System and method for secure migration of virtual trusted platform modules
The virtual machine system securely migrates vTPMs using a Manufacturer Migration Server and HSMs as RoT to unwrap and rewrap APKs, addressing the security challenges of vTPM migration and ensuring integrity and confidentiality of cryptographic assets.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-10
- Publication Date
- 2026-03-19
AI Technical Summary
Current methods for securely migrating virtual Trusted Platform Modules (vTPMs) between cloud VM servers lack robust mechanisms, risking the integrity and confidentiality of cryptographic assets, especially during failures or load balancing.
A virtual machine system utilizing a Manufacturer Migration Server and Hardware Security Modules (HSMs) as Roots of Trust (RoT) to securely unwrap and rewrap Asset Protection Keys (APKs) during vTPM migration, with automatic detection and revocation of vTPMs to enhance security and integrity.
Ensures secure and seamless vTPM migration between cloud servers, maintaining cryptographic asset confidentiality and integrity, reducing unauthorized access and downtime, and enhancing the resilience of cloud infrastructure.
Smart Images

Figure EP2024075211_19032026_PF_FP_ABST
Abstract
Description
[0001] SYSTEM AND METHOD FOR SECURE MIGRATION OF VIRTUAL TRUSTED PLATFORM MODULES
[0002] TECHNICAL FIELD
[0003] The present disclosure relates to virtual machine systems and their administration in cloud computing environments. Moreover, the present disclosure relates to the secure management and migration of virtual trusted platform modules (vTPMs) using hardware security modules (HSM) as a root of trust.
[0004] BACKGROUND
[0005] Virtual machine (VM) systems have become integral to modem cloud computing infrastructures, providing the necessary flexibility and scalability for deploying and managing applications. However, the security of these virtualized environments remains a critical concern, particularly with the increasing need for secure storage and handling of sensitive cryptographic keys and other assets. Trusted Platform Modules (TPM) are traditionally used to secure these cryptographic operations in physical systems. In virtual environments, the concept of virtual TPMs (vTPM) has been introduced to extend these security benefits to VMs.
[0006] Existing technologies for managing vTPMs often rely on software-based mechanisms, which can be vulnerable to various attack vectors. The introduction of hardware security modules (HSM) to provide a root of trust (RoT) in virtual environments has enhanced security by binding cryptographic keys to the hardware. However, the migration of vTPMs between cloud VM servers, especially in response to failures or load balancing, presents significant challenges. Current methods lack robust mechanisms to securely transfer the asset protection keys (APK) associated with vTPMs between different HSMs without compromising security.
[0007] Therefore, in light of the foregoing discussion, there exists a need to overcome the aforementioned drawbacks.
[0008] SUMMARY
[0009] The present disclosure provides a virtual machine system, a method for the virtual machine system and a computer program product comprising program instructions for performing the method when executed by one or more processors in the virtual machine system. The present disclosure provides a solution to the existing problem of securely migrating virtual Trusted Platform Modules (vTPMs) between cloud servers without compromising the integrity and confidentiality of cryptographic assets. In current cloud environments, the process of moving vTPMs across different servers can be fraught with risks, mainly when the original server is unavailable or compromised. An objective of the present disclosure is to provide a solution that overcomes at least partially the problems encountered in the prior art and provides an improved system and method for securely managing the migration of vTPMs. Additionally, the solution aims to allow for the effective revocation of vTPMs from the original server, reducing the risk of unauthorized duplication and enhancing overall security within cloud computing environments.
[0010] One or more objectives of the present disclosure are achieved by the solutions provided in the enclosed independent claims. Advantageous implementations of the present disclosure are further defined in the dependent claims.
[0011] In one aspect, the present disclosure provides a virtual machine system, including a virtual machine (VM) administrator server communicatively connected to a manufacturer migration server. The VM administrator server being configured to administrate a first cloud VM server and a second cloud VM server. Each of the cloud VM server is configured to execute one or more virtual trusted platforms modules (vTPM), each vTPM utilizing an Asset Protection Key (APK). Further, each cloud VM server comprises a Hardware Security Module (HSM), which is configured to operate as Root of Trust (RoT) for at least one of the vTPMs and to unwrap the APK based on an identifier and a Hardware Unique Secret (HUS) of the HSM, and the Manufacturer Migration Server is configured to store identifiers and HUSs of manufactured HSMs, and the VM administrator server is further configured to inform the Manufacturer Migration Server that the first cloud VM server and the second cloud VM server are associated in a cloud migration group. The VM administrator server is further configured to inform the Manufacturer Migration Server of the HSMs of the first cloud VM server and the second cloud VM server, whereby the Manufacturer Migration Server has access to the identifiers and the HUSs of the HSMs of the first cloud VM server and the second cloud VM server and the VM administrator server is further configured to determine that there is a request to move at least one of the vTPM(s) from the first cloud VM server to the second cloud VM server and in response thereto request the Manufacturer Migration Server to rewrap the APK(s) of the vTPM(s) of the first cloud VM server based on the HSM of the second cloud VM server, and then revoke the vTPM(s) of the first cloud VM server on the second cloud VM server utilizing the rewrapped APK(s).
[0012] The virtual machine system securely manages the migration of the vTPMs between cloud servers while maintaining the integrity and confidentiality of cryptographic assets. By incorporating the Manufacturer Migration Server and utilizing HSMs as the RoT for each vTPM, the virtual machine system ensures that the APKs are securely unwrapped and rewrapped during migration. The secure wrapping and unwrapping during migration prevent unauthorized access to sensitive data, even in scenarios where one of the cloud servers fails or becomes unavailable. Furthermore, the ability to revoke vTPMs from the original server after migration enhances security by minimizing the risk of unauthorized duplication or continued use of outdated cryptographic keys. The seamless communication between the VM administrator server and the Manufacturer Migration Server ensures that the necessary identifiers and HUSs are adequately managed, facilitating a secure and efficient migration process. Overall, the VM system provides a robust solution to the challenges of secure vTPM migration in cloud computing environments, improving both data protection and reliability.
[0013] In an implementation form, the VM administrator server is further configured to determine that there is a request to move at least one of the vTPM(s) by determining that there has been a failure in the first cloud VM server.
[0014] Advantageously, by automatically detecting server failures and responding by securely transferring the vTPMs, the VM administrator server enhances the resilience and reliability of the VM system. The automatic detection reduces the need for manual intervention, accelerates recovery time, and maintains the integrity of sensitive cryptographic operations, leading to a more robust and fault-tolerant cloud infrastructure.
[0015] In an implementation form, the VM administrator server is further configured to authenticate itself to the Manufacturer Migration Server during instantiation and to request a cloud migration group for the VM administrator server in the Manufacturer Migration Server.
[0016] Advantageously, by authenticating itself, the VM administrator server ensures that only authorized entities can manage vTPM migrations. Requesting a cloud migration group secures the process by limiting operations to specific, controlled cloud VM servers. This approach prevents unauthorized access, safeguards sensitive data, and enhances the efficiency and reliability of the migration process.
[0017] In an implementation form, the Manufacturer Migration Server is further configured to ensure that each HSM only belongs to one migration group.
[0018] Ensuring that each HSM belongs to only one migration group enhances security by preventing unauthorized or accidental crossgroup migrations. This restriction minimizes the risk of data breaches and ensures that cryptographic keys and other sensitive assets remain isolated within their designated environment, maintaining the integrity and trustworthiness of the migration process. Additionally, it simplifies management by clearly defining the boundaries and associations of each HSM, reducing the likelihood of configuration errors, and ensuring that migrations occur within a controlled and secure framework. In an implementation form, wherein the VM administrator server is further configured to replace an APK of a vTPM with the rewrapped APK in a data file of the vTPM.
[0019] In such an implementation form, replacing the APK of the vTPM with the rewrapped APK in its data file ensures that the vTPM remains securely functional after migration to a new cloud VM server. The process maintains the confidentiality and integrity of the protected assets by aligning the vTPMs security credentials with the unfamiliar environment. Further, the rewrapped APK in its data file also ensures a seamless transition, preventing any disruption in the vTPM's operations, and reinforces the overall security by keeping the encryption keys up-to-date and consistent with the current HSM.
[0020] In an implementation form, the VM administrator server is further configured to request the Manufacturer Migration Server to remove the first cloud VM server from the cloud migration group.
[0021] Advantageously, requesting the removal of the first cloud VM server from the cloud migration group after migration ensures that the server is no longer associated with the sensitive data and keys of the migrated vTPMs. The removal action prevents unauthorized access or potential security breaches by severing ties between the old environment and the migrated assets. It enhances the security and integrity of the migration process by ensuring that only the current, active cloud VM server retains access to the critical security elements, thereby reducing the risk of vulnerabilities in the cloud infrastructure.
[0022] In another implementation form, the VM system comprises the Manufacturer Migration Server.
[0023] Incorporating the Manufacturer Migration Server within the VM system provides seamless integration and direct control over the migration processes. The setup eliminates the need for external communication with separate entities, thereby reducing latency and potential points of failure.
[0024] In another implementation form, each vTPM is configured to transmit a request to a coprocessor, the request being associated with a sensitive asset for a functionality of the virtual trusted platform module. Further, each vTPM is configured to receive a response from the coprocessor, the response indicating a security information associated with the functionality of the virtual trusted platform module and provide the functionality of the vTPM based on the received security information. The vTPM is extended with a Computer Virtual Trusted Platform Module (Co-vTPM), and the Co-vTPM is configured to store protected assets of the Co-Trusted Platform Module in memory outside Co-vTPM, wherein the APK is a protected asset.
