IP Library › Granted Patent US 11,489,874
Granted Patent B2
US 11,489,874 · App. 16/712,587 · Granted Nov 1, 2022

Trusted-code generated requests

Inventors: Gregory Branchek Roth (Seattle, WA); Eric Jason Brandwine (Haymarket, VA)
Assignee: Amazon Technologies, Inc.
H04L63/20G06F21/33G06F21/44G06F21/57G06F21/64H04L9/0825H04L9/0897H04L9/3213H04L9/3263H04L63/0823H04L9/32H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,874
App. No.
16/712,587
Granted
Nov 1, 2022
Kind
B2
Abstract

Custom policies are definable for use in a system that enforces policies. A user, for example, may author a policy using a policy language and transmit the system through an application programming interface call. The custom policies may specify conditions for computing environment attestations that are provided with requests to the system. When a custom policy applies to a request, the system may determine whether information in the attestation is sufficient for the request to be fulfilled.

Claims (43)

1. One or more non-transitory computer readable media storing executable instructions that, as a result of being executed on one or more processors of a computer system, cause the computer system to at least:

generate an attestation of a computing environment of the computer system;

submit, to an application programming interface accessible via a computer network, the attestation for signature to a remote attestation service, causing the remote attestation service to produce a signed attestation by signing the attestation with a private key of a public-private key pair, the signed attestation produced from the attestation in accordance with a policy that has a computing attestation condition, evaluation of the policy with respect to a first computing environment attestation causing a different result than evaluation of the policy with respect to a second computing environment attestation different from the first computing environment attestation, the attestation generated and signed before the policy is applied to a request, with application of the policy including a determination of whether information in the attestation complies with a condition of the policy; and

obtain, via the computer network, the signed attestation from the remote attestation service.

2. The one or more non-transitory computer readable media of claim 1 , wherein the executable instructions, as a result of being executed by the one or more processors, further cause the computer system to provide the signed attestation to an application server via the computer network.

3. The one or more non-transitory computer readable media of claim 2 , wherein:

the policy is enforced by the application server; and

as a result of the policy being applicable to a received request, fulfillment of the request is dependent on the signed attestation.

4. The one or more non-transitory computer readable media of claim 3 , wherein the executable instructions, as a result of being executed by the one or more processors, further cause the computer system to obtain, from the application server, results of the attestation.

5. The one or more non-transitory computer readable media of claim 1 , wherein the executable instructions, as a result of being executed by the one or more processors, further cause the computer system to obtain, from an application running on the computer system, via an application programming interface, a request for attestation.

6. The one or more non-transitory computer readable media of claim 1 , wherein the computer system is a handheld device that includes the one or more processors and one or more memories storing the executable instructions.

7. A handheld computing device comprising:

the one or more non-transitory computer readable media of claim 1 ; and

a cellular communication interface.

8. One or more non-transitory computer readable media storing executable instructions that, as a result of being executed on one or more processors of a computer system, cause the computer system to at least:

generate a request for attestation of the computer system;

submit, under control of an application running on the computer system, via an application programming interface, the request to an attestation service;

as a result of submitting the request, cause the attestation service to produce an attestation in accordance with a policy that has a computing attestation condition, evaluation of the policy with respect to a first computing environment attestation causing a different result than evaluation of the policy with respect to a second computing environment attestation different from the first computing environment attestation, the attestation generated and signed before the policy is applied to a request including by a determination that the attestation complies with the policy;

obtain, via a computer network, a signed attestation in exchange for the attestation from a remote attestation service, the signed attestation signed with a private key of a public-private key pair; and

obtain, at the application, the signed attestation from the attestation service.

9. The one or more non-transitory computer readable media of claim 8 , wherein the executable instructions, as a result of being executed by the one or more processors, further cause the computer system to provide the signed attestation to an application server via the computer network.

10. The one or more non-transitory computer readable media of claim 9 , wherein:

the policy is enforced by the application server; and

the application server helps fulfill the request based at least in part on the signed attestation.

11. The one or more non-transitory computer readable media of claim 10 , wherein the executable instructions, as a result of being executed by the one or more processors, further cause the computer system to obtain, from the application server, results of the attestation.

12. The one or more non-transitory computer readable media of claim 8 , wherein the executable instructions, as a result of being executed by the one or more processors, further cause the computer system to submit, via the computer network, the attestation for signature to the remote attestation service.

13. The one or more non-transitory computer readable media of claim 8 , wherein the executable instructions, as a result of being executed by the one or more processors, further cause the computer system to further verify that the attestation is based at least in part on a cryptographic key.

14. The one or more non-transitory computer readable media of claim 13 , wherein the cryptographic key is a public cryptographic key associated with a hardware device.

15. A first computer system comprising:

one or more processors; and

memory storing executable instructions that, as a result of being executed by the one or more processors, cause the first computer system to:

obtain, from an attestation service running on a second computer system, via a computer network, an attestation of a computing environment of the second computer system;

produce a signed attestation by signing the attestation with a private key of a public-private key pair, the signed attestation produced in accordance with a policy that has a computing attestation condition, evaluation of the policy with respect to a first computing environment attestation causing a different result than evaluation of the policy with respect to a second computing environment attestation different from the first computing environment attestation, the attestation generated and signed before the policy is applied to a request including by a determination of whether information in the attestation complies with a condition of the policy; and

provide, via the computer network, the signed attestation to the attestation service running on the second computer system.

16. The first computer system of claim 15 , wherein the attestation is generated by the attestation service as the result of a request generated by an application running on the second computer system.

17. The first computer system of claim 15 , wherein the signed attestation is produced using a private cryptographic key associated with the first computer system.

18. The first computer system of claim 17 , wherein:

the first computer system provides a digital certificate to the second computer system; and

the digital certificate includes a public cryptographic key corresponding to the private cryptographic key.

19. The first computer system of claim 15 , wherein the attestation comprises a cryptographic hash of executable instructions stored on the second computer system.

20. The first computer system of claim 15 , wherein:

the second computer system comprises a cellular phone; and

the computer network is a cellular network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2019
From: ROTH, GREGORY BRANCHEK; BRANDWINE, ERIC JASON
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 051269/0180 →
Continuity (3)
Continuation 15619979 · Jun 12, 2017
Continuation 14225249 · Mar 25, 2014
Related Publication 20200120140A1 · Apr 16, 2020
Cited By (1)
US 12,536,290