Firmware Controlled Secrets for TPM Platform Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing devices with TPMs face security issues such as physical attackers being able to extract data by mimicking the original platform or intercepting devices during transit, and authentication mechanisms being subverted by attackers.

Innovation Solution

The implementation of firmware-controlled locking and unlocking mechanisms for TPMs, where a secret is used to bind the TPM to its platform, ensuring data is only released when the correct user credential is provided and the setup is verified as expected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If TPM stores data without firmware control, then data accessibility is improved, but security against physical attacks deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity against physical attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces firmware as an intermediary layer between the TPM hardware and the rest of the system. This firmware-controlled secret acts as a mediator that binds the TPM to the specific platform, allowing data to be accessible when needed while preventing extraction by physical attackers. The firmware verifies platform integrity before releasing the secret, thus resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If TPM is portable across platforms, then versatility is improved, but platform binding security deteriorates

Engineering Contradiction:
ImproveTPM portabilityVSAvoidplatform binding security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary binding of the TPM to the platform during the firmware initialization phase. The firmware-controlled secret is generated and stored in a way that binds the TPM to the specific platform configuration before any data operations occur. This preliminary action ensures that even if the TPM is physically moved, it cannot function on a different platform without the correct firmware secret, thus maintaining platform binding security while allowing legitimate platform changes.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication mechanisms are simplified, then ease of operation is improved, but susceptibility to authentication subversion deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces traditional mechanical authentication mechanisms (physical keys, hardware tokens) with a firmware-controlled secret system. This substitution maintains operational simplicity for users while enhancing security by tying authentication to the firmware layer, which is more resistant to subversion than traditional authentication mechanisms. The firmware secret system provides both ease of operation and improved resistance to authentication subversion.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250200199A1Firmware controlled secrets
Publication Date: 2025.06.19 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US20250200199A1 patent drawing
  • US20250200199A1 patent drawing
  • US20250200199A1 patent drawing

AI summary

In an example, a computing device is described. The computing device comprises a component to perform a crypto-graphic operation and store an indication of a measured state of the computing device obtained during booting of the computing device. The computing device further comprises a processor to obtain a secret for use by the component, install an administration credential in a firmware of the computing device and transmit the secret to the component via the firmware.