[0025] Extending the vTPM with a Co-vTPM that stores protected assets externally enhances security against memory attacks and leaks. By storing sensitive assets like keys and seeds outside the Co-vTPM environment in encrypted form, the risk of exposure to memory disclosure attacks or leaks is significantly reduced. The sensitive assets are only decrypted within the Co-vTPM during specific operations, minimizing the time they are vulnerable. The architecture also reduces the memory footprint of the Co-vTPM, allowing efficient scaling while maintaining security. Additionally, provisioning the Hardware-Based Key (HBK) during Co-vTPM manufacturing ensures its secure embedding, preventing tampering and maintaining the integrity of the device.
[0026] In another aspect, the present disclosure provides a method for the VM system. The method includes the Manufacturer Migration Server storing identifiers and HUSs of manufactured HSMs. The method further includes the VM administrator server informing the Manufacturer Migration Server that the first cloud VM server and the second cloud VM server are associated in a cloud migration group and informing the Manufacturer Migration Server of the HSMs of the first cloud VM server and the second cloud VM server, whereby the Manufacturer Migration Server has access to the identifiers and the HUSs of the HSMs of the first cloud VM server and the second cloud VM server. The method further includes determining by the VM administrator server that there is a request to move at least one of the vTPM(s) from the first cloud VM server to the second cloud VM server and, in response thereto requesting the Manufacturer Migration Server to rewrap the APK(s) of the vTPM(s) of the first cloud VM server based on the HSM of the second cloud VM server, and then revoking the vTPM(s) of the first cloud VM server on the second cloud VM server utilizing the rewrapped APK(s).
[0027] The method for the VM system achieves all the advantages and technical effects of the VM system of the present disclosure.
[0028] In another aspect, the present disclosure provides a computer program product comprising program instructions for performing the method when executed by one or more processors in the VM system.
[0029] In yet another aspect, the present disclosure provides a VM administrator server. The VM administrator server communicatively connected to the Manufacturer Migration Server, and the VM administrator server is configured to administrate the first cloud VM server and the second cloud VM server. Each cloud VM server is configured to execute one or more virtual vTPM, each utilizing the APK, and each cloud VM server comprises the HSM, which is configured to operate as RoT for at least one of the vTPMs and to unwrap the APK based on an identifier and the HUS of the HSM. The Manufacturer Migration Server is configured to store identifiers and HUSs of manufactured HSMs. The VM administrator server is further configured to inform the Manufacturer Migration Server that the first cloud VM server and the second cloud VM server are associated in a cloud migration group, and to inform the Manufacturer Migration Server of the HSMs of the first cloud VM server and the second cloud VM server, whereby the Manufacturer Migration Server has access to the identifiers and the HUSs of the HSMs of the first cloud VM server and the second cloud VM server. The VM administrator server is further configured to determine that there is a request to move at least one of the vTPM(s) from the first cloud VM server to the second cloud VM server, and in response thereto, request the Manufacturer Migration Server to rewrap the APK(s) of the vTPM(s) of the first cloud VM server based on the HSM of the second cloud VM server, and then revoke the vTPM(s) of the first cloud VM server on the second cloud VM server utilizing the rewrapped APK(s).
[0030] By enabling the VM administrator server to coordinate with the Manufacturer Migration Server, the VM system allows for seamless migration of vTPMs between cloud VM servers without disrupting the security of the assets. The rewrapping of APKs ensures that the vTPMs are securely transitioned. By using the identifiers and HUSs, the rewrapping process protects sensitive keys and data during transfers between cloud VM servers. Associating the first and second cloud VM servers within a cloud migration group and managing vTPM migrations through the Manufacturer Migration Server provides flexibility in handling dynamic cloud environments, making it easier to scale and manage workloads securely. The configuration of the VM system allows the VM administrator server to manage and automate the migration process centrally, reducing manual intervention, lowering the risk of errors, and increasing operational efficiency.
[0031] In yet another aspect, the present disclosure includes a Manufacturer Migration Server communicatively connected to the VM administrator server in the VM system, the VM administrator server being configured to administrate the first cloud VM server and the second cloud VM server. Each cloud VM server is configured to execute one or more vTPM, each utilizing the APK, and each cloud VM server includes HSM, which is configured to RoT for at least one of the vTPMs, and to unwrap the APK based on an identifier and the HUS of the HSM. The Manufacturer Migration Server is configured to store identifiers and HUSs of manufactured HSMs, receive information from the VM administrator server that the first cloud VM server and the second cloud VM server are associated in a cloud migration group and receive information from the VM administrator server on the HSMs of the first cloud VM server and the second cloud VM server. The Manufacturer Migration Server has access to the identifiers and the HUSs of the HSMs of the first cloud VM server and the second cloud VM server. The Manufacturer Migration Server is further configured to receive a request to rewrap the APK(s) of the vTPM(s) of the first cloud VM server based on the HSM of the second cloud VM server from the VM administrator server in response to the VM administrator server determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server to the second cloud VM server, and thereby enabling the VM administrator server to revoke the vTPM(s) of the first cloud VM server on the second cloud VM server utilizing the rewrapped APK(s). By using the Manufacturer Migration Server to rewrap the APK of the vTPM based on the target cloud VM server's HSM, the VM system ensures that the migration of vTPMs between cloud servers is both secure and seamless. The use of HSMs as the RoT ensures that the integrity of the vTPM is maintained during and after the migration process, as the APK is securely unwrapped and rewrapped based on verified HSM credentials. The VM system reduces downtime and potential errors during migration by automating the rewrapping and revocation of APKs through the Manufacturer Migration Server, enabling a smooth and efficient transition between cloud VM servers. By centralizing the storage and management of HSM identifiers and HUSs in the Manufacturer Migration Server, the system VM simplifies and enhances the control of the migration process, making it easier to manage multiple cloud VM servers and their associated vTPMs.
[0032] In an implementation form, the Manufacturer Migration Server is also communicably connected to a second VM administrator server.
[0033] The second VM administrator server reduces the risk of single points of failure, making the VM system more robust and reliable for managing cloud migrations. Further, the second VM administrator server ensures better coordination and synchronization between different VM administrator servers, leading to more efficient management and migration processes.
[0034] In another aspect, the present disclosure provides a method for the Manufacturer Migration Server. The method includes storing identifiers and HUSs of manufactured HSMs, receiving information from the VM administrator server that the first cloud VM server and the second cloud VM server are associated in a cloud migration group and receiving information from the VM administrator server on the HSMs of the first cloud VM server and the second cloud VM server, whereby the Manufacturer Migration Server has access to the identifiers and the HUSs of the HSMs of the first cloud VM server and the second cloud VM server. The method further comprises the Manufacturer Migration Server receiving a request to rewrap the APK(s) of the vTPM(s) of the first cloud VM server based on the HSM of the second cloud VM server from the VM administrator server the in response to the VM administrator server determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server to the second cloud VM server, and thereby enabling the VM administrator server to revoke the vTPM(s) of the first cloud VM server on the second cloud VM server utilizing the rewrapped APK(s).
[0035] The method for the Manufacturer Migration Server achieves all the advantages and technical effects of the Manufacturer Migration Server of the present disclosure.
[0036] It is to be appreciated that all the aforementioned implementation forms can be combined.
[0037] It has to be noted that all devices, elements, circuitry, units, and means described in the present application could be implemented in the software or hardware elements or any kind of combination thereof. All steps which are performed by the various entities described in the present application as well as the functionalities described to be performed by the various entities are intended to mean that the respective entity is adapted to or configured to perform the respective steps and functionalities. Even if, in the following description of specific embodiments, a specific functionality or step to be performed by external entities is not reflected in the description of a specific detailed element of that entity which performs that specific step or functionality, it should be clear for a skilled person that these methods and functionalities can be implemented in respective software or hardware elements, or any kind of combination thereof. It will be appreciated that features of the present disclosure are susceptible to being combined in various combinations without departing from the scope of the present disclosure as defined by the appended claims.
[0038] Additional aspects, advantages, features, and objects of the present disclosure would be made apparent from the drawings and the detailed description of the illustrative implementations construed in conjunction with the appended claims that follow. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The summary above, as well as the following detailed description of illustrative embodiments, is better understood when read in conjunction with the appended drawings. For the purpose of illustrating the present disclosure, exemplary constructions of the disclosure are shown in the drawings. However, the present disclosure is not limited to specific methods and instrumentalities disclosed herein. Moreover, those in the art will understand that the drawings are not to scale. Wherever possible, like elements have been indicated by identical numbers.
[0040] Embodiments of the present disclosure will now be described, by way of example only, with reference to the following diagrams wherein:
[0041] FIG. 1 is a block diagram that depicts a virtual machine system, in accordance with an embodiment of the present disclosure;
[0042] FIG. 2A is a block diagram of vTPM extended with a computer virtual trusted platform module (Co-vTPM), in accordance with an embodiment of the present disclosure;
[0043] FIG. 2B is an exemplary diagram that depicts the utilization of the Hardware Bound Key (HBK) and Asset Protection Key (APK), in accordance with an embodiment of the present disclosure;
[0044] FIG. 3 is a flowchart depicting a method for the virtual machine system, in accordance with an embodiment of the present disclosure;
[0045] FIG. 4 is an exemplary diagram depicting the process flow for migrating virtual machines (VMs) and their associated vTPMs between different cloud servers, in accordance with an embodiment of present disclosure;
[0046] FIG. 5 is flowchart depicting a method for the VM administrator server, in accordance with an embodiment of the present disclosure; and
[0047] FIG. 6 is a flowchart depicting a method for the Manufacturer Migration Server, in accordance with an embodiment of the present disclosure.
