Software Root of Trust Establishment on Untrusted Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods fail to establish a root of trust (RoT) unconditionally on untrusted systems, as they rely on trusted hardware modules, secrets, or polynomial bounds on adversary computing power, and cannot prove malware-free initial system states, especially in multi-device systems.
Innovation Solution
A verifier device uses non-secret randomness and space-time optimal computations to initialize and verify the system state, ensuring that only chosen content is present, without relying on trusted hardware or secrets, and using k-independent universal hash functions to prevent malware insertion and detection of unaccounted content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional attestation protocols are used, then software integrity can be verified, but system state root of trust cannot be established unconditionally
Solution Approach 1:
The patent extracts the root of trust from trusted hardware modules and secrets, establishing it instead through mathematical properties of space-time optimal computations and k-independent universal hash functions that can be verified in software alone
Solution Approach 2:
The patent replaces hardware-based trust mechanisms with a software-based verification system that uses mathematical computations to establish and verify root of trust, eliminating dependence on physical hardware trust
2Reliability
If trusted hardware modules are used, then boot verification can be performed, but persistence of malware in non-volatile memories cannot be prevented
Solution Approach 1:
The patent performs preliminary verification of system state before booting trusted programs, checking that all memory and register contents are zero or contain only expected initialization data, thereby preventing malware persistence
Solution Approach 2:
The patent applies preliminary anti-action by verifying system state cleanliness before trusted execution begins, using space-time optimal computations to detect and prevent malware that might otherwise persist in non-volatile memories
3Reliability
If cryptographic protocols with third-party keys are used, then conditional security can be provided, but unconditional security cannot be proved
Solution Approach 1:
The patent removes dependence on third-party cryptographic keys and trusted hardware modules, establishing security through verifiable mathematical properties of computations that can be independently verified
Solution Approach 2:
The patent substitutes cryptographic protocols with a verification system based on space-time optimal computations and universal hash functions, enabling unconditional security proofs without third-party trust
4Reliability
If software-based attestation approaches are used, then system software integrity can be checked, but control-flow integrity and space-time optimality cannot be proven
Solution Approach 1:
The patent replaces conventional software attestation with a verification system based on space-time optimal computations that provide provable control-flow integrity and mathematical guarantees of optimality
Solution Approach 2:
The patent introduces space and time as verifiable parameters in the attestation process, using space-time optimal computations to prove both software integrity and control-flow properties simultaneously
Data Source
AI summary
A method and apparatus for establishing a software root of trust (RoT) ensures that the state of an untrusted computer system contains all and only content chosen by an external verifier and the system code begins execution in that state, or that the verifier discovers the existence of unaccounted for content. The method enables program booting into computer system states that are free of persistent malware such that an adversary cannot retain undetected control of an untrusted system.


