Remote Device Integrity Verification via Embedded Attestation Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote attestation schemes are vulnerable to corruption and resource-intensive, making it impractical for devices with limited resources to verify device integrity effectively.
Innovation Solution
A method where a client device generates a measurement result related to its status, uses it to create an attestation key, and encrypts data units based on this key, allowing a receiver to detect changes by attempting decryption, thereby verifying device integrity without additional computational resources or bandwidth usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote attestation schemes are used to verify device integrity, then device integrity can be remotely verified, but the measurements may be corrupted if they are easily identifiable and the scheme requires large amounts of resources
Solution Approach 1:
The patent extracts the measurement result from the original data unit and embeds it within the encrypted payload. Only the necessary encrypted portion is transmitted, while the measurement result remains embedded and protected within the data unit itself. This reduces the amount of data that needs to be transmitted and processed separately, thereby reducing resource consumption while maintaining verification capability.
Solution Approach 2:
The patent merges the measurement result with the encrypted data unit by embedding it within the payload. The measurement result is combined with the encrypted data in a single transmitted unit, eliminating the need for separate transmission channels or additional processing steps. This integration reduces overall resource consumption while preserving both the verification and encryption functions.
2Reliability
If measurements are embedded in easily identifiable locations, then remote verification can be performed, but the measurements may be corrupted by attackers
Solution Approach 1:
The patent applies local quality by embedding the measurement result within the encrypted payload of the data unit rather than placing it in a separate, easily identifiable location. The measurement result is positioned locally within the protected encrypted region, making it less susceptible to external tampering while maintaining its accessibility for verification purposes.
Solution Approach 2:
The patent applies preliminary anti-action by encrypting the measurement result within the data unit before transmission. This pre-encryption protection is applied in advance, creating a protective barrier against potential corruption or tampering by attackers during transmission and storage, while still allowing legitimate verification when the proper decryption keys are available.
3Reliability
If traditional remote attestation schemes are used, then device integrity can be verified, but additional computational resources and bandwidth are required
Solution Approach 1:
The patent merges the measurement result with the encrypted data unit, allowing both to be transmitted and processed together in a single operation. This consolidation eliminates the need for separate computational steps to handle measurement extraction, transmission, and verification, thereby reducing the overall computational resource usage and energy consumption while maintaining verification integrity.
Solution Approach 2:
The patent extracts and embeds the measurement result within the encrypted payload, eliminating the need for separate transmission channels or additional processing infrastructure. This extraction and integration approach reduces bandwidth requirements and computational overhead by handling everything within the existing encrypted data flow, thereby reducing energy consumption.
Data Source
AI summary
A computer-implemented method for use by a client device is provided. The client device comprises a memory and is configured to send data according to a cryptographic protocol that uses a key. The method comprises: generating a data unit and a seed related to the data unit; generating a measurement result of the client device related to the seed; generating an attestation key based on the measurement result and a key that is agreed in accordance with the cryptographic protocol; encrypting the data unit at least in part based on the attestation key; and generating an output comprising the encrypted data unit. Related methods for use by a server device and a network component, and related client device, server device and network component are also provided.


