发明名称 Data Security and Integrity by Remote Attestation
摘要 The invention includes a system comprising a device, software installed on the device and coupled to the device's hardware and software stack to execute data encryption and remote attestation. The invention includes a process to configure the device for encryption and remote attestation and performing an initial inventory and content scan of the device's hardware and software stack with results transmitted across a communication network to the attestation server. The invention includes periodic inventory and content scans of the device's hardware and software stack with results transmitted again to the server via the network. The attestation server stores the results in a database for comparison to subsequent results sent by devices. The attestation server notes any differences in the most recent results and sends an alert to the device if the device is configured differently based on the previous scan, or configured the same if no differences were noted.
申请公布号 US2015163229(A1) 申请公布日期 2015.06.11
申请号 US201514623497 申请日期 2015.02.16
申请人 Lindteigen Ty 发明人 Lindteigen Ty
分类号 H04L29/06;H04L9/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A system to ensure the security of data comprising: at least one device; an application software installed on the device and coupled to a hardware and a software stack of the device, wherein the application software provides a set of instructions to remotely command the device to perform an inventory scan and a content scan of the hardware and the software stack of the device, consolidate and secure a collection of results of the inventory scan and the content scan of the hardware and the software stack of the device, store the collection of results in a database, use the collection of results to determine a statistically known-good configuration for a type of device, compare the collection of results with the statistically known-good configuration for the type of device, note any differences in a most recent message digest compared to the statistically known-good configuration, and send an alert to the device; a data encryption software and a remote attestation software installed on the device and coupled to the hardware and software stack of the device wherein the data encryption software and the remote attestation software is installed within a user space of the software stack of the device and associated with a data storage wherein the data storage includes persistent memory that is subdivided into a user data, a system image, and a boot partition; and an attestation server to communicate with the device via a communication network.
地址 Chandler AZ US