IP Library › Granted Patent US 12,505,202
Granted Patent B2
US 12,505,202 · App. 18/548,396 · Granted Dec 23, 2025

Methods and means for attestation of a platform

Inventors: Ilhan Gurel (Espoo, FI); Bernard Smeets (Dalby, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
G06F21/53G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,202
App. No.
18/548,396
Granted
Dec 23, 2025
Kind
B2
Abstract

A method for enabling attestation of a platform comprising a Trusted Execution Environment, TEE, and a Trusted Platform Module, TPM is disclosed. The method is performed by the TEE and comprises: receiving, from an Application of the platform, a request for generation of an attestation quote, the request comprising a nonce, information on which PCR(s) to be used and information about Attestation Keys; establishing a connection to the TPM and obtaining from it at least one PCR value; generating an attestation quote based on the received nonce and the at least one PCR value; signing the attestation, and rendering the attestation quote available for the Application.

Claims (28)

1 . A method for enabling attestation of a platform comprising a Trusted Execution Environment (TEE) and a Trusted Platform Module (TPM), the TPM comprising a TPM Platform Configuration Register(s) (PCR(s)), the method being performed by the TEE and comprising:

receiving, from an Application of the platform, a request for generation of an attestation quote, the request comprising a nonce, information on which PCR(s) to be used and information relating to Attestation Keys;

establishing a connection to the TPM and obtaining from the TPM at least one PCR value;

generating the attestation quote based on the received nonce and the at least one PCR value;

signing the attestation quote, and

rendering the attestation quote available for the Application, wherein the signing the attestation quote comprises signing the attestation quote using an attestation key and appending an associated certificate to the attestation quote.

2 . The method as claimed in claim 1 , further comprising: before the rendering, providing the attestation quote to the Application for verification of the attestation quote.

3 . A Trusted Execution Environment (TEE) for enabling attestation of a platform, the TEE comprising:

processing circuitry configured to:

receive, from an Application of the platform, a request for generation of an attestation quote, the request comprising a nonce and information on which Platform Configuration Register(s) (PCR(s)) to be used;

establish a connection to a Trusted Platform Module (TPM) and obtaining from the TPM at least one PCR value;

generate the attestation quote based on the received nonce and the at least one PCR value;

sign the attestation quote, and

render the attestation quote available for the Application, wherein the signing the attestation quote comprises signing the attestation quote using an attestation key and appending an associated certificate to the attestation quote.

4 . The TEE as claimed in claim 3 , wherein the processing circuitry is configured to: before the rendering, provide the attestation quote to the Application for verification of the attestation quote.

5 . A method for generating an attestation quote, the method being performed by an Application stored on a host of a platform, the method comprising:

providing, to a Trusted Execution Environment (TEE) of the platform, a nonce and information on a Trusted Platform Module Platform Configuration Register (PCR), which is to be used,

obtaining in response to the providing, the attestation quote from the TEE, and

providing the attestation quote to a Verifier for verification of authenticity of a signature of the attestation quote, wherein the obtained attestation quote is signed by the TEE using an attestation key and appended with an associated certificate.

6 . The method as claimed in claim 5 , wherein the application is associated with a single TEE.

7 . An Application enabling generation of an attestation quote, the Application comprising:

processing circuitry configured to:

provide, to a Trusted Execution Environment (TEE) of a platform on which the Application is stored, a nonce and information on a Trusted Platform Module Platform Configuration Register (PCR), which is to be used,

obtain in response to the providing, the attestation quote from the TEE, and provide the attestation quote to a Verifier for verification of authenticity of a signature of the attestation quote, wherein the obtained attestation quote is signed by the TEE using an attestation key and appended with an associated certificate.

8 . The Application as claimed in claim 7 , wherein the Application is associated with a single TEE.

9 . A platform comprising a Trusted Platform Module (TPM) and a Trusted Execution Environment (TEE), the platform further comprising processing circuitry, the processing circuitry being configured to cause the platform to perform the method of claim 1 .

10 . The platform as claimed in claim 9 , further comprising an application.

11 . The platform as claimed in claim 9 , wherein the platform is a user equipment, a wireless communication device, a personal computer or a laptop.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2023
From: SMEETS, BERNARD
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064753/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2023
From: GUREL, ILHAN
To: OY L M ERICSSON AB
Reel/Frame 064753/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2023
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064753/0702 →
Continuity (2)
Related Publication 20240134966A1 · Apr 25, 2024
Related Publication 20240232332A9 · Jul 11, 2024
References Cited (11)
US 10735190B1 · Khare · 2020 [cited by examiner]
US 20120246470A1 · Nicolson et al. · 2012 [cited by applicant]
US 20140130124A1 · Ekberg · 2014 [cited by applicant]
US 20160050071A1 · Collart et al. · 2016 [cited by applicant]
US 20190140846A1 · Moore et al. · 2019 [cited by applicant]
US 20210117534A1 · Maximov et al. · 2021 [cited by applicant]
EP 3193485A1 · 2017 [cited by applicant]
WO WO2017131775A1 · 2017 [cited by examiner]
WO 2019185125A1 · 2019 [cited by applicant]
Wagner, P.G. et al.; “Establishing Secure Communication Channels Using Remote Attestation with TPM 2.0”; Security Trust and Management; 16th International Workshop; XP47561829A; Sep. 17-18, 2020; 17 pages. [cited by applicant]
Communication pursuant to 94(3) EPC mailed Oct. 11, 2024 for European Patent Application No. 21716371.6, 9 pages. [cited by applicant]