Dual TPM Root of Trust for Virtualized Mobile Personas
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication devices with virtualized operating systems are susceptible to security vulnerabilities due to the underlying platform's lack of enhanced security measures, necessitating improved security in device virtualization architectures.
Innovation Solution
The implementation of a mobile communication device with a first and second trusted platform module, along with a processor and storage medium, establishes a root of trust for each persona, including an operating system and trusted execution environment, and stores measurements defining this root of trust in their respective modules, enabling secure operation and secure boot processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If device virtualization is implemented to run multiple operating systems on one device, then device functionality and versatility are improved, but security vulnerabilities increase due to the underlying platform's lack of enhanced security measures
Solution Approach 1:
The system segments the virtualization architecture by introducing separate trusted execution environments (TEE) for each persona/operating system. Each TEE is isolated and protected by its own root of trust, preventing security compromises from affecting other personas. This segmentation resolves the contradiction by maintaining versatility through multiple OSes while improving security through isolation.
Solution Approach 2:
A hypervisor acts as an intermediary layer between the hardware platform and multiple operating systems, managing I/O access operations and facilitating separation. The hypervisor enables secure coexistence of multiple personas by mediating their access to shared hardware resources, thus maintaining both versatility and security.
2Productivity
If multiple virtualized operating systems are run simultaneously on a single device, then system utilization and productivity are improved, but the complexity of managing security for each persona increases
Solution Approach 1:
Each persona is assigned a dedicated trusted execution environment with its own root of trust stored in separate trusted platform modules. This segmentation automates security management by providing isolated, pre-configured security boundaries for each persona, reducing the complexity of managing security across multiple virtualized systems while maintaining high system utilization.
3Reliability
If security measures are enhanced in the virtualization architecture by implementing separate trusted execution environments for each persona, then security and reliability are improved, but device complexity and resource requirements increase
Solution Approach 1:
The hypervisor provides universal functionality by managing I/O access operations for all personas simultaneously. This multi-functional approach consolidates security management tasks into a single component that handles multiple personas, improving security while minimizing the increase in overall architectural complexity through resource sharing.
Solution Approach 2:
Roots of trust are established and measurements are stored in trusted platform modules before personas are loaded and executed. This preliminary security configuration ensures that security boundaries are pre-defined and enforced from the start of each persona's execution, improving reliability while keeping the architecture manageable through automated security setup.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A mobile communication device is provided. The mobile communication device includes a first trusted platform module, a second trusted platform module, a processor, and a storage medium. The storage medium includes instructions that cause the processor to establish a root of trust for a first persona and a second persona, wherein the first persona includes a first operating system and a first trusted execution environment, and the second persona includes a second operating system and a second trusted execution environment. The instructions also cause the processor to store measurements defining the root of trust for the first persona in the first trusted platform module, store measurements defining the root of trust for the second persona in the second trusted platform module, and load the first persona and the second persona using the roots of trust for the first and second personas.