Attestation Relay Circuitry for Secure Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attestation processes in processing systems face challenges in achieving improved security and resource efficiency, particularly in verifying the configuration and trustworthiness of devices without direct connections and detailed knowledge of expected software.

Innovation Solution

An apparatus and method that acts as a relay between relying party circuitry, attester circuitry, and verifier circuitry, facilitating attestation by transmitting attestation requests, evidence data, and results through interface circuitry, allowing for secure verification without direct connections and reducing processing overhead, while maintaining security policies through software authority circuitry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct connection between relying party and verifier is established for attestation verification, then verification security is improved, but device complexity and connection requirements increase

Engineering Contradiction:
Improveverification securityVSAvoidconnection requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a relay device as an intermediary component that facilitates secure attestation verification without requiring direct connection between the relying party and verifier. The relay device receives attestation requests from the relying party, forwards them to the verifier, receives verification results, and relays them back, thereby maintaining security while reducing connection complexity requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed knowledge of expected software is required for attestation, then verification precision is improved, but adaptability to different software configurations decreases

Engineering Contradiction:
Improveverification precisionVSAvoidsoftware configuration adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal attestation framework where the relay device and verification mechanism can handle multiple software configurations and types without requiring specific customization for each. The system uses standardized attestation requests and responses that can accommodate different software environments, thereby maintaining verification precision while enhancing adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent allows the attestation system to dynamically adjust verification parameters based on the software configuration being verified. Rather than requiring fixed detailed knowledge of expected software, the system can modify its verification approach according to the actual software present, maintaining security and precision while adapting to various configurations.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If offline verification is enabled for attestation, then resource efficiency is improved, but verification time may increase

Engineering Contradiction:
Improveresource efficiencyVSAvoidverification time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by enabling the relay device to cache and store verification results from previous attestation operations. When the same or similar attestation requests are made, the system can retrieve pre-computed verification results, thereby reducing the time required for verification while maintaining security and improving resource efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11595213B2Methods and apparatus for performing attestation
Publication Date: 2023.02.28 IZUMA TECH INC
  • US11595213B2 patent drawing
  • US11595213B2 patent drawing
  • US11595213B2 patent drawing

AI summary

Aspects of the present disclosure relate to an apparatus comprising first interface circuitry to communicate with relying party circuitry, the first interface circuitry being configured to receive, from the relying party circuitry, an attestation request in respect of a processing operation requested by attester circuitry to be performed by the relying party circuitry; second interface circuitry to communicate with the attester circuitry, the second interface circuitry being configured to: transmit the attestation request to the attester circuitry; and receive, from the attester circuitry, evidence data associated with the processing operation, and third interface circuitry to communicate with verifier circuitry, the third interface circuitry being configured to: transmit the evidence data to the verifier circuitry; and receive, from the verifier circuitry, attestation result data indicative of a verification of the evidence data, wherein the first interface circuitry is configured to transmit the attestation result data to the relying party circuitry.