Chained Security Systems for Cloud VM Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, ensuring the security and integrity of virtual machines and data is challenging due to shared resources and lack of direct customer control over hardware and software, leading to potential compromises in security and data integrity.
Innovation Solution
A tiered credentialing approach is implemented, using a trusted co-processor as a limited subsystem (l-sys) to manage administrative processes and provide credentials to a main subsystem (m-sys), enabling attestation and verification of virtual machine states to ensure pristine and trusted execution environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud computing resources are shared and managed by providers, then resource scalability and accessibility are improved, but security control and data integrity are worsened
Solution Approach 1:
The system segments security verification into multiple hierarchical levels: hardware layer (TRM device), virtualization layer (hypervisor), and guest OS layer. Each layer has its own measurement and verification mechanisms, allowing security to be maintained at each segment while enabling overall system scalability.
Solution Approach 2:
A trusted measurement root device (TRM) acts as an intermediary between the cloud provider's hardware and the customer's virtual machines. The TRM provides remote attestation capabilities that enable customers to verify VM integrity without having direct control over the physical hardware, thus maintaining security while enabling cloud resource sharing.
2Productivity
If virtual machines run in shared cloud environments, then resource utilization efficiency is improved, but security assurance and execution environment trust are worsened
Solution Approach 1:
The system performs preliminary measurements and attestation of the hardware and software stack before virtual machines are deployed. The TRM device pre-establishes a chain of trust by measuring the hypervisor and other critical components, ensuring that the execution environment is trustworthy before resources are allocated to multiple customers.
Solution Approach 2:
The system implements continuous feedback through remote attestation mechanisms that allow customers to verify the integrity of their virtual machines and the underlying infrastructure. This feedback loop provides ongoing security assurance even in shared environments where resources are dynamically allocated.
3Ease of manufacture
If customers rent cloud resources without owning hardware, then capital expenditure and maintenance costs are reduced, but direct control over security and integrity are worsened
Solution Approach 1:
The system enables customers to perform self-verification of their virtual machine security and integrity through remote attestation capabilities provided by the TRM device. Customers can independently verify that their VMs are running in the expected environment without requiring direct hardware control or trusting the provider blindly.
Data Source
AI summary
A tiered credentialing approach provides assurance to customers having virtual machines running in a remote environment that the virtual images for these machines are in a pristine state and running in a trusted execution environment. The environment can be divided into multiple subsystems, each having its own cryptographic boundary, secure storage, and trusted computing capabilities. A trusted, limited subsystem can handle the administrative tasks for virtual machines running on the main system of a host computing device. The limited system can receive a certificate from a certificate authority, and can act as a certificate authority to provide credentials to the main system. Upon an attestation request, the subsystems can provide attestation information using the respective credentials as well as the certificate chain. An entity having the appropriate credentials can determine the state of the system from the response and verify the state is as expected.


