Secure Hardware Cross-Device Trusted Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Trusted Platform Modules (TPMs) are ill-suited for cross-device scenarios due to their design limitations, which hinder seamless data sharing across multiple computing devices and are often slow and inefficient, making them unsuitable for fast or frequent operations.

Innovation Solution

A computing device equipped with secure hardware that includes a shared secret provisioned by a server computing system, enabling cross-device trusted computing by allowing secure access to remote resources and overcoming performance limitations of traditional TPMs through a cryptographic engine and remote access control component.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional TPM hardware is used to ensure security and trust, then security and reliability are improved, but cross-device functionality and data sharing capability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcross-device functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system divides the TPM functionality into two parts: a traditional TPM chip for security operations and a separate software-based TPM (S-TPM) component for cross-device functionality. This segmentation allows each component to specialize - the hardware TPM maintains security while the software component enables flexible cross-device operations through virtualization and cloud integration

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A software-based TPM acts as an intermediary between the hardware TPM and cross-device applications. This S-TPM layer provides the cross-device functionality by mediating between the secure hardware root of trust and the need for flexible data sharing across multiple devices, using virtualization and cloud-based services

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional TPM hardware is used to ensure security, then reliability is improved, but operational speed and efficiency deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidoperational speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments cryptographic operations between the hardware TPM for security-critical functions and software-based processing for performance-intensive operations. This allows fast software-based cryptographic operations to handle bulk operations while the hardware TPM provides secure key management and attestation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces mechanical hardware-based TPM operations with software-based cryptographic operations for functions that require high performance. Software-based cryptographic libraries and algorithms provide faster execution for operations like encryption/decryption of large data sets while maintaining security through hardware-protected keys

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If hardware-based TPM is used for secure operations, then security is improved, but cost increases when performance enhancements are implemented

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system segments TPM functionality into a basic hardware TPM (required for security) and optional software-based enhancements. This allows manufacturers to include only the essential hardware TPM at low cost, while advanced cross-device and performance features are provided through software and cloud services that add minimal hardware cost

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses virtualization to create software-based copies of TPM functionality that can be replicated across multiple devices without additional hardware cost. The S-TPM software layer can be deployed as virtual instances that provide enhanced functionality while relying on the underlying hardware TPM for security

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10404466B2Secure hardware for cross-device trusted applications
Publication Date: 2019.09.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10404466B2 patent drawing
  • US10404466B2 patent drawing
  • US10404466B2 patent drawing

AI summary

Various technologies described herein pertain to a computing device that includes secure hardware (e.g., a TPM, a secure processor of a processing platform, protected memory that includes a software-based TPM, etc.). The secure hardware includes a shared secret, which is shared by the secure hardware and a server computing system. The shared secret is provisioned by the server computing system or a provisioning computing system of a party affiliated with the server computing system. The secure hardware further includes a cryptographic engine that can execute a cryptographic algorithm using the shared secret or a key generated from the shared secret. The cryptographic engine can execute the cryptographic algorithm to perform encryption, decryption, authentication, and/or attestation.