Attestation Facilitation Component for Secure Memory Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure computer systems face challenges in ensuring the secure state of secure memory applications (SMAs) across different types of secure platforms and health attestation services, requiring specific coding for each platform and service, limiting flexibility and interoperability.

Innovation Solution

An attestation facilitation component is instantiated to identify and customize properties of secure platforms and health attestation services, verifying the secure state of SMAs and generating quotes that can be used by remote applications to verify the security of both the platform and SMA, allowing for multiple platform and service types to be utilized without needing separate coding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If separate coding is implemented for each secure platform and health attestation service type, then security verification accuracy is improved, but system complexity and development time increase

Engineering Contradiction:
Improvesecurity verification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal attestation facilitation component that can work with multiple types of secure platforms and health attestation services through a standardized interface. This component provides multi-functional capability to handle different platform types (e.g., Intel SGX, ARM TrustZone) and attestation services without requiring separate coding for each combination, thus reducing system complexity while maintaining security verification accuracy through proper abstraction and adaptation layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple secure platform types and health attestation services are supported, then system versatility is improved, but code complexity increases

Engineering Contradiction:
Improvesystem versatilityVSAvoidcode complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an attestation facilitation component as an intermediary layer between the secure memory application and the various secure platforms/attestation services. This mediator handles the complexity of multiple platform types and service protocols internally, while presenting a simplified, unified interface to the application. The intermediary translates between different platform-specific protocols and a standardized internal representation, enabling versatility without exposing code complexity to the application layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: the secure memory application, the attestation facilitation component, and the underlying secure platform/attestation service infrastructure. This segmentation allows each component to be developed and maintained independently, with the attestation facilitation component serving as an adapter layer that manages the diversity of platform types. Each segment has a specific responsibility, reducing overall code complexity while supporting multiple platform types.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If remote applications can verify secure state across different platforms, then interoperability is improved, but trust protocol complexity increases

Engineering Contradiction:
ImproveinteroperabilityVSAvoidtrust protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The attestation facilitation component acts as a trust intermediary that manages complex trust protocols between remote applications and various secure platforms. It standardizes the trust verification process by implementing a unified protocol interface that handles platform-specific trust mechanisms internally. This allows remote applications to verify secure states across different platforms without directly dealing with platform-specific trust protocol complexities, as the facilitation component translates and harmonizes the trust verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10482034B2Remote attestation model for secure memory applications
Publication Date: 2019.11.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10482034B2 patent drawing
  • US10482034B2 patent drawing
  • US10482034B2 patent drawing

AI summary

Instantiating an attestation facilitation component that allows a remote application to attest to a secure state of a secure memory application executing upon a secure platform of a computer system regardless of a type of either the secure platform or a health attestation service. Instantiation comprises identifying a property that includes at least one of the secure platform type and the health attestation service type. The instantiation is customized with the identified property. The attestation facilitation component verifies that a report generated by the secure platform represents that the secure memory application is operating in a secure state, and accesses a token generated by the health attestation service that represents that the secure platform is operating in a secure state. The attestation facilitation component generates a quote that allows the remote application to verify that the secure platform and the secure memory application are both operating in secure states.