Runtime Monitoring via Hash-Locked Remote Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Trusted devices or systems incorporating commercial off-the-shelf components may be compromised by untrusted third-party hardware or software modules, leading to malicious operations and data exfiltration due to potential malware or trojans.

Innovation Solution

A runtime monitoring system utilizing trusted processors with primary and auxiliary oscillators to generate and correlate hashes, ensuring continuous real-time attestation of remote processing components by seeding op codes with unique challenges and comparing attestation responses to maintain alignment and detect unintended behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If commercial off-the-shelf components are used in trusted devices, then device complexity and cost are reduced, but system reliability and security are compromised due to potential malware or trojans in third-party components

Engineering Contradiction:
Improvesystem complexityVSAvoidsystem reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements continuous feedback loops where remote attestation responses are constantly monitored and compared against expected values. The system provides real-time feedback about the trust status of remote components, enabling dynamic adjustment of system behavior based on current security conditions rather than static pre-attestation checks

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary attestation mechanism that mediates between untrusted remote components and the trusted system. This intermediary layer verifies the integrity of remote components through cryptographic proof and challenge-response protocols, allowing COTS components to be used while maintaining security through the mediating verification layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous runtime monitoring is implemented to detect malicious operations, then system security is improved, but processing overhead and system performance are degraded

Engineering Contradiction:
Improvesystem securityVSAvoidprocessing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent employs periodic challenge-response attestation cycles rather than continuous monitoring. The trusted system periodically issues challenges to remote components and verifies responses at scheduled intervals, providing security assurance without requiring constant verification of every operation, thus reducing processing overhead while maintaining security

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent performs preliminary attestation verification by pre-computing expected attestation responses and comparing them against actual responses received from remote components. This preliminary comparison approach allows for efficient detection of tampering before malicious operations can execute, reducing the need for extensive continuous monitoring

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11347841B1System and method for runtime monitoring during hash-locked remote attestation
Publication Date: 2022.05.31 ROCKWELL COLLINS INC
  • US11347841B1 patent drawing
  • US11347841B1 patent drawing
  • US11347841B1 patent drawing

AI summary

A runtime monitoring system for a trusted computing environment is disclosed. In embodiments, the environment includes a trusted processor driven by a primary oscillator and a remote processing component driven by an auxiliary oscillator. A trusted reference hashing module hashes operating codes sent by the trusted processor for execution by the remote processing component; the received operating codes are also hashed by a trusted remote hashing module monitoring the remote processing component. A correlation module matches the remote and reference hashes and advances or delays the auxiliary oscillator to loop-lock the remote processing component to the trusted processor. The trusted processor periodically seeds the operating codes with a unique challenge having a unique hash response. The hash response received from the remote hashing module is checked against the reference hash response generated by the reference hashing module to verify that the remote processing component remains trusted and uncompromised.