IP Library › Granted Patent US 12,547,706
Granted Patent B2
US 12,547,706 · App. 17/551,690 · Granted Feb 10, 2026

Platform health verification

Inventors: Mateusz Bronk (Gdansk, PL); Arkadiusz Berent (Pomorskie, PL); Piotr Zmijewski (Gdansk, PL)
Assignee: INTEL CORPORATION
G06F21/552H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,706
App. No.
17/551,690
Filed
Dec 15, 2021
Granted
Feb 10, 2026
Kind
B2
Examiner
ALATA, AYOUB
Art Unit
2494
USPC
726/23
Abstract

A method comprises issuing a challenge to a target computing device, receiving, from the target computing device, a response to the challenge, the response comprising a self-attestation proof, a root of trust (RoT) certificate, and a set of current attestation measurements, and generating a signal indicative of a security status of the target based upon a determination of whether the set of current attestation measurements match a set of expected attestation measurements for the target computing device.

Claims (31)

1 . A method comprising:

issuing, by a computing device, a challenge to a target computing device;

receiving, from the target computing device, a response to the challenge, the response comprising one or more of a self-attestation proof, a root of trust certificate, or a set of current attestation measurements; and

generating a signal indicative of a security status relating to the target computing device based on whether the set of current attestation measurements matches a set of expected attestation measurements associated with the target computing device, wherein the signal indicative of the security status is presented via an interface associated with the target computing device, wherein the expected attestation measurements are associated with the target computing device and obtained based on an appraisal of the target computing device in an isolated environment such that sensitive information is secured prior to interaction with the target computing device.

2 . The method of claim 1 , further comprising:

establishing an out-of-band (OOB) communication channel with the target computing device, wherein the signal comprises one or more of a visual indicator presented on a display; an audible indicator; or a tactile indicator;

obtaining, from a trusted third party, the set of expected attestation measurements associated with the target computing device;

transmitting the security status relating to the target computing device to the trusted third party; and

storing the security status relating to the target computing device.

3 . The method of claim 1 , wherein the computing device comprises a processor including an application processor or a graphics processor.

4 . A computing device comprising:

processor circuitry coupled to a memory, the processor circuitry to:

issue a challenge to a target computing device;

receive, from the target computing device, a response to the challenge, the response comprising one or more of a self-attestation proof, a root of trust certificate, or a set of current attestation measurements; and

generate a signal indicative of a security status relating to the target computing device based on whether the set of current attestation measurements matches a set of expected attestation measurements associated with the target computing device, wherein the signal indicative of the security status is presented via an interface associated with the target computing device, wherein the expected attestation measurements are associated with the target computing device and obtained based on an appraisal of the target computing device in an isolated environment such that sensitive information is secured prior to interaction with the target computing device.

5 . The computing device of claim 4 , wherein the processor circuitry is further to:

establish an out-of-band (OOB) communication channel with the target computing device, wherein the signal comprises one or more of a visual indicator presented on a display; an audible indicator; or a tactile indicator;

obtain, from a trusted third party, the set of expected attestation measurements associated with the target computing device

transmit the security status relating to the target computing device to the trusted third party; and

store the security status relating to the target computing device.

6 . The computing device of claim 4 , wherein the processor circuitry comprises application processor circuitry or graphics processor circuitry.

7 . At least one non-transitory computer-readable medium having stored thereon instructions which, when executed, cause a computing device to perform operations comprising:

issuing a challenge to a target computing device;

receiving, from the target computing device, a response to the challenge, the response comprising one or more of a self-attestation proof, a root of trust certificate, or a set of current attestation measurements; and

generating a signal indicative of a security status relating to the target based on whether the set of current attestation measurements matches a set of expected attestation measurements associated with the target computing device, wherein the signal indicative of the security status is presented via an interface associated with the target computing device, wherein the expected attestation measurements are associated with the target computing device and obtained based on an appraisal of the target computing device in an isolated environment such that sensitive information is secured prior to interaction with the target computing device.

8 . The non-transitory computer-readable medium of claim 7 , wherein the operations further comprise:

establishing an out-of-band (OOB) communication channel with the target computing device, wherein the signal comprises one or more of a visual indicator presented on a display; an audible indicator; or a tactile indicator;

obtaining, from a trusted third party, the set of expected attestation measurements for the target computing device;

transmitting the security status relating to the target computing device to the trusted third party; and

storing the security status relating to the target computing device.

9 . The computer-readable medium of claim 7 , wherein the computing device comprises one or more processors including one or more application processors or one or more graphics processors.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2022
From: BRONK, MATEUSZ; BERENT, ARKADIUSZ; ZMIJEWSKI, PIOTR
To: INTEL CORPORATION
Reel/Frame 058651/0106 →
Continuity (1)
Related Publication 20220108008A1 · Apr 7, 2022
References Cited (5)
US 20080046752A1 · Berger · 2008 [cited by examiner]
US 20130263262A1 · Forristal · 2013 [cited by examiner]
US 20140173689A1 · Klustaitis · 2014 [cited by examiner]
US 20170353308A1 · Reitsma · 2017 [cited by examiner]
US 20220070178A1 · Lee · 2022 [cited by examiner]