A trusted motherboard system

By designing a trusted motherboard system that is compatible with SPI and I2C interfaces, the complex and incompatible design of existing TPM modules is solved, and the development cost and easier warehousing and transportation are achieved.

CN115203762BActive Publication Date: 2025-06-13INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210891719.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-27
Publication Date
2025-06-13
Estimated Expiration
2042-07-27

AI Technical Summary

Technical Problem

In existing servers, the design of TPM modules is complex and divided into two types: SPI interface and I2C interface, which leads to incompatibility in design and increases the development cost and difficulty in warehousing and transportation.

Method used

A trusted motherboard system is designed to realize SPI signal transmission between the PCH and the first TPM chip through a connector and I2C signal transmission between the BMC and the second TPM chip, so as to realize the compatible design of the TPM module.

Benefits of technology

The design implements the TPM module to support both SPI and I2C interfaces, reducing development costs and simplifying warehousing and transportation processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115203762B_ABST
    Figure CN115203762B_ABST
Patent Text Reader

Abstract

The present application discloses a trusted motherboard system, including: a motherboard, a connector electrically connected to the motherboard, and a TPM module plugged into the connector. The motherboard includes a PCH and a BMC, and the TPM module includes a first TPM chip and a second TPM chip; the PCH and the first TPM chip are respectively connected to the connector through an SPI interface to realize the transmission of SPI signals between the PCH and the first TPM chip; the BMC and the second TPM chip are respectively connected to the connector through an I2C interface to realize the transmission of I2C signals between the BMC and the second TPM chip. Thus, it can be seen that the present application realizes the compatible design of the TPM module through hardware, and simultaneously supports the TPM module using the SPI interface and the TPM module using the I2C interface, greatly reducing the development cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technologies, and more specifically, to a trusted motherboard system. Background Art

[0002] In recent years, trusted computing has become a hot topic in the field of information security. Trusted computing in China has now received increasing attention from the national cryptography management department and has been elevated to a national standard. There is an increasing demand for trusted computing in many places with high requirements for security and confidentiality. Existing trusted computing includes the TCM (Trusted Cryptography Module) security specification and the TPM (Trusted Platform Module) security specification.

[0003] In server design, a relatively common encryption method is to use a TPM module to implement the encryption and verification of Firmware. The TPM module is designed to be an essential part of the system design. Currently, TPM chips are mainly divided into two types. One is a chip with an SPI (Serial Peripheral Interface) interface or an LPC (Low pin count) interface hanging under the PCH (Platform Controller Hub, integrated south bridge), and the other is a chip with an I2C (Inter-Integrated Circuit, bidirectional two-wire synchronous serial bus) interface hanging under the BMC (Baseboard Management Controller). Depending on the different hosts they are mounted on, they respectively verify the BIOS (Basic Input Output System) flash and the BMC flash. The design of the TPM module is based on the TCG (Trusted Computing Group) protocol, which defines module interfaces, signal definitions, device addresses, etc.

[0004] In current servers, TPM modules with SPI interfaces, TPM modules with I2C interfaces, TCM modules, etc. are often designed separately and implemented using different hardware. The design is complex and the number of boards is excessive, which is not conducive to warehousing and transportation.

[0005] Therefore, how to make the TCM module compatible with different types of interfaces is a technical problem that needs to be solved by those skilled in the art. Summary of the Invention

[0006] The purpose of the present application is to provide a trusted motherboard system, which realizes the simultaneous support for TPM modules using SPI interfaces and TPM modules using I2C interfaces.

[0007] To achieve the above object, the present application provides a trusted motherboard system, including: a motherboard, a connector electrically connected to the motherboard, and a TPM module plugged into the connector; the motherboard includes a PCH and a BMC, and the TPM module includes a first TPM chip and a second TPM chip;

[0008] The PCH and the first TPM chip are respectively connected to the connector through an SPI interface to realize the transmission of SPI signals between the PCH and the first TPM chip;

[0009] The BMC and the second TPM chip are respectively connected to the connector through an I2C interface to realize the transmission of I2C signals between the BMC and the second TPM chip.

