Sealing Cryptographic Keys to Trusted Platform Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems are vulnerable to data breaches and unauthorized access, especially in mobile devices, as cryptographic keys can be compromised or stolen, leading to potential data theft and loss of security.

Innovation Solution

A method and system for sealing cryptographic keys to a trusted platform configuration using measurement values representing platform resources, such as embedded firmware and BIOS, ensuring that data can only be accessed if the platform is in its original configuration, with optional password or biometric confirmation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are stored on mobile devices, then data accessibility is improved, but security is worsened due to vulnerability to theft and unauthorized access

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the cryptographic key from the mobile device by sealing it to the platform configuration, effectively removing the key from direct access while maintaining data accessibility through the sealed mechanism. The key is taken out of the vulnerable storage location and bound to the platform's trusted configuration.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a sealed key as an intermediary between the cryptographic key and the data repository. The sealed key acts as a mediator that can only be unsealed when the platform configuration matches the original sealing configuration, providing a secure layer between the key and potential threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic keys are protected by encryption, then security is improved, but key management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service key management through the sealing mechanism, where the system automatically binds the cryptographic key to the platform configuration without requiring manual intervention. The sealed key autonomously prevents unauthorized access based on platform state, eliminating the need for complex manual key management procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary action by sealing the cryptographic key to the platform configuration before any potential security threats can occur. This advance binding ensures that the key is already protected and can only be accessed under the specific trusted configuration, eliminating the need for complex runtime key management decisions.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If data repositories are encrypted, then security is improved, but data access speed is reduced due to decryption overhead

Engineering Contradiction:
ImprovesecurityVSAvoiddata access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary decryption by unsealing the cryptographic key during the platform initialization process before data access operations begin. This advance key preparation eliminates decryption overhead during actual data access, maintaining both security and speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous access to the cryptographic key once unsealed, allowing multiple data access operations to proceed without repeated decryption overhead. The sealed key remains available in the trusted platform environment, enabling continuous fast access to encrypted data while maintaining security through the sealed mechanism.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS7421588B2Apparatus, system, and method for sealing a data repository to a trusted computing platform
Publication Date: 2008.09.02 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US7421588B2 patent drawing
  • US7421588B2 patent drawing
  • US7421588B2 patent drawing

AI summary

An apparatus, method, and system to seal a data repository to a trusted computing platform is described. The data repository may be sealed by encrypting the data on the repository and sealing a cryptographic key to a specific set of platform resources. With the data repository sealed to the platform, the system boot sequence will fail if the system configuration is compromised, for example by insertion of “snoopware” or a modified BIOS. Additionally, if the computer containing the data repository is lost or stolen, the encrypted data remains secure even if the repository is attached to a system modified to bypass normal safeguards.