SSD Master Controller Root of Trust Implementation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional trusted computing platforms face challenges in ensuring the security and trustworthiness of system firmware during startup, as existing solutions like TPM and TCM are passive and require modifications to system design, making them costly and difficult to implement widely, especially in cost-sensitive applications.
Innovation Solution
Establishing the root of trust on an intermediate stage in the boot chain, specifically using the master controller of a solid-state drive, which includes cryptographic engines, a true random number generator, and protected storage, enabling measurement and authentication without modifying system design or adding hardware overhead, and utilizing pre-boot authentication to ensure secure boot processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional TPM or TCM modules are used to establish root of trust, then system security measurement capability is improved, but device complexity and manufacturing cost increase due to additional hardware components
Solution Approach 1:
The patent merges the root of trust functions (cryptographic engines, random number generator, protected storage) with the existing solid-state drive master controller, eliminating the need for separate TPM/TCM hardware modules. The master controller's existing resources are utilized to perform security measurement functions, thereby reducing device complexity while maintaining security capabilities.
Solution Approach 2:
The solid-state drive master controller is designed to perform multiple functions: traditional storage control operations plus security measurement and authentication functions. By making the master controller universal, the system eliminates dedicated security hardware while maintaining comprehensive security measurement capability across the system boot chain.
2Reliability
If TPM or TCM modules are added to the system, then trusted computing functionality is improved, but manufacturing cost increases due to additional hardware overhead
Solution Approach 1:
The patent combines trusted computing functionality into the existing master controller of the solid-state drive, eliminating the need for separate TPM or TCM hardware modules. This merging approach maintains full trusted computing functionality while reducing bill of materials costs and simplifying the manufacturing process by removing additional hardware components.
Solution Approach 2:
The master controller utilizes its own internal resources (cryptographic engines, random number generator, protected storage areas) to perform security measurement and authentication functions, making the system self-sufficient for trusted computing operations without requiring external security hardware additions.
3Measurement precision
If system design is modified to include dedicated security modules, then security measurement accuracy is improved, but ease of operation and deployment difficulty worsen
Solution Approach 1:
The patent merges security measurement functions into the existing master controller, eliminating the need for system design modifications. The master controller maintains full security measurement accuracy by using its cryptographic engines to measure the firmware and boot chain, while the system operates with standard architecture, improving ease of deployment.
4Reliability
If additional protected storage areas are added for security data, then security data protection capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent merges security data protection capabilities into the existing solid-state drive storage structure. The master controller uses its protected storage areas (such as reserved regions in the flash memory) to store security-critical data like measurement logs and authentication credentials, eliminating the need for separate secure storage hardware while maintaining protection capability.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach allows for a secure and trustworthy system environment without additional hardware costs, providing a robust security mechanism that cannot be bypassed, suitable for both factory-installed and after-market solutions, and is applicable to various host interfaces.
Implementation Method 1
which includes cryptographic engines, a true random number generator, and protected storage, enabling measurement and authentication
Implementation Method 2
which includes cryptographic engines, a true random number generator, and protected storage
Data Source
AI summary
The present disclosure relates to an implementation for a trusted computing system. According to the embodiments of the present disclosure, a master controller in an SSD, which is necessarily configured in the system, is used to provide all necessary security functionality of the system's RoT. The system does not need to contain any special RoT chip or module, does not need any modifications in the system design, is easy to adopt, and can be implemented by any system comprising a hard drive. All necessary security functions are completed by the master controller of the system's hard drive. Thus, not only can the cost of the security module be reduced, but more importantly, the mechanism directly protects information and resources (e.g., operating system, user programs, user data, etc.) that actually need to be protected in the system, and once the mechanism is enabled, the protection function cannot be bypassed.


