Hardware Signal Control for Software Trust Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The open-source model in mobile phones exposes critical interfaces, increasing the risk of misuse by hackers, which can harm the device, network, and users, and poses licensing issues due to the lack of secure software verification.
Innovation Solution
A method and apparatus that verify the trustworthiness of software by using a hardware signal switched into a first state when untrusted software is detected, disabling processing components and interfaces, and employing digital fingerprints compared to reference integrity fingerprints, ensuring only certified software operates, using a Trusted Computing Group (TCG) standard-based trusted platform module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If open-source software is used in mobile phones, then software adaptability and community improvement are enhanced, but security and interface protection are worsened due to lack of verification
Solution Approach 1:
The patent implements preliminary verification of software trustworthiness before allowing execution. A hardware processing component verifies the software stack against reference integrity fingerprints stored in non-volatile memory, and only permits software execution if verification succeeds. This preliminary action prevents untrusted software from running while still allowing open-source software to be used.
Solution Approach 2:
The patent introduces a hardware processing component as an intermediary between the software stack and the system interfaces. This intermediary verifies software trustworthiness and controls access to interfaces based on verification results, mediating between the need for software flexibility and security requirements.
2Ease of manufacture
If debugging and inspection tools are made available, then software development and improvement are facilitated, but interface security is worsened due to potential exposure of critical APIs
Solution Approach 1:
The patent implements dynamic control of interface accessibility based on software verification status. When software is verified as trustworthy, interfaces are accessible for debugging and development purposes. When verification fails or is bypassed, interfaces are disabled or restricted. This dynamic approach allows flexible software development while preventing misuse by untrusted software.
3Reliability
If software verification is implemented, then interface protection and security are improved, but device complexity increases due to additional hardware components
Solution Approach 1:
The hardware processing component performs multiple functions: it verifies software trustworthiness, stores reference integrity fingerprints, controls interface accessibility, and manages the hardware signal states. By consolidating these security-related functions into a single multi-functional component, the patent reduces overall device complexity while maintaining comprehensive security.
4Adaptability or versatility
If untrusted software is allowed to operate, then software flexibility is maintained, but harm to network and users increases due to potential misuse of interfaces
Solution Approach 1:
The patent applies preliminary anti-action by preventing untrusted software from accessing critical interfaces before harm can occur. The verification mechanism identifies potentially harmful software in advance, and the hardware signal control prevents such software from manipulating interfaces that could cause network or user harm, thereby counteracting potential damage before it happens.
Data Source
Figure 1a
Figure 1b
Figure 2a~2b
AI summary
A method, an apparatus and a computer program product are disclosed for verifying the trustworthiness of a software in an apparatus, and switching a hardware signal in the apparatus into a first state when the software is not trustworthy.