LCS Virtual TPM Trust Chain for Dynamic Resource Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The dynamic and fluid nature of server devices and components used in Logically Composed Systems (LCSs) can break established trust relationships, compromising the trusted operation of these systems.
Innovation Solution
An LCS trust system is implemented using a resource management engine with a virtual Trusted Platform Module (vTPM) to establish and maintain trust relationships among System Control Processor (SCP) devices and resource devices, forming a chain of trust based on physical Trusted Platform Modules (pTPMs) to ensure secure operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If server devices and components are dynamically changed to improve adaptability and resource utilization, then the system can provide flexible LCS services, but the established trust relationships are broken and system reliability deteriorates
Solution Approach 1:
The patent establishes trust relationships preliminarily between the resource management system and each resource device before dynamic changes occur. When resources are allocated or changed, the pre-established trust relationships are leveraged to maintain continuity. The resource management system uses these preliminary trust relationships to verify and manage dynamically changing resources without breaking the chain of trust.
Solution Approach 2:
The patent introduces an intermediary trust verification mechanism where the resource management system acts as a mediator between the LCS and dynamically changing resource devices. This intermediary layer maintains trust relationships by verifying resource identities and managing trust credentials, allowing resource changes while preserving reliability through the mediating trust management layer.
2Reliability
If traditional trust relationships are established between server devices and components, then trusted operation can be verified, but the trust chain is broken when server configuration changes
Solution Approach 1:
The patent transforms the traditional static trust relationship model into a dynamic one. Instead of fixed trust relationships between specific server components, the system establishes trust relationships between the resource management system and individual resource devices that can be dynamically allocated. This dynamic trust model allows the trust chain to adapt to configuration changes while maintaining verification capabilities through the resource management system's ongoing trust management.
3Adaptability or versatility
If resource devices are dynamically allocated to LCS, then system flexibility improves, but the complexity of maintaining trust relationships increases
Solution Approach 1:
The patent creates a universal trust management approach where the resource management system serves multiple functions: resource allocation, trust relationship establishment, and trust verification. This multi-functional approach simplifies complexity by consolidating trust management responsibilities in a single system that handles diverse resource types (storage, networking, computing) through a unified trust framework rather than separate trust mechanisms for each resource type.
Data Source
AI summary
An LCS trust system includes resource devices including respective resource device pTPMs, and an SCP device including an SCP device pTPM and providing a resource management system with a resource management system vTPM. The resource management system uses the resource management system vTPM to establish a first trust relationship with the SCP device via the SCP device pTPM, and respective second trust relationships with each of the resource devices via their respective resource device pTPMs. The resource management system the uses a subset of the resource devices to provide an LCS that includes an LCS vTPM and that uses the LCS vTPM to establish a respective third trust relationship with each of the subset of the resource devices via their respective resource device pTPMs. As such, a chain of trust is provided for the LCS that is based at least upon the first, respective second, and respective third trust relationships.


