Host Software Stack Attestation via Privileged Memory Locking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing confidential computing systems lack a mechanism to securely verify the trustworthiness of the host software stack to a virtual machine, which is essential for building trust and ensuring the integrity of computations.
Innovation Solution
The system allows a virtual machine to integrate a measurement of a host software stack into the attestation process, using a security service with higher privilege levels to lock and measure the host memory pages, generating a cryptographic report that can be verified by the attestation server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a virtual machine runs in a host environment, then computing flexibility and resource sharing are improved, but the ability to verify trustworthiness of the host software stack deteriorates
Solution Approach 1:
The patent introduces a security service as an intermediary component with elevated privileges that acts as a mediator between the host software stack and the virtual machine. This security service performs cryptographic measurements of the host software stack and provides attestation reports, enabling the virtual machine to verify host trustworthiness without compromising the host's operational flexibility or resource sharing capabilities.
2Productivity
If the host software stack is allowed to modify memory pages freely, then system flexibility and performance are improved, but the integrity and trustworthiness of the host deteriorates
Solution Approach 1:
The patent applies preliminary action by performing cryptographic measurements of the host software stack before the virtual machine begins execution. The security service measures the host software stack's memory pages and generates attestation reports in advance, establishing trust before the virtual machine operates, thus not interfering with the host's performance while ensuring integrity.
Solution Approach 2:
The security service serves as an intermediary that independently verifies host software integrity without restricting the host's ability to modify memory pages for performance optimization. The security service uses elevated privileges to measure memory pages and provide attestation, separating the verification function from the execution function.
3Reliability
If a security service with higher privilege levels is introduced to measure and lock memory pages, then trust verification capability is improved, but device complexity increases
Solution Approach 1:
The security service is designed as a multi-functional component that performs multiple tasks: it has elevated privileges for accessing protected memory, executes cryptographic measurements of the host software stack, generates attestation reports, and provides verification data to the virtual machine. By consolidating these functions into a single service, the patent reduces overall system complexity compared to having separate components for each function.
Data Source
AI summary
An example method may include booting, by a host computer system, an operating system (OS) kernel; locking, by a security service running on the host computer system, a plurality of physical pages in a memory of the host computer system, wherein the plurality of physical pages is designated for use by the OS kernel, wherein the plurality of physical pages, upon locking, are unmodifiable by the OS kernel, and wherein the security service is associated with a privilege level higher than a privilege level of the OS kernel; performing, by the security service, a cryptographic measurement on the plurality of the physical pages; and generating, by the host computer system, a measurement report based on the cryptographic measurement.


