Nova Patents
EP1980970A2

Dynamic trust management

Abstract

A method and apparatus are provided for tracking the state of a software component (71) in use on a computing platform. Upon a change of a first type in the software component (such as a change to an integrity-critical part of the component), an appropriate integrity metric of the software component (71) is reliably measured and recorded in cumulative combination with any previous integrity metric values recorded for changes of the first type to the software component. Upon a change of a second type in the software component (such as a change to a non integrity-critical part of the component), an appropriate integrity metric of the software component (71) is reliably measured and recorded as a replacement for any previous integrity metric value recorded for changes of the second type to the software component. The two resultant values provide an indication of the integrity state of the software component (71).

EP1980970A2, drawing sheet 1
Sheet 1 of 9

Term

1.5 yearsto projected expiry

Projected expiry 27 March 2028, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

26 claims: 4 independent, 22 dependent

  1. 1
    A method of tracking the state of a software component (71) in use on a computing platform, the method comprising:upon a change of a first type in the software component (71), reliably measuring and recording an appropriate integrity metric of the software component in cumulative combination with any previous integrity metric values recorded for changes of said first type to the software component;and upon a change of a second type in the software component (71), reliably measuring and recording an appropriate integrity metric of the software component as a replacement for any previous integrity metric value recorded for changes of said second type to the software component.
  2. 4
    A method according to any one of the preceding claims, wherein the software component (71) comprises:a functionality group (F) that provides the necessary component functionality;and an execution environment ( E NV) in which the functionality group executes.
  3. 5
    A method according to any one of claims 1 to 4, wherein the integrity metric measured as a result of a change of said first type is recorded to a first register (78) and the integrity metric measured as a result of change of said second type is recorded to a second register (79), the first and second registers being logically part of a trusted entity (75) associated with the software component (71).
  4. 10
    A method according to any one of claims 7 to 9, wherein the base component (102) is part of a trusted computing base (100) of the platform.
  5. 11
    A method according to any one of the preceding claims, further comprising preventing use of confidential data associated with a said software component (71) unless:the current cumulative value arising from integrity metrics recorded for changes of said first type, and the integrity metric value last recorded for changes of said second type, both match respective expected values
  6. 15
    A computing platform including a monitoring arrangement for tracking the state of a software component (71) in use on the computing platform, the monitoring arrangement comprising:change responsive means (72) for detecting and distinguishing first and second types of changes to the software component (71);first and second memory registers (78, 79);first measuring means (73) responsive to detection of a change of the first type in the software component (71), to reliably measure an appropriate integrity metric of the software component;first recording means (77) for recording the integrity metric measured by the first measuring means (73) in the first register (78) in cumulative combination with any previous integrity metric values recorded in the first register for changes of said first type to the software component (71);second measuring means (73) responsive to detection of a change of the second type in the software component (71), to reliably measure an appropriate integrity metric of the software component;second recording means (77) for recording the integrity metric measured by the second measuring means (73) in the second register (79) as a replacement for any previous integrity metric values recorded in the second register for changes of said second type to the software component(71).
  7. 18
    A computing platform_according to any one of claims 15 to 17, wherein the software component (71) comprises:a functionality group (F) that provides the necessary component functionality;and an execution environment ( E NV) in which the functionality group executes.
  8. 19
    A computing platform_according to any one of claims 15 to 18, wherein the first and second registers (78, 79) are logically part of a trusted entity (75) associated with the software component (71).
  9. 24
    A computing platform according to any one of claims 19 to 21, wherein the base component (102) is part of a trusted computing base (100) of the platform.
  10. 25
    A computing platform according to any one of claims 15 to 24, further including an access control arrangement for preventing use of confidential data associated with a said software component (71) unless:the current cumulative value arising from integrity metrics recorded for changes of said first type, and the integrity metric value last recorded for changes of said second type, both match respective expected values