Cryptoprocessor Lockdown via PCR Scrambling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for locking down information handling systems and protecting their data are time-consuming and risky, especially in urgent scenarios like military combat or virus attacks, as they require manual processes that can lead to data breaches and pose risks to personnel.

Innovation Solution

An information handling system equipped with a cryptoprocessor that stores cryptographic data for secure boot, initiates a lockdown by overwriting storage locations with invalid data and triggering a reboot, ensuring data security through scrambled PCR values upon reboot.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual deletion processes or physical damage methods are used to destroy data, then data security is improved, but the time required and operational complexity increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidtime required for data destruction
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-configures cryptographic data in storage locations that are essential for system operation. When lockdown is triggered, these pre-positioned storage locations are immediately overwritten with invalid data, causing the system to become inoperable without requiring time-consuming manual deletion or physical destruction processes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts the critical cryptographic data from its normal operational storage locations and targets these specific locations for immediate overwriting. By identifying and attacking the essential cryptographic components rather than attempting to delete all data, the system achieves rapid lockdown while ensuring data security

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If manual deletion processes or physical damage methods are used to destroy data, then data security is improved, but the operational complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically identifies and overwrites the critical cryptographic storage locations when a lockdown trigger is received. This self-service mechanism eliminates the need for manual identification and deletion processes, reducing operational complexity while maintaining data security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention extracts the essential cryptographic components into identifiable storage locations that can be automatically targeted. This extraction allows the system to focus on destroying only the critical elements needed for data protection, rather than requiring complex manual processes to identify and destroy all potential data sources

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If traditional data destruction methods are used, then data security is improved, but the risk to personnel and data breach risk increase

Engineering Contradiction:
Improvedata securityVSAvoidrisk to personnel and data breach
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The invention replaces manual mechanical processes (physical damage, hand-deletion) with an automated electronic system that overwrites cryptographic data through software control. This substitution eliminates personnel exposure to physical risks and reduces data breach opportunities by removing manual handling steps

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system extracts and targets only the essential cryptographic storage locations for overwriting, rather than requiring personnel to physically access and destroy storage media. This focused approach minimizes the attack surface and eliminates risks associated with manual data destruction operations

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If cryptographic data is overwritten with invalid data, then data protection is improved, but the system becomes inoperable

Engineering Contradiction:
Improvedata protectionVSAvoidsystem operability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies preliminary anti-action by overwriting the cryptographic data that enables system operation. This intentional destruction of operational capability is the desired outcome of lockdown, preventing any future operation that could compromise data security

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The invention extracts and targets the specific cryptographic storage locations that are essential for system operation. By destroying only these critical components rather than the entire system, the patent achieves selective incapacitation that protects data while minimizing collateral damage to non-essential system functions

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11275817B2System lockdown and data protection
Publication Date: 2022.03.15 DELL PROD LP
  • US11275817B2 patent drawing
  • US11275817B2 patent drawing
  • US11275817B2 patent drawing

AI summary

An information handling system may include a processor, and a cryptoprocessor comprising at least one storage location. The information handling system may be configured to: store, in the at least one storage location, cryptographic data regarding secure boot of the information handling system; receive an indication that a lockdown is to be initiated; in response to the indication, overwrite the at least one storage location with invalid data; and initiate the lockdown by triggering a reboot of the information handling system.