US2012047557A1PendingUtilityA1

Method and System for Device Integrity Authentication

Assignee: LEE SUNGPriority: Aug 20, 2010Filed: Nov 16, 2010Published: Feb 23, 2012
Est. expiryAug 20, 2030(~4.1 yrs left)· nominal 20-yr term from priority
Y04S40/20H04L 63/126G06F 21/57
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Device integrity authentication is performed by receiving, at a second device, a measured integrity value from a first device. The measured integrity value of the first device is compared at the second device to an embedded integrity value associated with the second device. A level of trust for the first device is determined by the second device based on the comparison. Application of a policy to the first device is facilitated by the second device based on the comparison.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for device integrity authentication, comprising:
 receiving, at a second device, a measured integrity value from a first device;   comparing, using the second device, the measured integrity value of the first device to an embedded integrity value associated with the second device;   determining, by the second device, a level of trust for the first device based on the comparison.   
     
     
         2 . The method of  claim 1 , wherein the level of trust is one of a plurality of levels of trust that can be determined based on the comparison. 
     
     
         3 . The method of  claim 2 , wherein the plurality of levels of trust include a low level of trust, a medium level of trust, and a high level of trust. 
     
     
         4 . The method of  claim 3 , wherein determining the level of trust includes determining that the first device has a low level of trust in response to the measured integrity value not matching the embedded integrity value. 
     
     
         5 . The method of  claim 1 , further comprising:
 facilitating, on the second device, application of one of a plurality of communication policies associated with communicating with the first device based on the determined level of trust.   
     
     
         6 . The method of  claim 5 , wherein one of the plurality of policies includes restricting functions of the first device based on the determined level of trust. 
     
     
         7 . The method of  claim 5 , wherein one of the plurality of policies includes rejecting all communications with the first device based on the determined level of trust. 
     
     
         8 . The method of  claim 1 , wherein determining the level of trust includes:
 communicating, by the second device, with a backend server in response to the measured integrity value not matching the embedded integrity value;   receiving, at the second device, an indication from the backend server an indication of the level of trust for the first device.   
     
     
         9 . The method of  claim 1 , wherein determining the level of trust includes:
 communicating, by the second device, with a backend server in response to the measured integrity value not matching the embedded integrity value;   receiving, at the second device, one of a plurality of communication policies associated with communicating with the first device from the backend server.   
     
     
         10 . The method of  claim 1 , wherein determining the level of trust includes:
 requesting additional information from the first device in response to the measured integrity value not matching the embedded integrity value;   
     
     
         11 . The method of  claim 10 , wherein the additional information includes an identity of the first device and one or more intermediate measured integrity values. 
     
     
         12 . A system for device integrity authentication, comprising:
 an integrity check processing module operable to:
 receiving a measured integrity value from a first device; 
 comparing the measured integrity value of the first device to an embedded integrity value associated with the integrity check processing module; 
   a control processing module operable to determine a level of trust for the first device based on the comparison.   
     
     
         13 . The system of  claim 12 , wherein the level of trust is one of a plurality of levels of trust that can be determined based on the comparison. 
     
     
         14 . The system of  claim 13 , wherein the plurality of levels of trust include a low level of trust, a medium level of trust, and a high level of trust. 
     
     
         15 . The system of  claim 14 , wherein determining the level of trust includes determining that the first device has a low level of trust in response to the measured integrity value not matching the embedded integrity value. 
     
     
         16 . The system of  claim 12 , wherein the control processing module is further operable to facilitate application of one of a plurality of communication policies associated with communicating with the first device based on the determined level of trust. 
     
     
         17 . The system of  claim 16 , wherein one of the plurality of policies includes restricting functions of the first device based on the determined level of trust. 
     
     
         18 . The system of  claim 16 , wherein one of the plurality of policies includes rejecting all communications with the first device based on the determined level of trust. 
     
     
         19 . The system of  claim 12 , wherein the control processing module is further operable to:
 communicate with a backend server in response to the measured integrity value not matching the embedded integrity value;   receive an indication from the backend server an indication of the level of trust for the first device.   
     
     
         20 . The system of  claim 12 , wherein the control processing module is further operable to:
 communicate with a backend server in response to the measured integrity value not matching the embedded integrity value;   receive one of a plurality of communication policies associated with communicating with the first device from the backend server.   
     
     
         21 . The system of  claim 12 , wherein the control processing module is further operable to:
 request additional information from the first device in response to the measured integrity value not matching the embedded integrity value;   
     
     
         22 . The system of  claim 21 , wherein the additional information includes an identity of the first device and one or more intermediate measured integrity values.

Join the waitlist — get patent alerts

Track US2012047557A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.