Mobile Trusted Core PC Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Publicly accessible computers lack the security measures found in corporate environments, posing risks of data loss, malware transmission, and application incompatibility for traveling users, which can compromise both user productivity and enterprise network security.
Innovation Solution
A mobile device with a configured CPU and OS acts as an immutable trusted core to verify the integrity of a PC, ensuring only unmodified trusted code is executed, and can store user personalization data to create a secure and personalized computing platform, even when connected to publicly accessible PCs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a mobile device with trusted core is combined with a PC, then security and integrity verification are improved, but device complexity increases
Solution Approach 1:
The system separates security functions (integrity verification, trusted execution) into a dedicated mobile device trusted core, while the PC handles general computing tasks. This segmentation allows the PC to remain relatively simple while security concerns are isolated to the specialized mobile device component.
Solution Approach 2:
The mobile device acts as an intermediary between the user and the PC, verifying the PC's integrity before allowing access. This intermediary role enables security enhancement without requiring complex changes to the PC itself, as the mobile device mediates the trust relationship.
2Object-affected harmful factors
If integrity verification of PC is performed, then protection against malware is improved, but time to access computing resources increases
Solution Approach 1:
The integrity verification is performed in advance before the user accesses the PC. The trusted core checks the PC's integrity state beforehand, so that once verified, the user can access computing resources without repeated verification delays. This preliminary action reduces subsequent access time while maintaining malware protection.
Solution Approach 2:
The system replaces traditional mechanical security checks (scanning, quarantine procedures) with a trust-based verification mechanism. The trusted core uses cryptographic verification of integrity measurements, which is computationally efficient and does not require time-consuming scanning or isolation procedures, thus reducing access time while maintaining protection.
3Loss of information
If user personalization data is stored on mobile device, then data privacy is improved, but data transfer and access complexity increases
Solution Approach 1:
User personalization data is extracted from the PC and stored on the mobile device, which the user controls. This extraction improves data privacy by removing sensitive information from potentially compromised public PCs. The mobile device becomes the secure repository, simplifying the data management model by centralizing control in one device.
Solution Approach 2:
The mobile device serves multiple functions: it acts as a security token for verification, a secure storage device for personalization data, and a portable identity manager. This multi-functionality consolidates data management operations into a single device, reducing overall system complexity despite the added capabilities.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A mobile device (105), such as a mobile phone, smart phone, personal music player, handheld game device, and the like, when operatively combined with a PC (110), creates a secure and personalized computing platform (100) through configuration of the mobile device's CPU (central processing unit) (312) and OS (operating system) (316) to function as an immutable trusted core (205). The trusted core (205) in the mobile device (105) verifies the integrity of the PC (110) including, for example, that its drivers, applications, and other software are trusted and unmodified, and thus safe to use without presenting a threat to the integrity of the combined computing platform. The mobile device (105) can further optionally store and transport the user's personalization data (616) - including, for example, the user's desktop, applications, data, certificates, settings, and preferences which can be accessed by the PC (110) when the devices are combined to thus create a personalized computing environment.