Removable TPM Interface for On-Demand Digital Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing devices relying on integrated trusted platform modules (TPM) for security functions face limitations in flexibility and accessibility, particularly in generating and authenticating digital certificates for network communications, as they require hardware integration and complex network-based certificate authorities.

Innovation Solution

A device with a removable TPM interface that allows for the use of a separate, removably connectable TPM device to generate and sign digital certificates, enabling authentication without the need for an integrated TPM, using a certificate authority service that communicates with the TPM via wired or wireless interfaces to verify and transmit certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an integrated TPM is used for certificate generation, then security reliability is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the TPM functionality from the main device architecture, allowing it to be implemented as a separate, removably connectable component rather than being integrated into the device's permanent hardware. This enables the device to obtain TPM capabilities on-demand while maintaining a simpler base architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal TPM interface that can work with multiple TPM devices from different manufacturers and types. The certificate authority service can generate certificates using various TPM implementations (integrated, removable, external), making the system flexible and adaptable to different security requirements and device types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a removable TPM interface is used, then adaptability and ease of operation are improved, but security reliability may worsen

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a certificate authority service as an intermediary layer between the removable TPM interface and the security operations. This service manages the TPM device lifecycle, handles certificate generation securely, and ensures that even with removable TPMs, the security process remains controlled and reliable through automated verification and management protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If network-based certificate authorities are used, then authentication capability is improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service certificate authority service that runs locally on the device itself rather than requiring external network-based CAs. The device can autonomously generate and manage its own digital certificates using the TPM, eliminating the need for complex network authentication infrastructure and reducing operational dependencies on external services.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10320571B2Techniques for authenticating devices using a trusted platform module device
Publication Date: 2019.06.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10320571B2 patent drawing
  • US10320571B2 patent drawing
  • US10320571B2 patent drawing

AI summary

Described are examples for authenticating a device including detecting an event related to communications with a trusted platform module (TPM) device, performing, in response to detecting the event, one or more security-related functions with the TPM device, such as generating and/or signing one or more digital certificates, which may be based on one or more keys on the TPM device.