IP Library Granted Patent US 12,425,860
Granted Patent B2
US 12,425,860 · App. 18/118,202 · Granted Sep 23, 2025

Apparatus and method for performing remote attestation by taking into account mobility

Inventors: Kyeong Tae Kim (Daejeon, KR); Young Ho Kim (Daejeon, KR); Jeong Nyeo Kim (Daejeon, KR); Seon Gyoung Sohn (Daejeon, KR); Yun Kyung Lee (Daejeon, KR); Jae Deok Lim (Daejeon, KR)
Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
H04W12/108H04L9/3073H04L9/3213H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,860
App. No.
18/118,202
Granted
Sep 23, 2025
Kind
B2
Abstract

Provided are an apparatus and method for performing remote attestation by taking into account mobility. The method includes obtaining, by each node constituting a network, a remote attestation result value by performing self-remote attestation, obtaining, by each of the nodes, remote attestation result values from the other nodes by broadcasting the obtained remote attestation result value to at least one neighboring node, and monitoring, by each of the nodes, remote attestation of each of the nodes on the basis of the obtained remote attestation result values of the nodes.

Claims (21)

1. A remote attestation method performed by taking into account mobility, comprising:

obtaining, by each node constituting a network, a remote attestation result value by performing self-remote attestation;

obtaining, by each of the nodes, remote attestation result values from other nodes by broadcasting the obtained remote attestation result value to at least one neighboring node; and

monitoring, by each of the nodes, remote attestation of each of the nodes based on the obtained remote attestation result values of the nodes, wherein in a snapshot state representing a final network state in which remote attestation result values from other nodes are obtained, each of the nodes updates its own network snapshot message using network snapshot messages of nodes whose integrity has been verified, wherein the obtaining of the remote attestation result value by performing the self-remote attestation comprises recording the remote attestation result value of each of the nodes in a predetermined network message using a Bloom filter.

2. The remote attestation method of claim 1 , wherein the obtaining of the remote attestation result values from the other nodes comprises obtaining remote attestation result values of the other nodes by broadcasting the network message to the at least one neighboring node and updating the network message using a preset consensus protocol and a network message received from the at least one neighboring node.

3. The remote attestation method of claim 2 , wherein the obtaining of the remote attestation result values from the other nodes comprises updating, by each of the nodes, the network message by combining a remote attestation result value recorded in the network message with a remote attestation result value recorded in the received network message.

4. The remote attestation method of claim 2 , wherein the consensus protocol comprises a symmetric key-based consensus protocol or an asymmetric key-based consensus protocol.

5. The remote attestation method of claim 2 , wherein the obtaining of the remote attestation result values from the other nodes comprises: verifying, by each of the nodes, integrity of each of the nodes using the consensus protocol; updating the network message with a network message of at least one node with verified integrity; and obtaining remote attestation result values of the other nodes through the updated network message.

6. The remote attestation method of claim 5 , wherein the verifying of the integrity of each of the nodes comprises: starting, by the nodes, generation of tokens by generating commitment values; generating the tokens by integrating identifiers and commitment values corresponding to neighboring nodes of the nodes; and verifying integrity of the nodes participating in the generation of the tokens using the tokens.

7. The remote attestation method of claim 6 , wherein the verifying of the integrity of the nodes participating in the generation of the tokens comprises: storing, by nodes participating in the generation of a token among the tokens, signature values corresponding to the nodes in the token; integrating the signature values corresponding to the nodes; and verifying integrity of the nodes participating in the generation of the tokens by verifying integrated commitment values and the integrated signature values.

8. The remote attestation method of claim 7 , wherein the commitment values (R i ) are generated to correspond to R i =g{circumflex over ( )}{r i } with respect to a group G with a prime order q, a generator g of the group G, and a secret random number r i .

9. The remote attestation method of claim 8 , wherein the signature values (Si) are generated to correspond to s i= r i +cx i with respect to a signature private key x i among pairs of signature keys, the secret random number r i , and a hash value c, and wherein the hash value c is generated to correspond to the integrated commitment values and a message requesting an electronic signature.

10. The remote attestation method of claim 9 , wherein the verifying of the integrated commitment values and the integrated signature values comprises using a common public key obtained by integrating signature public keys among the pairs of signature keys.

11. A remote attestation method performed by taking into account mobility, comprising:

performing, by each node constituting a network, self-remote attestation to obtain a remote attestation result value and recording the obtained remote attestation result value in a network message of the node; receiving, by each of the nodes, a network message broadcast from at least one neighboring node; updating by each of the nodes the network message using the received network message and a preset consensus protocol; and monitoring, by each of the nodes, remote attestation of the nodes constituting the network based on a remote attestation result value updated in the network message, wherein in a snapshot state representing a final network state in which remote attestation result values from other nodes are obtained, each of the nodes updates its own network snapshot message using network snapshot messages of nodes whose integrity has been verified, wherein the recording of the obtained remote attestation result value in the network message comprises recording the obtained remote attestation result value in the network message using a Bloom filter.

