Data processing system for trusted computing
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- MUSE ELECTRONICS GMBH
- Filing Date
- 2024-06-14
- Publication Date
- 2026-04-29
Smart Images

Figure AT2024060230_26122024_PF_FP_ABST
Abstract
Description
[0001] Data processing system for trusted computing
[0002] The present invention relates to a data processing system comprising a central processor unit which is fed by a power supply, at least two mass storage devices, one of which can be optionally connected to the central processor unit via a first data bus, and a trusted platform module which can be connected to the central processor unit via a second data bus.
[0003] A data processing system with a Trusted Platform Module (TPM) is also referred to as a Trusted Computing Platform (TC Platform). The TPM is a hardware or software element according to the TPM specification, which is standardized by the Trusted Computing Group (TCG), most recently in version TPM 2.0. In practice, the TPM is usually implemented as a separate hardware chip that is directly connected to the central processing unit via its own data bus, for example a serial bus according to the SPI (Serial Peripheral Interface), LPC (Low Pin Count) or i standards. 2 C .
[0004] A TPM can be used for many security applications within a data processing system. For example, it provides a random number generator, cryptographic encryption algorithms, keys, and protected storage areas for encrypted data. In connection with mass storage devices, the TPM can be used, for example, for hardware-level encryption of the contents of the mass storage device. Or the TPM serves as protected storage for encrypted hash values of snapshots of the hardware and / or the operating system stored on a mass storage device when the operating system is booted, in order to verify its software integrity or to ensure correct hardware assignment.
[0005] Using the same data processing system with different operating systems stored on different mass storage devices, or with differently encrypted mass storage devices, is difficult with existing solutions. The invention aims to overcome these limitations and create a data processing system that can provide mass storage-related TPM services for use with different mass storage devices.
[0006] This aim is achieved in a first embodiment of the invention with a data processing system of the type mentioned in the introduction, which is characterized by a microcontroller which can be connected to the second data bus, wherein the trusted platform module has at least two register banks of platform configuration registers, of which only one register bank is active in an operating mode of the data processing system and the active register bank can be set by a control command received from the microcontroller, wherein the microcontroller is designed to set the active register bank in a configuration mode of the data processing system by means of the control command in accordance with the mass storage device selected for the operating mode.
[0007] In this embodiment, the data processing system preferably has a switch which is adjustable by the microcontroller and connected to the second data bus, which switch connects the Trusted Platform module either to the central processor unit or to the microcontroller, wherein the microcontroller is designed to use the switch to connect the Trusted Platform module to the central processor unit in operating mode and to the microcontroller in configuration mode.
[0008] In a second embodiment, the invention achieves its objective with a data processing system of the type mentioned in the introduction, which is characterized by a microcontroller and a changeover switch which is adjustable by the microcontroller and is connected to the second data bus and which connects the central processor unit in an operating mode of the data processing system via the second data bus either to the first trusted platform module or to a second trusted platform module, wherein the microcontroller is designed to set the changeover switch in a configuration mode of the data processing system in accordance with the mass storage device selected for the operating mode.
[0009] In a third embodiment, the invention creates a data processing system of the type mentioned in the introduction, which is characterized by a microcontroller which is connected to the second data bus and is designed to emulate both the first trusted platform module and a second trusted platform module as a software instance, of which software instances only one is active in an operating mode of the data processing system, wherein the microcontroller is designed to set the active software instance in a configuration mode of the data processing system according to the mass storage device selected for the operating mode.
[0010] In this embodiment, the two Trusted Platform modules of the second embodiment are implemented as software instances in the microcontroller, which simplifies practical implementation.
[0011] In all three embodiments mentioned, it is particularly advantageous if each mass storage device is provided with a machine-readable identifier and the microcontroller is connected to a reader for reading identifiers and is designed to detect the mass storage device selected for the operating mode on the basis of the identifier read by the reader.
[0012] Preferably, the configuration mode is an alternative to the operating mode, but could also be used temporarily in parallel with the operating mode.
[0013] In a fourth embodiment, the invention achieves the stated object with a data processing system of the type mentioned in the introduction, which is characterized by a second trusted platform module which can be connected to the second data bus optionally instead of the first trusted platform module, wherein one of the mass storage devices and one of the trusted platform modules which is assigned to this mass storage device are arranged in a common transport housing which is detachably connected to the rest of the data processing system.
[0014] In each of the four embodiments mentioned, the data processing system according to the invention enables the optional use of different mass storage devices, for example those loaded with different operating systems or encrypted in different ways, in conjunction with the TPM services of a TPM individually configured for the respective mass storage device or individually configured platform configuration registers (PCRS) of a TPM.
