IP Library Granted Patent US 12,476,870
Granted Patent B2
US 12,476,870 · App. 17/513,841 · Granted Nov 18, 2025

Data collection method and device

Inventors: Liang Xia (Shenzhen, CN); Zitao Wang (Nanjing, CN); Yulin Shi (Nanjing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L41/0886H04L9/3263H04L41/0816H04L41/0843H04L41/0866
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,870
App. No.
17/513,841
Granted
Nov 18, 2025
Kind
B2
Abstract

In a data collection method for a remote attestation process, a remote attestation server delivers a subscription configuration to a network device, where the subscription configuration for subscribing to information related to remote attestation performed by the network device. The remote attestation server receives the subscription information returned by the network device based on the subscription configuration.

Claims (77)

1 . A data collection method for a remote attestation process, comprising:

delivering without using a polling challenge-response mechanism, by a remote attestation (RA) server in a trusted computing system, a subscription configuration to a device acting as an RA client in the trusted computing system, wherein the subscription configuration is for subscribing to information related to remote attestation to be performed by the RA server to prove whether the device is trusted,

wherein the subscription configuration comprises a data stream subscription configuration specifying multiple types of subscribed information to be sent from the device, the multiple types of subscribed information comprising at least two of:

integrity information of software at each layer of a trust chain, wherein the integrity information of software at each layer of the trust chain is recorded when the device is booted up;

dynamic integrity information of an operating system that is recorded when the device runs;

dynamic integrity information of software that is recorded when the device runs;

an identity certificate related to the device; or

a remote attestation certificate related to the device,

wherein the subscription configuration further comprises a subscription mode configuration that specifies, for each of the multiple types of subscribed information to be sent from the device, a corresponding subscription mode selected from:

a periodic feedback based subscription mode, in which subscribed information is pushed to a subscriber after a specified time period expires; and

an event-triggered feedback based subscription mode, in which subscribed information is pushed to the subscriber when the subscribed information changes; and

receiving, by the remote attestation server, each of the multiple types subscribed information sent by the device in the corresponding subscription mode determined by the device based on the data stream subscription configuration and the subscription mode configuration included in the subscription configuration,

wherein the subscription mode configuration specifies that at least a first type of the multiple types of subscribed information is to be sent in the periodic feedback-based subscription mode, and that at least a different second type of the multiple types of subscribed information is to be sent in the event-triggered feedback-based subscription mode.

2 . The method according to claim 1 , wherein the subscription configuration further comprises an event subscription configuration.

3 . The method according to claim 2 , wherein the subscribed information comprises information related to one or more of triggered events including: device boot, device upgrade, a specific mode attack event, master/slave switchover, board insertion/removal/switchover, or a certificate life cycle event.

4 . The method according to claim 1 , wherein the subscription configuration further comprises a filter configuration, and the subscribed information comprises information obtained after filtering is performed based on the filter configuration.

5 . The method according to claim 1 , further comprising: delivering a data processing parameter to the device, wherein the subscribed information comprises information obtained after processing is performed based on the data processing parameter.

6 . The method according to claim 1 , further comprising:

establishing a network configuration protocol session with the device; and

delivering the subscription configuration to the device based on the network configuration protocol session.

7 . The method according to claim 6 , time validity of the subscription configuration is bound to time validity of the network configuration protocol session.

8 . The method according to claim 1 , wherein the subscription mode for sending the subscribed information is determined by the device based on a type of the subscribed information.

9 . The method according to claim 1 , wherein subscribed information to be transmitted by the device in the event-triggered feedback based subscription mode has a higher level of security than subscribed information to be transmitted by the device in the periodic feedback based subscription mode.

10 . A data collection method for a remote attestation process, comprising:

receiving without using a polling challenge-response mechanism, by a device, a subscription configuration delivered by a remote attestation (RA) server in a trusted computing system, wherein the subscription configuration is used to subscribe to information related to remote attestation that to be performed by the RA server to prove whether the device is trusted,

wherein the subscription configuration comprises a data stream subscription configuration specifying multiple types of subscribed information to be sent from the device, the multiple types of subscribed information comprising at least two of:

integrity information of software at each layer of a trust chain, wherein the integrity information of software at each layer of the trust chain is recorded when the device is booted up;

dynamic integrity information of an operating system that is recorded when the device runs;

dynamic integrity information of software that is recorded when the device runs;

