IP Library Granted Patent US 7,600,134
Granted Patent B2
US 7,600,134 · App. 10/984,400 · Granted Oct 6, 2009

Theft deterrence using trusted platform module authorization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,600,134
App. No.
10/984,400
Granted
Oct 6, 2009
Kind
B2
Abstract

A method for theft deterrence of a computer system is disclosed. The computer system includes a trusted platform module (TPM) and storage medium. The method comprises providing a binding key in the TPM; and providing an encrypted symmetric key in the storage medium. The method further includes providing an unbind command to the TPM based upon an authorization to provide a decrypted symmetric key; and providing the decrypted symmetric key to the secure storage device to allow for use of the computer system. Accordingly, by utilizing a secure hard disk drive (HDD) that requires a decrypted key to function in conjunction with a TPM, a computer if stolen is virtually unusable by the thief. In so doing, the risk of theft of the computer is significantly reduced.

Claims (19)

1. A method for theft deterrence of a computer system, the computer system having a trusted platform module (TPM) with a stored root key (SRK), and storage medium requiring a decrypted symmetric key to function in relation to the TPM, the method comprising:

providing a non-migratable binding key loadable by a basic input/output system (BIOS) in the TPM;

providing an encrypted symmetric key and an encrypted encryption key in the storage medium to provide a secure storage medium;

providing an unbind command from the BIOS to the TPM based upon an authorization to provide a decrypted symmetric key, wherein the unbind command includes the encrypted symmetric key and an authorization digest, wherein the authorization digest is derived from a password authorization prompt and is defined as using a particular payload for the unbind command during a particular instance; and

providing the decrypted symmetric key to the secure storage medium to enable use of the computer system.

2. The method of claim 1 wherein the BIOS prompts for binding key authorization.

3. A computer system comprising:

a input/output (I/O);

a processor coupled to the I/O:

a trusted platform module (TPM) with a stored root key (SRK), coupled to the I/O, the TPM including a non-migratable binding key loadable by a basic input/output system (BIOS);

the BIOS coupled to the I/O; and

a secure storage medium requiring a decrypted symmetric key to function in relation to the TOP and coupled to the I/O, the secure storage medium including an encrypted symmetric key blob, comprised of an encrypted symmetric key and an encrypted encryption key, decryptable by an unbind command provided from the BIOS to the TPM, wherein the unbind command include the encrypted symmetric key and an authorization digest, wherein the authorization digest is derived from a password authorization prompt and is defined as using a particular payload for the unbind command during a particular instance.

4. The computer system of claim 3 wherein the BIOS prompts for binding key authorization.

5. A computer readable medium containing program instructions for theft deterrence of a computer system, the computer system including a trusted platform module (TPM) with a stored root key (SRK), and storage medium requiring a decrypted symmetric key to function in relation to the TPM, the program instructions for:

providing a non-migratable binding key loadable by a basic input/output system (BIOS) in the TPM;

providing an encrypted symmetric key and an encrypted encryption key in the storage medium to provide a secure storage medium;

providing an unbind command from the BIOS to the TPM based upon an authorization to provide a decrypted symmetric key, wherein the unbind command includes the encrypted symmetric key and an authorization digest, wherein the authorization digest is derived from a password authorization prompt and is defined as using a particular payload for the unbind command during a particular instance; and

providing the decrypted symmetric key to the secure storage medium to enable use of the computer system.

6. The computer readable medium of claim 5 wherein the BIOS prompts for binding key authorization.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2025
From: LENOVO PC INTERNATIONAL LIMITED
To: LENOVO SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 069870/0670 →
NUNC PRO TUNC ASSIGNMENT Recorded Nov 25, 2015
From: LENOVO (SINGAPORE) PTE LTD.
To: LENOVO PC INTERNATIONAL
Reel/Frame 037160/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2005
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: LENOVO (SINGAPORE) PTE LTD.
Reel/Frame 016891/0507 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2005
From: CATHERMAN, RYAN C.; CHALLENER, DAVID C.; HOFF, JAMES P.; PENNISI, JOSEPH; SPRINGFIELD, RANDALL S.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 016143/0434 →