Dynamic Hardware BOM Verification for Computing Device Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for ensuring the integrity of computing devices throughout the supply chain are inadequate, as they either focus on software components or require static data that can be tampered with, lacking robust verification of hardware components.
Innovation Solution
A method involving a trusted application that measures hardware component identifiers and generates a dynamic bill of materials within a secure environment, comparing it to a predefined static bill to verify the integrity of hardware components before booting the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static bill of materials is used for verification, then verification simplicity is improved, but security against tampering deteriorates
Solution Approach 1:
The patent transitions from static bill of materials to dynamic bill of materials that are automatically generated and updated. The dynamic BOMs are created by executing a trusted application that reads component identifiers directly from hardware, ensuring they reflect the actual current state of the device and cannot be tampered with statically.
Solution Approach 2:
The patent introduces a trusted application as an intermediary between the hardware components and the verification process. This trusted application executes in a secure environment, reads component identifiers, generates the dynamic BOM, and performs verification, thereby mediating between the physical hardware and the verification system while ensuring integrity.
2Reliability
If trusted application in secure environment is used, then hardware verification reliability is improved, but system complexity deteriorates
Solution Approach 1:
The trusted application performs multiple functions: it reads identifiers from hardware components, generates the dynamic bill of materials, verifies component integrity, and controls the boot process. By consolidating these functions into a single trusted application executing in a secure environment, the system achieves high verification reliability without proportionally increasing complexity.
Solution Approach 2:
The trusted application executes before the operating system boots, performing verification of hardware components in advance. This preliminary action ensures that the boot process only proceeds if hardware integrity is confirmed, preventing malicious hardware from executing system software while maintaining a relatively simple overall system architecture.
Data Source
Figure 1~3
Figure 4~5
Figure 6~7
AI summary
The invention relates to a method of verifying integrity of a computing device (1) comprising a number of hardware device components (1), the method comprising the steps of: a) measuring (S1) a number of identifiers (30) of each of the hardware device components (10); and b) generating (S2) a dynamic bill of materials (3) from the number of measured identifiers (30), wherein steps a) and b) are performed by executing an application (21) comprised in a trusted code base (121) of the computing device (1). The dynamic bill of materials generated by the application that is part of the trusted code base allows to verify the integrity of the hardware device components of the computing device in a trusted manner.