Security Hardened Management Agent Device Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access to computing devices in a corporate or similar environment while ensuring security and compliance with desired access restrictions is challenging, as existing technologies struggle to verify the security state and enforce policies on devices effectively.

Innovation Solution

Implementing a secure boot process that generates measurements of loaded components and the security state of a computing device, using a hardened device management agent to communicate with an attestation service for verification, and enforcing policies received from a management service via a network, ensuring the device is secure and compliant with enterprise standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a computing device is allowed to access enterprise resources, then productivity and ease of operation are improved, but security and compliance control deteriorate

Engineering Contradiction:
Improveaccess to enterprise resourcesVSAvoidsecurity and compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification of the device management agent's security state through secure boot measurements and attestation services before granting access to enterprise resources. This advance verification ensures that only devices meeting security requirements can access resources, resolving the contradiction by preventing unauthorized access before it occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device management agent acts as an intermediary between the computing device and enterprise resources, mediating access control decisions. The agent verifies the device's security state through attestation and enforces compliance policies, allowing productive resource access while maintaining security and compliance through this intermediate verification layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security verification and policy enforcement are implemented, then reliability and security are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device management agent operates autonomously on the computing device, performing self-verification of security state through secure boot measurements and self-enforcement of compliance policies. This self-service approach reduces the need for complex external verification systems, as the device independently demonstrates its security posture to enterprise resources.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements verification only for critical security attributes through secure boot measurements and attestation, rather than comprehensive analysis of all device components. This partial verification approach provides sufficient security assurance while avoiding the complexity of exhaustive device analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If policy enforcement is strict, then security and compliance are improved, but ease of operation deteriorates

Engineering Contradiction:
Improvecompliance enforcementVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The device management agent continuously monitors the device's security state and provides feedback to enterprise resources through attestation. This real-time feedback mechanism allows automatic enforcement of compliance policies without manual intervention, maintaining strict security while improving ease of operation through automated decision-making that eliminates manual approval processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10803175B2Device attestation through security hardened management agent
Publication Date: 2020.10.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10803175B2 patent drawing
  • US10803175B2 patent drawing
  • US10803175B2 patent drawing

AI summary

A device boots in a secure manner that allows measurements reflecting which components are loaded during booting to be generated. Measurements of such components, as well as of a device management agent and the security state of the device, are also obtained. The device management agent accesses an attestation service for an enterprise, which is a collection of resources managed by a management service. The device management agent provides the obtained measurements to the attestation service, which evaluates the measurements and based on the evaluation determines whether the device is verified for use in the enterprise. The management service uses this verification to ensure that the device management agent is running in a secure manner, is accurately providing indications of the state of the device to the management service, and is implementing policy received from the management service.