Trusted Entity Labeling for Simplified Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information security systems are complex and costly to maintain, requiring a complex online infrastructure and individual application development for security features, leading to increased complexity and risk of security compromise.
Innovation Solution
A computer system with a trusted entity and labels that indicate the presence or potential presence of a predetermined software state, allowing for simplified security management by reducing the number of secrets and eliminating the need for extensive PKI infrastructure, enabling secure access to computing resources and services without complex gatekeeper mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional PKI infrastructure and secret distribution systems are used, then security authentication and authorization can be achieved, but system complexity and maintenance costs increase significantly
Solution Approach 1:
The patent extracts the security verification function from the complex PKI infrastructure and implements it directly within the trusted computing platform. The platform self-attests its software state through internal measurement and verification mechanisms, eliminating the need for external certificate authorities and complex secret distribution systems.
Solution Approach 2:
The trusted computing platform performs self-attestation by automatically measuring its own software state and generating verification evidence without external intervention. The platform independently verifies its integrity through internal trusted paths, reducing dependency on external security infrastructure.
2Reliability
If multiple secrets are distributed and stored for each user/application pair, then access control can be enforced, but the complexity of managing authorization information increases rapidly
Solution Approach 1:
The patent changes the fundamental parameter of security verification from checking multiple distributed secrets to verifying the software state of the platform. Instead of managing numerous authorization tokens and certificates, the system verifies whether the platform's measured state matches expected security states, dramatically reducing management complexity.
Solution Approach 2:
The software state verification mechanism serves multiple security functions simultaneously: authentication, authorization, and integrity verification. A single verification process replaces multiple secret-checking mechanisms, providing universal security coverage across different access control scenarios.
3Adaptability or versatility
If security functions are distributed across individual applications, then applications can have customized security, but the number of security mechanisms increases and risk of poor construction increases
Solution Approach 1:
The patent segments security functions into two layers: platform-level trusted execution environment that provides core security capabilities, and application-level policies that define security requirements. This segmentation allows applications to specify security needs without implementing security mechanisms themselves.
Solution Approach 2:
The trusted computing platform acts as an intermediary between applications and the underlying hardware/security infrastructure. Applications interact with the platform's attestation interface rather than directly managing cryptographic secrets or security protocols, simplifying application development while maintaining security.
Data Source
AI summary
An information security system is disclosed having a considerably simplified access control infrastructure. The number of secrets in a computer system domain is reduced to a minimum, yet individual users may still be identified and access to applications may still be individually controlled. The trusted entity in each of a plurality of platforms (100, 200, 202, 203) of the computer system may store an identity secret of the platform (100, 200, 202, 203) and may be trusted to use that secret in conjunction with an information label only when the platform (100, 200, 202, 203) is running the correct software to provide and/or take part in a particular service associated with that information label.


