Hypervisor PCR Validation for VM Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing trusted computing systems, including those using Trusted Platform Modules (TPMs), fail to effectively validate compliance with service level agreements (SLAs) and environmental requirements for virtual machines (VMs), especially when VMs migrate across different physical systems, as they lack comprehensive remote verification capabilities to ensure hardware and software configurations meet specified conditions.
Innovation Solution
A system and method that utilizes a hypervisor to cryptographically store and analyze configuration data in platform configuration registers (PCRs), allowing for remote verification of VM compliance by comparing stored data against predefined requirements, ensuring that the VM environment meets specified conditions through the integration of a Trusted Platform Module (TPM) and a Flexible Service Processor (FSP), even when the VM is running on a different physical system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If VMs are deployed in remote data-centres to provide cost benefits, then platform owners achieve cost efficiency, but system owners face difficulty in validating compliance with service level agreements
Solution Approach 1:
The patent introduces a Flexible Service Processor (FSP) as an intermediary component that resides on the remote data centre system and can be remotely accessed. The FSP acts as a mediator between the system owner and the remote data centre infrastructure, enabling the system owner to validate compliance with service level agreements without needing physical access to the remote system. The FSP stores cryptographic measurements of the host environment configuration and allows remote verification of these measurements, thus resolving the contradiction between cost efficiency of remote deployment and the ability to validate compliance.
2Adaptability or versatility
If VMs migrate from one physical system to another, then system flexibility and resource utilization improve, but compliance with environmental requirements may be broken without detection
Solution Approach 1:
The patent implements preliminary action by having the Flexible Service Processor store cryptographic measurements of the host environment configuration (such as hardware identifiers, firmware versions, and system settings) into platform configuration registers before the VM migration occurs. These measurements are cryptographically secured and can be later verified by the system owner. When a VM migrates to a new physical system, the system owner can remotely verify whether the new environment meets the required compliance standards by comparing cryptographic measurements, thus ensuring compliance assurance is maintained despite VM migration flexibility.
3Productivity
If administrators make changes to physical systems to improve system functionality, then system capabilities are enhanced, but VM requirements may be inadvertently broken
Solution Approach 1:
The patent implements a feedback mechanism where the Flexible Service Processor continuously monitors and stores cryptographic measurements of the host environment configuration. When administrators make changes to the physical system to enhance functionality, these changes are captured in the cryptographic measurements stored by the FSP. The system owner can then remotely verify whether these changes have caused any compliance violations by comparing the new cryptographic measurements against the stored baseline measurements. This feedback loop allows the system to maintain productivity improvements while ensuring SLA compliance is not inadvertently broken.
Data Source
AI summary
A system, method, and computer program product for providing validation of the compliance of a trusted host environment with a requirement of a virtual machine (VM). The system includes: a store component for cryptographically storing configuration data associated with the trusted host environment in at least one cryptographic data structure; a send component, responsive to the store component storing the configuration data, for sending the at least one cryptographic data structure to a control component; an analyze component, responsive to the control component receiving the at least one cryptographic data structure, for analyzing the at least one cryptographic data structure; a compare component, responsive to the analyze component determining the configuration data, for comparing the configuration data with the requirement; and a verify component, responsive to the compare component determining that the configuration data matches the requirement, for allowing verification of the VM.


