Layered Certification
Abstract
A certification provenance tree (CPT) structure may provide information concerning a layered certification of a device that comprises a hierarchy of components. The CPT structure may include a hierarchy of secure certification provenance document (SCPD) structures. Each SCPD structure in the hierarchy may represent a given component at a given level of the hierarchy of components of the device. Each SCPD structure may include a field that stores a certification proof indicating that security properties of the given component have been certified by a certification authority. An SCPD structure may further include accreditation information fields that store a pointer to an SCPD structure of a component at a next layer of the hierarchy of components of the device. The pointer may provide an indication of assurance that the component at that next layer will perform securely within this component at said given layer.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A non-transitory computer-readable storage medium on which is stored a certification provenance tree structure for providing information concerning a layered certification of a device that comprises a hierarchy of components, the certification provenance tree structure comprising:
a hierarchy of secure certification provenance document (SCPD) structures, each SCPD structure representing a given component of the device, each SCPD structure comprising:
a first field that stores a certification proof indicating that security properties of the given component at that given level of the hierarchy have been certified by a certification authority; and
zero or more accreditation information fields, each accreditation information field storing a pointer to an SCPD structure of a component at a next level of the hierarchy of components of the device and providing an indication of assurance that the component at that next level will perform securely within this component at said given level.
2 . The non-transitory computer-readable storage medium of claim 1 , wherein the non-transitory computer-readable storage medium further stores a device node structure comprising a first field that stores an identity of the device, a second field that stores an identity of a manufacturer of the device, a third field that stores a device certificate signed by the manufacturer of the device or a certification authority, and a fourth field that provides a pointer to a root SCPD structure of the SCPD structures that represents a root node of the hierarchy of components of the device.
3 . The non-transitory computer-readable medium of claim 2 , wherein the device node structure is stored on the device and the certification provenance tree structure is stored outside of the device, and wherein the device node structure is cryptographically bound to the root SCPD structure via the fourth field that provides the pointer to the root SCPD structure.
4 . The non-transitory computer-readable medium of claim 1 , wherein at least a portion of certification provenance tree structure is cryptographically bound to the device.
5 . The non-transitory computer-readable medium of claim 1 , wherein the device includes the non-transitory computer-readable medium such that the certificate provenance tree structure is stored on the device.
6 . The non-transitory computer-readable medium of claim 1 , wherein each component in the hierarchy of components is at least one of a software component or a hardware component.
7 . The non-transitory computer-readable medium of claim 1 , wherein the certification authority is a manufacturer of the device.
8 . The non-transitory computer-readable medium of claim 1 , wherein the certification authority is the manufacturer or developer of the given component that has been certified by the certification authority.
9 . The non-transitory computer-readable medium of claim 1 , wherein the device is a user equipment for accessing a network that is controlled by a mobile network operator.
10 . A method of evaluating security properties of a device, the method comprising:
obtaining a certificate provenance tree structure for the device, the certification provenance tree structure comprising a hierarchy of secure certification provenance document (SCPD) structures, each SCPD structure representing a given component at a given level of the hierarchy of components of the device, each SCPD structure comprising a first field that stores a certification proof indicating that security properties of the given component have been certified by a certification authority; and zero or more accreditation information fields, each accreditation information field storing a pointer to an SCPD structure of a component at a next level of the hierarchy of components of the device and providing an indication of assurance that the component at that next level will perform securely within this component at said given level; and traversing the hierarchy of SCPD structures using said pointers until the security properties of the device are verified or until a security exception is discovered.
11 . The method of claim 10 , wherein traversing the hierarchy of SCPD structures comprises:
determining whether each SCPD structure at the given level has been previously verified such that the security properties of the given component that the SCPD structure represents are sufficiently trusted; and when it is determined that one given component at the given level has not been previously verified, using the pointers of the given component that has not been previously verified to iteratively identify the SCPD structures at the next layer that should be evaluated; and when it is determined that one given component at the given level has been previously verified, determining whether another component at the given level has been previously verified until all of the components at the given level have been verified or until a security exception is discovered.
12 . The method of claim 10 , the method further comprising:
identifying a component as being disposed at a lowest level of the hierarchy of components; determining that the component at the lowest level has not been previously verified; and verifying security properties of the component at the lowest level.
13 . The method of claim 12 , wherein verifying security properties of the component at the lowest level comprises:
determining that the certification proof in the first field is authentic; and determining that the certification authority that certified the security properties of the component at the lowest level is a trusted certification authority.
14 . The method of claim 10 , wherein the method is performed by a mobile network operator that controls a network, the method further comprising:
in response to traversing the hierarchy of the SCPD structures using said pointers until the security properties of the device are verified, granting the device access to the network.
15 . The method of claim 10 , the method further comprising:
requesting, by a mobile network operator that controls a network, an evaluation of the certificate provenance tree structure for the device; receiving an indication that the security properties of the device are verified; and based on the indication that the security properties of the device are verified, granting the device access to the network.
16 . The method of claim 10 , wherein the certification provenance tree structure is obtained from the device.
17 . The method of claim 10 , wherein the certification provenance tree structure is cryptographically bound to the device, the certification provenance tree structure being stored outside of the device.
18 . The method of claim 16 , wherein the device is a user equipment for accessing a network that is controlled by a mobile network operator.
19 . A non-transitory computer-readable storage medium on which is stored a certificate provenance tree structure for providing information concerning a layered certification of a device that comprises a hierarchy of components, the certificate provenance tree structure comprising:
a first secure certification provenance document (SCPD) structure representing a root node of the hierarchy of components of the device and comprising a first field that stores a certification proof indicating that security properties of the device as a whole have been certified by a certification authority, and one or more accreditation information fields, each accreditation information field (i) storing a pointer to an SPCD structure of a component at a first layer of the hierarchy of components of the device; and (ii) providing an indication of assurance that the component will perform securely within the device, wherein each SPCD of a component of the first layer of the hierarchy of components of the device comprising a first field that stores a certification proof indicating that security properties of the component have been certified by a certification authority, and zero or more accreditation information fields, each accreditation information field (i) storing a pointer to an SPCD structure of a component at a next layer of the hierarchy of components of the device; and (ii) providing an indication of assurance that the component at that next layer will perform securely within this component at the first layer.
20 . The non-transitory computer-readable storage medium of claim 18 , wherein the non-transitory computer-readable storage medium further stores a device node structure comprising a first field that stores an identity of the device, a second field that stores an identity of a manufacturer of the device, a third field that stores a device certificate signed by the manufacturer of the device or a certification authority, and a fourth field that provides a pointer to the first SPCD structure.Join the waitlist — get patent alerts
Track US2018131687A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.