TPM Encryption Key Restoration via Dynamic Authentication Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing apparatuses face challenges in promptly restoring functionality when an encryption key is changed due to hardware security module replacement, leading to disruptions in user authentication and decryption processes, especially since the new TPM encryption key differs from the old one, preventing system administrators from restoring the TPM encryption key.

Innovation Solution

An information processing apparatus equipped with a verification unit to assess the usability of the encryption key and a disabling unit to temporarily disable user authentication, allowing for prompt restoration of the encryption key without requiring a safe mode or secondary OS, enabling the TPM encryption key restoration even when the user authentication function is not usable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the user authentication function is enabled to ensure security, then the system security is improved, but the restoration of TPM encryption key becomes impossible when the key changes due to TPM replacement

Engineering Contradiction:
Improvesystem securityVSAvoidTPM encryption key restoration
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The system dynamically adjusts the user authentication function based on the usability status of the TPM encryption key. When the key is determined to be unusable (e.g., after TPM replacement), the authentication function is temporarily disabled to enable restoration operations. This dynamic state change allows the system to transition between secure operation mode and restoration mode, resolving the contradiction between maintaining security and enabling repair.

Inventive Principle:
Principle #15Dynamics

2Ease of repair

If the safe mode activation process is implemented to enable TPM key restoration, then the ease of repair is improved, but the device complexity and operation time increase

Engineering Contradiction:
ImproveTPM encryption key restorationVSAvoidsafe mode function
Core Design Contradiction:
Ease of repairVSDevice complexity

Solution Approach 1:

The invention extracts the essential function of safe mode (enabling restoration when authentication fails) and integrates it directly into the existing activation process. Instead of requiring a separate safe mode entry point, the system uses the normal activation flow combined with usability verification to achieve the same restoration capability, thereby eliminating the need for additional safe mode infrastructure while maintaining repair ease.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If the user authentication function is disabled to enable TPM key restoration, then the restoration speed is improved, but the system security is temporarily reduced

Engineering Contradiction:
Improverestoration speedVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification of the TPM encryption key usability status before attempting restoration operations. By detecting the unusable state in advance (through verification of key usability rather than attempting authentication), the system proactively disables authentication only when needed, allowing restoration to proceed without unnecessary security checks and thereby improving restoration speed while maintaining security during normal operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9985783B2Information processing apparatus and information processing method for restoring apparatus when encryption key is changed
Publication Date: 2018.05.29 CANON KK
  • US9985783B2 patent drawing
  • US9985783B2 patent drawing
  • US9985783B2 patent drawing

AI summary

An information processing apparatus including a hardware security module includes a verification unit configured to verify whether an encryption key of the hardware security module is usable and a disabling unit configured to disable a user authentication function if the verification unit verifies that the encryption key is not usable.