Remote Attestation via Server Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As remote attestation of system trustworthiness is applied to more extensive scenarios, there is a risk of security breaches when network devices send measurement information to untrusted servers, potentially leading to large security risks.

Innovation Solution

A remote attestation method and apparatus that verify the system trustworthiness of a server before allowing it to obtain measurement information from a network device, ensuring that only trusted servers perform remote attestation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices send measurement information to multiple servers for remote attestation, then the coverage and applicability of remote attestation is improved, but the security risk increases due to potential untrusted servers

Engineering Contradiction:
Improvecoverage of remote attestationVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the first network device verify the system trustworthiness of the second network device (server) before sending measurement information. The verification of system trustworthiness measurement information is performed in advance to ensure the server is trusted, preventing security risks before they can occur while still allowing broad server participation in remote attestation

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If network devices verify system trustworthiness of servers before sending measurement information, then the security risk is reduced, but the complexity of the remote attestation process increases

Engineering Contradiction:
Improvesecurity riskVSAvoidremote attestation process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses the second network device (server) itself as an intermediary to perform the verification of system trustworthiness measurement information. The server receives measurement information, verifies it, and then determines whether to send it to the third network device. This mediator approach distributes the verification burden and simplifies the overall process architecture while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12314398B2Remote attestation method and apparatus
Publication Date: 2025.05.27 HUAWEI TECH CO LTD
  • US12314398B2 patent drawing
  • US12314398B2 patent drawing
  • US12314398B2 patent drawing

AI summary

This application discloses a remote attestation method and an apparatus. The method specifically includes: A first network device receives encrypted information and first measurement information of a second network device through the second network device, where the encrypted information is information obtained by encrypting second measurement information of a third network device; the first network device determines, based on the first measurement information, that the second network device is system-trusted; and the first network device decrypts the encrypted information to obtain the second measurement information.