[0048] In the accompanying drawings, an underlined number is employed to represent an item over which the underlined number is positioned or an item to which the underlined number is adjacent. A non-underlined number relates to an item identified by a line linking the non-underlined number to the item. When a number is non-underlined and accompanied by an associated arrow, the non-underlined number is used to identify a general item at which the arrow is pointing.
[0049] DETAILED DESCRIPTION OF EMBODIMENTS
[0050] The following detailed description illustrates embodiments of the present disclosure and ways in which they can be implemented. Although some modes of conducting the present disclosure have been disclosed, those skilled in the art would recognize that other embodiments for conducting or practicing the present disclosure are also possible.
[0051] FIG. 1 is a block diagram that depicts a virtual machine system, in accordance with an embodiment of the present disclosure. With reference to FIG.1 , there is shown a block diagram 100 that includes a virtual machine (VM) system 102. The VM system 102 includes a VM administrator server 106 communicatively connected to a Manufacturer Migration Server 104. The VM system 102 further includes a first cloud VM server 108 and a second cloud VM server 116. Further, each cloud VM server includes a Hardware Security Module (HSM), i.e. a first HSM 112 (HSM of the first cloud server 108) and a second HSM 120 (HSM of the second cloud server 116). The first cloud server 108 includes a plurality of virtual trusted platform modules (vTPM), i.e., a first vTPM 110A, a second vTPM HOB up to nth vTPM HON. Similarly, the second cloud server 108 includes a plurality of virtual trusted platform modules (vTPM) i.e., a first vTPM H8A, a second vTPM H8B up to nth vTPM H8N.
[0052] The VM system 102 refers to a computing environment that includes multiple virtual machines running on cloud infrastructure. The Manufacturer Migration Server 104 is a dedicated server that manages the secure migration of cryptographic assets within a cloud environment. It stores and manages identifiers and Hardware Unique Secrets (HUSs) of Hardware Security Modules (HSMs) used by cloud servers. This server ensures that each HSM is securely associated with only one migration group at any given time.
[0053] The VM Administrator Server 106 is responsible for managing and coordinating operations between multiple cloud VM servers and is designed to administrate and oversee the execution of (vTPMs) across different cloud environments. The VM administrator server ensures that each VM server is secure and that cryptographic keys, such as Asset Protection Keys (APKs), are appropriately managed during operations such as migration, instantiation, and key management.
[0054] The cloud VM server (i.e., the first cloud VM server 108 and the second VM server 116) is a virtualized server hosted in a cloud computing environment, where the physical hardware resources are abstracted into virtual machines. Each VM operates as an independent server with its own operating system and applications, running on shared physical infrastructure managed by a cloud provider. The cloud VM servers offer flexibility, scalability, and cost-efficiency, allowing users to deploy, manage, and scale virtualized computing resources on demand.
[0055] The vTPM (for example, a plurality of vTPM 110, i.e., a first vTPM 110A, a second vTPM HOB up to nth vTPM HON) is a virtual counterpart of a physical Trusted Platform Module (TPM) designed to provide secure cryptographic functions in virtualized environments. The vTPM ensures the integrity and security of virtual machines (VMs) by leveraging the functionalities of the physical TPM.
[0056] The VM administrator server being configured to administrate a first cloud VM server and a second cloud VM server, wherein each cloud VM server is configured to execute one or more virtual trusted platforms modules, vTPM, each utilizing an Asset Protection Key, APK, and each cloud VM server comprises a Hardware Security Module ( HSM), which is configured to operate as Root of Trust (RoT) for at least one of the vTPMs, and to unwrap the APK based on an identifier and a Hardware Unique Secret (HUS) of the HSM. The HSM is a hardware unit that stores cryptographic keys to keep them private while ensuring they are available to those authorized to use them. The endorsement key is an encryption key that is permanently embedded in the Trusted Platform Module (TPM) security hardware, at the time of manufacture.
[0057] The VM administrator server 106 is further configured to replace an APK of the vTPM with the rewrapped APK in a data file of the vTPM. Replacing the APK of the vTPM with the rewrapped APK in its data file ensures that the vTPM remains securely functional after migration to a new cloud VM server. This process maintains the confidentiality and integrity of the protected assets by aligning the vTPMs security credentials with the unfamiliar environment. It also ensures a seamless transition, preventing any disruption in the vTPM's operations, and reinforces the overall security by keeping the encryption keys up-to- date and consistent with the current HSM.
[0058] The RoT is an essential, foundational security component that provides a set of trustworthy functions that the rest of the device or system can use to establish strong levels of security. Often integrated as a chip, using a RoT gives devices a trusted source that can be relied upon within any cryptographic system. These functions include trusted boot, measurement, secure storage, reporting and verification, with the RoT able to store confidential cryptographic keys away from system software, which is often targeted by hackers.
[0059] The Manufacturer Migration Server 104 is configured to store identifiers and HUSs of manufactured HSMs, and the VM administrator server 106 is further configured to inform the Manufacturer Migration Server 104 that the first cloud VM server 108 and the second cloud VM server 116 are associated with a cloud migration group and to inform the Manufacturer Migration Server 104 of the HSMs of the first cloud VM server 108 and the second cloud VM server 116. The Manufacturer Migration Server 104 has access to the identifiers and the HUSs of the HSMs of the first cloud VM server 108 and the second cloud VM server 116.
[0060] In operation, the VM administrator server 106 identifies and informs the Manufacturer Migration Server 104 that two cloud VM servers (the first cloud VM server 108 and the second cloud server 116) are associated in a cloud migration group, that means that these servers are part of the same security domain, allowing for the secure transfer of VMs and their vTPMs between them. The Manufacturer Migration Server 104 stores the identifiers and HUSs of the HSMs used by these cloud VM servers. The information is critical for securely managing the cryptographic keys during VM operations and migrations.
[0061] The VM administrator server 106 is further configured to determine that there is a request to move at least one of the vTPM(s) from the first cloud VM server 108 to the second cloud VM server 116 and, in response thereto, request the Manufacturer Migration Server 104 to rewrap the APK(s) of the vTPM(s) of the first cloud VM server 108 based on the HSM 120 of the second cloud VM server 116, and then revoke the vTPM(s) of the first cloud VM server 108 on the second cloud VM server 116 utilizing the rewrapped APK(s). When there is a request to move one or more vTPMs from the first cloud VM server 108 to the second cloud VM server 116, the VM administrator server 106 initiates the migration process, the VM administrator server 106 requests the Manufacturer Migration Server 104 to rewrap the APKs of the vTPMs based on the HSM 120 of the second cloud VM server 116. Rewrapping is a process where the keys are securely encrypted using the new HSM's identifier and HUS, making them valid and secure for use on the second cloud VM server 116. Once the APKs have been rewrapped, the VM administrator server 106 then revokes the vTPMs on the first cloud VM server 108 and activates them on the second cloud VM server 116 using the rewrapped APKs. This ensures that the vTPMs are securely transferred and continue to function correctly on the new server without exposing the cryptographic keys to any potential security risks.
[0062] In accordance with an embodiment, the VM administrator server 106 is further configured to authenticate itself to the Manufacturer Migration Server 104 during instantiation and to request a cloud migration group for the VM administrator server in the Manufacturer Migration Server 104. By authenticating itself, the VM administrator server 106 ensures that only authorized entities can manage vTPM migrations. Requesting a cloud migration group secures the process by limiting operations to specific, controlled cloud VM servers. This approach prevents unauthorized access, safeguards sensitive data, and enhances the efficiency and reliability of the migration process.
[0063] For example, a company is running a critical application on the cloud VM server (the first cloud VM server 108) that uses vTPMs for securing data. Due to a failure in the first server, the company needs to migrate the application to another cloud VM server (the second cloud VM server 116) quickly. The VM administrator server 106 detects the failure and initiates a migration request. It communicates with the Manufacturer Migration Server 104, which rewraps the cryptographic keys (APKs) used by the vTPMs of the first server, making them valid for use on the second server. The vTPMs are then securely moved to the second server, where they continue to protect the application’s data, ensuring minimal downtime and maintaining the security of sensitive information during the migration process.
[0064] The first cloud VM server 108 has an HSM 112 with the identifier "HSM123" and HUS "secretA123". The second cloud VM server 116 has the HSM 120 with identifier "HSM456" and HUS "secretB456”. The Manufacturer Migration Server 104 has a database entry “HSM123:secretA123” and “HSM456:secretB456”. The first cloud VM server 108 is running two vTPMs namely the first vTPM 110A and the second vTPM HOB. The second cloud VM server 116 is running the first vTPM 118A. Each vTPM has its own APK. The first vTPM 110A uses the first APK. The second vTPM HOB uses a second APK. Further, the first vTPM 118A of the second cloud VM server 116 uses a third APK. The VM Administrator server 106 decides that it should be in the migration group. The VM Administrator Server 106 sends a message to the Manufacturer Migration Server 104. The Manufacturer Migration Server 104 now knows that vTPMs can be migrated between these servers. When the first vTPM 110A needs to perform a cryptographic operation. The first vTPM 110A requests HSM 112 to unwrap the first APK. The HSM 112 uses its identifier "HSM123" and HUS "secretA123" to unwrap the first APK. The first vTPM 110A uses the unwrapped APK to perform the cryptographic operation. Once done, the first APK is securely erased from memory.
