Attesting Interactive Component Use During Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The trusted boot process is compromised in advanced computing systems with interactive components, as these components can be vulnerable to malicious attacks, making it difficult to determine whether actions performed during their use are trusted.

Innovation Solution

A method and apparatus for attesting the use of an interactive component during the boot process by recording user interactions using a special Platform Configuration Register (PCR) and determining whether the input is trusted, allowing for the creation of a trusted cryptographic value and subsequent matching with trusted values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an interactive component is used during boot process, then system flexibility and administrative capability are improved, but security and trustworthiness of the boot process deteriorate

Engineering Contradiction:
Improvesystem flexibilityVSAvoidboot process trustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the boot process into measured portions and unmeasured portions. The measured boot process includes components that are cryptographically verified, while the unmeasured portion accommodates interactive components. This segmentation allows the system to maintain trustworthiness for critical functions while permitting flexibility in interactive sections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a measurement of a measurement (MoM) as an intermediary mechanism. The interactive component generates a measurement of its execution, which is then measured by a trusted component and stored in a PCR. This MoM acts as a mediator that provides cryptographic evidence of interactive component behavior without requiring the interactive component itself to be fully trusted.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If interactive component is allowed to execute arbitrary code, then administrative capability is improved, but vulnerability to malicious attacks increases

Engineering Contradiction:
Improveadministrative capabilityVSAvoidmalicious attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the interactive component's execution is continuously measured and reported to a trusted component. The measurement of the interactive component's state is fed back into the trusted boot process through the MoM, allowing the system to verify and respond to the interactive component's actions in real-time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary measurements of the interactive component before full execution. The interactive component's code and initial state are measured and stored in PCRs before execution begins. This preliminary action establishes a baseline of trust that can be verified throughout the execution process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9342696B2Attesting use of an interactive component during a boot process
Publication Date: 2016.05.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9342696B2 patent drawing
  • US9342696B2 patent drawing
  • US9342696B2 patent drawing

AI summary

A method for attesting use of an interactive component during a boot process, comprising the steps of: reading, in response to determining use of the interactive component, associated interactive input; determining whether the input should be trusted; and in response to determining that the input should be trusted, processing the input to create a trusted cryptographic value, further comprising: matching, in response to a subsequent interactive input being read, the subsequent interactive input with one or more of the trusted cryptographic values in order to determine whether the subsequent interactive input is trusted.