12. The remote attestation method of claim 11 , wherein the updating of the network message comprises: verifying integrity of each of the nodes using the consensus protocol; and updating the network message with a network message of a node with verified integrity.

13. The remote attestation method of claim 12 , wherein the verifying of the integrity of each of the nodes comprises: starting, by the nodes, generation of tokens by generating commitment values; generating the tokens by integrating identifiers and commitment values corresponding to neighboring nodes of the nodes; and verifying integrity of the nodes participating in the generation of the tokens using the tokens.

14. The remote attestation method of claim 13 , wherein the verifying of the integrity of the nodes participating in the generation of the tokens comprises: storing, by nodes participating in the generation of a token among the tokens, signature values corresponding to the nodes in the token; integrating the signature values corresponding to the nodes; and verifying integrity of the nodes participating in the generation of the tokens by verifying integrated commitment values and the integrated signature values.

15. A remote attestation apparatus for performing remote attestation by taking into account mobility, comprising: a processor configured to perform self-remote attestation to obtain a remote attestation result value and record the obtained remote attestation result value in a network message of the self-verifier; and a receiver configured to receive a network message broadcast from at least one neighboring node, wherein the processor is further configured to update the network message using the received network message and a preset consensus protocol and to monitor remote attestation of nodes constituting a network based on a remote attestation result value updated in the network message, wherein in a snapshot state representing a final network state in which remote attestation result values from other nodes are obtained, each of the nodes updates its own network snapshot message using network snapshot messages of nodes whose integrity has been verified, wherein the processor records the obtained remote attestation result value in the network message using a Bloom filter.

16. The remote attestation apparatus of claim 15 , wherein the processor verifies integrity of each of the nodes using the consensus protocol and updates the network message with a network message of a node with verified integrity.

17. The remote attestation apparatus of claim 16 , wherein the processor is further configured to: start generation of tokens by generating commitment values of the nodes; generate the tokens by integrating identifiers and commitment values corresponding to neighboring nodes of the nodes; store signature values corresponding to nodes participating in the generation of a token among the tokens in the token; integrate the signature values corresponding to the nodes; and verify integrity of the nodes participating in the generation of the tokens by verifying the integrated commitment values and the integrated signature values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2023
From: KIM, KYEONG TAE; KIM, YOUNG HO; KIM, JEONG NYEO; SOHN, SEON GYOUNG; LEE, YUN KYUNG; LIM, JAE DEOK
To: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
Reel/Frame 062901/0238 →
Priority Claims (1)
KR 10-2022-0029162 · Mar 8, 2022 · national
Continuity (1)
Related Publication 20230292129A1 · Sep 14, 2023
References Cited (18)
US 10180842B2 · Moon · 2019 [cited by applicant]
US 10511488B2 · Moon et al. · 2019 [cited by applicant]
US 11343091B2 · Sheth · 2022 [cited by examiner]
US 20160149708A1 · Garcia Morchon · 2016 [cited by examiner]
US 20180089014A1 · Smith · 2018 [cited by examiner]
US 20190349426A1 · Smith · 2019 [cited by examiner]
US 20220200985A1 · Simon · 2022 [cited by examiner]
CN 110635904B · 2020 [cited by examiner]
CN 112217775A · 2021 [cited by examiner]
CN 114070733A · 2022 [cited by examiner]
EP 3740918A1 · 2020 [cited by examiner]
KR 1020170122545A · 2017 [cited by applicant]
KR 102176115B1 · 2020 [cited by applicant]
KR 102205779B1 · 2021 [cited by applicant]
N. Asokan et al., “SEDA: Scalable embedded device attestation”, CCS'15, Oct. 12-16, 2015, Denver, Colorado, USA. [cited by applicant]
Xavier Carpent et al., “Lightweight Swarm Attestation: A Tale of Two Lisa-s”, Asia CCS '17, Apr. 2-6, 2017, Abu Dhabi, United Arab Emirates. [cited by applicant]
Salvatore Frontera et al, “Bloom Filter based Collective Remote Attestation for Dynamic Networks”, ARES 21 (Aug. 31, 2021). [cited by applicant]
Florian Kohnhauser et al, “A Practical Attestation Protocol for Autonomous Embedded Systems”, 2019 IEEE European Symposium on Security and Privacy (Jun. 19, 2019). [cited by applicant]