Method, computer program product, computing node for confirming a physical presence to a trusted platform module by physically connecting or disconnecting a hot-pluggable device

The method of using a hot-pluggable device to generate a physical presence signal to a TPM addresses the challenge of confirming presence without manual node manipulation, enhancing security and usability by detecting connection changes, thus protecting features like Secure Boot.

DE112014003976B4Active Publication Date: 2025-08-07LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE112014003976
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2013-08-29
Filing Date
2014-08-22
Publication Date
2025-08-07
Estimated Expiration
2034-08-22

AI Technical Summary

Technical Problem

Existing systems lack an efficient method to confirm physical presence to a trusted platform module (TPM) without requiring users to manually manipulate internal components or switches, thereby compromising security and ease of use.

Method used

A method and system that utilize a hot-pluggable device, such as a USB connector, to detect changes in physical connection to a port, generating a physical presence signal to the TPM, which can include multiple connections/disconnections within a predetermined time or pattern, optionally requiring authorization through a software interface.

Benefits of technology

Enhances security by confirming physical presence to the TPM without needing to open the compute node, thereby preventing unauthorized access and ensuring features like Secure Boot are protected, while providing user-friendly operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Procedure comprising the following steps: Asserting a physical presence signal to a trusted platform module on a motherboard of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to a port of the compute node, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUNDField of the invention

[0001] The present invention relates to systems having a trusted platform module and methods for confirming physical presence to a trusted platform module. General state of the art

[0002] A trusted platform module (TPM) is a microcontroller that stores keys, passwords, and digital certificates. A TPM is typically installed on the motherboard of a computer or any computing device requiring these functions. The nature of this microcontroller ensures that the information stored on the computer is better protected against external software attacks and physical theft. Security processes such as digital signatures and key exchange are protected by the TPM. For example, the TPM can deny access to data and secrets in a platform if the boot sequence does not proceed as expected. Critical applications and capabilities such as secure email, secure web access, and local data protection are thus better secured.

[0003] Publication US 2013 / 0 152 220 A1 teaches that software installed on a Universal Plug and Play device by a service provider can be managed only by that service provider using a method comprising: receiving a software installation command sent from a first control device; installing software according to the software installation command and storing first authentication information required during management of the software; receiving a software management command sent from a second control device; acquiring second authentication information corresponding to the software management command, the command being used in management of the software; and if the second authentication information matches the first authentication information, executing the software management command. SUMMARY

[0004] It is an object of the present invention to enable improved confirmation of physical presence to a trusted platform module.

[0005] This object is solved by the subject matter of main claim 1 and the independent claims 11 and 16, which define the present invention.

[0006] Preferred embodiments of the present invention are the subject of the subclaims.

[0007] An embodiment of the present invention provides a method comprising asserting a physical presence signal to a trusted platform module on a motherboard of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to a port of the compute node, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof.

[0008] Another embodiment of the present invention provides a computer program product comprising computer-readable program code embodied on a computer-readable storage medium. The computer program product comprises computer-readable program code for asserting a physical presence signal to a trusted platform module on a motherboard of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to the compute node, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof.

[0009] Another embodiment of the present invention provides a compute node comprising a motherboard having a trusted platform module and a port for selectively coupling a hot-pluggable device in communication with the motherboard. The compute node further comprises circuitry coupled to the port for detecting a change in the physical connection of the hot-pluggable device to the port and for asserting a physical presence signal for the trusted platform module in response to detecting a change in the physical connection of the hot-pluggable device to the port, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof. BRIEF DESCRIPTION OF THE MULTIPLE VIEWS OF THE DRAWINGS

[0010] They show: Fig. 1 is a diagram of a compute node including circuitry to assert physical presence to a trusted platform module in response to detecting the physical presence of a USB device on a USB port of the compute node. Fig. 2A is a diagram of a USB device physically disconnected from the compute node's USB port. Fig. Figure 2B is a diagram of a USB device physically connected to the USB port of the compute node. Fig. 3 is a flowchart of a method including confirming physical presence at a computing node having a trusted platform module. DETAILED DESCRIPTION

[0011] An embodiment of the present invention provides a method comprising asserting a physical presence signal to a trusted platform module of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to a port of the compute node, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof.

