The ten-page introduction to Trusted Computing

Andrew Martin · Oxford University Research Archive (ORA) (University of Oxford) · 2008

Networked computer systems underlie a great deal of business, social, and government activity today. Everyone is expected to place a great deal of trust in their correct operation, but experience shows that this trust is often misplaced. Such systems have always been subject to failures due to oversights and mistakes by those who designed them; increasingly such failures are exploited by those with malicious intent. The concept of Trusted Computing has been present in the computer security literature for quite some time, and has influenced the design of some high-assurance solutions. These ideas are now becoming incorporated in mainstream products — PCs, mobile phones, disc drives, servers — and are the subject of much discussion and sometimes misinformation. Trusted computing implies a re-design of systems architecture in such a way as to support its factorization into relatively discrete components with well-defined characteristics. This permits, in particular, rational decisions based upon reasonable expectations of behaviour. Any such systems thinking must be motivated by an analysis of risks — so that effort is expended where it may give the best return — and an awareness of the limitations of such risk assessment (because frequently the raw data and parameters are simply not available, and because security properties are typically not compositional). The approach described here is largely the result of the work of an industry consortium (the Trusted Computing Group, TCG), itself informed by a history of research, largely in the area of high-assurance systems, from government and academe. TCG’s approach is distinctive in that previous trusted systems were usually bespoke and highly expensive: the current work aims to touch every computing device. This tutorial surveys the relevant notions of ‘trust’, exploring what this means for ‘trusted computing’. We describe briefly the interventions needed in hardware and software required to give a stable platform upon which such systems can be constructed. In essence, this gives us two new systems characteristics: (a) a high degree of confidence in the state (configuration, running software, etc.) of a local computing system—and hence a measure of its relative freedom from unwanted intervention; (b) a relatively high degree of confidence in the state of a remote system (a property called ‘remote attestation’). The first of those characteristics has perhaps always informed the way that users interact with desktop personal computers: many malware attacks exploit misplaced trust in the local system. The second characteristic is genuinely novel, and may be seen as an enabler of many new kinds of pattern of interaction in distributed systems. Knowing that a platform is in a particular state is neither a necessary nor sufficient condition for trustworthiness (or, indeed, security) — but helps to inform decisions about that. We explore how these capabilities are constructed, and some uses to which they might be put. We also briefly describe the state of deployment of these technologies, and some current areas of research.

Read the paper · More papers on PaperTik