Security Coprocessor PCR Segmentation for Concurrent Update Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems face challenges in securely handling concurrent updates, as they often fail to maintain the integrity of boot sequences and firmware updates, leading to issues with remote and local attestation, especially when updates change Platform Configuration Registers (PCRs) values, which can result in compromised security and failed authentication.
Innovation Solution
The method involves using separate sets of Platform Configuration Registers (PCRs) to store and extend measurements of the boot sequence, configuration parameters, and concurrent updates, allowing for local and remote attestation by measuring initial code loads into one set and subsequent updates into different sets, ensuring secure authentication and integrity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate sets of PCRs are used to store measurements of boot sequence, configuration parameters, and concurrent updates, then security and attestation reliability are improved, but device complexity increases
Solution Approach 1:
The patent divides the measurement storage into three separate sets of PCRs: first set for boot sequence measurements, second set for configuration parameter measurements, and third set for concurrent update measurements. This segmentation allows each PCR set to independently track specific system states, enabling reliable attestation without compromising system security while managing complexity through structured organization.
2Reliability
If measurements of concurrent updates are stored in separate PCRs, then integrity verification is improved, but measurement precision requirements increase
Solution Approach 1:
By segmenting measurement storage into dedicated PCR sets, each set can maintain its own measurement chain with appropriate precision requirements. The first set captures boot sequence integrity, the second set captures configuration parameters, and the third set captures concurrent updates, allowing each to be verified independently with tailored precision levels.
Solution Approach 2:
Each PCR set is assigned specific measurement responsibilities with localized quality requirements. The boot sequence PCRs require high precision for firmware integrity, configuration PCRs require precision for parameter validation, and update PCRs require precision for change tracking. This local quality approach optimizes measurement precision for each specific function rather than requiring uniform high precision across all measurements.
Data Source
AI summary
According to one or more embodiments of the present invention, an example computer-implemented method for measuring concurrent updates in a security coprocessor includes using a first set of platform configuration registers of the security coprocessor to store and extend measurement of a code-load used during a boot sequence of a computing device. The method further includes using a second set of platform configuration registers of the security coprocessor to store and extend measurement of configuration parameters of the code-load used during the boot sequence. The method further includes using a third set of platform configuration registers of the security coprocessor to store and extend measurements of a concurrent update that changes the code-load that was used during the boot sequence.


