Trusted remote attestation agent (traa)
Abstract
Systems and methods for use with a service provider and a consumer electronic device include a trusted remote attestation agent (TRAA) configured to perform a set of checking procedures or mechanisms to help ensure the security status of a consumer electronic device (e.g., a mobile terminal or phone) that holds financial instruments. The checking procedures may include: self-verifying integrity by the TRAA; checking for presence of a provisioning SIM card (one that was present when the financial instruments were enabled on the device); checking that a communication connection between the consumer electronic device and the service provider is available and active; and checking that communication connectivity to a home mobile network is available and active. The frequency of the checking mechanisms may be adjusted, for example, according to a risk-profile of a user associated with the device or the location (e.g., GPS location) of the device. The checks may be used, for example, to temporarily disable or limit the use of the financial instruments from the device.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A system, comprising:
a Trusted Integrity Manager (TIM) configured to provide authentication services; at least one processor; and at least one memory device storing computer-executable instructions that, in response to execution by the at least one processor, cause the system to perform operations comprising:
receiving a request from an electronic device to authenticate a user with an application on the electronic device;
receiving, from the electronic device via a communication channel that provides a chain of trust between the electronic device and the system, data associated with a zero-knowledge proof authentication of the electronic device, the zero-knowledge proof authentication based on a secret material stored within a hardware secure element of the electronic device;
receiving, from the electronic device, time and geo-location information associated with the electronic device;
verifying, by the TIM, identity credentials of the user of the electronic device using the zero-knowledge proof authentication data and the time and geo-location information;
generating, by the TIM, verification data in response to the verifying of the identity credentials of the user of the electronic device;
transmitting the verification data to the electronic device for storage within the hardware secure element; and
in response to a determination that the verification data matches stored verification data stored within the hardware secure element, receiving a communication from the electronic device using the chain of trust that the verification data is trusted as representing the identity of the user of the electronic device.
3 . The system of claim 2 , wherein the communication channel includes one or more communication hops, each hop having two endpoints, wherein each hop of the communication channel is protected; and the endpoints of each hop mutually authenticate each other such that the communication channel provides an end-to-end chain of trust from the electronic device to the system.
4 . The system of claim 2 , wherein the secret material is a private key material that serves as proof material for the zero-knowledge proof authentication to authenticate the electronic device.
5 . The system of claim 2 , wherein the secret material is a private key material unique and resistant to forgery and to being guessed such that the private key material serves as an identity of the user of the electronic device.
6 . The system of claim 2 , wherein the operations further comprise authenticating a first end-point of the communication channel and a second end-point of the communication channel prior to establishing the communication channel.
7 . The system of claim 5 , wherein the operations further comprise encrypting the communication channel between the first end-point and the second end-point.
8 . The system of claim 2 , wherein: the secret material is a private key material that remains private after the zero-knowledge proof authentication of the electronic device is completed such that the private key material is not disclosed to the system.
9 . A method, comprising:
receiving a request from an electronic device to authenticate a user with an application on an electronic device; receiving, from the electronic device via a communication channel that provides a chain of trust between the electronic device and a system, data associated with a zero-knowledge proof authentication of the electronic device, the zero-knowledge proof authentication based on a secret material stored within a hardware secure element of the electronic device; receiving, from the electronic device, time and geo-location information associated with the electronic device; verifying, by a Trust Integrity Manager (TIM), identity credentials of the user of the electronic device using the zero-knowledge proof authentication data and the time and geo-location information; generating, by the TIM, verification data in response to the verifying of the identity credentials of the user of the electronic device; transmitting the verification data to the electronic device for storage within the hardware secure element; and in response to a determination that the verification data matches stored verification data stored within the hardware secure element, receiving a communication from the electronic device using the chain of trust that the verification data is trusted as representing the identity of the user of the electronic device.
10 . The method of claim 9 , wherein the communication channel includes one or more communication hops, each hop having two endpoints, wherein each hop of the communication channel is protected; and the endpoints of each hop mutually authenticate each other such that the communication channel provides an end-to-end chain of trust from the electronic device to the system.
11 . The method of claim 9 , wherein the secret material is a private key material that serves as proof material for the zero-knowledge proof authentication to authenticate the electronic device.
12 . The method of claim 9 , wherein the secret material is a private key material unique and resistant to forgery and to being guessed such that the private key material serves as an identity of the user of the electronic device.
13 . The method of claim 9 , further comprising authenticating a first end-point of the communication channel and a second end-point of the communication channel prior to establishing the communication channel.
14 . The method of claim 12 , further comprising encrypting the communication channel between the first end-point and the second end-point.
15 . The method of claim 9 , wherein: the secret material is a private key material that remains private after the zero-knowledge proof authentication of the electronic device is completed such that the private key material is not disclosed to the system.
16 . A non-transitory machine-readable medium comprising instructions which, in response to a computer system, cause the computer system to perform operations comprising:
receiving a request from an electronic device to authenticate a user with an application on an electronic device; receiving, from the electronic device via a communication channel that provides a chain of trust between the electronic device and a system, data associated with a zero-knowledge proof authentication of the electronic device, the zero-knowledge proof authentication based on a secret material stored within a hardware secure element of the electronic device; receiving, from the electronic device, time and geo-location information associated with the electronic device; verifying, by a Trust Integrity Manager (TIM), identity credentials of the user of the electronic device using the zero-knowledge proof authentication data and the time and geo-location information; generating, by the TIM, verification data in response to the verifying of the identity credentials of the user of the electronic device; transmitting the verification data to the electronic device for storage within the hardware secure element; and in response to a determination that the verification data matches stored verification data stored within the hardware secure element, receiving a communication from the electronic device using the chain of trust that the verification data is trusted as representing the identity of the user of the electronic device.
17 . The non-transitory machine-readable medium of claim 16 , wherein the communication channel includes one or more communication hops, each hop having two endpoints, wherein each hop of the communication channel is protected; and the endpoints of each hop mutually authenticate each other such that the communication channel provides an end-to-end chain of trust from the electronic device to the system.
18 . The non-transitory machine-readable medium of claim 16 , wherein the secret material is a private key material that serves as proof material for the zero-knowledge proof authentication to authenticate the electronic device.
19 . The non-transitory machine-readable medium of claim 16 , wherein the secret material is a private key material unique and resistant to forgery and to being guessed such that the private key material serves as an identity of the user of the electronic device.
20 . The non-transitory machine-readable medium of claim 16 , wherein the operations further comprise authenticating a first end-point of the communication channel and a second end-point of the communication channel prior to establishing the communication channel.
21 . The non-transitory machine-readable medium of claim 19 , wherein the operations further comprise encrypting the communication channel between the first end-point and the second end-point.Join the waitlist — get patent alerts
Track US2018068298A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.