Composable Attestation Architecture for Flexible Trust Decisions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current attestation systems are inflexible and narrowly focused, unable to address complex scenarios involving diverse hardware and software platforms, and often compromise on privacy and completeness of measurement to meet varying trust requirements among parties.
Innovation Solution
A flexible attestation architecture that allows for the composition of composable components to handle complex attestation scenarios, where an attester examines and reports on the target system's properties independently, enabling secure and privacy-preserving trust decisions across heterogeneous networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing attestation systems are used, then specific narrow use-cases are addressed, but flexibility and adaptability to general attestation problems are lost
Solution Approach 1:
The attestation system is divided into separate functional components: a measurement component that collects system state data, an attestation component that evaluates measurements against policies, and a reporting component that communicates results. This segmentation allows each component to be independently configured and reused across different use-cases, providing flexibility without increasing overall system complexity.
Solution Approach 2:
The patent creates a universal attestation framework that can handle multiple types of attestation scenarios (remote attestation, local attestation, continuous attestation, on-demand attestation) through a single unified architecture. The measurement component, policy evaluation component, and reporting component work together in a standardized manner across all use-cases, eliminating the need for separate specialized systems for each scenario.
2Reliability
If the target system reports its own properties, then self-attestation is achieved, but reliability and trustworthiness of the information are compromised
Solution Approach 1:
The patent introduces a separate measurement component that acts as an intermediary between the target system and the attestation evaluator. This measurement component independently collects system state data and generates measurements without being influenced by the target system's self-reported information. The attestation component then evaluates these independent measurements against security policies, ensuring reliable and trustworthy attestation results.
3Loss of information
If comprehensive measurements are collected, then complete attestation information is obtained, but privacy concerns and information disclosure risks increase
Solution Approach 1:
The patent implements policy-based control over information disclosure where different levels of measurement detail are provided to different parties based on their authorization and trust relationships. The attestation system can selectively disclose specific measurement results or aggregate statistics while withholding sensitive detailed information, allowing complete attestation capability while protecting privacy through localized information release policies.
Solution Approach 2:
The system dynamically adjusts the level of measurement detail and information disclosure based on policy parameters and trust relationships. Policies can specify whether to report full system state, aggregated metrics, or only critical security-relevant information. This parameter-based control allows the same attestation infrastructure to provide different levels of information completeness while maintaining appropriate privacy protection for each scenario.
4Adaptability or versatility
If existing attestation systems are used, then specific properties are measured, but ability to address complex attestation scenarios is limited
Solution Approach 1:
The patent combines multiple attestation functionalities into a unified framework where a single measurement component can serve multiple attestation scenarios, a single policy evaluation component can handle different types of security policies, and a single reporting component can communicate with multiple parties. This merging reduces the effective number of components needed while expanding the system's capability to handle complex attestation scenarios including remote attestation, continuous monitoring, and multi-party verification.
Data Source
AI summary
An architecture and system are provided for flexible, composable attestation systems. Systems built according to this attestation architecture can be composed to accomplish complex attestation scenarios. The system is designed around composable components to permit flexible recombination. A system, method, and computer program product are provided for proving attestations to an appraiser regarding a target system. In an embodiment, an attestation request is sent from an appraiser to a target system, wherein the attestation request includes queries regarding properties of the target system needed by the appraiser to make trust decisions regarding the target system. The attestation request is forwarded from the target system to an attester which collects the requested data. The attester sends an attestation response to the appraiser, wherein the response includes at least information regarding properties of the target system requested by the appraiser in order to make a trust decision regarding the target system.