[0012] The hot-pluggable device may be of any type or have any plug-in configuration. However, the hot-pluggable device is preferably easily accessible for a user to manually grasp the hot-pluggable device to physically connect or disconnect it from the device. Most preferably, the compute node's connector may be externally accessible, such as by being exposed on a front panel of the compute node. Further, the compute node may be a narrow blade installed in a multi-blade chassis. For example, the front panel of an ITE (Information Technology Equipment) or compute node may include little more than a power button and one or more connectors. According to embodiments of the present invention, a connector may be used instead of a button to effect physical presence confirmation.Furthermore, embodiments of the present invention can confirm physical presence without requiring the user to remove the node from a chassis, open the node, and toggle a switch or jumper wire within the node, as is necessary with some existing compute nodes.

[0013] As a non-limiting example, the compute node includes a USB port, and the hot-pluggable device includes a USB connector that is physically connectable to and physically detachable from the USB port. Any of various common hot-pluggable USB devices may be used in this manner, such as a USB flash drive (also referred to as a thumb drive) or a hard disk drive. For the present invention, the specific functionality of the hot-pluggable device is irrelevant.

[0014] In another embodiment, a change in the physical connection of the hot-pluggable device to the compute node may be detected by detecting a voltage change at the compute node's connector. An electrical connection between the hot-pluggable device and the connector enables circuitry within the compute node to detect the voltage change. In particular, the circuitry may detect a voltage change when a previously disconnected hot-pluggable device is connected to the connector and may also detect a voltage change when a connected hot-pluggable device is disconnected from the connector.

[0015] Optionally, the physical presence signal can be asserted to the trusted platform module of the compute node in response to detecting at least a predetermined number of changes (two or more) in the physical connection of the hot-pluggable device to the compute node within a predetermined period of time. To cause the predetermined number of changes in the physical connection, it is necessary to use a specific combination of connecting and disconnecting the hot-pluggable device to / from the compute node's port.By way of non-limiting example, if confirmation of physical presence requires three changes in physical connection within a five-second period, then a user may physically handle a USB flash drive and, within the predetermined five-second period: (1) connect the USB flash drive to a USB port, (2) disconnect the USB flash drive from the USB port, and (3) reconnect the USB flash drive to the USB port. Alternatively, but for the purposes of the same non-limiting example, a USB flash drive that is already connected to the USB port may be physically handled to confirm physical presence by, within the predetermined five-second period: (1) disconnecting the USB flash drive from the USB port, (2) reconnecting the USB flash drive to the USB port, and (3) reconnecting the USB flash drive from the USB port.In another option, the physical presence signal may be asserted to the trusted platform module of the compute node in response to detecting a plurality of changes in the physical connection of the hot-pluggable device to the compute node that occur in a predetermined pattern.

[0016] In yet another embodiment, additional conditions must be met before a physical presence signal is asserted to a trusted platform module of a compute node. For example, a physical presence signal may be asserted to a trusted platform module of a compute node in response to: (a) detecting a change in the physical connection of the hot-pluggable device to the compute node; and (b) releasing the physical presence signal via a software interface of the compute node. Requiring multiple conditions, such as these two conditions, provides greater security against inadvertently asserting physical presence. In this example, a user accidentally connecting, disconnecting, and reconnecting a USB flash drive would not be sufficient to assert physical presence.Rather, a user with appropriate authorization may log into a software interface, such as an interface for maintaining TPM settings, and enable the physical presence signal (perhaps enabled for a predetermined period of time) just before connecting, disconnecting, and reconnecting a USB flash drive (i.e., by causing three voltage changes in less than five seconds, according to the preceding non-limiting example).

