IP Library › Granted Patent US 12,613,966
Granted Patent B2
US 12,613,966 · App. 18/369,938 · Granted Apr 28, 2026

Attestation of a device under test

Inventors: Christopher Altick (Kettering, OH); Amy Sue Christopher (Miamisburg, OH); Kathleen Jo Frazier (Dayton, OH)
Assignee: BAE Systems Space & Mission Systems Inc.
G06F21/57G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,613,966
App. No.
18/369,938
Granted
Apr 28, 2026
Kind
B2
Abstract

Attestation of an electronic device provides assurances that the device is trustworthy and operating as intended or, at least, within acceptable parameters. Methods and systems are provided herein wherein a device under test (DUT) is subject to tests, the results of which are provided to a trust verifier (TV) to indicate whether the DUT passed or failed. To protect the integrity of the test from being discovered by malware, the test logic is developed “off board” and only machine code is provided to the DUT. Similarly, memory values and other data of the DUT are not revealed to the TV, which is only provided with test results.

Claims (68)

1 . A trust verification system for attesting whether a device under test (DUT) is trustworthy, comprising:

a processor coupled with a computer memory comprising computer readable instructions; and

a communication interface;

wherein, while the processor of the trust verification system is in communication the DUT via the communication interface, the processor:

receives, via the communication interface, testable attributes from the DUT;

generates, from the testable attributes, tests for execution on the DUT;

loads the tests into an executable memory of the DUT;

loads a test manager into the DUT;

signals the test manager to execute the tests; and

receives results from the test manager executing the tests.

2 . The system of claim 1 , wherein the processor further analyzes the results and selectively provides or withholds attestation of the DUT, wherein the DUT is enabled for service when the attestation is provided and disabled from service when the attestation is withheld.

3 . The system of claim 1 , wherein the DUT comprises a private computer memory maintaining proprietary data, and wherein the tests are generated to include at least one test of the private computer memory and the processor receives test results that are limited to indicia of success or failure of the at least one test.

4 . The system of claim 1 , wherein the DUT comprises a private software application and wherein the tests are generated to include at least one test of the private software application and the processor receives test results that are limited to indicia of success or failure of the at least one test.

5 . The system of claim 1 , wherein the processor generates a script to comprise the tests, and the script is generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the script is unknown to the DUT.

6 . The system of claim 5 , wherein the processor generates the script to comprise the at least one randomization of an order of the test therein.

7 . The system of claim 5 , wherein the processor generates the script to comprise the at least one randomization of a test attribute of at least one test.

8 . The system of claim 1 , wherein the processor generates the tests to comprise at least one test that further comprises a timing portion to measure the time utilized by the DUT to execute the at least one test and the results thereof include indicia of the time utilized.

9 . A method, comprising:

establishing communications between a trusted verifier and a device under test (DUT);

while the communications are established between the trusted verifier and the DUT:

collecting testable attributes from the DUT;

in response to collecting the testable attributes, generating, by the trusted verifier and from the testable attributes, tests for execution on the DUT;

loading the tests into an executable memory of the DUT;

loading a test manager into the DUT; and

executing the test manager by the DUT to perform the tests and report results therefrom to the trusted verifier.

10 . The method of claim 9 , wherein the DUT comprises a private computer memory and wherein the tests are generated to include at least one test of the private computer memory and report results that are limited to indicia of success or failure of the at least one test.

11 . The method of claim 9 , wherein the DUT comprises a proprietary software application and wherein the tests are generated to include at least one test of the proprietary software application and report results that are limited to indicia of success or failure of the at least one test.

12 . The method of claim 9 , wherein the tests are generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the tests is unknown to the DUT.

13 . The method of claim 12 , wherein the tests are generated to comprise the at least one randomization of an order of the test therein.

14 . The method of claim 12 , wherein the tests are generated to comprise the at least one randomization of a test attribute of at least one test.

15 . The method of claim 9 , wherein the tests comprise at least one test that further comprises a timing portion for the DUT to execute the at least one test and wherein the results include indicia of the time utilized to execute the at least one test.

