TPM Trust Status Determination Without Remote Attestation Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The flexibility of determining the trust status of a Trusted Platform Module (TPM) is limited as it requires a pre-deployed remote attestation server, which restricts the ability of any verifier to assess the TPM's trust status independently.
Innovation Solution
A method where a verifier can determine the TPM's trust status by sending an unsealing request to the host, which seals and unseals PCR values using a seal key handle and verification keys on an encrypted channel, eliminating the need for a pre-deployed remote attestation server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a pre-deployed remote attestation server is used to determine TPM trust status, then the trust status can be determined through centralized verification, but the flexibility of determining trust status deteriorates because any verifier cannot independently assess the TPM status
Solution Approach 1:
The patent extracts the trust status determination capability from the centralized remote attestation server and embeds it directly into the TPM device. The TPM now contains sealing and unsealing functions that allow any verifier to independently determine trust status by unsealing PCR values, eliminating the mandatory dependency on a pre-deployed remote attestation server while maintaining reliable verification.
2Reliability
If a remote attestation server is deployed independently, then trust status verification can be performed, but the system complexity increases due to the need for separate server infrastructure
Solution Approach 1:
The patent merges the trust status verification functionality into the TPM device itself by integrating sealing and unsealing capabilities. Instead of requiring a separate remote attestation server infrastructure, the TPM can directly seal PCR values during initialization and allow any verifier to unseal and check them, thereby reducing system infrastructure complexity while maintaining verification reliability.
3Reliability
If PCR values are sealed during host initialization with encrypted verification keys, then security is improved, but the operation complexity increases due to the sealing and unsealing process
Solution Approach 1:
The patent applies preliminary action by sealing the PCR values and embedding the encrypted verification key during the host initialization phase. This preliminary sealing operation ensures that the trust status data is securely protected from the outset. During verification, any verifier can simply perform an unsealing operation without needing to understand the complex encryption processes, thus maintaining ease of operation while ensuring security.
Data Source
AI summary
Various embodiments provide a method and an apparatus for determining a trust status of a TPM, and a storage medium, and pertains to the field of data security technologies. In those embodiments, a verifier send an unsealing request to a host, so that the host unseals current PCR values in the TPM based on a seal key handle carried in the unsealing request, and sends verification information to the verifier based on the unseal verification key obtained after the unsealing. Therefore, any verifier that establishes an encrypted channel with the host can determine the trust status of the TPM in the host based on a second verification key transmitted on the encrypted channel, and there is no need to pre-deploy a remote attestation server to determine the trust status of the TPM.


