Secure External TPM Password Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security mechanisms for PCs and TPM-based systems are vulnerable to physical and logical attacks, with traditional methods like encryption keys and firewalls being inadequate, and there is a need for secure password generation and usage that prevents inadvertent or malicious detection of codes and secrets during origination and conveyance.

Innovation Solution

A method and system for secure external TPM password generation and usage, where a secure access code is generated at a remote device, conveyed to a TPM-based system, and received with unique data characteristics, ensuring secure content provision without exposing the codes to software attacks or malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security mechanisms (encryption keys, digital certificates, firewalls) are used to secure PC systems, then basic security protection is provided, but the systems remain vulnerable to physical and logical attacks including malware and password sniffers

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Trusted Platform Module (TPM) as an intermediary hardware component that mediates security operations. The TPM securely generates, stores, and manages cryptographic keys and passwords, acting as a trusted mediator between the user and the system. This intermediary approach prevents direct exposure of security credentials to potentially compromised software environments, thereby addressing vulnerabilities to malware and logical attacks while maintaining security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If passwords are stored in unprotected hard drives and memory, then easy access is provided, but security information becomes vulnerable to unauthorized access and attacks

Engineering Contradiction:
Improveaccess to security informationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts security information (passwords, keys) from vulnerable storage locations (unprotected hard drives and memory) and relocates them to a dedicated secure hardware module (TPM). This extraction removes the security credentials from the attack surface of the general-purpose computer system, preventing unauthorized access while maintaining ease of operation through the TPM's automated key management and authentication mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If secure high-entropy passwords are used, then resistance to guessing attacks is improved, but the passwords remain subject to malware attacks and inadvertent surrender of secure information

Engineering Contradiction:
Improveresistance to guessing attacksVSAvoidmalware attacks and inadvertent surrender
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements self-service security where the TPM automatically generates high-entropy passwords and cryptographic keys without user intervention, and automatically manages their storage and usage. The system performs self-authentication operations using these credentials, eliminating the need for users to manually create, remember, or transmit passwords. This self-service approach prevents inadvertent surrender of secure information while maintaining resistance to guessing attacks through high-entropy credential generation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8261072B2Method and system for secure external TPM password generation and use
Publication Date: 2012.09.04 CRESTONE IP MANAGEMENT LLC
  • US8261072B2 patent drawing
  • US8261072B2 patent drawing
  • US8261072B2 patent drawing

AI summary

Aspects of the present invention include a method and system for generating a secure access code at a remote device in communication with a computer system having a secure storage device; conveying the secure access code to the system secure storage device; receiving the secure access code at the system secure storage device with unique data characteristics associated with remote device; and, securely providing content to the remote device.