TEE Attestation Artifact Renewal During TPM-Unresponsive Cold Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional attestation techniques using trusted platform modules (TPMs) become unresponsive during cold boot sessions, rendering them incapable of renewing device health certificates, leading to potential security vulnerabilities and inefficiencies.
Innovation Solution
Renew signed attestation artifacts using attestation artifacts received from the computing system, such as a public portion of an ephemeral cryptographic key generated by a trusted execution environment (TEE), without interacting with the TPM, to verify health and generate device health certificates during cold boot sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional attestation techniques use TPM to attest to health of computing system each time attestation is requested, then security validation is ensured, but TPM becomes unresponsive during cold boot sessions leading to inability to renew device health certificates
Solution Approach 1:
The patent introduces an intermediary approach by using previously obtained attestation artifacts (cryptographic keys and measurements) as mediators between the computing system and the attestation service. Instead of directly querying the unresponsive TPM during cold boot, the system uses stored attestation artifacts to prove system health, enabling certificate renewal without direct TPM interaction during the cold boot period.
Solution Approach 2:
The patent applies preliminary action by obtaining and storing attestation artifacts (cryptographic keys and system measurements) before the cold boot session begins. These pre-obtained artifacts are then used during the cold boot period when TPM is unresponsive, allowing the system to renew certificates in advance of the TPM becoming available again.
2Reliability
If TPM is queried for attestation information during cold boot session, then health verification can be performed, but TPM lockout mode is triggered extending unresponsiveness
Solution Approach 1:
The system performs health verification in advance by obtaining attestation artifacts before the cold boot session begins. This preliminary verification allows the system to have valid health proof ready before TPM becomes unresponsive, eliminating the need to query TPM during cold boot and avoiding lockout mode entirely.
Solution Approach 2:
The patent implements beforehand cushioning by preparing attestation artifacts in advance that can serve as a buffer or cushion during the cold boot period. These pre-prepared artifacts provide a safety mechanism that allows certificate renewal without stressing the TPM during its vulnerable cold boot state, preventing lockout scenarios.
3Reliability
If attestation service continuously queries TPM for certificate renewal, then up-to-date health certificates are maintained, but resource consumption increases during cold boot sessions
Solution Approach 1:
The patent implements periodic action by renewing attestation artifacts and certificates at specific intervals - specifically before cold boot sessions begin and at defined checkpoints during operation. Instead of continuous querying during cold boot, the system performs periodic updates at strategically chosen moments when TPM is responsive, reducing resource consumption while maintaining certificate freshness.
Solution Approach 2:
The system applies self-service by using previously obtained attestation artifacts to automatically prove system health during cold boot periods without requiring active TPM participation. The pre-stored cryptographic keys and measurements enable the system to self-validate its health state, eliminating the need for resource-intensive continuous queries to the TPM.
Data Source
AI summary
Techniques are described herein that are capable of renewing a signed attestation artifact with limited usage of a trusted platform module (TPM). Based on initiation of a cold boot of a host, attestation artifacts are received from the host. The attestation artifacts prove trust in a trusted execution environment (TEE) that runs on the host. The attestation artifacts include a public portion of an ephemeral cryptographic key (ECKeyPub), a public portion of a signing key (SKeyPub), and a signed key claim. The attestation artifacts are validated, and a signed attestation artifact, which includes the ECKeyPub and the SKeyPub, is generated and provided to the host. Based on a request to renew the signed attestation artifact including the signed attestation artifact, which includes the ECKeyPub and the SKeyPub, and further based on the TEE possessing the ephemeral cryptographic key, the signed attestation artifact is renewed during the cold boot session.


