Firmware Controlled Secrets for TPM Platform Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing devices with TPMs face security issues such as physical attackers being able to extract data by mimicking the original platform or intercepting devices during transit, and authentication mechanisms being subverted by attackers.
Innovation Solution
The implementation of firmware-controlled locking and unlocking mechanisms for TPMs, where a secret is used to bind the TPM to its platform, ensuring data is only released when the correct user credential is provided and the setup is verified as expected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If TPM stores data without firmware control, then data accessibility is improved, but security against physical attacks deteriorates
Solution Approach 1:
The patent introduces firmware as an intermediary layer between the TPM hardware and the rest of the system. This firmware-controlled secret acts as a mediator that binds the TPM to the specific platform, allowing data to be accessible when needed while preventing extraction by physical attackers. The firmware verifies platform integrity before releasing the secret, thus resolving the contradiction between accessibility and security.
2Adaptability or versatility
If TPM is portable across platforms, then versatility is improved, but platform binding security deteriorates
Solution Approach 1:
The patent implements preliminary binding of the TPM to the platform during the firmware initialization phase. The firmware-controlled secret is generated and stored in a way that binds the TPM to the specific platform configuration before any data operations occur. This preliminary action ensures that even if the TPM is physically moved, it cannot function on a different platform without the correct firmware secret, thus maintaining platform binding security while allowing legitimate platform changes.
3Ease of operation
If authentication mechanisms are simplified, then ease of operation is improved, but susceptibility to authentication subversion deteriorates
Solution Approach 1:
The patent replaces traditional mechanical authentication mechanisms (physical keys, hardware tokens) with a firmware-controlled secret system. This substitution maintains operational simplicity for users while enhancing security by tying authentication to the firmware layer, which is more resistant to subversion than traditional authentication mechanisms. The firmware secret system provides both ease of operation and improved resistance to authentication subversion.
Data Source
AI summary
In an example, a computing device is described. The computing device comprises a component to perform a crypto-graphic operation and store an indication of a measured state of the computing device obtained during booting of the computing device. The computing device further comprises a processor to obtain a secret for use by the component, install an administration credential in a firmware of the computing device and transmit the secret to the component via the firmware.


