• DocumentCode
    2969425
  • Title

    An adaptive system architecture for mitigating asymmetric cryptography weaknesses on TPMs

  • Author

    Malipatlolla, Sunil ; Feller, Thomas ; Huss, Sorin A.

  • Author_Institution
    Center for Adv. Security Res. Darmstadt (CASED), Darmstadt, Germany
  • fYear
    2012
  • fDate
    25-28 June 2012
  • Firstpage
    221
  • Lastpage
    226
  • Abstract
    A Trusted Platform Module (TPM) is a microcontroller-based chip, which provides a hardware-based security to the user´s data, cryptographic keys, and other secrets. For this purpose, the TPM is equipped with hardwired cryptographic engines such as RSA, SHA-1, and HMAC that rely on correspondingly uncompromised cryptographic algorithms. For example, the RSA (asymmetric) engine on the TPM utilizes the RSA algorithm for encrypting and decrypting the user data as well as for signature generation and verification. Therefore, in case of a compromised RSA algorithm, not only the data protected by the TPM is lost but also the generated signatures become invalid. One possible solution to this problem is to replace (i.e., update) the RSA engine on the TPM with a new uncompromised asymmetric engine (e.g., ECC). However, the current TPMs are in general implemented as Application Specific Integrated Circuits (ASICs), thus they can not be modified after manufacture. Further, the update of an engine on the TPM leads to a loss of trust kept in the system before an update. Thus, in this contribution, we propose dedicated procedures for regaining the trust in the system after the RSA engine update utilizing the novel Sustainable Trusted Platform Module (STPM) architecture.
  • Keywords
    application specific integrated circuits; handwriting recognition; microcontrollers; public key cryptography; security of data; trusted computing; ASIC; ECC; HMAC hard-wired cryptographic engine; RSA hard-wired cryptographic engine; SHA-1 hard-wired cryptographic engine; STPM architecture; adaptive system architecture; application specific integrated circuit; asymmetric cryptography weakness mitigation; cryptographic key; data protection; decryption; encryption; hardware-based security; microcontroller-based chip; signature generation; signature verification; sustainable trusted platform module architecture; trusted computing; uncompromised asymmetric engine; user data security; Computer architecture; Elliptic curve cryptography; Engines; Field programmable gate arrays; Heuristic algorithms; Asymmetric Cryptography; Secure Update; Trusted Platform Module; Trustworthiness;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Adaptive Hardware and Systems (AHS), 2012 NASA/ESA Conference on
  • Conference_Location
    Erlangen
  • Print_ISBN
    978-1-4673-1915-7
  • Electronic_ISBN
    978-1-4673-1914-0
  • Type

    conf

  • DOI
    10.1109/AHS.2012.6268654
  • Filename
    6268654