[0015] By using a switch, it can be ensured in the first two embodiments that the TPM always communicates with only a single component on the bus via the second data bus, thus avoiding communication disruptions. Furthermore, this embodiment is particularly suitable for simple TPMs that are not equipped for multi-partner communication.
[0016] In the fourth embodiment, in which a TPM and a mass storage device are combined in a separate housing that can be connected to the rest of the data processing system, instead of selectively switching a switch, a different transport housing can simply be connected. The invention thus creates a new product, namely a replaceable unit consisting of a mass storage device and a TPM that can be used interchangeably with one and the same central processing unit.
[0017] In the first three embodiments, it is preferable to interrupt the power supply of the central processing unit in configuration mode. As a result, the central processing unit restarts after returning to operating mode and thus reconnecting the power supply and boots using the connected mass storage device and associated TPM.
[0018] The first data bus can be implemented according to any known state-of-the-art technology suitable for connecting mass storage devices. Preferably, the first data bus is implemented according to one of the following standards: USB, USB-C, Thunderbolt, SATA, eSATA, PCI, or PCIe.
[0019] The second data bus can also be implemented according to any known standard suitable for connecting TPMs. The second data bus is preferably implemented according to one of the following standards: i2C, SPI, or LPC.
[0020] In all the above-mentioned embodiments, each of the mass storage devices is preferably a semiconductor hard disk or a non-volatile memory chip.
[0021] The invention is explained in more detail below with reference to exemplary embodiments illustrated in the accompanying drawings. In the drawings:
[0022] Fig. 1 shows a first embodiment of the data processing system of the invention in a block diagram;
[0023] Fig. 2 shows a second and a third embodiment of the data processing system of the invention in a block diagram; and
[0024] Fig. 3 shows a fourth embodiment of the data processing system of the invention in a block diagram.
[0025] Fig. 1 shows a first embodiment of a data processing system 1. The data processing system 1 comprises a central processor unit 2, to which a main memory 3 and at least one input / output unit 4, e.g., a monitor, a keyboard, a touchscreen, a printer, a network adapter, and / or any input / output interface, are connected.
[0026] One of several mass storage devices 6i, 62, ..., generally 6i, can be optionally connected to the central processor unit 2 via a first data bus 5. The mass storage devices 6i are, in particular, persistent mass storage devices, i.e., they store their contents for extended periods even without a power supply. Examples of such persistent mass storage devices are magnetic or optical hard disks, semiconductor hard disks, or non-volatile memory chips such as flash RAMs, ROMs, PROMs, EPROMs, EEPROMs, SSDs (Solid State Disks), etc. The first data bus 5 can be designed according to a standard suitable for such mass storage devices 6i, for example, according to the USB, USB-C, Thunderbolt, SATA, eSATA, PCI, or PCIe standards.
[0027] A trusted platform module (TPM) 8 is connected to the central processor unit 2 via a second data bus 7, in the example shown via a switch 9 which is connected to the second data bus 7. The TPM 8 is a trusted platform module according to a TPM standard of the Trusted Computing Group (TCG), for example according to the TPM 1.2 or TPM 2.0 standard. The TPM 8 provides the data processing system 1 with standardized TPM services and for this purpose has at least one bank of platform configuration registers (PCRs) for storing keys, hash values, etc., which can be stored or retrieved via the second data bus 7 (e.g. encrypted).
[0028] In the example shown here, the TPM 8 has two or more banks PCRi, PCR2, ..., generally PCRi, of platform configuration registers. An internal switch 10 in the TPM 8 can be used to select the ("active") register bank PCRi used in the operating mode of the data processing system 1, i.e., when the central processor unit 2 wishes to communicate with the TPM 8 via the data bus 7.
[0029] To set the switches 9 and 10, the data processing system 1 comprises a microcontroller 11. The microcontroller 11 is either permanently connected to the second data bus 7 or - as in the example shown - can be connected to the TPM 8 via the switch 9 instead of the central processor unit 2. In the operating mode of the data processing system 1 shown in Fig. 1, the switch 9, if present, is in the lower switch position shown, so that the microcontroller 11 is disconnected from the second data bus 7 and is inactive. If, on the other hand, no switch 9 is used, i.e. both the microcontroller 11 and the TPM 8 are connected to the second data bus 7 of the central processor unit 2, the microcontroller 11 refrains from any communication on the second data bus 7 in the operating mode of the data processing system 1 in order not to disrupt the communication between the TPM 8 and the central processor unit 7.
[0030] The data processing system 1 can be placed into a special configuration mode—in addition to, or particularly alternatively to, its operating mode. If a changeover switch 9 is present, the changeover switch 9 is then placed in its upper position in Fig. 1, thereby connecting the TPM 8 to the microcontroller 11 via the second data bus 7. The microcontroller 11 can itself initiate the switching of the changeover switch 9, see control path 12.
