Extending Chain of Trust to Application Routines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems fail to ensure that the chain of trust is extended to specific application routines within computing devices, leaving them vulnerable to interference from other routines and potential execution on unauthorized devices.

Innovation Solution

A method is implemented to form a unidirectional secure pipeline between computing devices, which is then extended to a particular application routine, and subsequently converted to a bidirectional secure pipeline, ensuring secure communications by verifying security credentials and signatures at both the pipeline and application levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure communications are established between two devices, then communication security is improved, but vulnerability to interference from other routines within the devices remains

Engineering Contradiction:
Improvecommunication securityVSAvoidinterference from other routines
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the trust verification process into two distinct levels: device-level verification (between computing devices) and application-level verification (within the application routine). This segmentation allows the system to independently verify both the device's ability to form secure pipelines and the application's execution environment, thereby addressing interference from other routines while maintaining communication security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extends the chain of trust from a single device-to-device dimension to a two-dimensional verification system that includes both device-level attestation and application-level attestation. This dimensional expansion ensures that security is verified not only between devices but also within the specific application context, preventing interference from other routines.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If secure pipeline is formed between devices, then trust between devices is established, but verification of application execution location is lost

Engineering Contradiction:
Improvedevice trustVSAvoidapplication execution verification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs preliminary verification of the application's execution environment before establishing secure communications. The application routine verifies its own execution context and generates attestation data proving it is running in the intended environment. This preliminary action ensures that even if device-level trust is established, the system can still detect if the application is executed on an unauthorized device or in an unauthorized environment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the application routine provides attestation data back to the remote device, confirming its execution environment. This feedback loop ensures that the remote device can verify not only that the local device is trustworthy but also that the specific application is executing in the intended location, preventing loss of execution verification information.

Inventive Principle:
Principle #23Feedback

3Reliability

If chain of trust is extended to application routine, then security against unauthorized execution is improved, but system complexity increases

Engineering Contradiction:
Improveexecution securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service verification where the application routine independently verifies its own execution environment and generates its own attestation data. Rather than requiring a complex external verification system, the application itself performs the verification, reducing system complexity while maintaining security against unauthorized execution.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal attestation framework that can be applied to any application routine within any secure pipeline. The same verification mechanisms and data structures are used regardless of the specific application or device, reducing overall system complexity through standardization while maintaining execution security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11374930B2Techniques for extending communications chain of trust to client applications
Publication Date: 2022.06.28 INTEL CORP
  • US11374930B2 patent drawing
  • US11374930B2 patent drawing
  • US11374930B2 patent drawing

AI summary

Various embodiments are generally directed to techniques to form secure communications between two computing devices in which the chain of trust of those communications is extended to a particular application routine executed by one of the two computing devices. An apparatus includes a processor component; a verifying component to verify a link attestation credential received from a server to verify an ability of the server to form a secure pipeline, and to signal an application routine with an indication of a result of the verification by the verifying component; and a hash component to generate a return hash of a return signature associated with the application routine to indicate to the server that the application routine has also verified the link attestation credential to form the secure pipeline between the server and the application routine. Other embodiments are described and claimed.