Secure Element PCR Copy for Trusted Platform Module Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for providing trusted platform module (TPM) services without using a dedicated TPM device, particularly in portable devices like smartphones, where chip area and power constraints limit the implementation of high-security and fast response times.

Innovation Solution

A circuit comprising a first processing device with platform configuration registers for storing boot measurements and a secure element with additional platform configuration registers, connected via a communications interface to copy and cryptographically sign data values, enabling TPM functionality without a dedicated TPM device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated TPM device is used, then security is improved, but chip area and power consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidchip area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent merges TPM functionality with existing processing devices and secure elements by sharing platform configuration registers and cryptographic resources. The first processing device and secure element both maintain PCR banks that can be used for TPM operations, eliminating the need for a separate dedicated TPM device while maintaining security functions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables existing hardware components to perform multiple functions - the processing device and secure element not only perform their primary functions but also provide TPM services through shared PCR banks and cryptographic operations. This multi-functionality reduces overall chip area by reusing existing infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a dedicated TPM device is used, then security is improved, but power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent combines TPM functionality with existing power-efficient secure elements and processing devices. By sharing cryptographic operations and PCR management between these components, the system avoids the continuous power consumption of a dedicated TPM device while maintaining security during active operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts TPM-specific cryptographic operations and isolates them to the secure element, which can enter low-power states when not actively performing cryptographic functions. This separates the always-on security monitoring from intensive cryptographic operations, reducing overall power consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

3Area of stationary object

If TPM services are provided without a dedicated TPM device, then chip area and power consumption are reduced, but response time may slow down

Engineering Contradiction:
Improvechip areaVSAvoidresponse time
Core Design Contradiction:
Area of stationary objectVSSpeed

Solution Approach 1:

The patent performs preliminary setup by establishing shared PCR banks between the processing device and secure element during system initialization. Boot measurements are pre-computed and stored in both locations, so that during runtime, TPM verification operations can proceed quickly without requiring complex real-time computation or data transfer.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a TPM service layer that acts as an intermediary, managing the shared PCR banks and coordinating operations between the processing device and secure element. This abstraction layer optimizes access patterns and caches frequently accessed data, reducing response time for TPM operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Area of stationary object

If TPM services are provided without a dedicated TPM device, then chip area and power consumption are reduced, but system complexity increases

Engineering Contradiction:
Improvechip areaVSAvoidsystem complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent introduces a TPM service layer that acts as an intermediary, managing the shared PCR banks and coordinating operations between the processing device and secure element. This abstraction layer simplifies the interface for applications while handling the complexity of multi-component coordination internally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments TPM functionality into distinct modular components: the processing device handles boot measurement collection, the secure element provides cryptographic operations, and the TPM service layer manages coordination. This modular segmentation makes the system easier to understand, implement, and maintain despite the distributed architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10275599B2Device and method for providing trusted platform module services
Publication Date: 2019.04.30 STMICROELECTRONICS BELGIUM
  • US10275599B2 patent drawing
  • US10275599B2 patent drawing

AI summary

The invention concerns a circuit having a first processing device which has one or more first platform configuration registers for storing one or more data values based on boot measurements relating to a boot sequence implemented by the first processing device. The first processing device also has a secure element, which has its own processing device and one or more second platform configuration registers. The first and second platform configuration registers are coupled together via a communications interface adapted to copy the one or more data values from the one or more first platform configuration registers to the one or more second platform configuration registers.