Key Cryptographic Processor TPM State Initialization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems face challenges in securely managing and transferring encrypted data encryption keys across devices, particularly in ensuring the integrity and authenticity of key management, especially when dealing with fraudulent replacement of storage media and TPM chip failures.
Innovation Solution
The system employs a key cryptographic processor, a retaining unit, and a key acquiring unit to manage and decrypt data encryption keys, utilizing a Trusted Platform Module (TPM) for secure key generation, verification, and transfer, ensuring that the TPM state is correctly initialized and recovered across different apparatuses, and allowing for decryption and exclusive use management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the data encryption key is stored encrypted in the retaining unit and decrypted by the key cryptographic processor, then the security of key management is improved, but the system complexity increases due to the need for TPM state initialization and verification mechanisms
Solution Approach 1:
The system performs preliminary initialization of the TPM chip before cryptographic operations. The initialization process sets the TPM in a known good state and generates necessary cryptographic parameters in advance, preventing the need for complex runtime state management and verification mechanisms.
Solution Approach 2:
The key cryptographic processor autonomously manages its own state through self-verification mechanisms. The processor verifies its own operational state and recovers from errors without external intervention, reducing the need for complex external verification systems.
2Reliability
If the TPM chip fails or storage media is fraudulently replaced, then the reliability of key management deteriorates, but implementing comprehensive verification and recovery mechanisms increases device complexity
Solution Approach 1:
The system implements continuous feedback mechanisms where the key cryptographic processor monitors the integrity of storage media and TPM state. When fraud or failure is detected, the system provides feedback signals that trigger automated verification and recovery procedures, maintaining reliability without requiring complex proactive verification systems.
Solution Approach 2:
The system prepares backup cryptographic parameters and recovery mechanisms in advance. If TPM failure or media replacement occurs, pre-prepared backup keys and state information enable rapid recovery without complex real-time decision-making systems.
3Speed
If the key cryptographic processor decrypts the data encryption key locally, then the speed of cryptographic operations is improved, but the risk of fraudulent key usage increases
Solution Approach 1:
The system introduces an intermediary verification layer between key storage and decryption operations. The key acquiring unit acts as a mediator that verifies the authenticity and authorization context before allowing the key cryptographic processor to decrypt keys, preventing fraudulent usage while maintaining fast local decryption capability.
Solution Approach 2:
Authorization and verification checks are performed in advance before key decryption. The system pre-validates user credentials, device state, and operational context, allowing fast local decryption to proceed only when pre-verified conditions are met, eliminating the need for slow runtime verification.
4Reliability
If the system implements comprehensive TPM state initialization and key verification mechanisms, then the security against fraudulent replacement is improved, but the time required for system startup and key acquisition increases
Solution Approach 1:
TPM state initialization and cryptographic parameter generation are performed during system manufacturing or first-boot setup, before normal operation begins. This preliminary preparation eliminates the need for time-consuming initialization during each startup, providing both security and fast boot performance.
Solution Approach 2:
The system creates verified copies of cryptographic state information and stores them in multiple locations (TPM, secure storage). These pre-verified copies can be quickly loaded during startup without repeating lengthy verification processes, reducing startup time while maintaining security.
Data Source
AI summary
An information processing apparatus includes a key cryptographic processor, a retaining unit, a key acquiring unit, and a processor. The key cryptographic processor performs cryptographic processing on a data encryption key used in a cryptographic process on data. The retaining unit retains the data encryption key encrypted by the key cryptographic processor. The key acquiring unit transmits, to an external apparatus, the data encryption key encrypted and acquires the data encryption key decrypted by the external apparatus. The processor performs cryptographic processing on data. The cryptographic processing is performed in such a manner that, when the key cryptographic processor decrypts the data encryption key, the data encryption key decrypted is used, and that, when the key cryptographic processor does not decrypt the data encryption key, the data encryption key acquired by the key acquiring unit is used.


