Offline Remote Attestation for Isolated Compute Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote attestation techniques are not suitable for environments where compute nodes are isolated from the Internet, as they require network communication with a remote attestation server, which is not possible across an air gap.

Innovation Solution

The implementation of an offline attestation technique that allows remote attestation to be performed on compute nodes without internet access by using a shared secret and certificate information transferred via removable storage media across an air gap.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote attestation techniques are used to verify node identity and application integrity, then security and trust are ensured, but network connectivity to the Internet is required which is not available in isolated environments

Engineering Contradiction:
Improvesecurity and trustVSAvoidnetwork connectivity requirement
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-provisioning certificate information and shared secrets into the isolated compute nodes during manufacturing or initial setup. This allows the nodes to perform remote attestation offline without needing real-time network connectivity to certification authorities, thus resolving the contradiction between maintaining security verification and operating in isolated environments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing offline attestation certificates that contain pre-established trust relationships. These certificates act as intermediaries between the isolated node and external certification authorities, enabling verification without direct network connection while maintaining the security guarantees of remote attestation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If offline attestation is implemented using removable storage media, then Internet connectivity is not required, but the complexity of certificate information transfer increases

Engineering Contradiction:
Improveoffline operation capabilityVSAvoidcertificate information transfer process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the certification authority's public key and certificate information from the online environment and embeds it directly into offline attestation certificates that are provisioned into the isolated nodes. This extraction eliminates the need for complex real-time certificate validation processes in isolated environments, simplifying the offline operation while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If certificate information is pre-provisioned into isolated nodes, then remote attestation can be performed offline, but the initial setup process becomes more complex

Engineering Contradiction:
Improveoffline attestation operationVSAvoidinitial provisioning process
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by incorporating certificate information and shared secrets into the node's firmware or secure storage during the manufacturing or initial deployment phase. This upfront provisioning simplifies subsequent offline operations, as nodes can immediately perform remote attestation without requiring complex initial setup procedures in the isolated environment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12289417B2Establishing provenance of applications in an offline environment
Publication Date: 2025.04.29 FORTANIX INC
  • US12289417B2 patent drawing
  • US12289417B2 patent drawing
  • US12289417B2 patent drawing

AI summary

A platform identifier for a first node may be determined based on hardware characteristics of the first node. The platform identifier may be sent to a certification service via non-network communication. Certificate information associated with the platform identifier may be received from the certification service via non-network communication. A key pair may be generated at a first node application enclave of the first node. The key pair may include a public key of the first node and an associated private key of the first node. A request to generate a signed digital certificate may be sent to a digital certificate manager, the request including the public key of the first node and the certificate information. A signed digital certificate including the public key and the certificate information may be received from the digital certificate manager, and the signed digital certificate may be stored at the first node application enclave.