Trusted Computing Entity Hash Agility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing trusted computing systems face challenges in maintaining data integrity over time due to the vulnerabilities of security algorithms used for hashing, which can become less effective with heavy use and study, compromising the integrity of recorded data.
Innovation Solution
Implementing a trusted computing platform with a TPM that supports multiple cryptographic algorithms, allowing data owners to specify permissible algorithms for use and maintaining a history and forbidden list to ensure compatibility with trusted environments, enabling hash agility and migration from compromised algorithms to secure ones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single hashing algorithm is used for producing digests in a trusted computing system, then the system operates with simple and consistent integrity verification, but the security effectiveness deteriorates over time as the algorithm becomes vulnerable through heavy use and study
Solution Approach 1:
The system dynamically selects which hashing algorithm to use based on the current security environment and threat landscape. The TPM can switch between multiple hashing algorithms (e.g., SHA-1, SHA-256, SHA-3) depending on which algorithms are currently considered secure, allowing the system to adapt to evolving cryptographic threats while maintaining data integrity verification.
Solution Approach 2:
The system changes the cryptographic parameters by supporting multiple hashing algorithm options rather than being fixed to a single algorithm. This allows the trusted computing system to modify its security parameters over time, transitioning from vulnerable algorithms to more secure alternatives as cryptographic weaknesses are discovered.
2Adaptability or versatility
If multiple cryptographic algorithms are supported in the TPM, then the system gains adaptability and hash agility to migrate from compromised algorithms, but the device complexity increases
Solution Approach 1:
The TPM is designed with multi-functionality to support multiple hashing algorithms within a single device. This universal capability allows the same hardware module to perform integrity verification using different cryptographic algorithms, providing hash agility without requiring separate dedicated hardware for each algorithm.
Solution Approach 2:
The system introduces an intermediary layer (the multi-algorithm TPM and associated software stack) that manages the complexity of multiple cryptographic algorithms. This intermediary handles algorithm selection, switching, and coordination, shielding the rest of the trusted computing system from the underlying complexity while providing adaptability.
3Ease of operation
If security algorithms are heavily used and studied, then the security mechanisms are well-understood and standardized, but security vulnerabilities emerge over time compromising data integrity
Solution Approach 1:
The system implements periodic reassessment and rotation of hashing algorithms. Instead of relying indefinitely on a single standardized algorithm, the trusted computing system periodically evaluates the security status of its algorithms and transitions to new standards, preventing long-term exposure to discovered vulnerabilities while maintaining operational simplicity through established cryptographic practices.
Data Source
AI summary
The present invention relates to trust in computing platforms and the like. In particular, embodiments of the invention provide a trusted computing entity (64), providing an environment comprising one or more of a set or sets of available security algorithms (62), the entity (64) being adapted to operate on data (702), which data has associated security criteria (704), only if the environment meets the associated security criteria.


