Trusted State Attestation for Heterogeneous Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Maintaining and interpreting trusted values for heterogeneous managed systems is complex due to variations in processor count and software configurations, and trusted boot processes do not protect against malicious attacks after the system has completed booting.
Innovation Solution
The method involves verifying a system's trusted state, requesting enrollment, retrieving and comparing enrollment data with current input data, and accepting the trusted state until an update notification is received, thereby simplifying the maintenance of trusted values and providing continuous security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a managing system maintains a database of trusted values for heterogeneous managed systems, then remote attestation can be performed, but the complexity of maintaining and interpreting trusted values increases due to variations in processor count and software configurations
Solution Approach 1:
The patent applies preliminary action by establishing an enrollment process before the managed system operates. During enrollment, the managing system captures the initial trusted state (PCR values) of the managed system and stores it as baseline data. This preliminary capture of trusted values eliminates the need for continuous maintenance and interpretation of trusted values across heterogeneous configurations, as the system only needs to compare current states against the pre-established enrollment baseline.
Solution Approach 2:
The patent applies parameter changes by shifting from maintaining absolute trusted values to maintaining relative trust relationships. Instead of storing and managing complex trusted values that must be interpreted across different hardware configurations, the system stores the difference (delta) between the enrollment state and current state. This parameter transformation simplifies maintenance by focusing only on changes rather than absolute values.
2Reliability
If trusted boot process is used to protect system integrity, then modifications during inactive state can be detected, but protection against malicious attacks after booting is not provided
Solution Approach 1:
The patent applies continuity of useful action by extending the trust verification process from only boot time to continuous operation. The system performs periodic attestation checks during runtime, not just during boot, by continuously monitoring PCR values and comparing them against the enrollment baseline. This continuous verification eliminates the security gap that exists between boot completion and next scheduled check, maintaining protection throughout the system's operational lifecycle.
Solution Approach 2:
The patent applies feedback by implementing a closed-loop attestation system. The managing system receives periodic attestation reports from the managed system, compares current PCR values against the enrollment baseline, and can trigger alerts or actions when deviations are detected. This feedback mechanism enables real-time detection of malicious attacks that occur after booting, allowing the system to respond to security threats dynamically rather than waiting for the next boot cycle.
Data Source
AI summary
A method, apparatus and program product for attesting a component of a system during a boot process. The method comprises the steps of: verifying that the system is in a trusted state; in response to verifying that the system is in a trusted state, requesting an enrollment of the system wherein the requesting step further comprises the step of: retrieving enrollment data associated with the system; retrieving current input data associated with the component of the system; comparing the current input data against the enrollment data in order to determine whether the system can retain its trusted state; wherein in response to the comparing step, if the current input data matches the enrollment data, the system retains its trusted state; and accepting the trusted state until receipt of a notification, from the system having a retained trusted state, of an update to the system.


