Client Device Security Vulnerability Attribution via Trusted Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat protection solutions fail to effectively assess security vulnerabilities by not considering device configurations and may analyze spoofed configurations if a machine has been compromised, lacking verification from independent trustworthy third parties.
Innovation Solution
A method and system that receive and analyze security configuration information and malware state information for client devices using a security risk model, such as a trained machine learning model, to identify vulnerable devices and provide configuration updates to mitigate risks, with secure data validation through trusted platform modules and attestation servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If threat protection solutions analyze device configuration information, then security vulnerability assessment capability is improved, but reliability deteriorates when the machine has been compromised and configuration information is spoofed
Solution Approach 1:
The patent introduces a trusted third-party device as an intermediary to verify device configuration information. This mediator independently attests to the security state of the client device, preventing spoofed configurations from being accepted as valid. The verification process involves the third-party device examining security-relevant information and providing authenticated feedback to the threat protection system.
Solution Approach 2:
The system performs preliminary verification of device configuration information before using it for threat protection analysis. By pre-validating the authenticity and integrity of configuration data through trusted third-party attestation, the system ensures that only verified information is used for vulnerability assessment, preventing compromised devices from providing false configuration data.
2Measurement precision
If threat protection solutions consider device configuration and security states, then security vulnerability identification is improved, but system complexity increases due to multiple verification requirements
Solution Approach 1:
The client device itself participates in the verification process by providing security-relevant information to the trusted third-party device. The device's own security mechanisms (such as secure enclaves or trusted platform modules) enable self-attestation, reducing the need for external verification infrastructure and simplifying the overall system architecture.
Data Source
AI summary
This disclosure relates to systems, devices, and methods for receiving security configuration information and malware state information for a plurality of client devices, the security configuration information comprising identification of at least one of security parameters, hardware configurations, or software configurations of each of the plurality of client devices, and the malware state information comprising identification of at least one or more types of malware on each of the plurality of devices. The security configuration information and malware state information may be analyzed to identify which client devices from the plurality of devices have a security configuration that places the identified client devices in a vulnerable security state.


