Trusted Platform Module Remote Attestation for Enterprise Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing integrity verification techniques for client computing devices are cumbersome and intrusive, lacking a non-invasive method for remote attestation to ensure the devices' legitimacy and compliance with enterprise standards.
Innovation Solution
A client computing device equipped with a trusted platform module (TPM) that stores endorsement, attestation, and enterprise-specific keys, enabling remote platform verification by providing identifying information to a platform verification server without sharing it with the application server, ensuring privacy and compliance verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical verification of client computing devices is performed, then integrity verification reliability is improved, but user privacy is compromised and operational convenience deteriorates
Solution Approach 1:
The patent introduces a platform verification server as an intermediary between the enterprise and client computing devices. This server performs remote attestation by verifying TPM measurements and cryptographic proofs without requiring physical access to devices, thereby maintaining verification reliability while eliminating the intrusiveness of physical inspections and preserving user privacy.
Solution Approach 2:
The patent replaces the mechanical/physical verification process with a cryptographic and software-based remote attestation system. Instead of administrators physically accessing devices to check integrity, the system uses TPM-generated cryptographic proofs, digital signatures, and secure communication protocols to verify device integrity remotely, eliminating the need for physical presence while maintaining verification effectiveness.
2Reliability
If physical verification of client computing devices is performed, then integrity verification reliability is improved, but privacy intrusion increases
Solution Approach 1:
The platform verification server acts as a privacy-respecting intermediary that verifies device integrity through cryptographic proofs without exposing sensitive user information. The server validates TPM measurements and device state while maintaining confidentiality of user data, thus achieving reliable verification without the privacy intrusion inherent in physical inspections where administrators would directly access user devices and potentially observe private information.
Solution Approach 2:
The system creates and verifies cryptographic copies (attestation proofs) of device integrity state rather than requiring direct physical access to the actual device. The TPM generates cryptographic representations of device measurements and configuration that can be verified remotely, allowing integrity verification without physically accessing or observing the actual user environment, thereby preserving privacy.
Data Source
AI summary
Systems and methods for enterprise platform verification are provided. In some aspects, a computing device includes a trusted platform module (TPM). The TPM includes an endorsement key (EK) physically embedded in the TPM. The TPM includes an attestation identity key (AIK), the AIK being used to verify that at least one TPM-protected key different from the EK and different from the AIK is generated at the TPM and is non-migratable. The TPM includes an enterprise machine key (EMK), the EMK being certified by the AIK, the EMK being uniquely associated with the client computing device, and the EMK being generated during enrollment of the client computing device with an enterprise and remaining active until a factory reset of the client computing device.


