Hardware Secure Attestation for Virtual Machine Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing systems, there is a need to securely store workload attestation reports and manage identity certificates and integrity protection for container image disks, especially to prevent tampering by hypervisors and ensure authenticity, given the increasing pace of system software development and rising security breaches.

Innovation Solution

The implementation of hardware-based secure attestation technologies using trusted platform modules (TPMs) and Secure Encrypted Virtualization (SEV) modules to create isolated environments for VMs, mediate access to key managers for attestation reports, and distribute identity certificates securely, ensuring cryptographic verification and integrity protection of workloads and container image disks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud vendors use traditional virtualization without hardware-based security, then system complexity and ease of operation are maintained at acceptable levels, but security reliability and protection against hypervisor access to sensitive data are insufficient

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Trust Authority service as an intermediary component that mediates between the hypervisor and VM workloads. This service manages attestation reports, identity certificates, and encryption keys, providing a structured security framework without requiring fundamental changes to the virtualization architecture. The Trust Authority acts as a security policy enforcement point that adds reliability while maintaining manageable system complexity through service-oriented design.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security functions into distinct components: hardware-based attestation (TPM/SEV), Trust Authority service for certificate management, and workload-specific security contexts. This segmentation allows each component to be independently configured, managed, and updated, improving security reliability without creating monolithic complexity. The separation of attestation, certification, and encryption key management enables targeted security enhancements.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware-based secure attestation and encryption technologies are implemented, then security reliability and protection of sensitive data are improved, but device complexity and difficulty of operation increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The Trust Authority service implements self-service mechanisms by automatically generating and managing attestation reports, identity certificates, and encryption keys. The system performs automated attestation verification, certificate issuance, and key distribution without requiring manual intervention. This automation maintains security reliability while significantly improving ease of operation, as the security infrastructure manages itself through standardized protocols and procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary security actions by establishing attestation reports and identity certificates before workloads execute sensitive operations. The Trust Authority pre-configures security contexts, validates workload identities in advance, and distributes encryption keys before data processing begins. This preliminary authentication and authorization framework ensures security reliability while simplifying operational workflows, as security checks are performed upfront rather than during execution.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If traditional identity management is used without hardware-based attestation, then device complexity is lower, but measurement precision and verification of workload authenticity are insufficient

Engineering Contradiction:
Improveverification precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional software-based identity verification with hardware-based attestation mechanisms. Trusted Platform Modules (TPM) and Secure Encrypted Virtualization (SEV) provide cryptographic proof of workload identity and integrity through hardware-enforced measurements. This substitution dramatically improves verification precision, as hardware-based attestation provides tamper-evident proof of system state, while the modular Trust Authority service manages the complexity of integrating these hardware mechanisms into the existing virtualization infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11709700B2Provisioning identity certificates using hardware-based secure attestation in a virtualized and clustered computer system
Publication Date: 2023.07.25 VMWARE INC
  • US11709700B2 patent drawing
  • US11709700B2 patent drawing
  • US11709700B2 patent drawing

AI summary

An example method of secure attestation of a workload deployed in a virtualized computing system is described. The virtualized computing system includes a host cluster and a virtualization management server, the host cluster having hosts and a virtualization layer executing on hardware platforms of the hosts. The method includes: launching, in cooperation with a security module of a host, a guest as a virtual machine (VM) managed by the virtualization layer, the security module generating an attestation report from at least a portion of the VM loaded into memory of the host; sending the attestation report from the security module to a trust authority; receiving, in response to verification of the attestation report by the trust authority, a secret from the trust authority at the security module; and providing the secret from the security module to the guest.