Dual TPM DevID Enrollment for Network Switch Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy network switch systems with single TPMs lack redundancy, leading to potential errors, failures, and poor recovery, especially when redundant management modules are installed, as existing enrollment processes are not designed to handle dual-TPM configurations effectively, resulting in contention and security weaknesses.
Innovation Solution
Implementing a dual-TPM configuration with hardware redundancy for management modules and TPMs, where each TPM has its own DevID certificate, and using a Certificate Authority (CA) with dual-ID enrollment techniques to create and verify matching DevID certificates for both TPMs, eliminating single-point failures and security vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single TPM is used in legacy network switch systems, then the device complexity is reduced, but the system reliability deteriorates due to lack of redundancy and single-point failures
Solution Approach 1:
The patent divides the TPM functionality into multiple separate TPMs (dual-TPM configuration) within the network switch system. Each TPM is independently enrolled with its own DevID certificate, eliminating the single-point failure issue while maintaining manageable complexity through modular segmentation of the security function.
2Reliability
If redundant management modules with dual-TPMs are installed, then the system reliability is improved, but the enrollment process complexity increases due to contention and lack of support for dual-ID configurations
Solution Approach 1:
The patent implements preliminary action by having the system determine whether it is configured with dual-TPMs before initiating the certificate enrollment process. This pre-determination allows the system to select the appropriate enrollment flow (dual-ID vs. single-ID) in advance, avoiding contention during enrollment and simplifying the overall process complexity.
Solution Approach 2:
The patent applies dynamics by making the enrollment process adaptive based on the detected TPM configuration. The system dynamically adjusts the enrollment behavior - using dual-ID enrollment for dual-TPM systems and single-ID enrollment for single-TPM systems - thereby simplifying the enrollment process complexity while supporting redundant configurations.
3Reliability
If dual-TPM configuration is implemented, then the system reliability is improved by eliminating single-point failures, but the contention during enrollment increases due to existing processes not being designed for dual-ID
Solution Approach 1:
The patent determines the dual-TPM configuration status before starting certificate enrollment, allowing the system to prepare the appropriate enrollment parameters in advance. This preliminary determination prevents enrollment contention by ensuring the correct enrollment flow is selected before the actual enrollment begins, thereby reducing enrollment time.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a determination step that mediates between the dual-TPM configuration and the certificate enrollment process. This intermediary determination allows the system to bridge the gap between existing single-ID enrollment processes and dual-TPM requirements, enabling smooth dual-ID enrollment without contention or time loss.
4Ease of operation
If existing enrollment processes are used for dual-TPM systems, then the ease of operation is maintained, but security weaknesses arise due to contention and lack of proper dual-ID support
Solution Approach 1:
The patent makes the enrollment process dynamic by adapting it to the detected TPM configuration. The system automatically adjusts the enrollment behavior based on whether dual-TPMs are present, maintaining ease of operation through automation while ensuring security strength by using the appropriate dual-ID enrollment process for dual-TPM systems.
Solution Approach 2:
The patent implements feedback by having the system determine and respond to the dual-TPM configuration status. This feedback mechanism ensures that the enrollment process is adjusted according to the actual hardware configuration, maintaining ease of operation through automatic adaptation while preventing security weaknesses by using the correct enrollment procedure for the detected configuration.
Data Source
AI summary
Methods and systems for implementing DevID enrollment for hardware redundant Trust Platform Modules (TPMs), are described. A system can include hardware redundancy for management modules, and for TPMs that correspond to each management module. Accordingly, a product can have a dual-TPM configuration, where both modules are associated with the same product. Further, a process that particularly considers the presence of dual-TPMs for creating, issuing, and enrolling DevID certificates is described. The process issues and maintains DevID certificates for each TPM by synchronizing dual sessions that correspond to each TPM. Also, the process accounts for duplicate identification data, for example allowing the certificate authority (CA) to sign certificates for dual-TPMs linked to the same chassis number. The process can include performing validation checks, rendezvous points, and locks to ensure that DevID certificates are successfully issued for each of the dual-TPMs, respectively.


