PROTECTING THE INTEGRITY OF COMMUNICATIONS FROM CLIENT DEVICES

    公开(公告)号:US20220321356A1

    公开(公告)日:2022-10-06

    申请号:US17634100

    申请日:2020-05-01

    Applicant: Google LLC

    Abstract: Methods, systems, and apparatus, including an apparatus for verifying the integrity of requests and the devices that sent the requests. In some aspects, a method includes receiving, from a client device, a request including an attestation token generated by the client device. The attestation token includes a set of data that includes at least a public key of the client device, a token creation, and a device integrity token that includes a verdict. The attestation token also includes a digital signature of the set of data generated using a private key corresponding to the public key. The integrity of the request is verified using the attestation token by determining that the token creation time being within a threshold duration of the time at which the request was received, the set of data was not modified since the attestation token was created, and the verdict indicates the client device is trustworthy.

Patent Agency Ranking