US2023042055A1PendingUtilityA1

Active attestation of embedded systems

Assignee: US GOV AIR FORCEPriority: Feb 26, 2018Filed: Oct 20, 2022Published: Feb 9, 2023
Est. expiryFeb 26, 2038(~11.6 yrs left)· nominal 20-yr term from priority
G06F 9/4401G06F 21/64H04L 9/088G06F 21/76G06F 21/575H04L 9/0643H04L 2209/127G06F 21/572G06F 2221/033
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An active attestation apparatus verifies at runtime the integrity of untrusted machine code of an embedded system residing in a memory device while it is being run/used with while slowing the processing time less than other methods. The apparatus uses an integrated circuit chip containing a microcontroller and a reprogrammable logic device, such as a field programmable gate array (FPGA), to implement software attestation at runtime and in less time than is typically possible with comparable attestation approaches, while not requiring any halt of the processor in the microcontroller. The reprogrammable logic device includes functionality to load an encrypted version of its configuration and operating code, perform a checksum computation, and communicate with a verifier. The checksum algorithm is preferably time optimized to execute computations in the reprogrammable logic device in the minimum possible time.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An active attestation query method performed by a reprogrammable logic device to ensure the integrity of untrusted machine code executed by a processor, wherein the untrusted machine code resides in memory locations of a memory device, the method comprising:
 (a) receiving an attestation request, including a nonce, from a verifier;   (b) performing a checksum computation over the memory locations of the memory device in which the untrusted machine code resides, the checksum computation performed using the nonce;   (c) generating a checksum result value based on the checksum computation; and   (d) sending the checksum result value to the verifier.   
     
     
         2 . The method of  claim 1  wherein the attestation request and response are encrypted. 
     
     
         3 . The method of  claim 2  wherein the checksum computation is performed periodically to verify that the untrusted machine code residing in the memory locations of the memory device has not been altered. 
     
     
         4 . The method of  claim 2  wherein the checksum computation is performed over the memory locations of the memory device without detection by the processor.

Join the waitlist — get patent alerts

Track US2023042055A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.