Software Root of Trust Establishment on Untrusted Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to establish a root of trust (RoT) unconditionally on untrusted systems, as they rely on trusted hardware modules, secrets, or polynomial bounds on adversary computing power, and cannot prove malware-free initial system states, especially in multi-device systems.

Innovation Solution

A verifier device uses non-secret randomness and space-time optimal computations to initialize and verify the system state, ensuring that only chosen content is present, without relying on trusted hardware or secrets, and using k-independent universal hash functions to prevent malware insertion and detection of unaccounted content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional attestation protocols are used, then software integrity can be verified, but system state root of trust cannot be established unconditionally

Engineering Contradiction:
Improveroot of trust establishmentVSAvoidtrust information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the root of trust from trusted hardware modules and secrets, establishing it instead through mathematical properties of space-time optimal computations and k-independent universal hash functions that can be verified in software alone

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces hardware-based trust mechanisms with a software-based verification system that uses mathematical computations to establish and verify root of trust, eliminating dependence on physical hardware trust

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If trusted hardware modules are used, then boot verification can be performed, but persistence of malware in non-volatile memories cannot be prevented

Engineering Contradiction:
Improveboot verificationVSAvoidpersistent malware
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary verification of system state before booting trusted programs, checking that all memory and register contents are zero or contain only expected initialization data, thereby preventing malware persistence

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by verifying system state cleanliness before trusted execution begins, using space-time optimal computations to detect and prevent malware that might otherwise persist in non-volatile memories

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If cryptographic protocols with third-party keys are used, then conditional security can be provided, but unconditional security cannot be proved

Engineering Contradiction:
ImprovesecurityVSAvoidtrustworthiness information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent removes dependence on third-party cryptographic keys and trusted hardware modules, establishing security through verifiable mathematical properties of computations that can be independently verified

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent substitutes cryptographic protocols with a verification system based on space-time optimal computations and universal hash functions, enabling unconditional security proofs without third-party trust

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If software-based attestation approaches are used, then system software integrity can be checked, but control-flow integrity and space-time optimality cannot be proven

Engineering Contradiction:
Improvesoftware integrityVSAvoidcontrol-flow integrity
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent replaces conventional software attestation with a verification system based on space-time optimal computations that provide provable control-flow integrity and mathematical guarantees of optimality

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces space and time as verifiable parameters in the attestation process, using space-time optimal computations to prove both software integrity and control-flow properties simultaneously

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12067110B2Method and apparatus for establishing a software root of trust on an untrusted computer system
Publication Date: 2024.08.20 CARNEGIE MELLON UNIV
  • US12067110B2 patent drawing
  • US12067110B2 patent drawing
  • US12067110B2 patent drawing

AI summary

A method and apparatus for establishing a software root of trust (RoT) ensures that the state of an untrusted computer system contains all and only content chosen by an external verifier and the system code begins execution in that state, or that the verifier discovers the existence of unaccounted for content. The method enables program booting into computer system states that are free of persistent malware such that an adversary cannot retain undetected control of an untrusted system.