[0017] In another embodiment, the method may permit a change to one or more settings of the compute node during a predetermined period of time after the physical presence signal is acknowledged. Alternatively, the method may permit a change to one or more settings of the compute node if the physical acknowledgement signal is acknowledged within a predetermined period of time after the request to change the one or more settings. For example, the one or more settings may affect the operation of the trusted platform module. One non-limiting example of a setting that may be protected by physical presence is the Secure Boot feature. When enabled, Secure Boot only boots an operating system (OS) whose bootloader is signed with a key from the operating system developer, such as Microsoft Corporation.Therefore, the physical presence verification of the present invention can be used to protect against malicious hackers disabling the Secure Boot feature.

[0018] Another embodiment of the present invention provides a computer program product comprising computer-readable program code embodied on a computer-readable storage medium. The computer program product comprises computer-readable program code for asserting a physical presence signal to a trusted platform module of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to the compute node, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof.

[0019] The above computer program product may further comprise computer-readable program code for implementing or initiating one or more aspects of the method described herein. Accordingly, a separate description of the method in connection with a computer program product will not be repeated.

[0020] Another embodiment of the present invention provides a compute node comprising a motherboard having a trusted platform module and a port for selectively coupling a hot-pluggable device in communication with the motherboard. The compute node further comprises circuitry coupled to the port for detecting a change in the physical connection of the hot-pluggable device to the port and for asserting a physical presence signal to the trusted platform module in response to detecting a change in the physical connection of the hot-pluggable device to the port, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof.

[0021] Fig. 1 is a diagram of a compute node 10 including circuitry 20 for asserting physical presence (PP) to a trusted platform module 32 in response to detecting the physical presence of a USB device (not shown) at a USB port 12 in the front panel 14 of the compute node 10. The USB port 12 provides physical support and electronic connections that enable the USB device (or other hot-pluggable device) to communicate with components on the motherboard 16.

[0022] The circuit 20 includes detection hardware 21 coupled to the port 12 for detecting a change in the physical connection of the hot-pluggable device to the port 12 and asserting a physical presence (PP) signal to the trusted platform module 32 in response to detecting a change in the physical connection of the hot-pluggable device to the port 12. As shown, the circuit 20 generates a detection signal 22 in response to detecting the change in the physical connection. The circuit is also coupled to a chipset 18 to receive an enable signal 24, and the circuit 20 includes an AND gate 26 that receives the enable signal and the detection signal and outputs the physical presence signal to the trusted platform module 32.The circuit 20 further includes an OR gate 30 that receives the physical presence signal 28 and a physical jumper detection signal 29, and wherein the output of the OR gate is coupled to the trusted platform module 32 to provide a physical presence signal 31 to the TPM 32. The utility of the OR gate 30 is to allow a user to confirm physical presence using either the present methods for connecting / disconnecting a hot-pluggable device to / from the port 12 or the method for toggling or positioning a jumper within the enclosure of the compute node 10.

[0023] Fig. Figure 2A is a diagram of a USB device 40 physically separated from the USB port 12 of the compute node 10. According to a universal serial bus configuration, the USB device 40 and the USB port 12 have four aligned conductors—a power line 41, 51, a first data line (D - ) 42, 52, a second data line (D + ) 43, 53 and a ground line 44, 54. The computing node 10 comprises a detection hardware or a comparison circuit 21, which measures the voltages on the D + - and D - -lines 52, 53 to generate the physical presence signal 22. It is understood that the PP signal 22 as in Fig. 1 can be coupled to the AND gate 26.

[0024] Fig. Figure 2B is a diagram of USB device 40 when physically connected to USB port 12 of compute node 10. When physically connected as shown, conductors 41 through 44 of hot-pluggable USB device 40 are electronically coupled to conductors 51 through 54 of port 50.

