Multi-tenant TPM Namespace Isolation for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant cloud environments, clients face challenges in ensuring the security of their applications running on virtualized computing services, as they lack direct access to hardware and virtualization management software, making it difficult to verify that the execution environment has not been tampered with or compromised.

Innovation Solution

Implementing multi-tenant trusted platform modules (MTTPMs) on virtualization hosts, which include shared and per-GVM subcomponents, enables cryptographic attestation and secure communication channels to verify and isolate execution environments, ensuring higher security levels by designating hardware subcomponents for each guest virtual machine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share hardware resources among multiple customers, then resource utilization efficiency is improved, but security and trust verification of execution environments deteriorate

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity and trust verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the TPM hardware into multiple isolated namespaces, where each namespace corresponds to a specific virtual machine or tenant. This segmentation allows each customer to have dedicated cryptographic resources and configuration registers within the shared TPM, ensuring isolation and security while enabling multi-tenant resource sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization management component as an intermediary between the virtual machines and the physical TPM hardware. This mediator manages the allocation and isolation of TPM resources, handling attestation requests and coordinating access to shared hardware resources while maintaining security boundaries between tenants.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If a single physical computing machine is shared among multiple users with virtual machines, then cost efficiency is improved, but the ability to verify execution environment integrity deteriorates

Engineering Contradiction:
Improvecost efficiencyVSAvoidexecution environment integrity verification
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The TPM is segmented into multiple namespaces that can independently verify the integrity of their associated virtual machines. Each namespace maintains separate configuration registers and cryptographic keys, enabling individual integrity verification for each tenant while sharing the same physical hardware, thus maintaining cost efficiency without sacrificing verification capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each namespace within the TPM is configured with specific local qualities tailored to its associated virtual machine, including dedicated configuration registers and cryptographic parameters. This allows each tenant to have customized security settings and verification criteria while sharing the underlying hardware infrastructure.

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional TPMs are used in multi-tenant environments, then hardware security is improved, but the complexity of managing isolated security contexts for multiple tenants increases

Engineering Contradiction:
Improvehardware securityVSAvoidmanagement of isolated security contexts
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The TPM internally segments its resources into isolated namespaces, each managing its own security context independently. This segmentation automates the isolation of security contexts, reducing the management complexity that would otherwise arise from trying to maintain separate security states for multiple tenants in a traditional single-namespace TPM.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each namespace within the TPM can independently perform its own security operations, including key generation, storage, and attestation, without requiring external coordination for context isolation. This self-service capability within each namespace simplifies the overall management of multi-tenant security contexts.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10303879B1Multi-tenant trusted platform modules
Publication Date: 2019.05.28 AMAZON TECH INC
  • US10303879B1 patent drawing
  • US10303879B1 patent drawing
  • US10303879B1 patent drawing

AI summary

A multi-tenant trusted platform module (MTTPM) is attached to a communication bus of a virtualization host. The MTTPM includes a plurality of per-guest-virtual-machine (per-GVM) memory location sets. In response to an indication of a first trusted computing request (TCR) associated with a first GVM of a plurality of GVMs instantiated at the virtualization host, a first memory location of a first per-GVM memory location set is accessed to generate a first response indicative of a configuration of the first GVM. In response to an indication of a second TCR associated with a second GVM, a second memory location of a second-per-GVM memory location set is accessed to generate a second response, wherein the second response is indicative of a different configuration of the second GVM.