Endpoint Image Signing with Segmented Trust Database Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint device security systems face brittleness issues when updating software, as comprehensive verification of trust databases impacts the use of security secrets, leading to compromised operations or inability to execute updated software.
Innovation Solution
Implement a security model where a trust database is divided into verified and unverified portions, allowing attested image entries to be added without impacting security processor secrets, ensuring trustworthy software execution and secure updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive verification of trust database is performed, then security reliability is improved, but software update capability deteriorates
Solution Approach 1:
The trust database is segmented into two distinct portions: a first portion containing verified entries that must be validated for security secrets to function, and a second portion containing unverified entries that can be added without impacting security processor operations. This segmentation allows the system to maintain security reliability through verification of critical entries while enabling software updates through addition of unverified entries.
Solution Approach 2:
Different portions of the trust database are assigned different verification requirements. The first portion requires comprehensive verification to ensure security secrets can be used, while the second portion allows unverified entries to be added. This local differentiation of quality requirements resolves the contradiction by applying strict verification only where necessary for security while permitting flexibility elsewhere for updates.
2Reliability
If trust database entries are verified, then security posture is maintained, but operational flexibility deteriorates
Solution Approach 1:
The trust database is divided into verified and unverified portions, allowing the system to maintain security posture through verification of the first portion while gaining operational flexibility by adding unverified entries to the second portion without requiring re-verification or impacting security secret usage.
Solution Approach 2:
Instead of verifying all trust database entries, the system performs partial verification only on the first portion containing critical security-related entries. This partial action approach maintains adequate security posture while avoiding the operational overhead of verifying every entry, thus preserving operational flexibility.
3Reliability
If security secrets are protected, then security reliability is improved, but software execution capability deteriorates
Solution Approach 1:
The trust database is segmented such that the first portion contains verified entries necessary for security secret protection, while the second portion contains unverified entries that can be added to enable new software execution. This segmentation allows security secrets to be protected through verification of critical entries while enabling software execution capability through addition of unverified entries.
Solution Approach 2:
The system performs preliminary verification of the first portion of the trust database during initialization, establishing security posture in advance. This preliminary action allows security secrets to be protected from the outset while leaving the second portion open for future software execution needs without requiring additional verification steps.
Data Source
AI summary
Methods and systems for securing endpoint devices are disclosed. Overtime, the functionality of endpoint devices may be modified as new software is developed. To secure endpoint devices, software images of the new software may be verified prior to execution. Information usable to verify the software images may be stored in a database. A set of rules may be used to verify the trustworthiness of the software images based on the content of the database. Another set of rules may be used to verify the content of the database.


