Security Co-Processor Multi-Dimensional Attribute Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security co-processor modules, such as TPMs, rely solely on machine mode for security operations, which is insufficient in providing comprehensive security and control, as it does not account for additional attributes like geographic location, trusted time, hardware vendor strings, and environmental factors, potentially leaving systems vulnerable to attacks.

Innovation Solution

Enhancing the security co-processor module by incorporating additional attributes like geographic location, trusted time, hardware vendor strings, and environmental factors into the measurement of the computing system's environment, processed within the secure hardware-bounded trusted computing base to improve security and control, thereby preventing higher-level software vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only machine mode binding is used for security operations, then the security co-processor module maintains simplicity in operation, but the system security and control are insufficient

Engineering Contradiction:
Improvesystem securityVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security verification process into multiple independent attributes (machine mode, geographic location, trusted time, hardware vendor string, environmental factors) that can be evaluated separately. Each attribute is measured and stored in distinct PCR registers, allowing the system to maintain simplicity in individual attribute handling while achieving comprehensive security through their combination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extends the security verification from a single dimension (machine mode) to multiple dimensions by incorporating geographic location, trusted time, hardware vendor strings, and environmental factors. This multi-dimensional approach creates a more robust security model where each dimension adds an independent layer of verification, resolving the contradiction between security comprehensiveness and operational simplicity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If additional attributes are incorporated into the measurement, then the security and control are improved, but the complexity of the security co-processor module increases

Engineering Contradiction:
Improvesecurity controlVSAvoidmodule complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the complex security measurement task into manageable segments by assigning each attribute (machine mode, geographic location, trusted time, etc.) to specific PCR registers. This segmentation allows the security co-processor to handle multiple attributes without becoming unwieldy, as each attribute is processed and stored independently according to predefined rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-defining the measurement rules and PCR register assignments for each attribute before execution. The security co-processor is configured in advance with the specific attributes to measure and the corresponding PCR registers to use, which simplifies the actual measurement process and reduces operational complexity despite handling multiple attributes.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple attributes are measured and processed, then the access control space is expanded, but the processing time and system resources increase

Engineering Contradiction:
Improveaccess control spaceVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring the measurement rules, PCR register mappings, and attribute priorities before the security measurement process begins. This preparation work is done once during system initialization, allowing the actual measurement of multiple attributes to proceed efficiently without repeated configuration overhead, thus expanding access control space while minimizing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security co-processor automatically measures and processes multiple attributes based on pre-defined rules without requiring external intervention for each attribute. The system self-manages the collection, measurement, and storage of attributes in PCR registers, reducing the time and resources needed for manual configuration and processing of each individual attribute.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8479017B2System and method for N-ary locality in a security co-processor
Publication Date: 2013.07.02 INTEL CORP
  • US8479017B2 patent drawing
  • US8479017B2 patent drawing
  • US8479017B2 patent drawing

AI summary

Enhancing locality in a security co-processor module of a computing system may be achieved by including one or more additional attributes such as geographic location, trusted time, a hardware vendor string, and one or more environmental factors into an access control space for machine mode measurement of a computing system.