Active TPM Provisioning for Multi-Node Server Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multi-node server environments face security threats such as spoofing, tampering, information disclosure, denial of service, and code and TPM event log integrity issues due to untrusted service processors during node merging processes.
Innovation Solution
An authentication protocol with active trusted platform module (TPM) provisioning is implemented, where a master compute node and slave nodes engage in a challenge/response exchange and quote request/response flow to authenticate each other, using a secure channel for key information exchange and TPM content verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service processor controls node merge operation, then node merging capability is improved, but security vulnerability increases due to untrusted service processor
Solution Approach 1:
The patent introduces an authentication protocol as an intermediary mechanism between the service processor and compute nodes. This protocol acts as a mediator that enables the service processor to control node merging while simultaneously providing security verification through TPM-based authentication, challenge-response exchanges, and quote validation, thus resolving the contradiction between merging capability and security vulnerability
Solution Approach 2:
The patent implements preliminary authentication actions before the node merging process. The authentication protocol performs TPM provisioning, key generation, and mutual authentication between compute nodes and the service processor before allowing any merge operations to proceed. This preliminary security setup prevents security vulnerabilities from arising during the merging process
2Reliability
If TPM provisioning is performed during node merge, then authentication capability is improved, but process complexity increases
Solution Approach 1:
The patent designs the authentication protocol to serve multiple functions simultaneously: it performs TPM provisioning, generates cryptographic keys, establishes mutual authentication, validates node identities, and ensures merge operation security. By consolidating these functions into a single integrated protocol, the patent improves authentication capability while managing process complexity through multi-functionality
3Reliability
If challenge/response exchange is implemented, then node authentication is improved, but communication overhead increases
Solution Approach 1:
The patent implements a partial challenge/response approach where the authentication protocol performs selective verification based on the merging context. The protocol exchanges only the necessary cryptographic challenges and responses required for authentication, avoiding excessive communication. The TPM quote validation process requests only specific PCR values and attestation data needed for verification, balancing authentication reliability with communication efficiency
Data Source
AI summary
Method, apparatus, and computer program product are provided for merging multiple compute nodes with trusted platform modules (TPMs) utilizing an authentication protocol with active TPM provisioning. In some embodiments, compute nodes are connected to be available for merger into a single multi-node system. Each compute node includes a TPM accessible to firmware on the node. One compute node is assigned the role of master compute node (MCN), with the other node(s) each assigned the role of slave compute node (SCN). Active TPM provisioning in each SCN produces key information that is sent to the MCN to enable use of a challenge/response exchange with each SCN. A quote request is sent from the MCN to each SCN. In response to receiving the quote request, a quote response is sent from each respective SCN to the MCN, wherein the quote response includes slave TPM content along with TPM logs and associated signatures.


