Trusted Computing Base Key Migration Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted computing environments fail to securely transfer application storage keys when the trusted computing base is modified, lacking user notification of potential message exposure and inadequate access control for law enforcement needs.

Innovation Solution

A computing device with a protected partition and a storage key derivation module that generates and migrates storage keys based on the trusted computing base version, ensuring secure key transfer and user notification, while maintaining separate partitions for secure and malicious software execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the trusted computing base is modified to improve functionality or security, then the system can provide enhanced features, but existing encrypted data becomes inaccessible and keys cannot be securely transferred

Engineering Contradiction:
Improvetrusted computing base versionVSAvoiddata accessibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by deriving and storing multiple storage keys corresponding to different trusted computing base versions before migration occurs. When a TCB version changes, the system can immediately provide the appropriate pre-derived storage key without requiring re-encryption or complex key migration procedures, thus maintaining data accessibility while adapting to TCB changes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the parameter of storage keys by deriving different keys based on different TCB version parameters. The storage key derivation module generates version-specific keys (e.g., TCB v1 key, TCB v2 key) so that when the TCB version parameter changes, the corresponding storage key parameter automatically changes to maintain compatibility and data accessibility.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If key escrow systems are implemented to allow law enforcement access, then authorized access can be provided, but users cannot know whether their messages have been exposed

Engineering Contradiction:
Improvelaw enforcement accessVSAvoiduser notification
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system implements feedback by notifying users when their storage keys have been exposed or migrated due to law enforcement access or TCB changes. The notification mechanism provides real-time or near-real-time information to users about the status of their encrypted data, allowing them to understand when messages have been exposed while still permitting authorized access through the key escrow mechanism.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple storage keys are derived for different TCB versions, then data accessibility is maintained during migration, but system complexity increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage key derivation module serves multiple functions: it derives storage keys for current TCB versions, derives storage keys for alternate TCB versions, verifies migration approvals, and provides appropriate keys based on TCB version detection. This multi-functional design consolidates what could be separate complex systems into a single versatile module, managing complexity while maintaining data accessibility across versions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11405201B2Secure transfer of protected application storage keys with change of trusted computing base
Publication Date: 2022.08.02 BRICKELL CRYPTOLOGY LLC
  • US11405201B2 patent drawing
  • US11405201B2 patent drawing
  • US11405201B2 patent drawing

AI summary

Methods and apparati for securely transferring application storage keys in an application in a trusted computing environment, when the trusted computing base is modified. In an apparatus embodiment of the present invention, a computing device comprises: a protected partition in which an application can execute without attack from outside a trusted computing base of the partition; and a storage key derivation module which provides a first storage key to said application, where the value of the first storage key is derived from a computation dependent upon a first version of the trusted computing base that is launched on the platform. The storage key derivation module is further configured to derive a second storage key from a computation dependent upon an alternate version of the trusted computing base; a migration key module is configured to verify whether there is an approval for providing the second storage key to the application while the application is executing with the first version of the trusted base having been launched; and the migration key module is further configured to provide the second storage key to the application after said approval has been verified.