Secure Enclave Key Provisioning for VM Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional communication security measures in virtual machines are ineffective against malicious actors due to lack of trust establishment, as they can be vulnerable to spoofing and man-in-the-middle attacks, especially when sensitive data is transmitted over networks.

Innovation Solution

The implementation of secure enclaves within virtual machines, which utilize cryptographic protections and access control mechanisms to ensure the confidentiality and integrity of data, along with attestation systems to verify the authenticity and trustworthiness of applications and their host systems, using secure execution environments and cryptographic keys for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional communication security measures are used in virtual machines, then ease of operation is maintained, but reliability deteriorates due to vulnerability to spoofing and man-in-the-middle attacks

Engineering Contradiction:
Improvetrust establishmentVSAvoidsecurity infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements secure enclaves nested within virtual machines, which are themselves nested within the host system. This nested architecture allows the secure enclave to provide hardware-based security guarantees while maintaining the virtualization layer's flexibility and ease of operation, thus improving reliability without significantly increasing operational complexity

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces an attestation system as an intermediary that verifies the identity and trustworthiness of virtual machines before allowing secure communication. This mediator component enables reliable trust establishment by providing cryptographic verification mechanisms that prevent spoofing and man-in-the-middle attacks while maintaining a manageable security infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure enclaves with cryptographic protections are implemented, then reliability improves through trusted execution, but device complexity increases due to additional security mechanisms

Engineering Contradiction:
Improvedata confidentiality and integrityVSAvoidcryptographic key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic key management functions into a dedicated secure enclave environment, separating them from the main virtual machine operations. This extraction allows complex cryptographic operations to be performed in a isolated, hardware-protected space, improving data confidentiality and integrity while managing complexity through functional separation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure enclave implements self-service mechanisms for key generation, storage, and management, operating autonomously within the hardware-protected environment. This self-service approach allows the system to handle complex cryptographic key management internally without requiring external intervention or increasing operational complexity for users

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10338957B2Provisioning keys for virtual machine secure enclaves
Publication Date: 2019.07.02 INTEL CORP
  • US10338957B2 patent drawing
  • US10338957B2 patent drawing
  • US10338957B2 patent drawing

AI summary

A secure migration enclave is provided to identify a launch of a particular virtual machine on a host computing system, where the particular virtual machine is launched to include a secure quoting enclave to perform an attestation of one or more aspects of the virtual machine. A root key for the particular virtual machine is generated using the secure migration enclave hosted on the host computing system for use in association with provisioning the secure quoting enclave with an attestation key to be used in the attestation. The migration enclave registers the root key with a virtual machine registration service.