Active TPM Provisioning for Multi-Node Server Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-node server environments face security threats such as spoofing, tampering, information disclosure, denial of service, and code and TPM event log integrity issues due to untrusted service processors during node merging processes.

Innovation Solution

An authentication protocol with active trusted platform module (TPM) provisioning is implemented, where a master compute node and slave nodes engage in a challenge/response exchange and quote request/response flow to authenticate each other, using a secure channel for key information exchange and TPM content verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service processor controls node merge operation, then node merging capability is improved, but security vulnerability increases due to untrusted service processor

Engineering Contradiction:
Improvenode merging capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication protocol as an intermediary mechanism between the service processor and compute nodes. This protocol acts as a mediator that enables the service processor to control node merging while simultaneously providing security verification through TPM-based authentication, challenge-response exchanges, and quote validation, thus resolving the contradiction between merging capability and security vulnerability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication actions before the node merging process. The authentication protocol performs TPM provisioning, key generation, and mutual authentication between compute nodes and the service processor before allowing any merge operations to proceed. This preliminary security setup prevents security vulnerabilities from arising during the merging process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If TPM provisioning is performed during node merge, then authentication capability is improved, but process complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the authentication protocol to serve multiple functions simultaneously: it performs TPM provisioning, generates cryptographic keys, establishes mutual authentication, validates node identities, and ensures merge operation security. By consolidating these functions into a single integrated protocol, the patent improves authentication capability while managing process complexity through multi-functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If challenge/response exchange is implemented, then node authentication is improved, but communication overhead increases

Engineering Contradiction:
Improvenode authenticationVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements a partial challenge/response approach where the authentication protocol performs selective verification based on the merging context. The protocol exchanges only the necessary cryptographic challenges and responses required for authentication, avoiding excessive communication. The TPM quote validation process requests only specific PCR values and attestation data needed for verification, balancing authentication reliability with communication efficiency

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10885197B2Merging multiple compute nodes with trusted platform modules utilizing authentication protocol with active trusted platform module provisioning
Publication Date: 2021.01.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10885197B2 patent drawing
  • US10885197B2 patent drawing
  • US10885197B2 patent drawing

AI summary

Method, apparatus, and computer program product are provided for merging multiple compute nodes with trusted platform modules (TPMs) utilizing an authentication protocol with active TPM provisioning. In some embodiments, compute nodes are connected to be available for merger into a single multi-node system. Each compute node includes a TPM accessible to firmware on the node. One compute node is assigned the role of master compute node (MCN), with the other node(s) each assigned the role of slave compute node (SCN). Active TPM provisioning in each SCN produces key information that is sent to the MCN to enable use of a challenge/response exchange with each SCN. A quote request is sent from the MCN to each SCN. In response to receiving the quote request, a quote response is sent from each respective SCN to the MCN, wherein the quote response includes slave TPM content along with TPM logs and associated signatures.