[0010] Preferably, the SPI signals include MOSI signals, MISO signals, CS signals, and SCLK signals. The MOSI signal occupies the third pin of the connector, the MISO signal occupies the fourth pin of the connector, the CS signal occupies the fifth pin of the connector, and the SCLK signal occupies the first pin of the connector.

[0011] Preferably, the I2C signals include SDA signals and CLK signals. The SDA signal occupies the sixth pin of the connector, and the CLK signal occupies the tenth pin of the connector.

[0012] Preferably, the TPM module further includes an IO expansion board, and the interrupt pin of the second TPM chip is connected to the sixth pin and / or the tenth pin of the connector through the IO expansion board.

[0013] Preferably, the power pins of the first TPM chip and the second TPM chip are connected to the power supply of the first preset voltage through the seventh pin of the connector, and the eleventh pin of the connector is grounded.

[0014] Preferably, the PCH is connected to the reset pin of the first TPM chip through the second pin of the connector, and the PCH sends a reset signal to the first TPM chip through the second pin;

[0015] The PCH is connected to the interrupt pin of the first TPM chip through the ninth pin of the connector, and the PCH receives the interrupt signal of the first TPM chip through the ninth pin.

[0016] Preferably, the main board further includes a comparator circuit, and the TPM module further includes a multiplexing circuit;

[0017] The PCH and the BMC are connected to the eighth pin of the connector through the comparator circuit, and the eighth pin is connected to the power pins and the reset pin of the first TPM chip and the second TPM chip through the multiplexing circuit. The PCH and the BMC receive the presence signal of the TPM module from the eighth pin through the comparator circuit, and the BMC sends a reset signal to the second TPM chip through the eighth pin.

[0018] Preferably, the multiplexing circuit includes:

[0019] A first resistor, one end connected to the eighth pin and the other end grounded;

[0020] A second resistor, one end connected to the eighth pin and the other end connected to the base of the first triode;

[0021] The first triode, the base connected to the second resistor, the emitter grounded, and the collector connected to the third resistor and the base of the second triode;

[0022] The third resistor, one end connected to the power pins of the first TPM chip and the second TPM chip, and the other end connected to the collector of the first triode;

[0023] A fourth resistor, one end connected to the power pins of the first TPM chip and the second TPM chip, and the other end connected to the collector of the second triode;

[0024] The second triode, the base connected to the collector of the first triode, the emitter grounded, and the collector connected to the fourth resistor and the reset pin of the second TPM chip.

[0025] Preferably, the second preset voltage is greater than the turn-on voltages of the first triode and the second triode, and the second preset voltage is less than the first preset voltage.

[0026] Preferably, the comparator circuit includes:

[0027] A comparator, the first input terminal connected to the power supply of the second preset voltage, the second input terminal connected to the eighth pin and the fifth resistor, and the output terminal connected to the PCH and the BMC;

[0028] The fifth resistor, one end connected to the second input terminal of the comparator and the other end connected to the power supply of the first preset voltage.

[0029] As can be seen from the above solution, a trusted motherboard system provided by the present application includes: a motherboard, a connector electrically connected to the motherboard, and a TPM module plugged into the connector; the motherboard includes a PCH and a BMC, and the TPM module includes a first TPM chip and a second TPM chip; the PCH and the first TPM chip are respectively connected to the connector through an SPI interface to implement the transmission of SPI signals between the PCH and the first TPM chip; the BMC and the second TPM chip are respectively connected to the connector through an I2C interface to implement the transmission of I2C signals between the BMC and the second TPM chip.

[0030] In the present application, the TPM module includes a first TPM chip and a second TPM chip. The first TPM chip is a TPM chip using an SPI interface, and the second TPM chip is a TPM chip using an I2C interface. The first TPM chip is connected to the PCH through a connector, and the second TPM chip is connected to the BMC through a connector. Thus, it can be seen that the present application realizes the compatible design of the TPM module through hardware, supports both the TPM module using an SPI interface and the TPM module using an I2C interface, and greatly reduces the development cost.

