Attestation Protocol Cryptographic Binding for Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attestation protocols are vertically integrated, costly, and cumbersome for device vendors and validating entities due to the need for hardware-specific porting and support of multiple protocols, creating commercial barriers and inefficiencies as secure systems grow larger.
Innovation Solution
A method using a Trusted Platform Module (TPM) to generate and cryptographically bind device-specific and application-specific attestation messages, allowing verification without requiring protocol-specific hardware, enabling standardized attestation across interacting entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vertically integrated attestation protocols are used, then device-specific security requirements are met, but device complexity and cost increase for vendors and validating entities
Solution Approach 1:
The patent implements a universal attestation protocol that can validate multiple device types (smartphones, tablets, wearables, IoT devices) through a single standardized interface. The validating entity uses one protocol to attest any device, eliminating the need for multiple device-specific protocol implementations while maintaining security requirements through device-agnostic measurement collection and verification
2Measurement precision
If hardware-specific attestation porting is required, then attestation accuracy is maintained, but adaptability to changing market conditions deteriorates
Solution Approach 1:
The patent extracts the device-specific hardware details from the attestation protocol itself and places them in device-specific measurement collections that are generated dynamically. The protocol remains hardware-agnostic, collecting measurements through standardized interfaces while capturing device-specific characteristics through configurable measurement templates, allowing the same protocol to adapt to new device types without modification
3Adaptability or versatility
If multiple attestation protocols are supported, then compatibility with different systems is improved, but validating entity complexity and cost increase
Solution Approach 1:
The validating entity implements a single universal attestation protocol that can verify any device type. The protocol achieves broad system compatibility by using standardized measurement collections that can represent different device architectures (mobile, IoT, wearables) without requiring multiple protocol implementations. The device information and measurements are normalized into a common format for verification
4Reliability
If device-specific attestation implementations are used, then security requirements are met, but loss of time for implementation and maintenance increases
Solution Approach 1:
The patent establishes device-specific measurement collections and templates in advance during device provisioning or manufacturing. These pre-configured measurement templates capture essential security-relevant measurements for different device types. When attestation is needed, the validating entity simply collects measurements using these pre-defined templates rather than configuring device-specific attestation logic from scratch, significantly reducing implementation time while maintaining security requirements
Data Source
Figure 1~3
Figure 4
Figure 5
AI summary
A method comprises: a first data processing device requesting attestation of a second data processing device; the second data processing device generating a device-specific attestation message in dependence upon a device-specific key, a hardware configuration of the second data processing device and a software configuration of software running on the second data processing device; the second data processing device generating an application-specific attestation message in dependence upon an interaction protocol by which the first data processing device and the second data processing device interact; the second data processing device cryptographically binding the application-specific attestation message to the device- specific attestation message; the first data processing device verifying the application-specific attestation message, the verifying step comprising detecting a trusted status of the application- specific attestation message by verifying the device-specific attestation message cryptographically bound to the application-specific attestation message; and the first data processing device establishing an interaction with the second data processing device according to the interaction protocol, in dependence upon the verified application-specific attestation message.