Post - event platform configuration certification

By creating a nonvolatile index in TPM and recording the state changes of the computing device using PCR policies, the problem that the computing device cannot verify the previous state after cold startup is solved, and reliable PCR proof is achieved, enhancing the security and trustworthiness of the device.

CN112334900BActive Publication Date: 2025-07-22MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201980041235.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-06-22
Filing Date
2019-06-10
Publication Date
2025-07-22
Estimated Expiration
2039-06-10

AI Technical Summary

Technical Problem

The prior art is difficult to accurately determine its previous state after restart of a computing device, especially after a cold start, resulting in the inability to effectively verify the historical state of the PCR.

Method used

By creating a nonvolatile (NV) index in the TPM of the computing device, using the PCR policy to specify that the PCR value on the TPM is equal to a predetermined set of values, and setting the NV write attribute when the policy is satisfied, recording the state that the device has satisfied since the last cold startup.

Benefits of technology

It realizes accurate determination of the previous state after the computing device is restarted, provides a reliable PCR proof mechanism, supports a large number of PCR proof requests, and enhances the security and trustworthiness of the computing device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112334900B_ABST
    Figure CN112334900B_ABST
Patent Text Reader

Abstract

The implementation described herein discloses a platform configuration register (PCR) attestation system that uses a trusted platform module (TPM) of a device. The PCR attestation system provides one or more computer-executable instructions to create a non-volatile (NV) index in the TPM of a computing device, where a PCR policy specifies that the value of a PCR on the TPM is equal to a predetermined set of values, and if the PCR policy is satisfied, sets the value of an NV write attribute to specify that the PCR policy has been satisfied since the last time the device was booted.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] In the past few years, Trusted Computing (TC) has become an important part of the computing field. This is because email viruses, Trojan horses, spyware, phishing scams, keyloggers, and security vulnerabilities have taken up a large part, and trusted computing addresses these challenges not only through computing devices such as desktops and laptops but also with mobile devices and devices used with Internet of Things (IoT) technology. Using TC, computing devices use a Trusted Platform Module (TPM) to protect the hardware with integrated encryption keys. The TPM may contain several Platform Configuration Registers (PCRs), which allow for the secure storage and reporting of security-related metrics. These metrics can be used to detect changes to a previous configuration and decide how to proceed. Summary of the Invention

[0002] The implementations described herein disclose a Platform Configuration Register (PCR) attestation system that uses the Trusted Platform Module (TPM) of a device. The PCR attestation system provides one or more computer-executable instructions to create a non-volatile (NV) index in the TPM of a computing device, where a PCR policy specifies that the PCR values on the TPM equal a predetermined set of values, and if the PCR policy is satisfied, the value of the NV write attribute is set to specify that the PCR policy has been satisfied since the device last booted.

[0003] The Summary of the Invention is provided to introduce a selection of concepts in a simplified form that will be further described in the Detailed Description below. The Summary of the Invention is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0004] Other implementations are also described and recited herein. Brief Description of the Drawings

[0005] A further understanding of the nature and advantages of the present technology can be realized by referring to the drawings described in the remainder of the specification.

[0006] Figure 1 An example implementation of a system using a Platform Configuration Register (PCR) attestation system of a device's Trusted Platform Module (TPM) is shown.

[0007] Figure 2 An example state diagram of a PCR attestation system using a device's TPM is shown.

[0008] Figure 3 An alternative example state diagram of a PCR attestation system using a device's TPM is shown.

[0009] Figure 4Illustrates an example operation for generating a non-volatile (NV) index for providing a PCR attestation using the TPM of a device.

[0010] Figure 5 Illustrates an example operation for providing post-boot PCR attestation using the TPM of a device.

[0011] Figure 6 Illustrates an example system that may be useful in implementing the described techniques. Detailed Description

[0012] A computing device undergoes many states from the time it is powered on until it is used. Over time, various parameters of the computing device change before the device is rebooted. Examples of some states may be hibernation and resume, a Dynamic Root of Trust for Measurement (DRTM) sequence (a partial reboot of the computing device's operating system), etc. These state change categories generate changes in the measured values of various parameters, and these parameter measurements can be stored in the Platform Configuration Registers (PCRs) of the computing device. Thus, the PCRs are modified as a result of these processes. In addition, the computing device may also include an event log that is measured in the PCRs. These logs are called Trusted Computing Group (TCG) logs and store a detailed description of the changes made to the PCRs.