[0031] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present application. Description of the Drawings

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. The drawings are used to provide a further understanding of the present disclosure and constitute a part of the specification, and are used together with the following specific embodiments to explain the present disclosure, but do not constitute a limitation to the present disclosure. In the drawings:

[0033] Figure 1 It is a structural diagram of a trusted motherboard system shown according to an exemplary embodiment;

[0034] Figure 2 It is a circuit connection schematic diagram of a trusted motherboard system provided by an application embodiment of the present application. Detailed Embodiments

[0035] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application. In addition, in the embodiments of the present application, "first", "second", etc. are used to distinguish similar objects and do not necessarily describe a specific order or sequence.

[0036] The embodiment of the present application discloses a trusted motherboard system, which realizes supporting both a TPM module using an SPI interface and a TPM module using an I2C interface.

[0037] See Figure 1 , a structural diagram of a trusted motherboard system shown according to an exemplary embodiment, as Figure 1 shown, includes: a motherboard 10, a connector 20 electrically connected to the motherboard 10, and a TPM module 30 plugged into the connector 20. The motherboard 10 includes a PCH 101 and a BMC 102. The TPM module 30 includes a first TPM chip 301 and a second TPM chip 302. The PCH 101 and the first TPM chip 301 are respectively connected to the connector 20 through an SPI interface to realize the transmission of SPI signals between the PCH 101 and the first TPM chip 301. The BMC 102 and the second TPM chip 302 are respectively connected to the connector 20 through an I2C interface to realize the transmission of I2C signals between the BMC 102 and the second TPM chip 302.

[0038] In this embodiment, the motherboard 10 is electrically connected to the connector 20, and the TPM module 30 is plugged into the connector 20, that is, the motherboard 10 and the TPM module 30 are electrically connected through the connector 20. The interface of the TPM module 30 refers to the TCG protocol, and the connector 20 can specifically be an 11-pin connector.

[0039] Further, the main board 10 includes a PCH 101 and a BMC 102. The TPM module 30 includes a first TPM chip 301 and a second TPM chip 302. The first TPM chip 301 is a TPM chip using an SPI interface, and the second TPM chip 302 is a TPM chip using an I2C interface. Both the first TPM chip 301 and the second TPM chip 302 can be packaged using QFN (Quad Flat No-leads Package). The SPI interface of the first TPM chip 301 is connected to the SPI interface of the PCH 101 through a connector 20, and SPI signals are transmitted between the PCH 101 and the first TPM chip 301. The I2C interface of the second TPM chip 302 is connected to the I2C interface of the BMC 102 through the connector 20, and I2C signals are transmitted between the BMC 102 and the second TPM chip 302, realizing that the TPM module 30 is compatible with both the SPI interface and the I2C interface.

[0040] In addition, the PCH 101 can be connected to a BIOS FLASH, and the PCH 101 can be connected to the RSMRST_N interface of a POR (Power-On Reset) chip through an RSMRST_N interface. The BMC 102 can be connected to a BMC FLASH, and the BMC 102 can be connected to the RSMRST_N interface of the POR chip through an SRST interface.

[0041] In an embodiment, the SPI signals include a MOSI (Master Output Slave Input) signal, a MISO (Master Input Slave Output) signal, a CS (chip select) signal, and an SCLK (serial clock) signal. The MOSI signal occupies the third pin of the connector 20, the MISO signal occupies the fourth pin of the connector 20, the CS signal occupies the fifth pin of the connector 20, and the SCLK signal occupies the first pin of the connector 20. In a specific implementation, the first pin of the connector 20 is SPI_TPM_CLK, the third pin is SPI_TPM_MOSI, the fourth pin is SPI_TPM_MISO, and the fifth pin is SPI_TPM_CS_N.

