Trusted Computing Group Platform Registers Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing TPM2 specifications are insufficient to support secure booting in mobile devices, as they require rigid preconditions for PCR value updates, leading to a setup where all certifications must be done in advance, which is not consistent with the original secure boot architecture that delegates signing rights during device integration.
Innovation Solution
The implementation of two platform configuration registers, a measurement PCR and a resettable binding PCR, allows for a posteriori delegation of components in the secure boot path, where the authorization chain is executed under a trusted engine, and the binding PCR is extended with a value enforced by the authorization, with a trusted OS monitoring the validation result to update the measurement PCR accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rigid preconditions are required for PCR value updates in TPM2, then authorization security is improved, but device integration flexibility deteriorates
Solution Approach 1:
The patent divides the PCR update mechanism into two separate PCRs: a measurement PCR that records integrity measurements and a binding PCR that enforces authorization preconditions. This segmentation allows the measurement PCR to maintain strict security requirements while the binding PCR provides flexible authorization management, resolving the contradiction between security and flexibility.
Solution Approach 2:
The binding PCR acts as an intermediary between the authorization system and the measurement PCR. It receives authorization decisions and translates them into precondition constraints, mediating between the need for secure authorization and the need for flexible device integration. The binding PCR extends with authorization-enforced values while the measurement PCR records actual measurements, allowing decoupled operation.
2Reliability
If all certifications must be done in advance, then authorization validation is improved, but setup complexity deteriorates
Solution Approach 1:
The system performs preliminary actions by setting up the binding PCR with authorization-enforced values before device integration. The binding PCR is extended with values that must be satisfied before any measurement PCR updates are allowed. This preliminary setup simplifies subsequent operations by establishing clear precondition boundaries before the actual certification process begins.
Solution Approach 2:
The patent introduces dynamic authorization where the binding PCR can be extended with different values based on authorization decisions made during device integration. Rather than requiring all certifications to be predetermined, the system dynamically adjusts the binding PCR based on real-time authorization results, reducing setup complexity while maintaining validation reliability.
3Reliability
If PCR values are tightly bound to authorization, then integrity protection is improved, but adaptability to different devices deteriorates
Solution Approach 1:
The patent segments the PCR functionality into measurement PCR and binding PCR, allowing different devices to have different binding PCR values while maintaining consistent integrity protection through the measurement PCR. Each device can be configured with device-specific binding values without compromising the universal integrity measurement mechanism.
Solution Approach 2:
The system allows parameter changes in the binding PCR values to adapt to different devices while maintaining the same integrity protection mechanism. The binding PCR can be extended with device-specific authorization values, and the measurement PCR continues to record integrity measurements using consistent parameters, enabling adaptability without sacrificing integrity protection.
Data Source
AI summary
Disclosed is a method that includes providing at least two platform configuration registers, where a first platform configuration register is a measurement platform configuration register and where a second platform configuration register is a resettable binding configuration platform configuration register. The method further includes during an authorization of a device, such as a mobile device, including a value of the measurement platform configuration register as a precondition and extending the binding platform configuration register with a value enforced by the authorization. The method further includes monitoring a validation result of the binding platform configuration register. If the validation result indicates success then the measurement platform configuration register can be extended with a reference value, while if the validation result instead indicates a failure then the measurement platform configuration register can be extended with a predetermined error value. Apparatus and computer program instructions that implement the method are also disclosed.


