System and method for performing device attestation
In some embodiments, a system includes a processor; and a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium including code that: requests, using a device-specific attestation request, a device-specific attestation of a device; receives, via a secure communication channel, device-specific attestation data from the device as a result of the device-specific attestation; and generates an enhanced attestation object based on the device-specific attestation data. In some embodiments, the enhanced attestation object is used to verify that an execution environment of an application on the device is secure. In some embodiments, a device-specific risk score is generated based upon the device-specific attestation data and an enhanced attestation risk score is generated based on the enhanced attestation data analysis, the enhanced attestation risk score being used to verify that the execution environment of the application on the device is secure.
1 . A method, comprising:
utilizing a server that includes a back-end attestation component, the server requesting, using the back-end attestation component, an attestation from a mobile device;
receiving, from the mobile device via a secure communication channel in a universal attestation system, mobile device attestation data;
performing, at the server using the back-end attestation component, an analysis of the attestation data;
using the analysis to generate a risk score for a mobile device execution environment;
utilizing the risk score to determine whether to generate a back-end-based attestation object;
based upon an affirmative determination, generating, at a back-end of the universal attestation system, the back-end-based attestation object;
tailoring, at the server, attestation instructions;
utilizing the risk score to verify that the mobile device execution environment is secure to execute an application on the mobile device,
wherein the attestation instructions are tailored to the back-end-based attestation object based on (i) a device type of the mobile device, (ii) a version of an operating system of the mobile device, and (iii) attestation-requestor-specific requirements, the attestation instructions being mapped to the back-end-based attestation object; and
serializing, at the back-end of the universal attestation system, the back-end-based attestation object, the mapped attestation instructions, and the risk score as a combined serialized package.
2 . The method of claim 1 , further comprising:
confirming or denying, at the back-end of the universal attestation system, access to the application executing at the mobile device execution environment of the mobile device at an end-point of the universal attestation system based on a security of a mobile device execution environment risk score, the security of the mobile device execution environment risk score being a second risk score generated at an enhanced attestation data analysis unit located at the back-end.
3 . The method of claim 2 , further comprising:
providing a serialized back-end-based attestation object, a serialized-back-end-based attestation instructions, and a serialized risk score to the end-point for attestation object validation.
4 . The method of claim 3 , further comprising:
validating, at the end-point of the universal attestation system, the serialized back-end-based attestation object by verifying a digital signature associated with the back-end-based attestation object, performing a checksum procedure of the back-end-based attestation object, and verifying a class type of the back-end-based attestation object.
5 . The method of claim 4 , further comprising:
performing, at the end-point of the universal attestation system, an end-point-based-back-end-based attestation object attestation of the mobile device based upon utilizing a deserialized back-end-based attestation object and deserialized-back-end-based attestation instructions.
6 . The method of claim 5 , wherein:
the serialized back-end-based attestation object, the serialized-back-end-based attestation instructions, and the serialized risk score are deserialized at the end-point of the universal attestation system.
7 . The method of claim 6 , wherein:
the deserialization is configured to extend end-point attestation capability without requiring interaction from an end-user of the mobile device.
8 . The method of claim 7 , wherein:
the affirmative determination that the back-end-based attestation object is to be generated at the back-end of the universal attestation system is generated using a back-end attestation object threshold.
9 . The method of claim 8 , wherein:
the risk score is compared to the back-end attestation object threshold in order to determine whether to generate the back-end-based attestation object.
10 . A system, comprising:
a processor; and
a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium comprising code that:
requests, using a back-end attestation component included in a server, an attestation from a mobile device;
receives, from the mobile device via a secure communication channel in a universal attestation system, mobile device attestation data;
performs, at the server using the back-end attestation component, an analysis of the attestation data;
uses the analysis to generate a risk score for a mobile device execution environment;
utilizes the risk score to determine whether to generate a back-end-based attestation object;
based upon an affirmative determination, generates, at a back-end of the universal attestation system, the back-end-based attestation object;
tailors, at the server, attestation instructions;
utilizes the risk score to verify that the mobile device execution environment is secure to execute an application on the mobile device,
wherein the attestation instructions are tailored to the back-end-based attestation object based on (i) a device type of the mobile device, (ii) a version of an operating system of the mobile device, and (iii) attestation-requestor-specific requirements, the attestation instructions being mapped to the back-end-based attestation object; and
serializes, at the back-end of the universal attestation system, the back-end-based attestation object, the mapped attestation instructions, and the risk score as a combined serialized package.
11 . The system of claim 10 , wherein:
confirming or denying access to the application executing at the mobile device execution environment of the mobile device at an end-point of the universal attestation system is based on a security of a mobile device execution environment risk score, the security of the mobile device execution environment risk score being a second risk score generated at an enhanced attestation data analysis unit.
12 . The system of claim 11 , wherein:
the processor provides a serialized back-end-based attestation object, a serialized-back-end-based attestation instructions, and a serialized risk score to the end-point for attestation object validation.
13 . The system of claim 12 , wherein:
the serialized back-end-based attestation object is validated at the end-point of the universal attestation system by verifying a digital signature associated with the back-end-based attestation object, performing a checksum procedure of the back-end-based attestation object, and verifying a class type of the back-end-based attestation object.