[0042] In one embodiment, the I2C signal includes an SDA (Serial Data) signal and a CLK (Clock) signal. The SDA signal occupies the sixth pin of the connector 20, and the CLK signal occupies the tenth pin of the connector 20. In a specific implementation, the sixth pin of the connector 20 is I2C_TPM_DATA, and the tenth pin is I2C_TPM_CLK.

[0043] In one embodiment, the power pins of the first TPM chip 301 and the second TPM chip 302 are connected to a power supply of a first preset voltage through the seventh pin of the connector 20, and the eleventh pin of the connector 20 is grounded. In a specific implementation, the power supply supplies power to the first TPM chip 301 and the second TPM chip 302 in the TPM module 30. As a preferred embodiment, the first preset voltage can be 3.3V, that is, the seventh pin of the connector 20 is P3V3_STBY, and the TPM module 30 is powered by P3V3_STBY. Since the power consumption of the TPM module 30 is low, 1-pin power supply is sufficient.

[0044] In one embodiment, the PCH 101 is connected to the reset pin of the first TPM chip 301 through the second pin of the connector 20, and the PCH 101 sends a reset signal to the first TPM chip 301 through the second pin. In a specific implementation, the second pin of the connector 20 is SPI_TPM_PLTRST_N, the PLTRST_N interface of the PCH 101 is connected to the second pin of the connector 20, the second pin of the connector 20 is connected to the reset pin (RST_N) of the first TPM chip 301, and the PCH 101 sends a reset signal to the first TPM chip 301 through the second pin of the connector 20 to initialize the first TPM chip 301.

[0045] In one embodiment, the PCH 101 is connected to the interrupt pin of the first TPM chip 301 through the ninth pin of the connector 20, and the PCH 101 receives the interrupt signal of the first TPM chip 301 through the ninth pin. In a specific implementation, the ninth pin of the connector 20 is SPI_TPM_IRQ_N, the first GPIO (General-purpose input / output) interface (GPIO0) of the PCH 101 is connected to the ninth pin of the connector 20, the ninth pin of the connector 20 is connected to the interrupt pin (IRQ_N) of the first TPM chip 301, and when the first TPM chip 301 triggers an interrupt, the ninth pin is pulled low to notify the PCH 101.

[0046] In one embodiment, the main board 10 further includes a comparator circuit, and the TPM module 30 further includes a multiplexing circuit; the PCH 101 and the BMC 102 are connected to the eighth pin of the connector 20 through the comparator circuit, and the eighth pin is connected to the power supply pin, the power supply pin and the reset pin of the second TPM chip 302 of the first TPM chip 301 through the multiplexing circuit. The PCH 101 and the BMC 102 receive the presence signal of the TPM module 30 from the eighth pin through the comparator circuit, and the BMC 102 sends a reset signal to the second TPM chip 302 through the eighth pin.

[0047] In a specific implementation, due to the limitation of the number of pins of the connector 20, the presence signal (TPM_MODULE_PRESENT_N) of the TPM module 30 and the reset signal (I2C_TPM_RST_N) of the second TPM chip 302 share the eighth pin of the connector 20, that is, the eighth pin is PRSNT_N / RST_N. The TPM_MODULE_PRESENT_N signal is an input signal for the main board 10 to indicate whether the TPM module 30 is present. The I2C_TPM_RST_N signal is an output signal for the main board 10 to output a reset signal to the second TPM chip 302. Since the signal directions are different, a comparator is used. The second GPIO interface (GPIO1) of the PCH 101 and the third GPIO interface (GPIO2) of the BMC 102 are connected to the eighth pin of the connector 20 through a comparator circuit, and the eighth pin of the connector 20 is connected to the power supply pin (VCC) of the first TPM chip 301 and the power supply pin (VCC) of the second TPM chip 302. At the same time, the fourth GPIO interface (GPIO3) of the BMC 102 is connected to the eighth pin of the connector 20, and the eighth pin of the connector 20 is connected to the reset pin (RST_N) of the second TPM chip 302. The BMC 102 sends a reset signal to the second TPM chip 302 through the eighth pin of the connector 20 to initialize the second TPM chip 302.

