Data processing system for trusted computing

The data processing system addresses compatibility issues by using a microcontroller to manage TPM services and switch connections based on mass storage devices, ensuring seamless operation and security with diverse storage configurations.

JP2026524616APending Publication Date: 2026-07-23MUSE ELECTRONICS GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
MUSE ELECTRONICS GMBH
Filing Date
2024-06-14
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Existing data processing systems face challenges in using Trusted Platform Modules (TPMs) with different mass storage devices due to compatibility issues and communication failures, particularly when different operating systems or encryption schemes are employed.

Method used

A data processing system with a microcontroller that manages TPM services by configuring active register banks and using changeover switches or software instances to connect TPMs to the central processing unit based on selected mass storage devices, ensuring seamless communication and compatibility.

Benefits of technology

Enables the use of diverse mass storage devices with individually configured TPM services, preventing communication failures and supporting different operating systems or encryption schemes, while maintaining system integrity and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026524616000001_ABST
    Figure 2026524616000001_ABST
Patent Text Reader

Abstract

Data processing system for trusted computing The data processing system (1) includes one of a processing device (2), at least two selectively connectable mass storage devices (6 i ), and a trusted platform module (8) having at least two switchable register banks (PCR i ), or at least two switchable physical or virtual trusted platform modules (8 i ). One of the register banks (PCR i ), or one of the trusted platform modules (8 i ) is activated according to the connected mass storage device (6 i ). Alternatively, any one of the trusted platform modules (8 i ) is connected together with the corresponding mass storage device (6 i ).
Need to check novelty before this filing date? Find Prior Art

Description

Detailed description of the invention

[0001] The present invention relates to a data processing system comprising: a central processing unit powered by a power supply unit; at least two mass storage devices, one of which can be selectively connected to the central processing unit via a first data bus; and a trusted platform module that can be connected to the central processing unit via a second data bus.

[0002] A data processing system with a Trusted Platform Module (TPM) is also called a Trusted Computing Platform (TC Platform). A TPM is a hardware or software element that conforms to the TPM specification standardized by the Trusted Computing Group (TCG), with the latest version being TPM 2.0. In practice, a TPM is typically configured as a separate hardware chip and uses SPI (Serial Peripheral Interface), LPC (Low Pin Count), or i 2 It is directly connected to the central processing unit via an independent data bus, such as a serial bus compliant with the C standard.

[0003] TPMs can be used for many security purposes as part of a data processing system. For example, they provide a random number generator, encryption algorithms, keys, and a protected memory area for encrypted data. In conjunction with mass storage devices, TPMs can be used, for example, to hardware-oriented encrypt the contents of the mass storage device. Alternatively, TPMs can function to verify software integrity or ensure correct hardware allocation by using encrypted hash values ​​of hardware and / or operating system snapshots stored in mass storage at operating system startup as protected memory.

[0004] Using different operating systems or different encryption schemes stored on different mass storage devices within the same data processing system is difficult to achieve using known solutions. The object of the present invention is to overcome these limitations and provide a data processing system that can provide a mass storage-based TPM service usable with different mass storage devices.

[0005] In a first embodiment of the present invention, this objective is achieved by a data processing system of the type described at the beginning. The data processing system comprises a microcontroller connectable to the second data bus, the trusted platform module having at least two register banks of platform configuration registers, in an operating mode of the data processing system only one of the register banks is active, the active register bank is configurable by a control command received from the microcontroller, and the microcontroller is configured to set the active register bank by the control command in a setting mode of the data processing system, depending on the mass storage device selected for the operating mode.

[0006] In this embodiment, the data processing system preferably includes a changeover switch configurable by a microcontroller. The changeover switch is inserted into the second data bus and connects the trusted platform module to either the central processing unit or the microcontroller. The microcontroller is configured to connect the trusted platform module to the central processing unit in the operating mode and to connect it to the microcontroller using the changeover switch in the configuration mode.

[0007] In a second embodiment, the present invention achieves this objective by a data processing system of the type described at the beginning. This data processing system comprises a microcontroller, a selectable switch settable by the microcontroller inserted into the second data bus, and in an operating mode of the data processing system, the central processing unit is connected to either the first trusted platform module or the second trusted platform module via the second data bus, and the microcontroller is configured to set the selectable switch in accordance with the mass storage device selected for the operating mode in a setting mode of the data processing system.