[0031] In configuration mode, the microcontroller 11 sends a control command 13 to the TPM 8 via the second data bus 7 to set the TPM-internal switch 10 (see dotted control path), in order to select one of the PCR register banks PCRi in the TPM 8 as the “active” register bank for further operation. After leaving the configuration mode and re-entering the operating mode, i.e. after setting the switch 9 to the lower position shown in Fig. 1, if present, or after the microcontroller 7 has abstained from any further communication on the data bus 7, the selected register bank PCRi continues to be used by the central processor unit 2. The central processor unit 2 does not notice that the active PCR register bank PCRi in the TPM 8 has changed. If switch 9 is not used, the configuration mode can also be entered temporarily during operation mode.
[0032] Optionally, in configuration mode, a power supply 14 supplying the central processor unit 2 can be interrupted by the microcontroller 11 via a controllable switch 15 and a corresponding control path 16. This also allows exclusive communication between the microcontroller 11 and the TPM 8 to be achieved in configuration mode, particularly if no switch 9 is provided.
[0033] The microcontroller 11 is programmed to select the respective register bank PRCi by controlling the switch 10 depending on the mass storage device 6i currently connected to the first data bus 5. For the first mass storage device 6i, the microcontroller 11, for example, sets the first register bank PCRi, for the second mass storage device 62, the second register bank PCR2, etc.
[0034] The microcontroller 11 can receive the information as to which mass storage device 6i is connected or is to be connected to the first data bus 5 in operating mode, for example, via an input device 17, i.e. the user, on the one hand, connects the respective mass storage device 6i to the data bus 5 and, on the other hand, sets the microcontroller 11 accordingly via the input device 17. Alternatively, the microcontroller 11 can receive this information automatically from the first data bus 5 via a corresponding data connection 18. A further possibility is for the microcontroller 11 to be connected to a reader 19 which reads out a corresponding identification 20 of the respective mass storage device 6i. The identification 20 can, for example, be a barcode, an RFID tag or the like, which is attached to or in the mass storage device 6i. The reading device 19 can be a corresponding barcode reader, RFID reader or the like.However, the identification 20 can also be stored, for example, in a special section or module of the mass storage device 6i, which can be read by the reading device 19; the reading device 19 can then be, for example, a corresponding interface.
[0035] Fig. 2 shows a second and a third embodiment of the data processing system 1, wherein only the differences compared to the embodiment of Fig. 1 are discussed here. Instead of a single TPM 8, the data processing system 1 has several TPMs 8i, 82, generally 8i.
[0036] In the second embodiment, the various TPMs 8i are physical units and can be alternatively connected to the central processor unit 2 via a switch 21 connected to the second data bus 7. The microcontroller 11 is now programmed such that, in configuration mode, it connects a TPM 8i assigned to a mass storage device 6i to the central processor unit 2 via the switch 21 and the data bus 7. Everything else, such as the selection or recognition of the mass storage device 6i used in the respective operating mode by the microcontroller 11 for the purpose of controlling the switch 21, takes place as described in the embodiment of Fig. 1 for controlling the TPM-internal switch 10.
[0037] In the third embodiment, the TPMs 8i are implemented as software instances in the programming of the microcontroller 11, as symbolized by the dash-dotted frame 11'. The switch 21 is accordingly also a software component in the programming of the microcontroller 11. It is understood that such software instances can also be implemented in firmware used to program the microcontroller 11. The microcontroller 11 is now programmed such that, in configuration mode, it uses the software switch 21 to set the TPM 8i assigned to the respective mass storage device 6i and connects it to the data bus 7. Everything else, such as the selection or recognition of the mass storage device 6i used in the operating mode by the microcontroller 11 for the purpose of controlling the switch 11 and setting the corresponding emulated TPM 8i, is again carried out as in the embodiment of Fig.1 for controlling the TPM internal switch 10.
[0038] Fig. 3 shows a fourth embodiment of the data processing system 1, which does not require switches 10 or 21 for selecting between different register banks PCRi of a TPM 8 or between different TPMs 8i. In Fig. 3, a TPM 8i with its associated mass storage device 6i is arranged in a separate transport housing 22. lz 222, generally 22i. Each transport housing 22i is detachably connectable to the remaining part 23 of the data processing system 1, namely via an interface 24, which comprises, for each transport housing 22i, a first interface 25 for detachable connection to the first data bus 5 and a second interface 26 for detachable connection to the second data bus 7.
[0039] The transport housing 22i can, for example, be the housing of a memory stick or an SSD, which in addition to the mass storage interface 25 for the mass storage 6i has the further interface 26 for the integrated TPM 8i.
