Localized device attestation
Abstract
Various approaches for deploying and controlling distributed compute operations with the use of infrastructure processing units (IPUs) and similar networked processing units are disclosed. For example, a request to verify integrity of a device is received at a networking infrastructure device. A representation of device components of the device may be obtained. The representation of the device components may be compared with a reference value held by the networking infrastructure device. A response to the request may be transmitted based on matching the representation of the device components and the reference value. Here, the response indicates that the integrity of the device is intact.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A networking infrastructure device for localized device attestation, the networking infrastructure device comprising:
a network interface; and processing circuitry that, when in operation, is configured to:
receive, from the network interface, a request to verify integrity of a device;
obtain a representation of device components of the device;
compare the representation of the device components with a reference value held by the networking infrastructure device; and
transmit a response to the request, the response indicating that the integrity of the device is intact based on matching the representation of the device components and the reference value.
2 . The networking infrastructure device of claim 1 , wherein the networking infrastructure device is a network processing unit included in a node of a network.
3 . The networking infrastructure device of claim 1 , wherein the networking infrastructure device is a switch or gateway.
4 . The networking infrastructure device of claim 3 , wherein the processing circuitry is configured to:
receive a second request to verify integrity of a second device; compare a second representation of second device components with a second reference value held by the networking infrastructure device; and block traffic to or from the second device based on a failure to match the second representation of the second device components and the second reference value.
5 . The networking infrastructure device of claim 1 , wherein the networking infrastructure device includes a database of reference values, an entry in the database corresponding with a device image.
6 . The networking infrastructure device of claim 5 , wherein the device image is a vector of values, a dimension in the vector corresponding to a component of the device that is verified when the integrity of the device is verified.
7 . The networking infrastructure device of claim 6 , wherein a value in a dimension is a hash of the component.
8 . The networking infrastructure device of claim 5 , wherein the processing circuitry is configured to:
receive a new entry to the database from a remote attestation server; and update the database with the new entry to enable verification of device integrity while a connection to the remote attestation server is unavailable.
9 . The networking infrastructure device of claim 1 , wherein, to obtain the representation of device components, the processing circuitry is configured to receive the representation of the device components from secure hardware on the device in response to an event.
10 . The networking infrastructure device of claim 9 , wherein the event is a boot event of the device.
11 . The networking infrastructure device of claim 9 , wherein the secure hardware is a networked processing unit of the device.
12 . The networking infrastructure device of claim 1 , wherein the request to verify the integrity of the device is a subscription from a second device; and wherein the comparison of the representation of the device components and transmission of the response are based on obtaining the representation of the device components.
13 . At least one non-transitory machine readable medium including instructions for localized device attestation, the instructions, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:
receiving, at a networking infrastructure device, a request to verify integrity of a device; obtaining a representation of device components of the device; comparing the representation of the device components with a reference value held by the networking infrastructure device; and transmitting a response to the request, the response indicating that the integrity of the device is intact based on matching the representation of the device components and the reference value.
14 . The least one non-transitory machine readable medium of claim 13 , wherein the networking infrastructure device is a networked processing unit included in a node of a network.
15 . The least one non-transitory machine readable medium of claim 13 , wherein the networking infrastructure device is a switch or gateway.
16 . The least one non-transitory machine readable medium of claim 15 , wherein the operations comprise:
receiving a second request to verify integrity of a second device; comparing a second representation of second device components with a second reference value held by the networking infrastructure device; and blocking traffic to or from the second device based on a failure to match the second representation of the second device components and the second reference value.
17 . The least one non-transitory machine readable medium of claim 13 , wherein the networking infrastructure device includes a database of reference values, an entry in the database corresponding with a device image.
18 . The least one non-transitory machine readable medium of claim 17 , wherein the device image is a vector of values, a dimension in the vector corresponding to a component of the device that is verified when the integrity of the device is verified.
19 . The least one non-transitory machine readable medium of claim 18 , wherein a value in a dimension is a hash of the component.
20 . The least one non-transitory machine readable medium of claim 17 , wherein the operations comprise:
receiving a new entry to the database from a remote attestation server; and updating the database with the new entry to enable verification of device integrity while a connection to the remote attestation server is unavailable.Join the waitlist — get patent alerts
Track US2023140252A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.