Mobile Trusted Module PCR Resetting for Dynamic Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile trusted module (MTM) technologies lack efficient mechanisms for resetting platform configuration registers (PCRs), which is essential for dynamic attestation and managing system state, particularly in non-persistent applications and network services, leading to complexities and inefficiencies in tracking application launches and terminations.

Innovation Solution

The implementation of a method and apparatus that define a subset of non-resettable and resettable PCRs, using the TPM_RESET_PCR command, with additional commands like MTM_setResettablePCRs and MTM_resetPCR, to dynamically manage PCR resetting, allowing for fine-grained control through RIM certificates and verification keys, ensuring secure and efficient attestation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all platform configuration registers are made resettable to enable dynamic attestation, then the flexibility and efficiency of tracking application states improve, but the security and integrity protection of system state information deteriorates

Engineering Contradiction:
Improveflexibility of dynamic attestationVSAvoidintegrity protection of system state
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the platform configuration registers into two distinct subsets: resettable PCRs and non-resettable PCRs. Resettable PCRs can be dynamically reset to enable flexible attestation for applications and services, while non-resettable PCRs maintain persistent system state information that cannot be altered. This segmentation allows the system to simultaneously achieve both flexibility in dynamic attestation and reliability in system state integrity protection.

Inventive Principle:
Principle #1Segmentation

2Productivity

If platform configuration registers are reset dynamically to support non-persistent applications, then the efficiency of attestation processes improves, but the complexity of managing different PCR subsets increases

Engineering Contradiction:
Improveefficiency of attestation processesVSAvoidcomplexity of managing PCR subsets
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different properties to different subsets of PCRs. Each PCR is tagged with an attribute indicating whether it belongs to the resettable or non-resettable subset. This allows the system to manage complexity through localized properties rather than global rules, enabling efficient dynamic attestation for specific applications while maintaining clear distinctions between resettable and persistent state registers.

Inventive Principle:
Principle #3Local quality

3Reliability

If a subset of non-resettable PCRs is maintained to protect system state, then the security and reliability improve, but the adaptability for dynamic attestation in network services deteriorates

Engineering Contradiction:
Improvesecurity of system stateVSAvoidadaptability for dynamic attestation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments PCRs into resettable and non-resettable subsets, allowing network services to utilize resettable PCRs for dynamic attestation needs while system state information is protected in non-resettable PCRs. This segmentation enables both security preservation and adaptability for dynamic services to coexist by providing dedicated register subsets for each purpose.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic control over PCR resetting through commands that can selectively reset specific PCRs based on service requirements. The system can dynamically determine which resettable PCRs to reset for each attestation request, providing adaptability for various network services while maintaining the protective barrier of non-resettable PCRs for critical system state.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9087198B2Method and apparatus to reset platform configuration register in mobile trusted module
Publication Date: 2015.07.21 NOKIA TECHNOLOGIES OY
  • US9087198B2 patent drawing
  • US9087198B2 patent drawing
  • US9087198B2 patent drawing

AI summary

In accordance with the exemplary embodiments of the invention there is at least a method, apparatus, and executable program of computer instructions to perform the operations of establishing and initializing a set of platform configuration registers, where a first subset of platform configuration registers is defined as being non-resettable, and a second subset of platform configuration registers is defined as being resettable, storing initial boot-up system state information in one or more non-resettable platform configuration registers, dynamically resetting (2) a value of a platform configuration register identified by a reference integrity metric to reflect a measurement value provided by the reference integrity metric, and responding to an attestation request (0) with an attestation response (5) including dynamic information from the platform configuration register that was reset and system state information from a non-resettable platform configuration register.