Firmware-Based TPM Using ARM TrustZone for Secure Execution Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Trusted Platform Modules (TPM) are hindered by high Bill of Materials (BOM) costs, energy inefficiency, and compatibility issues, leading to limited adoption in low-power devices and form factors like mobile phones and tablets, which results in restricted TPM usage scenarios.

Innovation Solution

A Firmware-Based TPM (fTPM) leverages existing ARM processor architectures and TrustZone extensions to provide a software-based trusted execution environment, eliminating the need for hardware TPM modules and enabling secure code and data isolation without additional hardware modifications, thus reducing BOM costs and power consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a discrete hardware TPM chip is integrated into the motherboard, then security protection is improved, but the bill of materials cost increases by about $1 to $2 per system

Engineering Contradiction:
Improvesecurity protectionVSAvoidbill of materials cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the TPM functionality with the existing ARM processor and TrustZone security extensions, eliminating the need for a separate discrete TPM chip. The firmware-based TPM implementation integrates security functions directly into the processor fabric, thereby reducing component count and bill of materials cost while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The ARM processor with TrustZone extensions serves multiple functions: general-purpose computing and dedicated security operations through the firmware-based TPM. This multi-functionality eliminates the need for specialized discrete TPM hardware, reducing costs while providing both computing and security capabilities through a single platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a discrete TPM chip is used, then security functionality is improved, but energy efficiency deteriorates and power consumption increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

By merging TPM security functions with the main ARM processor, the system eliminates the need for a separate power-consuming TPM chip. The security operations share the processor's power supply and energy management infrastructure, reducing overall power consumption while maintaining security functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The ARM processor serves itself by providing both general-purpose computing and dedicated security operations through integrated firmware-based TPM functionality. This self-service approach eliminates the need for additional external security hardware that would consume extra power.

Inventive Principle:
Principle #25Self-service

3Reliability

If a discrete TPM chip is implemented, then security capabilities are improved, but device compatibility deteriorates due to form factor constraints

Engineering Contradiction:
Improvesecurity capabilitiesVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The ARM processor platform provides universal security capabilities across diverse form factors including mobile phones, tablets, and embedded systems. The firmware-based TPM implementation is platform-agnostic and adapts to various device types without requiring form-factor-specific hardware adaptations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts TPM functionality from discrete hardware and implements it purely in firmware within the TrustZone secure environment. This extraction eliminates the need for physical TPM chips and their associated form factor constraints, enabling security capabilities across all ARM-based device types.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If a discrete TPM chip is used, then security protection is improved, but the processor speed deteriorates due to BOM constraints requiring slower processors

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessor speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

By merging TPM functions with the main processor, the system utilizes the full computational power of the ARM processor for both security operations and general computing. This eliminates the constraint of needing separate slower TPM processors, as the main processor handles all security operations at full speed.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9489512B2Trustzone-based integrity measurements and verification using a software-based trusted platform module
Publication Date: 2016.11.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9489512B2 patent drawing
  • US9489512B2 patent drawing
  • US9489512B2 patent drawing

AI summary

A “Firmware-Based TPM” or “fTPM” ensures that secure code execution is isolated to prevent a wide variety of potential security breaches. Unlike a conventional hardware based Trusted Platform Module (TPM), isolation is achieved without the use of dedicated security processor hardware or silicon. In general, the fTPM is first instantiated in a pre-OS boot environment by reading the fTPM from system firmware or firmware accessible memory or storage and placed into read-only protected memory of the device. Once instantiated, the fTPM enables execution isolation for ensuring secure code execution. More specifically, the fTPM is placed into protected read-only memory to enable the device to use hardware such as the ARM® architecture's TrustZone™ extensions and security primitives (or similar processor architectures), and thus the devices based on such architectures, to provide secure execution isolation within a “firmware-based TPM” without requiring hardware modifications to existing devices.