TPM Authorization Principals for OS Context Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computers are vulnerable to attacks such as dictionary and brute force attacks on passwords and personal identification numbers, leading to reduced user trust and security concerns.
Innovation Solution
The representation of operating system context in a trusted platform module using authorization principals, which are derived and bound to security assets, enhances system security by characterizing and controlling access to security assets based on operating system attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwords or personal identification numbers are used for data protection, then users can access their data, but computers become vulnerable to dictionary attacks or brute force attacks
Solution Approach 1:
The patent introduces an authorization principal as an intermediary between the user and security assets. Instead of directly using passwords, the system derives authorization principals from operating system context (process IDs, user IDs, group IDs) that serve as mediators for access control. This intermediary layer prevents direct exposure of passwords to attackers while maintaining user access capability.
Solution Approach 2:
The patent replaces the mechanical password-based authentication system with a context-based authorization system. Rather than relying on users to remember and input passwords (mechanical interaction), the system automatically derives authorization principals from operating system context attributes, substituting the manual password entry mechanism with automated context-based authentication that is resistant to dictionary and brute force attacks.
2Reliability
If a trusted platform module is used to store security assets, then system security is improved, but device complexity increases
Solution Approach 1:
The patent makes the trusted platform module universal by enabling it to handle multiple security functions: storing security assets, deriving authorization principals from various operating system context attributes, and enforcing access policies. This multi-functionality reduces the need for separate security modules for different purposes, thereby limiting the increase in device complexity while maintaining enhanced security.
Solution Approach 2:
The patent implements nesting by integrating the authorization principal derivation functionality within the trusted platform module itself. The TPM contains nested components including security asset storage, context attribute processing units, and authorization policy enforcement mechanisms, all housed within the single TPM hardware boundary. This nested structure consolidates multiple security functions into one module rather than requiring separate hardware components.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques for representation of operating system context in a trusted platform module are described. In at least some embodiments, authorization principals that correspond to representations of operating system context are derived in a trusted platform module. The authorization principals can be used to define authorization policies for access to security assets stored in a trusted platform module.