[0025] With reference to both Fig. 2A as well as on Fig. 2B, it can be seen that a change in the physical connection of the hot-pluggable device 40 to the connector 12 results from physically connecting the hot-pluggable device to the connector (moving the hot-pluggable device from the position in Fig. 2A into the position in Fig. 2B), physically disconnecting the hot-pluggable device from the connector (moving the hot-pluggable device from the position in Fig. 2B into the position in Fig. 2A) and combinations thereof. Circuit 21 is capable of detecting these two changes in the physical connection of hot-pluggable device 40 to compute node 10 by detecting a voltage change at terminal 12.

[0026] Fig.3 is a flowchart of a method including confirming physical presence in a compute node having a trusted platform module. As shown in box 62, a user physically connects and / or disconnects a hot-pluggable device to a port of a compute node. As shown in box 64, a change in the physical connection of the hot-pluggable device to the compute node port is detected. Then, in step 66, the method confirms a physical presence signal to a trusted platform module of the compute node in response to detecting a change in the physical connection of the hot-pluggable device to the compute node port.

[0027] As will be understood by those skilled in the art, various aspects of the present invention may be embodied as a system, method, or computer program product. Accordingly, aspects of the present invention may take the form of an all-hardware embodiment, an all-software embodiment (including firmware, in-memory software, microcode, etc.), or an embodiment combining software and hardware aspects, all of which are generally referred to herein as a "circuit," "module," or "system." Further, aspects of the present invention may take the form of a computer program product embodied in one or more computer-readable media having computer-readable program code embodied therein.

[0028] Any combination of one or more computer-readable media may be used. The computer-readable medium may be a computer-readable medium or a computer-readable storage medium. A computer-readable storage medium may, for example, be, without limitation, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination thereof.More specific examples (a non-exhaustive list) of the computer-readable storage medium would include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the context of this specification, a computer-readable storage medium may be any tangible medium that can contain or store a program for use in connection with a system, apparatus, or device for executing instructions.

[0029] A computer-readable signal medium may comprise a propagated data signal embodying computer-readable program code, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, without limitation, electromagnetic, optical, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium, other than a computer-readable storage medium, that can communicate, propagate, or transport a program for use by or in connection with an instruction-executing system, apparatus, or device.

[0030] Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including, without limitation, wirelessly, wired, via optical fiber, RF, etc., or any suitable combination thereof. Computer program code for performing operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, Smalltalk, C++, or the like, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server.In the latter case, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., over the Internet using an Internet service provider).

[0031] Aspects of the present invention may be described with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, may be implemented by computer-readable program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a specific computer, and / or other programmable data processing apparatus to result in a machine, such that the instructions, executing via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the block or blocks of the flowcharts and / or block diagrams.

[0032] These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing apparatus or other devices to function in a particular manner, such that the instructions stored on the computer-readable storage medium result in a product that includes instructions that implement the function / action specified in the block or blocks of the flowchart and / or block diagram.

[0033] The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable device, or other devices to result in a computer-implemented process, such that the instructions executing on the computer or other programmable device provide processes to implement the functions / acts specified in the block or blocks of the flowchart and / or block diagram.

[0034] The flowcharts and block diagrams in the figures depict the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of code comprising one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions mentioned in the block may occur in a different order than mentioned in the figures. For example, two blocks shown sequentially may actually execute substantially concurrently, or the blocks may sometimes execute in reverse order, depending on the functionality involved.It should also be understood that each block of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented with special purpose hardware-based systems that perform the specified functions or actions, or with combinations of special purpose hardware and computer instructions.

[0035] The description of the present invention has been presented for the purpose of illustration and description. Numerous modifications and variations will become apparent to those skilled in the art without departing from the scope of the invention, which is defined by the claims.

