IP Library Granted Patent US 9,715,597
Granted Patent B2
US 9,715,597 · App. 14/496,056 · Granted Jul 25, 2017

Data verification using enclave attestation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,715,597
App. No.
14/496,056
Granted
Jul 25, 2017
Kind
B2
Abstract

Particular embodiments described herein provide for an electronic device that can be configured to receive untrusted input data at an enclave in an electronic device, isolate the untrusted input data from at least a portion of the enclave, communicate at least a portion of the untrusted data to an integrity verification module using an attestation channel, and receive data integrity verification of the untrusted input data from the integrity verification module. The integrity verification module can perform data integrity attestation functions to verify the untrusted data and the data integrity attestation functions include a data attestation policy and a whitelist.

Claims (50)

1. At least one non-transitory computer-readable medium comprising one or more instructions that when executed by at least one processor:

receive untrusted data for input to an application at an enclave in an electronic device, wherein the enclave includes a protected region of memory in which the application resides for execution;

receive a flag associated with the application;

determine whether the flag associated with the application indicates that the application is to be used with integrity verification, wherein the integrity verification module performs data integrity attestation functions to verify the untrusted data for input and wherein the data integrity attestation functions include a data attestation policy specifying constraints on input values for the application;

responsive to determining the application is to be used with integrity verification:

isolate the untrusted data for input from at least a portion of the enclave;

communicate at least a portion of the untrusted data for input to an integrity verification module using an attestation channel;

receive data integrity verification of the untrusted data for input from the integrity verification module; and

return the verified untrusted data for input to the application for processing.

2. The at least one computer-readable medium of claim 1 , wherein the data integrity attestation functions further include a whitelist.

3. The at least one computer-readable medium of claim 1 , wherein the integrity verification module is located in the electronic device.

4. The at least one computer-readable medium of claim 1 , wherein the integrity verification module is located in the enclave.

5. The at least one computer-readable medium of claim 1 , wherein the integrity verification module is located in a server that is remote from the electronic device.

6. The at least one computer-readable medium of claim 1 , wherein the integrity verification module is located in a cloud that is remote from the electronic device.

7. An apparatus comprising:

an integrity verification module configured to:

receive untrusted data for input to an application from an enclave in an electronic device, wherein the untrusted data is isolated from at least a portion of the enclave, wherein the enclave includes a protected region of memory in which the application resides for execution, and wherein the untrusted data is communicated using an attestation channel;

receive a flag associated with the application;

determine whether the flag associated with the application indicates that the application is to be used with integrity verification, wherein the integrity verification module performs data integrity attestation functions to verify the untrusted data for input and wherein the data integrity attestation functions include a data attestation policy specifying constraints on input values for the application;

responsive to determining the application is to be used with integrity verification:

perform data integrity verification of the untrusted data for input; and

return the results of the data integrity verification to the enclave.

8. The apparatus of claim 7 , wherein the data integrity attestation functions further include a whitelist.

9. The apparatus of claim 7 , wherein the integrity verification module is located in the electronic device.

10. The apparatus of claim 7 , wherein the integrity verification module is located in the enclave.

11. The apparatus of claim 7 , wherein the integrity verification module is located in a server that is remote from the electronic device.

12. The apparatus of claim 7 , wherein the integrity verification module is located in a cloud that is remote from the electronic device.

13. A method comprising:

receiving untrusted data for input to an application at an enclave in an electronic device, wherein the enclave includes a protected region of memory in which the application resides for execution;

receiving a flag associated with the application;

determining whether the flag associated with the application indicates that the application is to be used with integrity verification, wherein the integrity verification module performs data integrity attestation functions to verify the untrusted data for input and wherein the data integrity attestation functions include a data attestation policy specifying constraints on input values for the application;

responsive to determining the application is to be used with integrity verification:

isolating the untrusted data for input from at least a portion of the enclave;

communicating at least a portion of the untrusted data for input to an integrity verification module using an attestation channel;

receiving data integrity verification of the untrusted data for input from the integrity verification module; and

returning the verified untrusted data for input to the application for processing.

14. The method of claim 13 , wherein the data integrity attestation functions further include a whitelist.

15. The method of claim 13 , wherein the integrity verification module is located in the electronic device.

16. The method of claim 13 , wherein the integrity verification module is located in a server that is remote from the electronic device.

17. The method of claim 13 , wherein the integrity verification module is located in a cloud that is remote from the electronic device.

18. A system for data verification using enclave attestation, the system comprising:

an integrity verification module configured for:

receiving untrusted data for input to an application at an enclave in an electronic device, wherein the enclave includes a protected region of memory in which the application resides for execution;

receiving a flag associated with the application;

determining whether the flag associated with the application indicates that the application is to be used with integrity verification, wherein the integrity verification module performs data integrity attestation functions to verify the untrusted data for input and wherein the data integrity attestation functions include a data attestation policy specifying constraints on input values for the application;

responsive to determining the application is subject to integrity verification:

isolating the untrusted data for input from at least a portion of the enclave;

communicating at least a portion of the untrusted data for input to an integrity verification module using an attestation channel;

receiving data integrity verification of the untrusted data for input from the integrity verification module; and

returning the verified untrusted data for input to the application for processing.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2014
From: SMITH, NED; GUTIERREZ, ESTEBAN; WOODRUFF, ANDREW; KAPOOR, ADITYA
To: MCAFEE INC.
Reel/Frame 034055/0921 →