Blockchain Boot Tracking for Persistent TPM Audit Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The lifetime of boot audit data in a Trusted Platform Module (TPM) is too short to satisfy integrity compliance requirements, as it resets at each power cycle, causing boot audit data to be reset or lost, which is a limitation in ensuring the security and integrity of the boot process in data processing systems.

Innovation Solution

Implementing a blockchain-based system for boot tracking, where a primary blockchain tracks the boot process and a secondary blockchain provides a persistent and distributed record of boot audit data, ensuring that measurements of firmware modules and configurations are securely stored and verified across multiple nodes, preventing tampering and ensuring integrity compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If boot audit data is stored in TPM, then security measurement capability is improved, but data persistence deteriorates due to reset at each power cycle

Engineering Contradiction:
Improvesecurity measurement capabilityVSAvoiddata persistence
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent transitions boot audit data storage from a single local TPM to a distributed blockchain network, adding the dimension of distributed consensus and network-wide persistence. This resolves the contradiction by maintaining local security measurement capability while achieving persistent storage through the immutable blockchain ledger that survives power cycles.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces blockchain as an intermediary between the TPM and persistent storage. The TPM generates boot audit measurements, which are then recorded on the blockchain network. This intermediary layer preserves the security measurement capability of the TPM while achieving long-term persistence through the blockchain's immutable ledger, solving the data persistence problem.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of stationary object

If blockchain-based boot tracking is implemented, then data persistence is improved, but device complexity increases due to distributed network requirements

Engineering Contradiction:
Improvedata persistenceVSAvoidsystem complexity
Core Design Contradiction:
Duration of action of stationary objectVSDevice complexity

Solution Approach 1:

The patent divides the blockchain system into two distinct layers: a primary blockchain for real-time boot tracking with high performance requirements, and a secondary blockchain for archival storage with emphasis on persistence. This segmentation allows each layer to be optimized independently, reducing the complexity burden on individual components while maintaining overall data persistence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the archival storage function from the primary blockchain system and places it on a separate secondary blockchain. This extraction reduces the complexity of the primary system by removing the burden of long-term archival management, while the secondary blockchain专门 handles persistence requirements with simpler, more efficient storage mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If primary and secondary blockchains are used, then data reliability is improved through distributed verification, but processing time increases due to dual-chain operations

Engineering Contradiction:
Improvedata reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by recording boot audit data on the primary blockchain in real-time during the boot process. This immediate recording ensures data reliability through distributed verification while minimizing processing delays. The secondary blockchain then archives this already-verified data, avoiding redundant verification steps and reducing overall processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges the boot tracking functionality of the primary blockchain with the archival capabilities of the secondary blockchain through a unified interface. This integration allows the system to leverage the speed and verification mechanisms of the primary chain while utilizing the persistence of the secondary chain, achieving both high reliability and efficient processing without the overhead of completely separate operations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10262140B2Methods and apparatus to facilitate blockchain-based boot tracking
Publication Date: 2019.04.16 INTEL CORP
  • US10262140B2 patent drawing
  • US10262140B2 patent drawing
  • US10262140B2 patent drawing

AI summary

A device with support for blockchain-based boot tracking comprises at least one processor, non-volatile storage responsive to the processor, and at least one boot module in the non-volatile storage. The boot module, when executed by the processor, enables the device to generate a measurement of the boot module, generate an internal ledger transaction based on the measurement of the boot module, and send the internal ledger transaction to a remote device. In addition, the boot module enables the device to (a) receive an external ledger transaction from the remote device, wherein the external ledger transaction is based on a measurement for a boot module of the remote device; (b) in response to receiving the external ledger transaction, verify the external ledger transaction; and (c) in response to verifying the external ledger transaction, add the external ledger transaction to a boot audit blockchain. Other embodiments are described and claimed.