[0008] In a third embodiment, the present invention provides a data processing system of the type described at the beginning. This data processing system comprises a microcontroller connected to the second data bus, the microcontroller being connected to the second data bus and configured to emulate the first trusted platform module and the second trusted platform module, respectively, as software instances, in each case only one of these software instances being active in the operating mode of the data processing system, and the microcontroller being configured in the setting mode of the data processing system to set the active software instance according to the mass storage device selected for the operating mode.

[0009] In this embodiment, the two trusted platform modules of the second embodiment are implemented as software instances within a microcontroller, thereby simplifying the practical implementation.

[0010] In all three of the above embodiments, it is particularly advantageous to provide each mass storage device with a machine-readable identifier, and to configure the microcontroller to connect to a reader for reading the identifier, and to detect the mass storage device selected for the operating mode based on the identifier read by the reader.

[0011] The setting mode is preferable as an alternative to the operating mode, but it can also be temporarily used in parallel with the operating mode.

[0012] In a fourth embodiment, the present invention solves the above problems using the type of data processing system described at the beginning. This system features a second trusted platform module that can be selectively connected to a second data bus instead of a first trusted platform module. One of the mass storage devices and one of the trusted platform modules assigned to this mass storage device are housed in a shared transport enclosure that is detachably connected to the rest of the data processing system.

[0013] In each of the four embodiments described above, the data processing system of the present invention enables the use of different mass storage devices as needed. For example, it enables the use of different mass storage devices as needed, such as those with different operating systems or those encrypted in different ways, in combination with TPM services of TPMs individually configured on each mass storage device, or individually configured platform configuration registers (PCRs) of TPMs.

[0014] By using a changeover switch, the first two embodiments can ensure that the TPM always communicates via the second data bus and only with a single component on that bus. This prevents communication failures. Furthermore, this embodiment is particularly suitable for simple TPMs that do not support inter-component communication.

[0015] In the fourth embodiment, the TPM and the mass storage device are each incorporated in separate housings, and the housings are connectable to the rest of the data processing system. Alternatively, instead of switching a switch, it is also possible to simply connect another transportation housing. Thus, the present invention provides a completely new product, namely, a replaceable device composed of a mass storage device and a TPM. This device can be used compatible with the same central processing unit.

[0016] In the first three embodiments, it is preferable to shut off the power supply to the central processing unit in the setting mode. As a result, after returning to the operation mode and the power supply is restarted, the central processing unit starts up and starts up using the connected mass storage device and the assigned TPM, respectively.

[0017] The first data bus can be configured according to any prior art known in the technical field suitable for connecting the mass storage device. The first data bus is preferably configured according to any one of the standards of USB, USB-C, Thunderbolt, SATA, eSATA, PCI, or PCIe.

[0018] The second data bus can also be configured according to any standard known in the technical field suitable for connecting the TPM. The second data bus is preferably configured according to any one of the standards of i2C, SPI, or LPC. In all the above embodiments, each of the mass storage devices is preferably a semiconductor hard disk or a non-volatile memory chip.

[0019] The present invention will be described in detail below with reference to the embodiments shown in the accompanying drawings. In the drawings: FIG. 1 shows a block diagram of a first embodiment of a data processing system of the present invention. FIG. 2 shows a block diagram of second and third embodiments of a data processing system of the present invention. FIG. 3 shows a block diagram of a fourth embodiment of a data processing system of the present invention. Figure 1 shows a first embodiment of the data processing system 1. The data processing system 1 includes a central processing unit 2. The central processing unit 2 is connected to a working memory 3 and at least one input / output device 4, such as a screen, keyboard, touchscreen, printer, network adapter, and / or any input / output interface.

[0020] Multiple large-capacity storage devices 61, 62, etc., generally 6 i One of these can be selectively connected to the central processing unit 2 via the first data bus 5 as needed. Mass storage device 6 i In particular, non-volatile mass storage devices retain their contents for long periods of time even without a power supply. Examples of such non-volatile mass storage devices include magnetic or optical hard disks, semiconductor hard disks, or non-volatile memory chips such as flash RAM, ROM, PROM, EPROM, EEPROM, and SSDs (solid-state disks). The first data bus 5 is connected to such mass storage devices 6 i It can be configured according to the appropriate standard, such as USB, USB-C, Thunderbolt, SATA, eSATA, PCI, PCIe, etc.

