Client Authentication Key Management for Secure Boot Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for verifying the integrity of client devices in telecommunications and information processing systems face challenges when software modules, such as OS updates, lead to delayed updates in PCR comparison values, resulting in authentication failures even when valid software modules are executed.
Innovation Solution
An information processing device with a key holding unit, key information holding unit, decryption processing unit, and authentication processing unit that securely manages and updates encryption keys to ensure integrity verification without requiring database updates, even after system program updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the server stores PCR comparison values in a database to verify platform integrity, then authentication reliability is improved, but device complexity and maintenance burden increase due to required database updates
Solution Approach 1:
The invention segments the authentication verification process by separating the PCR comparison functionality from the server database. Instead of storing and updating PCR comparison values centrally on the server, the patent implements a local PCR register in the information processing device that autonomously maintains and compares PCR values. This segmentation eliminates the need for server-side database updates while preserving authentication reliability.
Solution Approach 2:
The information processing device performs self-service by autonomously maintaining its own PCR comparison values locally. The device's control unit automatically updates the PCR register with hash values of executed programs and performs integrity verification without requiring external server intervention or database updates. This self-service mechanism resolves the contradiction by making the system independent of centralized database maintenance.
2Measurement precision
If the server updates PCR comparison values after software module updates, then measurement precision is maintained, but loss of time occurs due to update delays causing authentication failures
Solution Approach 1:
The invention applies preliminary action by pre-establishing the PCR register and its update mechanism within the information processing device itself. The control unit is configured to automatically update the PCR register with hash values of executed programs in real-time, before any authentication verification is needed. This eliminates the time loss associated with waiting for server updates, as the device maintains current PCR comparison values locally and continuously.
3Reliability
If the system uses centralized server verification with database storage, then information security is improved, but ease of operation deteriorates due to complex update procedures
Solution Approach 1:
The invention extracts the PCR comparison and integrity verification functionality from the centralized server system and relocates it to the local information processing device. The control unit in the device independently maintains the PCR register and performs verification operations without requiring server involvement. This extraction simplifies operation by eliminating complex update procedures while preserving information security through local cryptographic verification.
Data Source
AI summary
The present invention provides an information processing device, an authentication system, etc. that save a server the trouble of updating a database, etc., even when a software module in a client device is updated, and that are capable of verifying whether software modules that have been started in the client device are valid. The terminal device A100 holds private keys 1 and 2, and performs authentication processing with the terminal device B101 using the private key 2. The private key 1 has been encrypted such that the private key 1 is decryptable only when secure boot is completed. The private key 2 has been encrypted such that the private key 2 is decryptable using the private key 1 only when the application module X that has been started is valid. When the authentication processing is successful, the terminal device B101 verifies that the terminal device A100 has completed secure boot and the application module X that has been started in the terminal device A100 is valid. Also, the terminal device B101 performs the authentication processing using the same private key 2, regardless of whether a program pertaining to the secure boot of the terminal device A100 is updated or not.


