Cross-Attestation for Electronic Device Security Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attestation methods in computer networks are inadequate for detecting security attacks that disable security components or reset measurement hashes, leading to incomplete information and unattainable verification in case of network tampering.
Innovation Solution
Cross-attestation among platforms is introduced, where security components collaborate to share measurement hashes, allowing a verifier to assess network conditions without directly challenging compromised platforms, by distributing PCR content among nodes and storing it for later validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional attestation methods are used where a verifier directly challenges a platform, then the verification process is simple and direct, but the system cannot detect security attacks that disable security components or reset measurement hashes
Solution Approach 1:
The patent divides the attestation system into multiple platforms, where each platform maintains measurement hashes of other platforms. This segmentation allows the verifier to query multiple sources rather than relying on a single platform's security component, thereby detecting attacks that disable individual components while increasing system complexity through distributed verification
Solution Approach 2:
The patent introduces intermediary platforms that store and provide measurement hashes of other platforms. When a platform's security component is compromised, these intermediary platforms serve as mediators to provide alternative verification sources, improving reliability while adding complexity through the intermediary verification layer
2Loss of information
If measurement hashes are stored only in local security components, then the storage is secure and simple, but the information is lost when security components are disabled or attacked
Solution Approach 1:
The patent merges the storage function of measurement hashes across multiple platforms. Each platform stores measurement hashes of other platforms in addition to its own, creating a combined distributed storage system that prevents total information loss when individual security components are attacked, while increasing storage complexity across the network
Solution Approach 2:
The patent implements beforehand cushioning by having platforms pre-store measurement hashes of other platforms before potential security attacks occur. This preparatory distribution of hash information ensures that if a security component is disabled during an attack, the measurement hashes are already preserved elsewhere in the system, preventing information loss while adding complexity to the pre-attack preparation process
3Measurement precision
If a verifier queries multiple platforms for attestation information, then comprehensive verification is achieved, but the communication overhead and verification time increase
Solution Approach 1:
The patent applies preliminary action by having platforms pre-compute and store measurement hashes of other platforms before verification is needed. When the verifier queries multiple platforms, the measurement hashes are already prepared and available, reducing the actual verification time while maintaining complete attestation information through multi-platform queries
Data Source
AI summary
A method includes providing, by a first electronic device, a first request to a second electronic device for the second electronic device to provide data to the first electronic device representing content that is stored in a security component of the second electronic device. The first electronic device receives the response from the second electronic device to the first request and, in response thereto, the first electronic device stores data in the first electronic device representing content that is stored in a security component of the second electronic device. The method includes performing cross-attestation. Performing the cross-attestation includes, in response to an attestation request that is provided by a verifier to the first electronic device, the first electronic device providing to the verifier data representing content that is stored in the security component of the first electronic device and data representing the content stored in the security component of the second electronic device.


