Secure Processor Segmentation for TPM and Non-TPM Coexistence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure processing systems, such as TPMs, face challenges in securely managing and protecting keys and data when non-TPM compliant applications are integrated, as they may compromise the security of TPM operations and expose sensitive information.

Innovation Solution

A secure processor is designed to support both TPM and non-TPM security functions, managing keys and performing cryptographic processes while maintaining the security boundary of the TPM, by using standard TPM commands and key structures for both TPM and non-TPM operations, ensuring that non-TPM operations do not affect or expose TPM data and keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a TPM is configured to support only TPM-compliant operations, then security and compliance are maintained, but functionality and adaptability are limited

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the secure processor into distinct functional areas: a TPM-compliant region that maintains strict security protocols and a non-TPM region that provides extended functionality. This segmentation allows non-TPM applications to access secure processing capabilities without compromising the integrity of TPM operations, as each region operates with appropriate security controls tailored to its specific requirements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure processor is designed with multi-functionality to support both TPM-compliant operations and non-TPM security functions within a single device. The processor can execute both standardized TPM commands and custom non-TPM commands, allowing it to serve diverse security needs while maintaining a unified security architecture under controlled conditions

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If additional non-TPM commands and resources are added to support non-TPM applications, then functionality is improved, but device complexity increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges non-TPM security functions with the TPM architecture by implementing them within the same secure processor boundary. Non-TPM commands share cryptographic resources, key management infrastructure, and security enforcement mechanisms with TPM operations, reducing the need for separate hardware components and minimizing overall system complexity while maintaining functionality

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If non-TPM applications are integrated into the TPM, then adaptability is improved, but security risks increase due to potential exposure of TPM data and keys

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The secure processor implements segmentation that isolates TPM data and keys from non-TPM applications through separate memory spaces, command validation layers, and access control mechanisms. This ensures that non-TPM operations cannot inadvertently or maliciously access TPM-protected information, maintaining security boundaries while enabling extended functionality

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary security mechanisms including command validation layers, authorized access controls, and isolated execution environments that mediate between non-TPM applications and the TPM core. These intermediaries enforce security policies, validate operations, and prevent unauthorized access to TPM resources, allowing safe integration of diverse applications

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9268971B2Secure processor supporting multiple security functions
Publication Date: 2016.02.23 NXP BV
  • US9268971B2 patent drawing
  • US9268971B2 patent drawing
  • US9268971B2 patent drawing

AI summary

A secure processor such as a trusted platform module supports multiple security functions within a single secure processing environment. For example, the secure processor may be configured to perform functions in accordance with the TPM specification and to perform other, non-TPM, security functions. These security functions may be operated independently such that the operation of one security function does not violate or compromising the security of other security functions.