Dual-TPM DevID Enrollment for Network Switch Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy network switch systems with single TPMs lack redundancy, leading to potential errors, failures, and poor recovery, especially when redundant management modules are installed, as existing enrollment processes are not designed to handle dual-TPM configurations effectively, resulting in challenges with certificate enrollment and security.

Innovation Solution

Implementing a dual-TPM configuration with hardware redundancy for management modules and TPMs, where each TPM has its own DevID certificate, and using a Certificate Authority (CA) with dual-ID enrollment techniques to manage the enrollment process, including dual-ID indicators and rendezvous schemes to ensure secure and concurrent certificate issuance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single TPM is used in legacy network switch systems, then the device complexity is reduced, but the system reliability deteriorates due to single-point failures and lack of redundancy

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is segmented into multiple independent TPM modules (primary TPM and secondary TPM), each capable of independently performing cryptographic operations. This segmentation eliminates single-point failures by distributing critical functions across multiple hardware components, thereby improving system reliability while maintaining manageable complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different TPM modules are assigned specific roles and responsibilities within the system. The primary TPM handles normal cryptographic operations, while the secondary TPM serves as a standby with identical capabilities. This local differentiation allows the system to maintain high reliability through redundancy without requiring complete duplication of the entire system architecture.

Inventive Principle:
Principle #3Local quality

2Reliability

If dual-TPM configuration is implemented, then the system reliability is improved through redundancy, but the certificate enrollment complexity increases due to existing processes not being designed for dual-TPM

Engineering Contradiction:
Improvesystem reliabilityVSAvoidenrollment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Certificate Authority is pre-configured with knowledge of dual-TPM systems and the specific enrollment protocol required. The system performs preliminary actions by establishing communication channels and authentication mechanisms before actual certificate enrollment begins, thereby simplifying the enrollment process for dual-TPM configurations rather than requiring complex post-hoc adjustments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A dedicated enrollment protocol acts as an intermediary between the dual-TPM system and the Certificate Authority. This intermediary layer translates the unique dual-TPM enrollment requirements into standard certificate enrollment operations, thereby reducing complexity by abstracting the dual-TPM specificities from the core enrollment process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dual-TPM configuration with separate DevID certificates is used, then the security is enhanced through redundant cryptographic identifiers, but the difficulty of detecting and measuring identity increases

Engineering Contradiction:
ImprovesecurityVSAvoididentity verification complexity
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

Both TPM modules are configured with identical cryptographic capabilities and security privileges. Each TPM can independently perform the same cryptographic operations and present the same type of DevID certificate to external systems. This equipotential configuration simplifies identity verification because external systems interact with either TPM using the same protocol and validation criteria, thereby reducing the difficulty of detecting and measuring identity despite the presence of dual TPMs.

Inventive Principle:
Principle #12Equipotentiality

Data Source

PatentUS11405222B2Methods and systems for enrolling device identifiers (DEVIDs) on redundant hardware
Publication Date: 2022.08.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11405222B2 patent drawing
  • US11405222B2 patent drawing
  • US11405222B2 patent drawing

AI summary

Methods and systems for implementing DevID enrollment for hardware redundant Trust Platform Modules (TPMs), are described. A system can include hardware redundancy for management modules, and for TPMs that correspond to each management module. Accordingly, a product can have a dual-TPM configuration, where both modules are associated with the same product. Further, a process that particularly considers the presence of dual-TPMs for creating, issuing, and enrolling DevID certificates is described. The process issues and maintains DevID certificates for each TPM by synchronizing dual sessions that correspond to each TPM. Also, the process accounts for duplicate identification data, for example allowing the certificate authority (CA) to sign certificates for dual-TPMs linked to the same chassis number. The process can include performing validation checks, rendezvous points, and locks to ensure that DevID certificates are successfully issued for each of the dual-TPMs, respectively.