IP Library › Granted Patent US 12,411,928
Granted Patent B2
US 12,411,928 · App. 18/284,429 · Granted Sep 9, 2025

Attestation-as-a-service for confidential computing

Inventors: Yeluri Raghuram (Sunnyvale, CA); Haidong Xia (Folsom, CA); Uttam Shetty (Granite Bay, CA); Anil Rao (Menlo Park, CA); Sudhir Subbarao Bangalore (Bangalore, IN); Raghavender Nagarajan (Bangalore, IN); Kekuut Hoomkwap (Clarksburg, VA); Wei Peng (Folsom, CA)
Assignee: Intel Corporation
G06F21/33G06F21/53G06F21/57G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,411,928
App. No.
18/284,429
Granted
Sep 9, 2025
Kind
B2
Abstract

Various systems and methods are described for implementing trust authority or trust attestation verification operations, including for Trust-as-a-Service or Attestation-as-a-Service implementations, in accordance with the techniques discussed herein. In various examples, operations and configurations are described to enable service-to-service attestation using a trust authority, to operate an attestation service, and to coordinate trust operations between relying and requesting parties.

Claims (30)

1. A computing system at a trust service provider, comprising:

communication circuitry to receive a communication from a requesting party; and

processing circuitry to perform operations that:

identify the communication as a request for attestation evidence of a compute configuration of the requesting party, the attestation evidence to provide trust claims for the requesting party to be evaluated by a relying party,

wherein the requesting party is located in a first operational domain, wherein the relying party is located in a second operational domain, and wherein the trust service provider is located at a third operational domain;

create an attestation token based on an attestation policy associated with the relying party, the attestation token providing a proof of trust for the trust claims in connection with at least one trusted computing component at the requesting party; and

provide the attestation token to the requesting party, to enable the requesting party to present the attestation token to the relying party as the proof of trust for the trust claims.

2. The computing system of claim 1 , wherein in response to providing of the attestation token to requesting party, the requesting party forwards the attestation token to the relying party, and the relying party verifies the trust claims based on the attestation token.

3. The computing system of claim 2 , wherein the relying party controls access to a resource based on verifying the trust claims.

4. The computing system of claim 2 , wherein the relying party performs a communication session with the requesting party based on verifying the trust claims.

5. The computing system of claim 1 , wherein the request for attestation evidence is provided from the requesting party to the trust service provider in response to a request for the proof of trust provided from the relying party to the requesting party.

6. The computing system of claim 1 , wherein the attestation policy specifies requirements for proof of attestation.

7. The computing system of claim 1 , wherein the operations are performed by an attestation service at the trust service provider, and wherein the attestation service operates with one or more microservices.

8. The computing system of claim 1 , wherein the first operational domain corresponds to a first compute environment controlled by a first cloud service provider, wherein the second operational domain corresponds to a second compute environment controlled by a second cloud service provider, and wherein the third operational domain corresponds to a third compute environment controlled by the trust service provider.

9. The computing system of claim 1 , wherein the compute configuration of the requesting party relates to use of a trusted execution environment at the requesting party.

10. The computing system of claim 1 , wherein operations of receiving the request, creating the attestation token, and providing the attestation token, are repeated on behalf of the requesting party, to obtain additional attestation evidence that provides additional trust claims for the relying party to be evaluated by the requesting party, to enable the relying party and the requesting party to perform mutual attestation.

11. A method for generating proof of attestation, performed at a trust service provider, comprising:

receiving a request from a requesting party for attestation evidence of a compute configuration of the requesting party, the attestation evidence to provide trust claims for the requesting party to be evaluated by a relying party,

wherein the requesting party is located in a first operational domain, wherein the relying party is located in a second operational domain, and wherein the trust service provider is located at a third operational domain;

creating an attestation token based on an attestation policy associated with the relying party, the attestation token providing a proof of trust for the trust claims in connection with at least one trusted computing component at the requesting party; and

providing the attestation token to the requesting party, to enable the requesting party to present the attestation token to the relying party as the proof of trust for the trust claims.

