LCS vTPM Provisioning Through SCP Isolation at Scale

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional LCS provisioning systems face security vulnerabilities due to hypervisor access to physical TPM devices, limited scalability, and inefficiency in managing large numbers of Logically Composed Systems (LCSs, particularly when providing multiple LCSs for different users.

Innovation Solution

The system employs a virtual Trusted Platform Module (vTPM) integrated with a secure SCP storage subsystem, enabling secure communication channels and vTPM management within a System Control Processor (SCP) framework to provide secure and scalable LCS provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical TPM devices are used for LCS provisioning, then security can be maintained for each LCS, but the system cannot scale to accommodate large numbers of LCSs and the hypervisor has full access to TPM contents increasing vulnerability

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the physical TPM device into multiple virtual TPM instances (vTPM1, vTPM2, vTPM3, etc.), each dedicated to a specific LCS. This segmentation allows the system to maintain security for each individual LCS while scaling to accommodate many LCSs simultaneously, as each vTPM is isolated and cannot be accessed by the hypervisor or other LCSs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates virtual copies of the physical TPM device functionality through vTPM instances. Instead of using the physical TPM directly for each LCS (which would require hypervisor access), the system creates software-based copies that emulate TPM functionality while maintaining security isolation and enabling scalable provisioning of numerous LCSs.

Inventive Principle:
Principle #26Copying

2Reliability

If physical TPM devices are used for LCS provisioning, then security can be maintained, but the physical TPM devices are not sized to accommodate large numbers of LCSs and lack durability for frequent swaps

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates virtual copies of TPM functionality that can be rapidly instantiated and destroyed without physical wear. These vTPM instances can be created in software and allocated to LCSs quickly, enabling frequent provisioning and deprovisioning operations without the durability limitations of physical TPM devices.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the fundamental parameter of TPM storage capacity from fixed physical limits to virtually unlimited software-based storage. The secure SCP storage subsystem can allocate storage space dynamically for each vTPM instance, allowing the system to accommodate any number of LCSs without being constrained by physical device size or endurance ratings.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If physical TPM devices are used with hypervisor management, then LCS provisioning can be performed, but the hypervisor having full access to TPM contents increases security vulnerability

Engineering Contradiction:
Improveprovisioning capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts TPM functionality from the physical device and relocates it to a virtualized form managed by the SCP engine rather than the hypervisor. This extraction removes the security vulnerability by ensuring that even the hypervisor cannot access vTPM contents, while the SCP engine maintains the ability to provision and manage LCSs securely.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the SCP engine as an intermediary between the resource management system and the vTPM instances. This intermediary layer provides secure management of TPM functionality without requiring hypervisor access to TPM contents, thereby maintaining provisioning capability while eliminating the security vulnerability of direct hypervisor-TPM access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260023607A1Secure LCS provisioning system
Publication Date: 2026.01.22 DELL PROD LP
  • US20260023607A1 patent drawing
  • US20260023607A1 patent drawing
  • US20260023607A1 patent drawing

AI summary

A secure LCS provisioning system includes a resource system coupled to a resource management system and including a resource system operating system and an SCP device. The SCP device receives LCS initialization information for an LCS from the resource management system and provides it to the resource system operating system. The SCP device also receives vTPM information for the LCS from the resource management system and uses it to provide an LCS vTPM for the LCS in a secure SCP storage subsystem. The SCP device then provides a secure communication channel between the resource system operating system and the secure SCP storage subsystem, and identifies a location of the LCS vTPM in the secure SCP storage subsystem to the resource system operating system, allowing the resource system operating system to access the LCS vTPM and use it with the LCS initialization information to provide an LCS.