Secure Platform State Reporting via Cryptographic Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securely obtaining platform state information from computing devices are inadequate, as they often rely on untrusted software and lack effective verification mechanisms, making it difficult for IT services to ensure the integrity and trustworthiness of the information, especially in scenarios where zero-touch provisioning is involved.

Innovation Solution

A communication system that allows a remote server to securely request and verify platform state information from a computing device using a cryptographic algorithm and a shared key, enabling untrusted software to report state information and ensuring its integrity through a response signature verification process, even in the absence of a trusted execution environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If untrusted software is used to obtain platform state information, then ease of operation is improved, but reliability deteriorates due to lack of verification mechanisms

Engineering Contradiction:
Improveease of obtaining state informationVSAvoidintegrity of state information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cryptographic intermediary mechanism where the processor generates a cryptographic response based on the platform state information. This cryptographic response acts as a mediator that allows untrusted software to access state information while maintaining reliability through cryptographic verification at the remote server

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the platform state information into a different parameter form (cryptographic response) that preserves the essential verification capability while changing the representation. The cryptographic response is generated by applying a cryptographic algorithm to the state information, allowing verification without exposing the raw state data

Inventive Principle:
Principle #35Parameter changes

2Reliability

If expensive secure solutions like Trusted Execution Technology are implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvetrustworthiness verificationVSAvoidcomplexity of security infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the processor itself to provide security verification services through built-in cryptographic capabilities. The processor generates cryptographic responses using its own cryptographic algorithm and shared key, eliminating the need for external trusted execution environments or additional security hardware

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a cryptographic copy or representation of the platform state information that can be verified remotely. Instead of requiring the remote server to trust the actual state information or implement complex verification infrastructure, a cryptographic response is generated that serves as a verifiable copy of the state's integrity

Inventive Principle:
Principle #26Copying

3Reliability

If cryptographic verification is implemented, then reliability is improved, but use of energy increases due to cryptographic computations

Engineering Contradiction:
Improveintegrity verificationVSAvoidenergy for cryptographic operations
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements selective cryptographic verification where only specific platform state information relevant to the remote server's needs is cryptographically processed. The system determines which state information to report and generates cryptographic responses only for those specific elements, rather than cryptographically verifying all possible state information

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11765239B2Secure reporting of platform state information to a remote server
Publication Date: 2023.09.19 INTEL CORP
  • US11765239B2 patent drawing
  • US11765239B2 patent drawing
  • US11765239B2 patent drawing

AI summary

Technologies disclosed herein provide a method for receiving at a device from a remote server, a request for state information from a first processor of the device, obtaining the state information from one or more registers of the first processor based on a request structure indicated by a first instruction of a software program executing on the device, and generating a response structure based, at least in part, on the obtained state information. The method further includes using a cryptographic algorithm and a shared key established between the device and the remote server to generate a signature based, at least in part, on the response structure, and communicating the response structure and the signature to the remote server. In more specific embodiments, both the response structure and the request structure each include a same nonce value.