Trusted Platform Module Software Update Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional software installation techniques lack the necessary security to ensure that software is only installed on authorized devices and prevent unauthorized duplication or distribution, especially in remote deployment scenarios where verifying device integrity is challenging and costly.

Innovation Solution

The use of a Trusted Platform Module (TPM) to encrypt and decrypt software updates, verifying device identity and configuration through platform configuration registers (PCRs), and binding the software update to the TPM to prevent unauthorized access and distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote software delivery is implemented, then software installation convenience is improved, but security risk increases

Engineering Contradiction:
Improvesoftware installation convenienceVSAvoidsoftware security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification of device integrity through PCR measurements before software delivery. The service provider checks the device's trusted configuration state in advance, and only delivers software to devices that pass verification, preventing compromised devices from receiving updates

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The TPM module acts as an intermediary between the device and service provider, providing cryptographic verification of device integrity. The TPM's PCR values serve as a trusted mediator to prove device authenticity, enabling secure remote software delivery without physical media

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If physical verification by technician is performed, then device integrity verification accuracy is improved, but cost and scalability worsen

Engineering Contradiction:
Improvedevice integrity verification accuracyVSAvoiddeployment scalability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The device performs self-verification of its integrity through the TPM module, which automatically measures and reports PCR values. This eliminates the need for technician intervention while maintaining verification accuracy, enabling scalable remote deployment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual physical verification by technicians with automated cryptographic verification using TPM and PCR values. This substitution of mechanical/physical processes with electronic/cryptographic processes maintains verification precision while dramatically improving scalability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Speed

If software is made accessible remotely, then deployment speed is improved, but risk of unauthorized duplication increases

Engineering Contradiction:
Improvedeployment speedVSAvoidunauthorized duplication risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The software is encrypted with device-specific keys stored in the TPM, making each device's software copy unique and non-transferable. This local customization of encryption ensures that even though software is delivered remotely, it cannot be duplicated or transferred to unauthorized devices

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system preemptively prevents unauthorized duplication by binding software to the device's TPM through cryptographic sealing. The software is rendered useless on any device other than the authorized one, countering duplication attempts before they can occur

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3479282B1Targeted secure software deployment
Publication Date: 2020.03.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3479282B1 patent drawingFigure 1
  • EP3479282B1 patent drawingFigure 2
  • EP3479282B1 patent drawingFigure 3A

AI summary

The techniques and systems described herein are directed to providing targeted, secure software deployment in a computing system. An identity of the computing device can be determined and verified using a trusted platform module (TPM) of the computing device, and a software update can be expressly configured to operate solely on the computing device. Further, a configuration of the computing device can be ascertained using platform configuration registers (PCRs) of the TPM to determine that the computing device has not been modified from a trusted configuration. For example, if malware or unauthorized software is operating on the computing device, the software update may be prevented from being installed. Further, the software update can be targeted for a particular computing device, such that when the software update is received at the computing device, the software update may not be duplicated and provided to an additional, unauthorized device.