[0021] The Trusted Platform Module (TPM) 8 is connected to the Central Processing Unit 2 via a second data bus 7. Specifically, in the illustrated example, it is connected to the Central Processing Unit 2 via a changeover switch 9 inserted into the second data bus 7. The TPM 8 is a Trusted Platform Module compliant with the Trusted Computing Group (TCG) TPM standard, such as TPM1.2 or TPM2.0. The TPM 8 provides standardized TPM services to the data processing system 1 and, for this purpose, includes at least one bank of Platform Configuration Registers (PCRs) for storing keys, hash values, etc. These can be stored or retrieved via the second data bus 7 (e.g., in an encrypted manner).

[0022] In the example shown here, TPM8 is one of two or more banks of platform configuration registers, namely PCR1, PCR2, etc., generally PCR i It has an internal switch 10 in the TPM8, which determines which register bank PCR is used (or "active") each time in the operating mode of the data processing system 1. i This option is selectable. In other words, it is selectable when the central processing unit 2 attempts to communicate with the TPM 8 via the data bus 7.

[0023] The data processing system 1 includes a microcontroller 11 for setting change switches 9 and 10. The microcontroller 11 is always connected to the second data bus 7, or, as in the illustrated example, it may be connected to the TPM 8 instead of the central processing unit 2 via the change switch 9. In the operating mode of the data processing system 1 shown in Figure 1, the change switch 9 is in the lower switch position shown, so that the microcontroller 11 is disconnected from the second data bus 7 and becomes inactive. However, when the change switch 9 is not used, i.e., when both the microcontroller 11 and the TPM 8 are connected to the second data bus 7 of the central processing unit 2, in the operating mode of the data processing system 1, the microcontroller 11 avoids any communication on the second data bus 7 so as not to interfere with communication between the TPM 8 and the central processing unit 7.

[0024] The data processing system 1 can be set to a special configuration mode in addition to, or especially as an alternative to, its operating mode. If a changeover switch 9 is present, it can be switched to its upper position in Figure 1. This connects the TPM 8 to the microcontroller 11 via the second data bus 7. The microcontroller 11 itself can initiate the switching of the changeover switch 9. See control path 12.

[0025] In the setting mode, the microcontroller 11 transmits a control command 13 to the TPM 8 via the second data bus 7 in order to set the switching switch 10 inside the TPM (please refer to the control path indicated by the dotted line). Thereby, for continuous operation, i one of the PCR register banks PCR i in the TPM 8 is selected as the "active" register bank. After leaving the setting mode and entering the operation mode again, that is, after the switching switch 9 (if it exists) is set to the lower position as shown in FIG. 1, or after further communication by the microcontroller 7 on the data bus 7 is avoided, the selected register bank PCR i is used again by the central processing unit 2. The central processing unit 2 does not notice that the active PCR register bank PCR

[0026] in the TPM 8 has been changed. If the switching switch 9 is not used, the setting mode may be temporarily assumed during the operation mode.

[0027] Optionally, in the setting mode, the microcontroller 11 can cut off the power supply device 14 that supplies power to the central processing unit 2 via the controllable switch 15 and the corresponding control path 16. Thereby, especially when the switching switch 9 is not provided, exclusive communication between the microcontroller 11 and the TPM 8 in the setting mode can be realized.

[0027] The microcontroller 11 is programmed to start the selection of each register bank PRC1 by controlling the switching switch 10 according to the mass storage device 61 immediately connected to the first data bus 5. For example, the microcontroller 11 sets the first register bank PCR1 for the first mass storage device 61 and sets the second register bank PCR2 for the second mass storage device 62.

[0028] In the operation mode, which mass storage device 6 iInformation regarding whether each mass storage device 6 is connected to or should be connected to the first data bus 5 can be obtained by the microcontroller 11, for example, via the input device 17. i The microcontroller 11 is configured appropriately via the input device 17 at the same time as connecting to the data bus 5. Alternatively, the microcontroller 11 may automatically acquire this information from the first data bus 5 via the corresponding data connection 18. Another option is for the microcontroller 11 to connect to each mass storage device 6 i It may be connected to a reader 19 that reads the corresponding identifier 20. The identifier 20 is, for example, a mass storage device 6 i This may be a barcode, RFID tag, or similar device affixed to or embedded in the device. For this purpose, the reader 19 may be a corresponding barcode reader, RFID reader, or similar device. However, the identifier 20 may be, for example, a mass storage device 6 i It can also be stored in a special part or module and read by reader 19. Reader 19 could be, for example, a corresponding interface.

