Peripheral Trust Verification Device for Computing Platform Root of Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current dynamic root of trust measurement (DRTM) technologies face limitations in establishing end-to-end trust across networks of computing platforms, including susceptibility to malware, hardware modification requirements, and inability to measure software integrity effectively, especially in legacy systems and embedded devices.
Innovation Solution
A hardware-enabled trust enabling device employing a software-based DRTM protocol that assesses trustworthiness by issuing challenges to computing platforms, measuring response times, and using sealed storage to verify the existence of a trusted execution environment, allowing for secure data unsealing and service enablement or disablement based on trustworthiness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based DRTM is used to establish root of trust, then trust verification reliability is improved, but device complexity and hardware modification requirements increase
Solution Approach 1:
The patent introduces a peripheral trust verification device as an intermediary component that mediates between the computing platform and the trust verification process. This external device contains the root of trust and performs challenge-response authentication, eliminating the need to modify the computing platform's hardware while maintaining reliable trust verification. The intermediary device seals data based on verification results without requiring changes to the target system.
Solution Approach 2:
The trust verification system is segmented into separate functional components: the computing platform being verified, the peripheral verification device containing the root of trust, and the sealed storage facility. This segmentation allows the trust verification functionality to be isolated in a dedicated device rather than embedded in the computing platform, reducing device complexity and modification requirements while preserving reliability.
2Ease of operation
If software-based DRTM protocol is used to assess trustworthiness, then ease of operation and compatibility are improved, but measurement precision and security against malware decrease
Solution Approach 1:
The peripheral trust verification device acts as an intermediary that bridges software-based challenge-response protocols with hardware-based trust anchoring. The software protocol provides ease of operation and compatibility, while the hardware root of trust in the peripheral device ensures measurement precision and security against malware. This combination allows legacy systems to be verified without modification while maintaining high security standards.
Solution Approach 2:
The system combines software-based DRTM protocols with hardware-based root of trust in a composite architecture. The software layer provides compatibility and ease of operation with legacy systems, while the hardware component ensures measurement precision and resistance to malware. This composite approach integrates the advantages of both software and hardware solutions while mitigating their individual weaknesses.
3Reliability
If sealed storage facility is used to store sensitive data, then security and protection are improved, but data access speed and productivity decrease
Solution Approach 1:
The system performs preliminary trust verification through challenge-response authentication before sealing or unsealing data. The root of trust in the peripheral device pre-evaluates the computing platform's trustworthiness, and only then does the sealed storage facility grant access. This preliminary action ensures security while enabling fast data access once trust is established, as subsequent access operations can proceed without repeated verification overhead.
Solution Approach 2:
The sealed storage facility dynamically adjusts its access control state based on the trust verification results. When the computing platform is verified as trustworthy, the storage facility transitions from a sealed (restricted) state to an unsealed (accessible) state. This dynamic behavior maintains high security when needed while enabling high-speed data access during legitimate operations, optimizing both security and productivity based on real-time trust assessment.
Data Source
AI summary
Verification of trustworthiness of a computing platform is provided. The trustworthiness of the computing platform is dynamically assessed to determine whether a root of trust exists on the computing platform. Responsive to determining existence of the root of trust, data is unsealed from a sealed storage facility. The sealed storage facility is unsealed responsive to a root of trust being determined to exist on the computing platform. The data can be used to attest to the trustworthiness of the computing platform to other device on a network.


