Mobile Attestation Metadata Binding for Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current attestation methods in computing and information security lack a comprehensive, policy-based system for managing and utilizing attestation data across mobile handsets, particularly in ensuring secure application execution, network access, and hardware feature usage, which can lead to vulnerabilities and inconsistent security measures.

Innovation Solution

A multiple-layer attestation system incorporating Application Attestation Metadata (AAM) bound to applications, utilizing a hierarchy of attestation authorities, and integrating attestation metadata within a policy-based system to manage and enforce security policies on mobile handsets, allowing for granular control over operations and resource access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a comprehensive policy-based attestation system is implemented, then security management and enforcement capability is improved, but device complexity and system overhead increase

Engineering Contradiction:
Improvesecurity management capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Policy Decision Point (PDP) server as an intermediary that centralizes attestation policy management and decision-making. The PDP receives attestation metadata from multiple attestation authorities, evaluates policies, and makes access decisions, thereby reducing the complexity burden on mobile devices while maintaining comprehensive security management capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments attestation management into multiple independent components: Application Attestation Metadata (AAM) bound to applications, hierarchy of attestation authorities, policy rules stored in the PDP, and enforcement points in the mobile device. This segmentation allows each component to be developed and maintained independently, reducing overall system complexity while providing comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple-layer attestation with Application Attestation Metadata is implemented, then security control granularity is improved, but processing overhead and performance impact increase

Engineering Contradiction:
Improvesecurity control granularityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs attestation metadata generation and policy evaluation in advance. The PDP pre-processes attestation metadata from multiple authorities and stores policy rules beforehand. When an application requests access, the enforcement point quickly retrieves pre-evaluated policies and metadata, significantly reducing real-time processing overhead while maintaining fine-grained security control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses Application Attestation Metadata (AAM) as a copyable, serializable representation of attestation information that can be bound to applications. This metadata copy contains essential security attributes that can be quickly evaluated without requiring complex real-time analysis of the original attestation sources, thus improving processing efficiency while maintaining security granularity.

Inventive Principle:
Principle #26Copying

3Reliability

If hierarchical attestation authorities are integrated, then trust verification robustness is improved, but system complexity and integration overhead increase

Engineering Contradiction:
Improvetrust verification robustnessVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PDP server merges attestation metadata from multiple hierarchical attestation authorities into a unified evaluation framework. Instead of requiring the mobile device to independently integrate and evaluate multiple authority outputs, the PDP consolidates these inputs, applies policy rules, and produces unified access decisions, thereby maintaining trust verification robustness while reducing device-side integration complexity.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If policy-based enforcement is implemented for each operation, then security policy compliance is improved, but processing time and operational overhead increase

Engineering Contradiction:
Improvepolicy complianceVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The enforcement point in the mobile device is designed to autonomously evaluate policies using pre-fetched attestation metadata and stored policy rules. Once policies are established and metadata is available, the enforcement point can make access decisions independently without requiring continuous external verification, thus maintaining high policy compliance while minimizing processing time for each operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9930071B2System and methods for secure utilization of attestation in policy-based decision making for mobile device management and security
Publication Date: 2018.03.27 SEQUITUR LABS INC
  • US9930071B2 patent drawing
  • US9930071B2 patent drawing
  • US9930071B2 patent drawing

AI summary

Policy-based client-server systems and methods for attestation in managing and securing mobile computing devices. Attestation provides the means to make efficient, secure, and reproducible use of knowledge possessed by trusted expert parties and authorities within the expression and enforcement of policies for controlling use of, and access to, onboard software and hardware, network capabilities, and remote assets and services. Aspects of secure attestation of applications that use shared and dynamically loaded libraries are presented, as well as potential business models for attestation used in such a policy-based system. The system of the present invention resolves attestation record conflicts using digital certificates and digital signatures.