Remote attestation with hash-based signatures
Abstract
An attestation protocol between a prover device (P), a verifier device (V), and a trusted third-party device (TPP). P and TPP have a first trust relationship represented by a first cryptographic representation based on a one-or-few-times, hash-based, signature key. V sends an attestation request to P, with the attestation request including a second cryptographic representation of a second trust relationship between V and TPP. In response to the attestation request, P sends a validation request to TPP, with the validation request being based on a cryptographic association of the first trust relationship and the second trust relationship. TPP provides a validation response including a cryptographic representation of verification of validity of the first trust relationship and the second trust relationship. P sends an attestation response to V based on the validation response.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A verifier device to obtain attestation from a prover device, comprising:
a computing platform including at least one processor core, data storage, and an attestation engine that, when executed, causes the computing platform to:
send an attestation request to the prover device, the attestation request including a cryptographic representation of a first trust relationship between the verifier device and the trusted computing platform; and
receive an attestation response from the prover device, the attestation response including attestation data describing the prover device and further including a cryptographic representation of a verification of validity of the first trust relationship, and validity of a second trust relationship between the prover device and the trusted computing platform, the second trust relationship being cryptographically represented based on a one-or-few-times, hash-based, signature key pair,
wherein the prover device lacks a trust relationship with the verifier device.
2 . The verifier device of claim 1 , wherein the attestation response is sent in response to a validation exchange between the prover device and the trusted computing platform, wherein the validation exchange is based on a cryptographic association of the second trust relationship and produces the verification of validity of the first trust relationship and the second trust relationship.
3 . The verifier device of claim 1 , wherein:
the attestation request includes an instance identifier associated with the attestation request; the validation request is based on the instance identifier; and the validation response and attestation response are associated with the instance identifier.
4 . The verifier device of claim 3 , wherein the instance identifier includes a nonce.
5 . The verifier device of claim 3 , wherein the instance identifier includes an identification of the prover device.
6 . The verifier device of claim 3 , wherein the instance identifier includes an attribute of the prover device.
7 . The verifier device of claim 1 , wherein the one-or-few-times, hash-based, signature key is a few-times signature key encoded for not more than ten uses.
8 . The verifier device of claim 1 , wherein the one-or-few-times, hash-based, signature key is a one-time signature key.
9 . The verifier device of claim 1 , wherein the second representation of the second trust relationship is based on a multi-time hash-based signature key, wherein the multi-time hash-based signature key is encoded for more than ten uses.
10 . The verifier device of claim 1 , wherein the verifier device lacks a trust relationship with the prover device.
11 . The verifier device of claim 1 , wherein the attestation data includes a representation of hardware of the prover device.
12 . The verifier device of claim 1 , wherein the attestation data includes a representation of firmware of the prover device.
13 . The verifier device of claim 1 , wherein the attestation data includes a representation of software of the prover device.
14 . The verifier device of claim 1 , wherein the first cryptographic representation of the first trust relationship between the verifier device and the trusted computing platform includes a pair of asymmetric hash-based multi-time cryptographic keys.
15 . The verifier device of claim 1 , wherein the cryptographic association of the first trust relationship with the second trust relationship includes the first cryptographic representation of the first trust relationship digitally signed by the one-or-few-times, hash-based, signature key.
16 . A method to obtain attestation from a prover device, the method being executed by a computing platform of a verifier device, and comprising:
sending an attestation request to the prover device, the attestation request including a cryptographic representation of a first trust relationship between the verifier device and the trusted computing platform; and receiving an attestation response from the prover device, the attestation response including attestation data describing the prover device and further including a cryptographic representation of a verification of validity of the first trust relationship, and validity of a second trust relationship between the prover device and the trusted computing platform, the second trust relationship being cryptographically represented based on a one-or-few-times, hash-based, signature key pair, wherein the prover device lacks a trust relationship with the verifier device.
17 . The method of claim 16 , wherein the attestation response is sent in response to a validation exchange between the prover device and the trusted computing platform, wherein the validation exchange is based on a cryptographic association of the second trust relationship and produces the verification of validity of the first trust relationship and the second trust relationship.
18 . The method of claim 16 , wherein:
the attestation request includes an instance identifier associated with the attestation request; the validation request is based on the instance identifier; and the validation response and attestation response are associated with the instance identifier.
19 . The method of claim 18 , wherein the instance identifier includes a nonce.
20 . The method of claim 18 , wherein the instance identifier includes an identification of the prover device.
21 . At least one non-transitory machine-readable medium comprising instructions that, when executed on a computing platform of a verifier device, cause the computing platform to perform operations including:
sending an attestation request to the prover device, the attestation request including a cryptographic representation of a first trust relationship between the verifier device and the trusted computing platform; and receiving an attestation response from the prover device, the attestation response including attestation data describing the prover device and further including a cryptographic representation of a verification of validity of the first trust relationship, and validity of a second trust relationship between the prover device and the trusted computing platform, the second trust relationship being cryptographically represented based on a one-or-few-times, hash-based, signature key pair, wherein the prover device lacks a trust relationship with the verifier device.
22 . The at least one non-transitory machine-readable medium of claim 21 , wherein the one-or-few-times, hash-based, signature key is a few-times signature key encoded for not more than ten uses.
23 . The at least one non-transitory machine-readable medium of claim 21 , wherein the one-or-few-times, hash-based, signature key is a one-time signature key.
24 . The at least one non-transitory machine-readable medium of claim 21 , wherein the second representation of the second trust relationship is based on a multi-time hash-based signature key, wherein the multi-time hash-based signature key is encoded for more than ten uses.
25 . The at least one non-transitory machine-readable medium of claim 21 , wherein the verifier device lacks a trust relationship with the prover device.Join the waitlist — get patent alerts
Track US2019327096A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.