Trusted Platform Module Secure Boot PCR Sealing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems are vulnerable during the boot process, as security features like Encrypted File System (EFS) and Trusted Platform Module (TPM) are ineffective in protecting data before user login and are susceptible to rogue code loading, and machine password authentication is cumbersome and insecure.
Innovation Solution
The use of a Trusted Platform Module (TPM) to securely boot a computer by sealing secrets to platform configuration register (PCR) values, ensuring that only correct measurements unseal secrets for proper system boot, and implementing a secure boot process that revokes access to resources after boot to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security features like EFS and TPM are used to protect data, then data security is improved, but these features are ineffective during boot process before user login
Solution Approach 1:
The patent applies preliminary action by sealing secrets to PCR values before the boot process begins. The TPM binds secrets to specific measurements of boot components, ensuring that these secrets can only be accessed after verified trusted code executes. This pre-establishes security controls that remain effective throughout the boot process, eliminating the vulnerability window that exists in conventional systems where security features are inactive before user login.
2Reliability
If logon procedure is used to protect access to keys, then key access security is improved, but rogue code loaded during boot can bypass this protection
Solution Approach 1:
The patent introduces the TPM as an intermediary between the boot process and secret access. Instead of relying solely on the operating system's logon procedure, the TPM acts as a hardware-based mediator that verifies boot component integrity through PCR measurements before releasing secrets. This intermediary layer prevents rogue code from bypassing security, as the TPM will not release secrets unless the measured boot components match the expected trusted values.
Solution Approach 2:
The system performs preliminary verification of boot component integrity by measuring components and comparing against expected values stored in the TPM before allowing secret access. This pre-authentication mechanism ensures that only trusted boot loaders and operating system components can access secrets, blocking rogue code before it can establish control.
3Reliability
If TPM seals secrets to PCR values to ensure integrity, then trustworthiness of software is improved, but access to secrets is restricted to specific boot states
Solution Approach 1:
The patent implements dynamic secret accessibility by allowing the system to transition between different secret states based on boot verification outcomes. During trusted boot, the system accesses secrets sealed to specific PCR values. If boot components are verified as trusted, the TPM releases the appropriate secrets for system operation. This dynamic approach maintains both security and operational flexibility, as secret access adapts to the actual trust state of the running system.
Data Source
AI summary
In a computer with a trusted platform module (TPM), an expected hash value of a boot component may be placed into a platform configuration register (PCR), which allows a TPM to unseal a secret. The secret may then be used to decrypt the boot component. The hash of the decrypted boot component may then be calculated and the result can be placed in a PCR. The PCRs may then be compared. If they do not, access to the an important secret for system operation can be revoked. Also, a first secret may be accessible only when a first plurality of PCR values are extant, while a second secret is accessible only after one or more of the first plurality of PCR values has been replaced with a new value, thereby necessarily revoking further access to the first secret in order to grant access to the second secret.


