IP Library › Granted Patent US 12,081,678
Granted Patent B2
US 12,081,678 · App. 17/508,842 · Granted Sep 3, 2024

Secure authentication using attestation tokens and inviolable quotes to validate request origins

Inventors: Richard Pakhang Ko (Kirkland, WA); Eric Arnold Jenkins, Jr. (Bellingham, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L9/3263G06F9/451H04L9/3213H04L9/3247H04L63/0442H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,081,678
App. No.
17/508,842
Granted
Sep 3, 2024
Kind
B2
Abstract

Secure authentication using attestation tokens and inviolable quotes to validate request origins is performed by systems and platforms. An application programming interface (API) service is hosted via secure enclave of a computing platform container. Requests to a resource system for highly confidential/sensitive information persisted in a data storage, or for computational services, are made through the enclave, which is a source from which requests are trusted. An API call is made from the secure enclave to the resource system to establish a secure communication session based on a signed certificate for the secure enclave that is signed using an encrypted memory of the secure enclave. The API call also includes an attestation token used to validate the secure enclave as the source requesting the information or service via the API call. Confidential/sensitive information is provided to the secure enclave if the API call source is validated by the resource system.

Claims (102)

1. A system comprising:

a secure enclave that comprises an encrypted memory, a program memory storing program code, and a processing system comprising a processor circuit configured to receive the program code from the program memory and, in response to receiving the program code, to:

generate a signed digital certificate that comprises:

a public key from a key pair generated by the secure enclave, and

a secure quote generated in the encrypted memory and comprising an identifier of the secure enclave and a hash value of the public key;

receive an attestation token from a trusted token provider, the attestation token based on the hash value of the public key and signed with a signing certificate;

receive, from a requestor, a request for confidential data; and

place a first application programming interface (API) call to a data storage that persists the confidential data in a first encrypted state, the first API call comprising the signed digital certificate and the attestation token; and

the trusted token provider configured to:

receive an update request from the data storage based on the signing certificate of the attestation token in the API call being unrecognized by the data storage;

update the signing certificate; and

provide the updated signing certificate to the data storage.

2. The system of claim 1 , wherein the trusted token provider is further configured to:

receive the secure quote and the signed digital certificate;

generate the attestation token based on receiving the secure quote and the digital signed certificate; and

provide the attestation token to the secure enclave.

3. The system of claim 1 , wherein the trusted token provider is configured to:

locally-store the signing certificate as part of stored signing certificates;

receive a certificate request from the data storage for the signing certificate; and

provide the signing certificate to the data storage.

4. The system of claim 1 , wherein the processing system, in response to at least receiving the program code, is further configured to:

place a second API call to the data storage, the second API call comprising the signed digital certificate and an updated attestation token, the updated attestation token signed by the updated signing certificate, the second API call establishing a secure session between the data storage and the secure enclave based on the updated signing certificate; and

receive, from the data storage via the secure communication session and based on a trust determination for the secure enclave made by the data storage, an API response that comprises the confidential information to fulfill the request from the requestor.

5. The system of claim 4 , wherein the trust determination is performed by the data storage and includes determining that the secure enclave is a trusted source for the API call based on:

a validation of a signature of the updated attestation token against the updated signing certificate; and

a validation of the signed digital certificate.

6. The system of claim 4 , wherein:

the processing system, in response to receiving the program code, is further configured to

provide the confidential information in the first encrypted state to the encrypted memory that includes a private key of the key pair,

receive the confidential information in a second encrypted state from the encrypted memory, and

provide the confidential information in the second encrypted state to the requestor as fulfillment of the request; and

the encrypted memory is configured to prevent access to both decrypting operations and encrypting operations that utilize the private key.

7. The system of claim 4 , wherein;

the secure enclave and the trusted token provider comprise a cloud-based platform;

the data storage comprises an on-premise computing device outside of the cloud-based platform; and

the secure communication session is a mutual transport layer security session via hyper-text transfer protocol (HTTP).

8. A method performed utilizing a secure enclave and a trusted token provider of a processing system, the method comprising:

generating, by the secure enclave, a signed digital certificate comprising:

a public key from a key pair generated by the secure enclave, and

a secure quote generated in an encrypted memory of the secure enclave and comprising an identifier of the secure enclave and a hash value of the public key;

receiving an attestation token by the secure enclave and from the trusted token provider, the attestation token based on the hash value of the public key and signed with a signing certificate;

receiving, by the secure enclave and from a requestor, a request for confidential data;

placing, by the secure enclave, a first application programming interface (API) call to a data storage that persists the confidential data in a first encrypted state, the API call comprising the signed digital certificate and the attestation token;

receiving, by the trusted token provider and from the data storage, an update request based on the signing certificate of the attestation token in the API call being unrecognized by the data storage;

updating, by the trusted token provider, the signing certificate; and

providing, by the trusted token provider, the updated signing certificate to the data storage.

9. The method of claim 8 ,

further comprising:

receiving, by the trusted token provider, the secure quote and the signed digital certificate;

generating, by the trusted token provider, the attestation token based on said receiving the secure quote and the digital signed certificate; and

providing, by the trusted token provider, the attestation token to the secure enclave.