[0040] In this fourth embodiment, the TPM 8i can again be emulated as a software instance by a microcontroller in the mass storage device 6i, if desired. It is understood that such software instances can also be implemented as microcontroller firmware.
[0041] The data processing system 1 can be designed in any form and for any purpose, for example as a server, terminal, computer, notebook, laptop, PDA (Personal Digital Assistant), smartphone or the like.
[0042] The invention is not limited to the illustrated embodiments, but includes all variants, modifications and combinations thereof that fall within the scope of the appended claims.
Claims
Patent claims:
1. A data processing system comprising a central processor unit (2) which is fed by a power supply (14), at least two mass storage devices (6i), one of which can be selectively connected to the processor unit (2) via a first data bus (5), and a trusted platform module (8) which can be connected to the processor unit (2) via a second data bus (7), characterized by a microcontroller (11) which can be connected to the second data bus (7), wherein the trusted platform module (8) has at least two register banks (PCRi) of platform configuration registers, of which only one register bank (PCRi) is active in an operating mode of the data processing system (1) and the active register bank (PCRi) can be set by a control command (13) received from the microcontroller (11), wherein the microcontroller (11) is designed toin a configuration mode of the data processing system (1), by means of the control command (13) to set the active register bank (PCRi) according to the mass storage device (6i) selected for the operating mode.
2. Data processing system according to claim 1, characterized by a changeover switch (9) which is adjustable by the microcontroller (11) and connected to the second data bus (7), which switch connects the trusted platform module (8) either to the processor unit (2) or to the microcontroller (11), wherein the microcontroller (11) is designed to connect the trusted platform module (8) to the processor unit (2) in operating mode and to the microcontroller (11) in configuration mode by means of the changeover switch (9).
3. Data processing system, comprising a central processor unit (2) which is fed by a power supply (14), at least two mass storage devices (6i), one of which can be selectively connected to the processor unit (2) via a first data bus (5), and a first trusted platform module (8i) which can be connected to the processor unit (2) via a second data bus (7), characterized by a microcontroller (11) and a changeover switch (21) which can be set by the microcontroller (11) and is connected to the second data bus (7), which switch connects the processor unit (2) in an operating mode of the data processing system (1) via the second data bus (7) either to the first trusted platform module (8i) or to a second trusted platform module (82), wherein the microcontroller (11) is designed to, in a configuration mode of the data processing system (1), changeover switch (21) in accordance with the Operating mode selected mass storage (6i).
4. Data processing system, comprising a central processor unit (2) which is fed by a power supply (14), at least two mass storage devices (6i), one of which can be selectively connected to the processor unit (2) via a first data bus (5), and a first trusted platform module (81) which can be connected to the processor unit (2) via a second data bus (7), characterized by a microcontroller (11) which is connected to the second data bus (7) and is designed to emulate both the first trusted platform module (81) and a second trusted platform module (82), each as a software instance (8i), of which software instances (8i) in an operating mode of the data processing system (1) only one is active at a time, wherein the microcontroller (11) is designed to set the active software instance (8i) in a configuration mode of the data processing system (1) according to the mass storage device (6i) selected for the operating mode.
5. Data processing system according to one of claims 1 to 4, characterized in that each mass storage device (6i) is provided with a machine-readable identifier (20) and the microcontroller (11) is connected to a reader (19) for reading identifiers (20) and is designed to detect the mass storage device (6i) selected for the operating mode on the basis of the identifier (20) read by the reader (19).
6. Data processing system according to one of claims 1 to 5, characterized in that the configuration mode is alternative to the operating mode.
7. Data processing system according to one of claims 1 to 6, characterized in that in the configuration mode the power supply (14) of the central processor unit (2) is interrupted.
8. Data processing system, comprising a central processor unit (2), at least two mass storage devices (6i), one of which can be selectively connected to the processor unit (2) via a first data bus (5), and a first trusted platform module (8i), which can be connected to the processor unit (2) via a second data bus (7), characterized by a second trusted platform module (82), which can be selectively connected to the second data bus (7) instead of the first trusted platform module (8i), wherein one of the mass storage devices (6i) and one of the trusted platform modules (8i) assigned to this mass storage device (6i) are in a common transport housing (22i) which is detachably connected to the remaining data processing system (23).
9. Data processing system according to one of claims 1 to 8, characterized in that the first data bus (5) is designed according to one of the standards USB, USB-C, Thunderbolt, SATA, eSATA, PCI or PCIe.
10. The data processing system according to one of claims 1 to 9, wherein the second data bus (7) is configured according to one of the i2C, SPI, or LPC standards.
11. The data processing system according to one of claims 1 to 10, wherein each of the mass storage devices (6i) is a semiconductor hard disk or a non-volatile memory chip.