DC-SCM Authentication Using TPM Boot Measurement Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DC-SCM systems in DC-MHS computing devices lack authentication mechanisms, allowing malicious actors to replace authentic DC-SCMs with modified ones, compromising data security.

Innovation Solution

Implement a DC-SCM authentication system that includes a TPM device to generate and verify initialization process measurements, comparing a measured initialization process measurement with a verified initialization process measurement to detect unauthenticated DC-SCM devices and generate an alert.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If DC-SCM devices are made easily removable and replaceable, then ease of operation and maintenance is improved, but security reliability deteriorates because malicious actors can replace authentic DC-SCMs with modified ones

Engineering Contradiction:
ImproveDC-SCM replaceabilityVSAvoidDC-SCM authentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication of the DC-SCM device before allowing operation. The authentication engine verifies the integrity of the DC-SCM by comparing its cryptographic signature against a known good signature stored in secure storage, preventing unauthorized or modified DC-SCMs from being used even though they are physically replaceable

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication engine is introduced as an intermediary component between the DC-SCM device and the computing device operations. This authentication engine acts as a mediator that verifies the authenticity of the DC-SCM through cryptographic validation, allowing the system to maintain both ease of replacement and security by filtering out unauthorized devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication mechanisms are added to DC-SCM systems, then security reliability is improved, but device complexity increases due to additional authentication components and processes

Engineering Contradiction:
ImproveDC-SCM authentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The DC-SCM device performs self-authentication by providing its own cryptographic signature for verification. The authentication engine validates the DC-SCM's integrity through automated cryptographic comparison without requiring manual intervention or complex external authentication infrastructure, reducing overall system complexity while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces complex mechanical or manual authentication mechanisms with cryptographic validation. Instead of using physical security tokens, manual verification procedures, or complex hardware locks, the system uses digital signatures and cryptographic comparison to authenticate the DC-SCM, simplifying the authentication process while enhancing security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12574244B2DC-SCM authentication system
Publication Date: 2026.03.10 DELL PROD LP
  • US12574244B2 patent drawing
  • US12574244B2 patent drawing
  • US12574244B2 patent drawing

AI summary

A DC-SCM authentication system includes a DC-SCM authentication subsystem coupled to a DC-SCM device and a TPM device. The DC-SCM authentication subsystem retrieves a measured initialization process measurement generated by the TPM device during a first initialization process performed by the DC-SCM device, and retrieves a verified initialization process measurement that may be published by the DC-SCM device during or following the first initialization process as, for example a UEFI variable. The DC-SCM authentication subsystem then determines whether the measured initialization process measurement generated during by the TPM device the first initialization process does not match the verified initialization process measurement published by the DC-SCM device during or following the first initialization process and, if so, generates an unauthenticated DC-SCM device alert.