Remote TPM Physical Presence Assertion via IPMI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for asserting physical presence to a Trusted Platform Module (TPM) are cumbersome and economically burdensome, especially in remote administration of computing facilities, as they require manual intervention and can be time-consuming, especially when managing large numbers of servers.

Innovation Solution

Implementing methods and arrangements that allow for remote signaling of physical presence to a TPM over a secure network connection using protocols like IPMI, Web Services Management, or GPIO lines, enabling remote management servers to direct and authenticate the assertion of physical presence through baseboard management controllers or service processors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual physical presence assertion is used for TPM state changes, then security is improved, but administrative time and cost increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a remote administration system as an intermediary between the administrator and the TPM. This intermediary includes a remote administration server that communicates with the TPM over a network, allowing the administrator to assert physical presence remotely without physically visiting each server. The intermediary handles the complex interaction between the administrator, network communication, and TPM state changes, resolving the contradiction by maintaining security while eliminating the need for physical presence.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If technician visits each machine for physical presence assertion, then security is improved, but productivity decreases due to time consumption

Engineering Contradiction:
ImprovesecurityVSAvoidadministration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical system of physical presence assertion (technician physically visiting servers, pressing buttons, or plugging in power cables) with an electronic/digital system. The remote administration server sends commands over a network to the TPM, which electronically asserts physical presence without requiring physical interaction. This substitution maintains the security requirement while dramatically improving productivity by eliminating travel and manual intervention time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If remote administration is implemented, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveadministration efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal remote administration server that can manage multiple TPMs across different servers through a single system. Rather than requiring separate physical presence assertion mechanisms for each server, the server provides a unified interface for remote administration. This multi-functionality approach improves productivity by centralizing management while the standardized protocol reduces the actual complexity increase compared to implementing separate solutions for each server.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7900058B2Methods and arrangements for remote communications with a trusted platform module
Publication Date: 2011.03.01 INTEL CORP
  • US7900058B2 patent drawing
  • US7900058B2 patent drawing
  • US7900058B2 patent drawing

AI summary

Methods and arrangements to provide computer security are contemplated. Embodiments include transformations, code, state machines or other logic to provide computer security by receiving over a secure network connection a message to signal physical presence to a trusted platform module (TPM) and by signaling physical presence to the TPM in response to receiving the message. Some embodiments may involve sending the message over a secure network connection. In some embodiments, the receiving may be performed by a platform system management module. In many further embodiments, the signaling may include sending a signal over a secure general purpose input/output (GPIO) line or other hardware signaling mechanism. Other further embodiments may include sending a message pursuant to the intelligent platform management interface (IPMI) or other remote management protocol. In other embodiments, the receiving may be performed by a network stack of a basic input/output system. Other embodiments are described and claimed.