[0013] The combination of the PCRs or TCG logs of a computing device can be used by the user or client of the computing device to determine the state of the computing device at various times. The state of such a device can be attested using the Attestation Identity Key (AIK) in the TPM of the computing device. For example, an attestation server can request the state of the PCRs from the TPM of the computing device, which is referred to herein as a PCR quote, and in response, can obtain the attested current value of the PCRs. However, a party may be interested in knowing the state of the PCRs at a previous point in time after the computing device has been powered on. For example, if the computing device is in state 3 (as Figure 3 shown), assuming the PCRs store the current state measurements for state 3, the user may not be able to determine the PCR state of the previous state, such as state 2 after the last cold boot of the computing device. A cold boot, also known as a hard boot, is a reboot of the computing device where the power of the computing device is physically turned off and then turned back on, resulting in the initial startup of the computing device. In addition, during a cold boot, the system memory is not restored from disk, as is the case with an S4 state resume. The system is said to be started "from scratch" after a cold boot. The PCRs from a given state may contain measurements made during the startup sequence or a previous DRTM sequence. These measurements may have been overwritten by a subsequent low-power state (also known as the "S4" state) or DRTM sequence, but are still relevant to the attestation server if the device has not been rebooted again since then.

[0014] The implementation disclosed herein provides a platform configuration register (PCR) attestation system that uses a device's Trusted Platform Module (TPM). The PCR attestation system provides one or more computer-executable instructions to create a non-volatile (NV) index in the TPM of a computing device, where a PCR policy specifies that the PCR values on the TPM equal a predetermined set of values, and if the PCR policy is satisfied, the value of the "NV write" attribute is set to specify that the PCR policy has been satisfied since the device last booted. The NV index can be used to determine the PCR state of the computing device at a given time and to determine that the computing device has not booted since that previous state.

[0015] In one implementation, the TPM for a computing device can be provided as part of the device. For example, the TPM might be part of the device's microprocessor. Alternatively, the TPM can be a discrete component of the device implemented on a chip connected to the device's motherboard. In such an implementation, the TPM chip can use the device's system bus to communicate with the device's microprocessor.

[0016] Figure 1 An example implementation of a PCR attestation system 100 is shown for providing post hoc platform attestation for various PCR states. The PCR attestation system 100 can be implemented on a computing device 101 configured to have a TPM 102 thereon. The computing device 101 can be any computing device, such as a laptop computer, a desktop computer, a mobile computing device, or an Internet of Things (IoT) device. The following Figure 6 Further discloses examples of computing devices and their components.

[0017] In an implementation of the PCR attestation system 100, the TPM 102 can include a processing unit or CPU 104, a non-volatile (NV) memory for storing the NV index 106, and an input / output (I / O) module 108. The TPM 102 can use the I / O module 108 to communicate with the operating system (OS) 120 of the computing device 101. For example, the I / O module 108 can communicate with the OS 120 using a communication bus such as Figure 6 the system bus 23 disclosed in.

[0018] One or more external applications residing on a computer 136, such as a remote application 132 or a local application 134, can communicate with the computing device 101 to request the PCR attestation system 100 of the computing device 101. For example, the remote application 132 can be a social media application that communicates with the computing device 101 using a network 150 such as the Internet to request the PCR attestation of the computing device 101 by sending a get request 140 to the operating system 120 of the computing device 101.

[0019] In one implementation, computing device 101 further includes a plurality of PCRs 112 and a PCR log 116. In response to receiving request 140, operating system 120 may generate a TPM2_Quote command and send the TPM2_Quote command to TPM 102. In response, TPM 102 may generate a PCR quote having the values of PCRs 112, attest it using a TPM102 AIK such as AIK 114a, AIK 114b, etc., and send the attested PCR quote to operating system 120. For example, TPM 102 may include computing code 118 to generate such an attested PCR quote.

[0020] In one implementation of TPM 102, computing code 118 is further configured to determine whether computing device 101 has been cold started, and in response to such determination, computing code 118 generates a non-volatile (NV) index 106. The NV index 106 may store various attributes and policies 110 that specify that to modify the NV index 106, the PCR 112 values are in a given state. For example, in one implementation, policy 110 may be used for the current PCR 112 values. As a result, the values of PCR 112 required to write to the NV index 106 are saved as part of the NV index 106. Thus, in a later state, the previous state of PCR 112 can be verified using policy 110 and the NV write and ordered attributes of the NV index 106.

