Cross-Attestation for Electronic Device Security Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attestation methods in computer networks are inadequate for detecting security attacks that disable security components or reset measurement hashes, leading to incomplete information and unattainable verification in case of network tampering.

Innovation Solution

Cross-attestation among platforms is introduced, where security components collaborate to share measurement hashes, allowing a verifier to assess network conditions without directly challenging compromised platforms, by distributing PCR content among nodes and storing it for later validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional attestation methods are used where a verifier directly challenges a platform, then the verification process is simple and direct, but the system cannot detect security attacks that disable security components or reset measurement hashes

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidattestation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the attestation system into multiple platforms, where each platform maintains measurement hashes of other platforms. This segmentation allows the verifier to query multiple sources rather than relying on a single platform's security component, thereby detecting attacks that disable individual components while increasing system complexity through distributed verification

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary platforms that store and provide measurement hashes of other platforms. When a platform's security component is compromised, these intermediary platforms serve as mediators to provide alternative verification sources, improving reliability while adding complexity through the intermediary verification layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If measurement hashes are stored only in local security components, then the storage is secure and simple, but the information is lost when security components are disabled or attacked

Engineering Contradiction:
Improvemeasurement hash availabilityVSAvoiddistributed storage complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges the storage function of measurement hashes across multiple platforms. Each platform stores measurement hashes of other platforms in addition to its own, creating a combined distributed storage system that prevents total information loss when individual security components are attacked, while increasing storage complexity across the network

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements beforehand cushioning by having platforms pre-store measurement hashes of other platforms before potential security attacks occur. This preparatory distribution of hash information ensures that if a security component is disabled during an attack, the measurement hashes are already preserved elsewhere in the system, preventing information loss while adding complexity to the pre-attack preparation process

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Measurement precision

If a verifier queries multiple platforms for attestation information, then comprehensive verification is achieved, but the communication overhead and verification time increase

Engineering Contradiction:
Improveattestation information completenessVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having platforms pre-compute and store measurement hashes of other platforms before verification is needed. When the verifier queries multiple platforms, the measurement hashes are already prepared and available, reducing the actual verification time while maintaining complete attestation information through multi-platform queries

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11290471B2Cross-attestation of electronic devices
Publication Date: 2022.03.29 HEWLETT PACKARD LTD
  • US11290471B2 patent drawing
  • US11290471B2 patent drawing
  • US11290471B2 patent drawing

AI summary

A method includes providing, by a first electronic device, a first request to a second electronic device for the second electronic device to provide data to the first electronic device representing content that is stored in a security component of the second electronic device. The first electronic device receives the response from the second electronic device to the first request and, in response thereto, the first electronic device stores data in the first electronic device representing content that is stored in a security component of the second electronic device. The method includes performing cross-attestation. Performing the cross-attestation includes, in response to an attestation request that is provided by a verifier to the first electronic device, the first electronic device providing to the verifier data representing content that is stored in the security component of the first electronic device and data representing the content stored in the security component of the second electronic device.