[0048] In one embodiment, the multiplexing circuit includes:

[0049] A first resistor, one end connected to the eighth pin and the other end grounded;

[0050] A second resistor, one end connected to the eighth pin and the other end connected to the base of the first triode;

[0051] The first triode, the base is connected to the second resistor, the emitter is grounded, and the collector is connected to the third resistor and the base of the second triode;

[0052] The third resistor has one end connected to the power supply pins of the first TPM chip 301 and the second TPM chip 302, and the other end connected to the collector of the first triode;

[0053] The fourth resistor has one end connected to the power supply pins of the first TPM chip 301 and the second TPM chip 302, and the other end connected to the collector of the second triode;

[0054] For the second triode, the base is connected to the collector of the first triode, the emitter is grounded, and the collector is connected to the fourth resistor and the reset pin of the second TPM chip 302.

[0055] In a specific implementation, one end of the first resistor (R1) is connected to the eighth pin of the comparator, and the other end is grounded. One end of the second resistor (R2) is connected to the eighth pin of the comparator, and the other end is connected to the base of the first triode (Q1). The base of the first triode (Q1) is connected to the second resistor (R2), the emitter is grounded, and the collector is connected to the third resistor (R3) and the base of the second triode (Q2). One end of the third resistor (R3) is connected to the power supply pins (VCC) of the first TPM chip 301 and the second TPM chip 302. The base of the second triode (Q2) is connected to the collector of the first triode (Q1), the emitter is grounded, and the collector is connected to the fourth resistor (R4) and the reset pin (RST_N) of the second TPM chip 302. One end of the fourth resistor (R4) is connected to the power supply pins (VCC) of the first TPM chip 301 and the second TPM chip 302, and the other end is connected to the collector of the second triode (Q2).

[0056] In an embodiment, the comparator circuit includes:

[0057] A comparator, with the first input terminal connected to the power supply of the second preset voltage, the second input terminal connected to the eighth pin and the fifth resistor, and the output terminal connected to the PCH 101 and the BMC 102;

[0058] The fifth resistor has one end connected to the second input terminal of the comparator, and the other end connected to the power supply of the first preset voltage.

[0059] In a specific implementation, the first input terminal of the comparator is connected to the power supply of the second preset voltage, the second input terminal is connected to the eighth pin of the connector 20 and the fifth resistor (R5), and the output terminal is connected to the second GPIO interface (GPIO1) of the PCH 101 and the third GPIO interface (GPIO2) of the BMC102. One end of the fifth resistor (R5) is connected to the second input terminal of the comparator, and the other end is connected to the power supply of the first preset voltage. As a preferred implementation, the reference level of the comparator, that is, the second preset voltage, is greater than the turn-on voltages of the first triode and the second triode, and the second preset voltage is less than the first preset voltage.

[0060] For example, the resistance value of the first resistor is 4.7 kΩ, the resistance value of the first resistor is 47 kΩ, the resistance value of the third resistor is 82 kΩ, the resistance value of the fourth resistor is 4.7 kΩ, and the turn-on voltages of the first triode and the second triode are less than 1.65 V. The reference level of the comparator is set to 2.2 V.

[0061] When the TPM module 30 is in place and the BMC 102 needs to reset the TPM module 30, the BMC 101 configures GPIO3 to output a low level. At this time, the first triode is turned off and the second triode is turned on. The TPM_MODULE_PRESENT_N signal output by the comparator is at a low level, notifying the BMC 102 and the PCH 101 that the TPM module 30 is in place.

[0062] When the TPM module 30 is in place and the BMC 102 needs to release the TPM module 30 from the reset state, the BMC 102 configures GPIO3 to a high level. At this time, the first triode is turned on and the second triode is turned off. The reset pin of the second TPM chip 302 is pulled high, and the release starts to work normally. The TPM_MODULE_PRESENT_N signal output by the comparator is at a low level, notifying the BMC102 and the PCH 101 that the TPM module 30 is in place.

