Remote Attestation via Server Trust Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As remote attestation of system trustworthiness is applied to more extensive scenarios, there is a risk of security breaches when network devices send measurement information to untrusted servers, potentially leading to large security risks.
Innovation Solution
A remote attestation method and apparatus that verify the system trustworthiness of a server before allowing it to obtain measurement information from a network device, ensuring that only trusted servers perform remote attestation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network devices send measurement information to multiple servers for remote attestation, then the coverage and applicability of remote attestation is improved, but the security risk increases due to potential untrusted servers
Solution Approach 1:
The patent applies preliminary action by having the first network device verify the system trustworthiness of the second network device (server) before sending measurement information. The verification of system trustworthiness measurement information is performed in advance to ensure the server is trusted, preventing security risks before they can occur while still allowing broad server participation in remote attestation
2Object-affected harmful factors
If network devices verify system trustworthiness of servers before sending measurement information, then the security risk is reduced, but the complexity of the remote attestation process increases
Solution Approach 1:
The patent uses the second network device (server) itself as an intermediary to perform the verification of system trustworthiness measurement information. The server receives measurement information, verifies it, and then determines whether to send it to the third network device. This mediator approach distributes the verification burden and simplifies the overall process architecture while maintaining security
Data Source
AI summary
This application discloses a remote attestation method and an apparatus. The method specifically includes: A first network device receives encrypted information and first measurement information of a second network device through the second network device, where the encrypted information is information obtained by encrypting second measurement information of a third network device; the first network device determines, based on the first measurement information, that the second network device is system-trusted; and the first network device decrypts the encrypted information to obtain the second measurement information.


