IP Library › Granted Patent US 11,256,818
Granted Patent B2
US 11,256,818 · App. 16/119,357 · Granted Feb 22, 2022

System and method for enabling and verifying the trustworthiness of a hardware system

Inventors: Antonio J. Espinosa (Menlo Park, CA); Shashi Sastry (Menlo Park, CA); Vincent Bemmel (Menlo Park, CA); Sameer Merchant (Menlo Park, CA)
Assignee: Corlina, Inc.
G06F21/606G06F8/65G06F16/2255G06F16/9038G06F16/951G06F16/9538H04L9/0637H04L9/3239H04L63/12H04L63/1416H04L63/1425G06F8/60H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,256,818
App. No.
16/119,357
Granted
Feb 22, 2022
Kind
B2
Abstract

To determine whether an IoT system connected with a network environment (e.g., the internet) is compromised, a networked Trust as a Service (TaaS) server receives system data indicative of various characteristics of the IoT system, wherein the system data is harvested by a software agent installed on the IoT system. The TaaS server initially establishes a baseline characteristics profile for the IoT system, such that subsequently received system data from the software agent may be compared against the baseline characteristics profile to quickly identify discrepancies between the originally established baseline characteristics profile and current operating characteristics of the system. Such discrepancies may be caused by desirable software updates, in which case the discrepancies may be integrated into the baseline characteristics profile, or the discrepancies may result from the IoT system being undesirably compromised.

Claims (42)

1. A computer-implemented method for determining trust of an Internet of Things (IoT) system within a networked environment, the method comprising:

receiving, via a communication interface of a trust-as-a-service system in communication with the IoT system via a communication channel, system data indicative of artifacts of the IoT system harvested by a software agent installed on the IoT system, wherein the system data is pushed across the communication channel by the software agent installed on the IoT system, wherein the IoT system is in networked communication via the networked environment with one or more devices for operational interactions of the IoT system, and wherein the communication channel is initiated by the software agent installed on the IoT system and is characterized by a uniform resource locator (URL) associated with the trust-as-a-service system;

generating, via one or more processors, a baseline characteristics profile based at least in part on the system data;

storing the baseline characteristics profile within a storage device accessible to the one or more processors;

receiving, from the software agent installed on the IoT system and via the communication channel, updated system data indicative of updated artifacts harvested from the IoT system; and

determining whether the updated system data indicates that the IoT system is compromised by:

comparing the updated system data against the baseline characteristics profile; and

upon detecting a discrepancy between the updated system data and the baseline characteristics profile, establishing a trust metric based at least in part on the detected discrepancy.

2. The computer-implemented method of claim 1 , wherein the system data comprises one or more of: system hardware data; system image data; application data; and system behavior data.

3. The computer-implemented method of claim 1 , wherein at least a portion of the system data is harvested from firmware of the IoT system.

4. The computer-implemented method of claim 1 , wherein the storage device implements a storage system embodied as a blockchain ledger.

5. The computer-implemented method of claim 1 , further comprising steps for updating the baseline characteristics profile by: replacing at least a portion of the baseline characteristics profile with at least a portion of the updated system data.

6. The computer-implemented method of claim 1 , further comprising steps for generating an alert upon determining that the trust metric indicates that the IoT system is compromised.

7. The computer-implemented method of claim 1 , wherein: generating the baseline characteristics profile comprises generating a hash based at least in part on the system data; and comparing the updated system data against the baseline characteristics profile comprises: generating a hash based on the updated system data; and comparing the hash of the updated system data against the baseline characteristics profile.