[0021] The NV index 106 may further include an "ordered" attribute. In one implementation, the ordered attribute may require that the "write" attribute be CLEAR at restart. The attributes of the NV index 106 may be flags having specific values. For example, the "ordered" attribute of the NV index 106 may take the value "1" or "0", where one of these values notifies CLEAR at the restart state. Additionally, the NV index 106 may further include an "NV write" attribute, where the value of the "NV write" attribute is set when writing to the NV index 106. For example, until the NV index 106 is written, the value of the "NV write" attribute may be zero (0), however, when an entity writes to the NV index 106, the value of the "NV write" attribute may be set to one (1). Thus, the value of the "NV write" attribute of the NV index 106 can be used to indicate whether it is being written while a given NV index 106 is being defined.

[0022] In one implementation of the NV index 106, there may be no restrictions on read access to the NV index 106. This can be specified by the "AUTHREAD" attribute, which, in combination with a zero-length AUTH value, specifies that all entities, including the owner of the computing device 101, the platform on which the computing device 101 is implemented, etc., can read the content of the NV index 106. In an alternative implementation, an attribute can be provided that specifies which entities can write to or modify the NV index 106. Additionally, the content of the NV index 106 can be any number, which can be used to specify the version of the NV index 106. In this implementation, for example, when the design of the policy 110 of the NV index 106 is changed, the content of the NV index 106 can change.

[0023] Figure 2 An example state diagram 200 of a PCR attestation system using the TPM of a device is shown. Specifically, the state diagram 200 shows the various states of the computing device along the timeline 202 and the corresponding PCRs and NV indices in the TPM 228. For example, the computing device may have just completed a cold start in state 204. Subsequently, certain events may change the PCR state, such as the DRTM sequence 206, resulting in a new state 208, hibernation 210, resulting in a new state 212, and so on. Additionally, after state 212, there is a restart that leads to state 214. Each of the states 204 - 212 can have a corresponding value of the PCR. For example, the value of PCR 220 in state 204 can be (x, y, a, b), the value of PCR 222 in state 208 can have changed to (x, y, a', b'), and the value of PCR 224 in state 214 can have changed to (x', y', a', b').

[0024] Figure 2 The NV indices for various computing device states are also shown. For example, the NV index 230 is associated with the computing device state 204 using the PCR policy 232, where the PCR policy 232 specifies that the PCR value is equal to the current value of the PCR as specified by 220. Similarly, the NV index 240 is associated with the computing device state 208 using the PCR policy 242, where the PCR policy 242 specifies that the PCR value is equal to the current value of the PCR as specified by 222.

[0025] The remote prover 250 can request a PCR status attestation for state 204 from the operating system 260 of the computing device from the new state 208 or 212 or any future state until the device is rebooted. In response, the operating system 260 sends a TPM2_NV_Certify command to the TPM 228. In response, the TPM 228 can send the attested NV index attributes determined according to the PCR policy 232 from the NV index 230 associated with state 204. The remote prover 250 can verify that the attested NV index 230 has a PCR policy 232 that requires the PCR status associated with state 204 and an attribute indicating that the policy has been satisfied since the last cold reboot of the system. It can then be concluded that the system has been in state 204 since the last cold reboot of the system.

[0026] Figure 3 An alternative example state diagram 300 of a PCR attestation system using the TPM of a computing device is shown. In this implementation, the circles (1)…(6) represent the system states of the computing device. An AIK called "AIK 1" 320 is created in this state (1). The system is rebooted between state (1) and (2), and DRTM or S4 resume is performed between each subsequent state. An NV index 350 is created in state (2) using the TPM_NV_DefineSpace command 330 and written using the TPM2_NV_Write command 332. Some other AIK, called "AIK 2" 322, is created in state (5). Platform attestation occurs in state (6). The arrow 334 from state (3) indicates that the attestation in state (2) can be manually revoked by using the TPM2_NV_UndefineSpace command 334 to undefine the NV index 350.

