US2006010326A1PendingUtilityA1

Method for extending the CRTM in a trusted platform

Assignee: IBMPriority: Jul 8, 2004Filed: Jul 8, 2004Published: Jan 12, 2006
Est. expiryJul 8, 2024(expired)· nominal 20-yr term from priority
G06F 21/572
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, system and computer program product for enhancing the functionality of the existing core root of trust measurement (CRTM). The CRTM is extended to allow platform manufacturer controlled and certified code to be incorporated into the function of the CRTM, wherein the manufacturer may define the policy for accepting a new function into the CRTM. When a firmware or software module image is compiled, the build process generates a hash value of the compiled firmware or software image, wherein the hash value reflects a fingerprint (or short hand) representation of the compiled image. A determination is made as to whether the hash value of the firmware or software image is to be a CRTM extension. If so, a digital signature of the module is created using the CRTM extension private key. This signature value is added to the firmware or software module.

Claims

exact text as granted — not AI-modified
1 . A method in a data processing system for extending a core root of trust measurement within a trusted computing platform, comprising: 
 responsive to compiling a module image, generating a hash value;    determining if the hash value of the module image is to be an extension of the core root of trust measurement;    in response to determining that the hash value of the module image is to be a core root of trust measurement extension, creating a digital signature for the module using the core root of trust measurement private key; and    adding the digital signature to the module, wherein adding the digital signature allows platform manufacturer controlled and certified code to be incorporated into functions of the core root of trust measurement.    
     
     
         2 . The method of  claim 1 , further comprising: 
 responsive to determining that the hash value of the module image is not to be a core root of trust measurement extension, releasing the module image.    
     
     
         3 . The method of  claim 1 , wherein incorporating platform manufacturer controlled and certified code into the core root of trust measurement allows the platform manufacturer to define a policy for accepting a new function into the core root of trust measurement.  
     
     
         4 . The method of  claim 3 , wherein the extended core root of trust measurement may be updated using the manufacturer defined policy.  
     
     
         5 . The method of  claim 1 , wherein the module is a firmware module.  
     
     
         6 . The method of  claim 1 , wherein the module is a software module.  
     
     
         7 . A method in a data processing system for allowing a core root of trust measurement within a trusted computing platform to validate a module signature against a public key of a manufacturer, comprising: 
 loading the module into the data processing system;    determining if the module is signed by a core root of trust measurement extension signing key;    responsive to determining that the module is signed, validating the module signature against the public key of the manufacturer; and    creating an entry in a platform configuration register, wherein the platform configuration register is extended to include functions of the core root of trust measurement.    
     
     
         8 . A data processing system for extending a core root of trust measurement within a trusted computing platform, comprising: 
 generating means for generating a hash value in response to compiling a module image;    determining means for determining if the hash value of the module image is to be a core root of trust measurement extension;    creating means for creating a digital signature for the module using the core root of trust measurement private key in response to determining that the hash value of the module image is to be a core root of trust measurement extension; and    adding means for adding the digital signature to the module, wherein adding the digital signature allows platform manufacturer controlled and certified code to be incorporated into functions of the core root of trust measurement.    
     
     
         9 . The data processing system of  claim 8 , further comprising: 
 releasing means for releasing the module image in response determining that the hash value of the module image is not to be a core root of trust measurement extension.    
     
     
         10 . The data processing system of  claim 8 , wherein incorporating platform manufacturer controlled and certified code into the core root of trust measurement allows the platform manufacturer to define a policy for accepting a new function into the CRTM.  
     
     
         11 . The data processing system of  claim 10 , wherein the extended core root of trust measurement may be updated using the manufacturer defined policy.  
     
     
         12 . The data processing system of  claim 8 , wherein the module is a firmware module.  
     
     
         13 . The data processing system of  claim 8 , wherein the module is a software module.  
     
     
         14 . A computer program product in a computer readable medium for extending a core root of trust measurement within a trusted computing platform, comprising: 
 first instructions for generating a hash value in response to compiling a module image;    second instructions for determining if the hash value of the module image is to be a core root of trust measurement extension;    third instructions for creating a digital signature for the module using the core root of trust measurement private key in response to determining that the hash value of the module image is to be a core root of trust measurement extension; and    fourth instructions for adding the digital signature to the module, wherein adding the digital signature allows platform manufacturer controlled and certified code to be incorporated into functions of the core root of trust measurement.    
     
     
         15 . The computer program product of  claim 14 , further comprising: 
 fifth instructions for releasing the module image in response to determining that the hash value of the module image is not to be a core root of trust measurement extension.    
     
     
         16 . The computer program product of  claim 14 , wherein incorporating platform manufacturer controlled and certified code into the core root of trust measurement allows the platform manufacturer to define a policy for accepting a new function into the core root of trust measurement.  
     
     
         17 . The computer program product of  claim 16 , wherein the extended core root of trust measurement may be updated using the manufacturer defined policy.  
     
     
         18 . The computer program product of  claim 14 , wherein the module is a firmware module.  
     
     
         19 . The computer program product of  claim 14 , wherein the module is a software module.

Join the waitlist — get patent alerts

Track US2006010326A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.