Platform Attestation via Secure Enclave Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers face challenges in ensuring the security and authenticity of software running on remote platforms, particularly in verifying the trustworthiness of applications and enclaves across distributed server environments, due to the lack of effective attestation and registration mechanisms.

Innovation Solution

The implementation of an attestation system that utilizes secure enclaves and provisioning systems to generate and manage attestation keys, enabling secure attestation and registration of platforms, applications, and enclaves through cryptographic mechanisms, ensuring the authenticity and security of software environments across multiple packages and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If service providers deploy software and services over the Internet, then service delivery capability is improved, but security and authenticity verification of remote platforms deteriorates

Engineering Contradiction:
Improveservice delivery capabilityVSAvoidsecurity and authenticity verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an attestation system as an intermediary between service providers and remote platforms. This system includes attestation keys, platform certificates, and verification mechanisms that mediate the trust relationship, allowing service providers to verify the authenticity and security state of remote platforms without direct access, thus resolving the contradiction between remote service delivery and security verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary attestation and registration actions before software deployment. Platforms must undergo attestation to obtain certificates and service providers must verify these certificates before provisioning applications. This preliminary verification establishes trust beforehand, enabling secure remote service delivery without compromising security

Inventive Principle:
Principle #10Preliminary action

2Reliability

If attestation and registration mechanisms are implemented across distributed server environments, then security verification is improved, but system complexity deteriorates

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal attestation framework that can be applied across different distributed server environments and platform configurations. The attestation system uses standardized certificates and verification protocols that work across multiple packages and networks, reducing the need for environment-specific security implementations and thereby managing complexity while maintaining broad security verification capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11489678B2Platform attestation and registration for servers
Publication Date: 2022.11.01 INTEL CORP
  • US11489678B2 patent drawing
  • US11489678B2 patent drawing
  • US11489678B2 patent drawing

AI summary

Embodiments include systems, methods, computer readable media, and devices configured to, for a first processor of a platform, generate a platform root key; create a data structure to encapsulate the platform root key, the data structure comprising a platform provisioning key and an identification of a registration service; and transmit, on a secure connection, the data structure to the registration service to register the platform root key for the first processor of the platform. Embodiments include systems, methods, computer readable media, and devices configured to store a device certificate received from a key generation facility; receive a manifest from a platform, the manifest comprising an identification of a processor associated with the platform; and validate the processor using a stored device certificate.