[0027] If the NV index 350 is not revoked, the AIK 2 322 created in state (5) can use the TPM2_NV_Certify command 336 to attest that the device was previously in state (2) since the last cold start, even from state (6). During platform attestation, the attributes and policies on the attested NV 342 are checked. The TCG log 302 stores the log events related to state (2), while the TCG log 304 stores the log events related to state (6). The PCR quote 340 generated using the TPM2_Quote command 338 in state (6) can also be signed by the AIK 2 322 and sent to a remote prover in response to a challenge 360 from such a remote prover. A valid response to this challenge indicates that the device is currently in state (6).

[0028] In addition, 310 represents a reset of the write attributes of the NV index 350 (since it also has an ordered attribute), and each of 312, 314, and 316 represents a PCR at states (2), (3), and (5), respectively.

[0029] Figure 4 Operation 400 for generating a non-volatile (NV) index for providing a PCR attestation using the TPM of a device is shown. Operation 400 may be implemented in the TPM of the device. Operation 402 determines a cold start of the computing device. In response, operation 404 generates an NV index in the TPM, and operation 406 generates a PCR policy for the NV index. Operation 408 evaluates the PCR policy using the current PCR value, and if the PCR policy is satisfied by determining that the PCR value according to the PCR policy is similar to the current value of the PCR, operation 410 sets the NV write attribute to indicate that the PCR policy of the NV index has been satisfied and the index has been written. The NV index is updated at operation 412.

[0030] Figure 5 Example operation 500 for providing post hoc PCR attestation using the TPM of a device is shown. Operation 500 may be implemented in the TPM of the device. Operation 502 determines whether a request for a PCR status attestation is received. If so, operation 504 verifies the values of all attributes (including write and ordered) of the NV index and the policy (associated with the PCR value). Subsequently, operation 506 signs the attributes and policy of the NV index using the AIK from the TPM, and operation 508 forwards the signed attestation to the requester.

[0031] Figure 6 Example system 600 is shown, which may be used to implement the described techniques for providing PCR attestation using the TPM of a computing device. For implementing the described techniques Figure 6 example hardware and operating environments include computing devices such as a general-purpose computing device in the form of a computer 20, a mobile phone, a personal data assistant (PDA), a tablet computer, a smartwatch, a game controller, or other types of computing devices. In Figure 6 an implementation, for example, computer 20 includes a processing unit 21, a system memory 22, and a system bus 23 that operably couples various system components including the system memory to the processing unit 21. There may be only one or there may be more than one processing unit 21 such that the processors of computer 20 include a single central processing unit (CPU) or multiple processing units, which are generally referred to as a parallel processing environment. Computer 20 may be a conventional computer, a distributed computer, or any other type of computer; the implementation is not limited thereto.

[0032] The system bus 23 can be any one of several types of bus structures, which include a memory bus or memory controller, a peripheral bus, a switch fabric, a point-to-point connection, and a local bus using any one of various bus architectures. The system memory 22 can also be simply referred to as memory 22 and includes a read-only memory (ROM) 24 and a random access memory (RAM) 25. The basic input / output system (BIOS) 26 is stored in the ROM 24, and the basic input / output system (BIOS) 26 contains basic routines that help transfer information between elements within the computer 20 during startup. The computer 20 also includes: a hard disk drive 27 for reading from and writing to a hard disk (not shown), a disk drive 28 for reading from or writing to a removable disk 29, and an optical disk drive 30 for reading from or writing to a removable optical disk 31, such as a CD ROM, DVD, or other optical media.

[0033] The hard disk drive 27, the disk drive 28, and the optical disk drive 30 are respectively connected to the system bus 23 through a hard disk drive interface 32, a disk drive interface 33, and an optical drive interface 34. The drives and their associated tangible computer-readable media provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computer 20. Those skilled in the art should understand that any type of tangible computer-readable media can be used in an exemplary operating environment.

[0034] Multiple program modules can be stored on the hard disk drive 27, the disk drive 28, the optical disk drive 30, the ROM 24, or the RAM 25, including an operating system 35, one or more application programs 36, other program modules 37, and program data 38. A user can generate reminders on the personal computer 20 through input devices such as a keyboard 40 and a pointing device 42. Other input devices (not shown) can include a microphone (for example, for voice input), a camera (for example, for a natural user interface (NUI)), a joystick, a gamepad, a dish satellite antenna, a scanner, etc. These and other input devices are typically connected to the processing unit 21 through a serial port interface 46 coupled to the system bus 23, but can be connected through other interfaces such as a parallel port, a game port, or a universal serial bus (USB) (not shown). A monitor 47 or other type of display device is also connected to the system bus 23 through an interface such as a video adapter 48. In addition to the monitor 47, a computer typically also includes other peripheral output devices (not shown), such as speakers and printers.

