Remote Attestation for Data Security and Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing data across computing devices are limited as they focus on isolating all applications rather than isolating secure applications from everything else, and are susceptible to malware that can circumvent anti-virus and firewall protections, leading to unauthorized access and data use.
Innovation Solution
Implementing a system that combines platform integrity with secure data management through data encryption and remote attestation, which involves installing application software on devices to encrypt data and perform remote attestation, taking inventory and content scans of the hardware and software stack, and comparing results to a statistically known-good configuration to detect anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing solutions isolate all applications from each other, then data security is improved, but system complexity and operational difficulty increase significantly
Solution Approach 1:
The system segments applications into secure and non-secure categories, applying isolation only where necessary. This selective segmentation maintains data security for sensitive applications while avoiding the complexity of isolating all applications, thereby resolving the contradiction between security and system complexity.
Solution Approach 2:
Different security measures are applied to different applications based on their sensitivity requirements. Secure applications receive isolation protections while non-secure applications operate without such overhead, creating local quality variations that reduce overall system complexity while maintaining necessary security.
2Reliability
If anti-virus and firewall software are deployed, then data protection is improved, but malware can circumvent these protections by modifying the underlying platform
Solution Approach 1:
The system performs preliminary actions by measuring and establishing a baseline configuration of the platform before malware can modify it. This baseline serves as a reference for detecting subsequent modifications, preventing malware from circumventing protections undetected.
Solution Approach 2:
The system continuously monitors platform configuration changes and provides feedback when deviations from the baseline are detected. This feedback mechanism enables real-time detection of malware modifications, countering the circumvention capability by alerting administrators to platform tampering.
3Reliability
If device-specific software and unique system images are implemented for each device type, then security customization is improved, but deployment time and resource requirements increase
Solution Approach 1:
The system implements a universal baseline configuration that can be deployed across multiple device types simultaneously. This single deployment approach provides consistent security customization across diverse devices without requiring separate deployment processes for each device type, thereby reducing deployment time while maintaining security effectiveness.
4Measurement precision
If comprehensive inventory and content scans are performed on hardware and software stack, then detection accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary scanning of the hardware and software stack to establish a baseline configuration before normal operation. This preliminary action captures the complete state once, and subsequent security checks compare against this baseline rather than performing full scans repeatedly, thereby maintaining high detection accuracy while reducing ongoing processing time.
Data Source
AI summary
The invention includes a system comprising a device, software installed on the device and coupled to the device's hardware and software stack to execute data encryption and remote attestation. The invention includes a process to configure the device for encryption and remote attestation and performing an initial inventory and content scan of the device's hardware and software stack with results transmitted across a communication network to the attestation server. The invention includes periodic inventory and content scans of the device's hardware and software stack with results transmitted again to the server via the network. The attestation server stores the results in a database for comparison to subsequent results sent by devices. The attestation server notes any differences in the most recent results and sends an alert to the device if the device is configured differently based on the previous scan, or configured the same if no differences were noted.


