associated with the service from addressable nodes, wherein the related service node is selected from the candidate nodes.

10. The service node of claim 7 , wherein the service node comprises a first trusted module and the related service node comprises a second trusted module, and wherein the first trusted module is different from the second trusted module.

11. A non-transitory computer readable medium comprising instructions, the instructions, when executed by a computing system, cause the computing system to:

receive a request for a security information of a service node from a client device, wherein the request includes information identifying a service to receive from the service node;

identify a related service node to communicate with the service node based on the service, wherein the related service node is associated with the service;

after identifying the related service node, request a security information of the related service node;

generate a composite security information from the security information of the service node and the security information of the related service node, including:

identify affirming claims and detracting claims in the security information of the service node and the security information of the related service node, the affirming claims being in support of providing security, and the detracting claims being opposed to provide security;

include in the composite security information matching affirming claims which appear in both the security information of the service node and the security information of the related service node;

exclude from the composite security information affirming claims which appear in one but not both of the security information of the service node and the security information of the related service node;

include in the composite security information any detracting claims that appear in either of the security information of the service node and the security information of the related service node; and

send the composite security information to the client device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: VOIT, ERIC; KATHAIL, PRADEEP KUMAR; KALYANARAMAN, AVINASH
To: CISCO TECHNOLOGY, INC.
Reel/Frame 058753/0223 →
Continuity (2)
Provisional Application 63169528 · Apr 1, 2021
Related Publication 20220321605A1 · Oct 6, 2022
References Cited (68)
US 7200865B1 · Roscoe · 2007 [cited by examiner]
US 7804791B2 · Farkas · 2010 [cited by examiner]
US 7920572B2 · Bates · 2011 [cited by examiner]
US 9425966B1 · Potlapally · 2016 [cited by examiner]
US 10083472B1 · Schroder · 2018 [cited by examiner]
US 10263861B2 · Akiya · 2019 [cited by examiner]
US 10498634B2 · Huang · 2019 [cited by examiner]
US 10517056B2 · Wylie · 2019 [cited by examiner]
US 10838779B1 · Yue · 2020 [cited by examiner]
US 10958667B1 · Maida · 2021 [cited by examiner]
US 10997177B1 · Howes · 2021 [cited by examiner]
US 11816662B2 · Buradagunta · 2023 [cited by examiner]
US 20070067847A1 · Wiemer et al. · 2007 [cited by applicant]
US 20070143605A1 · Metke et al. · 2007 [cited by applicant]
US 20070143629A1 · Hardjono et al. · 2007 [cited by applicant]
US 20110078775A1 · Yan · 2011 [cited by applicant]
US 20140191875A1 · Wedig · 2014 [cited by examiner]
US 20140279808A1 · Strassner · 2014 [cited by examiner]
US 20170230245A1 · Jacquin et al. · 2017 [cited by applicant]
US 20170324618A1 · Lapukhov · 2017 [cited by examiner]
US 20180121250A1 · Qi · 2018 [cited by examiner]
US 20180157838A1 · Bushey et al. · 2018 [cited by applicant]
US 20190036900A1 · Zhang et al. · 2019 [cited by applicant]
US 20190182273A1 · Walsh · 2019 [cited by examiner]
US 20190347440A1 · Langley · 2019 [cited by examiner]
US 20200204476A1 · Voit et al. · 2020 [cited by applicant]
US 20200213302A1 · Saha et al. · 2020 [cited by applicant]
CN 101472276B · 2011 [cited by examiner]
CN 102420812A · 2012 [cited by examiner]
CN 101578841B · 2013 [cited by examiner]
CN 104426876A · 2015 [cited by examiner]
