Pluggable Trust Architecture for Hardware Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing systems face vulnerabilities due to untrusted hardware and software components, which can lead to unauthorized access, data manipulation, and integrity issues, making it difficult to ensure system security and privacy, especially with complex supply chains and intellectual property restrictions.

Innovation Solution

A pluggable trust architecture is introduced, featuring a separately manufactured and verified hardware element that acts as a gatekeeper, physically isolating untrusted components and ensuring only correctly executed data is communicated externally, using a hardware element like 'Sentry' that can be independently sourced and verified, decoupling execution from verification to minimize performance impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a pluggable hardware element is introduced to verify system output, then system security and trust are improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into two independent parts: an untrusted computing system and a separately manufactured pluggable hardware element (trust element). The trust element is a standalone component that can be physically separated from the main system, allowing it to be independently verified and trusted while the main system remains untrusted. This segmentation resolves the contradiction by isolating the trust function from the complex untrusted system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The pluggable hardware element acts as an intermediary between the untrusted computing system and the external world. It receives output from the untrusted system, verifies its correctness independently, and only releases verified output externally. This intermediary approach allows the system to maintain security without requiring the entire system to be trusted, resolving the contradiction between security and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If execution information is sent to the hardware element for checking, then detection precision of malicious behavior is improved, but loss of time increases

Engineering Contradiction:
Improvedetection precisionVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The trust element is pre-configured with the untrusted system's binary code during manufacturing, before the system operates. This preliminary action allows the trust element to have the verification logic ready in advance, eliminating the need for real-time compilation or analysis of system code during operation, thus reducing verification time while maintaining high detection precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification process is replaced from a software-based analysis (which would be time-consuming) to a hardware-based comparison mechanism. The trust element uses dedicated hardware circuits to directly compare output signals with independently computed expected values, enabling fast verification without sacrificing detection precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Manufacturing precision

If the hardware element is separately manufactured and verified, then manufacturing precision of the trust component is improved, but device complexity increases

Engineering Contradiction:
Improvetrust component verificationVSAvoidsupply chain complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The trust verification function is extracted from the main system manufacturing process and placed into a separately manufactured pluggable hardware element. This extracted component can be manufactured in a controlled, trusted environment with verified supply chain processes, while the main system can be manufactured independently. The separate manufacturing approach improves trust component verification without requiring the entire supply chain to be restructured.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The pluggable hardware element is designed as a universal trust component that can be used with multiple different untrusted systems. By creating a standardized, multi-functional trust element that can verify various systems, the manufacturing process achieves economies of scale and standardized verification procedures, improving manufacturing precision while actually reducing overall supply chain complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11314865B2Pluggable trust architecture
Publication Date: 2022.04.26 THE TRUSTEES OF PRINCETON UNIV
  • US11314865B2 patent drawing
  • US11314865B2 patent drawing
  • US11314865B2 patent drawing

AI summary

A pluggable trust architecture addresses the problem of establishing trust in hardware. The architecture has low impact on system performance and comprises a simple, user-supplied, and pluggable hardware element. The hardware element physically separates the untrusted components of a system from peripheral components that communicate with the external world. The invention only allows results of correct execution of software to be communicated externally.