Shared Security Processor for Management Device Integrity Across Resets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ensuring trusted operations in a computer system's management domain with multiple management devices, particularly across different reset domains, is challenging due to the complexity and cost of deploying separate security processors for each device, and obtaining accurate measurement values post-reset is difficult.
Innovation Solution
Implementing a shared security processor to manage multiple management devices across different reset domains, where a primary management device interacts with a secondary management device to provide measurement values to the security processor for verification, using a primary management device to extend these values to platform configuration registers, and maintaining a persistent record of measurement values for attestation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate security processors are deployed for each management device, then security verification reliability is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines multiple security verification functions into a single shared security processor. The security processor receives measurement values from multiple management devices (first management device and second management device) and performs verification operations for all of them, eliminating the need for separate security processors for each management device while maintaining security verification reliability
Solution Approach 2:
The security processor is designed with universal functionality to handle verification operations for multiple different management devices. It can receive measurement values, perform verification operations, and manage platform configuration registers for various management devices within the management domain, making a single processor serve multiple security verification purposes
2Reliability
If separate security processors are deployed for each management device, then security verification reliability is improved, but cost increases
Solution Approach 1:
The patent merges the security processing functions that would otherwise require separate processors for each management device into one shared security processor. This consolidation reduces the total number of security processors needed in the system, thereby reducing hardware costs while maintaining the ability to verify multiple management devices
3Device complexity
If a shared security processor is used, then device complexity is reduced, but measurement value accuracy after reset deteriorates
Solution Approach 1:
The security processor performs preliminary actions by saving measurement values to persistent storage before a reset occurs. When the first management device resets, the security processor can retrieve these previously saved measurement values from persistent storage and restore them to the platform configuration registers, ensuring measurement value accuracy is maintained across reset events
Solution Approach 2:
The patent introduces persistent storage as an intermediary between the security processor and the platform configuration registers. This intermediary allows measurement values to be preserved across reset events, enabling the security processor to maintain accurate measurement values even when management devices reset, without requiring separate security processors
4Ease of operation
If measurement values are not persisted across resets, then ease of operation is improved, but reliability of attestation deteriorates
Solution Approach 1:
The security processor performs preliminary saving of measurement values to persistent storage before resets occur. This allows the system to automatically restore accurate measurement values after resets without requiring complex manual intervention, maintaining ease of operation while ensuring reliable attestation by preserving the integrity of measurement values across reset events
Data Source
AI summary
In some examples, a security processor receives, from a first management device, measurement data of one or more second management devices. The measurement data is computed at the one or more second management devices based on information in the one or more second management devices and sent from the one or more second management devices to the first management device. The security processor stores the measurement data in a secure storage of the security processor, and provides a representation of the measurement data to validate an integrity of the information in the one or more second management devices.


