TPM-Based Secure Remote Management Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current system administration tools face challenges in securely managing and controlling remote computing systems, especially in OS-absent environments, where unauthorized access and malicious code can compromise authentication and data security.

Innovation Solution

The implementation of a secure computing management system using a Trusted Platform Module (TPM) and Alert Standard Format (ASF) standards, which includes a secure processor for authentication and cryptographic operations, ensures secure key management and protection against unauthorized access by keeping sensitive keys encrypted within the TPM's boundary, even in OS-absent states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote system management tools are implemented to provide visibility and control over remote systems, then system administration efficiency is improved, but security vulnerabilities increase due to unauthorized access and malicious code

Engineering Contradiction:
Improvesystem administration efficiencyVSAvoidunauthorized access and security vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Trusted Platform Module (TPM) as an intermediary security device that mediates between remote management tools and the target system. The TPM securely stores authentication credentials and cryptographic keys, acting as a trusted mediator that enables remote management while preventing unauthorized access. The management console communicates through the TPM, which verifies authenticity before allowing any management operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security functions by separating authentication and cryptographic operations into a dedicated TPM module, distinct from the main system components. This segmentation isolates security-critical functions from potential attacks on the main system, allowing remote management tools to operate efficiently while the TPM independently handles security verification.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If authentication credentials are stored in accessible locations for remote management, then ease of operation is improved, but security is compromised as malicious code can access and steal credentials

Engineering Contradiction:
Improveremote management accessibilityVSAvoidcredential theft by malicious code
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The TPM acts as an intermediary that holds authentication credentials securely without requiring them to be accessible to the main system or external attackers. The management console interacts with the TPM through controlled interfaces, obtaining authentication data only when needed and through verified channels, preventing malicious code from stealing credentials while maintaining operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts authentication credentials from the main system memory and storage, placing them exclusively in the TPM. This extraction removes the vulnerability where malicious code could access credentials in system memory, while the TPM provides controlled access mechanisms that maintain ease of operation for legitimate remote management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Use of energy by moving object

If the system enters low-power mode to minimize power consumption, then energy efficiency is improved, but remote management capability is reduced

Engineering Contradiction:
Improvepower consumptionVSAvoidremote management capability
Core Design Contradiction:
Use of energy by moving objectVSAdaptability or versatility

Solution Approach 1:

The TPM maintains authentication credentials and security contexts in advance, prepared for quick authentication even when the system is in low-power mode. The TPM can remain in a minimal power state while preserving cryptographic keys, allowing the system to enter low-power mode without sacrificing remote management capability. When management is needed, the TPM quickly resumes operation to verify credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic power management where the TPM can operate at different power levels independent of the main system. The TPM can stay in a low-power state during system sleep mode, consuming minimal energy, but can quickly transition to full operation when remote management requests arrive, maintaining adaptability while optimizing power consumption.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7940934B2System and method for securing computing management functions
Publication Date: 2011.05.10 NXP BV
  • US7940934B2 patent drawing
  • US7940934B2 patent drawing
  • US7940934B2 patent drawing

AI summary

In a computing management system authentication procedures are secured by protecting keys and/or processes used during the authentication procedures. In some embodiments the system cryptographically protects any keys used to mutually authenticate a management console and client. In some embodiments the system cryptographically protects execution of one or more of the algorithms used to mutually authenticate a management console and client.