[0035] Computer 20 can operate in a networked environment using logical connections to one or more remote computers, such as remote computer 49. These logical connections are implemented through a communication device that is coupled to or part of computer 20; the implementation is not limited to a specific type of communication device. Remote computer 49 can be another computer, a server, a router, a network PC, a client, a peer device, or other common network node, and typically includes many or all of the elements described above with respect to computer 20. Figure 6 The depicted logical connections include a local area network (LAN) 51 and a wide area network (WAN) 52. Such networked environments are common in office networks, enterprise-wide computer networks, intranets, and the Internet, which are all types of networks.

[0036] When used in a LAN network environment 51, computer 20 is connected to the local network 51 through a network interface or adapter 53, which is a communication device. When used in a WAN network environment, computer 20 typically includes a modem 54, a network adapter, a communication device, or any other type of communication device for establishing communication over the wide area network 52. Modem 54, which can be internal or external, can be connected to the system bus 23 via a serial port interface 46. In a networked environment, the program engine or portions thereof described with respect to personal computer 20 can be stored in a remote memory storage device. It should be understood that the network connections shown are examples, and other means of communication devices for establishing communication links between computers can be used.

[0037] In an example implementation, software or firmware instructions for providing provable and breakable device identification can be stored in memory 22 and / or removable disk 29 or removable optical disk 31 and processed by processing unit 21. Rules for providing provable and breakable device identification can be stored in memory 22 and / or removable disk 29 or removable optical disk 31 as persistent data storage. For example, a TPM module 602 can be implemented on computer 20 to provide PCR attestation (alternatively, TPM module 602 can be implemented on a server or in a cloud environment). TPM module 602 can utilize one or more of processing unit 21, memory 22, system bus 23, and other components of personal computer 20.

[0038] In contrast to a tangible computer-readable storage medium, an intangible computer-readable communication signal can embody computer-readable instructions, data structures, program modules, or other data residing in a modulated data signal such as a carrier wave or other signal transmission mechanism. The term "modulated data signal" refers to a signal having one or more of its characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, intangible communication signals include wired media such as a wired network or direct wired connection, and wireless media such as acoustic, RF, infrared, and other wireless media.

[0039] Some embodiments may include an article of manufacture. The article of manufacture may include a tangible storage medium for storing logic. Examples of storage media may include one or more types of computer-readable storage media capable of storing electronic data, including volatile memory or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, and the like. Examples of logic may include various software elements, such as software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, programs, software interfaces, application programming interfaces (APIs), instruction sets, computing code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. In one embodiment, for example, an article of manufacture may store executable computer program instructions that, when executed by a computer, cause the computer to perform the methods and / or operations according to the described embodiments. The executable computer program instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, etc. The executable computer program instructions may be implemented according to a predefined computer language, manner, or syntax to direct the computer to perform a particular function. The instructions may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language.

[0040] A system for providing PCR attestation using a TPM module may include various tangible computer-readable storage media and intangible computer-readable communication signals. The tangible computer-readable storage may be used by the PCR attestation system 100 as Figure 1Any available medium accessible (as disclosed in the Chinese patent) can be used to embody it, and includes volatile and non-volatile storage media, removable and non-removable storage media. Tangible computer-readable storage media do not include intangible and transient communication signals, and include volatile and non-volatile, removable and non-removable storage media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Tangible computer-readable storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other storage technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic tape cartridges, tapes, magnetic disk storage or other magnetic storage devices, or any other tangible medium that can be used to store the required information and can be accessed by the PCR attestation system 100 (as Figure 1 shown). In contrast to tangible computer-readable storage media, intangible computer-readable communication signals can embody computer-readable instructions, data structures, program modules, or other data residing in a modulated data signal such as a carrier wave or other signal transmission mechanism. The term "modulated data signal" refers to a signal having one or more of its characteristics set or changed in such a manner as to encode information in the signal. By way of example and not limitation, intangible communication signals include wired media such as a wired network or a direct wired connection, and wireless media such as acoustic, RF, infrared, and other wireless media.

