IP Library › Granted Patent US 8,566,606
Granted Patent B2
US 8,566,606 · App. 12/297,966 · Granted Oct 22, 2013

Apparatus and method for performing trusted computing integrity measurement reporting

Inventors: Sasidhar Movva (Wheatley Heights, NY); Richard D. Herschaft (Whitestone, NY); Renuka Racha (Kings Park, NY); Inyhok Cha (Yardley, PA)
Assignee: InterDigital Technology Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,566,606
App. No.
12/297,966
Granted
Oct 22, 2013
Kind
B2
Abstract

An apparatus and methods that use trusted platform modules (TPM) to perform integrity measurements of multiple subsystems are disclosed. The state of platform configuration registers (PCRs) after boot up are stored as the base state of the system. In another embodiment, and application that is to be verified requests that its state be extended from the base state of the system. When such a request is received, the state of the system is extended directly from the base state PCR contents and not from the system state. In another embodiment, a virtual PCR is used, where such a virtual PCR uses a larger memory space than a conventional TPM provides for a physical PCR, by use of encrypted storage on external, protected memory.

Claims (6)

1. A user device comprising:

a memory in which a certificate repository is implemented, the certificate repository having a plurality of signed reference base state (RBS) certificates, each signed RBS certificate being associated with an application and comprising (1) a base state that is specific to the associated application and (2) a hash value of a statement indicating whether an actual system state of the user device matches the base state of the associated application;

a platform agent configured to get a platform configuration associated with a loaded application for which a challenger is interested in verifying an integrity, wherein the platform configuration is computed using the base state of the signed RBS certificate, of the plurality of signed RBS certificates, for the loaded application, and wherein the platform agent is further configured to construct another hash value, the another hash value of another statement indicating whether a second actual system state of the user device matches the base state of the associated application contained in the RBS certificate; and

a trusted platform module (TPM) configured to obtain the signed RBS certificate from the certificate repository, and extend a platform configuration register (PCR) that is (1) dedicated to the signed RBS certificate, controlled by the TPM, and (2) associated with the loaded application, after verifying that the hash value of the signed RBS certificate is the same as the another hash value constructed by the platform agent, wherein the TPM is further configured to sign a PCR value with an attestation identification key (AIK), and send the signed PCR value to the platform agent.

2. The user device of claim 1 wherein the platform agent is further configured to send platform configuration information, including the signed PCR value, to the challenger.

3. The user device of claim 2 wherein the challenger is configured to verify that the loaded application associated with the signed RBS certificate was loaded from a correct base state as indicated in the signed RBS certificate.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR'S NAME PREVIOUSLY RECORDED AT REEL 023113 FRAME 0329. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNOR'S INTEREST EFFECTIVE OCTOBER 21,2008. Recorded Sep 1, 2009
From: MOVVA, SASIDHAR; HERSCHAFT, RICHARD D.; RACHA, RENUKA; CHA, INHYOK
To: INTERDIGITAL TECHNOLOGY CORPORATION
Reel/Frame 023174/0412 →
NUNC PRO TUNC ASSIGNMENT, EFFECTIVE OCTOBER 21, 2008, Recorded Aug 18, 2009
From: MOVVA, SASIDHER; HERSCHAFT, RICHARD D.; RACHA, RENUKA; CHA, INHYOK
To: INTERDIGITAL TECHNOLOGY CORPORATION
Reel/Frame 023113/0329 →
Continuity (2)
Provisional Application 60794165 · Apr 21, 2006
Related Publication 20090307487A1 · Dec 10, 2009