16 . A device under test (DUT), comprising:

a processor coupled with a computer memory comprising computer readable instructions;

a communication interface to a network;

a volatile memory; and

a data storage;

wherein the processor performs:

upon being placed in communication with a trust verifier (TV), via the communication interface, accessing testable attributes of the DUT from the data storage and sending the testable attributes to the TV;

while in communication with the TV, and in response to sending the testable attributes to the TV, receiving from the TV tests and a test manager, loading the tests and the test manager into the volatile memory, executing the test manager, and returning test results to the TV; and

upon receiving a signal from the test manager that the tests are finished, initiating at least one of a shutdown of the DUT or a reboot.

17 . The DUT of claim 16 , further comprising:

a data loader; and

wherein the processor, in response to sending the testable attributes to the TV, executes the data loader to perform the loading of the tests and the test manager into the volatile memory and executing the test manager.

18 . The DUT of claim 16 , further comprising:

a private computer memory maintaining proprietary data; and

wherein the processor provides at least one attribute of the private computer memory as a portion of the testable attributes; and

wherein the test manager is generated to permit at least one test of the private computer memory and output test results exclusively limited to indicia of success or failure of the at least one test.

19 . The DUT of claim 16 , further comprising:

a private software application; and

wherein the processor provides at least one attribute of the private software application as a portion of the testable attributes; and

wherein the test manager is generated to permit at least one test of the private software application and output test results exclusively limited to indicia of success or failure of the at least one test.

20 . The DUT of claim 16 , wherein the processor receives indicia of pass or fail from the TV and, in accordance with the indicia of pass or fail, selectively enables or disables a function of the DUT.

21 . A trust verification system for attesting whether a device under test (DUT) is trustworthy, comprising:

a processor coupled with a computer memory comprising computer readable instructions; and

a communication interface; and

wherein the processor performs:

upon being placed in communication with the DUT, via the communication interface, receiving testable attributes from the DUT;

generating, from the testable attributes, tests on the DUT, wherein the processor generates a script to comprise the tests, and the script is generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the script is unknown to the DUT;

loading the tests into an executable memory of the DUT;

loading a test manager into the DUT;

signaling the test manager to execute the tests; and

receiving results from the test manager executing the tests.

22 . A method, comprising:

collecting testable attributes from a device under test (DUT);

generating, from the testable attributes, tests on the DUT, wherein the tests are generated to comprise at least one randomization of the tests therein, wherein the at least one randomization utilized to generate the tests is unknown to the DUT;

loading the tests into an executable memory of the DUT;

loading a test manager into the DUT; and

executing the test manager by the DUT to perform the tests and report results therefrom.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2024
From: ALTICK, CHRISTOPHER; CHRISTOPHER, AMY SUE; FRAZIER, KATHLEEN JO
To: BALL AEROSPACE & TECHNOLOGIES CORP.
Reel/Frame 069606/0344 →
CHANGE OF NAME Recorded Dec 17, 2024
From: BALL AEROSPACE & TECHNOLOGIES CORP.
To: BAE SYSTEMS SPACE & MISSION SYSTEMS INC.
Reel/Frame 069606/0533 →
Continuity (2)
Provisional Application 63421658 · Nov 2, 2022
Related Publication 20240143766A1 · May 2, 2024
References Cited (14)
US 9369484B1 · Lacerte et al. · 2016 [cited by applicant]
US 10182065B1 · Ryon et al. · 2019 [cited by applicant]
US 10523688B1 · Ryon et al. · 2019 [cited by applicant]
US 10546130B1 · Chaney · 2020 [cited by applicant]
US 11010268B1 · Chaney · 2021 [cited by applicant]
US 11086997B1 · Stephenson et al. · 2021 [cited by applicant]
US 11347841B1 · Bean et al. · 2022 [cited by applicant]
US 11514168B2 · Stephenson et al. · 2022 [cited by applicant]
US 20020073375A1 · Hollander · 2002 [cited by applicant]
US 20150012237A1 · Balog et al. · 2015 [cited by applicant]
US 20200110879A1 · Linton · 2020 [cited by examiner]
US 20230042055A1 · Stephenson et al. · 2023 [cited by applicant]
International Search Report and Written Opinion for International (PCT) Patent Application No. PCT/US23/74605, dated Dec. 12, 2023 14 pages. [cited by applicant]
International Preliminary Report on Patentability for International (PCT) Patent Application No. PCT/US2023/074605, dated May 15, 2025 8 pages. [cited by applicant]