Trusted Computing Device Master Controller Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments, the increasing threat of hacking attacks necessitates continuous security patches, and existing trusted computing technologies face challenges in ensuring the integrity of authentication values for firmware-driven devices, which is crucial for security attestation.

Innovation Solution

A trusted computing device with a master controller that generates and checks authentication values using an authentication value generator and repository, and a security core that blocks external access, ensuring integrity through periodic checks by an integrity checker, and reset by an attack detector when integrity is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication values are stored in a accessible repository for security attestation, then security verification capability is improved, but integrity and protection against unauthorized access deteriorates

Engineering Contradiction:
Improvesecurity attestation capabilityVSAvoidunauthorized access and integrity compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the master controller into distinct functional modules: an authentication value generator for creating authentication values, an authentication value repository for secure storage, a security core for access control, and an integrity checker for verification. This segmentation allows each component to perform its specific function while maintaining overall system security and integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security core acts as an intermediary between the authentication value repository and external systems. It mediates all access requests to the authentication values, ensuring that only authorized operations can read or modify these critical security parameters, thereby preventing unauthorized access while maintaining availability for security attestation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity checks are performed continuously to ensure security, then reliability is improved, but processing time and system overhead increase

Engineering Contradiction:
Improveintegrity verificationVSAvoidprocessing time for integrity checks
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The integrity checker performs integrity verification at specific periodic intervals rather than continuously. This periodic action maintains security reliability by regularly verifying authentication values while reducing processing time and system overhead compared to continuous monitoring, allowing the system to balance security requirements with performance considerations.

Inventive Principle:
Principle #19Periodic action

3Object-affected harmful factors

If security patches are applied continuously to prevent hacking attacks, then security is improved, but system stability and operational continuity deteriorate

Engineering Contradiction:
Improvehacking attack protectionVSAvoidsystem operational continuity
Core Design Contradiction:
Object-affected harmful factorsVSStability of the object's composition

Solution Approach 1:

The system generates and stores authentication values in advance using the authentication value generator, and the security core is pre-configured with access control mechanisms. This preliminary action allows the system to be ready for security attacks without requiring continuous patching or modification of operational firmware, thereby maintaining security while preserving system stability and operational continuity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12074983B2Trusted computing device and operating method thereof
Publication Date: 2024.08.27 SAMSUNG ELECTRONICS CO LTD
  • US12074983B2 patent drawing
  • US12074983B2 patent drawing
  • US12074983B2 patent drawing

AI summary

A trusted computing device and an operating method thereof are provided. Provided is a trusted computing device including, a device driven by firmware, and a master controller generating an authentication value from the firmware and checking integrity for the authentication value at a first period, wherein the master controller includes, an authentication value generator generating the authentication value, an authentication value repository storing the authentication value, a security core blocking access from the outside with respect to the authentication value stored in the authentication value repository, and an integrity checker checking integrity for the authentication value stored in the authentication value repository.