[0041] The PCR attestation system disclosed herein provides a solution to the problems of various malware intrusions into computing devices and other technical problems that other solutions cannot and / or are ineffective to timely support a large number of PCR attestation requests. Specifically, the PCR attestation system disclosed herein provides an unconventional technical solution to this technical problem by providing a TPM-based NV index to store a PCR policy that specifies that the value of the PCR on the TPM is equal to a predetermined set of values, and if the PCR policy is satisfied, resetting the value of the NV write attribute to specify a cold start of the computing device.

[0042] The physical article disclosed herein includes one or more tangible computer-readable storage media encoded with computer-executable instructions for performing a computer process on a computing device, the computer process including: creating a non-volatile (NV) index in a trusted platform module (TPM) of the device using a platform configuration register (PCR) policy that specifies that the PCR value on the TPM is equal to a predetermined set of values, and if the PCR policy is satisfied, setting the value of the NV write attribute to specify that the PCR policy has been satisfied since the last cold start of the device. In one implementation, the PCR policy further specifies that the value of the PCR is equal to its current value.

[0043] In an alternative implementation, the computer processing further includes determining whether a cold start has been performed on the computing device, and in response to determining a cold start of the computing device, creating an NV index. Alternatively, the computer process further includes signing the NV index using the attestation identity key (AIK) of the TPM. Yet alternatively, the computer process further includes: verifying the value of the NV write attribute, and in response to verifying the value of the NV write attribute to indicate that the computing device has not been restarted since the NV index was generated, attesting to the previous state of the TPM.

[0044] In one implementation, attesting to the previous state of the TPM further includes signing the NV index using a newly generated attestation identity key (AIK). In another implementation, attesting to the previous state of the TPM further includes attesting that the event log in the PCR indicates the current state of the computing device since the last boot of the computing device. In one implementation, the computer process further includes deleting the NV index in response to determining the presence of a malware attack. In another implementation, the computer process further includes writing one or more attributes of the NV index in response to determining the initiation of a clean shutdown of the computing device.

[0045] The method disclosed herein includes generating a non-volatile (NV) index in a trusted platform module (TPM) of a device using a platform configuration register (PCR) policy, the platform configuration register (PCR) policy specifying that the PCR values on the TPM are equal to a predetermined set of values, and in response to determining that the PCR policy is satisfied, setting the value of the NV write attribute to specify that the PCR policy has been satisfied since the last cold start of the device. In one implementation, the PCR policy specifies that the values of the PCRs on the TPM are equal to a predetermined set of values. In another implementation, the PCR policy further specifies that the values of the PCRs are equal to their current values. Yet another implementation further includes writing one or more attributes of the NV index in response to determining the initiation of a clean shutdown of the computing device.

[0046] In an alternative implementation, the method further includes: verifying the value of the NV write attribute, and in response to verifying the value of the NV write attribute to indicate that the computing device has not been restarted since the NV index was generated, attesting to the previous state of the TPM. In one implementation, attesting to the previous state of the TPM further includes signing the NV index using a newly generated attestation identity key (AIK). In another implementation, attesting to the previous state of the TPM further includes attesting that the event log in the PCR indicates the current state of the computing device since the last boot of the computing device.

[0047] The system disclosed herein includes a memory, one or more processor units, and a platform configuration register (PCR) attestation system that is stored in the memory and executable by one or more processor units, the PCR attestation system encoding computer-executable instructions on the memory for execution on one or more processor units, the computer process including determining whether a cold start has been performed on a computing device and, in response to determining a cold start of the computing device, generating a non-volatile (NV) index in a trusted platform module (TPM) of the device, generating a PCR policy that specifies that PCR values on the TPM are equal to a predetermined set of values, and, in response to determining that the PCR policy is satisfied, resetting an NV write attribute value for specifying that the PCR policy has been satisfied since the last time the device was cold started.

[0048] In one implementation, the PCR policy further specifies that the values of the PCRs are equal to their current values. In another implementation, the computer process further includes: verifying the value of the NV write attribute and, in response to verifying that the value of the NV write attribute indicates that the computing device has not been restarted since the NV index was generated, attesting to a previous state of the TPM. Alternatively, attesting to a previous state of the TPM further includes: signing the NV index with a newly generated attestation identity key (AIK).

