Hardware Trust Evaluation Device for Software Integrity Indication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for conveying software integrity validation results on computing devices are vulnerable to imitation by malicious code, making it difficult for users to trust the trustworthiness of executing program code.

Innovation Solution

A hardware trust evaluation device, such as a Trusted Platform Module (TPM), is integrated with a trust indicator like an LED, which provides a resilient indication of software integrity by validating program code and restricting or enabling device functionality based on trustworthiness, minimizing the risk of imitation attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional on-screen methods are used to convey validation results, then user interface simplicity is maintained, but the indication becomes vulnerable to imitation by malicious code

Engineering Contradiction:
Improvetrustworthiness of integrity indicationVSAvoidhardware trust evaluation device
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A hardware trust evaluation device (such as a TPM) is introduced as an intermediary component that independently validates program code and generates integrity indicators. This mediator separates the validation function from the display system, ensuring that the trust indication cannot be forged by malicious software running on the main processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based on-screen validation displays with hardware-based physical indicators (such as LEDs). This substitution moves the trust indication from the vulnerable software domain to the more secure hardware domain, making it resistant to imitation attacks while maintaining user visibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a hardware trust evaluation device is integrated with a physical trust indicator, then resistance to imitation attacks is improved, but device complexity increases

Engineering Contradiction:
Improveresistance to imitation attacksVSAvoidhardware trust evaluation device
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation logic and trust indication function are extracted into a separate hardware trust evaluation device (such as a TPM chip). This extraction isolates the critical security function from the main system, allowing it to operate independently and provide unforgeable validation without compromising the overall system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware trust evaluation device is designed to perform multiple functions including code validation, key storage, and generation of trust indicators. By consolidating these functions into a single hardware component, the patent achieves high security without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10354075B1Trustworthy indication of software integrity
Publication Date: 2019.07.16 AMAZON TECH INC
  • US10354075B1 patent drawing
  • US10354075B1 patent drawing
  • US10354075B1 patent drawing

AI summary

Computing devices are disclosed that include functionality for providing a trustworthy indication of software integrity. The computing devices include a hardware trust evaluation device capable of determining the trustworthiness of computer programs executing on the devices. At least one trust indicator is also connected to the hardware trust evaluation device for providing an external indication of the trustworthiness of a computer program. Additional security information regarding the trustworthiness of the computer program may be displayed on the primary display device of the computing device. The display of the security information is triggered by a user of the computing device submitting a request through a secure mechanism, where the request is unobservable and inaccessible to programs executing on the computing device. Additional secure mechanisms, such as a unique user interface for displaying the security information, can be utilized to ensure the authenticity of the displayed security information.