Method and apparatus for evaluating actions performed on a client device
Disclosed is a method and apparatus for evaluating actions performed on a client device. For each of the performed actions, a current key is generated from a previous key and an associated action attestation value is generated from the previous key and information about each action (stored in a log file). The previous key is then deleted. A final attestation value is also generated using a publicly non-invertible function and is based at least on the current key. The client device transmits information about the performed actions (stored in a log file), the plurality of action attestation values, and the final attestation value to the server so that the server can authenticate the action attestation values and the final attestation value. If the server cannot authenticate these attestation values, then the server can determine that the log file has been tampered with.
1 . A method of operation of a client device for enabling a server to evaluate a plurality of actions performed on the client device, said method comprising:
for each of said plurality of actions,
(a) generating a current key,
(b) generating an associated action attestation value based on a previous key and information about said each action, and
(c) deleting said previous key;
generating a final attestation value based at least on said current key using a publicly non-invertible function; and
transmitting information about said plurality of actions, a plurality of action attestation values, and said final attestation value to said server so that said server can authenticate said plurality of action attestation values and said final attestation value.
2 . The method of claim 1 wherein the action comprises at least the generation of said current key.
3 . The method of claim 1 further comprising receiving a first key from said server.
4 . The method of claim 1 wherein said current key becomes said previous key when a new current key is generated before another action is performed by said client device.
5 . The method of claim 1 wherein said previous key is a key generated immediately before said current key.
6 . The method of claim 1 wherein said final attestation value is based on said current key and information about a last action.
7 . The method of claim 1 wherein said each of said plurality of actions further comprises at least one of downloading malware, disabling an antivirus software program, downloading copyrighted material, originating or transmitting an email or another file, changing a configuration, and visiting a particular website.
8 . A method for determining that a log of events transmitted by a first device to a second device has been tampered with, the method comprising:
receiving a plurality of action attestation values, a final attestation value, and said log from said first device;
evaluating said plurality of action attestation values and said final attestation value; and
determining that said log has been tampered with based on said evaluating step.
9 . The method of claim 8 wherein the tampering is a result of malware infection of said first device.
10 . The method of claim 8 wherein the tampering is a result of an adverse user-initiated event.
11 . The method of claim 8 further comprising, for each event in said log of events, generating a current key based on a previous key.
12 . The method of claim 11 further comprising, for each event in said log of events, generating an associated server action attestation value based on said previous key and information about said each event in said log.
13 . The method of claim 12 wherein said evaluating further comprises comparing said associated server action attestation value with a corresponding action attestation value in said plurality of action attestation values.
14 . The method of claim 11 further comprising generating a server final attestation value based at least on said current key.
15 . The method of claim 14 wherein said evaluating further comprises comparing said server final attestation value with said final attestation value.
16 . The method of claim 8 further comprising using a publicly non-invertible function to generate said final attestation value.
17 . A computer readable medium comprising computer program instructions capable of being executed in a processor and defining the steps comprising:
for each of a plurality of actions performed on a client device,
(a) generating a current key,
(b) generating an associated action attestation value based on a previous key and information about said each action, and
(c) deleting said previous key;
generating a final attestation value based at least on said current key using a publicly non-invertible function; and
transmitting information about said plurality of actions, a plurality of action attestation values, and said final attestation value to a server so that said server can authenticate said plurality of action attestation values and said final attestation value.
18 . The computer readable medium of claim 17 further comprising computer program instructions defining the step of receiving a first key from said server.
19 . The computer readable medium of claim 17 wherein said current key becomes said previous key when a new current key is generated before another action is performed by said client device.
20 . The computer readable medium of claim 17 wherein said previous key is a key generated immediately before said current key.
21 . The computer readable medium of claim 17 wherein said final attestation value is based on said current key and information about a last action.
22 . The computer readable medium of claim 17 wherein said each of said plurality of actions further comprises at least one of downloading malware, disabling an antivirus software program, downloading copyrighted material, originating or transmitting an email or another file, changing a configuration, and visiting a particular website.
