Hardware Attestation via Identification Code Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing systems, physical access can lead to security breaches as malicious actors can attach untrusted hardware components, compromising the system's security, especially in co-location or on-premises scenarios where physical control is shared or lacking.

Innovation Solution

Incorporating a 'root of trust' hardware component, such as a management controller or attestation device, which verifies the identity of connected components by checking for an identification code, and disables untrusted components by disconnecting power or holding them in reset, ensuring only trusted hardware is operational.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If physical access controls are shared in co-location or on-premises scenarios, then device accessibility and resource utilization are improved, but security vulnerability increases due to potential physical tampering

Engineering Contradiction:
Improvedevice accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The attestation device performs verification of hardware components before they are allowed to operate in the computing system. The identification code is checked in advance during the attestation process, and only after successful verification is the component permitted to function, preventing potential security threats from executing malicious code

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attestation device acts as an intermediary between the hardware component and the computing system. It verifies the identification code of connected components and controls whether they should be allowed to operate, serving as a security gatekeeper that mediates access without preventing physical connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware components are verified through identification codes, then security is improved, but device complexity increases due to additional verification mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The attestation function is extracted as a separate, dedicated hardware component (the attestation device) rather than being integrated into the main computing system. This isolation simplifies the verification mechanism to a focused function of reading and validating identification codes, while the rest of the system continues to operate normally

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware component contains its own identification code and performs self-verification when connected to the computing system. The attestation device automatically reads and validates the code without requiring manual intervention or complex external verification processes

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10896266B1Computer hardware attestation
Publication Date: 2021.01.19 AMAZON TECH INC
  • US10896266B1 patent drawing
  • US10896266B1 patent drawing
  • US10896266B1 patent drawing

AI summary

Provided are systems and methods for hardware attestation. Hardware attestation can ensure that only trusted hardware components are being used in a computing system. In various implementations, the computing system can include a hardware component coupled to the motherboard, where the hardware component is independent of the main processor of the computing system. The hardware component can determine whether a particular component connected to the motherboard includes an identification code, where the identification code can be used to attest to an identity of the particular component. The hardware component can further determining whether the identification code matches an expected value. The hardware component can further configure the particular component based on whether the identification code matches the expected value.