IP Library Patent Application 15476542
Patent Application
App. No. 15/476,542

TRUSTED REMOTE CONFIGURATION AND OPERATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/476,542
Abstract

Techniques related to trusted remote configuration and operation using multiple devices are disclosed. The techniques include a machine-readable medium, on which are stored instructions, comprising instructions that when executed cause a target device to receive, from a connecting device, a capabilities request, measure, in response to the capabilities request, the trusted capabilities of the target device, generate a list of trusted capabilities, transmit, to the connecting device, the list of trusted capabilities, receive, from the connecting device, an access request for a trusted capability, the access request describing a workload for the trusted capability, perform the workload to obtain a result, and transmit, to the connecting device, the obtained result.

Claims (66)

1 . A machine-readable medium, on which are stored instructions, comprising instructions that when executed cause a target device to:

receive, from a connecting device, a capabilities request;

measure, in response to the capabilities request, trusted capabilities of the target device;

generate a list of trusted capabilities;

transmit, to the connecting device, the list of trusted capabilities;

receive, from the connecting device, an access request for a trusted capability, the access request comprising a workload for the trusted capability;

perform the workload to obtain a result; and

transmit, to the connecting device, the obtained result.

2 . The machine-readable medium of claim 1 , wherein the capabilities request is included in a remote attestation request and the measuring is performed as a part of performing a remote attestation protocol.

3 . The machine-readable medium of claim 1 , wherein the access request includes an indication of constrained operations for execution by the target device with enhanced security.

4 . The machine-readable medium of claim 3 , wherein the instructions that when executed further cause the target device to:

receive an input requesting execution of a constrained operation from a list of constrained operations;

perform another measurement of software or hardware components associated with the constrained operation; and

execute the constrained operation if the another measurement is successful.

5 . The machine-readable medium of claim 1 , wherein the list of trusted capabilities comprise a list of capabilities the target device may execute within a trusted execution environment (TEE).

6 . The machine-readable medium of claim 5 , wherein the workload comprises code associated with the trusted capability for execution by the target device, and wherein the instructions that when executed further cause the target device to:

execute the workload within the TEE; and

transmit a response to the connecting device, the response having an indication of the workload executed and results of the workload execution.

7 . A machine-readable medium, on which are stored instructions, comprising instructions that when executed cause a connecting device to:

transmit, to a target device, a capabilities request;

receive, in response to the capabilities request, a list of trusted capabilities;

determine the list of trusted capabilities includes one or more required capabilities; and

transmit, to the target device, a request for access to a trusted capability.

8 . The machine-readable medium of claim 7 , wherein the capabilities request is included in a remote attestation request.

9 . The machine-readable medium of claim 7 , wherein the request for access includes an indication of constrained operations for execution by the target device with enhanced security.

10 . The machine-readable medium of claim 9 , wherein the indication of constrained operations comprises a list of constrained operations and wherein the instructions that when executed further cause the target device to:

receive, from the target device, an indication that execution of a constrained operation, from the list of constrained operations, is requested; and

perform another measurement of software or hardware components associated with the constrained operation.

11 . The machine-readable medium of claim 7 , wherein the list of trusted capabilities comprise a list of capabilities the target device may execute within a trusted execution environment (TEE).

12 . The machine-readable medium of claim 7 , wherein the access request includes a workload, the workload comprising code associated with the trusted capability for execution by the target device, and wherein the instructions further comprise instructions that when executed cause the connecting device to:

receive a response from the target device, the response having an indication of the workload executed and results of executing the workload; and

take one or more actions based on the results.

13 . An apparatus for performing trusted operations, comprising:

a memory storing instructions for performing trusted operations; and

a processor operatively coupled to the memory and adapted to execute the instructions stored in the memory to cause the processor to:

receive, as a target device, a message from a connecting device, the message requesting trusted capabilities of the target device;

exchange attestation information with the connecting device;

obtain a list of trusted capabilities;

receive, from the connecting device, an access request for a trusted capability of the list of trusted capabilities, the access request comprising a workload for the trusted capability;

perform the workload to obtain a result; and

transmit, to the connecting device, the obtained result.

14 . The apparatus of claim 13 , wherein the access request is received as a part of the exchanged attestation information.

15 . The apparatus of any of claim 13 , wherein the access request includes an indication of constrained operations for execution by the target device with enhanced security.

16 . The apparatus of claim 15 , further comprising instructions to cause the processor to:

receive an input requesting execution of a constrained operation from a list of constrained operations;

exchange another attestation information related to software or hardware components associated with the constrained operation; and

execute the constrained operation if the other attestation information attests to the software or hardware components.

17 . The apparatus of any of claim 13 , wherein the list of trusted capabilities comprises a list of capabilities the target device may execute within a trusted execution environment (TEE).

18 . The apparatus of claim 17 , wherein the workload comprises code associated with the trusted capability for execution by the target device further comprising instructions to cause the processor to:

execute the workload within the TEE; and

transmit a response to the connecting device, the response having an indication of the workload executed and results of the workload execution.

19 . A method for performing trusted operations, comprising:

transmitting, to a target device, a capabilities request;

exchanging attestation information with the target device;

receiving, a list of trusted capabilities;

determining the list of trusted capabilities includes one or more required capabilities; and

transmitting, to the target device, a request for access to a trusted capability.

20 . The method of claim 19 , wherein the capabilities request is included in the exchanging attestation information.

21 . The method of claim 19 , wherein the request for access includes an indication of constrained operations for execution by the target device with enhanced security.

22 . The method of claim 21 , wherein the indication of constrained operations comprises a list of constrained operations and further comprising:

receiving, from the target device, an indication that execution of a constrained operation, from the list of constrained operations, is requested; and

exchanging another attestation information related to software or hardware components associated with the constrained operation.

23 . The method of claim 19 , wherein the list of trusted capabilities comprise a listing of capabilities the target device may execute within a trusted execution environment (TEE).

24 . The method of claim 19 , wherein the access request includes a workload, the workload comprising code associated with the trusted capability for execution by the target device, and further comprising:

receiving a response from the target device, the response having an indication of the workload executed and results of executing the workload; and

taking one or more actions based on the results.

Assignments (2)
CHANGE OF NAME Recorded Jan 9, 2018
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 045029/0406 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2017
From: SAMBANDAM, VENKATA RAMANAN; WOODWARD, CARL D.; RUBAKHA, DMITRI
To: MCAFEE, INC.
Reel/Frame 043784/0217 →