[0063] When the TPM module 30 is not in place, there is no multiplexing circuit, and the TPM_MODULE_PRESENT_N signal output by the comparator is at a high level, notifying the BMC 102 and the PCH 101 that the TPM module 30 is not in place.

[0064] In one embodiment, the TPM module further includes an IO expansion board, and the interrupt pin of the second TPM chip is connected to the sixth pin and / or the tenth pin of the connector through the IO expansion board. In a specific implementation, since there are no extra pins on the connector 20, the interrupt pin (IRQ_N) of the second TPM chip 302 is implemented using an I2C IO Expander (expansion board). At the same time, a 3-pin Board ID is added on the IO Expander to distinguish different SKUs (Stock Keeping Unit, inventory unit) for software to distinguish, such as optional SKUs like single TPM or TPMs from different manufacturers.

[0065] In the embodiments of the present application, the TPM module includes a first TPM chip and a second TPM chip. The first TPM chip is a TPM chip using an SPI interface, and the second TPM chip is a TPM chip using an I2C interface. The first TPM chip is connected to the PCH through a connector, and the second TPM chip is connected to the BMC through a connector. Thus, it can be seen that the present application realizes a compatible design of the TPM module through hardware, and at the same time supports TPM modules using SPI interfaces and TPM modules using I2C interfaces, greatly reducing the development cost.

[0066] The following introduces an application embodiment provided by the present application. Refer to Figure 2 , Figure 2 which is a circuit connection schematic diagram of a trusted motherboard system provided for the application embodiment of the present application. As Figure 2 shown, the motherboard includes a PCH and a BMC. The PCH is connected to the BIOS FLASH, and the PCH is connected to the RSMRST_N interface of the POR chip through the RSMRST_N interface. The BMC is connected to the BMCFLASH, and the BMC is connected to the RSMRST_N interface of the POR chip through the SRST interface. The TPM module includes a first TPM chip (First TPM IC) and a second TPM chip (Second TPM IC). The first TPM chip is a TPM chip using an SPI interface, and the second TPM chip is a TPM chip using an I2C interface. Both the first TPM chip and the second TPM chip adopt a QFN 32 Package.

[0067] The SPI interface of the first TPM chip is connected to the SPI interface of the PCH through a connector, and SPI signals are transmitted between the PCH and the first TPM chip. The I2C interface of the second TPM chip is connected to the I2C interface of the BMC through a connector, and I2C signals are transmitted between the BMC and the second TPM chip, realizing the compatibility of the TPM module 30 with both SPI interfaces and I2C interfaces.

[0068] The main board and the TPM module are electrically connected through an 11-pin connector. The definitions of each pin of the connector are shown in Table 1:

[0069] Table 1

[0070] pin number pin name 1 SPI_TPM_CLK 2 SPI_TPM_PLTRST_N 3 SPI_TPM_MOSI 4 SPI_TPM_MISO 5 SPI_TPM_CS_N 6 I2C_TPM_DATA 7 P3V3_STBY 8 PRSNT_N / RST_N 9 SPI_TPM_IRQ_N 10 I2C_TPM_CLK 11 GND

[0071] Among them, the SPI signal includes 4 signals, namely MOSI, MISO, CS, and SCLK, which respectively occupy pins 3, 4, 5, and 1. The I2C includes 2 signals, namely SDA and CLK, which respectively occupy pins 6 and 10. The 7th pin is P3V3_STBY. The TPM module is powered by P3V3_STBY, with low power consumption, and only 1 pin for power supply is required. The 11th pin is GND. The 2nd pin is PLTRST_N. The PLTRST_N of the PCH 101 is connected to the 2nd pin, and the 2nd pin is connected to the RST_N of the first TPM IC, that is, the 2nd pin is used for resetting the first TPM IC. The 9th pin is SPI_TPM_IRQ_N, which is connected to the PCH, that is, GPIO0 of the PCH is connected to the 9th pin, and the 9th pin is connected to the IRQ_N of the first TPM IC. When the first TPM IC triggers an interrupt, this pin is pulled low to notify the PCH.

