DPU Secure Vault Partitioning for Virtual TPM Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management solutions for computing fabrics do not adequately address the need for a collective trust zone environment, particularly in virtualized environments with Virtual Machines (VMs) and Containers, and the cost of implementing hardware security modules (HSMs) can be prohibitive.
Innovation Solution
Implement a virtualized firmware Trusted Platform Module (TPM) using a secure vault-backed DPU, partitioned into multiple secure domains, to provide a Root-of-Trust (ROT) for VMs and Containers, leveraging standard TPM style open APIs and reducing the need for hardware HSMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware security modules (HSMs) are implemented for each VM and Container, then security and trust zone environment are improved, but cost and device complexity increase significantly
Solution Approach 1:
The patent segments a single physical HSM into multiple virtual HSM instances through virtualization. The HSM controller divides the secure vault into multiple isolated domains, each providing dedicated security services to VMs and containers. This segmentation allows multiple security instances to share one physical device, reducing overall complexity while maintaining security isolation.
Solution Approach 2:
The patent implements a universal HSM controller that can serve multiple VMs and containers simultaneously through virtualization. The single HSM device performs multiple security functions for different virtual machines, eliminating the need for separate physical HSMs for each VM. This multi-functionality reduces device complexity while maintaining security through virtualized isolation.
2Device complexity
If a single HSM is shared among multiple VMs and Containers through virtualization, then cost and device complexity are reduced, but security isolation and trust zone integrity may be compromised
Solution Approach 1:
The secure vault within the HSM is segmented into multiple isolated domains using eFuses and memory partitioning. Each domain provides dedicated security services to specific VMs or containers, ensuring that compromise of one domain does not affect others. This segmentation maintains security isolation while enabling resource sharing.
Solution Approach 2:
Different domains within the secure vault are configured with distinct security policies, access controls, and cryptographic parameters tailored to specific VMs or containers. Each domain has customized security characteristics appropriate to its workload, while sharing the same physical HSM infrastructure.
3Adaptability or versatility
If firmware TPM is virtualized into multiple virtual TPMs, then adaptability to different VMs and Containers is improved, but device complexity and management overhead increase
Solution Approach 1:
The firmware TPM is virtualized into multiple virtual TPM instances that can be allocated to different VMs and containers. A single physical TPM device provides security services to multiple virtual machines through the virtualization layer, enabling adaptability to diverse workloads while managing complexity through centralized control.
Solution Approach 2:
A virtualization layer acts as an intermediary between the physical firmware TPM and multiple VMs/containers. This intermediary manages the complexity of virtualizing TPM functionality, handling domain isolation, resource allocation, and API translation, while presenting simplified interfaces to individual VMs.
4Extent of automation
If identity management solutions are implemented for computing fabrics, then automated provisioning and updates are improved, but they do not address the need for collective trust zone environment
Solution Approach 1:
The patent merges identity management capabilities with HSM virtualization to create a unified trust infrastructure. The virtualized HSM not only provides security services but also establishes collective trust zones across multiple VMs and containers, combining automated provisioning with trust establishment in a single integrated system.
Solution Approach 2:
The virtualized HSM acts as an intermediary that bridges identity management and trust zone creation. It receives automated provisioning requests and translates them into secure trust zone configurations, ensuring that automated processes maintain security integrity and establish proper trust relationships.
Data Source
AI summary
A system and method of securing and virtualizing firmware trusted platform modules (TPMs) for virtualizing a hardware security module (HSM) for a host within a network fabric is provided. The system and method include operably coupling a set of components associated with a host comprising a data processing unit (DPU) secure vault and a firmware trusted platform module (TPM). The firmware TPM is configured as a virtual firmware TPM. The DPU secure vault secures the virtual firmware TPM into one or more virtual firmware TPMs based on one or more partitions configured with the DPU secure vault. A virtual TPM manager communicatively coupled to the DPU secure vault manages one or more virtual TPMs for hosting a set of Virtual Machines (VMs) or Containers.


