Cryptoprocessor Control Register Pre-calculation for Secure Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During the installation of a secure operating system, there is a challenge in storing a disk encryption key using a PCR 7 value that does not exist for the current system boot, especially when there is only one boot cycle for installation.

Innovation Solution

A method is implemented during the installation of an operating system, where mock measurements for configuration registers of a cryptoprocessor are performed based on values that will exist after installation. These mock measurements are extended into mock configuration registers, and an encryption key is stored such that it is accessible during subsequent boot sessions if the configuration register values match the firmware measurements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Secure Boot values are cleared and custom values are installed before operating system installation, then the system can boot securely with vendor-approved software, but the PCR 7 measurement value changes between installation time and subsequent boot sessions, preventing encryption key accessibility

Engineering Contradiction:
Improvesecure boot integrityVSAvoidencryption key accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by calculating and storing the future PCR 7 measurement value (after Secure Boot values are installed) before the actual installation occurs. The installation agent pre-computes what the PCR 7 hash will be after Secure Boot values are set, and uses this pre-calculated value to store the encryption key in the TPM. This allows the encryption key to be accessible during subsequent boot sessions when the actual PCR 7 matches the pre-stored value, resolving the contradiction between maintaining secure boot integrity and ensuring encryption key accessibility.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If only one boot cycle is available for operating system installation, then installation can be completed quickly, but there is no opportunity to update Secure Boot keys separately, requiring both key update and installation to occur simultaneously

Engineering Contradiction:
Improveinstallation speedVSAvoidinstallation process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent enables single-boot installation by performing preliminary calculation of the PCR 7 value that will exist after Secure Boot values are installed. The installation agent computes the future hash value in advance, allowing the encryption key to be stored with the correct reference value during the same boot cycle when installation occurs. This eliminates the need for a separate boot cycle to update Secure Boot keys, maintaining high productivity while managing complexity through automated pre-calculation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If custom Secure Boot values are installed to restrict booting to vendor-approved software, then system security is improved, but the PCR 7 measurement value becomes different from default values, creating a mismatch for encryption key storage

Engineering Contradiction:
Improveboot securityVSAvoidmeasurement value consistency
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent resolves the measurement value inconsistency by applying preliminary action - the installation agent calculates the PCR 7 hash value that will result from installing custom Secure Boot values, before the installation actually occurs. This pre-calculated future value is then used to store the encryption key in the TPM. When the system subsequently boots with the installed Secure Boot values, the actual PCR 7 measurement matches the pre-stored value, ensuring both boot security through custom values and measurement consistency for encryption key access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12277229B2Pre-calculation of cryptoprocessor control register
Publication Date: 2025.04.15 EVERFOX HOLDINGS LLC
  • US12277229B2 patent drawing
  • US12277229B2 patent drawing

AI summary

A computer-implementable method may include, during execution of an installation image for installing an operating system on an information handling system performing mock measurements for one or more configuration registers of a cryptoprocessor of the information handling system based on values for the one or more configuration registers that will exist for a boot session of the information handling system immediately following installation of the operating system, extending the mock measurements into the one or more mock configuration registers, and storing an encryption key to the cryptoprocessor such that the encryption key is accessible to a subsequent boot session of the information handling system if the contents of the one or more configuration registers are equal to measurements performed by firmware of the information handling system during the subsequent boot session.