The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 02, 2021

Filed:

Aug. 21, 2018
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Timothy R. Block, Rochester, MN (US);

Elaine R. Palmer, Hanover, NH (US);

Kenneth A. Goldman, Norwalk, CT (US);

William E. Hall, Clinton, UT (US);

Hugo M. Krawczyk, Tarrytown, NY (US);

David D. Sanner, Rochester, MN (US);

Christopher J. Engel, Rochester, MN (US);

Peter A. Sandon, Essex Junction, VT (US);

Alwood P. Williams, III, Spicewood, TX (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/08 (2006.01); G06F 9/455 (2018.01); G06F 9/4401 (2018.01); G06F 9/445 (2018.01);
U.S. Cl.
CPC ...
H04L 63/0823 (2013.01); G06F 9/4416 (2013.01); G06F 9/44505 (2013.01); G06F 9/45558 (2013.01); H04L 9/085 (2013.01); G06F 2009/45595 (2013.01);
Abstract

A method and computer system for implementing authentication protocol for merging multiple server nodes with trusted platform modules (TPMs) utilizing provisioned node certificates to support concurrent node add and node remove. Each of the multiple server nodes boots an instance of enablement level firmware and extended to a trusted platform module (TPM) on each node as the server nodes are powered up. A hardware secure channel is established between the server nodes for firmware message passing as part of physical configuration of the server nodes to be merged. A shared secret is securely exchanged via the hardware secure channel between the server nodes establishing an initial authentication value shared among all server nodes. All server nodes confirm common security configuration settings and exchange TPM log and platform configuration register (PCR) data to establish common history for future attestation requirements, enabling dynamic changing the server nodes and concurrently adding and removing nodes.


Find Patent Forward Citations

Loading…