an identity certificate related to the device; or

a remote attestation certificate related to the device,

wherein the subscription configuration further comprises a subscription mode configuration that specifies, for each of the multiple types of subscribed information to be sent from the device, a corresponding subscription mode selected from:

a periodic feedback based subscription mode, in which subscribed information is pushed to a subscriber after a specified time period expires; and

an event-triggered feedback based subscription mode, in which subscribed information is pushed to the subscriber when the subscribed information changes;

determining, by the device, the corresponding subscription mode for each of the multiple types of subscribed information based on the data stream subscription configuration and the subscription mode configuration included in the subscription configuration; and

sending, by the device, each of the multiple types of subscribed information to the remote attestation server in the corresponding subscription mode, wherein the device is configured to act as a RA client in the trusted computing system,

wherein the subscription mode configuration specifies that at least a first type of the multiple types of subscribed information is to be sent in the periodic feedback-based subscription mode, and that at least a different second type of the multiple types of subscribed information is to be sent in the event-triggered feedback-based subscription mode.

11 . The method according to claim 10 , wherein the subscription configuration further comprises an event subscription configuration.

12 . The method according to claim 11 , wherein the sending of subscribed information comprises:

sending, to the remote attestation server based on one or more of the event subscription configuration, a device boot event, a device upgrade event, a specific mode attack event, a master/slave switchover event, a board insertion/removal/switchover event, or a certificate life cycle event.

13 . The method according to claim 10 , wherein the subscription configuration further comprises a filter configuration, and the subscribed information comprises information obtained after filtering is performed based on the filter configuration.

14 . The method according to claim 10 , further comprising:

receiving a data processing parameter delivered by the remote attestation server, wherein the subscribed information comprises information obtained after processing is performed based on the data processing parameter.

15 . The method according to claim 10 , further comprising:

establishing a network configuration protocol session with the remote attestation server, and

receiving, based on the network configuration protocol session, the subscription configuration delivered by the remote attestation server.

16 . A remote attestation (RA) server in a trusted computing system, the RA server comprises:

a memory storing executable instructions; and

a processor configured to execute the executable instructions to perform operations comprising:

delivering without using a polling challenge-response mechanism, a subscription configuration to a device acting as an RA client in the trusted computing system, wherein the subscription configuration is for subscribing to information related to remote attestation that to be performed by the RA server to prove whether the device is trusted,

wherein the subscription configuration comprises a data stream subscription configuration specifying multiple types of subscribed information to be sent from the device, the multiple types of subscribed information comprising at least two of:

integrity information of software at each layer of a trust chain, wherein the integrity information of software at each layer of the trust chain is recorded when the device is booted up;

dynamic integrity information of an operating system that is recorded when the device runs;

dynamic integrity information of software that is recorded when the device runs;

an identity certificate related to the device; or

a remote attestation certificate related to the device,

wherein the subscription configuration further comprises a subscription mode configuration that specifies, for each of the multiple types of subscribed information to be sent from the device, a corresponding subscription mode selected from:

a periodic feedback based subscription mode, in which subscribed information is pushed to a subscriber after a specified time period expires; and

an event-triggered feedback based subscription mode, in which subscribed information is pushed to the subscriber when the subscribed information changes; and

receiving each of the multiple types of subscribed information sent by the device in the corresponding subscription mode determined by the device based on the data stream subscription configuration and the subscription mode configuration included in the subscription configuration,

wherein the subscription mode configuration specifies that at least a first type of the multiple types of subscribed information is to be sent in the periodic feedback-based subscription mode, and that at least a different second type of the multiple types of subscribed information is to be sent in the event-triggered feedback-based subscription mode.

17 . A device acting as a remote attestation (RA) client in a trusted computing system, the device comprises:

a memory storing executable instructions; and

a processor configured to execute the executable instructions to perform operations comprising:

receiving without using a polling challenge-response mechanism, a subscription configuration delivered by a remote attestation (RA) server in the trusted computing system, wherein the subscription configuration is for subscribing to information related to remote attestation that to be performed by the RA server to prove whether the device is trusted,

wherein the subscription configuration comprises a data stream subscription configuration specifying multiple types of subscribed information to be sent from the device, the multiple types of subscribed information comprising at least two of:

integrity information of software at each layer of a trust chain, wherein the integrity information of software at each layer of the trust chain is recorded when the device is booted up;

dynamic integrity information of an operating system that is recorded when the device runs;

dynamic integrity information of software that is recorded when the device runs;

