Software Integrity Verification Without TPM Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing TPM-based solutions for verifying the integrity of a computing platform require specific hardware and correct implementation, excluding billions of systems without these features from secure integrity measurement, making them vulnerable to malicious attacks.

Innovation Solution

A software image is generated that, when executed on a target computing platform, verifies integrity by comparing execution parameters with those from a secure platform, using encrypted data structures and instructions to measure and decrypt parameters, and generates a verification message to ensure the platform's integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TPM-based solutions are used to verify integrity, then measurement security is improved, but hardware requirements and system compatibility deteriorate

Engineering Contradiction:
Improveintegrity measurement securityVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the hardware-based TPM mechanical system with a software-based integrity measurement system. The verification module executes software instructions that perform integrity measurements without requiring physical TPM hardware, thereby substituting the mechanical/hardware approach with a software-based approach that achieves the same security function while improving system compatibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a software-based copy of the TPM functionality. Instead of requiring actual TPM hardware, the system implements a virtual TPM through software that replicates the essential functions of integrity measurement and verification, allowing systems without physical TPM to achieve equivalent security capabilities.

Inventive Principle:
Principle #26Copying

2Reliability

If TPM hardware is required for integrity verification, then security assurance is improved, but device complexity and cost deteriorate

Engineering Contradiction:
Improvesecurity assuranceVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent substitutes the complex TPM hardware system with a simpler software-based verification module. The verification module consists of software instructions that can be executed on general-purpose processors, eliminating the need for specialized hardware components while maintaining security assurance through software-based integrity measurement and verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent employs software-based integrity measurement that can be deployed and updated without requiring expensive hardware components. The software verification module can be distributed as code that runs on existing systems, replacing the need for costly TPM hardware modules while achieving equivalent security functions.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Measurement precision

If correct TPM implementation is required, then integrity verification accuracy is improved, but ease of deployment deteriorates

Engineering Contradiction:
Improveintegrity verification accuracyVSAvoiddeployment simplicity
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent distributes the integrity verification functionality as software code that can be copied and executed on target systems. The verification module is provided as a software image or executable that contains pre-configured measurement parameters and verification logic, eliminating the need for complex hardware configuration while maintaining measurement accuracy through software-based validation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs integrity verification measurements in advance during system initialization or boot processes. The verification module executes predetermined verification sequences that check critical system components before full system operation begins, ensuring measurement accuracy while simplifying deployment by integrating verification into existing system startup routines.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11188653B1Verifying the integrity of a computing platform
Publication Date: 2021.11.30 HAMLIN CHRISTOPHER LUIS
  • US11188653B1 patent drawing
  • US11188653B1 patent drawing
  • US11188653B1 patent drawing

AI summary

Systems and techniques are described for verifying the integrity of a computing platform. Specifically, a software image can be generated that, when executed at a computing platform, verifies integrity of the computing platform. Next, the software image can be sent to the computing platform. The computing platform can execute the software image, thereby enabling the verification of the integrity of the computing platform.