TPM Secure Boot Recovery and Update Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure boot processes with Trusted Platform Modules (TPM) lack effective mechanisms for maintenance and updates, making them vulnerable during the boot process, as security features are not initialized until after boot, leaving them susceptible to tampering and bypass.

Innovation Solution

The system and methods for maintaining and updating a secure boot process involve inspecting TPM activity logs to recover from boot failures, authenticating users to bypass security features, and migrating TPM sealed secrets to temporary storage for updates, ensuring the secure resealing of secrets to new platform configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security features are enabled during boot process, then system security is improved, but the system becomes vulnerable to tampering before security features are initialized

Engineering Contradiction:
Improvesystem securityVSAvoidsusceptibility to tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by implementing a secure boot process that validates and measures boot components before the operating system security features are initialized. The TPM (Trusted Platform Module) performs measurements of boot components and stores them in PCRs (Platform Configuration Registers) before the OS security features become active, ensuring that the boot process is secured in advance rather than relying on post-boot security mechanisms.

Inventive Principle:
Principle #10Preliminary action

2Ease of repair

If TPM sealed secrets are updated, then boot process maintainability is improved, but the risk of security compromise during update increases

Engineering Contradiction:
Improveboot process maintainabilityVSAvoidsecurity integrity
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The patent uses an intermediary approach by introducing a secure update mechanism that involves measuring and validating update components through the TPM before applying updates. The update process uses PCR measurements and sealed secrets to ensure that only authenticated updates are applied, with the TPM acting as an intermediary that verifies the integrity of update components before allowing them to modify the boot process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The update mechanism performs preliminary validation of update components by measuring them through the TPM and verifying their authenticity before actually applying the updates. This ensures that the boot process maintainability is improved while security integrity is preserved through pre-update verification.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure boot process is made more resilient to failures, then system availability is improved, but the complexity of the boot process increases

Engineering Contradiction:
Improveboot process resilienceVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms by logging TPM measurements and boot process states, and using this information to detect and recover from boot failures. The system monitors the boot process through PCR measurements and can identify when measurements diverge from expected values, enabling automated recovery actions or informed manual intervention while maintaining relatively simple implementation through structured logging and measurement comparison.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8028172B2Systems and methods for updating a secure boot process on a computer with a hardware security module
Publication Date: 2011.09.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8028172B2 patent drawing
  • US8028172B2 patent drawing
  • US8028172B2 patent drawing

AI summary

Systems and methods are provided for maintaining and updating a secure boot process on a computer with a trusted platform module (TPM). A boot process may be maintained by inspecting a log of TPM activity, determining data that prevented a secret to unseal, and returning the data to an original state. In situations where this type of recovery is not workable, techniques for authenticating a user may be used, allowing the authenticated user to bypass the security features of the boot process and reseal the boot secrets to platform configuration register (PCR) values that may have changed. Finally, a secure boot process may be upgraded by migrating TPM sealed secrets to a temporary storage location, updating one or more aspects of a secure boot process, and resealing the secrets to the resulting new platform configuration. Other advantages and features of the invention are described below.