TPM Local Credential Storage for Fast Host Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches for managing security information in cloud computing environments are inadequate for quick and secure recovery of host computing devices from large-scale events like network faults and power failures, as they rely on network communication for credential retrieval, leading to latency and increased recovery time.

Innovation Solution

Implementing a trusted platform module (TPM) on host computing devices to securely store credentials and recovery images, allowing local decryption and booting without network reliance, and performing remote attestation using boot firmware measurement to ensure secure communication with other devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional approaches rely on network communication for credential retrieval during recovery, then security verification can be performed, but recovery time increases due to latency and network dependencies

Engineering Contradiction:
Improvesecurity verificationVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The TPM credentials are provisioned and stored in the secure store before the failure event occurs. This preliminary action enables the host to perform local authentication immediately upon failure without needing to contact external credential servers, thus resolving the contradiction between maintaining security verification and reducing recovery time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The TPM secure store acts as an intermediary that holds credentials locally on the host device. This intermediary enables secure authentication to occur locally without requiring network communication with external credential servers, simultaneously achieving both security verification and fast recovery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If credentials are stored locally on the host device, then recovery speed improves, but security risks increase from potential credential compromise

Engineering Contradiction:
Improverecovery speedVSAvoidcredential compromise risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The TPM secure store provides locally-contained security capabilities on each host device. This local quality enables fast recovery while maintaining security through hardware-based protection, resolving the contradiction between recovery speed and security risk by making security a local property rather than a network-dependent one.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The TPM credentials are device-specific and can be regenerated or reissued if compromised. This approach allows the system to accept the risk of local storage by making credentials replaceable and device-bound, thus enabling fast recovery while mitigating long-term security risks through the ability to reset credentials.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If the system uses centralized credential management for security, then credential distribution is controlled, but mean time to recovery increases due to network dependencies

Engineering Contradiction:
Improvecredential management controlVSAvoidmean time to recovery
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The centralized credential management system is segmented by provisioning unique TPM credentials on each host device during manufacturing or initial setup. This segmentation allows each device to operate independently during recovery, eliminating network dependencies while maintaining the control benefits of centralized provisioning during normal operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Credentials are provisioned in advance during device setup or manufacturing, before any failure events occur. This preliminary action enables the system to maintain centralized control over credential distribution while allowing devices to perform autonomous fast recovery without real-time network connectivity.

Inventive Principle:
Principle #10Preliminary action

4Loss of time

If the host device performs local decryption and authentication without network reliance, then recovery time is reduced, but device complexity increases due to TPM integration

Engineering Contradiction:
Improverecovery timeVSAvoidTPM integration complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The host device with TPM is designed to be self-sufficient for authentication purposes, performing local decryption and self-attestation without requiring external authentication services during recovery. This self-service capability reduces recovery time while the TPM hardware abstracts the complexity, making the system easier to operate despite increased internal complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The TPM module replaces complex software-based credential storage and verification mechanisms with hardware-based cryptographic operations. This substitution reduces the operational complexity of local authentication while enabling fast recovery, as the hardware module handles the complex cryptographic operations automatically.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10810015B2Remote attestation of host devices
Publication Date: 2020.10.20 AMAZON TECH INC
  • US10810015B2 patent drawing
  • US10810015B2 patent drawing
  • US10810015B2 patent drawing

AI summary

Approaches are described for enabling a host computing device to store credentials and other security information useful for recovering the state of the host computing device in a secure store, such as a trusted platform module (TPM) on the host computing device. When recovering the host computing device in the event of a failure (e.g., power outage, network failure, etc.), the host computing device can obtain the necessary credentials from the secure store and use those credentials to boot various services, restore the state of the host and perform various other functions. In addition, the secure store (e.g., TPM) may provide boot firmware measurement and remote attestation of the host computing devices to other devices on a network, such as when the recovering host needs to communicate with the other devices on the network.