Processor-Based Security for Trusted Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

TPM-based trusted computing systems face security vulnerabilities, performance issues, scalability limitations, and usability challenges due to their reliance on a separate, low-cost security chip, which is susceptible to attacks and unable to efficiently handle modern processor speeds and complex operating systems.

Innovation Solution

A processor-based security system that integrates security functions within the processor, using a hypervisor program to create secure memory areas, perform secure launches, and generate attestation reports, eliminating the need for a separate security chip and enhancing performance and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a separate TPM security chip is used, then cost is reduced, but performance becomes very low (hundreds of milliseconds for operations) and scalability is limited

Engineering Contradiction:
ImprovecostVSAvoidperformance
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent merges the TPM security chip functionality directly into the processor architecture. The processor includes integrated security features such as a security unit that can perform cryptographic operations, measure boot integrity, and manage secure storage keys, eliminating the need for a separate TPM chip while achieving high performance suitable for modern processor speeds

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The processor is designed to perform multiple functions including general computation and security operations. The security unit within the processor can handle various security tasks (integrity measurement, key management, attestation) that were previously dedicated to separate TPM hardware, enabling the processor to serve both computational and security roles

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If a separate TPM security chip is used, then cost is reduced, but the system becomes vulnerable to security attacks (Cold Boot, TPM reset attacks) due to physical memory accessibility

Engineering Contradiction:
ImprovecostVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the security-critical components from the general-purpose processor components. The security unit is a separate module within the processor that handles integrity measurement and key management, isolating security functions from potentially compromised software environments and physical memory spaces

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security unit as an intermediary between the processor and external security operations. This security unit measures boot integrity, manages encryption keys, and coordinates secure storage operations, acting as a mediator that protects against attacks by centralizing security functions in a dedicated, protected environment

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If TPM-based approaches are used, then security services are provided, but usability is difficult due to complex programming requirements and unfamiliar TPM programming

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security unit automatically performs security operations without requiring manual programming or configuration. The processor autonomously measures boot integrity, manages encryption keys, and handles secure storage operations, eliminating the need for users or developers to program TPM commands while maintaining strong security

Inventive Principle:
Principle #25Self-service

4Reliability

If a separate TPM chip is used, then security functions are isolated, but scalability is limited to a limited number of separate software contexts that can be measured concurrently

Engineering Contradiction:
Improvesecurity isolationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from a hardware-based security architecture (separate TPM chip with fixed resources) to a software-based security architecture within the processor. This enables virtualization and software-defined security contexts, allowing unlimited numbers of software contexts to be measured and managed concurrently through virtual TPM instances rather than being constrained by physical hardware resources

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9989043B2System and method for processor-based security
Publication Date: 2018.06.05 CORESECURE TECH LLC
  • US9989043B2 patent drawing
  • US9989043B2 patent drawing
  • US9989043B2 patent drawing

AI summary

A system and method for processor-based security is provided, for on-chip security and trusted computing services for software applications. A processor is provided having a processor core, a cache memory, a plurality of registers for storing at least one hash value and at least one encryption key, a memory interface, and at least one on-chip instruction for creating a secure memory area in a memory external to the processor, and a hypervisor program executed by the processor. The hypervisor program instructs the processor to execute the at least one on-chip instruction to create a secure memory area for a software area for a software module, and the processor encrypts data written to, and decrypts data read from, the external memory using the at least one encryption key and the verifying data read from the external memory using the at least one hash value.