Per-LCS Secure Enclaves With vTPM for Workload Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems (IHSs) face challenges in securely migrating workloads due to the reliance on physical TPMs, which limits mobility and consistency in trust management, resource distribution, and multitenancy, as measurements and secrets are trapped locally, preventing seamless migration and efficient resource orchestration.

Innovation Solution

Implementing a microvisor and virtual TPM (vTPM) to provision and manage secure enclaves (LCSs) that allow for centralized management of secrets, enabling migration and consistent trust management across distributed environments, with a system control plane manager (SCPM) orchestrating resource distribution and multitenancy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical TPMs are used for secure workload execution, then security and trust management are improved, but workload mobility and resource distribution are limited

Engineering Contradiction:
ImprovesecurityVSAvoidworkload mobility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates virtual copies of TPM functionality through vTPM instances that can be migrated with workloads. Instead of relying on a single physical TPM, the system provisions virtual TPM instances that replicate the security functions of physical TPMs, enabling secure workload execution while maintaining mobility across different physical hosts.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The SCPM acts as an intermediary between physical TPM resources and virtualized workloads. It manages the provisioning, migration, and orchestration of vTPM instances, decoupling the security functions from specific physical hardware while maintaining trust management capabilities across the distributed system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical TPMs are used for secure enclaves, then trust management is improved, but resource distribution and multitenancy are limited

Engineering Contradiction:
Improvetrust managementVSAvoidresource distribution
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monolithic physical TPM resource into multiple virtual TPM instances, each capable of providing secure enclave functionality. This segmentation allows multiple tenants and workloads to have dedicated security resources while the SCPM orchestrates their distribution and management across the infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SCPM provides a universal management platform that handles multiple functions including vTPM provisioning, workload orchestration, secret management, and migration coordination. This centralized controller simplifies resource distribution by providing a single point of control for managing complex multi-tenant security resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If measurements and secrets are stored locally in physical TPMs, then security is improved, but migration capability is lost

Engineering Contradiction:
ImprovesecurityVSAvoidmigration speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system creates virtual representations of security measurements and secrets within the vTPM instances. These virtual security artifacts can be copied and migrated along with the workload to different physical hosts, maintaining security while enabling mobility. The actual physical TPM remains stationary while its security functions are virtualized and movable.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The SCPM mediates the migration process by coordinating the transfer of vTPM instances and their associated security measurements. It manages the orchestration of moving security state between hosts while maintaining trust relationships, enabling fast migration without requiring physical TPM movement.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If physical TPMs are bound to specific hosts, then security consistency is improved, but resource utilization efficiency deteriorates

Engineering Contradiction:
Improvesecurity consistencyVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent transforms the static binding between physical TPMs and hosts into a dynamic system where vTPM instances can be migrated and reassigned based on workload requirements. The SCPM dynamically orchestrates vTPM placement and movement, maintaining security consistency through coordinated migration while optimizing resource utilization by allocating security resources to where they are most needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The SCPM serves as an intermediary that decouples security consistency from physical host binding. It maintains trust relationships and security measurements while enabling flexible resource allocation by managing vTPM instances independently of specific physical hosts, thus improving both security consistency and resource utilization simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12602243B2Method and system for migratable composed per-LCS secure enclaves
Publication Date: 2026.04.14 DELL PROD LP
  • US12602243B2 patent drawing
  • US12602243B2 patent drawing
  • US12602243B2 patent drawing

AI summary

A method for managing an LCS includes: sending a request to a microvisor kernel of a microvisor to provision an LCS on a first information handling system (IHS), wherein the request comprises at least a configuration template (CT); sending a second request to the microvisor kernel to verify that an enclave with a virtual trusted platform module (vTPM) is ready to communicate with the LCS; initiating, based successfully verifying, provisioning of the LCS based on the CT, wherein the provisioning of the LCS comprises at least an initiation of a guest basic input/output system (BIOS) of the LCS; receiving a notification, from the microvisor kernel, specifying that the LCS has been provisioned; after the notification has been received: sending a second notification to a user of the first IHS, wherein the second notification specifies a predetermined expiry date of the enclave with the vTPM on the first IHS.