Trusted Computing Device for Environment Trustworthiness Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The conflict between security and ease of use in computing platforms, particularly in e-commerce, where transactions are vulnerable to modifications and users are concerned about the trustworthiness of remote or unfamiliar data processing environments, necessitates a method to ascertain the status of devices within these environments.

Innovation Solution

A trusted computing device challenges other devices within the environment, records their responses, and maintains a log of integrity metrics to determine trustworthiness, allowing users to verify the security and facilities available without individually challenging each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a trusted computing device challenges and records responses from all devices in the environment, then security and trustworthiness assessment is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvetrustworthiness assessmentVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A trusted computing device acts as an intermediary between user devices and other devices in the data processing environment. The trusted device receives challenge requests from user devices, performs the challenge-response verification with target devices, and returns the verification results. This intermediary approach improves security assessment while reducing the operational overhead on individual user devices, as they only need to communicate with the trusted device rather than directly challenging each device in the environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If users verify each device individually through challenge-response protocols, then measurement precision of device integrity is improved, but time consumption and productivity decrease

Engineering Contradiction:
Improvedevice integrity verificationVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The trusted computing device performs preliminary challenge-response verification with devices in the data processing environment before users need to access them. The trusted device maintains an updated record of verified devices and their integrity status, so when users need to interact with devices, the verification work has already been done in advance. This eliminates the need for users to perform time-consuming individual verification while maintaining precise integrity measurement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of requiring users to verify every single device they might interact with, the system performs verification on a selective basis through the trusted computing device. The trusted device challenges devices based on predefined criteria and maintains a record of verified devices, allowing users to rely on this pre-performed verification rather than conducting exhaustive checks themselves. This partial verification approach maintains security while significantly reducing time consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security applications are installed on computing platforms, then protection against viruses and malicious users is improved, but the assumption that the platform operates as intended becomes vulnerable

Engineering Contradiction:
Improveprotection against threatsVSAvoidtrust in platform operation
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The trusted computing device serves as an intermediary that verifies the integrity of the computing platform itself through challenge-response protocols. Rather than trusting the platform to operate as intended, the trusted device actively challenges the platform and verifies its responses. This approach maintains protection against threats while restoring trust, as the verification is performed by an independent trusted entity rather than relying on self-reported platform integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8219496B2Method of and apparatus for ascertaining the status of a data processing environment
Publication Date: 2012.07.10 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8219496B2 patent drawing
  • US8219496B2 patent drawing
  • US8219496B2 patent drawing

AI summary

In order to facilitate a user's ability to trust a computing environment, a trusted computing device (2) is arranged to challenge other devices in the computing environment and to record a log of the facilities available within the computing environment and an indication of whether those facilities are trustworthy. A new user (40) entering the computing environment can obtain the log from the trusted computing device in order to ascertain the status of the environment. Alternatively any device can hold data concerning platforms in its vicinity and its operation can be authenticated by the trusted device.