[0065] In accordance with an embodiment, the VM administrator server 106 is further configured to the Manufacturer Migration Server to remove the first cloud VM server from the cloud migration group. In order to migrate the second vTPM HOB from the first cloud VM server 108 to the second cloud server 116. A user requests to move a VM associated with the second vTPM 110B to the second cloud server 116. The VM Administrator Server 106 recognizes this need and initiates the migration process. The VM Administrator Server 106 sends a request to the Manufacturer Migration Server 104. To Rewrap the second APK for migration from “HSM123” to “HSM456”.
[0066] Further, the Manufacturer Migration Server 104 unwraps the second APK using “HSM123's secrets”. Re-encrypts the second APK using HSM456's secrets. Sends the rewrapped second APK back to the VM Administrator Server 106. The VM Administrator Server 106 transfers the second vTPM 110B, and its rewrapped APK to the second cloud server 116.
[0067] On the first cloud server 108, the VM Administrator Server 106 instructs the first cloud server 108 to be revoked. The first cloud server 108 removes all traces of the second vTPM 110B and its original APK. On the second cloud server 116, the VM Administrator Server instructs the second cloud server 116 to establish the second vTPM 110A. The HSM 120 unwraps the rewrapped APK using its identifier "HSM456" and HUS "secretB456". The vTPM HOB is now operational on the second cloud server 116 with its correctly unwrapped APK.
[0068] In accordance with an embodiment, the Manufacturer Migration Server 104 is further configured to ensure that each HSM only belongs to one migration group. Ensuring that each HSM belongs to only one migration group enhances security by preventing unauthorized or accidental cross-group migrations. The restriction minimizes the risk of data breaches and ensures that cryptographic keys and other sensitive assets remain isolated within their designated environment, maintaining the integrity and trustworthiness of the migration process. Additionally, it simplifies management by clearly defining the boundaries and associations of each HSM, reducing the likelihood of configuration errors, and ensuring that migrations occur within a controlled and secure framework.
[0069] In accordance with an embodiment, the VM administrator server 106 is further configured to determine that there is a request to move at least one of the vTPM(s) by determining that there has been a failure in the first cloud VM server. Advantageously, by automatically detecting server failures and responding by securely transferring the vTPMs, the VM administrator server 106 enhances the resilience and reliability of the virtual machine system. The automatic detection reduces the need for manual intervention, accelerates recovery time, and maintains the integrity of sensitive cryptographic operations, leading to a more robust and fault-tolerant cloud infrastructure.
[0070] FIG. 2A is a block diagram of vTPM extended with a computer virtual trusted platform module (Co-vTPM), in accordance with an embodiment of the present disclosure. With reference to FIG.2A, there is shown a block diagram 200A that includes a virtual trusted platform module (vTPM) 202. The vTPM 202 is extended with computer virtual trusted platform module (Co- vTPM) 216 via a co-trusted platform module 208. Further, the vTPM 202 is bound to the co-trusted platform module 208. The co-trusted platform module 208 includes a processor 210, a transceiver 212, and a memory 214. An extended co-trusted platform module 206 is an arrangement in which the co-trusted platform module 208 is extended with the Co-vTPM 216. The extended co-trusted platform module 206 extends the functionality of a traditional TPM to provide secure virtualization of TPM functionality in a virtualized environment. The extended co-trusted platform module 206 incorporates a dedicated coprocessor called the Co-vTPM 216, which securely manages and protects the sensitive assets of multiple vTPM instances while allowing external storage of the encrypted assets, mitigating memory limitations and the risk of unauthorized duplication or access. The vTPM 202 is a virtualized counterpart of a physical TPM, i.e., a co-trusted platform module designed to provide secure cryptographic functions within virtualized environments. The vTPM 202 ensures the integrity and security of virtual machines by utilizing the functionalities of the co-trusted platform module 208. The vTPM 202 may be implemented alongside the hypervisor, in a dedicated virtual machine, or within trusted execution environments / enclaves, offering various levels of security and isolation to protect sensitive data and cryptographic operations. The Co-vTPM 216 supports the vTPM 202 by serving as a coprocessor. The Co-vTPM stores protected assets of the vTPM 202 outside the vTPM 202 itself, enhancing security and reducing memory footprint. The Co-vTPM 216 supports vTPM 202 functionalities and ensures the confidentiality and integrity of sensitive assets, further strengthening the security posture of virtualized environments.
[0071] The communication network 204 includes a medium (e.g., a communication channel) through which the Co-vTPM 216 communicates with the vTPM 202 present inside the virtual machine platform. The communication network 204 may be wired or wireless. Examples of the communication network 204 may include, but are not limited to, a Local Area Network (LAN), a wireless personal area network (WPAN), a Wireless Local Area Network (WLAN), a wireless wide area network (WWAN), a cloud network, a Long-Term Evolution (LTE) network, a plain old telephone service (POTS), a Metropolitan Area Network (MAN), and / or Internet.
[0072] The Co-Trusted Platform Module 208 refers to a specialized hardware component, also called a physical Trusted Platform Module of the HSM, that collaborates with the vTPM 202 to enhance the security of the virtual environment. The Co-Trusted Platform Module 208 serves as the primary repository for cryptographic keys used in the encryption and protection of sensitive data associated with the vTPM 202.
[0073] The processor 210 is configured to execute all necessary operations of the co-trusted platform module 208. Examples of processor 210 may include, but are not limited to, a microcontroller, a microprocessor, a central processing unit (CPU), a complex instruction set computing (CISC) processor, an application-specific integrated circuit (ASIC) processor, a reduced instruction set (RISC) processor, a very long instruction word (VLIW) processor, a data processing unit, and other processors or control circuitry.
[0074] The transceiver 212 refers to a component responsible for sending and receiving signals related to security functions and communication protocols within the co-trusted platform module 208. The transceiver 212 facilitates the exchange of information between the co-trusted platform module 208 and other components of the co-trusted platform module 208, such as the central processing unit (CPU), memory, and input / output devices.
[0075] The memory 214 is configured to store the instructions executable by the processor 210. Examples of the memory 214 may include, but are not limited to, an Electrically Erasable Programmable Read-Only Memory (EEPROM), Random Access Memory (RAM), Read-Only Memory (ROM), Hard Disk Drive (HDD), Flash memory, Solid-State Drive (SSD), persistent memory, remote direct memory access (RDMA), or CPU cache memory.
[0076] The transceiver 212, memory 214 and the processor 210 may be implemented in separate chipsets or may be implemented in the common co- trusted platform module 208.
[0077] The Co-vTPM 216 is a coprocessor integrated into the extended co-trusted platform module 206. The Co-vTPM 216 is designed to securely support and protect multiple vTPM instances in a virtualized environment. The Co-vTPM 216 is configured to store protected assets 218 of the Co-Trusted Platform Module 208 in a memory outside Co-vTPM 216.
[0078] The protected assets 218 refer to sensitive information or resources associated with the virtual trusted platform module 202 that are safeguarded from unauthorized access or manipulation. The protected assets 218 may include several types of data or cryptographic keys crucial for the secure functioning of the vTPM 202 and the overall trusted computing environment. There is provided the vTPM 202 that is configured to transmit a request to a coprocessor. The request being associated with a sensitive asset for a functionality of the vTPM 202. The vTPM 202 sends a request to a designated coprocessor. The request may involve operations that require access to sensitive assets, such as cryptographic keys, endorsement certificates, or attestation data. The sensitive assets are critical for various security functions performed by the vTPM 202, such as secure boot, remote attestation, or cryptographic operations. The request sent by the vTPM 202 is strongly associated with sensitive assets that are crucial for its operation. These assets may include private cryptographic keys, seed values, or other confidential information required for secure operation. For example, the request might involve generating an attestation signature using the private attestation key stored within the vTPM 202. Transmitting requests to a coprocessor helps isolate sensitive operations from the primary processing environment of the vTPM 202. The isolation may prevent potential security threats, such as sidechannel attacks or memory-based exploits, from compromising the confidentiality or integrity of sensitive assets stored within the vTPM 202.
[0079] The vTPM 202 is further configured to receive a response from the coprocessor the response indicating a security information associated with the functionality of the vTPM 202. After receiving the request, the coprocessor processes the task and generates a response. The response contains security information that is directly associated with the functionality of the vTPM 202. The nature of this security information depends on the specific operation requested by the vTPM 202. For example, if the vTPM 202 requested the generation of a cryptographic key pair, the response would include the newly generated public and private keys. Further, if the vTPM 202 requested an attestation signature, the response would include the signed attestation data. If the vTPM 202 requested secure storage or retrieval of data, the response would indicate the success or failure of the operation and any relevant metadata or verification information.
