Software Trusted Computing Base for Grid Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In grid computing environments, users lack assurance about the trustworthiness of computers allocated for tasks due to the inefficiency of conventional attestation protocols, which are slow and unable to handle multiple user requests effectively, leaving systems vulnerable to malware.
Innovation Solution
An Active Trusted Computing Base (ATCB) is implemented as a Software Trusted Computing Base (STCB) that operates on top of trusted hardware, using a trusted virtual machine manager (hypervisor) to provide faster and more efficient attestation by intercepting and managing bus activity, extending trust assurances from specialized hardware to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional attestation protocols are used, then security assurance is provided, but the system speed and efficiency deteriorate due to slow hardware-based verification
Solution Approach 1:
The patent introduces a Software Trusted Computing Base (STCB) as an intermediary layer between the hardware TCB and users. The STCB handles attestation requests through software-based verification, acting as a mediator that prevents direct interaction between multiple users and the slow hardware TCB, thereby improving attestation speed while maintaining security assurance through the underlying hardware foundation.
2Reliability
If specialized hardware provides attestation, then trust verification is achieved, but the hardware becomes overloaded and inefficient when serving multiple users
Solution Approach 1:
The patent segments the attestation functionality into two distinct layers: a hardware TCB layer that provides foundational trust verification and a software STCB layer that handles user-specific attestation requests. This segmentation allows the hardware to perform its core verification function once during system initialization, while the software layer efficiently serves multiple users without overloading the hardware, thereby improving both trust verification and hardware efficiency.
3Productivity
If grid computers are allocated based on resource metrics, then computing efficiency is improved, but users lose control over the trustworthiness of allocated systems
Solution Approach 1:
The patent implements a feedback mechanism where the STCB provides users with attestation information and trust verification results for allocated grid computers. This feedback loop enables users to verify the trustworthiness of allocated systems while maintaining the resource manager's efficiency in computer allocation, as the verification process occurs independently through the STCB without interfering with the resource allocation metrics.
Data Source
AI summary
A software trusted platform module (sTPM) operates in a hypervisor, receives trust assurances from specialized hardware, and extends this trust such that the hypervisor performs trust attestation. The hypervisor receives a startup sequence validation from a TPM, or Trusted Platform Module. The TPM performs bus monitoring during a boot sequence of the computer system, records the startup sequence from the bus, and performs a hash on the sequence. The TPM performs an authentication exchange with the hypervisor such that the hypervisor authenticates the attestation of the computer system from the TPM, and the hypervisor, now delegated with trust assurances from the TPM, provides assurances to users via an authentication chain. The ATCB then performs the attestation of the computer system according to the attestation protocol much faster than the TPM. In this manner, the hypervisor operates as a software delegate of the TPM for providing user assurances of trust.


