CRTM Chain Authentication via TPM PCR Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for authenticating a Core Root of Trust Measurement (CRTM) chain do not reliably verify that the hypervisor has not been corrupted, modified, or infected with a computer virus, especially at lower levels of boot operations, making it difficult to detect and repair such infections.

Innovation Solution

An apparatus and method that includes modules for retrieving a value from a predetermined location to unlock a decryption key, decrypting an authentication signal using the key, and communicating it to the user, utilizing a Trusted Platform Module (TPM) interface, PCR interface, and virus scan module to ensure the authenticity of the CRTM chain, with options for audio, video, and LED-based authentication signals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the TPM verifies the boot block and decrypts the hypervisor code, then the authentication process is improved, but it cannot guarantee that the underlying code has not been modified, corrupted, or infected with a virus

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcode corruption or virus infection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the TPM verify and measure the boot block before executing it, and by having each subsequent component verify and measure the previous component in the boot chain. This preliminary verification ensures that any corruption or infection is detected before the compromised code can execute or spread, addressing the limitation where traditional TPM verification does not guarantee code integrity throughout the boot process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the boot block is encrypted and verified by the TPM, then security is improved, but the verification process does not completely ensure that processes have not been modified, corrupted, or infected

Engineering Contradiction:
ImprovesecurityVSAvoidverification completeness
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback by creating a measurement chain where each component in the boot process verifies the previous component and records its own measurement in the TPM. The final component (such as the hypervisor or operating system) can read back all the measurements from the TPM to verify the entire boot chain integrity. This feedback mechanism ensures that any modification, corruption, or infection is detected, providing complete verification rather than just checking the boot block in isolation.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple operating systems run on a single hardware platform through a hypervisor, then system versatility is improved, but the risk of hypervisor infection becomes extremely difficult to detect and repair

Engineering Contradiction:
Improvesystem versatilityVSAvoidhypervisor infection detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by verifying and measuring the hypervisor code before it executes and before any operating systems are loaded. The TPM measures the hypervisor's cryptographic hash and stores it in a PCR register. This preliminary verification ensures that if the hypervisor is infected or corrupted, the infection is detected before it can compromise any of the multiple operating systems running on the platform, making infection detection feasible even in virtualized environments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by providing a mechanism where the measurements of all boot components including the hypervisor are stored in the TPM and can be read back and verified. This allows the system to provide feedback on the integrity of the hypervisor, enabling detection of infections or corruptions. The measurement chain creates a verifiable record that can be used to detect hypervisor compromises, addressing the difficulty of detecting and measuring hypervisor infections in multi-OS environments.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8433924B2Apparatus, system, and method for authentication of a core root of trust measurement chain
Publication Date: 2013.04.30 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8433924B2 patent drawing
  • US8433924B2 patent drawing
  • US8433924B2 patent drawing

AI summary

An apparatus, system, and method are disclosed for authentication of a core root of trust measurement chain. The apparatus for authentication of a CRTM chain is provided with a plurality of modules configured to carry out the steps of retrieving a decryption key from a predetermined location on the device selected for authentication, decrypting an authentication signal using the decryption key, and communicating the decrypted authentication signal to a user. In the described embodiments, these modules include a retrieval module, a decryption module, and a communication module. Beneficially, such an apparatus, system, and method would reliably verify that a link in the CRTM chain has not been corrupted, modified, or infected with a computer virus. Specifically, such an apparatus, system, and method would enable verification that the hypervisor has not been corrupted, modified, or infected with a computer virus.