[0029] Figure 2 shows second and third embodiments of the data processing system 1. Here, only the differences from the embodiment in Figure 1 are described. Instead of a single TPM 8, the data processing system 1 uses multiple TPMs 81, 82, etc., generally 8. i It has.

[0030] In the second embodiment, different TPM8 i This is a physical device and can be connected to the central processing unit 2 as needed via a changeover switch 21 inserted into the second data bus 7. Subsequently, the microcontroller 11, in setting mode, sets the mass storage device 6 i Each TPM8 assigned to i It is programmed to connect to the central processing unit 2 via the changeover switch 21 and the data bus 7. Mass storage device 6 is used by the microcontroller 11 to control the changeover switch 21 in operating mode.i All other actions, such as the selection or identifier, are performed in the same manner as in the embodiment of Figure 1 that controls the TPM internal switching switch 10.

[0031] In the third embodiment, TPM8 i As indicated by the dotted box 11', it is implemented as a software instance in the programming of the microcontroller 11. Therefore, the changeover switch 21 is also a software component in the programming of the microcontroller 11. Needless to say, such a software instance can also be implemented in the firmware used for programming the microcontroller 11. In configuration mode, the microcontroller 11 has a large-capacity storage device 6 i TPM8 assigned to i The settings are configured and programmed to connect to the data bus 7 via the software changeover switch 21. The changeover switch 11 controls the corresponding emulated TPM 8. i For the purpose of setting up the microcontroller 11, the mass storage device 6 used in the operating mode i All other actions, such as the selection or identifier, are performed in a manner similar to that of the embodiment in Figure 1 that controls the TPM internal switching switch 10.

[0032] Figure 3 shows a fourth embodiment of the data processing system 1. The data processing system 1 performs PCR on different register banks of TPM8. i between, or different TPM8 i The configuration omits the changeover switches 10 and / or 21 for selecting between the two. In Figure 3, each TPM8 i The corresponding high-capacity storage device 6 i Along with separate transport enclosures 221, 222, etc., generally 22 i They are located in each transport enclosure 22 i It can be detachably connected to the rest of the data processing system 1 23, specifically via interface 24. Interface 24 is connected to the transport housing 22 iEach interface includes a first interface 25 for detachable connection to the first data bus 5 and a second interface 26 for detachable connection to the second data bus 7.

[0033] Transport enclosure 22 i This may be, for example, a Memory Stick or SSD enclosure. The Memory Stick or SSD enclosure is a mass storage device 6 i In addition to the mass storage interface 25 for use, an integrated TPM 8 i It also features an interface 26 for use with the device.

[0034] In this fourth embodiment, TPM8 i If necessary, a large-capacity storage device 6 i It can also be emulated again as a software instance by the internal microcontroller. Needless to say, such a software instance can also be implemented as firmware for the microcontroller.

[0035] Data processing system 1 can be configured in any form and for any purpose, including servers, terminals, computers, notebooks, laptops, PDAs (personal digital assistants), and smartphones.

[0036] The present invention is not limited to the embodiments described, but encompasses all variations, modifications, and combinations thereof that fall within the scope of the appended claims. [Brief explanation of the drawing]

[0037] [Figure 1] A first embodiment of the data processing system of the present invention is shown in a block diagram. [Figure 2] The second and third embodiments of the data processing system of the present invention are shown in block diagrams. [Figure 3] A fourth embodiment of the data processing system of the present invention is shown in a block diagram.

