TPM Platform Key Software Entitlement Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems lack secure methods to tie software entitlements to specific hardware platforms, making them vulnerable to unauthorized use and malicious activities.
Innovation Solution
A system utilizing a Trusted Platform Module (TPM) compliant with TPM 2.0 standards, which generates and stores a private platform key during manufacturing, verifies software entitlements by creating a verification signature with a public key, ensuring that only authorized software is executed on the intended hardware platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software authorization keys are used to permit copying and execution of software, then software licensing and distribution are enabled, but the system becomes vulnerable to unauthorized use and system information can be altered to break the authorization binding
Solution Approach 1:
The patent introduces a Trusted Platform Module (TPM) as an intermediary hardware component that securely stores system information and provides cryptographic proof of system state. The TPM acts as a mediator between the software authorization key and the information handling system, creating a trusted binding that cannot be easily altered. The TPM generates and stores cryptographic keys and provides attestation capabilities that verify the system's hardware and software configuration, thereby securing the authorization binding against tampering while maintaining software licensing functionality.
2Ease of manufacture
If TPM 1.2 with single storage hierarchy is used, then basic security functions are provided, but security feature limitations and lack of platform integrity verification exist
Solution Approach 1:
The patent implements TPM 2.0 with three distinct storage hierarchies (platform hierarchy, storage hierarchy, and endorsement hierarchy) instead of the single hierarchy in TPM 1.2. Each hierarchy serves a specific security function: the platform hierarchy stores keys for platform integrity verification, the storage hierarchy handles user data encryption, and the endorsement hierarchy provides identity verification. This segmentation isolates security functions, prevents key confusion, and enables comprehensive platform integrity verification while maintaining manageable complexity through clear separation of duties.
Data Source
AI summary
Validation of entitlements to software is provided with a Trusted Platform Module (TPM) platform hierarchy private key created at manufacture of an information handling system and an associated public key. At initiation of an entitlement request, such as to install a software application, a verification signature associated with the request is verified by the TPM to ensure that the information handling system is entitled to run the software.


