TPM Binding Keys for Data Accessibility and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing TPM systems enter 'Attack Mode' when tampered with or moved to a different platform, which is not desirable in all scenarios, as it disrupts the protection and accessibility of encrypted data.

Innovation Solution

A TPM that does not distinguish between tampering and platform changes, allowing it to continue normal operation and protect encrypted data by using specific keys for binding, enabling data accessibility only on the original host or compatible platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the TPM distinguishes tampering from platform changes and enters Attack Mode, then security protection is improved, but data accessibility is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the operational parameters of the TPM by introducing different binding key types (machine-specific keys vs. platform-specific keys) that correspond to different operational modes. When a machine-specific key is used, the TPM binds data to the specific machine and enters Attack Mode upon removal, providing high security. When a platform-specific key is used, the TPM allows normal operation across compatible platforms, providing high accessibility. This parameter change resolves the contradiction by allowing the system to optimize for either security or accessibility based on the binding key type selected.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the TPM is bound to a specific platform using machine-specific keys, then security is improved, but adaptability to different platforms is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidplatform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the binding mechanism into two distinct types: machine-specific binding and platform-specific binding. Each type serves a different purpose and can be selected based on requirements. Machine-specific binding uses keys unique to each machine for maximum security, while platform-specific binding uses keys compatible across multiple platforms for maximum adaptability. This segmentation resolves the contradiction by providing separate specialized solutions rather than a single compromise approach.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic behavior through the TPM's ability to respond differently based on the type of binding key used. When a machine-specific key is used, the TPM dynamically enters Attack Mode upon detecting platform changes. When a platform-specific key is used, the TPM dynamically allows continued operation. This dynamic response resolves the contradiction by adapting the security behavior to the specific binding scenario.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If the TPM allows normal operation when moved to a new platform, then data accessibility is improved, but security protection is worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the security parameter by introducing platform-specific binding keys that have different security characteristics than machine-specific keys. Platform-specific keys are configured to allow the TPM to operate normally across multiple compatible platforms without entering Attack Mode, thereby prioritizing accessibility over strict security. This parameter change resolves the contradiction by allowing the system to optimize for accessibility when platform-specific keys are used.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9015454B2Binding data to computers using cryptographic co-processor and machine-specific and platform-specific keys
Publication Date: 2015.04.21 VALTRUS INNOVATIONS LTD
  • US9015454B2 patent drawing
  • US9015454B2 patent drawing
  • US9015454B2 patent drawing

AI summary

Using a cryptographic co-processor in a computing system to encode data parameters determined during initialization, or during operation, or determined from machine specific values or states to bind data optionally to a specific machine, a specific cryptographic co-processor, or a specific operating environment machine state.