Claims

1. A data processing system, A central processing unit (2) is powered by a power supply unit (14), At least two mass storage devices (6) which can be selectively connected to the processing device (2) via the first data bus (5). i )and, The system includes a trusted platform module (8) that can be connected to the processing unit (2) via a second data bus (7), It is characterized by having a microcontroller (11) that can be connected to the second data bus (7), The Trusted Platform Module (8) has at least two register banks (PCR) of platform configuration registers. i ) has, and in the operating mode of the data processing system (1), one of the register banks (PCR i Only the active register bank (PCR) becomes active, and the active register bank (PCR) becomes active. i ) can be set by a control command (13) received from the microcontroller (11), The microcontroller (11) in the setting mode of the data processing system (1) selects the mass storage device (6) for the operating mode. i ) In accordance with the control command (13), the active register bank (PCR i A data processing system characterized by being configured to set ).

2. The changeover switch (9), which can be set by the microcontroller (11), is inserted into the second data bus (7) and connects the trusted platform module (8) to either the processing unit (2) or the microcontroller (11). The data processing system according to claim 1, characterized in that the microcontroller (11) is configured to connect the trusted platform module (8) to the processing unit (2) by the changeover switch (9) in the operating mode, and to connect to the microcontroller (11) by the changeover switch (9) in the setting mode.

3. A data processing system, A central processing unit (2) is powered by a power supply unit (14), At least two mass storage devices (6) which can be selectively connected to the processing device (2) via the first data bus (5). i )and, The system includes a trusted platform module (8) that can be connected to the processing unit (2) via a second data bus (7), It is characterized by being equipped with a microcontroller (11), The switch (21) that can be set by the microcontroller (11) is inserted into the second data bus (7), and in the operation mode of the data processing system (1), the processing device (2) is connected to the first trusted platform module (8 1 ), or the second trusted platform module (8 2 ) via the second data bus (7), The microcontroller (11) in the setting mode of the data processing system (1) selects the mass storage device (6) for the operating mode. i A data processing system characterized by being configured to set the changeover switch (21) according to ).

4. A data processing system, A central processing unit (2) is powered by a power supply unit (14), At least two mass storage devices (6) which can be selectively connected to the processing device (2) via the first data bus (5). i )and, A first trusted platform module (8) is connectable to the processing unit (2) via a second data bus (7). 1 ) and, The microcontroller (11) is connected to the second data bus (7) and the first trusted platform module (8) 1 ) and the second trusted platform module (8 2 Each of these is a software instance (8 i It is configured to emulate as, In either case, these software instances (8 i Only one of the above is active in the operating mode of the data processing system (1), The microcontroller (11) in the setting mode of the data processing system (1) selects the mass storage device (6) for the operating mode. 1 ) in accordance with the active software instance (8 i A data processing system characterized by being configured to set ).

5. Each mass storage device (6 i The mass storage device (6) is provided with a machine-readable identifier (20), and the microcontroller (11) is connected to a reader (19) for reading the identifier (20), and the mass storage device (6) is selected for the operating mode based on the identifier (20) read by the reader (19). i A data processing system according to any one of claims 1 to 4, characterized in that it is configured to detect ).

6. The data processing system according to any one of claims 1 to 5, characterized in that the setting mode is a substitute for the operation mode.

7. The data processing system according to any one of claims 1 to 6, characterized in that the power supply (14) to the central processing unit (2) is shut off in the setting mode.

8. A data processing system, Central processing unit (2), At least two mass storage devices (6) which can be selectively connected to the processing device (2) via the first data bus (5). i )and, A first trusted platform module (8) is connectable to the processing unit (2) via a second data bus (7). 1 ) and, The first trusted platform module (8 1 A second trusted platform module (8) can be connected to the second data bus (7) instead of the aforementioned second data bus (7). 2 It is characterized by having the following features: The aforementioned large-capacity storage device (6 i ) one of them and this large-capacity storage device (6 i The Trusted Platform Module (8) assigned to the Trusted Platform Module (8) i One of these is detachably connected to the rest of the data processing system (23), and is a shared transport housing (22 i A data processing system characterized by being located within ).

9. The data processing system according to any one of claims 1 to 8, wherein the first data bus (5) is configured according to any of the following standards: USB, USB-C, Thunderbolt, SATA, eSATA, PCI, or PCIe.

10. The data processing system according to any one of claims 1 to 9, wherein the second data bus (7) is configured according to any one of the standards i2C, SPI, or LPC.

11. The aforementioned large-capacity storage device (6 i The data processing system according to any one of claims 1 to 10, wherein each of the elements is a semiconductor hard disk or a non-volatile memory chip.