Method and System for Device Integrity Authentication
Abstract
Device integrity authentication is performed by receiving, at a second device, data from a first device. A determination is made at the second device as to whether at least a portion of the data is associated with a protected datatype. A measured integrity value of the first device is determined in response to the portion of the data being associated with the protected datatype. The measured integrity value of the first device is compared to an embedded integrity value associated with the second device. Application of at least one of a plurality of policies associated with processing the data is facilitated at the second device based on the comparison and the protected datatype.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for device integrity authentication, comprising:
receiving, at a second device, data from a first device; determining, at the second device, whether at least a portion of the data is associated with a protected datatype; determining, at the second device, a measured integrity value of the first device in response to the portion of the data being associated with the protected datatype; comparing, at the second device, the measured integrity value of the first device to an embedded integrity value associated with the second device; facilitating, by the second device, application of at least one of a plurality of policies associated with processing the data based on the comparison and the protected datatype.
2 . The method of claim 1 , wherein the data includes the measured integrity value of the first device.
3 . The method of claim 1 , wherein determining the measured integrity value includes requesting the measured integrity value from the first device.
4 . The method of claim 1 , wherein facilitating application of at least one of the plurality of policies includes processing the data under a normal processing policy in response to the data not being associated with the protected datatype.
5 . The method of claim 1 , wherein facilitating application of at least one of the plurality of policies includes processing the data under a normal processing policy in response to the measured integrity value matching the embedded integrity value.
6 . The method of claim 1 , wherein facilitating application of at least one of the plurality of policies includes processing the data under a restricted processing policy in response to the measured integrity value not matching the embedded integrity value.
7 . The method of claim 1 , wherein facilitating application of at least one of the plurality of policies includes:
communicating, by the second device, with a backend server in response to the measured integrity value not matching the embedded integrity value; receiving, at the second device, a restricted processing policy from the backend server associated with processing the data from the first device.
8 . The method of claim 1 , wherein facilitating application of at least one of the plurality of policies includes:
communicating, by the second device, with a backend server in response to the measured integrity value not matching the embedded integrity value; receiving, at the second device, a normal processing policy from the backend server associated with processing the data from the first device.
9 . A computer readable storage medium including code for device integrity authentication, the code operable to:
receive data from a first device for a second device; determine whether at least a portion of the data is associated with a protected datatype; determine a measured integrity value of the first device in response to the portion of the data being associated with the protected datatype; compare the measured integrity value of the first device to an embedded integrity value associated with the second device; facilitate application of at least one of a plurality of policies associated with processing the data at the second device based on the comparison and the protected datatype.
10 . The computer readable storage medium of claim 9 , wherein the data includes the measured integrity value of the first device.
11 . The computer readable storage medium of claim 9 , wherein the code operable to determine the measured integrity value includes code operable to request the measured integrity value from the first device.
12 . The computer readable storage medium of claim 9 , wherein the code operable to facilitate application of at least one of the plurality of policies includes code operable to process the data under a normal processing policy in response to the data not being associated with the protected datatype.
13 . The computer readable storage medium of claim 9 , wherein the code operable to facilitate application of at least one of the plurality of policies includes code operable to process the data under a normal processing policy in response to the measured integrity value matching the embedded integrity value.
14 . The computer readable storage medium of claim 9 , wherein the code operable to facilitate application of at least one of the plurality of policies includes code operable to process the data under a restricted processing policy in response to the measured integrity value not matching the embedded integrity value.
15 . The computer readable storage medium of claim 9 , wherein the code operable to facilitate application of at least one of the plurality of policies includes code operable to:
communicate with a backend server in response to the measured integrity value not matching the embedded integrity value; receive a restricted processing policy from the backend server associated with processing the data from the first device.
16 . The computer readable storage medium of claim 9 , wherein the code operable to facilitate application of at least one of the plurality of policies includes:
code operable to communicate with a backend server in response to the measured integrity value not matching the embedded integrity value; receive a normal processing policy from the backend server associated with processing the data from the first device.
17 . A system for device integrity authentication, comprising:
an integrity check processing module operable to:
receive data from a first device for a second device;
determine whether at least a portion of the data is associated with a protected datatype;
determine a measured integrity value of the first device in response to the portion of the data being associated with the protected datatype;
a control processing module operable to:
compare the measured integrity value of the first device to an embedded integrity value associated with the second device;
facilitate application of at least one of a plurality of policies associated with processing the data at the second device based on the comparison and the protected datatype.
18 . The system of claim 17 , wherein the data includes the measured integrity value of the first device.
19 . The system of claim 17 , wherein the integrity check processing module is operable to request the measured integrity value from the first device.
20 . The system of claim 17 , wherein the control processing module is further operable to process the data under a normal processing policy in response to the data not being associated with the protected datatype.
21 . The system of claim 17 , wherein the control processing module is further operable to process the data under a normal processing policy in response to the measured integrity value matching the embedded integrity value.
22 . The system of claim 17 , wherein the control processing module is further operable to process the data under a restricted processing policy in response to the measured integrity value not matching the embedded integrity value.
23 . The system medium of claim 17 , wherein the control processing module is further operable to:
communicate with a backend server in response to the measured integrity value not matching the embedded integrity value; receive a restricted processing policy from the backend server associated with processing the data from the first device.
24 . The system of claim 17 , wherein the control processing module is further operable to:
communicate with a backend server in response to the measured integrity value not matching the embedded integrity value; receive a normal processing policy from the backend server associated with processing the data from the first device.Join the waitlist — get patent alerts
Track US2012047578A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.