Secure Hardware Cross-Device Trusted Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Trusted Platform Modules (TPMs) are ill-suited for cross-device scenarios due to their design limitations, which hinder seamless data sharing across multiple computing devices and are often slow and inefficient, making them unsuitable for fast or frequent operations.
Innovation Solution
A computing device equipped with secure hardware that includes a shared secret provisioned by a server computing system, enabling cross-device trusted computing by allowing secure access to remote resources and overcoming performance limitations of traditional TPMs through a cryptographic engine and remote access control component.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional TPM hardware is used to ensure security and trust, then security and reliability are improved, but cross-device functionality and data sharing capability deteriorate
Solution Approach 1:
The system divides the TPM functionality into two parts: a traditional TPM chip for security operations and a separate software-based TPM (S-TPM) component for cross-device functionality. This segmentation allows each component to specialize - the hardware TPM maintains security while the software component enables flexible cross-device operations through virtualization and cloud integration
Solution Approach 2:
A software-based TPM acts as an intermediary between the hardware TPM and cross-device applications. This S-TPM layer provides the cross-device functionality by mediating between the secure hardware root of trust and the need for flexible data sharing across multiple devices, using virtualization and cloud-based services
2Reliability
If traditional TPM hardware is used to ensure security, then reliability is improved, but operational speed and efficiency deteriorate
Solution Approach 1:
The system segments cryptographic operations between the hardware TPM for security-critical functions and software-based processing for performance-intensive operations. This allows fast software-based cryptographic operations to handle bulk operations while the hardware TPM provides secure key management and attestation
Solution Approach 2:
The patent replaces mechanical hardware-based TPM operations with software-based cryptographic operations for functions that require high performance. Software-based cryptographic libraries and algorithms provide faster execution for operations like encryption/decryption of large data sets while maintaining security through hardware-protected keys
3Reliability
If hardware-based TPM is used for secure operations, then security is improved, but cost increases when performance enhancements are implemented
Solution Approach 1:
The system segments TPM functionality into a basic hardware TPM (required for security) and optional software-based enhancements. This allows manufacturers to include only the essential hardware TPM at low cost, while advanced cross-device and performance features are provided through software and cloud services that add minimal hardware cost
Solution Approach 2:
The patent uses virtualization to create software-based copies of TPM functionality that can be replicated across multiple devices without additional hardware cost. The S-TPM software layer can be deployed as virtual instances that provide enhanced functionality while relying on the underlying hardware TPM for security
Data Source
AI summary
Various technologies described herein pertain to a computing device that includes secure hardware (e.g., a TPM, a secure processor of a processing platform, protected memory that includes a software-based TPM, etc.). The secure hardware includes a shared secret, which is shared by the secure hardware and a server computing system. The shared secret is provisioned by the server computing system or a provisioning computing system of a party affiliated with the server computing system. The secure hardware further includes a cryptographic engine that can execute a cryptographic algorithm using the shared secret or a key generated from the shared secret. The cryptographic engine can execute the cryptographic algorithm to perform encryption, decryption, authentication, and/or attestation.


