Host Software Stack Attestation via Privileged Memory Locking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing confidential computing systems lack a mechanism to securely verify the trustworthiness of the host software stack to a virtual machine, which is essential for building trust and ensuring the integrity of computations.

Innovation Solution

The system allows a virtual machine to integrate a measurement of a host software stack into the attestation process, using a security service with higher privilege levels to lock and measure the host memory pages, generating a cryptographic report that can be verified by the attestation server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a virtual machine runs in a host environment, then computing flexibility and resource sharing are improved, but the ability to verify trustworthiness of the host software stack deteriorates

Engineering Contradiction:
Improvecomputing flexibilityVSAvoidtrust verification capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a security service as an intermediary component with elevated privileges that acts as a mediator between the host software stack and the virtual machine. This security service performs cryptographic measurements of the host software stack and provides attestation reports, enabling the virtual machine to verify host trustworthiness without compromising the host's operational flexibility or resource sharing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the host software stack is allowed to modify memory pages freely, then system flexibility and performance are improved, but the integrity and trustworthiness of the host deteriorates

Engineering Contradiction:
Improvesystem performanceVSAvoidhost software integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing cryptographic measurements of the host software stack before the virtual machine begins execution. The security service measures the host software stack's memory pages and generates attestation reports in advance, establishing trust before the virtual machine operates, thus not interfering with the host's performance while ensuring integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security service serves as an intermediary that independently verifies host software integrity without restricting the host's ability to modify memory pages for performance optimization. The security service uses elevated privileges to measure memory pages and provide attestation, separating the verification function from the execution function.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a security service with higher privilege levels is introduced to measure and lock memory pages, then trust verification capability is improved, but device complexity increases

Engineering Contradiction:
Improvetrust verification capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security service is designed as a multi-functional component that performs multiple tasks: it has elevated privileges for accessing protected memory, executes cryptographic measurements of the host software stack, generates attestation reports, and provides verification data to the virtual machine. By consolidating these functions into a single service, the patent reduces overall system complexity compared to having separate components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250190235A1Mechanism allowing a host software stack to prove its identity and build trust to a guest
Publication Date: 2025.06.12 RED HAT INC
  • US20250190235A1 patent drawing
  • US20250190235A1 patent drawing
  • US20250190235A1 patent drawing

AI summary

An example method may include booting, by a host computer system, an operating system (OS) kernel; locking, by a security service running on the host computer system, a plurality of physical pages in a memory of the host computer system, wherein the plurality of physical pages is designated for use by the OS kernel, wherein the plurality of physical pages, upon locking, are unmodifiable by the OS kernel, and wherein the security service is associated with a privilege level higher than a privilege level of the OS kernel; performing, by the security service, a cryptographic measurement on the plurality of the physical pages; and generating, by the host computer system, a measurement report based on the cryptographic measurement.