[0080] The vTPM 202 is further configured to provide the functionality of the virtual trusted platform module based on the received security information, the vTPM 202 is extended with a Computer Virtual Trusted Platform Module (Co-vTPM) 216. The Co- vTPM 216 is configured to store protected assets of the Co-Trusted Platform Module in a memory outside Co-vTPM 216, the APK is a protected asset. Once the vTPM 202 receives the security information from the coprocessor, it utilizes this information to perform its intended functionality. The functionality provided by the vTPM 202 may vary depending on the specific task or operation for which it was designed. This could include tasks related to secure boot, cryptographic key management, attestation, encryption / decryption, or any other security-related operation. The received security information plays a crucial role in ensuring that the vTPM 202 operates securely and effectively, as it may contain data necessary for cryptographic operations, access control decisions, or integrity verification. The method involves extending the functionality of the vTPM 202 by incorporating a Computer Virtual Trusted Platform Module, referred to as the Co-vTPM 216. The Co-vTPM 216 serves as an additional security component that works alongside the vTPM 202 to enhance its capabilities and protect sensitive assets. By introducing the Co-vTPM216,the overall security posture ofthe virtual trusted platform module is strengthened, as it provides an additional layer of protection for critical assets and operations. The outside storage mechanism ensures that sensitive assets, such as cryptographic keys, configuration data, or attestation secrets, are safeguarded against unauthorized access or tampering. By storing these assets outside the Co-vTPM 216, the vTPM 202 adopts a defence-in-depth approach to security, reducing the risk of asset exposure or compromise in the event of a security breach.
[0081] FIG. 2B is an exemplary diagram that depicts the utilization of HBK and the APK, in accordance with an embodiment of the present disclosure. FIG. 2B is described in conjunction with elements from FIG 2A. With reference to FIG.2B, there is shown the key components involved in protecting the sensitive assets of the Co-vTPM instance 220 using the Co-vTPM 216. The exemplary diagram 200B is divided into two main sections a VMM-vTPMl 222 and the extended co-trusted platform module 206. The VMM-vTPMl 222 section represents the software component running within the virtualized environment, responsible for emulating the TPM functionality for a specific virtual machine (VM). The Protected vTPM asset 224 represents a sensitive asset (e.g., endorsement key, attestation key, or state information) that needs to be protected. The protected APK 228 is the Asset Protection Key (APK) that is wrapped (encrypted) using the HBK 232 from the Co-trusted platform module 208. A Universally Unique Identifier (UUID) 230 is used to associate the Co-vTPM instance 220 with a VM it serves.
[0082] The extended co-trusted platform module 206 section represents the hardware component that acts as a secure coprocessor for the Co-vTPM instance 220. A first asset 236 of vTPMl , represents the sensitive vTPM asset that needs to be processed within the Co-vTPM 216. The Asset Protection Key is protected by the HBK 232 and is specific to the Co- vTPM instance 220 being served. The VMM-vTPMl 222 has a sensitive Protected vTPM asset 224 that needs to be processed by the Co-vTPM 216. The VMM-vTPMl 222 sends the Protected vTPM asset 224 and the Protected APK 228 to the Co-vTPM 216, along with the UUID 230. Inside the Co-vTPM 216, the protected APK 228 is unwrapped (decrypted) using the HBK 232, yielding the APK 234. The Protected vTPM asset 224 is decrypted using the APK 234 to get the first asset 238 using, e.g. AES (Advanced Encryption Standard) algorithm. The necessary operations (e.g., cryptographic operations, key generation) are performed on the first asset 238 of vTPMl within the Co-vTPM 216. The processed first asset 236 of vTPMl is encrypted using the APK and the AES algorithm. The encrypted first asset 236 of vTPMl is returned to the VMM-vTPMl 222 for storage or further processing. Sensitive vTPM assets are only present unencrypted within the Co-vTPM 216 during processing, ensuring their protection. The APK 234 is generated using a true random bit generator 240 and protected using the HBK 232 and is specific to each vTPM instance, binding the assets to the Co-vTPM 216. The vTPM assets are stored encrypted outside the Co-vTPM 216, mitigating memory limitations within the hardware module. The UUID 230 associates the Co-vTPM instance 220 with the corresponding VM, preventing asset mixing or interchange. The approach provides hardware-based protection for the sensitive vTPM assets while enabling external storage and secure processing through the Co-vTPM 216.
[0083] FIG. 3 is a flowchart depicting a method for the VM system, in accordance with an embodiment of the present disclosure. With reference to FIG. 3, there is shown a flowchart of a method 300 for the VM system 102. The method 300 includes steps 302 to 312.
[0084] At step 302, the method 300 includes Manufacturer Migration Server 104 storing identifiers and HUSs of manufactured HSMs. The Manufacturer Migration Server 104 is responsible for storing the identifiers and the HUSs of the HSMs) that are manufactured. The HSMs are installed in the cloud VM servers. The identifier is a unique tag that identifies each HSM, while the HUS is a secret key embedded in the HSM during its manufacture. The Manufacturer Migration Server 104 stores this information to manage HSMs during operations like key migration. When the HSM is manufactured, its identifier and HUS are sent to the Manufacturer Migration Server 104. The Manufacturer Migration Server 104 securely stores these details in its database for future operations.
[0085] At step 304, the method 300 includes VM administrator server 106 informing the Manufacturer Migration Server 104 that the first cloud VM server 108 and the second cloud VM server 116 are associated in a cloud migration group. The VM administrator server 106 informs the Manufacturer Migration Server 104 that two cloud VM servers are associated with a cloud migration group. This means that the two cloud VM servers are linked in a way that allows secure migration of vTPMs between them. The VM administrator server 106 sends a request to the Manufacturer Migration Serve 104 containing the identifiers of the first cloud VM server 108 and the second cloud VM server 116. The Manufacturer Migration Serve 104 then associates these servers as part of the same cloud migration group.
[0086] At step 306, the method 300 includes VM administrator server 106 informing the Manufacturer Migration Server 104 of the HSMs of the first cloud VM server 108 and the second cloud VM server 116, whereby the Manufacturer Migration Server 104 has access to the identifiers and the HUSs of the HSMs of the first cloud VM server 108 and the second cloud VM server 116. The VM administrator server 106 provides the Manufacturer Migration Serve 104 with information about the HSMs on both the first cloud VM server 108 and the second cloud VM server 116. This includes the HSM identifiers and ensures that the Manufacturer Migration Serve 104 has access to their HUSs. The VM administrator server 106 retrieves the HSM identifiers from both cloud VM servers. This information is communicated to the Manufacturer Migration Serve 104, which checks its records to match the identifiers with the stored HUSs.
[0087] At step 308, the method 300 includes the VM administrator server 106, determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server 108 to the second cloud VM server 116. The VM administrator server 106 determines that there is a request to move one or more vTPMs from the first cloud VM server to the second. This could be triggered by various conditions, such as server failure or load balancing. The VM administrator server 106 monitors the cloud VM servers for conditions that require vTPM migration. When such a condition is detected, the server flags a migration request.
[0088] At step 310, the method 300 includes VM administrator server 106 requesting the Manufacturer Migration Server 104 to rewrap the APK(s) of the vTPM(s) of the first cloud VM server 108 based on the HSM of the second cloud VM server 116. In response to the migration request, the VM administrator server 106 directs the Manufacturer Migration Serve 104 to rewrap APKs of the vTPMs being moved. The rewrapping process involves securing the APKs using the HUS of the HSM on the second cloud VM server 116. The VM administrator server 106 sends a request to the Manufacturer Migration Serve 104 to rewrap the APKs. The Manufacturer Migration Server 104 retrieves the HUS 122 of the HSM 120 on the second cloud VM server 116 and rewraps the APKs with this new HUS. The rewrapped APKs are then sent back to the VM administrator server 106.
[0089] At step 312, the method 300 includes VM administrator server 106 revoking the vTPM(s) of the first cloud VM server 108 on the second cloud VM server 116 utilizing the rewrapped APK(s). Revoking the vTPMs on the first cloud VM Server 108. Once the APKs are rewrapped, the VM administrator server 106 can revoke the vTPMs on the first cloud VM server 108 and activate them on the second cloud VM server 116 using the new rewrapped APKs. The VM administrator server 106 removes or disables the vTPMs on the first cloud VM server 108. It then installs the vTPMs on the second cloud VM server using the rewrapped APKs, ensuring they function securely under the new HSM’s protection.
[0090] The steps 302 to 312 are only illustrative, and other alternatives can also be provided where one or more steps are added, one or more steps are removed, or one or more steps are provided in a different sequence without departing from the scope of the claims herein.
[0091] There is provided a computer program product comprising program instructions for performing the method 300, when executed by one or more processors in the VM system 102. In an example, the instructions are implemented on the computer-readable media, which include, but are not limited to, Electrically Erasable Programmable Read-Only Memory (EEPROM), Random Access Memory (RAM), Read-Only Memory (ROM), Hard Disk Drive (HDD), Flash memory, a Secure Digital (SD) card, Solid-State Drive (SSD), a computer-readable storage medium, and / or CPU cache memory. In an example, the instructions are generated by a computer program, which is implemented in view of the method 300 for optimizing the CDP with the large keyvalue store.
