Client Device Security Vulnerability Attribution via Trusted Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat protection solutions fail to effectively assess security vulnerabilities by not considering device configurations and may analyze spoofed configurations if a machine has been compromised, lacking verification from independent trustworthy third parties.

Innovation Solution

A method and system that receive and analyze security configuration information and malware state information for client devices using a security risk model, such as a trained machine learning model, to identify vulnerable devices and provide configuration updates to mitigate risks, with secure data validation through trusted platform modules and attestation servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If threat protection solutions analyze device configuration information, then security vulnerability assessment capability is improved, but reliability deteriorates when the machine has been compromised and configuration information is spoofed

Engineering Contradiction:
Improvesecurity vulnerability assessment capabilityVSAvoidtrustworthiness of configuration information
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a trusted third-party device as an intermediary to verify device configuration information. This mediator independently attests to the security state of the client device, preventing spoofed configurations from being accepted as valid. The verification process involves the third-party device examining security-relevant information and providing authenticated feedback to the threat protection system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification of device configuration information before using it for threat protection analysis. By pre-validating the authenticity and integrity of configuration data through trusted third-party attestation, the system ensures that only verified information is used for vulnerability assessment, preventing compromised devices from providing false configuration data.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If threat protection solutions consider device configuration and security states, then security vulnerability identification is improved, but system complexity increases due to multiple verification requirements

Engineering Contradiction:
Improvesecurity vulnerability identification accuracyVSAvoidverification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The client device itself participates in the verification process by providing security-relevant information to the trusted third-party device. The device's own security mechanisms (such as secure enclaves or trusted platform modules) enable self-attestation, reducing the need for external verification infrastructure and simplifying the overall system architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11531766B2Systems and methods for attributing security vulnerabilities to a configuration of a client device
Publication Date: 2022.12.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11531766B2 patent drawing
  • US11531766B2 patent drawing
  • US11531766B2 patent drawing

AI summary

This disclosure relates to systems, devices, and methods for receiving security configuration information and malware state information for a plurality of client devices, the security configuration information comprising identification of at least one of security parameters, hardware configurations, or software configurations of each of the plurality of client devices, and the malware state information comprising identification of at least one or more types of malware on each of the plurality of devices. The security configuration information and malware state information may be analyzed to identify which client devices from the plurality of devices have a security configuration that places the identified client devices in a vulnerable security state.