Trusted Platform Module Capability Store for Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Device manufacturers face challenges in controlling device capabilities, as users with malicious intent can unlock additional functions without acquiring them from the manufacturer, leading to unauthorized use of premium features.
Innovation Solution
A trusted platform module (TPM) or protector mechanism provides a tamper-proof device capability store by imprinting a fingerprint of an endorsement key into the device's firmware, ensuring only authorized entities can access and add capabilities, using an access policy to manage read and write permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the device includes multiple capabilities unlocked by default, then the device functionality and user satisfaction are improved, but the security and manufacturer control are worsened
Solution Approach 1:
The patent segments device capabilities into locked and unlocked categories, with a trusted platform module separating capability storage from capability execution. The capability store is divided into authorized sections that require verification, allowing manufacturers to control access while enabling legitimate functionality.
Solution Approach 2:
The trusted platform module acts as an intermediary between the capability store and the device functionality. It verifies capabilities before execution, preventing unauthorized access while allowing legitimate capabilities to function. This mediator ensures manufacturer control is maintained even when capabilities are expanded.
2Reliability
If the device includes a trusted platform module with access policies, then the security and manufacturer control are improved, but the device complexity is worsened
Solution Approach 1:
The trusted platform module performs multiple functions within a single component: storing capabilities, verifying capabilities, enforcing access policies, and managing endorsements. This multi-functionality reduces the need for separate security components, mitigating the complexity increase despite enhanced security features.
3Reliability
If the manufacturer locks capabilities on the device, then the manufacturer control is improved, but the ease of operation and user flexibility are worsened
Solution Approach 1:
The device capability state is made dynamic rather than static. Capabilities can transition from locked to unlocked state through authorized processes. The trusted platform module enables this dynamic adjustment, allowing manufacturers to maintain control while permitting legitimate user flexibility when capabilities are properly authorized.
Data Source
AI summary
Systems and methods for facilitating a trusted platform module (TPM) or other protector mechanism that provides a device with a trusted device capability store. To provide the device with a trusted device capability store, a fingerprint of an endorsement key that is associated with the TPM or other protector mechanism can be imprinted into firmware of the device. By imprinting the fingerprint into the firmware, the device can determine whether or not the TPM or other protector mechanism the device is communicating with is the TPM or other protector mechanism associated with the device. The TPM or other protector mechanism can include the endorsement key, the trusted device capability store, and an access policy. The trusted device capability store can include one or more capabilities associated with the device. The access policy can indicate both unauthorized read access and authorized write access associated with the TPM or other protector mechanism.


