Trusted Computing Base Attestation with Quantified Size

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face challenges in securely managing and verifying the size of their trusted computing base (TCB), which is crucial for attestation processes, as current methods do not effectively quantify and communicate the size of secure computing environments, impacting security and trust verification.

Innovation Solution

The proposed solution involves a measurement generator that calculates and communicates the cumulative size of TCB components during attestation, using a compound device identifier (CDI) and trusted computing base component identifier (TCI) through hash functions, incorporating the size of binary code as an additional parameter, compatible with existing standards like DICE and TPM.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the TCB size is increased to improve security coverage, then the security trustworthiness is improved, but the system complexity and verification difficulty increase

Engineering Contradiction:
Improvesecurity trustworthinessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the TCB into multiple discrete components, each with its own identifier. This allows the large TCB to be divided into manageable parts that can be individually measured and verified, reducing the complexity of verifying the entire TCB at once while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of measurement by incorporating TCB size (in bytes) as an additional parameter alongside traditional cryptographic measurements. This quantitative size metric provides a new way to assess and verify TCB trustworthiness without requiring complex analysis of the entire system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If traditional attestation methods are used without size quantification, then the attestation process is simple, but the security verification is incomplete

Engineering Contradiction:
Improvesecurity verification completenessVSAvoidattestation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces compound device identifiers (CDIs) as intermediary measurements that combine traditional cryptographic measurements with TCB size information. These CDIs serve as mediators that encapsulate complex size verification into a single verifiable parameter, completing security verification without exposing the underlying complexity of the attestation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the TCB size is not quantified, then the attestation format is simple, but the risk assessment capability is limited

Engineering Contradiction:
Improverisk assessment capabilityVSAvoidTCB size information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent performs preliminary measurement of TCB component sizes and incorporates this information into compound device identifiers before the attestation process. By pre-calculating and embedding size information into the CDI structure, the system enables comprehensive risk assessment without requiring complex real-time analysis during attestation.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enhances the security and trust verification of computing systems by quantifying the TCB size, allowing for better risk assessment and trustworthiness evaluation, thereby improving the overall security of the computing environment.

Implementation Method 1

calculates and communicates the cumulative size of TCB components during attestation, using a compound device identifier (CDI) and trusted computing base component identifier (TCI) through hash functions

Methodology Applied
Scientific EffectHash function:

Data Source

PatentUS11741224B2Attestation with a quantified trusted computing base
Publication Date: 2023.08.29 INTEL CORP
  • US11741224B2 patent drawing
  • US11741224B2 patent drawing
  • US11741224B2 patent drawing

AI summary

An apparatus and method include generating a trusted computing base (TCB) component identifier (TCI) of a current component of a computing system, generating a compound device identifier (ID) (CDI) of the current component from a CDI of a previous component of the computing system and the TCI of the current component, and determining a size of the TCI of the current component. The system and method further include summing the size of the TCI of the current component and the cumulative size of the TCIs of previous components of the computing system to generate a current cumulative size, combining the current cumulative size and the CDI of the current component, and including the combined current cumulative size and the CDI of the current component in a chain of measurements for attestation of the computing system.