Hardware Security Unit Inter-System Binding for Trusted Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware security units, such as Trusted Platform Modules, are limited to securing individual devices and lack a method to establish trusted relationships between different devices, leading to security hazards during data transmission and cumbersome key management processes when transferring encrypted files between devices.

Innovation Solution

An inter-trusted-computing-system binding method that configures binding requirements, exchanges and validates hardware security unit information, verifies binding compliance, and establishes an encrypted pipe using asymmetric keys to secure data transmission between trusted computing systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware security units are used to secure individual devices, then device security is improved, but the ability to establish trusted relationships between different devices is lost

Engineering Contradiction:
Improvedevice securityVSAvoidinter-device trusted relationship capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the hardware security unit's functionality from securing only local devices to establishing trusted relationships across multiple devices. By introducing binding information that links hardware security units of different devices, the system achieves multi-functionality: it maintains original device security while adding inter-device trust capability. The binding information acts as a universal credential that enables trusted operations across device boundaries.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If files are transmitted between devices using traditional decryption/encryption procedures, then data can be transferred, but security hazards arise during transmission and key management becomes cumbersome

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidtransmission security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs binding and key establishment in advance before actual data transfer operations. The binding information is pre-configured in hardware security units, and trusted relationships are established beforehand. When data needs to be transferred, the security framework is already in place, eliminating the need for cumbersome real-time key management and preventing transmission security hazards. This preliminary action enables secure data transfer without requiring users to manually manage keys during the transfer process.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If plain text transmission is used for data exchange between devices, then transmission simplicity is improved, but security hazards are introduced

Engineering Contradiction:
Improvetransmission simplicityVSAvoidtransmission security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements automatic encryption and decryption through the binding mechanism. When data is transmitted between bound devices, the hardware security units automatically perform cryptographic operations based on the pre-established trusted relationship. The user simply needs to initiate the transfer, and the system handles all security operations autonomously. This self-service approach maintains transmission simplicity while eliminating security hazards, as the encrypted channel is automatically established without requiring user awareness of cryptographic details.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8090946B2Inter-system binding method and application based on hardware security unit
Publication Date: 2012.01.03 LENOVO (BEIJING) LTD
  • US8090946B2 patent drawing
  • US8090946B2 patent drawing
  • US8090946B2 patent drawing

AI summary

The present invention discloses an inter-trusted-computing-system binding method based on hardware security unit, comprising steps of: configuring binding requirements for hardware security units of trusted computing systems; exchanging hardware security unit information between the hardware security units of the trusted computing systems to be bound, and checking device validities of the counter-party hardware security unit; and if passing the validation check, it continues to the following steps; otherwise, exiting the binding procedure; respectively verifying whether the binding meets their respective binding requirements by the hardware security units of the trusted computing systems to be bound; and if passing the verification, it continues to the following steps; otherwise, exiting the binding procedure; and respectively storing platform information and hardware security unit binding information by the hardware security units of the trusted computing systems. The present method provides a processing mechanism based on hardware security unit in order to establish trusts between trusted computing systems.