TPM Extraction for Automatic Reserved System Board Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing system board partitioning with a Trusted Platform Module (TPM) faces challenges in automatically switching to a reserved system board upon failure, leading to errors during system restart due to different encryption generation for each TPM chip, making it difficult to implement the reserved system board function without manual intervention.
Innovation Solution
An information processing device with multiple processing units, including a security unit, setting data holding unit, notification unit, and exclusive control unit, which sets up partitions to reserve another processing unit to operate in place of a failed one, ensuring seamless operation and avoiding errors by managing TPM settings through a system control device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a TPM chip is mounted on the system board to provide security function, then the security of the hardware resource is improved, but the automatic reserved system board function cannot be realized due to different encryption for each TPM chip
Solution Approach 1:
The patent extracts the TPM chip from the system board and mounts it on the reserved system board instead. This allows the main system board to be replaced without changing the TPM chip, thereby maintaining the same encryption and allowing automatic reserved system board function to work while preserving security.
Solution Approach 2:
The patent pre-configures the reserved system board with the same TPM chip that is used in the main system board before any failure occurs. This preliminary action ensures that when the main system board fails, the reserved system board can immediately take over without encryption errors, enabling automatic failover while maintaining security.
2Ease of operation
If the reserved system board function is implemented to automatically incorporate the reserved system board upon failure, then the ease of operation is improved, but the system cannot restart automatically when TPM is mounted due to encryption errors
Solution Approach 1:
The patent separates the TPM chip from the system board it originally belonged to, and re-mounts it on the reserved system board. This extraction allows the main system board to be replaced without TPM changes, eliminating encryption errors and enabling both automatic replacement and automatic restart capabilities.
Solution Approach 2:
The patent creates a copy of the TPM chip configuration from the main system board and applies it to the reserved system board in advance. This copying ensures that the reserved system board has identical encryption settings, allowing seamless automatic takeover and restart without errors.
3Reliability
If each TPM chip creates different encryption, then the security is improved through unique encryption for each chip, but errors occur during automatic construction certify function when system board changes
Solution Approach 1:
The patent extracts the TPM chip from the failed main system board and re-mounts it on the reserved system board. This ensures that the same TPM chip (with the same unique encryption) is used in both configurations, eliminating construction certify errors while preserving the security benefits of unique encryption.
Solution Approach 2:
The patent ensures homogeneity by using the same TPM chip in both the main system board and the reserved system board. This creates identical encryption settings across both boards, allowing automatic construction certify function to work correctly while maintaining the security advantages of TPM-based unique encryption.
Data Source
AI summary
An information processing device includes a replacement function of a system unit in a partition and a TPM (trusted platform module) function in the system unit. The system unit sets the TPM to valid or invalid and a management unit sets a reserved system board in the partition. The TPM setting information of the system unit and the reserved setting information of the system unit by the management unit are notified each other and are exclusive controlled. It is effectively possible to execute a reserved SB function, which integrates the reserved system board and re-starts without manual operation even though using a system unit which mounts the trusted platform module.


