Externally Managed Security Device for Virtual TPM Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security and validation systems, such as Trusted Platform Modules (TPMs), are limited in virtual computing environments where a virtual computer can be moved among different systems, as they often require a physical binding to a specific TPM, restricting flexibility and compatibility.
Innovation Solution
An externally managed security and validation processing device with a cryptographic processing subsystem, application interface, and secure management interface that allows credentials like private signed keys and digital certificates to be managed externally, enabling security services without physical binding to a specific TPM, facilitating movement across different computing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If credentials are physically bound to a specific TPM, then security is improved, but adaptability deteriorates
Solution Approach 1:
The system separates credential management from the TPM hardware by introducing an external service profile system. Credentials are segmented into TPM-stored cryptographic material and externally-managed service profiles, allowing the service profiles to be independently updated and migrated across different TPM instances while maintaining security through the TPM's cryptographic operations.
Solution Approach 2:
An external service profile system acts as an intermediary between the application system and the TPM. This intermediary manages credentials externally, allowing updates and migrations without requiring physical rebinding to specific TPM hardware, thus resolving the contradiction between security (maintained through TPM) and adaptability (enabled through external management).
2Device complexity
If configuration information is managed internally through the application system, then device complexity is reduced, but security deteriorates
Solution Approach 1:
Configuration information management is extracted from the application system and placed in a dedicated external service profile system. This extraction secures configuration information by isolating it from the application system's attack surface while maintaining simplified internal device architecture, as the TPM only needs to handle cryptographic operations without complex credential management logic.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An externally managed security and validation processing device includes a cryptographic processing subsystem configured for performing security or validation services; an application interface configured for communicating security or validation services with an application system; and a secure management interface configured for communicating information, including configuration information for the cryptographic processing system for performing said security or validation services, with a service profile system external to the apparatus without passing said configuration information through the application system. The service profile system can typically also migrate security services provided by one apparatus to another apparatus.