Chained Security Systems for Cloud VM Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, ensuring the security and integrity of virtual machines and data is challenging due to shared resources and lack of direct customer control over hardware and software, leading to potential compromises in security and data integrity.

Innovation Solution

A tiered credentialing approach is implemented, using a trusted co-processor as a limited subsystem (l-sys) to manage administrative processes and provide credentials to a main subsystem (m-sys), enabling attestation and verification of virtual machine states to ensure pristine and trusted execution environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud computing resources are shared and managed by providers, then resource scalability and accessibility are improved, but security control and data integrity are worsened

Engineering Contradiction:
Improveresource scalabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments security verification into multiple hierarchical levels: hardware layer (TRM device), virtualization layer (hypervisor), and guest OS layer. Each layer has its own measurement and verification mechanisms, allowing security to be maintained at each segment while enabling overall system scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted measurement root device (TRM) acts as an intermediary between the cloud provider's hardware and the customer's virtual machines. The TRM provides remote attestation capabilities that enable customers to verify VM integrity without having direct control over the physical hardware, thus maintaining security while enabling cloud resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If virtual machines run in shared cloud environments, then resource utilization efficiency is improved, but security assurance and execution environment trust are worsened

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity assurance
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary measurements and attestation of the hardware and software stack before virtual machines are deployed. The TRM device pre-establishes a chain of trust by measuring the hypervisor and other critical components, ensuring that the execution environment is trustworthy before resources are allocated to multiple customers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback through remote attestation mechanisms that allow customers to verify the integrity of their virtual machines and the underlying infrastructure. This feedback loop provides ongoing security assurance even in shared environments where resources are dynamically allocated.

Inventive Principle:
Principle #23Feedback

3Ease of manufacture

If customers rent cloud resources without owning hardware, then capital expenditure and maintenance costs are reduced, but direct control over security and integrity are worsened

Engineering Contradiction:
Improvecost reductionVSAvoiddirect control
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The system enables customers to perform self-verification of their virtual machine security and integrity through remote attestation capabilities provided by the TRM device. Customers can independently verify that their VMs are running in the expected environment without requiring direct hardware control or trusting the provider blindly.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10621366B2Chained security systems
Publication Date: 2020.04.14 AMAZON TECH INC
  • US10621366B2 patent drawing
  • US10621366B2 patent drawing
  • US10621366B2 patent drawing

AI summary

A tiered credentialing approach provides assurance to customers having virtual machines running in a remote environment that the virtual images for these machines are in a pristine state and running in a trusted execution environment. The environment can be divided into multiple subsystems, each having its own cryptographic boundary, secure storage, and trusted computing capabilities. A trusted, limited subsystem can handle the administrative tasks for virtual machines running on the main system of a host computing device. The limited system can receive a certificate from a certificate authority, and can act as a certificate authority to provide credentials to the main system. Upon an attestation request, the subsystems can provide attestation information using the respective credentials as well as the certificate chain. An entity having the appropriate credentials can determine the state of the system from the response and verify the state is as expected.