Removable TPM With Connection-Dependent Secure Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Trusted Platform Modules (TPMs) being permanently attached to devices allow malicious actors to steal valuable secrets by obtaining the TPM, as they travel with the device and cannot be physically separated.

Innovation Solution

Implementing a removable TPM that requires connection for boot operations and selected functions, disabling device functionality when disconnected, and enabling secure operations only with the TPM present.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the TPM is permanently attached to the device, then the device can continuously access cryptographic keys for secure operations, but the TPM can be stolen along with the device and secrets can be compromised

Engineering Contradiction:
ImprovesecurityVSAvoidtheft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system separates the TPM from the main device by making it a removable component that connects through a connector. The TPM can be physically separated from the device, allowing it to remain secure while the device operates. This segmentation resolves the contradiction by enabling security functions without requiring the TPM to permanently travel with the device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TPM is extracted from the permanent integrated structure and made into a removable component. By taking the TPM out of the fixed attachment and allowing it to be removed, the system eliminates the risk that stealing the device automatically gives access to the TPM and its secrets, while still allowing the TPM to provide security when connected.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If the TPM is removable from the device, then the risk of theft and unauthorized access is reduced, but the device cannot perform secure boot operations when the TPM is disconnected

Engineering Contradiction:
Improvetheft riskVSAvoidsecure operation availability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system dynamically adjusts its operational state based on the presence or absence of the TPM. When the TPM is connected, secure operations are enabled; when disconnected, the system transitions to a state where secure operations require the TPM. This dynamic behavior allows the system to maintain security while accommodating the removable nature of the TPM.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors the connection status of the TPM and adjusts its operational capabilities accordingly. The processor detects whether the TPM is present and enables or disables secure functions based on this feedback. This ensures that secure operations are only performed when the TPM is available, maintaining reliability while allowing the TPM to be removable.

Inventive Principle:
Principle #23Feedback

3Reliability

If the TPM is permanently attached, then secure operations are always available, but physical security cannot be ensured in shared workspaces or remote locations

Engineering Contradiction:
Improvesecure operation availabilityVSAvoidphysical security
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The TPM is extracted from the permanent attachment and made removable, allowing it to be physically separated from the device in unsecured environments. This enables users to leave the TPM in a secure location while the device operates in shared or remote workspaces, improving physical security without completely eliminating secure operation availability when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

By segmenting the system into a removable TPM and the main device, the patent allows the TPM to be kept secure in controlled locations while the device can operate independently in unsecured environments. This segmentation resolves the contradiction by separating the security function from the operational device.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4300335B1Removable trusted platform module
Publication Date: 2025.09.24 XEROX CORP
  • EP4300335B1 patent drawingFigure 1~2
  • EP4300335B1 patent drawingFigure 3
  • EP4300335B1 patent drawingFigure 4

AI summary

Apparatuses have a processing device that is operable with a connection to a physical cryptographic key device that has a valid cryptographic key. Such devices further include a connector that is adapted to connect to the physical cryptographic key device. The processing device is operatively connected to the connector. The processing device is adapted to change available functionality based on connection to, and disconnection from, the physical cryptographic key device.