Runtime Monitoring via Hash-Locked Remote Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Trusted devices or systems incorporating commercial off-the-shelf components may be compromised by untrusted third-party hardware or software modules, leading to malicious operations and data exfiltration due to potential malware or trojans.
Innovation Solution
A runtime monitoring system utilizing trusted processors with primary and auxiliary oscillators to generate and correlate hashes, ensuring continuous real-time attestation of remote processing components by seeding op codes with unique challenges and comparing attestation responses to maintain alignment and detect unintended behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If commercial off-the-shelf components are used in trusted devices, then device complexity and cost are reduced, but system reliability and security are compromised due to potential malware or trojans in third-party components
Solution Approach 1:
The patent implements continuous feedback loops where remote attestation responses are constantly monitored and compared against expected values. The system provides real-time feedback about the trust status of remote components, enabling dynamic adjustment of system behavior based on current security conditions rather than static pre-attestation checks
Solution Approach 2:
The patent introduces an intermediary attestation mechanism that mediates between untrusted remote components and the trusted system. This intermediary layer verifies the integrity of remote components through cryptographic proof and challenge-response protocols, allowing COTS components to be used while maintaining security through the mediating verification layer
2Reliability
If continuous runtime monitoring is implemented to detect malicious operations, then system security is improved, but processing overhead and system performance are degraded
Solution Approach 1:
The patent employs periodic challenge-response attestation cycles rather than continuous monitoring. The trusted system periodically issues challenges to remote components and verifies responses at scheduled intervals, providing security assurance without requiring constant verification of every operation, thus reducing processing overhead while maintaining security
Solution Approach 2:
The patent performs preliminary attestation verification by pre-computing expected attestation responses and comparing them against actual responses received from remote components. This preliminary comparison approach allows for efficient detection of tampering before malicious operations can execute, reducing the need for extensive continuous monitoring
Data Source
AI summary
A runtime monitoring system for a trusted computing environment is disclosed. In embodiments, the environment includes a trusted processor driven by a primary oscillator and a remote processing component driven by an auxiliary oscillator. A trusted reference hashing module hashes operating codes sent by the trusted processor for execution by the remote processing component; the received operating codes are also hashed by a trusted remote hashing module monitoring the remote processing component. A correlation module matches the remote and reference hashes and advances or delays the auxiliary oscillator to loop-lock the remote processing component to the trusted processor. The trusted processor periodically seeds the operating codes with a unique challenge having a unique hash response. The hash response received from the remote hashing module is checked against the reference hash response generated by the reference hashing module to verify that the remote processing component remains trusted and uncompromised.


