Trusted Platform Integrity Measurement Extension via Policy Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Trusted computing platforms face challenges in efficiently managing integrity metrics and enforcing policies due to limitations in existing hardware trusted components, which can lead to increased costs and resource inefficiencies, particularly in mobile environments.
Innovation Solution
The implementation of an external policy engine that delegates policy enforcement responsibilities, allowing for the use of software-based solutions to perform complex policies without requiring additional resources within the trusted device, thereby maintaining cost-effectiveness and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated commands are used in a trusted environment, then security and reliability are improved, but device complexity and cost increase
Solution Approach 1:
The patent replaces dedicated security commands with generalised commands that can perform multiple functions. The trusted component uses a universal command interface that can handle both security-critical operations and general computing tasks, reducing device complexity while maintaining security through software-based policy enforcement rather than hardware-specific dedicated commands.
Solution Approach 2:
The patent introduces a measurement agent as an intermediary layer between the trusted component and the external environment. This agent handles complex policy enforcement and measurement tasks, allowing the trusted component to use simpler generalised commands while maintaining high security through the intermediary's sophisticated logic and policy verification capabilities.
2Adaptability or versatility
If more functions are added to trusted components, then adaptability and versatility are improved, but manufacturing cost increases
Solution Approach 1:
The trusted component is designed with a universal command set that can perform multiple functions including integrity measurement, policy enforcement, and various security operations. This multi-functional approach allows the same hardware to adapt to different security requirements without requiring additional dedicated hardware for each function, thereby maintaining cost-effectiveness while improving versatility.
Solution Approach 2:
The patent uses software-based policy engines and configurable measurement agents that can be modified through parameter changes rather than hardware modifications. This allows the trusted component to adapt to different security policies and requirements by changing software parameters and configurations, providing high adaptability without increasing manufacturing costs.
3Reliability
If complex policies are enforced within the trusted device, then security is improved, but resource consumption and cost increase
Solution Approach 1:
The patent introduces external policy engines as intermediaries that handle complex policy enforcement tasks outside the trusted device. These external engines perform sophisticated policy verification and enforcement, reducing the resource burden on the trusted device while maintaining high security through the intermediary's computational capabilities.
Solution Approach 2:
The patent extracts complex policy enforcement functionality from the trusted device and places it in external policy engines. This separation allows the trusted device to maintain security functions with minimal resource consumption, while the external engines handle the computationally intensive policy analysis and enforcement, effectively removing the resource burden from the trusted component.
Data Source
AI summary
A method of extending an integrity measurement in a trusted device operating in an embedded trusted platform by using a set of policy commands to extend a list of Platform Configuration Registers (PCRs) for the device and the current values of the listed PCRs and an integrity value identifying the integrity measurement into a policy register, verify a signature over the integrity value extended into the policy register, and, if verification succeeds, extend a verification key of the trusted platform, plus an indication that it is a verification key, into the policy register, compare the integrity value extended into the policy register with a value stored in the trusted platform, and, if they are the same: extend the stored value, plus an indication that it is a stored value, into the policy register, and extend the integrity measurement in the trusted device if the value in the policy register matches a value stored with the integrity measurement.


