TPM Credential Storage for Host Self-Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches for managing security information in cloud computing environments are inadequate for quick and secure recovery of host computing devices from large-scale events like network faults and power failures, as they rely on remote communication for credentials, leading to latency and prolonged recovery times.

Innovation Solution

Implementing a trusted platform module (TPM) on host computing devices to securely store credentials and boot firmware measurements, allowing local decryption and loading of recovery images, thereby enabling self-recovery without network dependence and ensuring secure communication with remote devices through remote attestation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional approaches rely on remote communication for credentials during host recovery, then security can be maintained through centralized control, but recovery time increases due to network latency and dependence

Engineering Contradiction:
ImprovesecurityVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The TPM securely stores credentials and boot firmware measurements in advance before any failure occurs. During recovery, these pre-stored credentials enable immediate local authentication and decryption operations without requiring remote communication, thus reducing recovery time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The TPM acts as an intermediary secure storage device between the host and remote credentials. It holds credentials locally and can provide them during recovery without requiring direct remote communication, serving as a mediator that reduces network dependence while maintaining security controls

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If credentials are stored remotely and fetched during recovery, then centralized security management is maintained, but network availability becomes a critical dependency for recovery

Engineering Contradiction:
Improverecovery independenceVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments credential storage from remote servers and places it in local TPM modules on each host. This segmentation allows each host to independently recover using its own locally-stored credentials, reducing network dependence while maintaining centralized provisioning capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each host equipped with a TPM can perform self-recovery using credentials stored in its own TPM module. The host does not need to contact remote servers to retrieve credentials during recovery, enabling autonomous recovery operations that are independent of network availability

Inventive Principle:
Principle #25Self-service

3Productivity

If local secure storage is implemented on each host, then recovery can proceed independently without network dependence, but the complexity of secure credential management increases

Engineering Contradiction:
Improverecovery speedVSAvoidcredential management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces complex software-based credential management with hardware-based TPM modules that provide cryptographic operations and secure storage. This substitution simplifies credential management by leveraging the TPM's built-in security features rather than implementing complex software solutions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9594638B2Host recovery using a secure store
Publication Date: 2017.03.14 AMAZON TECH INC
  • US9594638B2 patent drawing
  • US9594638B2 patent drawing
  • US9594638B2 patent drawing

AI summary

Approaches are described for enabling a host computing device to store credentials and other security information useful for recovering the state of the host computing device in a secure store, such as a trusted platform module (TPM) on the host computing device. When recovering the host computing device in the event of a failure (e.g., power outage, network failure, etc.), the host computing device can obtain the necessary credentials from the secure store and use those credentials to boot various services, restore the state of the host and perform various other functions. In addition, the secure store (e.g., TPM) may provide boot firmware measurement and remote attestation of the host computing devices to other devices on a network, such as when the recovering host needs to communicate with the other devices on the network.