Information Terminal PCR Reference Value Management for Secure Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Trusted Computing Group (TCG) technology faces issues with decrypting sealed data and providing information services when program data is updated, as the Trusted Platform Module (TPM) cannot decrypt data sealed with a previous PCR value, and updating the PCR reference value on the service provider's server is not synchronized with the program data updates, leading to safety concerns and service disruptions.

Innovation Solution

An information terminal with an update certificate system that includes old and new characteristic values, allowing the terminal to judge whether the current program matches the new program and use the old characteristic value to remove data use restrictions, ensuring the new program can access data as before the update without returning to a vulnerable state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the program data is updated to improve security and functionality, then the reliability is improved, but the sealed data cannot be decrypted and service continuity is lost

Engineering Contradiction:
Improveprogram data securityVSAvoiddata access compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by storing multiple PCR reference values (first and second reference values) in advance in the storage unit. When a program update occurs, the system can switch to using the second reference value that was pre-prepared for the updated program, allowing seamless decryption without requiring real-time PCR value generation or service interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements parameter changes by allowing the PCR reference value to change from the first reference value (for old program) to the second reference value (for new program). The judgment unit dynamically selects which reference value to use based on whether the current program matches the old or new program, enabling the system to adapt to different program versions while maintaining decryption capability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the PCR reference value is updated on the service provider's server to match the new program, then the service authentication is improved, but the synchronization timing creates security gaps

Engineering Contradiction:
Improveservice authentication accuracyVSAvoidsynchronization delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent eliminates synchronization delays by performing preliminary action - the second PCR reference value is stored in advance in the terminal's storage unit before the program update occurs. This pre-stored reference value is immediately available when the updated program needs to access sealed data, removing any waiting time for server synchronization and eliminating the security gap that would exist during update transitions.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system requires exact match between PCR value and reference value for decryption, then the security is improved, but the system cannot adapt to program updates

Engineering Contradiction:
Improvedecryption securityVSAvoidprogram version compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the PCR reference value dynamic rather than static. The judgment unit dynamically selects between the first reference value (for old program) and the second reference value (for new program) based on program identification. This dynamic adaptation allows the system to maintain strict security verification (exact match required) while accommodating different program versions through appropriate reference value selection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by allowing the PCR reference value parameter to change based on the program version. When the program is updated, the system transitions from using the first reference value to the second reference value. This parameter change enables the system to maintain security through exact matching while adapting to different program versions by using the appropriate reference value for each version.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If the system stores multiple PCR reference values for different program versions, then the adaptability is improved, but the device complexity increases

Engineering Contradiction:
Improvemulti-version program supportVSAvoidstorage and judgment mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the reference value management into distinct segments - the first PCR reference value for the old program and the second PCR reference value for the new program. The judgment unit segments the decryption process by first determining which program version is running, then selecting the corresponding reference value segment. This segmentation approach manages complexity by organizing multiple reference values into clearly defined, separately managed groups rather than requiring a complex unified management system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8392724B2Information terminal, security device, data protection method, and data protection program
Publication Date: 2013.03.05 PANASONIC HOLDINGS CORP
  • US8392724B2 patent drawing
  • US8392724B2 patent drawing
  • US8392724B2 patent drawing

AI summary

An information terminal that decrypts sealed data without returning program data after update to the state before update. The information terminal includes update certificate storage unit storing an update certificate for certifying update of the program data to be executed by CPU, and a selection unit which, when the CPU is to execute program data, judges whether or not digest of the post-update program data in the update certificate matches digest of the program data to be executed, and selects digest of the pre-update program data in the update certificate when it judges that they match. The CPU executes the post-update program data. The information terminal further includes a security device that stores an extend value of a program data digest when the pre-update program data is executed by the CPU according to a request from the selection unit.