Peripheral Trust Verification Device for Computing Platform Root of Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dynamic root of trust measurement (DRTM) technologies face limitations in establishing end-to-end trust across networks of computing platforms, including susceptibility to malware, hardware modification requirements, and inability to measure software integrity effectively, especially in legacy systems and embedded devices.

Innovation Solution

A hardware-enabled trust enabling device employing a software-based DRTM protocol that assesses trustworthiness by issuing challenges to computing platforms, measuring response times, and using sealed storage to verify the existence of a trusted execution environment, allowing for secure data unsealing and service enablement or disablement based on trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based DRTM is used to establish root of trust, then trust verification reliability is improved, but device complexity and hardware modification requirements increase

Engineering Contradiction:
Improvetrust verification reliabilityVSAvoidhardware modification requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a peripheral trust verification device as an intermediary component that mediates between the computing platform and the trust verification process. This external device contains the root of trust and performs challenge-response authentication, eliminating the need to modify the computing platform's hardware while maintaining reliable trust verification. The intermediary device seals data based on verification results without requiring changes to the target system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trust verification system is segmented into separate functional components: the computing platform being verified, the peripheral verification device containing the root of trust, and the sealed storage facility. This segmentation allows the trust verification functionality to be isolated in a dedicated device rather than embedded in the computing platform, reducing device complexity and modification requirements while preserving reliability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If software-based DRTM protocol is used to assess trustworthiness, then ease of operation and compatibility are improved, but measurement precision and security against malware decrease

Engineering Contradiction:
Improvecompatibility with legacy systemsVSAvoidsoftware integrity measurement accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The peripheral trust verification device acts as an intermediary that bridges software-based challenge-response protocols with hardware-based trust anchoring. The software protocol provides ease of operation and compatibility, while the hardware root of trust in the peripheral device ensures measurement precision and security against malware. This combination allows legacy systems to be verified without modification while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system combines software-based DRTM protocols with hardware-based root of trust in a composite architecture. The software layer provides compatibility and ease of operation with legacy systems, while the hardware component ensures measurement precision and resistance to malware. This composite approach integrates the advantages of both software and hardware solutions while mitigating their individual weaknesses.

Inventive Principle:
Principle #40Composite materials

3Reliability

If sealed storage facility is used to store sensitive data, then security and protection are improved, but data access speed and productivity decrease

Engineering Contradiction:
Improvedata securityVSAvoiddata access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary trust verification through challenge-response authentication before sealing or unsealing data. The root of trust in the peripheral device pre-evaluates the computing platform's trustworthiness, and only then does the sealed storage facility grant access. This preliminary action ensures security while enabling fast data access once trust is established, as subsequent access operations can proceed without repeated verification overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The sealed storage facility dynamically adjusts its access control state based on the trust verification results. When the computing platform is verified as trustworthy, the storage facility transitions from a sealed (restricted) state to an unsealed (accessible) state. This dynamic behavior maintains high security when needed while enabling high-speed data access during legitimate operations, optimizing both security and productivity based on real-time trust assessment.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8966642B2Trust verification of a computing platform using a peripheral device
Publication Date: 2015.02.24 ASSURED INFORMATION SECURITY
  • US8966642B2 patent drawing
  • US8966642B2 patent drawing
  • US8966642B2 patent drawing

AI summary

Verification of trustworthiness of a computing platform is provided. The trustworthiness of the computing platform is dynamically assessed to determine whether a root of trust exists on the computing platform. Responsive to determining existence of the root of trust, data is unsealed from a sealed storage facility. The sealed storage facility is unsealed responsive to a root of trust being determined to exist on the computing platform. The data can be used to attest to the trustworthiness of the computing platform to other device on a network.