Security Co-Processor Multi-Dimensional Attribute Measurement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security co-processor modules, such as TPMs, rely solely on machine mode for security operations, which is insufficient in providing comprehensive security and control, as it does not account for additional attributes like geographic location, trusted time, hardware vendor strings, and environmental factors, potentially leaving systems vulnerable to attacks.
Innovation Solution
Enhancing the security co-processor module by incorporating additional attributes like geographic location, trusted time, hardware vendor strings, and environmental factors into the measurement of the computing system's environment, processed within the secure hardware-bounded trusted computing base to improve security and control, thereby preventing higher-level software vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If only machine mode binding is used for security operations, then the security co-processor module maintains simplicity in operation, but the system security and control are insufficient
Solution Approach 1:
The patent segments the security verification process into multiple independent attributes (machine mode, geographic location, trusted time, hardware vendor string, environmental factors) that can be evaluated separately. Each attribute is measured and stored in distinct PCR registers, allowing the system to maintain simplicity in individual attribute handling while achieving comprehensive security through their combination.
Solution Approach 2:
The patent extends the security verification from a single dimension (machine mode) to multiple dimensions by incorporating geographic location, trusted time, hardware vendor strings, and environmental factors. This multi-dimensional approach creates a more robust security model where each dimension adds an independent layer of verification, resolving the contradiction between security comprehensiveness and operational simplicity.
2Reliability
If additional attributes are incorporated into the measurement, then the security and control are improved, but the complexity of the security co-processor module increases
Solution Approach 1:
The patent divides the complex security measurement task into manageable segments by assigning each attribute (machine mode, geographic location, trusted time, etc.) to specific PCR registers. This segmentation allows the security co-processor to handle multiple attributes without becoming unwieldy, as each attribute is processed and stored independently according to predefined rules.
Solution Approach 2:
The patent implements preliminary action by pre-defining the measurement rules and PCR register assignments for each attribute before execution. The security co-processor is configured in advance with the specific attributes to measure and the corresponding PCR registers to use, which simplifies the actual measurement process and reduces operational complexity despite handling multiple attributes.
3Adaptability or versatility
If multiple attributes are measured and processed, then the access control space is expanded, but the processing time and system resources increase
Solution Approach 1:
The patent applies preliminary action by pre-configuring the measurement rules, PCR register mappings, and attribute priorities before the security measurement process begins. This preparation work is done once during system initialization, allowing the actual measurement of multiple attributes to proceed efficiently without repeated configuration overhead, thus expanding access control space while minimizing processing time.
Solution Approach 2:
The security co-processor automatically measures and processes multiple attributes based on pre-defined rules without requiring external intervention for each attribute. The system self-manages the collection, measurement, and storage of attributes in PCR registers, reducing the time and resources needed for manual configuration and processing of each individual attribute.
Data Source
AI summary
Enhancing locality in a security co-processor module of a computing system may be achieved by including one or more additional attributes such as geographic location, trusted time, a hardware vendor string, and one or more environmental factors into an access control space for machine mode measurement of a computing system.


