Dual TPM DevID Enrollment for Network Switch Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy network switch systems with single TPMs lack redundancy, leading to potential errors, failures, and poor recovery, especially when redundant management modules are installed, as existing enrollment processes are not designed to handle dual-TPM configurations effectively, resulting in contention and security weaknesses.

Innovation Solution

Implementing a dual-TPM configuration with hardware redundancy for management modules and TPMs, where each TPM has its own DevID certificate, and using a Certificate Authority (CA) with dual-ID enrollment techniques to create and verify matching DevID certificates for both TPMs, eliminating single-point failures and security vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single TPM is used in legacy network switch systems, then the device complexity is reduced, but the system reliability deteriorates due to lack of redundancy and single-point failures

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the TPM functionality into multiple separate TPMs (dual-TPM configuration) within the network switch system. Each TPM is independently enrolled with its own DevID certificate, eliminating the single-point failure issue while maintaining manageable complexity through modular segmentation of the security function.

Inventive Principle:
Principle #1Segmentation

2Reliability

If redundant management modules with dual-TPMs are installed, then the system reliability is improved, but the enrollment process complexity increases due to contention and lack of support for dual-ID configurations

Engineering Contradiction:
Improvesystem reliabilityVSAvoidenrollment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the system determine whether it is configured with dual-TPMs before initiating the certificate enrollment process. This pre-determination allows the system to select the appropriate enrollment flow (dual-ID vs. single-ID) in advance, avoiding contention during enrollment and simplifying the overall process complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies dynamics by making the enrollment process adaptive based on the detected TPM configuration. The system dynamically adjusts the enrollment behavior - using dual-ID enrollment for dual-TPM systems and single-ID enrollment for single-TPM systems - thereby simplifying the enrollment process complexity while supporting redundant configurations.

Inventive Principle:
Principle #15Dynamics

3Reliability

If dual-TPM configuration is implemented, then the system reliability is improved by eliminating single-point failures, but the contention during enrollment increases due to existing processes not being designed for dual-ID

Engineering Contradiction:
Improvesystem reliabilityVSAvoidenrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent determines the dual-TPM configuration status before starting certificate enrollment, allowing the system to prepare the appropriate enrollment parameters in advance. This preliminary determination prevents enrollment contention by ensuring the correct enrollment flow is selected before the actual enrollment begins, thereby reducing enrollment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a determination step that mediates between the dual-TPM configuration and the certificate enrollment process. This intermediary determination allows the system to bridge the gap between existing single-ID enrollment processes and dual-TPM requirements, enabling smooth dual-ID enrollment without contention or time loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If existing enrollment processes are used for dual-TPM systems, then the ease of operation is maintained, but security weaknesses arise due to contention and lack of proper dual-ID support

Engineering Contradiction:
Improveease of operationVSAvoidsecurity strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent makes the enrollment process dynamic by adapting it to the detected TPM configuration. The system automatically adjusts the enrollment behavior based on whether dual-TPMs are present, maintaining ease of operation through automation while ensuring security strength by using the appropriate dual-ID enrollment process for dual-TPM systems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback by having the system determine and respond to the dual-TPM configuration status. This feedback mechanism ensures that the enrollment process is adjusted according to the actual hardware configuration, maintaining ease of operation through automatic adaptation while preventing security weaknesses by using the correct enrollment procedure for the detected configuration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12113907B2Methods and systems for enrolling Device Identifiers (DevIDs) on redundant hardware
Publication Date: 2024.10.08 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12113907B2 patent drawing
  • US12113907B2 patent drawing
  • US12113907B2 patent drawing

AI summary

Methods and systems for implementing DevID enrollment for hardware redundant Trust Platform Modules (TPMs), are described. A system can include hardware redundancy for management modules, and for TPMs that correspond to each management module. Accordingly, a product can have a dual-TPM configuration, where both modules are associated with the same product. Further, a process that particularly considers the presence of dual-TPMs for creating, issuing, and enrolling DevID certificates is described. The process issues and maintains DevID certificates for each TPM by synchronizing dual sessions that correspond to each TPM. Also, the process accounts for duplicate identification data, for example allowing the certificate authority (CA) to sign certificates for dual-TPMs linked to the same chassis number. The process can include performing validation checks, rendezvous points, and locks to ensure that DevID certificates are successfully issued for each of the dual-TPMs, respectively.