[0092] FIG. 4. is an exemplary diagram depicting the process flow for migrating virtual machines (VMs) and their associated vTPMs between different cloud servers, in accordance with an embodiment of the present disclosure. FIG. 4 is explained in conjunction with the elements from FIGs 1 to 3. With reference to FIG. 4, there is shown an exemplary diagram 400 including a cloud migration group 402. The cloud migration group 402 represents the group of cloud servers managed by the VM Administrator Server 106. Each Cloud VM Host server runs VMs (virtual machines), each with its own vTPM. For example, a first cloud VM host 406 present inside the first cloud VM server 108 includes a plurality of virtual machines i.e., a first virtual machine 408A, up to nth virtual machine 408N. The first cloud host 406 further includes a migration engine 410 and a plurality of Secure Virtual Machine (SVM) with corresponding vTPM, for example, a first SVM with a first vTPM 412A up to nth SVM with nth vTPM 412N. Similarly, nth cloud VM host 418 presents inside the nth cloud VM server 416 includes a plurality of virtual machines i.e., a first virtual machine 420 A, up to nth virtual machine 420N. The nth cloud VM host 418 further includes a migration engine 422 and a plurality of Secure Virtual Machine (SVM) with corresponding vTPM, for example, a first SVM with a first vTPM 424A up to nth SVM with nth vTPM 424N.
[0093] The vTPMs are bound to the HSM on the respective cloud VM host server, using the HSM's HUS as the Root of Trust. When there is a request to move a VM from one cloud VM host server to another, the VM Administrator Server 106 is responsible for coordinating the migration. The VM Administrator Server 106 informs the Manufacturer Migration Server 104 about the migration, providing the details of the source and destination cloud VM servers and their associated HSMs. The Manufacturer Migration Server 104 has access to the identifiers 430 and HUSs of the HSMs used across the cloud servers. Upon receiving the migration request from the VM Administrator Server 106, the Manufacturer Migration Server 104 can rewrap the APK of the vTPM associated with the migrating VM. The Manufacturer Migration Server 104 uses the HUS of the destination HSM to rewrap the APK, ensuring the vTPM data remains securely bound to the new cloud VM server. After the Manufacturer Migration Server 104 has rewrapped the APK, the VM Administrator Server 106 can complete the migration process by revoking the vTPM on the source Cloud VM Host server and enabling the vTPM on the destination Cloud VM Host server using the new, rewrapped APK.
[0094] A Cloud Disk Server 428 is a shared storage component in the cloud migration group 402 and serves as a central storage location for the VMs and vTPM data, to enable migration of VMs between the different Cloud VM servers. By storing the VMs and vTPM data on the shared the Cloud Disk Server 428 it allows the VMs to be moved between the hosts without requiring the entire VM and vTPM state to be transferred directly between the hosts. The shared storage approach facilitates the migration process and helps enable the resilience and flexibility of the overall VM and vTPM management.
[0095] A Migration Manager 404 is present within the VM Administrator Server 106. The Migration Manager 404 coordinates and orchestrates the migration of the VMs, including their associated vTPMs, between the different Cloud VM servers. When a migration request is triggered, the Migration Manager 404 interacts with the Manufacturer Migration Server 104 to facilitate the secure rewrapping of the vTPMs Asset Protection Key (APK). The Migration Manager 404 ensures the migration process is executed correctly, including revoking the vTPM on the source host and enabling it on the destination host using the new, rewrapped APK. By centralizing the migration management within the VM Administrator Server 106, the Migration Manager 404 provides a unified control point to manage the mobility of the VMs and vTPMs across the cloud cluster. The process allows for the secure migration of VMs and their associated vTPMs between different cloud servers, even if the original HSM is not available. The Manufacturer Migration Server 104 plays a crucial role in facilitating the migration by rewrapping the APK, ensuring the vTPM data remains protected and can be successfully migrated to the new host.
[0096] FIG. 5 is a flowchart depicting a method for the VM administrator server, in accordance with an embodiment of the present disclosure. FIG. 5 is described in conjunction with elements from FIGs. 1 to 4. With reference to FIG. 5, there is shown a flowchart of a method 500 for the VM administrator server 104. The method 500 includes steps 502 to 510.
[0097] At step 502, the method 500 includes VM administrator server 106 informing the Manufacturer Migration Server 104 that the first cloud VM server 108 and the second cloud VM server 116 are associated in a cloud migration group. The VM Administrator Server 106 establishes a secure communication link with the Manufacturer Migration Server 104. The VM Administrator Server 106 identifies the first cloud VM server 108 and the second cloud VM server 116. Each of these servers (the first cloud VM server 108 and the second cloud VM server) has unique identifiers, which might include details like their network addresses, names, or other system-specific identifiers. The VM Administrator Server 106 then groups these two servers together under a "cloud migration group. " The cloud migration group is a logical grouping that tells the Manufacturer Migration Server 104 that these servers are to be treated as part of the same migration process. The VM Administrator Server 106 sends a message or a series of data packets to the Manufacturer Migration Server 104. The message contains the identifiers of both the first cloud VM server 108 and the second cloud VM server A notification that the first cloud VM server 108 and the second cloud VM server are now associated with each other for migration purposes. The Manufacturer Migration Server 104 receives this information and acknowledges the association. It may store the details of this group and prepare to manage any future requests related to migration between these servers, such as rewrapping security keys or transferring virtual machines.
[0098] At step 504, the method 500 includes informing the Manufacturer Migration Server 104 of the HSMs of the first cloud VM server 108 and the second cloud VM server 116, whereby the Manufacturer Migration Server 104 has access to the identifiers and the HUSs of the HSMs of the first cloud VM server 108 and the second cloud VM server 116. Each cloud VM server (the first cloud VM server 108 and the second cloud VM server 116) is equipped with a Hardware Security Module (HSM). The HSM is a dedicated hardware device used for securely managing cryptographic keys. Each HSM has a unique identifier and a Hardware Unique Secret (HUS), which are crucial for its operation and security functions. The VM Administrator Server 106 retrieves the relevant details about the HSMs from both the first cloud VM server 108 and second cloud VM server 116.
[0099] The VM Administrator Server 106 securely transmits the identifiers and HUSs of the HSMs to the Manufacturer Migration Server. This is done over a secure communication channel to ensure that sensitive information, such as the HUSs, is not exposed or intercepted during the transmission. Upon receiving the information, the Manufacturer Migration Server 104 stores the identifiers and HUSs for both HSM of the first cloud VM server 108 and the second cloud VM server 116. This information is critical for the Manufacturer Migration Server 104 to manage and coordinate migrations securely between the first cloud VM server 108 and the second cloud VM server 116. The Manufacturer Migration Server 104 may verify the received information to ensure it is correct and consistent. After verification, the Manufacturer Migration Server 104 acknowledges the receipt and readiness to use this information for any future migration processes.
[0100] With the identifiers and HUSs of the HSMs now accessible, the Manufacturer Migration Server 104 can facilitate secure operations involving these HSMs. For example, it can manage the rewrapping of cryptographic keys when the vTPM is migrated from one cloud VM server to another. The process ensures that the Manufacturer Migration Server 104 has all the necessary information to securely manage and facilitate migrations between the first and second cloud VM servers, specifically focusing on the cryptographic integrity provided by the HSMs.
[0101] At step 506, the method 500 includes the VM administrator server 106 determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server 108 to the second cloud VM server 116. The VM administrator server 106 constantly monitors for any requests related to the management of virtual machines (VMs) or their associated components, such as vTPMs. These requests can come from system administrators, automated scripts, or other management tools. A request is made to move the vTPM from the first cloud VM server 108 to the second cloud VM server 116. The request may be triggered by various scenarios, such as load balancing, hardware maintenance, disaster recovery, or upgrading server capabilities. The request typically includes details about which specific vTPM(s) need to be migrated, the current location (the first cloud VM server 108), and the target location (the second cloud VM server 116). The VM administrator server 106 validates the request to ensure that it is legitimate and feasible, which includes checking whether the target server has the necessary resources and whether the move complies with security and operational policies. The VM administrator server 106 also analyses any dependencies or requirements that must be met for the migration to occur, such as ensuring the second cloud VM server 116 has the appropriate HSM to support the vTPM. After validating the request, the VM administrator server 106 decides whether to proceed with the migration. If all conditions are met, the VM administrator server 106 prepares for the migration process. Once the decision is made to move the vTPM, the VM administrator server 106 initiates the necessary steps to conduct the migration, which may involve notifying the Manufacturer Migration Server 104 to manage cryptographic keys and ensuring the secure transfer of the vTPM. At step 508, the method 500 includes the Manufacturer Migration Server 104 to rewrap the APK(s) of the vTPM(s) of the first cloud VM server 108 based on the HSM of the second cloud VM server 116. Each vTPM uses the APK to encrypt and protect sensitive data. This key is originally wrapped (encrypted) by the EISM on the first cloud VM server 108, which is the root of trust for that vTPM. When a vTPM needs to be migrated from the first cloud VM server 108 to the second cloud VM server 116, the APK wrapped by the first server’s EISM cannot be directly used by the second server’s EISM. To ensure security, the APK must be "rewrapped" or re-encrypted using the EISM of the second cloud VM server 116. The VM administrator server 106 sends a request to the Manufacturer Migration Server 104 to rewrap the APK(s) of the vTPMs. This request includes details about the vTPMs to be moved and the target EISM (the EISM of second cloud VM server 116). The Manufacturer Migration Server 104 retrieves the necessary identifiers and EIUSs for both the first cloud VM server's EISM (where the APK is currently wrapped) and the second cloud VM server's EISM (where the APK needs to be rewrapped). The Manufacturer Migration Server 104 uses the PIUS of the first cloud VM server's HSM to unwrap (decrypt) the APK. It then re-encrypts the APK using the HUS of the second cloud VM server's HSM. This process changes the wrapping of the APK so that it is now secured by the second cloud VM server’s HSM. Once the APK is rewrapped, it is sent to the second cloud VM server, where it can be used by the migrated vTPM. The vTPM on the second cloud VM server can now function securely, with its APK protected by the new HSM. The VM administrator server 106 verifies that the migration is complete and that the vTPM is operating correctly on the second cloud VM server 116.
