Regulating Firmware Update Warnings via TPM Binding Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems with hardware security modules like TPMs face challenges in determining whether the operating system relies on trusted computing base measurements, leading to unnecessary warnings during firmware updates that may not impact security functionality, potentially discouraging users from updating firmware.

Innovation Solution

The system regulates the display of firmware update warnings by determining whether the operating system binds operations to trusted computing base measurements stored in the TPM, only displaying the warning if such bindings are detected, thereby preventing unnecessary alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system displays firmware update warnings to ensure security awareness, then security protection is improved, but user convenience deteriorates due to unnecessary warnings

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by making the warning message display conditional rather than universal. The system checks whether the operating system binds operations to TPM measurements locally, and only displays warnings in those specific cases. This resolves the contradiction by providing security warnings only where actually needed, avoiding unnecessary warnings that would reduce user convenience while maintaining security protection where required.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback by having the system check the TPM binding status before displaying warnings. The system receives feedback about whether the OS binds operations to TPM measurements, and uses this feedback to determine whether to display the warning message. This feedback mechanism ensures warnings are displayed only when security is actually impacted, resolving the contradiction between security protection and user convenience.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If the system checks TPM measurement bindings to regulate warnings, then warning accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvewarning accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by checking whether the operating system binds operations to TPM measurements before displaying firmware update warnings. This preliminary check ensures that warnings are only shown when actually necessary, improving warning accuracy. The complexity added is minimal and focused on a specific pre-check condition, rather than comprehensive system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11544382B2Regulating messages warning about impacts of firmware changes
Publication Date: 2023.01.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11544382B2 patent drawing
  • US11544382B2 patent drawing
  • US11544382B2 patent drawing

AI summary

A technique includes detecting a presence of a hardware security module in a computer. The hardware security module performs trusted computing base measurements in response to the boot of the computer. The technique includes detecting an intention to change firmware of the computer and regulating providing a message warning about an impact of the change based on the determination. The regulation includes determining whether an operating system of the computer binds operations to the trusted computing base measurements and allowing communication of the message based on the determination.