IP Library Granted Patent US 11,977,620
Granted Patent B2
US 11,977,620 · App. 17/648,362 · Granted May 7, 2024

Attestation of application identity for inter-app communications

Inventors: Simon Paul Brooks (Napa, CA); Anuj Panwar (Atlanta, GA); Siavash James Joorabchian Hawkins (Canterbury, GB)
Assignee: VMware LLC
G06F21/44H04L63/0823H04L67/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,977,620
App. No.
17/648,362
Granted
May 7, 2024
Kind
B2
Abstract

Examples for validating the identify of an application in an inter-app communication protocol are described. An attestation payload is obtained from a third party attestation service that is executed remotely from a device on which the application is running. The attestation payload can be validated by another application on the device in order to validate the identity of the application providing the attestation payload.

Claims (34)

1. A system, comprising:

a client device comprising at least one processor; and

a sending application executable by the client device that, when executed, direct the client device to at least:

generate a key pair comprising a public key and a private key;

transmit a request for an attestation payload from an attestation service executed remotely from the client device, the request for the attestation payload comprising the public key or an identifier corresponding to the public key;

obtain the attestation payload from the attestation service, the attestation payload comprising an identifier identifying the sending application; and

provide the attestation payload to a receiving application executed on the client device, wherein the receiving application validates an identity of the sending application based upon the attestation payload obtained from the attestation service.

2. The system of claim 1 , wherein the attestation payload comprises a hash value based upon an application identifier associated with the sending application.

3. The system of claim 1 , wherein the attestation payload is signed using an attestation certificate associated with an operating system platform provider that is verifiable by the receiving application.

4. The system of claim 1 , wherein the sending application provides the attestation payload in an OpenURL request generated by the sending application, wherein the attestation payload is provided as a parameter to the OpenURL request.

5. The system of claim 4 , wherein the OpenURL request is signed by the private key of the sending application.

6. The system of claim 4 , wherein the OpenURL request further comprises a device secret, wherein the device secret comprises an uptime counter obtained from an operating system of the client device.

7. The system of claim 1 , wherein the receiving application provides a token in response to validating the identity of the sending application.

8. A non-transitory computer-readable medium embodying instructions executed by a client device, the instructions, when executed, causing the client device to at least:

generate a key pair comprising a public key and a private key;

transmit a request for an attestation payload from an attestation service executed remotely from the client device, the request for the attestation payload comprising the public key or an identifier corresponding to the public key;

obtain the attestation payload from the attestation service, the attestation payload comprising an identifier identifying a sending application; and

provide the attestation payload to a receiving application executed on the client device, wherein the receiving application validates an identity of the sending application based upon the attestation payload obtained from the attestation service.

9. The non-transitory computer-readable medium of claim 8 , wherein the attestation payload comprises a hash value based upon an application identifier associated with the sending application.

10. The non-transitory computer-readable medium of claim 8 , wherein the attestation payload is signed using an attestation certificate associated with an operating system platform provider that is verifiable by the receiving application.

11. The non-transitory computer-readable medium of claim 8 , wherein the instructions provide the attestation payload in an OpenURL request generated by the sending application, wherein the attestation payload is provided as a parameter to the OpenURL request.

12. The non-transitory computer-readable medium of claim 11 , wherein the OpenURL request is signed by the private key of the sending application.

13. The non-transitory computer-readable medium of claim 11 , wherein the OpenURL request further comprises a device secret, wherein the device secret comprises an uptime counter obtained from an operating system of the client device.

14. The non-transitory computer-readable medium of claim 8 , wherein the receiving application provides a token in response to validating the identity of the sending application.

15. A method, comprising:

generating, on a client device, a key pair comprising a public key and a private key;

transmitting, on the client device, a request for an attestation payload from an attestation service executed remotely from the client device, the request for the attestation payload comprising the public key or an identifier corresponding to the public key;

obtaining, on the client device, the attestation payload from the attestation service, the attestation payload comprising an identifier identifying a sending application; and

providing, on the client device, the attestation payload to a receiving application executed on the client device, wherein the receiving application validates an identity of the sending application based upon the attestation payload obtained from the attestation service.

16. The method of claim 15 , wherein the attestation payload comprises a hash value based upon an application identifier associated with the sending application.

17. The method of claim 15 , wherein the attestation payload is signed using an attestation certificate associated with an operating system platform provider that is verifiable by the receiving application.

18. The method of claim 15 , further comprising providing, on the client device, the attestation payload in an OpenURL request generated by the sending application, wherein the attestation payload is provided as a parameter to the OpenURL request.

19. The method of claim 18 , wherein the OpenURL request is signed by the private key of the sending application.

20. The method of claim 18 , wherein the OpenURL request further comprises a device secret, wherein the device secret comprises an uptime counter obtained from an operating system of the client device.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2022
From: BROOKS, SIMON PAUL; PANWAR, ANUJ; HAWKINS, SIAVASH JAMES JOORABCHIAN
To: VMWARE, INC.
Reel/Frame 058697/0260 →
Continuity (1)
Related Publication 20230229752A1 · Jul 20, 2023