[0102] At step 510, the method 500 revoke the vTPM(s) of the first cloud VM server 108 on the second cloud VM server 116 utilizing the rewrapped APK(s). During the migration, the original APKs (used to secure the vTPMs on the first cloud VM server 108) are rewrapped by the Manufacturer Migration Server (MMS) so that they can be securely used on the second cloud VM server 116 with its HSM. Once the vTPMs have been migrated, the original versions of these vTPMs (still associated with the first cloud VM server) need to be deactivated or "revoked" to prevent them from functioning on the new server (second cloud VM server) in an unauthorized or conflicting manner. After the vTPMs are successfully migrated to the second cloud VM server using the rewrapped APKs, the original vTPMs on the first cloud VM server are no longer needed and could pose a security risk if left active.
[0103] On the second cloud VM server 116, the rewrapped APKs are used to validate the newly migrated vTPMs. Using these rewrapped APKs to ensure that only the new, securely migrated vTPMs can operate on the second cloud VM server 116. This step ensures that the original APKs (associated with the first cloud VM server) cannot be used again on the second cloud VM server, effectively "revoking" the old vTPMs. The revocation process ensures that any remnants of the vTPMs from the first cloud VM server 108 are not allowed to function on the second cloud VM server 116. This prevents any conflicts or potential security breaches, ensuring that only the correctly migrated vTPMs, secured by the rewrapped APKs, are active on the second cloud VM server. By revoking the original vTPMs on the second cloud VM server using the rewrapped APKs, the method guarantees that the migration is secure and that only the intended, authorized vTPMs are operational.
[0104] The steps 502 to 510 are only illustrative, and other alternatives can also be provided where one or more steps are added, one or more steps are removed, or one or more steps are provided in a different sequence without departing from the scope of the claims herein.
[0105] FIG. 6 is a flowchart depicting a method for the Manufacturing Migration Manager, in accordance with an embodiment of the present disclosure. FIG. 6 is described in conjunction with elements from FIGs. 1 to 5. With reference to FIG. 6, there is shown a flowchart of a method 600 for the Manufacturing Migration Manager 104. The method 600 includes steps 602 to 610.
[0106] At step 602, the method 600 includes the Manufacturer Migration Server 104 storing identifiers and HUSs of manufactured HSMs. The Manufacture Migration Manager 104 is responsible for securely storing the identifiers and HUSs of all HSMs that are manufactured. Each HSM is associated with a unique identifier and HUS, which serve as the cryptographic foundation for securing vTPMs. The centralized storage ensures that the Manufacturing Migration Manager 104 has complete knowledge of all HSMs used across the cloud VM servers, allowing it to facilitate secure migration and management of vTPMs between different servers. It establishes a secure and trusted environment for HSM-based operations.
[0107] At step 604, the method 6 00 includes receiving information from the VM administrator server 106 that the first cloud VM server 108 and the second cloud VM server 116 are associated with the cloud migration group 402. The VM administrator server 106 informs the Manufacturing Migration Manager 104 that two or more cloud VM servers are associated with a cloud migration group 402. This group association indicates that these servers may need to share vTPMs or migrate them between each other. By grouping the cloud VM servers, the MMS can manage vTPM migrations more efficiently and securely. The grouping ensures that migrations occur only between trusted and pre-verified servers, reducing the risk of unauthorized data access or loss during migration.
[0108] At step 606, the method 600 includes the Manufacturer Migration Server 104 receiving information from the VM administrator server 106 on the HSMs of the first cloud VM server 108 and the second cloud VM server 116, whereby the Manufacturer Migration Server 104 has access to the identifiers and the HUSs of the HSMs of the first cloud VM server 108 and the second cloud VM server 116. The VM administrator server 106 provides the Manufacturer Migration Serve 104 with details about the HSMs in the first and second cloud VM servers, including their identifiers and HUSs. The information allows the Manufacturer Migration Serve 104 to understand the security environment of both servers. Having detailed information about the HSMs enables the Manufacturer Migration Serve 104 to manage the rewrapping of Asset Protection Keys (APKs) securely. The Manufacturer Migration Serve 104 can ensure that the security parameters of the destination HSM match those of the source HSM, maintaining the integrity of the vTPM during migration.
[0109] At step 608, the method 600 includes the Manufacturer Migration Server 104 receiving a request to rewrap the APK(s) of the vTPM(s) of the first cloud VM server 108 based on the HSM 122 of the second cloud VM server 116 from VM administrator server 106 the in response to the VM administrator server 106 determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server 108 to the second cloud VM server 116. When the VM administrator server 106 determines that a vTPM needs to be migrated from the first cloud VM server to the second, it requests the Manufacturer Migration Server 104 to rewrap the APK(s) associated with the vTPM(s). The rewrapping process adjusts the APK(s) so that they are compatible with the HSM of the second cloud VM server. Rewrapping the APKs ensures that the vTPMs can be securely transferred to the new server without compromising the security keys. This process enables seamless migration while maintaining the confidentiality and integrity of the protected assets.
[0110] At step 610, the method 600 includes the Manufacturer Migration Manager 104, enabling the VM administrator server 106 to revoke the vTPM(s) of the first cloud VM server 108 on the second cloud VM server 116 utilizing the rewrapped APK (s After rewrapping, the Manufacturing Migration Manager 104 allows the VM administrator server 106 to revoke the vTPMs on the first cloud VM server and instantiate them on the second server using the rewrapped APKs. The vTPM is securely decommissioned on the first server and activated on the second. This step ensures that the vTPMs are securely transferred without leaving residual data on the original server, which mitigates security risks. The use of rewrapped APKs guarantees that the vTPM functions properly in its pristine environment with the appropriate cryptographic keys.
[0111] The steps 602 to 610 are only illustrative, and other alternatives can also be provided where one or more steps are added, one or more steps are removed, or one or more steps are provided in a different sequence without departing from the scope of the claims herein.
[0112] Modifications to embodiments of the present disclosure described in the foregoing are possible without departing from the scope of the present disclosure as defined by the accompanying claims. Expressions such as "including", "comprising", "incorporating", "have", "is" used to describe, and claim the present disclosure are intended to be construed in a non-exclusive manner, namely allowing for items, components or elements not explicitly described also to be present. Reference to the singular is also to be construed to relate to the plural. The word "exemplary" is used herein to mean "serving as an example, instance or illustration". Any embodiment described as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments or to exclude the incorporation of features from other embodiments. The word "optionally" is used herein to mean "is provided in some embodiments and not provided in other embodiments". It is appreciated that certain features of the present disclosure, which are, for clarity, described in the context of separate embodiments, may also be provided in combination in a single embodiment. Conversely, various features of the invention, which are, for brevity, described in the context of a single embodiment, may also be provided separately or in any suitable combination or as suitable in any other described embodiment of the disclosure.
Claims
CLAIMS1. A virtual machine system (102) comprising a virtual machine, VM, administrator server (106) communicatively connected to a Manufacturer Migration Server (104), the VM administrator server (106) being configured to administrate a first cloud VM server (108) and a second cloud VM server (116), wherein each cloud VM server is configured to execute one or more virtual trusted platforms modules, vTPM, each utilizing an Asset Protection Key, APK, and wherein each cloud VM server comprises a Hardware Security Module, HSM, which is configured to: operate as Root of Trust, RoT for at least one of the vTPMs, and to unwrap the APK based on an identifier and a Hardware Unique Secret, HUS of the HSM, and wherein the Manufacturer Migration Server (104) is configured to store identifiers and HUSs of manufactured HSMs, and wherein the VM administrator server (106) is further configured to: inform the Manufacturer Migration Server (104) that the first cloud VM server (108) and the second cloud VM server (116) are associated in a cloud migration group, and to inform the Manufacturer Migration Server (104) of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), whereby the Manufacturer Migration Server (104) has access to the identifiers and the HUSs of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), wherein the VM administrator server (106) is further configured to: determine that there is a request to move at least one of the vTPM(s) from the first cloud VM server (108) to the second cloud VM server (116), and in response thereto request the Manufacturer Migration Server (104) to rewrap the APK(s) of the vTPM(s) of the first cloud VM server (108) based on the HSM of the second cloud VM server (116), and then revoke the vTPM(s) of the first cloud VM server (108) on the second cloud VM server (116) utilizing the rewrapped APK(s).
2. The VM system (102) according to claim 1, wherein the VM administrator server (106) is further configured to determine that there is a request to move at least one of the vTPM(s) by determining that there has been a failure in the first cloud VM server (108).
3. The VM system (102) according to claim 1 or 2, wherein the VM administrator server (106) is further configured to authenticate itself to the Manufacturer Migration Server (104) during instantiation and to request a cloud migration group for the VM administrator server (106) in the Manufacturer Migration Server (104).
