Invention Grant
- Patent Title: Key attestation statement generation providing device anonymity
-
Application No.: US17004929Application Date: 2020-08-27
-
Publication No.: US11750591B2Publication Date: 2023-09-05
- Inventor: Saurav Sinha , Victor Warren Heller
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F21/73 ; H04L9/32 ; G06F21/72 ; H04L9/08 ; H04L9/00 ; G06F21/57 ; G06F21/33

Abstract:
A computing device sends a request for an attestation certificate to an attestation service along with information regarding the hardware and/or software of the device. The attestation service processes the request and verifies the information received from the device. After verifying the information, the attestation service selects a public/private key pair from a collection of reusable public/private key pairs and generates an attestation certificate for the device and public key of the public/private key pair. This attestation certificate is digitally signed by the attestation service and returned to the device. The private key of the selected public/private key pair is also encrypted to a trusted secure component of the device, ensuring that the key cannot be stolen by malware and re-used on another device, and is returned to the device. The device uses this attestation certificate to access relying parties, and optionally generates additional public/private key pairs and attestation certificates.
Information query