TPM Platform Key Software Entitlement Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems lack secure methods to tie software entitlements to specific hardware platforms, making them vulnerable to unauthorized use and malicious activities.

Innovation Solution

A system utilizing a Trusted Platform Module (TPM) compliant with TPM 2.0 standards, which generates and stores a private platform key during manufacturing, verifies software entitlements by creating a verification signature with a public key, ensuring that only authorized software is executed on the intended hardware platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software authorization keys are used to permit copying and execution of software, then software licensing and distribution are enabled, but the system becomes vulnerable to unauthorized use and system information can be altered to break the authorization binding

Engineering Contradiction:
Improvesoftware licensing capabilityVSAvoidauthorization binding reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a Trusted Platform Module (TPM) as an intermediary hardware component that securely stores system information and provides cryptographic proof of system state. The TPM acts as a mediator between the software authorization key and the information handling system, creating a trusted binding that cannot be easily altered. The TPM generates and stores cryptographic keys and provides attestation capabilities that verify the system's hardware and software configuration, thereby securing the authorization binding against tampering while maintaining software licensing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If TPM 1.2 with single storage hierarchy is used, then basic security functions are provided, but security feature limitations and lack of platform integrity verification exist

Engineering Contradiction:
ImproveTPM implementation simplicityVSAvoidplatform integrity verification
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements TPM 2.0 with three distinct storage hierarchies (platform hierarchy, storage hierarchy, and endorsement hierarchy) instead of the single hierarchy in TPM 1.2. Each hierarchy serves a specific security function: the platform hierarchy stores keys for platform integrity verification, the storage hierarchy handles user data encryption, and the endorsement hierarchy provides identity verification. This segmentation isolates security functions, prevents key confusion, and enables comprehensive platform integrity verification while maintaining manageable complexity through clear separation of duties.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11012241B2Information handling system entitlement validation
Publication Date: 2021.05.18 DELL PROD LP
  • US11012241B2 patent drawing
  • US11012241B2 patent drawing
  • US11012241B2 patent drawing

AI summary

Validation of entitlements to software is provided with a Trusted Platform Module (TPM) platform hierarchy private key created at manufacture of an information handling system and an associated public key. At initiation of an entitlement request, such as to install a software application, a verification signature associated with the request is verified by the TPM to ensure that the information handling system is entitled to run the software.