Secure Element PCR Copy for Trusted Platform Module Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for providing trusted platform module (TPM) services without using a dedicated TPM device, particularly in portable devices like smartphones, where chip area and power constraints limit the implementation of high-security and fast response times.
Innovation Solution
A circuit comprising a first processing device with platform configuration registers for storing boot measurements and a secure element with additional platform configuration registers, connected via a communications interface to copy and cryptographically sign data values, enabling TPM functionality without a dedicated TPM device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated TPM device is used, then security is improved, but chip area and power consumption increase
Solution Approach 1:
The patent merges TPM functionality with existing processing devices and secure elements by sharing platform configuration registers and cryptographic resources. The first processing device and secure element both maintain PCR banks that can be used for TPM operations, eliminating the need for a separate dedicated TPM device while maintaining security functions.
Solution Approach 2:
The patent enables existing hardware components to perform multiple functions - the processing device and secure element not only perform their primary functions but also provide TPM services through shared PCR banks and cryptographic operations. This multi-functionality reduces overall chip area by reusing existing infrastructure.
2Reliability
If a dedicated TPM device is used, then security is improved, but power consumption increases
Solution Approach 1:
The patent combines TPM functionality with existing power-efficient secure elements and processing devices. By sharing cryptographic operations and PCR management between these components, the system avoids the continuous power consumption of a dedicated TPM device while maintaining security during active operations.
Solution Approach 2:
The patent extracts TPM-specific cryptographic operations and isolates them to the secure element, which can enter low-power states when not actively performing cryptographic functions. This separates the always-on security monitoring from intensive cryptographic operations, reducing overall power consumption.
3Area of stationary object
If TPM services are provided without a dedicated TPM device, then chip area and power consumption are reduced, but response time may slow down
Solution Approach 1:
The patent performs preliminary setup by establishing shared PCR banks between the processing device and secure element during system initialization. Boot measurements are pre-computed and stored in both locations, so that during runtime, TPM verification operations can proceed quickly without requiring complex real-time computation or data transfer.
Solution Approach 2:
The patent introduces a TPM service layer that acts as an intermediary, managing the shared PCR banks and coordinating operations between the processing device and secure element. This abstraction layer optimizes access patterns and caches frequently accessed data, reducing response time for TPM operations.
4Area of stationary object
If TPM services are provided without a dedicated TPM device, then chip area and power consumption are reduced, but system complexity increases
Solution Approach 1:
The patent introduces a TPM service layer that acts as an intermediary, managing the shared PCR banks and coordinating operations between the processing device and secure element. This abstraction layer simplifies the interface for applications while handling the complexity of multi-component coordination internally.
Solution Approach 2:
The patent segments TPM functionality into distinct modular components: the processing device handles boot measurement collection, the secure element provides cryptographic operations, and the TPM service layer manages coordination. This modular segmentation makes the system easier to understand, implement, and maintain despite the distributed architecture.
Data Source
AI summary
The invention concerns a circuit having a first processing device which has one or more first platform configuration registers for storing one or more data values based on boot measurements relating to a boot sequence implemented by the first processing device. The first processing device also has a secure element, which has its own processing device and one or more second platform configuration registers. The first and second platform configuration registers are coupled together via a communications interface adapted to copy the one or more data values from the one or more first platform configuration registers to the one or more second platform configuration registers.