23 . A server for determining that a log of events transmitted by a device to said server has been tampered with, the server comprising:
means for receiving a plurality of action attestation values, a final attestation value, and said log from said device;
means for evaluating said plurality of action attestation values and said final attestation value; and
means for determining that said log has been tampered with from said means for evaluating.
24 . The server of claim 23 further comprising means for generating a current key from a previous key for each event in said log of events.
25 . The server of claim 24 further comprising means for generating a server action attestation value based on said previous key and information about said each event for each event in said log of events.
26 . The server of claim 25 wherein said means for evaluating further comprises means for comparing said server action attestation value with a corresponding action attestation value.
27 . The server of claim 24 further comprising means for generating a server final attestation value based at least on said current key.
28 . The server of claim 27 wherein said means for evaluating further comprises means for comparing said server final attestation value with said final attestation value.
29 . The server of claim 23 further comprising means for generating said final attestation value using a publicly non-invertible function.
30 . A computer readable medium comprising computer program instructions capable of being executed in a processor and defining the steps comprising:
receiving a plurality of action attestation values, a final attestation value, and a log of events from a first device;
evaluating said plurality of action attestation values and said final attestation value; and
determining that said log has been tampered with based on said evaluating step.
31 . The computer readable medium of claim 30 further comprising, for each event in said log of events, computer program instructions defining the step of generating a current key based on a previous key.
32 . The computer readable medium of claim 31 further comprising, for each event in said log of events, computer program instructions defining the step of generating an associated server action attestation value based on said previous key and information about said each event in said log.
33 . The computer readable medium of claim 32 wherein said evaluating step further comprises computer program instructions defining the step of comparing said associated server action attestation value with a corresponding action attestation value in said plurality of action attestation values.
34 . The computer readable medium of claim 31 further comprising computer program instructions defining the step of generating a server final attestation value based at least on said current key.
35 . The computer readable medium of claim 34 wherein said evaluating step further comprises computer program instructions defining the step of comparing said server final attestation value with said final attestation value.
36 . The computer readable medium of claim 30 further comprising computer program instructions defining the step of using a publicly non-invertible function to generate said final attestation value.
37 . A system comprising:
a first device configured to record at least one event in a forward-secure log and configured to compute a final attestation value for at least a portion of said forward-secure log; and
a second device configured to verify the integrity of said at least a portion of said forward-secure log from said final attestation value.
38 . The system of claim 37 wherein said at least one event is at least one of a software-configuration event, creation of a communication session with another device, execution of software, and installing software.
39 . The system of claim 38 wherein said at least one event is downloading software by said first device.
40 . The system of claim 39 wherein said at least one event is recorded before said downloading of said software.
41 . The system of claim 38 wherein said at least one event is recorded before at least one of a software-configuration event, creation of a communication session with another device, execution of software, and installing software.
42 . The system of claim 39 wherein said first device is further configured to retrieve software-classification data and a software configuration record comprising a classification of said software.
43 . The system of claim 42 wherein said software-classification data is a list of software distribution points.
44 . The system of claim 42 wherein said software configuration record comprises at least one of a URL from which said software is downloaded by said first device, an IP address from which said software is downloaded by said first device, values derived from at least a portion of said software, and a web site certificate.
45 . The system of claim 37 wherein said at least one event is a change in system security policy.
46 . The system of claim 37 wherein said second device is further configured to select an access-control procedure for said first device.
47 . The system of claim 46 wherein said access-control procedure further comprises execution of at least one device-authentication procedure and user-authentication procedure.
48 . A method comprising:
recording, by a first device, at least one event in a forward-secure log;
computing, by said first device, a final attestation value for at least a portion of said forward-secure log; and
verifying, by a second device, the integrity of said at least a portion of said forward-secure log from said final attestation value.
49 . The method of claim 48 wherein said at least one event is at least one of a software-configuration event, creation of a communication session with another device, execution of software, and installing software.
50 . The method of claim 48 wherein said at least one event is downloading software by said first device.
51 . The method of claim 50 wherein said recording of said at least one event occurs before said downloading of said software.
52 . The method of claim 38 wherein said recording of said at least one event occurs before at least one of a software-configuration event, creation of a communication session with another device, execution of software, and installing software.