TPM Key Usage Tracking via PCR Sealing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key protection mechanisms, such as those using Trusted Platform Modules (TPMs), face challenges in securely managing repeat-use keys, as making the original key available in plain form is undesirable, and re-encrypting it merely adds obfuscation without effective protection.
Innovation Solution
A TPM-based system that encrypts a key using an encryption key sealed against platform configuration registers (PCRs), allowing the key to be unsealed only when the PCR values match expected access states, and repeatedly resealing the encryption key with each access to track usage and detect unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the original key is made available in plain form for repeat use, then the key can be accessed multiple times, but the security protection is compromised
Solution Approach 1:
The key is segmented into an encrypted form stored in secure storage and an encryption key sealed against PCRs. This segmentation allows the key material to remain protected while enabling controlled access through the sealing mechanism, resolving the contradiction between accessibility and security.
Solution Approach 2:
The encryption key acts as an intermediary between the sealed key material and the plaintext key. It enables controlled decryption only when PCR conditions are met, providing a middle ground that allows repeat access while maintaining security through the sealing constraint.
2Reliability
If re-encryption is applied to protect the key, then obfuscation is added, but effective protection is not achieved
Solution Approach 1:
Instead of repeatedly re-encrypting the key, the system creates a sealed copy of the encryption key against PCRs. This sealed copy can be unsealed only when PCR conditions match, providing effective protection without the complexity of repeated re-encryption operations.
Solution Approach 2:
The system changes the protection parameter from dynamic re-encryption to static sealing against immutable PCR values. This transformation provides stronger protection with less complexity by leveraging the inherent security properties of PCR immutability and the sealing mechanism.
3Reliability
If the key is sealed against PCRs with strict matching requirements, then security is improved, but access flexibility is reduced
Solution Approach 1:
The system introduces dynamic access control by allowing PCR values to be extended with authorized access information. This enables flexible access policies where different authorized entities can be granted access under different PCR conditions, maintaining security while improving adaptability.
Solution Approach 2:
The sealing mechanism serves multiple functions: it provides security through PCR matching, enables repeat access for authorized entities, and supports access tracking. This multi-functionality resolves the contradiction by making the strict matching requirement work in favor of both security and flexibility.
4Reliability
If usage tracking is implemented through repeated resealing, then unauthorized access detection is improved, but operational overhead increases
Solution Approach 1:
The system implements feedback by extending PCRs with access count information during each authorized access. This creates a natural tracking mechanism where the PCR state reflects usage history, enabling unauthorized access detection without separate tracking operations and minimizing overhead.
Solution Approach 2:
The system merges the access control function with the usage tracking function by combining authorization verification and access counting into a single PCR extension operation. This integration eliminates separate tracking overhead while maintaining both security and detection capabilities.
Data Source
AI summary
Disclosed systems and methods implement a tracking system that tracks accesses to a TPM-secured key. In embodiments, the key may be encrypted using an encryption key, which is sealed using the TPM. A first value indicating an initial access state of the key is stored in a PCR of the TPM, and the encryption key is sealed against the PCR, so that it can be unsealed when contents of PCR match a next value derived from the first value. When the key is accessed, contents of the PCR is verified against an expected access state. If successfully verified, the PCR is extended hold the next value, the encryption key is unsealed, and the key decrypted. With each access, the encryption key is repeatedly resealed against the successive states stored in PCR. In this manner, the PCR may be used to track accesses and detect unauthorized accesses to the key.


