Attestation of a device under test
Attestation of an electronic device provides assurances that the device is trustworthy and operating as intended or, at least, within acceptable parameters. Methods and systems are provided herein wherein a device under test (DUT) is subject to tests, the results of which are provided to a trust verifier (TV) to indicate whether the DUT passed or failed. To protect the integrity of the test from being discovered by malware, the test logic is developed “off board” and only machine code is provided to the DUT. Similarly, memory values and other data of the DUT are not revealed to the TV, which is only provided with test results.
1 . A trust verification system for attesting whether a device under test (DUT) is trustworthy, comprising:
a processor coupled with a computer memory comprising computer readable instructions; and
a communication interface;
wherein, while the processor of the trust verification system is in communication the DUT via the communication interface, the processor:
receives, via the communication interface, testable attributes from the DUT;
generates, from the testable attributes, tests for execution on the DUT;
loads the tests into an executable memory of the DUT;
loads a test manager into the DUT;
signals the test manager to execute the tests; and
receives results from the test manager executing the tests.
2 . The system of claim 1 , wherein the processor further analyzes the results and selectively provides or withholds attestation of the DUT, wherein the DUT is enabled for service when the attestation is provided and disabled from service when the attestation is withheld.
3 . The system of claim 1 , wherein the DUT comprises a private computer memory maintaining proprietary data, and wherein the tests are generated to include at least one test of the private computer memory and the processor receives test results that are limited to indicia of success or failure of the at least one test.
4 . The system of claim 1 , wherein the DUT comprises a private software application and wherein the tests are generated to include at least one test of the private software application and the processor receives test results that are limited to indicia of success or failure of the at least one test.
5 . The system of claim 1 , wherein the processor generates a script to comprise the tests, and the script is generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the script is unknown to the DUT.
6 . The system of claim 5 , wherein the processor generates the script to comprise the at least one randomization of an order of the test therein.
7 . The system of claim 5 , wherein the processor generates the script to comprise the at least one randomization of a test attribute of at least one test.
8 . The system of claim 1 , wherein the processor generates the tests to comprise at least one test that further comprises a timing portion to measure the time utilized by the DUT to execute the at least one test and the results thereof include indicia of the time utilized.
9 . A method, comprising:
establishing communications between a trusted verifier and a device under test (DUT);
while the communications are established between the trusted verifier and the DUT:
collecting testable attributes from the DUT;
in response to collecting the testable attributes, generating, by the trusted verifier and from the testable attributes, tests for execution on the DUT;
loading the tests into an executable memory of the DUT;
loading a test manager into the DUT; and
executing the test manager by the DUT to perform the tests and report results therefrom to the trusted verifier.
10 . The method of claim 9 , wherein the DUT comprises a private computer memory and wherein the tests are generated to include at least one test of the private computer memory and report results that are limited to indicia of success or failure of the at least one test.
11 . The method of claim 9 , wherein the DUT comprises a proprietary software application and wherein the tests are generated to include at least one test of the proprietary software application and report results that are limited to indicia of success or failure of the at least one test.
12 . The method of claim 9 , wherein the tests are generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the tests is unknown to the DUT.
13 . The method of claim 12 , wherein the tests are generated to comprise the at least one randomization of an order of the test therein.
14 . The method of claim 12 , wherein the tests are generated to comprise the at least one randomization of a test attribute of at least one test.
15 . The method of claim 9 , wherein the tests comprise at least one test that further comprises a timing portion for the DUT to execute the at least one test and wherein the results include indicia of the time utilized to execute the at least one test.
16 . A device under test (DUT), comprising:
a processor coupled with a computer memory comprising computer readable instructions;
a communication interface to a network;
a volatile memory; and
a data storage;
wherein the processor performs:
upon being placed in communication with a trust verifier (TV), via the communication interface, accessing testable attributes of the DUT from the data storage and sending the testable attributes to the TV;
while in communication with the TV, and in response to sending the testable attributes to the TV, receiving from the TV tests and a test manager, loading the tests and the test manager into the volatile memory, executing the test manager, and returning test results to the TV; and
upon receiving a signal from the test manager that the tests are finished, initiating at least one of a shutdown of the DUT or a reboot.
17 . The DUT of claim 16 , further comprising:
a data loader; and
wherein the processor, in response to sending the testable attributes to the TV, executes the data loader to perform the loading of the tests and the test manager into the volatile memory and executing the test manager.
18 . The DUT of claim 16 , further comprising:
a private computer memory maintaining proprietary data; and
wherein the processor provides at least one attribute of the private computer memory as a portion of the testable attributes; and
wherein the test manager is generated to permit at least one test of the private computer memory and output test results exclusively limited to indicia of success or failure of the at least one test.
19 . The DUT of claim 16 , further comprising:
a private software application; and
wherein the processor provides at least one attribute of the private software application as a portion of the testable attributes; and
wherein the test manager is generated to permit at least one test of the private software application and output test results exclusively limited to indicia of success or failure of the at least one test.
20 . The DUT of claim 16 , wherein the processor receives indicia of pass or fail from the TV and, in accordance with the indicia of pass or fail, selectively enables or disables a function of the DUT.
21 . A trust verification system for attesting whether a device under test (DUT) is trustworthy, comprising:
a processor coupled with a computer memory comprising computer readable instructions; and
a communication interface; and
wherein the processor performs:
upon being placed in communication with the DUT, via the communication interface, receiving testable attributes from the DUT;
generating, from the testable attributes, tests on the DUT, wherein the processor generates a script to comprise the tests, and the script is generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the script is unknown to the DUT;
loading the tests into an executable memory of the DUT;
loading a test manager into the DUT;
signaling the test manager to execute the tests; and
receiving results from the test manager executing the tests.
22 . A method, comprising:
collecting testable attributes from a device under test (DUT);
generating, from the testable attributes, tests on the DUT, wherein the tests are generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the tests is unknown to the DUT;
loading the tests into an executable memory of the DUT;
loading a test manager into the DUT; and
executing the test manager by the DUT to perform the tests and report results therefrom.