Dual TPM Root of Trust for Virtualized Mobile Personas

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices with virtualized operating systems are susceptible to security vulnerabilities due to the underlying platform's lack of enhanced security measures, necessitating improved security in device virtualization architectures.

Innovation Solution

The implementation of a mobile communication device with a first and second trusted platform module, along with a processor and storage medium, establishes a root of trust for each persona, including an operating system and trusted execution environment, and stores measurements defining this root of trust in their respective modules, enabling secure operation and secure boot processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If device virtualization is implemented to run multiple operating systems on one device, then device functionality and versatility are improved, but security vulnerabilities increase due to the underlying platform's lack of enhanced security measures

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the virtualization architecture by introducing separate trusted execution environments (TEE) for each persona/operating system. Each TEE is isolated and protected by its own root of trust, preventing security compromises from affecting other personas. This segmentation resolves the contradiction by maintaining versatility through multiple OSes while improving security through isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hypervisor acts as an intermediary layer between the hardware platform and multiple operating systems, managing I/O access operations and facilitating separation. The hypervisor enables secure coexistence of multiple personas by mediating their access to shared hardware resources, thus maintaining both versatility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple virtualized operating systems are run simultaneously on a single device, then system utilization and productivity are improved, but the complexity of managing security for each persona increases

Engineering Contradiction:
Improvesystem utilizationVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Each persona is assigned a dedicated trusted execution environment with its own root of trust stored in separate trusted platform modules. This segmentation automates security management by providing isolated, pre-configured security boundaries for each persona, reducing the complexity of managing security across multiple virtualized systems while maintaining high system utilization.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security measures are enhanced in the virtualization architecture by implementing separate trusted execution environments for each persona, then security and reliability are improved, but device complexity and resource requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hypervisor provides universal functionality by managing I/O access operations for all personas simultaneously. This multi-functional approach consolidates security management tasks into a single component that handles multiple personas, improving security while minimizing the increase in overall architectural complexity through resource sharing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Roots of trust are established and measurements are stored in trusted platform modules before personas are loaded and executed. This preliminary security configuration ensures that security boundaries are pre-defined and enforced from the start of each persona's execution, improving reliability while keeping the architecture manageable through automated security setup.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3044674B1Mobile communication device and method of operating thereof
Publication Date: 2021.09.29 THE BOEING CO
  • EP3044674B1 patent drawingFigure 1~2
  • EP3044674B1 patent drawingFigure 3
  • EP3044674B1 patent drawingFigure 4

AI summary

A mobile communication device is provided. The mobile communication device includes a first trusted platform module, a second trusted platform module, a processor, and a storage medium. The storage medium includes instructions that cause the processor to establish a root of trust for a first persona and a second persona, wherein the first persona includes a first operating system and a first trusted execution environment, and the second persona includes a second operating system and a second trusted execution environment. The instructions also cause the processor to store measurements defining the root of trust for the first persona in the first trusted platform module, store measurements defining the root of trust for the second persona in the second trusted platform module, and load the first persona and the second persona using the roots of trust for the first and second personas.