Sharing TPM Integrity Values Across Dual-Environment OS Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Dual-environment computing devices face challenges in sharing a common integrity security module, as existing TPMs measure environment-specific metrics, leading to inconsistencies when switching between operating environments, which can result in unrecognized environments and restricted access.

Innovation Solution

A method and apparatus that utilize a detection module to identify power state transitions and a regeneration module to regenerate integrity values from a stored integrity metric log, allowing two operating environments to share a single TPM by storing and replaying PCR digest values, ensuring accurate integrity measurements across environment switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single TPM is shared between two operating environments, then device complexity is reduced and resource utilization is improved, but integrity measurement consistency deteriorates due to environment-specific metric mismatches

Engineering Contradiction:
Improvenumber of integrity security modulesVSAvoidintegrity measurement consistency
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the integrity measurement process by creating separate integrity metric logs for each operating environment. The TPM maintains distinct measurement records (PCR values) that are specific to each environment, allowing environment-specific integrity verification while sharing the same physical TPM hardware. This resolves the contradiction by enabling one TPM to reliably serve multiple environments through logical segmentation of measurement data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by detecting power state transitions before they occur and proactively regenerating integrity values in advance. The system monitors for transitions between operating environments and pre-regenerates the appropriate integrity metrics before the actual environment switch, ensuring that correct integrity values are ready when needed, thus maintaining measurement consistency across environment changes.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If integrity values are regenerated during power state transitions, then integrity measurement accuracy is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improveintegrity measurement accuracyVSAvoidinitialization sequence duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary detection of power state transitions and initiates integrity value regeneration before the actual environment switch completes. By detecting the transition early in the initialization sequence and starting regeneration proactively, the system minimizes the impact on boot time while ensuring accurate integrity measurements are ready when the new environment becomes active.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by regenerating integrity values from stored templates or previous measurements rather than performing complete integrity assessments from scratch. The system copies and adapts existing integrity metric structures, filling in environment-specific details, which significantly reduces processing time compared to full integrity verification while maintaining measurement accuracy.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8943329B2Method and apparatus for sharing an integrity security module in a dual-environment computing device
Publication Date: 2015.01.27 LENOVO (SINGAPORE) PTE LTD
  • US8943329B2 patent drawing
  • US8943329B2 patent drawing
  • US8943329B2 patent drawing

AI summary

A method and apparatus are disclosed for sharing an integrity security module in a dual-environment computing device. The apparatus include an integrity security module, one or more processors, a detection module and a regeneration module. The one or more processors may have access to the integrity security module and may operate in two distinct operating environments of a dual-environment computing device. The detection module may detect, during an initialization sequence, a power state transition of an operating environment of the dual-environment computing device. The regeneration module may regenerate one or more integrity values from a stored integrity metric log in response to detecting the power state transition of the operating environment of the dual-environment computing device.