Reducing Trusted Computing Base via Dynamic Application Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of computer security issues due to diverse applications necessitates a reduction in the trusted computing base (TCB) to prevent security vulnerabilities, as bugs within the TCB can jeopardize the entire system's security.

Innovation Solution

A processor-measured application protection service (P-MAPS) is dynamically instantiated to measure and protect applications, reducing the TCB by isolating memory regions and providing protection through a measured launch environment, thereby enabling secure execution of trusted applications with a smaller TCB.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the trusted computing base (TCB) is reduced to improve security, then system security is improved, but the complexity of ensuring security for fewer critical components increases

Engineering Contradiction:
Improvesystem securityVSAvoidTCB management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the TCB into two distinct parts: a minimal static TCB containing only essential security components, and a dynamic measured environment that can be verified. This segmentation allows the system to maintain a small, manageable core TCB while still providing comprehensive security through measurement and verification of the broader execution environment.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If a minimal TCB is used to reduce attack surface, then security vulnerability risk is reduced, but the capability to provide comprehensive security services is limited

Engineering Contradiction:
Improvesecurity vulnerability riskVSAvoidsecurity service capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent introduces measurement and verification mechanisms as intermediaries between the minimal TCB and the untrusted execution environment. These intermediaries enable the small TCB to securely manage and verify a larger measured environment, effectively extending security service capabilities without increasing the core TCB size or vulnerability exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8776245B2Executing trusted applications with reduced trusted computing base
Publication Date: 2014.07.08 INTEL CORP
  • US8776245B2 patent drawing
  • US8776245B2 patent drawing
  • US8776245B2 patent drawing

AI summary

A system for executing trusted applications with a reduced trusted computing base. In one embodiment, the system includes a processor to dynamically instantiate an application protection module in response to a request by a program to be executed under a trusted mode. The system further includes memory to store the program which is capable of interacting with a remote service for security verification. In one embodiment, the application protection module includes a processor-measured application protection service (P-MAPS) operable to measure and to provide protection to the application.