8. A system for determining trust of an Internet of Things (IoT) system within a networked environment, the system comprising:

a communication interface in communication with the IoT system via a communication channel, wherein the communication interface is configured to receive system data indicative of artifacts of the IoT system harvested by a software agent installed on the IoT system, wherein the system data is pushed across the communication channel by the software agent installed on the IoT system, wherein the IoT system is in networked communication via the networked environment with one or more devices for operational interactions of the IoT system, and wherein the communication channel is initiated by the software agent installed on the IoT system and is characterized by a uniform resource locator (URL) associated with the trust-as-a- service system;

a storage device; and

one or more processors collectively configured to:

generate a baseline characteristics profile based at least in part on the system data;

store the baseline characteristics profile within the storage device;

receive, via the communication interface in communication with the software agent installed on the IoT system and via the communication channel, updated system data indicative of updated artifacts harvested from the IoT system; and

determine whether the updated system data indicates that the IoT system is compromised by:

comparing the updated system data against the baseline characteristics profile; and

upon detecting a discrepancy between the updated system data and the baseline characteristics profile, establishing a trust metric based at least in part on the detected discrepancy.

9. The system of claim 8 , wherein the system data comprises one or more of:

system hardware data; system image data; application data; and system behavior data.

10. The system of claim 8 , wherein at least a portion of the system data is harvested from firmware of the IoT system.

11. The system of claim 8 , wherein the storage device implements a storage system embodied as a blockchain ledger.

12. The system of claim 8 , wherein the one or more processors are further configured for updating the baseline characteristics profile by: replacing at least a portion of the baseline characteristics profile with at least a portion of the updated system data.

13. The system of claim 8 , wherein the one or more processors are further configured for generating an alert upon determining that the trust metric indicates that the IoT system is compromised.

14. The system of claim 8 , wherein: generating the baseline characteristics profile comprises generating a hash based at least in part on the system data; and comparing the updated system data against the baseline characteristics profile comprises: generating a hash based on the updated system data; and comparing the hash of the updated system data against the baseline characteristics profile.

15. A non-transitory computer-readable storage medium comprising executable portions stored thereon, wherein the executable portions are configured to, when executed by a processor, cause the processor to:

receive, via a communication interface in communication with an IoT system via a communication channel, system data indicative of artifacts of the IoT system harvested by a software agent installed on the IoT system, wherein the system data is pushed across the communication channel by the software agent installed on the IoT system, wherein the IoT system is in networked communication via the networked environment with one or more devices for operational interactions of the IoT system, and wherein the communication channel is initiated by the software agent installed on the IoT system and is characterized by a uniform resource locator (URL) associated with the trust-as- a-service system;

generate a baseline characteristics profile based at least in part on the system data; store the baseline characteristics profile within a storage device accessible to the one or more processors;

receive, from the software agent installed on the IoT system via the communication channel, updated system data indicative of updated artifacts harvested from the IoT system; and

determine whether the updated system data indicates that the IoT system is compromised by: comparing the updated system data against the baseline characteristics profile; and

upon detecting a discrepancy between the updated system data and the baseline characteristics profile, establishing a trust metric based at least in part on the detected discrepancy.

16. The non-transitory computer readable storage medium of claim 15 , wherein the system data comprises one or more of: system hardware data; system image data; application data; and system behavior data.

17. The non-transitory computer readable storage medium of claim 15 , wherein the storage device implements a storage system embodied as a blockchain ledger.

18. The non-transitory computer readable storage medium of claim 15 , wherein the executable portions are further configured to, when executed by the processor, cause the processor to: replace at least a portion of the baseline characteristics profile with at least a portion of the updated system data.

19. The non-transitory computer readable storage medium of claim 15 , wherein the executable portions are further configured to, when executed by the processor, cause the processor to generate an alert upon determining that the trust metric indicates that the IoT system is compromised.

20. The non-transitory computer readable storage medium of claim 15 , wherein: generating the baseline characteristics profile comprises generating a hash based at least in part on the system data; and comparing the updated system data against the baseline characteristics profile comprises: generating a hash based on the updated system data; and comparing the hash of the updated system data against the baseline characteristics profile.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2018
From: ESPINOSA, ANTONIO J.; SASTRY, SHASHI; BEMMEL, VINCENT; MERCHANT, SAMEER
To: CORLINA, INC.
Reel/Frame 047590/0376 →
Continuity (5)
Provisional Application 62639813 · Mar 7, 2018
Provisional Application 62611508 · Dec 28, 2017
Provisional Application 62613006 · Jan 2, 2018
Provisional Application 62623838 · Jan 30, 2018
Related Publication 20190207957A1 · Jul 4, 2019