Tamper-Aware Virtual TPM Using Security-Patrol Threads
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for computer systems, particularly software-based TPMs, lack effective mechanisms to detect physical attacks, which poses a significant risk in today's increasingly connected and vulnerable computing environment.
Innovation Solution
Implementing a tamper-aware virtual TPM using multiple threads on a multi-threaded processor, where one thread provides TPM functionality and another security-patrol thread simulates sensors to detect physical attacks through mathematical logic operations, without requiring hardware modifications or additional processor workload.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a software-based TPM (virtual TPM) is used instead of hardware TPM, then device complexity and cost are reduced, but the ability to detect physical attacks is lost
Solution Approach 1:
The patent creates a virtual copy of hardware sensor functionality within the software-based TPM. The virtual TPM thread implements sensor simulation that replicates the detection capabilities of physical TPM sensors, allowing the software implementation to detect physical attacks without requiring actual hardware sensor components.
Solution Approach 2:
The patent replaces the mechanical/hardware sensor system with a software-based detection mechanism. Instead of relying on physical sensors embedded in hardware TPM, the system uses a virtual TPM thread that simulates sensor behavior through mathematical logic operations, substituting the physical detection mechanism with a computational equivalent.
2Reliability
If multiple threads are used in the virtual TPM implementation, then security detection capability is improved, but processor workload increases
Solution Approach 1:
The patent merges the security patrol functionality with the existing virtual TPM operations by having the security-patrol thread share the same processor resource pool as the virtual TPM thread. Both threads execute on the same multi-threaded processor, sharing computational resources and memory, which reduces overall energy consumption compared to implementing separate independent systems.
3Reliability
If hardware-based TPM with sensor detection is used, then physical attack detection is enabled, but additional hardware requirements increase device complexity
Solution Approach 1:
The patent creates a virtual replica of hardware sensor functionality within the software-based TPM. The virtual TPM thread implements sensor simulation that replicates the detection capabilities of physical TPM sensors, allowing the software implementation to detect physical attacks without requiring actual hardware sensor components.
Data Source
AI summary
Methods, software/firmware and apparatus for implementing a tamper-aware virtual trusted platform module (TPM). Under the method, respective threads comprising a virtual TPM thread and a security-patrol threads are executed on a host processor. In one embodiment, the host processor is a multi-threaded processor having multiple logical processors, and the respective threads are executed on different logical processors. While the virtual TPM thread is used to perform various TPM functions, the security-patrol thread monitors for physical attacks on the processor by implementing various numerical calculation loops, wherein an erroneous calculation is indicative of a physical attack. In response to detection of such an attack, various actions can be taken in view of one or more predefined security policies, such as logging the event, shutting down the platform and/or informing a remote management entity.


