Trusted Computing Entity Hash Agility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted computing systems face challenges in maintaining data integrity over time due to the vulnerabilities of security algorithms used for hashing, which can become less effective with heavy use and study, compromising the integrity of recorded data.

Innovation Solution

Implementing a trusted computing platform with a TPM that supports multiple cryptographic algorithms, allowing data owners to specify permissible algorithms for use and maintaining a history and forbidden list to ensure compatibility with trusted environments, enabling hash agility and migration from compromised algorithms to secure ones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single hashing algorithm is used for producing digests in a trusted computing system, then the system operates with simple and consistent integrity verification, but the security effectiveness deteriorates over time as the algorithm becomes vulnerable through heavy use and study

Engineering Contradiction:
Improvedata integrityVSAvoidalgorithm flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically selects which hashing algorithm to use based on the current security environment and threat landscape. The TPM can switch between multiple hashing algorithms (e.g., SHA-1, SHA-256, SHA-3) depending on which algorithms are currently considered secure, allowing the system to adapt to evolving cryptographic threats while maintaining data integrity verification.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the cryptographic parameters by supporting multiple hashing algorithm options rather than being fixed to a single algorithm. This allows the trusted computing system to modify its security parameters over time, transitioning from vulnerable algorithms to more secure alternatives as cryptographic weaknesses are discovered.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple cryptographic algorithms are supported in the TPM, then the system gains adaptability and hash agility to migrate from compromised algorithms, but the device complexity increases

Engineering Contradiction:
Improvehash agilityVSAvoidTPM complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The TPM is designed with multi-functionality to support multiple hashing algorithms within a single device. This universal capability allows the same hardware module to perform integrity verification using different cryptographic algorithms, providing hash agility without requiring separate dedicated hardware for each algorithm.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer (the multi-algorithm TPM and associated software stack) that manages the complexity of multiple cryptographic algorithms. This intermediary handles algorithm selection, switching, and coordination, shielding the rest of the trusted computing system from the underlying complexity while providing adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If security algorithms are heavily used and studied, then the security mechanisms are well-understood and standardized, but security vulnerabilities emerge over time compromising data integrity

Engineering Contradiction:
Improvealgorithm standardizationVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements periodic reassessment and rotation of hashing algorithms. Instead of relying indefinitely on a single standardized algorithm, the trusted computing system periodically evaluates the security status of its algorithms and transitions to new standards, preventing long-term exposure to discovered vulnerabilities while maintaining operational simplicity through established cryptographic practices.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8689318B2Trusted computing entities
Publication Date: 2014.04.01 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8689318B2 patent drawing
  • US8689318B2 patent drawing
  • US8689318B2 patent drawing

AI summary

The present invention relates to trust in computing platforms and the like. In particular, embodiments of the invention provide a trusted computing entity (64), providing an environment comprising one or more of a set or sets of available security algorithms (62), the entity (64) being adapted to operate on data (702), which data has associated security criteria (704), only if the environment meets the associated security criteria.