Portable Security Device With TPM For Cross-Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing difficulty in managing passwords and secure information across multiple devices, coupled with the rising risk of user accounts being hacked or compromised by malicious software, highlights the need for enhanced security measures beyond conventional software-based solutions.

Innovation Solution

A portable security device equipped with a trusted platform module (TPM) that provides secure hardware-based encryption, key management, remote attestation, and dictionary attack prevention, ensuring the integrity and security of associated devices by generating cryptographic keys, binding data, and forming a 'chain of trust' to protect against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional software-based security solutions are used for password management across multiple devices, then ease of operation is improved, but reliability deteriorates due to increased vulnerability to hacking and malicious software

Engineering Contradiction:
Improvepassword managementVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A portable security device acts as an intermediary between the user and multiple computing devices. The device contains a TPM that generates and manages cryptographic keys, storing them securely in isolated memory. The TPM creates a chain of trust by attesting to the identity of each device it connects to, enabling secure passwordless authentication across multiple devices without exposing private keys. This mediator approach allows easy cross-device operation while maintaining high security reliability through hardware-based protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic keys are stored in conventional software-based key management systems, then ease of operation is improved, but object-generated harmful factors worsen due to key vulnerability to attacks

Engineering Contradiction:
Improvekey managementVSAvoidkey vulnerability
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent replaces software-based key management with a hardware-based Trusted Platform Module (TPM). The TPM is a dedicated security chip that provides hardware-enforced isolation for cryptographic operations. Private keys are generated and stored within the TPM's secure memory, which is physically isolated from the host system's memory and processing units. This mechanical/hardware substitution eliminates software vulnerabilities that could expose keys to attacks, while maintaining ease of operation through automated cryptographic operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of key storage from software memory to hardware-isolated memory within a TPM. This parameter change transforms the security model by moving keys from a vulnerable software environment to a protected hardware environment with physical security boundaries. The TPM's memory is designed to prevent unauthorized access, even by the host system, fundamentally changing the attack surface and vulnerability profile of key management.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a portable security device with TPM is used to securely generate and manage cryptographic keys, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidhardware structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The portable security device is designed as a universal solution that can securely authenticate across multiple different computing devices (laptops, desktops, mobile devices). The TPM within the device provides multi-functional security services including key generation, key storage, remote attestation, and secure authentication protocols. This universality justifies the added hardware complexity by providing comprehensive security protection across diverse platforms and use cases, rather than requiring device-specific security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3251044B1Portable security device
Publication Date: 2020.10.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3251044B1 patent drawingFigure 1
  • EP3251044B1 patent drawingFigure 2
  • EP3251044B1 patent drawingFigure 3

AI summary

A portable security device for a computing system includes a housing, an interface at least partially disposed within the housing, a trusted platform module within the housing that is coupled to the interface, and a controller within the housing that is coupled to the trusted platform module and the interface. The interface is configured to engage a plurality of different devices and provide communication between the portable security device and an individual device when engaged with the individual device. In some examples, the trusted platform module can receive power from the individual device via the interface when the portable security device is engaged with the individual device. The controller includes logic to detect when the portable security device is coupled to the individual device via the interface.