Cryptographic Key Reuse for Application Clip Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application attestation systems require duplicate verification processes for application clips and full applications, leading to inefficiencies and resource wastage, as the cryptographic key for the application clip is deleted during the installation of the full application, necessitating repeated attestation verification.

Innovation Solution

A method where the computing device stores the cryptographic key associated with the application clip in a key database, allowing it to be reused for the full application during an upgrade event, thereby eliminating the need for repeated attestation verification by associating the key with the full application, enabling continuous attestation using the existing cryptographic key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the cryptographic key for the application clip is deleted during installation of the full application, then the full application can be installed, but the attestation verification must be repeated causing time and resource waste

Engineering Contradiction:
Improveattestation verification efficiencyVSAvoidtime for repeated attestation verification
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The cryptographic key is certified and stored in the key database before the full application is installed. This preliminary certification action allows the attestation to be performed once for the application clip, and the same certified key can be reused when the full application is installed, eliminating the need for repeated attestation verification and saving time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The same cryptographic key serves multiple functions: it is used for attestation verification of the application clip and then reused for attestation verification of the full application. This multi-functionality of the cryptographic key eliminates redundant verification processes and improves overall attestation efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If duplicate verification processes are performed for application clips and full applications, then each version can be independently verified, but resource wastage occurs

Engineering Contradiction:
Improveattestation verification reliabilityVSAvoidcomputational resources for duplicate verification
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The verification processes for the application clip and full application are merged by using the same cryptographic key for both. Instead of performing separate independent verifications, the system combines the verification into a single process that validates both versions, reducing computational resource consumption while maintaining verification reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Instead of discarding the cryptographic key certification after verifying the application clip, the system recovers and reuses the same certified key for verifying the full application. This recovery and reuse of the cryptographic key certification eliminates duplicate verification efforts and reduces energy consumption.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS11985231B2Integrity attestation for application clips
Publication Date: 2024.05.14 APPLE INC
  • US11985231B2 patent drawing
  • US11985231B2 patent drawing
  • US11985231B2 patent drawing

AI summary

Certain embodiments disclosed herein provide attestation for a transient version of an application while reusing the attestation and the cryptographic key on which the attestation is based for the full version of the application should the user obtain the full version of the application prior to the transient version being deleted. As an example, a computing device can detect an upgrade event corresponding to replacing an application clip with the full version of the application, and associate the cryptographic key already stored in a key database with the full version of the application. Associating the existing key with the full version of the application enables the full application to automatically take over the attestation previously provided for the application clip, saving time and resources that would otherwise be used for establishing a new attestation for the full version of the application.