10. The method of claim 8 , further comprising:

updating, by the trusted token provider, stored signing certificates by:

locally-storing the signing certificate as part of the stored signing certificates;

receiving a certificate request from the data storage for the signing certificate; and

providing the signing certificate to the data storage.

11. The method of claim 8 , further comprising:

placing, by the secure enclave, a second API call to the data storage, the second API call comprising the signed digital certificate and an updated attestation token, the updated attestation token signed by the updated signing certificate, the second API call establishing a secure session between the data storage and the secure enclave based on the updated signing certificate; and

receiving, by the secure enclave and from the data storage via the secure communication session and based on a trust determination for the secure enclave made by the data storage, an API response that comprises the confidential information to fulfill the request from the requestor.

12. The method of claim 11 , wherein the data storage makes the trust determination by determining that the secure enclave is a trusted source for the API call based on:

a validation of a signature of the updated attestation token against the updated signing certificate; and

a validation of the signed digital certificate.

13. The method of claim 11 , further comprising:

providing, by the secure enclave, the confidential information in the first encrypted state to the encrypted memory that includes a private key of the key pair,

receiving, by the secure enclave, the confidential information in a second encrypted state from the encrypted memory, and

providing, by the secure enclave, the confidential information in the second encrypted state to the requestor as fulfillment of the request; and

wherein the encrypted memory is configured to prevent access to both decrypting operations and encrypting operations that utilize the private key.

14. The method of claim 11 , wherein the secure enclave and the trusted token provider comprise a cloud-based platform;

wherein the data storage comprises an on-premise computing device outside of the cloud-based platform; and

wherein the secure communication session is a mutual transport layer security session via hyper-text transfer protocol (HTTP).

15. A computer readable storage medium having program code recorded thereon that, when executed by a processing system, perform a method utilizing a secure enclave and a trusted token provider, the method comprising:

generating, by the secure enclave, a signed digital certificate comprising:

a public key from a key pair generated by the secure enclave, and

a secure quote generated in an encrypted memory of the secure enclave and comprising an identifier of the secure enclave and a hash value of the public key;

receiving an attestation token by the secure enclave and from the trusted token provider, the attestation token based on the hash value of the public key and signed with a signing certificate;

receiving, by the secure enclave and from a requestor, a request for confidential data;

placing, by the secure enclave, a first application programming interface (API) call to a data storage that persists the confidential data in a first encrypted state, the API call comprising the signed digital certificate and the attestation token;

receiving, by the trusted token provider and from the data storage, an update request based on the signing certificate of the attestation token in the API call being unrecognized by the data storage;

updating, by the trusted token provider, the signing certificate; and

providing, by the trusted token provider, the updated signing certificate to the data storage.

16. The computer readable storage medium of claim 15 , wherein the method further comprises:

receiving, by the trusted token provider, the secure quote and the signed digital certificate;

generate, by the trusted token provider, the attestation token based on said receiving the secure quote and the digital signed certificate; and

providing, by the trusted token provider, the attestation token to the secure enclave.

17. The computer readable storage medium of claim 15 , wherein the method further comprises:

updating, by the trusted token provider, stored signing certificates by:

locally-storing the signing certificate as part of the stored signing certificates;

receiving a certificate request from the data storage for the signing certificate; and

providing the signing certificate to the data storage.

18. The computer readable storage medium of claim 15 , wherein the method further comprises:

placing, by the secure enclave, a second API call to the data storage, the second API call comprising the signed digital certificate and an updated attestation token, the updated attestation token signed by the updated signing certificate, the second API call establishing a secure session between the data storage and the secure enclave based on the updated signing certificate; and

receiving, by the secure enclave and from the data storage via the secure communication session and based on a trust determination for the secure enclave made by the data storage, an API response that comprises the confidential information to fulfill the request from the requestor.

19. The computer readable storage medium of claim 18 , wherein the data storage makes the the trust determination by determining that the secure enclave is a trusted source for the API call based on:

a validation of a signature of the updated attestation token against the updated signing certificate; and

a validation of the signing certificate.

20. The computer readable storage medium of claim 18 , wherein:

the method further comprises:

providing, by the secure enclave, the confidential information in the first encrypted state to the encrypted memory that includes a private key of the key pair,

receiving, by the secure enclave, the confidential information in a second encrypted state from the encrypted memory, and

providing, by the secure enclave, the confidential information in the second encrypted state to the requestor as fulfillment of the request,

wherein the encrypted memory is configured to prevent access to both decrypting operations and encrypting operations that utilize the private key; or

the secure enclave and the trusted token provider comprise a cloud-based platform, wherein the data storage comprises an on-premise computing device outside of the cloud-based platform, and wherein the secure communication session is a mutual transport layer security session via hyper-text transfer protocol (HTTP).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2021
From: KO, RICHARD PAKHANG; JENKINS, ERIC ARNOLD, JR.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 057892/0021 →
Continuity (1)
Related Publication 20230131060A1 · Apr 27, 2023
Cited By (3)
US 12,353,588 US 12,598,085 US 12,744,678