CN 105848152A · 2016 [cited by examiner]
CN 106211219A · 2016 [cited by examiner]
CN 110225012A · 2019 [cited by examiner]
CN 110287045A · 2019 [cited by examiner]
CN 111915078A · 2020 [cited by examiner]
CN 111932380A · 2020 [cited by examiner]
CN 111988188A · 2020 [cited by examiner]
CN 112417406A · 2021 [cited by examiner]
CN 109947567B · 2021 [cited by examiner]
CN 113645262A · 2021 [cited by examiner]
JP 2005301550A · 2005 [cited by applicant]
JP 2012215994A · 2012 [cited by applicant]
JP 2016536713A · 2016 [cited by applicant]
JP 2018063716A · 2018 [cited by applicant]
JP 2020527298A · 2020 [cited by applicant]
WO 2009155849 · 2009 [cited by applicant]
WO 2016085517A1 · 2016 [cited by applicant]
WO 2020226979A1 · 2020 [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/US2022/071419, mailed on Jun. 22, 2022, 12 pages. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2022/071419, mailed Oct. 12, 2023, 9 Pages. [cited by applicant]
Office Action for Australian Application No. 2022246728, dated Sep. 12, 2023, 4 Pages. [cited by applicant]
Edgeless Systems, “Marblerun—The service mesh for Confidential Computing,” Nov. 27, 2020, available at https://blog.edgeless.systems/why-we-need-a-service-mesh-for-confidential-computing-part-3-3-ffc00b2c3508, downloade… [cited by applicant]
“MarbleRun,” available at https://marblerun.sh/, downloaded Nov. 17, 2021, 128 pages. [cited by applicant]
“Microsoft Azure Attestation,” A unified solution for remotely verifying the trustworthiness of a platform and intergrity of the binaries running inside it, available at https://azure.microsoft.com/en-us/services/azure-… [cited by applicant]
Voit, Eric, et al., “Trusted Path Routing,” draft-voit-rats-trustworthy-path-routing-o4, Sep. 7, 2021, 18 pages, available at https://datatracker.ietf.org/doc/draft-voit-rats-trustworthy-path-routing/. [cited by applicant]
“Multiple Spanning Tree Protocol,” Wikipedia, last edited Oct. 11, 2021, available at https://en.wikipedia.org/wiki/Multiple_Spanning_Tree_Protocol, downloaded Nov. 14, 2021, 10 pages. [cited by applicant]
Jang, Miyoung, et al., “A New Integrity Verification Method with Cluster-based Data Transformation in Cloud Computing Environment,” International Journal of Smart Home, vol. 9, No. 4 (2015), pp. 225-238. [cited by applicant]
Reiter, Michael K., “A Secure Group Membership Protocol,” IEEE Transactions on Software Engineering, vol. 22, No. 1, Jan. 1996, pp. 31-42. [cited by applicant]
Ricciardi, Aleta M., et al., “Using Process Groups to Implement failure Detection in Asynchronous Environments,” Department of Computer Science, Cornell University, Feb. 7, 1991, 34 pages. [cited by applicant]
Christian, Flaviu, “Reaching Agreement on Processor Group Membership in Synchronous Distributed Systems,” Computer Science and Engineering, University of California, San Diego, La Jolla, California, 1991, 26 pages. [cited by applicant]
Nejdl, Wolfgang, et al., “PeerTrust: Automated Trust Negotiation for Peers on the Semantic Web,” L3S and University of Illinois at Urbana-Champaign, USA, 2004, pp. 118-132. [cited by applicant]
Jonker, Willem, et al., “Secure Data Management,” VLDB 2004 Workshop, SDM 2004, Toronto, Canada, Aug. 2004 Proceedings, part 1 of 3, 75 pages. [cited by applicant]
Jonker, Willem, et al., “Secure Data Management,” VLDB 2004 Workshop, SDM 2004, Toronto, Canada, Aug. 2004 Proceedings, part 2 or 3, 65 pages. [cited by applicant]
Jonker, Willem, et al., “Secure Data Management,” VLDB 2004 Workshop, SDM 2004, Toronto, Canada, Aug. 2004 Proceedings, part 3 of 3, 91 pages. [cited by applicant]
Office Action for Japanese Application No. 2023509609, dated Apr. 22, 2024, 18 Pages. [cited by applicant]
Office Action for Korean Application No. 1020237011630, dated Aug. 15, 2024, 11 Pages. [cited by applicant]
Office Action for Japanese Application No. 2023509609, dated Nov. 1, 2024, 4 Pages. [cited by applicant]
Cited By (2)
US 12,531,789 US 12,683,998