[0049] The foregoing specification, examples, and data provide a complete description of the structure and use of exemplary embodiments of the invention. Since many implementations of the invention can be made without departing from the spirit and scope of the invention, the invention resides in the claims hereinafter appended. Further, structural features of different embodiments may be combined in another implementation without departing from the recited claims.

Claims

1. A physical article for trusted computing, comprising one or more tangible computer-readable storage media encoding computer-executable instructions for performing a computer process on a computing device, the computer process comprising: Creating a non-volatile NV index in a trusted platform module TPM of the device using a platform configuration register PCR policy that specifies that the values of the PCRs on the TPM are equal to a predetermined set of values; Evaluating the PCR policy; In response to determining that the PCR policy is satisfied, setting the value of an NV write attribute to specify that the PCR policy has been satisfied since the device was last cold-started; And Signing the NV index with a newly generated attestation identity key AIK to attest to a previous state of the TPM, where attesting to the previous state of the TPM further comprises: Verifying the value of the NV write attribute; And In response to verifying the value of the NV write attribute to indicate that the computing device has not been restarted since the NV index was generated, attesting to the previous state of the TPM.

2. The physical article according to claim 1, wherein the PCR policy further specifies that the values of the PCRs are equal to their current values.

3. The physical article according to claim 1, the computer process further comprising determining whether a cold start has been performed on the computing device and, in response to determining a cold start of the computing device, creating the NV index.

4. The physical article according to claim 1, wherein the computer process further comprises signing the NV index with the attestation identity key AIK.

5. The physical article according to claim 1, wherein attesting to the previous state of the TPM further comprises attesting that a log of events in the PCRs indicates the current state of the computing device since the last boot of the computing device.

6. The physical article according to claim 1, wherein the computer process further comprises deleting the NV index in response to determining the presence of a malware attack.

7. The physical article according to claim 1, wherein the computing process further comprises writing one or more attributes of the NV index in response to determining the initiation of a clean shutdown of the computing device.

8. A method at least partially executed on at least one processor of a computing device in a computing environment, the method comprising: Generating a non-volatile NV index in a trusted platform module TPM of the device using a platform configuration register PCR policy that specifies that the values of the PCRs on the TPM are equal to a predetermined set of values; Evaluating the PCR policy; In response to determining that the PCR policy is satisfied, setting the value of an NV write attribute to specify that the PCR policy has been satisfied since the device was last cold-started; And Signing the NV index with a newly generated attestation identity key AIK to attest to a previous state of the TPM, where attesting to the previous state of the TPM further comprises: Verifying the value of the NV write attribute; And Authenticate the previous state of the TPM in response to verifying the value of the NV write attribute to indicate that the computing device has not been restarted since the NV index was generated.

9. The method according to claim 8, wherein the method further comprises deleting the NV index in response to determining the presence of a malware attack.

10. The method according to claim 9, wherein the PCR policy further specifies that the values of the PCRs are equal to their current values.

11. The method according to claim 8, further comprising writing one or more attributes of the NV index in response to determining the initiation of a clean shutdown of the computing device.

12. The method according to claim 8, wherein authenticating the previous state of the TPM further comprises authenticating that the log of events in the PCRs indicates the current state of the computing device since the last boot of the computing device.

13. A system in a computing environment, comprising: a memory; one or more processor units; a platform configuration register (PCR) authentication system stored in the memory and executable by the one or more processor units, the PCR authentication system encoding computer-executable instructions on the memory for execution on the one or more processor units, the computer process comprising: determining whether a cold boot has been performed on the computing device; and in response to determining that a cold boot has been performed on the computing device: generating a non-volatile (NV) index in a trusted platform module (TPM) of the device, generating a PCR policy that specifies that the values of the PCRs on the TPM are equal to a set of predetermined values, in response to determining that the PCR policy is satisfied, resetting the value of the NV write attribute to specify that the PCR policy has been satisfied since the last time the device was cold booted; and signing the NV index with a newly generated attestation identity key (AIK) to authenticate the previous state of the TPM, wherein authenticating the previous state of the TPM further comprises: verifying the value of the NV write attribute; and in response to verifying the value of the NV write attribute to indicate that the computing device has not been restarted since the NV index was generated, authenticating the previous state of the TPM.

14. The system according to claim 13, wherein the PCR policy further specifies that the values of the PCRs are equal to their current values.

Citation Information

Patent Citations

  • Secure storage of temporary secrets

    CN102549594A