Offline Attestation Device for Network-Disrupted Computers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote attestation methods rely on network connectivity, making it impossible to verify the security health status of computers during network disruptions.

Innovation Solution

A portable device, referred to as a 'verifier on a stick,' performs remote attestation procedures offline using a USB or other interfaces, such as HID, NFC, and serial connections, and provides immediate security status indication through LEDs, displays, or wireless communication, with an internal memory for result storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote attestation relies on network connectivity, then security verification can be performed continuously, but verification becomes impossible during network disruptions

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidoperational capability during network disruption
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the remote attestation function into two parts: a portable verification device that can operate offline and a computer system that stores security credentials. This segmentation allows the verification function to be performed locally without network dependency, while maintaining the ability to perform remote attestation when network is available.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The portable verification device acts as an intermediary between the computer system and the verification authority. It stores trusted security credentials (TPM public keys, certificates) locally and can perform verification operations independently, mediating between the need for continuous verification and the reality of network disruptions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a portable verification device is used, then offline security checking is enabled, but device complexity increases

Engineering Contradiction:
Improveoffline verification capabilityVSAvoidportable device structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The portable verification device is designed to perform multiple functions: storing security credentials, performing remote attestation verification, providing security indication, and storing verification results. This multi-functionality reduces the need for separate devices for each function, thereby managing complexity while enhancing capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The portable verification device contains all necessary verification credentials and processing capabilities within itself, making it self-sufficient for offline verification operations. It does not require external infrastructure or continuous network connection to perform its core function, thereby simplifying the overall system architecture despite the added portability features.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If security credentials are stored locally in the portable device, then offline verification is possible, but security risk increases if the device is compromised

Engineering Contradiction:
Improveoffline attestation capabilityVSAvoidsecurity exposure to physical attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs security verification before allowing network reconnection or sensitive operations. By checking the security health status in advance using the portable device, potential compromises are detected before they can lead to further security incidents, thereby mitigating the risk of storing credentials locally.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The portable verification device provides immediate feedback on the security health status of the computer system through security indication. This feedback mechanism allows operators to take corrective actions based on verification results, creating a closed-loop security system that continuously monitors and responds to potential compromises.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4617929A1Offline device attestation using a small, portable device
Publication Date: 2025.09.17 ABB (SCHWEIZ) AG
  • EP4617929A1 patent drawingFigure 1~4
  • EP4617929A1 patent drawing
  • EP4617929A1 patent drawing

AI summary

The invention relates to the field of security measures, particularly for checking and/or for signalling a security health status of a computer. The invention further relates to device for realizing this, to a use, to a method, to a non-transitory computer-readable storage medium, and to an application program, App. The invention relates to a device (10) for checking and/or signalling a security health status of a computer (20). The device (10) comprises a security checking unit (12), configured for performing a remote attestation procedure in cooperation with the computer (20); an interface (16) configured for connecting to the computer (20); and a security indication unit (14), configured for indicating the security health status of the computer (20).