12. The method of claim 11 , wherein in response to providing of the attestation token to requesting party, the requesting party forwards the attestation token to the relying party, and the relying party verifies the trust claims based on the attestation token.

13. The method of claim 12 , wherein the relying party controls access to a resource based on verifying the trust claims.

14. The method of claim 12 , wherein the relying party performs a communication session with the requesting party based on verifying the trust claims.

15. The method of claim 11 , wherein the request for attestation evidence is provided from the requesting party to the trust service provider in response to a request for the proof of trust provided from the relying party to the requesting party.

16. The method of claim 11 , wherein the attestation policy specifies requirements for proof of attestation.

17. The method of claim 11 , wherein the method is performed by an attestation service at the trust service provider, and wherein the attestation service operates with one or more microservices.

18. The method of claim 11 , wherein the first operational domain corresponds to a first compute environment controlled by a first cloud service provider, wherein the second operational domain corresponds to a second compute environment controlled by a second cloud service provider, and wherein the third operational domain corresponds to a third compute environment controlled by the trust service provider.

19. The method of claim 11 , wherein the compute configuration of the requesting party relates to use of a trusted execution environment at the requesting party.

20. The method of claim 11 , wherein operations of receiving the request, creating the attestation token, and providing the attestation token, are repeated on behalf of the requesting party, to obtain additional attestation evidence that provides additional trust claims for the relying party to be evaluated by the requesting party, to enable the relying party and the requesting party to perform mutual attestation.

Priority Claims (1)
IN 202141028574 · Jun 25, 2021 · national
Continuity (2)
Provisional Application 63339847 · May 9, 2022
Related Publication 20240160717A1 · May 16, 2024
References Cited (21)
US 11037118B2 · Kraemer · 2021 [cited by examiner]
US 11122346B1 · Kumar · 2021 [cited by examiner]
US 12132844B1 · Allen · 2024 [cited by examiner]
US 20170251025A1 · Varley et al. · 2017 [cited by applicant]
US 20180096412A1 · Scott-Nash · 2018 [cited by examiner]
US 20180315026A1 · Kraemer et al. · 2018 [cited by applicant]
US 20190327096A1 · Liu et al. · 2019 [cited by applicant]
US 20200084202A1 · Smith · 2020 [cited by examiner]
US 20200344265A1 · Kelly · 2020 [cited by examiner]
US 20220394054A1 · Sheth · 2022 [cited by examiner]
US 20230297410A1 · Sood · 2023 [cited by examiner]
CN 117121006 · 2023 [cited by applicant]
KR 20210061541A · 2021 [cited by applicant]
WO WO2022272064A1 · 2022 [cited by applicant]
“U.S. Appl. No. 18/284,429, Preliminary Amendment filed Sep. 27, 2023”, 7 pages. [cited by applicant]
“International Application Serial No. PCT US2022 034906, International Preliminary Report on Patentability mailed Jan. 4, 2024”, 7 pgs. [cited by applicant]
“European Application Serial No. 22829386.6, Extended European Search Report mailed Mar. 20, 2025”, 12 pgs. [cited by applicant]
Kirkman, Stephen S, “Bridging the Cloud Trust Gap Using ORCON Policy to Manage Consumer Trust between Different Clouds”, IEEE International Conference On Edge Computing (EDGE), IEEE, (Jun. 25, 2017), 82-89. [cited by applicant]
“International Application Serial No. PCT/US2022/034906, International Search Report mailed Oct. 13, 2022”, 4 pgs. [cited by applicant]
“International Application Serial No. PCT/US2022/034906, Written Opinion mailed Oct. 13, 2022”, 5 pgs. [cited by applicant]
“European Application Serial No. 22829386.6, Response Filed Apr. 28, 2025 to Extended European Search Report mailed Mar. 20, 2025”, 20 pgs. [cited by applicant]
Cited By (1)
US 12,549,380