Attestation Manifest Derivation for Coordinated Software Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current MEC deployments face challenges in coordinating software updates across disparate systems, leading to invalidation of device characteristics and authentication tokens, resulting in stale attestation statuses and inefficient orchestration.

Innovation Solution

The use of a software update package that derives a Reference Integrity Measurement (RIM) to create a RIM manifest, which is broadcast for re-verifying authentication tokens and cryptographic identities, and regenerates attestation tokens to reflect device state changes, improving coordination and reducing stale attestation statuses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software updates are deployed across MEC systems, then device functionality and security are improved, but device characteristics and authentication tokens become invalid, requiring complex re-attestation processes

Engineering Contradiction:
Improvesoftware update reliabilityVSAvoidattestation coordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent generates an attestation manifest before the software update is applied. This manifest contains pre-calculated integrity measurements and attestation information that will be valid after the update. By performing the attestation preparation in advance, the system avoids the complexity of coordinating re-attestation after the update, as the manifest is already ready to be presented and verified post-update without requiring complex coordination between multiple systems.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional attestation methods are used after software updates, then device security can be verified, but stale attestation statuses occur due to coordination delays between disparate systems

Engineering Contradiction:
Improvedevice security verificationVSAvoidattestation status staleness
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The attestation manifest is generated in advance, before the software update is applied to the device. This pre-generation ensures that the attestation information is current and accurate at the time of creation. When the update is applied and the manifest is later verified, there is no coordination delay or staleness issue because the manifest was created with the exact device state that will exist after the update, eliminating the time loss associated with post-update re-attestation coordination.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple systems coordinate software updates, then comprehensive device management is achieved, but authentication tokens and cryptographic identities become invalid, requiring complex re-synchronization

Engineering Contradiction:
Improvedevice management coordinationVSAvoidauthentication re-synchronization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the attestation information into a separate, self-contained attestation manifest that is generated before the software update. This manifest contains all necessary integrity measurements and attestation data that would otherwise need to be re-synchronized across multiple systems after the update. By taking out the attestation information as a独立 artifact, the system avoids the complexity of re-synchronizing authentication tokens and cryptographic identities across multiple coordinated systems, as the manifest can be independently verified without requiring complex inter-system coordination.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12481492B2Attestation manifest derivation and distribution using software update image
Publication Date: 2025.11.25 INTEL CORP
  • US12481492B2 patent drawing
  • US12481492B2 patent drawing
  • US12481492B2 patent drawing

AI summary

Various systems and methods for enabling derivation and distribution of an attestation manifest for a software update image are described. In an example, these systems and methods include orchestration functions and communications, providing functionality and components for a software update process which also provides verification and attestation among multiple devices and operators.