IP Library › Granted Patent US 12,505,258
Granted Patent B2
US 12,505,258 · App. 18/575,055 · Granted Dec 23, 2025

Enforcement of attestation of read-only protected memory during attestation validity period

Inventors: Maxwell Christopher Renke (Sammamish, WA); Andrea Allievi (Seattle, WA); Giridhar Viswanathan (Redmond, WA); Benjamin M. Schultz (Bellevue, WA); Hari R. Pulapaka (Redmond, WA); David Guy Weston (Seattle, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,258
App. No.
18/575,055
Granted
Dec 23, 2025
Kind
B2
Abstract

Enforcing attestation of read-only protected memory during attestation validity period. A client computer system identifies a change in a read-only protected memory protection status for a software component loaded at the client computer system. The client computer system then determines that a validity time period of an attestation report is unexpired. The attestation report comprises one or more attested properties, including one or more read-only memory protection (ROMP) attested properties for the software component. The client computer system also determines that at least one ROMP attested property for the software component is no longer valid due to the change in the read-only protected memory protection status for a software component. Based on the at least one ROMP attested property for the software component being no longer valid, the client computer system initiates a remedial action to prevent interaction of the software component with a relying party computer system.

Claims (35)

1 . A computer system for enforcing attestation of read-only protected memory during an attestation validity period, comprising:

a processor; and

a hardware storage device that stores computer-executable instructions that are executable by the processor to cause the computer system to at least:

identify a change in a read-only memory protection (ROMP) status for a software component loaded at the computer system;

determine that a validity time period of an attestation report is unexpired, the attestation report comprising one or more attested properties, including one or more ROMP attested properties for read-only protected memory allocated to the software component;

determine that at least one ROMP attested property for the software component is no longer valid due to the change in the ROMP status for a software component;

based on the at least one ROMP attested property for the software component being no longer valid, initiate a remedial action to prevent interaction of the software component with a relying party computer system, the remedial action comprising blocking a communication from the software component; and

permit communication by the software component after expiration of the validity time period.

2 . The computer system of claim 1 , wherein the remedial action also comprises suspending one or more processes corresponding to the software component.

3 . The computer system of claim 2 , wherein the computer-executable instructions are also executable by the processor to cause the computer system to resume the one or more processes after expiration of the validity time period.

4 . The computer system of claim 1 , wherein the remedial action also comprises terminating one or more processes corresponding to the software component.

5 . The computer system of claim 1 , wherein the remedial action also comprises initiating obtaining a new attestation report.

6 . The computer system of claim 1 , wherein the remedial action also comprises notifying the relying party computer system.

7 . A method, implemented at a computer system that comprises a processor for enforcing attestation of read-only protected memory during an attestation validity period, the method comprising:

identifying a change in a read-only memory protection (ROMP) status for a software component loaded at the computer system;

determining that a validity time period of an attestation report is unexpired, the attestation report comprising one or more attested properties, including one or more ROMP attested properties for read only protected memory allocated to the software component;

determining that at least one ROMP attested property for the software component is no longer valid due to the change in the ROMP status for a software component;

based on the at least one ROMP attested property for the software component being no longer valid, initiating a remedial action to prevent interaction of the software component with a relying party computer system, the remedial action comprising blocking a communication from the software component; and

permit communication by the software component after expiration of the validity time period.

8 . The method of claim 7 , wherein the remedial action also comprises suspending one or more processes corresponding to the software component.

9 . The method of claim 8 , further comprising resuming the one or more processes after expiration of the validity time period.

10 . The method of claim 7 , wherein the remedial action also comprises terminating one or more processes corresponding to the software component.

11 . The method of claim 7 , wherein the remedial action also comprises

initiating obtaining a new attestation report.

12 . The method of claim 7 , wherein the remedial action also comprises notifying the relying party computer system.