an identity certificate related to the device; or

a remote attestation certificate related to the device,

wherein the subscription configuration further comprises a subscription mode configuration that specifies, for each of the multiple types of subscribed information to be sent from the device, a corresponding subscription mode selected from:

a periodic feedback based subscription mode, in which subscribed information is pushed to a subscriber after a specified time period expires; and

an event-triggered feedback based subscription mode, in which subscribed information is pushed to the subscriber when the subscribed information changes;

determining the corresponding subscription mode for each of the multiple types of subscribed information based on the data stream subscription configuration and the subscription mode configuration included in the subscription configuration; and

sending each of the multiple types of subscribed information to the remote attestation server in the corresponding subscription mode,

wherein the subscription mode configuration specifies that at least a first type of the multiple types of subscribed information is to be sent in the periodic feedback-based subscription mode, and that at least a different second type of the multiple types of subscribed information is to be sent in the event-triggered feedback-based subscription mode.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2025
From: XIA, LIANG; WANG, ZITAO; SHI, YULIN
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 072660/0293 →
Priority Claims (1)
CN 201910357610.X · Apr 29, 2019 · national
Continuity (2)
Continuation PCTCN2020083396 · Apr 5, 2020
Related Publication 20220052919A1 · Feb 17, 2022
References Cited (34)
US 9088509B1 · Sella · 2015 [cited by examiner]
US 9288199B1 · Winn · 2016 [cited by examiner]
US 10374956B1 · Tracy · 2019 [cited by examiner]
US 20070118642A1 · Kumbalimutt · 2007 [cited by examiner]
US 20080072329A1 · Herschaft · 2008 [cited by applicant]
US 20100057849A1 · Ji · 2010 [cited by applicant]
US 20110040957A1 · Berger · 2011 [cited by examiner]
US 20120216244A1 · Kumar · 2012 [cited by examiner]
US 20140094162A1 · Heo · 2014 [cited by examiner]
US 20150156615A1 · Gao · 2015 [cited by examiner]
US 20150341821A1 · Hong · 2015 [cited by examiner]
US 20160205580A1 · Pragada · 2016 [cited by examiner]
US 20190020738A1 · Paul · 2019 [cited by examiner]
US 20190380017A1 · Thangarasa · 2019 [cited by examiner]
US 20200042324A1 · Ayolasomyajula · 2020 [cited by examiner]
CN 103460215A · 2013 [cited by applicant]
CN 108306740A · 2018 [cited by applicant]
CN 109691154A · 2019 [cited by applicant]
JP 2006072682A · 2006 [cited by applicant]
JP 2009534749A · 2009 [cited by applicant]
JP 2016157323A · 2016 [cited by applicant]
KR 20130091353A · 2013 [cited by applicant]
WO 2017178811A1 · 2017 [cited by applicant]
WO 2018125989A2 · 2018 [cited by applicant]
WO 2018136087A1 · 2018 [cited by applicant]
WO 2018140628A1 · 2018 [cited by applicant]
E. Voit et al., “Customized Subscriptions to a Publisher's Event Streams,” Apr. 6, 2018. (Year: 2018). [cited by examiner]
H. Birkholz et al., Architecture and Reference Terminology for Remote Attestation Procedures, draft-birkholz-rats-architecture-01, Network Working Group Internet-Draft, Mar. 12, 2019, total 31 pages. [cited by applicant]
H. Birkholz et al., Reference Interaction Model for Challenge-Response-based Remote Attestation, draft-birkholz-rats-reference-interaction-model-00, TBD Internet-Draft, Mar. 12, 2019, total 8 pages. [cited by applicant]
Request for Comments: 8340, M. Bjorklund et al., YANG Tree Diagrams, Internet Engineering Task Force (IETF), Mar. 2018, total 13 pages. [cited by applicant]
Request for Comments: 4949, R. Shirey, Internet Security Glossary, Version 2, Network Working Group, Aug. 2007, total 365 pages. [cited by applicant]
Notice of Allowance issued in KR10-2021-7015357, dated Jun. 29, 2023, 2 pages. [cited by applicant]
E. Voit et al., “Subscription to YANG Event Notifications draft-ietf-netconf-subscribes-notifications-22”, NETCONT Internet-Draft, Jan. 23, 2019,total 78 pages, XP015130765. [cited by applicant]
Communication pursuant to Article 94(3), dated Sep. 4, 2024, 7 pages. [cited by applicant]