Attestation Relay Circuitry for Secure Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attestation processes in processing systems face challenges in achieving improved security and resource efficiency, particularly in verifying the configuration and trustworthiness of devices without direct connections and detailed knowledge of expected software.
Innovation Solution
An apparatus and method that acts as a relay between relying party circuitry, attester circuitry, and verifier circuitry, facilitating attestation by transmitting attestation requests, evidence data, and results through interface circuitry, allowing for secure verification without direct connections and reducing processing overhead, while maintaining security policies through software authority circuitry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If direct connection between relying party and verifier is established for attestation verification, then verification security is improved, but device complexity and connection requirements increase
Solution Approach 1:
The patent introduces a relay device as an intermediary component that facilitates secure attestation verification without requiring direct connection between the relying party and verifier. The relay device receives attestation requests from the relying party, forwards them to the verifier, receives verification results, and relays them back, thereby maintaining security while reducing connection complexity requirements.
2Measurement precision
If detailed knowledge of expected software is required for attestation, then verification precision is improved, but adaptability to different software configurations decreases
Solution Approach 1:
The patent implements a universal attestation framework where the relay device and verification mechanism can handle multiple software configurations and types without requiring specific customization for each. The system uses standardized attestation requests and responses that can accommodate different software environments, thereby maintaining verification precision while enhancing adaptability.
Solution Approach 2:
The patent allows the attestation system to dynamically adjust verification parameters based on the software configuration being verified. Rather than requiring fixed detailed knowledge of expected software, the system can modify its verification approach according to the actual software present, maintaining security and precision while adapting to various configurations.
3Productivity
If offline verification is enabled for attestation, then resource efficiency is improved, but verification time may increase
Solution Approach 1:
The patent implements preliminary action by enabling the relay device to cache and store verification results from previous attestation operations. When the same or similar attestation requests are made, the system can retrieve pre-computed verification results, thereby reducing the time required for verification while maintaining security and improving resource efficiency.
Data Source
AI summary
Aspects of the present disclosure relate to an apparatus comprising first interface circuitry to communicate with relying party circuitry, the first interface circuitry being configured to receive, from the relying party circuitry, an attestation request in respect of a processing operation requested by attester circuitry to be performed by the relying party circuitry; second interface circuitry to communicate with the attester circuitry, the second interface circuitry being configured to: transmit the attestation request to the attester circuitry; and receive, from the attester circuitry, evidence data associated with the processing operation, and third interface circuitry to communicate with verifier circuitry, the third interface circuitry being configured to: transmit the evidence data to the verifier circuitry; and receive, from the verifier circuitry, attestation result data indicative of a verification of the evidence data, wherein the first interface circuitry is configured to transmit the attestation result data to the relying party circuitry.


