Security Processor Secure Table for Flexible TPM Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing TPM chipsets are inflexible and costly due to the need for customization with specific security architectures and encryption algorithms for different users, and they lack the ability to securely unload or reload security applications.

Innovation Solution

A security processor with a secure table in nonvolatile memory that stores certified endorsement keys and hash values, allowing for the execution of certified applications and supporting various security architectures, enabling flexible and secure support of different encryption algorithms and architectures, and allowing applications to be unloaded and loaded while maintaining security and updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a standard general purpose TPM is used with a particular set of encryption algorithms, then the device can be manufactured with a single architecture, but it cannot satisfy users who require different encryption algorithms such as GOST, SMS4, or proprietary algorithms

Engineering Contradiction:
Improvesupport for different encryption algorithmsVSAvoidcustomization of TPM chipset
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal TPM architecture that can execute multiple different security applications through a loadable module mechanism. The microcontroller is designed to load and execute different security architecture applications (e.g., TPM 1.2, TPM 2.0, or proprietary algorithms) from external memory, allowing a single hardware platform to provide multiple cryptographic algorithm sets including AES, GOST, SMS4, and proprietary algorithms without requiring separate customized chipsets for each algorithm set.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If different TPM chipsets are customized for each user specification, then each user gets their required security architecture, but the manufacturing cost increases greatly

Engineering Contradiction:
Improveuser-specific security architectureVSAvoidmanufacturing cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal security processor platform that can be manufactured once and then configured for different users by loading appropriate security architecture applications into external memory. This eliminates the need to manufacture separate customized TPM chipsets for each user specification, significantly reducing manufacturing costs while still providing each user with their required security architecture and algorithms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a mechanism where security architecture applications can be copied from external memory to the microcontroller's memory space and executed. This allows the same hardware platform to serve multiple users with different security requirements by copying and executing different security application versions, rather than manufacturing unique hardware for each user.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If a TPM architecture is securely unloaded from the microcontroller, then other applications can be loaded on the chip, but prior implementations did not allow secure reloading of the most recent version

Engineering Contradiction:
Improveloading and unloading applicationsVSAvoidsecure reloading
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a secure reload mechanism that uses hash value verification to ensure the integrity of security architecture applications. When reloading an application, the system computes a hash value of the loaded application and compares it against a stored reference hash value. This feedback mechanism ensures that only authentic, unmodified applications can be executed, maintaining security while enabling flexible loading and unloading of different security architectures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8099789B2Apparatus and method for enabling applications on a security processor
Publication Date: 2012.01.17 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8099789B2 patent drawing
  • US8099789B2 patent drawing
  • US8099789B2 patent drawing

AI summary

Method and apparatus for enabling applications on security processors of computer systems. In one aspect, a security processor apparatus includes a processor and a memory coupled to the processor and operative to store a secure table. The secure table stores different certified endorsement keys and different values, each value associated with one of the endorsement keys. Each stored value is derived from a different application that is certified by the associated endorsement key to be executed on the processor.