Trusted Computing Device for Environment Trustworthiness Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The conflict between security and ease of use in computing platforms, particularly in e-commerce, where transactions are vulnerable to modifications and users are concerned about the trustworthiness of remote or unfamiliar data processing environments, necessitates a method to ascertain the status of devices within these environments.
Innovation Solution
A trusted computing device challenges other devices within the environment, records their responses, and maintains a log of integrity metrics to determine trustworthiness, allowing users to verify the security and facilities available without individually challenging each device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a trusted computing device challenges and records responses from all devices in the environment, then security and trustworthiness assessment is improved, but device complexity and operational overhead increase
Solution Approach 1:
A trusted computing device acts as an intermediary between user devices and other devices in the data processing environment. The trusted device receives challenge requests from user devices, performs the challenge-response verification with target devices, and returns the verification results. This intermediary approach improves security assessment while reducing the operational overhead on individual user devices, as they only need to communicate with the trusted device rather than directly challenging each device in the environment.
2Measurement precision
If users verify each device individually through challenge-response protocols, then measurement precision of device integrity is improved, but time consumption and productivity decrease
Solution Approach 1:
The trusted computing device performs preliminary challenge-response verification with devices in the data processing environment before users need to access them. The trusted device maintains an updated record of verified devices and their integrity status, so when users need to interact with devices, the verification work has already been done in advance. This eliminates the need for users to perform time-consuming individual verification while maintaining precise integrity measurement.
Solution Approach 2:
Instead of requiring users to verify every single device they might interact with, the system performs verification on a selective basis through the trusted computing device. The trusted device challenges devices based on predefined criteria and maintains a record of verified devices, allowing users to rely on this pre-performed verification rather than conducting exhaustive checks themselves. This partial verification approach maintains security while significantly reducing time consumption.
3Reliability
If security applications are installed on computing platforms, then protection against viruses and malicious users is improved, but the assumption that the platform operates as intended becomes vulnerable
Solution Approach 1:
The trusted computing device serves as an intermediary that verifies the integrity of the computing platform itself through challenge-response protocols. Rather than trusting the platform to operate as intended, the trusted device actively challenges the platform and verifies its responses. This approach maintains protection against threats while restoring trust, as the verification is performed by an independent trusted entity rather than relying on self-reported platform integrity.
Data Source
AI summary
In order to facilitate a user's ability to trust a computing environment, a trusted computing device (2) is arranged to challenge other devices in the computing environment and to record a log of the facilities available within the computing environment and an indication of whether those facilities are trustworthy. A new user (40) entering the computing environment can obtain the log from the trusted computing device in order to ascertain the status of the environment. Alternatively any device can hold data concerning platforms in its vicinity and its operation can be authenticated by the trusted device.