13 . A hardware storage device that stores computer-executable instructions that are executable by a processor to cause a computer system to at least: identify a change in a read-only memory protection (ROMP) status for a software component loaded at the computer system;

determine that a validity time period of an attestation report is unexpired, the attestation report comprising one or more attested properties, including one or more ROMP attested properties for read-only protected memory allocated to the software component;

determine that at least one ROMP attested property for the software component is no longer valid due to the change in the ROMP status for a software component;

based on the at least one ROMP attested property for the software component being no longer valid, initiate a remedial action to prevent interaction of the software component with a relying party computer system, the remedial action comprising blocking a communication from the software component; and

permit communication by the software component after expiration of the validity time period.

14 . The hardware storage device of claim 13 , wherein the remedial action also comprises suspending one or more processes corresponding to the software component.

15 . The hardware storage device of claim 14 , wherein the computer executable instructions are also executable by the processor to cause the computer system to resume the one or more processes after expiration of the validity time period.

16 . The hardware storage device of claim 13 , wherein the remedial action also comprises terminating one or more processes corresponding to the software component.

17 . The hardware storage device of claim 13 , wherein the remedial action also comprises initiating obtaining a new attestation report.

18 . The hardware storage device of claim 13 , wherein the remedial action also comprises notifying the relying party computer system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2023
From: RENKE, MAXWELL CHRISTOPHER; ALLIEVI, ANDREA; VISWANATHAN, GIRIDHAR; SCHULTZ, BENJAMIN M.; PULAPAKA, HARI R.; WESTON, DAVID GUY
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 065974/0491 →
Priority Claims (1)
LU LU500442 · Jul 16, 2021 · national
Continuity (1)
Related Publication 20240338493A1 · Oct 10, 2024
References Cited (24)
US 8578175B2 · Boivie · 2013 [cited by examiner]
US 9531547B2 · Dabak · 2016 [cited by examiner]
US 9659177B1 · Juels et al. · 2017 [cited by applicant]
US 9953167B2 · Wooten · 2018 [cited by examiner]
US 10614223B2 · Abramovsky · 2020 [cited by examiner]
US 11609996B2 · Falk · 2023 [cited by examiner]
US 11687656B2 · Palanki · 2023 [cited by examiner]
US 12105807B1 · Bagh · 2024 [cited by examiner]
US 20180239901A1 · Jeansonne · 2018 [cited by examiner]
US 20200084202A1 · Smith et al. · 2020 [cited by applicant]
US 20200394308A1 · Angelo · 2020 [cited by examiner]
US 20240143784A1 · Lee · 2024 [cited by examiner]
US 20240338493A1 · Renke · 2024 [cited by examiner]
CN 101473333A · 2009 [cited by applicant]
CN 103051451A · 2013 [cited by applicant]
CN 106537873A · 2017 [cited by applicant]
Decision to grant a European patent pursuant to Article 97(1) received in European Application No. 22747564.7, mailed on Aug. 16, 2024, 2 pages. [cited by applicant]
Communication under Rule 71(3) Received for European Application No. 22747564.7, mailed on Apr. 8, 2024, 9 pages. [cited by applicant]
Notice of Allowance Received for Chinese Application No. 202280050015.1, mailed on Apr. 30, 2025, 04 pages. (English translation Provided). [cited by applicant]
Office Action Received for Chinese Application No. 202280050015.1, mailed on Oct. 19, 2024, 7 pages (English Translation Provided). [cited by applicant]
Arnaud Jumelet et al., “Control the health of Windows 10-based devices,” Oct. 26, 2022, XP055400355, [retrieved on Jan. 11, 2022] Retrieved from the Internet: Retrieved From: https://learn.microsoft.com/en-us/windows/se… [cited by applicant]
International Search Report & Written Opinion issued in PCT Application No. PCT/US2022/073636, Oct. 7, 2022, 11 Pages. [cited by applicant]
Introducing Kernel Data Protection, a new platform security technology for preventing data corruption, accessed on: https://www.microsoft.com/en-us/security/blog/2020/07/08/introducing-kernel-data-protection-a-new-platf… [cited by applicant]
Office Action and Search report Issued in Luxembourg Patent Application No. LU500442, mailed on Mar. 25, 2022, 10 Pages. [cited by applicant]