CRTM Chain Authentication via TPM PCR Measurement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for authenticating a Core Root of Trust Measurement (CRTM) chain do not reliably verify that the hypervisor has not been corrupted, modified, or infected with a computer virus, especially at lower levels of boot operations, making it difficult to detect and repair such infections.
Innovation Solution
An apparatus and method that includes modules for retrieving a value from a predetermined location to unlock a decryption key, decrypting an authentication signal using the key, and communicating it to the user, utilizing a Trusted Platform Module (TPM) interface, PCR interface, and virus scan module to ensure the authenticity of the CRTM chain, with options for audio, video, and LED-based authentication signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the TPM verifies the boot block and decrypts the hypervisor code, then the authentication process is improved, but it cannot guarantee that the underlying code has not been modified, corrupted, or infected with a virus
Solution Approach 1:
The patent applies preliminary action by having the TPM verify and measure the boot block before executing it, and by having each subsequent component verify and measure the previous component in the boot chain. This preliminary verification ensures that any corruption or infection is detected before the compromised code can execute or spread, addressing the limitation where traditional TPM verification does not guarantee code integrity throughout the boot process.
2Reliability
If the boot block is encrypted and verified by the TPM, then security is improved, but the verification process does not completely ensure that processes have not been modified, corrupted, or infected
Solution Approach 1:
The patent implements feedback by creating a measurement chain where each component in the boot process verifies the previous component and records its own measurement in the TPM. The final component (such as the hypervisor or operating system) can read back all the measurements from the TPM to verify the entire boot chain integrity. This feedback mechanism ensures that any modification, corruption, or infection is detected, providing complete verification rather than just checking the boot block in isolation.
3Adaptability or versatility
If multiple operating systems run on a single hardware platform through a hypervisor, then system versatility is improved, but the risk of hypervisor infection becomes extremely difficult to detect and repair
Solution Approach 1:
The patent applies preliminary action by verifying and measuring the hypervisor code before it executes and before any operating systems are loaded. The TPM measures the hypervisor's cryptographic hash and stores it in a PCR register. This preliminary verification ensures that if the hypervisor is infected or corrupted, the infection is detected before it can compromise any of the multiple operating systems running on the platform, making infection detection feasible even in virtualized environments.
Solution Approach 2:
The patent implements feedback by providing a mechanism where the measurements of all boot components including the hypervisor are stored in the TPM and can be read back and verified. This allows the system to provide feedback on the integrity of the hypervisor, enabling detection of infections or corruptions. The measurement chain creates a verifiable record that can be used to detect hypervisor compromises, addressing the difficulty of detecting and measuring hypervisor infections in multi-OS environments.
Data Source
AI summary
An apparatus, system, and method are disclosed for authentication of a core root of trust measurement chain. The apparatus for authentication of a CRTM chain is provided with a plurality of modules configured to carry out the steps of retrieving a decryption key from a predetermined location on the device selected for authentication, decrypting an authentication signal using the decryption key, and communicating the decrypted authentication signal to a user. In the described embodiments, these modules include a retrieval module, a decryption module, and a communication module. Beneficially, such an apparatus, system, and method would reliably verify that a link in the CRTM chain has not been corrupted, modified, or infected with a computer virus. Specifically, such an apparatus, system, and method would enable verification that the hypervisor has not been corrupted, modified, or infected with a computer virus.


