LCS vTPM Provisioning Through SCP Isolation at Scale
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional LCS provisioning systems face security vulnerabilities due to hypervisor access to physical TPM devices, limited scalability, and inefficiency in managing large numbers of Logically Composed Systems (LCSs, particularly when providing multiple LCSs for different users.
Innovation Solution
The system employs a virtual Trusted Platform Module (vTPM) integrated with a secure SCP storage subsystem, enabling secure communication channels and vTPM management within a System Control Processor (SCP) framework to provide secure and scalable LCS provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical TPM devices are used for LCS provisioning, then security can be maintained for each LCS, but the system cannot scale to accommodate large numbers of LCSs and the hypervisor has full access to TPM contents increasing vulnerability
Solution Approach 1:
The patent segments the physical TPM device into multiple virtual TPM instances (vTPM1, vTPM2, vTPM3, etc.), each dedicated to a specific LCS. This segmentation allows the system to maintain security for each individual LCS while scaling to accommodate many LCSs simultaneously, as each vTPM is isolated and cannot be accessed by the hypervisor or other LCSs.
Solution Approach 2:
The patent creates virtual copies of the physical TPM device functionality through vTPM instances. Instead of using the physical TPM directly for each LCS (which would require hypervisor access), the system creates software-based copies that emulate TPM functionality while maintaining security isolation and enabling scalable provisioning of numerous LCSs.
2Reliability
If physical TPM devices are used for LCS provisioning, then security can be maintained, but the physical TPM devices are not sized to accommodate large numbers of LCSs and lack durability for frequent swaps
Solution Approach 1:
The patent creates virtual copies of TPM functionality that can be rapidly instantiated and destroyed without physical wear. These vTPM instances can be created in software and allocated to LCSs quickly, enabling frequent provisioning and deprovisioning operations without the durability limitations of physical TPM devices.
Solution Approach 2:
The patent changes the fundamental parameter of TPM storage capacity from fixed physical limits to virtually unlimited software-based storage. The secure SCP storage subsystem can allocate storage space dynamically for each vTPM instance, allowing the system to accommodate any number of LCSs without being constrained by physical device size or endurance ratings.
3Ease of operation
If physical TPM devices are used with hypervisor management, then LCS provisioning can be performed, but the hypervisor having full access to TPM contents increases security vulnerability
Solution Approach 1:
The patent extracts TPM functionality from the physical device and relocates it to a virtualized form managed by the SCP engine rather than the hypervisor. This extraction removes the security vulnerability by ensuring that even the hypervisor cannot access vTPM contents, while the SCP engine maintains the ability to provision and manage LCSs securely.
Solution Approach 2:
The patent introduces the SCP engine as an intermediary between the resource management system and the vTPM instances. This intermediary layer provides secure management of TPM functionality without requiring hypervisor access to TPM contents, thereby maintaining provisioning capability while eliminating the security vulnerability of direct hypervisor-TPM access.
Data Source
AI summary
A secure LCS provisioning system includes a resource system coupled to a resource management system and including a resource system operating system and an SCP device. The SCP device receives LCS initialization information for an LCS from the resource management system and provides it to the resource system operating system. The SCP device also receives vTPM information for the LCS from the resource management system and uses it to provide an LCS vTPM for the LCS in a secure SCP storage subsystem. The SCP device then provides a secure communication channel between the resource system operating system and the secure SCP storage subsystem, and identifies a location of the LCS vTPM in the secure SCP storage subsystem to the resource system operating system, allowing the resource system operating system to access the LCS vTPM and use it with the LCS initialization information to provide an LCS.


