Trusted Execution Environment for Cloud VM Co-location Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud services lack the ability for customers to verify whether virtual machines (VMs) are co-located on the same physical machine, which is crucial for enforcing affinity or anti-affinity policies, leading to security and risk management concerns, as customers cannot trust information provided by the cloud provider.
Innovation Solution
The method leverages Trusted Execution Environment (TEE) functionalities, such as sealing/unsealing and local attestation, to collect and verify evidence on VM co-location, allowing cloud customers to reliably determine if their VMs are deployed on the same physical machine, even when the VM hypervisor or host operating system is not trustworthy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud providers deploy VMs on host machines without transparency, then cloud service scalability and cost reduction are improved, but customer trust and security verification capability deteriorate
Solution Approach 1:
The patent introduces TEE-based trusted applications as intermediaries between the cloud provider's VM deployment system and the customer's verification system. These trusted apps run in isolated TEE environments on host machines and generate cryptographically verifiable evidence about VM co-location, acting as mediators that enable customer verification without compromising cloud provider operational autonomy or scalability
2Adaptability or versatility
If cloud providers use traditional VM deployment methods, then deployment flexibility and cost efficiency are improved, but the ability to verify VM co-location deteriorates
Solution Approach 1:
The patent implements preliminary action by installing and configuring TEE-based trusted applications on host machines before VM deployment. These trusted applications are pre-configured to collect and report evidence about VM placement and co-location, enabling verification capability to be established in advance without interfering with the flexibility of actual VM deployment operations
3Device complexity
If cloud infrastructure lacks TEE-based verification, then system complexity and deployment cost are reduced, but security verification and policy enforcement capability deteriorate
Solution Approach 1:
The patent applies local quality by implementing TEE-based trusted applications specifically at the host machine level where VMs are deployed. Rather than requiring system-wide complexity changes, the solution locally enhances security verification capability at each host through isolated TEE environments that provide cryptographic proof of VM co-location without affecting other parts of the cloud infrastructure
Data Source
AI summary
A method for detecting co-located virtual machines (VMs) includes receiving one or more VM deployment requests from a user device. One or more VMs are deployed in a cloud infrastructure based on the VM deployment requests. The cloud infrastructure includes one or more host machines each having a trusted execution environment (TEE). Evidence is collected for each of the one or more VMs using a trusted application running in the respective TEE of the respective host machine. The collected evidence is inspected to determine whether at least two VMs in the one or more VMs share a same host machine in the one or more host machines. At least one VM is requested to be redeployed to meet a policy based on results of inspecting the collected evidence.


