Security Chip Dynamic Trust Verification for Cryptographic Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Trusted Platform Module (TPM) and Trusted Platform Control Module (TPCM) methods fail to guarantee dynamic trust during high-speed cryptographic operations, particularly in ensuring the trust chain transfer and trusted loading and execution of dynamic measurement codes.
Innovation Solution
A method and apparatus where a security chip receives a cryptographic operation request, measures a dynamic measurement module using a platform measurement root, and starts the operation only if the measurement result matches a pre-stored standard value, ensuring dynamic trust by verifying the measurement result.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional TPM or TPCM measurement methods are used for high-speed cryptographic operations, then the cryptographic operation can be performed, but dynamic trust for measurement codes cannot be guaranteed
Solution Approach 1:
The system performs preliminary actions by pre-storing standard values for measurement results and pre-loading the dynamic measurement module before cryptographic operations begin. This ensures that trust verification mechanisms are already in place, enabling dynamic trust guarantee without adding operational complexity during the cryptographic process
Solution Approach 2:
A security chip is introduced as an intermediary component that specifically handles measurement and verification of the dynamic measurement module. This mediator separates the trust verification function from the general cryptographic operation flow, ensuring dynamic trust without complicating the overall system architecture
2Adaptability or versatility
If dynamic measurement of cryptographic operations is implemented, then measurement capability is enhanced, but trust chain transfer cannot be guaranteed
Solution Approach 1:
The system implements feedback by comparing the actual measurement result with the pre-stored standard value. This feedback mechanism verifies that the dynamic measurement module maintains its integrity and trust chain throughout the cryptographic operation, ensuring reliability while preserving measurement adaptability
Solution Approach 2:
The measurement process is segmented into distinct components: the dynamic measurement module that performs measurements, the security chip that verifies results, and the pre-stored standard values that provide reference. This segmentation allows each component to specialize in its function, maintaining trust chain transfer while supporting dynamic measurement capability
Data Source
AI summary
A method including a security chip receiving a cryptographic operation request; the security chip acquiring a measurement result, wherein the measurement result is a result of measuring a dynamic measurement module in a cryptographic operation module by using a platform measurement root; and the security chip starting a cryptographic operation when determining that the measurement result is identical to a pre-stored standard value. The present disclosure solves a technical problem of failure to guarantee a dynamic trust for measurement code when starting dynamic measurement of a cryptographic operation.


