Anonymous TPM Authentication via Group Key Broadcast

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems for trusted platforms face challenges in maintaining anonymity while ensuring the authenticity of Trusted Platform Modules (TPMs) and minimizing computational and communication overhead, particularly due to the reliance on Certificate Authorities and the need for revocation mechanisms that may compromise user privacy.

Innovation Solution

An anonymous authentication system using a group key assigned to each data processing system, where a service provider provides an encrypted authenticator decryptable by the group key, and upon revocation, a new group key is distributed using broadcast encryption, ensuring TPM authenticity without revealing manufacturer attestation information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a Certificate Authority is used to verify TPM authenticity, then the reliability of authentication is improved, but the loss of information increases due to potential exposure of manufacturer attestation information and user privacy compromise

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser privacy information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the essential authentication function from the CA-based system by using group keys shared among trusted platforms. The authentication mechanism removes reliance on CA-issued certificates and instead uses a group key distribution scheme where each trusted platform shares a group key with the service provider. This extraction eliminates the information loss pathway through CA while maintaining authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication system manager as an intermediary that handles group key distribution and management. This intermediary component enables the service provider to authenticate multiple trusted platforms without directly accessing or storing sensitive manufacturer attestation information or user privacy data, thus preventing information loss while maintaining reliable authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individual authentication keys are used for each TPM, then the reliability of authentication is improved, but the device complexity increases due to key management and revocation overhead

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication keys of multiple trusted platforms into a single group key that is shared among all members of the trusted platform group. This consolidation reduces the number of individual keys that need to be managed, distributed, and revoked, thereby reducing device complexity while maintaining authentication reliability through the group key mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The group key serves multiple functions: it authenticates any member of the trusted platform group, enables revocation of individual members without affecting others, and simplifies key distribution. This multi-functionality reduces the overall complexity of the authentication system compared to managing separate keys for each platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a new group key is distributed to all systems upon revocation, then the reliability of revocation is improved, but the loss of time increases due to communication overhead for key distribution

Engineering Contradiction:
Improverevocation reliabilityVSAvoidkey distribution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the key distribution process by using broadcast encryption technology that allows the authentication system manager to efficiently distribute the new group key to all active trusted platforms simultaneously. This segmentation enables parallel transmission to multiple recipients, reducing the time required for key distribution while maintaining reliable revocation of the revoked platform.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7516326B2Authentication system and method
Publication Date: 2009.04.07 VALTRUS INNOVATIONS LTD
  • US7516326B2 patent drawing
  • US7516326B2 patent drawing
  • US7516326B2 patent drawing

AI summary

An authentication system and method for anonymous authentication of a data processing system from a group of data processing systems by a service provider are disclosed. A group key (110) is assigned to each data processing system (100) of the group of data processing systems. A service provider (120) is arranged to provide an encrypted authenticator (140) that is decryptable using the group key (110) to one of the data processing systems (100) to be authenticated and positively authenticate the data processing system upon receipt of data associated with the decrypted authenticator (130). Upon revocation of authentication rights of one of the data processing systems of the group, a new group key is distributed to the other data processing systems of the group using broadcast encryption.