Software-Based Computing Platform Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for verifying the integrity of a computing platform, such as those using Trusted Platform Module (TPM) hardware, are limited by the requirement for specific hardware and correct implementation, excluding billions of systems from secure integrity measurement, especially those vulnerable to malicious hypervisor attacks.

Innovation Solution

A software image is generated that, when executed on a target computing platform, verifies integrity by comparing execution parameters measured during execution with those from a secure platform, using encryption and decryption processes to ensure the integrity of the platform, allowing for secure operation even in insecure environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If TPM-based hardware solutions are used for integrity verification, then measurement precision is improved, but device complexity and cost increase, excluding billions of existing systems from secure integrity measurement

Engineering Contradiction:
Improveintegrity measurement capabilityVSAvoidhardware requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/hardware-based TPM system with a software-based integrity verification mechanism. The software image contains embedded verification logic that measures execution parameters and compares them against expected values, eliminating the need for dedicated hardware security modules while achieving comparable integrity measurement capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The software image serves multiple functions: it performs the actual computation, measures execution parameters for integrity verification, encrypts and decrypts data, and compares measured values against expected values. This multi-functional approach replaces the specialized TPM hardware with a universal software solution that can run on any computing platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If TPM-based security architecture is implemented, then reliability is improved, but ease of manufacture and deployment deteriorates due to correct implementation requirements

Engineering Contradiction:
Improveplatform integrity assuranceVSAvoidimplementation correctness
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The software image performs self-verification by measuring its own execution parameters and comparing them against expected values embedded in the image. This self-service mechanism eliminates the need for external TPM hardware and complex implementation architectures, making deployment simple while maintaining reliability through built-in verification logic.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The expected execution parameters are pre-computed and embedded in the software image before deployment. This preliminary action ensures that verification can be performed locally without requiring complex implementation architectures or external hardware, simplifying both manufacture and deployment while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If existing systems without hardware security features are used, then adaptability is improved, but security against malicious hypervisor attacks deteriorates

Engineering Contradiction:
Improvesystem compatibilityVSAvoidmalicious hypervisor attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent substitutes hardware-based security features with software-based verification mechanisms that run within the existing system. The software image measures execution parameters such as instruction count, timing, and memory access patterns, providing security against malicious hypervisors without requiring specialized hardware, thus maintaining adaptability across all system types.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The software image acts as an intermediary between the computation and the verification process. It measures execution parameters and compares them against expected values, providing a layer of security that protects against malicious hypervisor attacks while working within existing system constraints, thereby maintaining broad adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9836611B1Verifying the integrity of a computing platform
Publication Date: 2017.12.05 HAMLIN CHRISTOPHER LUIS
  • US9836611B1 patent drawing
  • US9836611B1 patent drawing
  • US9836611B1 patent drawing

AI summary

Systems and techniques are described for verifying the integrity of a computing platform. Specifically, a software image can be generated that, when executed at a computing platform, verifies integrity of the computing platform. Next, the software image can be sent to the computing platform. The computing platform can execute the software image, thereby enabling the verification of the integrity of the computing platform.