[0072] Due to the insufficient number of pins of the comparator, the 8th pin is implemented by multiplexing the TPM_MODULE_PRESENT_N signal and the I2C_TPM_RST_N signal. TPM_MODULE_PRESENT_N is an input to the main board, indicating whether the TPM module is present. I2C_TPM_RST_N is an output to the main board, outputting a reset signal. Due to the different signal directions, a comparator is used to implement this.

[0073] The GPIO1 of the PCH and the GPIO2 of the BMC are connected to the 8th pin through a comparator circuit, and the 8th pin is connected to the VCC of the first TPM IC and the VCC of the second TPM IC. At the same time, the GPIO3 of the BMC is connected to the 8th pin, and the 8th pin is connected to the RST_N of the second TPM IC. One end of R1 is connected to the 8th pin and the other end is grounded. One end of R2 is connected to the 8th pin and the other end is connected to the base of Q1. The base of Q1 is connected to R2, the emitter is grounded, and the collector is connected to R3 and the base of Q2. One end of R3 is connected to the VCC of the first TPM IC and the VCC of the second TPM IC. The base of Q2 is connected to the collector of Q1, the emitter is grounded, and the collector is connected to R4 and the RST_N of the second TPM IC. One end of R4 is connected to the VCC of the first TPM IC and the VCC of the second TPM IC, and the other end is connected to the collector of Q2. The first input terminal of the comparator is connected to a 2.2V power supply, the second input terminal is connected to the 8th pin and R5, and the output terminal is connected to the GPIO1 of the PCH and the GPIO2 of the BMC. One end of R5 is connected to the second input terminal of the comparator and the other end is connected to a 3.3V power supply.

[0074] Logic device: A comparator is used on the motherboard side, such as Figure 2 at the positions numbered 7, 8, and 9. On the TPM module, it is implemented using resistors and transistors. The resistor values are selected as R1 = 4.7 kΩ, R2 = 47 kΩ, R3 = 82 kΩ, R4 = 4.7 kΩ, R5 = 4.7 kΩ. Transistors Q1 and Q2 should be selected with a turn-on voltage less than 1.65V.

[0075] When the TPM module is in place and the BMC needs to reset the TPM, the BMC configures GPIO3 as output L. At this time, the levels at points 1 and 8 are L, Q1 is turned off, the level at point 3 is 3.3V, Q2 is turned on, points 5 and 6 are connected and the level is L. At this time, the reference level of the motherboard comparator is set to 2.2V, the level at point 8 is 0V, and the TPM_MODULE_PRESENT_N signal output by the comparator is L, notifying the BMC and the PCH that the TPM module is in place.

[0076] When the TPM module is in place and the BMC needs to release the TPM from the reset state, the BMC configures GPIO3 as H. Due to the voltage division of R1 and R5, the levels at points 8 and 1 are 1.65V. At this time, Q1 is turned on, the level at point 3 is L, Q2 is turned off, the level at point 5 is H, and the reset pin of the second TPM IC is pulled high, and the release starts to work normally. At this time, the reference level of the motherboard comparator is set to 2.2V, the level at point 8 is 1.65V, and the TPM_MODULE_PRESENT_N signal output by the comparator is L, notifying the BMC and the PCH that the TPM module is in place.

[0077] When the TPM module is not present, there is no circuit for the TPM Module. At this time, pin 8 is pulled up to 3.3V, and the TPM_MODULE_PRESENT_N signal output by the comparator is H, notifying the BMC and PCH that the TPM module is not present.

[0078] Since there are no extra pins on the connector, the IRQ_N of the second TPM IC is implemented using an I2C IO Expander. At the same time, 3-pin BoardID is added on the IO Expander to distinguish different SKUs for software differentiation, such as optional SKUs like single TPM or TPMs from different manufacturers.

[0079] In the embodiment of the present application, the TPM module includes a first TPM chip and a second TPM chip. The first TPM chip is a TPM chip using the SPI interface, and the second TPM chip is a TPM chip using the I2C interface. The first TPM chip is connected to the PCH through a connector, and the second TPM chip is connected to the BMC through a connector. Thus, it can be seen that the present application realizes the compatible design of the TPM module through hardware, and at the same time supports the TPM module using the SPI interface and the TPM module using the I2C interface, greatly reducing the development cost.