4. The VM system (102) according to claim 1, 2 or 3, wherein the Manufacturer Migration Server (104) is further configured to ensure that each HSM only belong to one migration group.
5. The VM system (102) according to any preceding claim, wherein the VM administrator server (106) is further configured to replace an APK of a vTPM with the rewrapped APK in a data file of the vTPM.
6. The VM system (102) according to any preceding claim, wherein the VM administrator server (106) is further configured to request the Manufacturer Migration Server (104) to remove the first cloud VM server (108) from the cloud migration group.
7. The VM system (102) according to any preceding claim, wherein the virtual machine system (102) comprises the Manufacturer Migration Server (104).
8. The VM system (102) according to any preceding claim wherein each virtual trusted platform module (vTPM), is configured to: transmit a request to a coprocessor, the request being associated with a sensitive asset for a functionality of the virtual trusted platform module; receive a response from the coprocessor, the response indicating a security information associated with the functionality of the virtual trusted platform module; and provide the functionality of the virtual trusted platform module based on the received security information, wherein the virtual trusted platform module is extended with a Computer Virtual Trusted Platform Module, Co-vTPM (216), and wherein the Co-vTPM (216) is configured to store protected assets of the Co-Trusted Platform Module in a memory outside Co-vTPM (216), wherein the APK is a protected asset.
9. A method (300) for a virtual machine system (102) comprising a virtual machine, VM, administrator server (106) communicatively connected to a Manufacturer Migration Server (104), the VM administrator server (106) being configured to administrate a first cloud VM server (108) and a second cloud VM server (116), wherein each cloud VM server is configured to execute one or more virtual trusted platforms modules, vTPM, each utilizing an Asset Protection Key, APK, and wherein each cloud VM server comprises a Hardware Security Module, HSM, which is configured to: operate as Root of Trust, RoT for at least one of the vTPMs, and to unwrap the APK based on an identifier and a Hardware Unique Secret, HUS of the HSM, and wherein the method (300) comprises the Manufacturer Migration Server (104) storing identifiers and HUSs of manufactured HSMs, and wherein the method further comprises the VM administrator server (106) informing the Manufacturer Migration Server (104) that the first cloud VM server (108) and the second cloud VM server (116) are associated in a cloud migration group, and informing the Manufacturer Migration Server (104) of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), whereby the Manufacturer Migration Server (104) has access to the identifiers and the HUSs of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), wherein the method (300) further comprises the VM administrator server (106) determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server (108) to the second cloud VM server (116), and in response thereto requesting the Manufacturer Migration Server (104) to rewrap the APK(s) of the vTPM(s) of the first cloud VM server (108) based on the HSM of the second cloud VM server (116), and then revoking the vTPM(s) of the first cloud VM server (108) on the second cloud VM server (116) utilizing the rewrapped APK(s).
10. A computer program product comprising program instructions for performing the method (300) according to claim 9, when executed by one or more processors in a VM system (102).
11. A virtual machine, VM, administrator server (106) communicatively connected to a Manufacturer Migration Server (104) and wherein the VM administrator server (106) is configured to administrate a first cloud VM server (108) and a second cloud VM server (116), wherein each cloud VM server is configured to execute one or more virtual trusted platforms, vTPM, each utilizing an Asset Protection Key, APK, and wherein each cloud VM server comprises a Hardware Security Module, HSM, which is configured to: operate as Root of Trust, RoT for at least one of the vTPMs, and to unwrap the APK based on an identifier and a Hardware Unique Secret, HUS of the HSM, andwherein the Manufacturer Migration Server (104) is configured to store identifiers and HUSs of manufactured HSMs, and wherein the VM administrator server (106) is further configured to: inform the Manufacturer Migration Server (104) that the first cloud VM server (108) and the second cloud VM server (116) are associated in a cloud migration group, and to inform the Manufacturer Migration Server (104) of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), whereby the Manufacturer Migration Server (104) has access to the identifiers and the HUSs of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), wherein the VM administrator server (106) is further configured to determine that there is a request to move at least one of the vTPM(s) from the first cloud VM server (108) to the second cloud VM server (116), and in response thereto cause the Manufacturer Migration Server (104) to rewrap the APK(s) of the vTPM(s) of the first cloud VM server (108) based on the HSM of the second cloud VM server (116), and then revoke the vTPM(s) of the first cloud VM server on the second cloud VM server utilizing the rewrapped APK(s).
12. A method (500) for a virtual machine, VM, administrator server (106) , the VM administrator server (106) being configured to be communicatively connected to a Manufacturer Migration Server (104) and wherein the VM administrator server (106) is further configured to administrate a first cloud VM server (108) and a second cloud VM server (116), wherein each cloud VM server is configured to execute one or more virtual trusted platforms, vTPM, each utilizing an Asset Protection Key, APK, and wherein each cloud VM server comprises a Hardware Security Module, HSM, which is configured to: operate as Root of Trust, RoT for at least one of the vTPMs, and to unwrap the APK based on an identifier and a Hardware Unique Secret, HUS of the HSM, and wherein the Manufacturer Migration Server (104) is configured to store identifiers and HUSs of manufactured HSMs, and wherein the method comprises the VM administrator server (106) informing the Manufacturer Migration Server (104) that the first cloud VM server (108) and the second cloud VM server (116) are associated in a cloud migration group, and to informing the Manufacturer Migration Server (104) of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), whereby the Manufacturer Migration Server (104) has access to the identifiers and the HUSs of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), wherein the method (500) further comprises the VM administrator server (106) determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server (108) to the second cloud VM server (116), and in response thereto causing the Manufacturer Migration Server (104) to rewrap the APK(s) of the vTPM(s) of the first cloud VM server (108) based on the HSM of the second cloud VM server (116), and then revoke the vTPM(s) of the first cloud VM server (108) on the second cloud VM server (116) utilizing the rewrapped APK(s).
13. A Manufacturer Migration Server (104) communicatively connected to a virtual machine, VM, administrator server (106) in a virtual machine system (102), the VM administrator server (106) being configured to administrate a first cloud VM server (108) and a second cloud VM server (116), wherein each cloud VM server is configured to execute one or more virtual trusted platforms modules, vTPM, each utilizing an Asset Protection Key, APK, and wherein each cloud VM server comprises a Hardware Security Module, HSM, which is configured to: operate as Root of Trust, RoT for at least one of the vTPMs, and to unwrap the APK based on an identifier and a Hardware Unique Secret, HUS of the HSM, and wherein the Manufacturer Migration Server (104) is configured to: store identifiers and HUSs of manufactured HSMs, receive information from the VM administrator server (106) that the first cloud VM server (108) and the second cloud VM server (116) are associated in a cloud migration group, receive information from the VM administrator server (106) on the HSMs of the first cloud VM server (108) and the second cloud VM server (116), whereby the Manufacturer Migration Server (104) has access to the identifiers and the HUSs of the HSMs of the first cloud VM server (108) and the second cloud VM server (116), wherein the Manufacturer Migration Server (104) is further configured to: receive a request to rewrap the APK(s) of the vTPM(s) of the first cloud VM server (108) based on the HSM of the second cloud VM server (116) from VM administrator server (106) the in response to the VM administrator server (106) determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server (108) to the second cloud VM server (116), and thereby enabling the VM administrator server (106) to revoke the vTPM(s) of the first cloud VM server (108) on the second cloud VM server (116) utilizing the rewrapped APK(s).
14. The Manufacturer Migration Server (104) according to claim 13, wherein the Manufacturer Migration Server (104) is also communicably connected to a second virtual machine administrator server.
15. A method (600) for a Manufacturer Migration Server (104) communicatively connected to a virtual machine, VM, administrator server (106) in a virtual machine system (102), the VM administrator server (106) being configured to administrate a first cloud VM server (108) and a second cloud VM server (118), wherein each cloud VM server is configured to execute one or more virtual trusted platforms modules, vTPM, each utilizing an Asset Protection Key, APK, and wherein each cloud VM server comprises a Hardware Security Module, HSM, which is configured to: operate as Root of Trust, RoT for at least one of the vTPMs, and to unwrap the APK based on an identifier and a Hardware Unique Secret, HUS of the HSM, and wherein the method (600) comprises the Manufacturer Migration Server (104) storing identifiers and HUSs of manufactured HSMs, receiving information from the VM administrator server (106) that the first cloud VM server (108) and the second cloud VM server (116) are associated in a cloud migration group, receiving information from the VM administrator server (104) on the HSMs of the first cloud VM server and the second cloud VM server, whereby the Manufacturer Migration Server has access to the identifiers and the HUSs of the HSMs of the first cloud VM server and the second cloud VM server, wherein the method (600) further comprises the Manufacturer Migration Server22receiving a request to rewrap the APK(s) of the vTPM(s) of the first cloud VM server based on the HSM of the second cloud VM server from VM administrator server the in response to the VM administrator server determining that there is a request to move at least one of the vTPM(s) from the first cloud VM server (108) to the second cloud VM server (116), and thereby enabling the VM administrator server (106) to revoke the vTPM(s) of the first cloud VM server (108) on the second cloud VM server (116) utilizing the rewrappedAPK(s).23
Citation Information
Patent Citations
Method and apparatus for migrating virtual trusted platform modules
US20070094719A1
Distributed trusted platform module key management protection for roaming data
US20230066427A1