Chipset with Integrated TPM for Secure Firmware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current chipsets for mobile devices require extensive evaluation each time firmware changes, as the Secure Processor must be re-evaluated for every variation of the Trusted Platform Module (TPM) implemented for securing firmware, leading to increased evaluation effort.

Innovation Solution

The chipset incorporates an integrated Trusted Platform Module (iTPM) stored outside the Secure Processor, which is loaded into the Secure Processor's working memory for execution, allowing the Secure Processor to maintain basic functionalities and reducing the need for frequent evaluations by storing the iTPM in non-volatile storage, with the Bootloader initiating and controlling the execution and integrity verification of the firmware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Trusted Platform Module (TPM) is integrated into the Secure Processor for every firmware variation, then the firmware security is improved, but the evaluation effort and complexity increase significantly

Engineering Contradiction:
Improvefirmware securityVSAvoidevaluation effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the TPM functionality from the Secure Processor by implementing it as a separate loadable module (iTPM) stored in external non-volatile memory. This allows the Secure Processor to remain unchanged and separately evaluable, while firmware-specific TPM configurations are loaded only when needed, resolving the contradiction between maintaining security and reducing evaluation complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The iTPM is extracted from the Secure Processor and stored as a separate image in external non-volatile memory. This extraction allows the Secure Processor to be evaluated once in its basic form, while the iTPM can be updated and reloaded without requiring re-evaluation of the entire Secure Processor, thus reducing evaluation effort while maintaining firmware security.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If the Secure Processor is re-evaluated for every firmware variation, then the firmware integrity verification is improved, but the time and resources required for evaluation increase

Engineering Contradiction:
Improvefirmware integrity verificationVSAvoidevaluation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The iTPM image is prepared in advance in external non-volatile memory with firmware-specific verification parameters. During operation, the Bootloader loads the appropriate iTPM image and executes it to perform integrity verification, eliminating the need for time-consuming re-evaluation of the Secure Processor for each firmware variation while maintaining precise integrity checking.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If the iTPM is stored outside the Secure Processor in non-volatile memory, then the evaluation effort is reduced, but the security of the iTPM during storage becomes a concern

Engineering Contradiction:
Improveevaluation effortVSAvoidsecurity risk during storage
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the Bootloader as an intermediary with trusted execution environment that securely manages the loading and execution of the iTPM image from external non-volatile memory. The Bootloader verifies the iTPM image integrity and controls its execution in the Secure Processor, mediating between the external storage and the secure processing environment to mitigate security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The iTPM image is stored in external non-volatile memory with the understanding that it will be loaded and executed only in the controlled environment of the Secure Processor. The system accepts partial security risk during storage but compensates by ensuring the iTPM is executed only under strict control within the Secure Processor, where it can perform its verification functions safely.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11361079B2Chipset with protected firmware
Publication Date: 2022.06.14 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US11361079B2 patent drawing

AI summary

A chipset for an end device comprises at least a Secure Processor into which a one-time programmable memory storage is integrated, wherein in the chipset at least an end-device serial number of the end device is stored, wherein in the one-time programmable memory information is stored for securing the end-device serial number against tampering.