Base Component Signing Key Association for Virtualized Platform Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing TCG integrity measurement approach is limited by the small number of PCRs in the TPM, making it infeasible to store individual measurements for a large number of virtualized platform components, and there is a challenge in providing a trustable signing key for the software component known as the base component during platform start-up.
Innovation Solution
A method and system for operatively associating a signing key with a software component of a computing platform, involving generating a signing key and certificate evidence, storing a key-related item in secure persistent storage, and using the trusted device to enable the component to obtain the key-related item during a specific period of platform start-up, ensuring the key is used consistently across sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the TPM contains only a small number of PCRs (typically 16), then the TPM structure remains simple and manageable, but it becomes infeasible to store individual measurements for a large number of virtualized platform components
Solution Approach 1:
The patent divides the measurement system into two segments: the TPM handles measurements for the trusted computing base components (stored in PCRs), while a separate software component called the base component handles measurements for virtualized platform components (stored in software-maintained registers). This segmentation allows the system to measure a large number of virtualized components without increasing the fixed number of TPM PCRs, thus resolving the contradiction between adaptability and device complexity.
2Reliability
If the base component securely stores integrity metrics provided by virtual trusted entities, then comprehensive integrity measurement is achieved, but the challenge arises of providing the base component with its signing key in a trustable manner during platform start-up
Solution Approach 1:
The patent applies preliminary action by having the signing key generated and made available to the base component during the early platform start-up process, before any untrusted software is loaded. The key is provided by a trusted entity (such as the TPM or a trusted bootloader) during this initial phase when the platform state is still trusted, ensuring the key can be securely established without complex ongoing key management mechanisms.
3Productivity
If virtualization is used to consolidate multiple virtual platforms on the same computing platform, then resource utilization improves, but new challenges arise in integrity measurement and trust dependency tracking
Solution Approach 1:
The base component serves multiple functions: it acts as a measurement agent for virtualized components, maintains integrity metrics in software registers, provides signing capabilities for integrity reports, and manages the connection between the TPM and virtualized platforms. This multi-functionality allows a single component to handle the complex integrity measurement requirements of virtualized environments without requiring separate dedicated systems for each function, thus managing complexity while supporting high resource utilization.
Data Source
AI summary
A method and system is provided for operatively associating a signing key with a software component of a computing platform. The computing platform includes a trusted device and on start-up first loads a set of software components with each component being measured prior to loading and a corresponding integrity metric recorded in registers of the trusted device. The system stores a key-related item in secure persistent storage, the key-related item being either the signing key or authorization data for its use. The trusted device is arranged to enable a component of the software-component set to obtain the key-related item, this enabling only occurring when the current register values correspond to values only present prior to loading of components additional to those of the software-component set. Certificate evidence is provided indicating that the signing key is operatively associated with a component of the software-component set.


