Multinode Cryptoprocessor Type Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multinode systems often fail to maintain and utilize multiple cryptoprocessor types effectively, leading to unnecessary upgrades and loss of flexibility, as they primarily focus on a single cryptoprocessor type for primary node selection without considering other types present in the system.

Innovation Solution

The method involves selecting a primary node based on user-defined cryptoprocessor type criteria, identifying nodes with specific cryptoprocessor types, and designating them as primary within the multinode system, while allowing for flexibility in maintaining different cryptoprocessor types and prohibiting unnecessary firmware updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the system focuses on a single cryptoprocessor type for primary node selection, then system simplicity and performance optimization are improved, but system flexibility and the ability to maintain multiple cryptoprocessor types deteriorate

Engineering Contradiction:
Improvesystem performanceVSAvoidsystem flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system is designed to support multiple cryptoprocessor types (e.g., TPM 1.2, TPM 2.0, TCM) simultaneously within the same multinode cluster, allowing different nodes to perform different cryptographic functions based on their hardware capabilities. This multi-functionality approach enables the system to maintain both legacy and modern cryptoprocessor types without requiring a single standardized type across all nodes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic primary node selection based on runtime conditions rather than static configuration. The system can dynamically determine which cryptoprocessor type to use for specific operations based on availability, performance requirements, and security policies. This dynamic approach allows the system to adapt to changing conditions while maintaining multiple cryptoprocessor types in the cluster.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the system upgrades cryptoprocessors to a single newer type, then security and performance are improved, but compatibility with legacy systems and hardware diversity are lost

Engineering Contradiction:
ImprovesecurityVSAvoidhardware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary assessments of cryptoprocessor capabilities and compatibility before selecting primary nodes or executing cryptographic operations. By evaluating hardware types in advance and maintaining awareness of what cryptoprocessor types are available in the cluster, the system can plan operations that are compatible with legacy hardware while gradually incorporating newer, more secure cryptoprocessors as they become available.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes operational parameters such as cryptographic algorithm selection, key management approaches, and protocol versions based on the specific cryptoprocessor type being used. This allows the system to optimize security and performance for each cryptoprocessor type while maintaining compatibility across different hardware generations through parameter adjustment rather than hardware standardization.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If the system designates primary nodes based on performance criteria only, then system efficiency is improved, but the ability to maintain cryptoprocessor type diversity and prevent unnecessary upgrades deteriorates

Engineering Contradiction:
Improvesystem efficiencyVSAvoidcryptoprocessor type management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms that monitor not only performance metrics but also cryptoprocessor type distribution and upgrade status across the cluster. This feedback allows the system to adjust primary node selection to maintain desired levels of hardware diversity, preventing unnecessary upgrades by providing information about the current state of cryptoprocessor types and their utilization patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9916476B2Maintaining cryptoprocessor types in a multinode environment
Publication Date: 2018.03.13 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US9916476B2 patent drawing
  • US9916476B2 patent drawing
  • US9916476B2 patent drawing

AI summary

Maintaining cryptoprocessor types in a multinode system includes receiving a selection of a cryptoprocessor type; identifying, within a multinode system, a node having a cryptoprocessor of the selected cryptoprocessor type; and designating the node having the cryptoprocessor of the selected cryptoprocessor type as a primary node for the multimode system.