DPU Secure Vault Partitioning for Virtual TPM Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management solutions for computing fabrics do not adequately address the need for a collective trust zone environment, particularly in virtualized environments with Virtual Machines (VMs) and Containers, and the cost of implementing hardware security modules (HSMs) can be prohibitive.

Innovation Solution

Implement a virtualized firmware Trusted Platform Module (TPM) using a secure vault-backed DPU, partitioned into multiple secure domains, to provide a Root-of-Trust (ROT) for VMs and Containers, leveraging standard TPM style open APIs and reducing the need for hardware HSMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware security modules (HSMs) are implemented for each VM and Container, then security and trust zone environment are improved, but cost and device complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments a single physical HSM into multiple virtual HSM instances through virtualization. The HSM controller divides the secure vault into multiple isolated domains, each providing dedicated security services to VMs and containers. This segmentation allows multiple security instances to share one physical device, reducing overall complexity while maintaining security isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal HSM controller that can serve multiple VMs and containers simultaneously through virtualization. The single HSM device performs multiple security functions for different virtual machines, eliminating the need for separate physical HSMs for each VM. This multi-functionality reduces device complexity while maintaining security through virtualized isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If a single HSM is shared among multiple VMs and Containers through virtualization, then cost and device complexity are reduced, but security isolation and trust zone integrity may be compromised

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The secure vault within the HSM is segmented into multiple isolated domains using eFuses and memory partitioning. Each domain provides dedicated security services to specific VMs or containers, ensuring that compromise of one domain does not affect others. This segmentation maintains security isolation while enabling resource sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different domains within the secure vault are configured with distinct security policies, access controls, and cryptographic parameters tailored to specific VMs or containers. Each domain has customized security characteristics appropriate to its workload, while sharing the same physical HSM infrastructure.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If firmware TPM is virtualized into multiple virtual TPMs, then adaptability to different VMs and Containers is improved, but device complexity and management overhead increase

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The firmware TPM is virtualized into multiple virtual TPM instances that can be allocated to different VMs and containers. A single physical TPM device provides security services to multiple virtual machines through the virtualization layer, enabling adaptability to diverse workloads while managing complexity through centralized control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

A virtualization layer acts as an intermediary between the physical firmware TPM and multiple VMs/containers. This intermediary manages the complexity of virtualizing TPM functionality, handling domain isolation, resource allocation, and API translation, while presenting simplified interfaces to individual VMs.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Extent of automation

If identity management solutions are implemented for computing fabrics, then automated provisioning and updates are improved, but they do not address the need for collective trust zone environment

Engineering Contradiction:
Improveautomated provisioningVSAvoidtrust zone environment
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent merges identity management capabilities with HSM virtualization to create a unified trust infrastructure. The virtualized HSM not only provides security services but also establishes collective trust zones across multiple VMs and containers, combining automated provisioning with trust establishment in a single integrated system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtualized HSM acts as an intermediary that bridges identity management and trust zone creation. It receives automated provisioning requests and translates them into secure trust zone configurations, ensuring that automated processes maintain security integrity and establish proper trust relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12561452B2Virtualizing secure vault of data processing unit for secure hardware security module for hosts
Publication Date: 2026.02.24 CISCO TECHNOLOGY INC
  • US12561452B2 patent drawing
  • US12561452B2 patent drawing
  • US12561452B2 patent drawing

AI summary

A system and method of securing and virtualizing firmware trusted platform modules (TPMs) for virtualizing a hardware security module (HSM) for a host within a network fabric is provided. The system and method include operably coupling a set of components associated with a host comprising a data processing unit (DPU) secure vault and a firmware trusted platform module (TPM). The firmware TPM is configured as a virtual firmware TPM. The DPU secure vault secures the virtual firmware TPM into one or more virtual firmware TPMs based on one or more partitions configured with the DPU secure vault. A virtual TPM manager communicatively coupled to the DPU secure vault manages one or more virtual TPMs for hosting a set of Virtual Machines (VMs) or Containers.