Claims

[1] Method comprising the following steps: Asserting a physical presence signal to a trusted platform module on a motherboard of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to a port of the compute node, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof. [2] The method of claim 1, wherein the compute node has a USB port and the hot-pluggable device has a USB connector selectively physically connectable to the USB port. [3] The method of claim 2, wherein detecting a change in the physical connection of the hot-pluggable device to the compute node comprises detecting a voltage change at the USB port. [4] The method of claim 2, wherein the compute node is a blade installed in a multi-blade chassis. [5] The method of claim 1, wherein the hot-pluggable device is a hard disk drive. [6] The method of claim 1, further comprising the step of: Allowing a change to one or more settings of the compute node during a predetermined period after the physical presence signal has been acknowledged. [7] The method of claim 6, wherein the one or more settings affect the operation of the trusted platform module. [8] The method of claim 1, wherein asserting a physical presence signal to a trusted platform module of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to the compute node comprises the steps of: Confirming a physical presence signal to a trusted platform module of a compute node in response to: Detecting a change in the physical connection of the hot-pluggable device to the compute node; and Releasing the physical presence signal via a software interface of the compute node. [9] The method of claim 1, wherein asserting a physical presence signal to a trusted platform module of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to the compute node comprises the step of: Asserting a physical presence signal to a trusted platform module of a compute node in response to detecting at least a predetermined number of changes in the physical connection of the hot-pluggable device to the compute node within a predetermined period of time, wherein the predetermined number is two or more. [10] The method of claim 1, wherein asserting a physical presence signal to a trusted platform module of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to the compute node comprises the step of: Asserting a physical presence signal to a trusted platform module of a compute node in response to detecting a plurality of changes in the physical connection of the hot-pluggable device to the compute node occurring in a predetermined pattern. [11] A computer program product comprising computer-readable program code embodied on a computer-readable storage medium, the computer program product comprising: Computer-readable program code for asserting a physical presence signal to a trusted platform module on a motherboard of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to the compute node, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof. [12] The computer program product of claim 11, further comprising: computer-readable program code for permitting a change in one or more settings of the compute node during a predetermined period of time after acknowledgment of the physical presence signal. [13] The computer program product of claim 12, wherein the one or more settings affect the operation of the trusted platform module. [14] The computer program product of claim 11, further comprising: computer-readable program code for releasing the physical presence signal via a software interface of the computing node. [15] The computer program product of claim 11, wherein the computer readable program code for asserting a physical presence signal to a trusted platform module of a compute node in response to detecting a change in the physical connection of a hot-pluggable device to the compute node comprises: Computer-readable program code for asserting a physical presence signal to a trusted platform module of a compute node in response to detecting at least a predetermined number of changes in the physical connection of a hot-pluggable device to the compute node within a predetermined period of time, wherein the predetermined number is two or more. [16] Compute nodes, comprising: a motherboard that includes a trusted platform module; a connector for selectively coupling a hot-pluggable device that is connected to the motherboard; and circuitry coupled to the port to detect a change in the physical connection of the hot-pluggable device to the port and to assert a physical presence signal to the trusted platform module in response to detecting a change in the physical connection of the hot-pluggable device to the port, wherein the change in the physical connection of the hot-pluggable device to the port is selected from physically connecting the hot-pluggable device to the port, physically disconnecting the hot-pluggable device from the port, and combinations thereof. [17] The compute node of claim 16, wherein the compute node includes a USB port and the hot-pluggable device includes a USB connector selectively physically connectable to the USB port. [18] The compute node of claim 16, wherein the circuit detects a change in the physical connection of the hot-pluggable device to the compute node by detecting a voltage change at the connector. [19] The compute node of claim 16, wherein the circuit generates a detection signal in response to detecting the change in the physical connection, the circuit also being coupled to a chipset to receive an enable signal, and the circuit comprising an AND gate receiving the enable signal and the detection signal and outputting the physical presence signal to the trusted platform module. [20] The compute node of claim 19, wherein the circuit further comprises an OR gate receiving the physical presence signal and a physical jumper detection signal, and wherein the output of the OR gate is coupled to the trusted platform module.

Citation Information

Patent Citations

  • Method, Apparatus and System for Software Management

    US20130152220A1