Attestation Facilitation Component for Secure Memory Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure computer systems face challenges in ensuring the secure state of secure memory applications (SMAs) across different types of secure platforms and health attestation services, requiring specific coding for each platform and service, limiting flexibility and interoperability.
Innovation Solution
An attestation facilitation component is instantiated to identify and customize properties of secure platforms and health attestation services, verifying the secure state of SMAs and generating quotes that can be used by remote applications to verify the security of both the platform and SMA, allowing for multiple platform and service types to be utilized without needing separate coding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If separate coding is implemented for each secure platform and health attestation service type, then security verification accuracy is improved, but system complexity and development time increase
Solution Approach 1:
The patent implements a universal attestation facilitation component that can work with multiple types of secure platforms and health attestation services through a standardized interface. This component provides multi-functional capability to handle different platform types (e.g., Intel SGX, ARM TrustZone) and attestation services without requiring separate coding for each combination, thus reducing system complexity while maintaining security verification accuracy through proper abstraction and adaptation layers.
2Adaptability or versatility
If multiple secure platform types and health attestation services are supported, then system versatility is improved, but code complexity increases
Solution Approach 1:
The patent introduces an attestation facilitation component as an intermediary layer between the secure memory application and the various secure platforms/attestation services. This mediator handles the complexity of multiple platform types and service protocols internally, while presenting a simplified, unified interface to the application. The intermediary translates between different platform-specific protocols and a standardized internal representation, enabling versatility without exposing code complexity to the application layer.
Solution Approach 2:
The system is segmented into distinct functional components: the secure memory application, the attestation facilitation component, and the underlying secure platform/attestation service infrastructure. This segmentation allows each component to be developed and maintained independently, with the attestation facilitation component serving as an adapter layer that manages the diversity of platform types. Each segment has a specific responsibility, reducing overall code complexity while supporting multiple platform types.
3Adaptability or versatility
If remote applications can verify secure state across different platforms, then interoperability is improved, but trust protocol complexity increases
Solution Approach 1:
The attestation facilitation component acts as a trust intermediary that manages complex trust protocols between remote applications and various secure platforms. It standardizes the trust verification process by implementing a unified protocol interface that handles platform-specific trust mechanisms internally. This allows remote applications to verify secure states across different platforms without directly dealing with platform-specific trust protocol complexities, as the facilitation component translates and harmonizes the trust verification processes.
Data Source
AI summary
Instantiating an attestation facilitation component that allows a remote application to attest to a secure state of a secure memory application executing upon a secure platform of a computer system regardless of a type of either the secure platform or a health attestation service. Instantiation comprises identifying a property that includes at least one of the secure platform type and the health attestation service type. The instantiation is customized with the identified property. The attestation facilitation component verifies that a report generated by the secure platform represents that the secure memory application is operating in a secure state, and accesses a token generated by the health attestation service that represents that the secure platform is operating in a secure state. The attestation facilitation component generates a quote that allows the remote application to verify that the secure platform and the secure memory application are both operating in secure states.


