TPM-SAM Direct Interface for Secure Appliance Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for verifying and identifying hardware and software of appliances and external data carriers are vulnerable to attacks and manipulations due to complex communication pathways and differing operating systems and encryption algorithms, leading to increased security risks and manufacturing complexity.
Innovation Solution
A direct communication interface between a Trusted Platform Module (TPM) and a Secure Application Module (SAM) allows for mutual verification and authorization without relying on the central arithmetic unit, using a simple protocol like I2C, and potentially sharing common components and memories, reducing the risk of manipulation and simplifying the design.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate modules TPM and SAM are used with communication via central arithmetic unit, then verification and identification of hardware/software and data carrier is achieved, but communication is susceptible to attacks and manipulations
Solution Approach 1:
The patent introduces a dedicated communication interface as an intermediary channel between TPM and SAM, separate from the central arithmetic unit. This intermediary interface enables direct secure communication between the security modules, eliminating the need to route communication through the potentially vulnerable central unit while maintaining verification and identification functions.
Solution Approach 2:
The patent segments the communication path by separating the TPM-SAM communication channel from the central arithmetic unit. The communication interface is divided into distinct functional components: a first interface in the TPM, a second interface in the SAM, and a dedicated communication path between them, isolating the security verification function from the central processing unit.
2Reliability
If separate modules TPM and SAM are used with different operating systems and encryption algorithms, then verification functionality is achieved, but direct communication is not possible
Solution Approach 1:
The communication interface acts as a standardized intermediary layer that translates between different operating systems and encryption algorithms. It provides a common protocol for TPM and SAM to interact, shielding the complexity of underlying system differences while enabling direct verification communication.
Solution Approach 2:
The communication interface is designed with universal functionality to handle multiple encryption algorithms and operating systems. It can adapt to different cryptographic protocols and system architectures, allowing TPM and SAM with diverse internal configurations to communicate directly for verification purposes.
3Reliability
If separate modules TPM and SAM are used, then verification and identification is achieved, but increased outlay for initialization is required
Solution Approach 1:
The patent merges the initialization process by enabling TPM and SAM to perform mutual verification and establish communication directly through the dedicated interface, eliminating the need for separate initialization procedures. The communication interface itself can be initialized once and used for both verification and identification functions, reducing overall setup complexity and cost.
Data Source
AI summary
In a method of and circuit for identifying and/or verifying the hardware and/or software of an appliance and of a data carrier, for example a smartcard, cooperating with the appliance, it is provided that a first unit (E1) for verifying the hardware and/or software of the appliance, in particular a Trusted Platform Module (TPM), and a second unit (E2) for verifying and/or identifying and authorizing the external data carrier, in particular a Secure Application Module (SAM), are coupled for direct data exchange via a communication interface (17) of the central arithmetic units (2, 10), in order to reduce or eliminate the possibility of attack or manipulation.


