Server Attestation via Trusted Credential Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing public key infrastructure systems lack a method to verify the integrity of servers after certificate issuance, allowing compromised servers to potentially exchange private data with client devices, as there is no way to determine if a server has been compromised post-certificate issuance.

Innovation Solution

A secure server utilizes a trusted third party, such as an attestation service, to securely establish communication with a client device by presenting a signed trusted credential, which is protected within a hardware secure module, ensuring the server's trustworthiness and preventing malware access, and the client device verifies this credential to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a server uses public key infrastructure with certificates to enable client access, then communication capability is expanded, but security reliability deteriorates because there is no way to verify server integrity after certificate issuance

Engineering Contradiction:
Improvecommunication capabilityVSAvoidserver security verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the server prove its clean state before receiving the certificate. The server executes clean boot components that measure and verify the integrity of operating system components during boot, and only then is the certificate issued. This pre-verification ensures that when the certificate is later presented to clients, the server has already demonstrated its integrity, resolving the contradiction by establishing reliability before communication capability is fully utilized

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary - a trusted third party authority - that issues certificates only after verifying the server's clean state through measured boot processes. This intermediary acts as a mediator between the server and clients, providing cryptographic proof that the server is trustworthy. The intermediary's verification process and certificate issuance resolve the reliability issue while maintaining the communication capability expansion enabled by public key infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a server is compromised after certificate issuance, then security is breached, but there is no detection mechanism to identify the compromise

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoidserver compromise detection
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback by having the server continuously provide cryptographic measurements of its operating system components to clients during communication. The server presents these measurements alongside its certificate, allowing clients to verify that the server's current state matches the state verified during certificate issuance. This ongoing feedback mechanism enables real-time detection of compromises, resolving the contradiction by making compromise detection feasible while maintaining efficient data exchange

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by establishing a baseline of trusted server state during the certificate issuance process. The trusted third party measures and records the server's clean state, creating a reference against which future server states can be compared. This preliminary establishment of trust criteria enables later detection of any deviations or compromises, solving the detection difficulty problem while preserving productive data exchange

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If traditional certificate verification is used, then server identity is authenticated, but integrity verification of the server state is impossible

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidserver state integrity information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies segmentation by separating identity verification from integrity verification. The certificate handles identity authentication while additional cryptographic measurements and attestation data handle integrity verification of the server's operating state. This segmentation allows both functions to be performed independently and combined, resolving the contradiction by preserving identity verification accuracy while preventing loss of integrity information through the addition of separate integrity proof mechanisms

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension to certificate verification by incorporating cryptographic measurements of operating system components and boot process states. Instead of relying solely on traditional certificate-based identity verification, the system adds a dimensional layer of integrity verification through measured boot attestations and runtime measurements. This dimensional expansion enables simultaneous verification of both identity and state integrity, resolving the contradiction between precise identity verification and integrity information preservation

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3061027B1Verifying the security of a remote server
Publication Date: 2019.10.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3061027B1 patent drawingFigure 1
  • EP3061027B1 patent drawingFigure 2
  • EP3061027B1 patent drawingFigure 3

AI summary

In one embodiment, a client device 110 may use an attestation service 140 to verify a secure server 120. The secure server 120 may receive a signed trusted credential 310 from an attestation service 140 validating the secure server 120 as trustworthy to a client device 110 seeking access. The secure server 120 may protect the signed trusted credential 310 in a server secure module 280.