[0080] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A trusted motherboard system, characterized in that, it includes: a motherboard, a connector electrically connected to the motherboard, and a TPM module plugged into the connector; the motherboard includes a PCH and a BMC, and the TPM module includes a first TPM chip and a second TPM chip; the PCH and the first TPM chip are respectively connected to the connector through an SPI interface to enable the transmission of SPI signals between the PCH and the first TPM chip; the BMC and the second TPM chip are respectively connected to the connector through an I2C interface to enable the transmission of I2C signals between the BMC and the second TPM chip; wherein, the motherboard further includes a comparator circuit, and the TPM module further includes a multiplexing circuit; the PCH and the BMC are connected to the eighth pin of the connector through the comparator circuit, the eighth pin is connected to the power supply pin of the first TPM chip, the power supply pin of the second TPM chip, and the reset pin through the multiplexing circuit, the PCH and the BMC receive the presence signal of the TPM module from the eighth pin through the comparator circuit, and the BMC sends a reset signal to the second TPM chip through the eighth pin; the multiplexing circuit includes: a first resistor, one end connected to the eighth pin and the other end grounded; a second resistor, one end connected to the eighth pin and the other end connected to the base of a first triode; the first triode, the base connected to the second resistor, the emitter grounded, and the collector connected to a third resistor and the base of a second triode; the third resistor, one end connected to the power supply pins of the first TPM chip and the second TPM chip, and the other end connected to the collector of the first triode; a fourth resistor, one end connected to the power supply pins of the first TPM chip and the second TPM chip, and the other end connected to the collector of the second triode; the second triode, the base connected to the collector of the first triode, the emitter grounded, and the collector connected to the fourth resistor and the reset pin of the second TPM chip; the comparator circuit includes: a comparator, the first input terminal connected to the power supply of a second preset voltage, the second input terminal connected to the eighth pin and a fifth resistor, and the output terminal connected to the PCH and the BMC; the fifth resistor, one end connected to the second input terminal of the comparator and the other end connected to the power supply of a first preset voltage.

2. The trusted motherboard system according to claim 1, characterized in that, the SPI signal includes a MOSI signal, a MISO signal, a CS signal, and an SCLK signal, the MOSI signal occupies the third pin of the connector, the MISO signal occupies the fourth pin of the connector, the CS signal occupies the fifth pin of the connector, and the SCLK signal occupies the first pin of the connector.

3. The trusted motherboard system according to claim 1, characterized in that, The I2C signal includes an SDA signal and a CLK signal. The SDA signal occupies the sixth pin of the connector, and the CLK signal occupies the tenth pin of the connector.

4. The trusted motherboard system according to claim 3, wherein, the TPM module further includes an IO expansion board, and the interrupt pin of the second TPM chip is connected to the sixth pin and / or the tenth pin of the connector through the IO expansion board.

5. The trusted motherboard system according to claim 1, wherein, the power pins of the first TPM chip and the second TPM chip are connected to the power supply of a first preset voltage through the seventh pin of the connector, and the eleventh pin of the connector is grounded.

6. The trusted motherboard system according to claim 1, wherein, the PCH is connected to the reset pin of the first TPM chip through the second pin of the connector, and the PCH sends a reset signal to the first TPM chip through the second pin; the PCH is connected to the interrupt pin of the first TPM chip through the ninth pin of the connector, and the PCH receives the interrupt signal of the first TPM chip through the ninth pin.

7. The trusted motherboard system according to claim 1, wherein, the second preset voltage is greater than the turn-on voltages of the first triode and the second triode, and the second preset voltage is less than the first preset voltage.

Citation Information

Patent Citations

  • TPM chip and method for improving application security of non-X86 system

    CN111241601A

  • High safe credible server based on homemade TPM

    CN208210006U