TPM Encryption Key Restoration via Dynamic Authentication Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing apparatuses face challenges in promptly restoring functionality when an encryption key is changed due to hardware security module replacement, leading to disruptions in user authentication and decryption processes, especially since the new TPM encryption key differs from the old one, preventing system administrators from restoring the TPM encryption key.
Innovation Solution
An information processing apparatus equipped with a verification unit to assess the usability of the encryption key and a disabling unit to temporarily disable user authentication, allowing for prompt restoration of the encryption key without requiring a safe mode or secondary OS, enabling the TPM encryption key restoration even when the user authentication function is not usable.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the user authentication function is enabled to ensure security, then the system security is improved, but the restoration of TPM encryption key becomes impossible when the key changes due to TPM replacement
Solution Approach 1:
The system dynamically adjusts the user authentication function based on the usability status of the TPM encryption key. When the key is determined to be unusable (e.g., after TPM replacement), the authentication function is temporarily disabled to enable restoration operations. This dynamic state change allows the system to transition between secure operation mode and restoration mode, resolving the contradiction between maintaining security and enabling repair.
2Ease of repair
If the safe mode activation process is implemented to enable TPM key restoration, then the ease of repair is improved, but the device complexity and operation time increase
Solution Approach 1:
The invention extracts the essential function of safe mode (enabling restoration when authentication fails) and integrates it directly into the existing activation process. Instead of requiring a separate safe mode entry point, the system uses the normal activation flow combined with usability verification to achieve the same restoration capability, thereby eliminating the need for additional safe mode infrastructure while maintaining repair ease.
3Productivity
If the user authentication function is disabled to enable TPM key restoration, then the restoration speed is improved, but the system security is temporarily reduced
Solution Approach 1:
The system performs preliminary verification of the TPM encryption key usability status before attempting restoration operations. By detecting the unusable state in advance (through verification of key usability rather than attempting authentication), the system proactively disables authentication only when needed, allowing restoration to proceed without unnecessary security checks and thereby improving restoration speed while maintaining security during normal operation.
Data Source
AI summary
An information processing apparatus including a hardware security module includes a verification unit configured to verify whether an encryption key of the hardware security module is usable and a disabling unit configured to disable a user authentication function if the verification unit verifies that the encryption key is not usable.


