Every device attests its health through the same chain

Governance-chain integrity unified with supply-chain provenance. Zero-trust device health.

The gap

Health monitoring and supply chain provenance are treated as separate domains. A device's governance-chain integrity (credential freshness, revocation status, trust-slope anomalies) is monitored by security teams; its supply-chain provenance (PUF challenge-response, SBOM attestation, tamper-evident seals) is tracked by logistics teams. There is no unified primitive that treats governance-chain health and supply-chain health as a single composite assessment.

This separation means that a device with revoked credentials but valid SBOM can be operationally trusted, and a device with valid credentials but tampered seals can be operationally trusted — each domain missing the other's signal.

The invention

A health monitoring primitive unifying governance-chain integrity with supply-chain provenance into a single composite cross-domain fleet-health assessment. Governance-chain integrity monitoring detects credential expiration, revocation propagation gaps, and trust-slope anomalies that may indicate compromise or impersonation. Supply-chain monitoring verifies PUF challenge-response consistency, SBOM attestation with per-component vulnerability tracking, and tamper-evident seal continuity.

Composite fleet health assessment identifies systemic patterns: simultaneous trust-slope anomalies across multiple devices suggesting mesh-level compromise, correlation between supply-chain discrepancies and operational anomalies, and cross-agency health patterns. Zero-trust device management requires continuous health verification for continued mesh participation. Regulatory compliance integration routes governed health observations to authorized consumers.

The inventive step

Prior art separates device health (endpoint protection, MDM) from supply-chain provenance (tracking, auditing). The health composite treats both as governed observations in the same chain — a credential revocation and a tampered seal are both mutations evaluated through the same governance framework, producing a unified fleet-health assessment.

The departure is that health is not a per-system metric — it is a composite governed observation across governance-chain integrity and physical supply-chain provenance, evaluated through the same admissibility framework as every other mutation.

Alone, and in composition

On its own, the health composite provides unified fleet-health monitoring for defense readiness, industrial IoT fleet management, medical device fleet cybersecurity, and automotive ECU fleet compliance — any domain where both governance integrity and physical provenance matter.

In composition, health monitoring feeds into cascade propagation (health degradation is a cascade trigger) and governed actuation (compromised devices can be gracefully downgraded to non-executing mode).

AQ

Health is a composite governed observation across governance-chain integrity and physical supply-chain provenance, evaluated through the same admissibility framework.

No rights are granted by this page. Claim scope is determined by the claims as issued, and any license requires a separate written agreement.