Secure Boot Tamper Detection Using TPM Random Byte Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems lack a mechanism to fail a secure boot when a case tampering event occurs, compromising data security.
Innovation Solution
A computer system equipped with a trusted platform module (TPM) generates random bytes for secure boot, which are stored and managed by a bootloader or operating system, and deleted upon detection of a case tampering event by sensors, thereby failing the secure boot.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If random bytes are stored in hardware for secure boot, then secure boot reliability is improved, but system security deteriorates when case tampering occurs
Solution Approach 1:
The system performs preliminary action by detecting case tampering events before the secure boot process completes. Sensors monitor the case status and trigger deletion of random bytes during the boot process, preventing unauthorized systems from booting with stolen cryptographic materials.
Solution Approach 2:
The system implements feedback by continuously monitoring case status through sensors and using this information to control the security state. When tampering is detected, the system responds by deleting critical boot data, creating a closed-loop security mechanism that adapts to physical threats.
2Object-affected harmful factors
If case tampering detection is implemented, then system security is improved, but device complexity increases
Solution Approach 1:
The patent introduces sensors as intermediary components that detect case tampering and translate physical events into electrical signals. These sensors act as mediators between the physical case and the digital security system, enabling tamper detection without requiring complex direct monitoring of the case structure.
Solution Approach 2:
The system implements self-service by automatically responding to tampering events without human intervention. When sensors detect case opening, the system autonomously deletes random bytes and fails the secure boot process, eliminating the need for manual security management.
Data Source
AI summary
A computer system for failing a secure boot in a case tampering event comprises a trusted platform module (TPM), for generating a plurality of random bytes for a secure boot of the computer system; a bootloader, for storing information in at least one hardware of the computer system and performing the secure boot, wherein the information comprises the plurality of random bytes, and the TPM is comprised in the bootloader; an operating system (OS), for performing the secure boot; and at least one sensor, for detecting a case tampering event in the computer system, and transmitting a signal for triggering a deletion of the plurality of random bytes, if the case tampering event happens in the computer system. The bootloader or the OS performs the operation of deleting the plurality of random bytes stored in the at least one hardware to fail the secure boot, in response to the signal.


