TPM Authorization Principals for OS Context Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computers are vulnerable to attacks such as dictionary and brute force attacks on passwords and personal identification numbers, leading to reduced user trust and security concerns.

Innovation Solution

The representation of operating system context in a trusted platform module using authorization principals, which are derived and bound to security assets, enhances system security by characterizing and controlling access to security assets based on operating system attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If passwords or personal identification numbers are used for data protection, then users can access their data, but computers become vulnerable to dictionary attacks or brute force attacks

Engineering Contradiction:
Improvedata accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authorization principal as an intermediary between the user and security assets. Instead of directly using passwords, the system derives authorization principals from operating system context (process IDs, user IDs, group IDs) that serve as mediators for access control. This intermediary layer prevents direct exposure of passwords to attackers while maintaining user access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical password-based authentication system with a context-based authorization system. Rather than relying on users to remember and input passwords (mechanical interaction), the system automatically derives authorization principals from operating system context attributes, substituting the manual password entry mechanism with automated context-based authentication that is resistant to dictionary and brute force attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a trusted platform module is used to store security assets, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidhardware structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the trusted platform module universal by enabling it to handle multiple security functions: storing security assets, deriving authorization principals from various operating system context attributes, and enforcing access policies. This multi-functionality reduces the need for separate security modules for different purposes, thereby limiting the increase in device complexity while maintaining enhanced security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements nesting by integrating the authorization principal derivation functionality within the trusted platform module itself. The TPM contains nested components including security asset storage, context attribute processing units, and authorization policy enforcement mechanisms, all housed within the single TPM hardware boundary. This nested structure consolidates multiple security functions into one module rather than requiring separate hardware components.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP3198511B1Representation of operating system context in a trusted platform module
Publication Date: 2020.07.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3198511B1 patent drawingFigure 1
  • EP3198511B1 patent drawingFigure 2
  • EP3198511B1 patent drawingFigure 3

AI summary

Techniques for representation of operating system context in a trusted platform module are described. In at least some embodiments, authorization principals that correspond to representations of operating system context are derived in a trusted platform module. The authorization principals can be used to define authorization policies for access to security assets stored in a trusted platform module.